Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Traffic Steering
    App Definitions 
    Certificate Pinned Applications

    Certificate Pinned Applications

    TLS certificate pinning is when a desktop or mobile application validates if the proposed server certificates match the hardcoded ones in the application. It’s a security technique used to prevent man-in-the-middle attacks (MITM) and secure access to your organization’s applications.

    Predefined certificate pinned applications bypass the Netskope cloud by default. You can also create custom certificate pinned apps and add them as exceptions for your steering configuration to bypass them.

    Certificate Pinned Apps

    On the Certificate Pinned Apps page (Settings > Security Cloud Platform > App Definition > Certificate Pinned Apps), you can:

    1. Search for a certificate pinned app by name or filter the apps by type or platform.
    2. Create a custom certificate pinned app.
    3. View a list of predefined and custom certificate pinned apps. For each app, you can see the following information:
      • Application: The name of the certificate pinned app. Click to edit the platform and definition information.
      • Type: The type of certificate pinned app.
        • Predefined: A common certificate pinned application that bypasses the Netskope cloud by default.
        • Custom: A certificate pinned app you created.
      • Platforms: The affected operating system platform for the certificate pinned app.
      • Bypassed in Steering: The total number of steering configurations where the certificate pinned app is added as an exception. Hover over the value to see the steering configuration names.
      • Last Edited: The last time the certificate pinned app was edited.
    4. Sort the table by application name, application type, or last edited.
    5. Click The More icon. to edit or delete a certificate pinned app. You can only delete custom apps.
    6. View up to 100 certificate pinned apps per page.
    7. View multiple pages of the table.
    Traffic-Steering-App-Definition-Certificate-Pinned-Apps.png

    Steering and Decrypting Certificate Pinned Applications

    You can decrypt traffic of some certificate pinned applications to apply Real-time Protection policies on it. In order to do so, you must first add the application in your steering profile.

    After you add the application, perform the following:

    1. Go to Settings > Security Cloud Platform > App Definition > Certificate Pinned Apps.

    2. Search for the certificate pinned application that you want to steer and decrypt the traffic.

    3. Click the ellipsis (…) for the selected application.

    4. Click Steering Config Exceptions.

    5. In the Actions column, click the dropdown menu for the steering profile you are configuring.

    6. Click More.

    7. If the traffic can be decrypted, select the Steer and decrypt at Netskope Cloud steering option.

      Once you select this option, all traffic corresponding to this application and operating system is steered through Netskope NewEdge Cloud and is automatically decrypted without any additional required configuration. You can then apply Real-time Protection policies on this application.

    Steering and Decrypting DevTools

    DevTools usually do not use the system’s certificate store, making the Netskope certificate deployed with NSClient ineffective. Such DevTools are either bypassed or require scripted configurations to deploy the Netskope certificate correctly.

    A simpler solution is to use Netskope’s advanced decryption technology to decrypt DevTools traffic without custom configuration.

    To do this, manually create these DevTools as custom cert-pinned applications. Refer to Creating a Custom Certificate Pinned Application for details.

    Netskope supports the following DevTools. Their configurations are outlined below:

    DEVTOOLPROCESSDOMAIN(S)
    Amazon Web Services (AWS) CLIaws.exe-
    Azure CLI (azcli)python.exe-
    Google Cloud (gcloud) CLIpython.exe-
    Composerphp.exe-
    Pythonpython.exe, pythonw.exe-

    After creating the custom cert-pinned app, configure its “steer and decrypt” option. Refer to Steering and decrypting certificate pinned applications for details.

    Predefined Certificate Pinned Application Exceptions

    By default, web traffic from the following predefined certificate pinned apps bypass the Netskope cloud and go directly to the destinations:

    ApplicationPlatform
    Adobe Creative CloudMac

    Windows

    Amazon DriveAndroid

    Mac

    Windows

    Amazon KindleMac

    Windows

    Amazon WorkSpacesMac
    Apple App StoreMac
    Backblaze B2 Cloud StorageWindows
    BitcasaMac

    Windows

    CarboniteMac

    Windows

    Cisco Webex TeamsMac

    Windows

    Citrix WorkspaceMac

    Windows

    CrowdStrike FalconMac

    Windows

    Diligent BoardsWindows
    DocuSigniOS

    Windows

    DropboxAndroid

    iOS

    Mac

    Windows

    DruvaMac

    Windows

    EgnyteMac

    Windows

    ElephantDriveMac

    Windows

    EventbriteiOS
    FacebookiOS

    Windows

    FilemailMac

    Windows

    FoursquareiOS

    Windows

    GitHubMac

    Windows

    Google Backup and SyncMac

    Windows

    Google DriveMac

    Windows

    Google HangoutsMac

    Windows

    Google PlayAndroid
    Google WorkspaceWindows
    GoToMeetingiOS

    Mac

    Windows

    iCloud DriveMac

    Windows

    Jungle DiskMac

    Windows

    KeybaseMac

    Windows

    LivePersonMac

    Windows

    Microsoft 365 OutlookMac

    Windows

    Microsoft Intune Company PortalMac
    Windows
    MozyMac
    OpenDriveWindows
    PingOne for EnterpriseAndroid
    Planview ProjectplaceWindows
    Rally SoftwareiOS
    Rescue Remote SupportMac

    Windows

    SalesforceMac
    SkypeWindows
    Skype for BusinessWindows
    SpiderOakiOS

    Windows

    SugarSyncMac

    Windows

    SwizznetWindows
    TeamVieweriOS

    Mac

    Windows

    Toggl TrackMac

    Windows

    TresoritWindows
    X (formerly Twitter)Android

    iOS

    Mac

    Windows

    WorkdayiOS
    ZoomMac

    Windows

    In this Topic
    • Certificate Pinned Applications