Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Netskope Private Access
    Private App Management
    Configure NPA Browser-based Access
    Enabling URL Rewrites, Custom Hostname and Portal Links for NPA Browser Access
    Configure a Custom Hostname for Browser Access

    Configure a Custom Hostname for Browser Access

    By default, Browser Access application segments are accessed through a default Netskope public host FQDN such as:

    192-168-1-100-443-tenantname.npaproxy.goskope.com

    Custom Hostname allows you to present a stable, branded external hostname, like myapps.example.com, to users when they launch Browser Access application segments from the portal, instead of the default Netskope public host FQDN. The Custom Hostname is used in the launch URL when users access Browser Access application segments from the portal, and remains active throughout the session. Portal tiles continue to display the application segment name or custom portal tile name.

    Tip

    Custom Hostname is optional. Browser Access functions normally with the default Netskope public host FQDN if no Custom Hostname is configured.

    Configure a Custom Hostname

    1. In the Browser Access application segment configuration, locate the Custom Hostname setting.
    2. Enter the desired external hostname (like myapps.example.com).
    3. Ensure that DNS for the custom hostname has a CNAME record pointing to the auto-generated tenant hostname.
    4. Confirm that a valid TLS certificate is in place for the custom hostname.
    5. Save the configuration.

    After propagation, launched sessions for this application will use the Custom Hostname as the external hostname.

    Considerations

    • Custom Hostname is configured per Browser Access application.
    • A valid TLS certificate must be configured for the custom hostname; certificate management is outside the Browser Access proxy.
    • If URL rewrite is also active, redirects issued by the backend application will be rewritten to use the Custom Hostname rather than the auto-generated hostname.

    Custom Hostname Verification

    1. Open the Browser Access portal and click the application tile. Confirm the launched URL uses the Custom Hostname.
    2. Complete authentication flows and confirm the Custom Hostname is retained throughout.

    Related Topics

    • Enabling URL Rewrites, Custom Hostname and Portal Links for NPA Browser Access
    • Configure Browser Access with URL Rewrite
    • Configure Portal Links
    • Configure Browser Access Applications

    In this Topic
    • Configure a Custom Hostname for Browser Access