To configure Atlassian Confluence for the Next Generation API Data Protection, follow the instructions below.
Prerequisites
Before configuring Atlassian Confluence for the Next Generation API Data Protection, review the prerequisite.
-
You require an Atlassian standard, premium or enterprise subscription plan.
-
An Atlassian dedicated user account with Confluence Administrator global permission. Refer to Global Permissions Overview for more information.
A few important points to note:
– Netskope recommends to create a dedicated user account (with appropriate permission) exclusively for the Netskope integration. Revoking access to this account will break the integration with Netskope. Creating a dedicated user account will ensure that the integration with Netskope will not break due to an exiting employee, and consequently a deactivation of the account.
– Netskope can only access resources that are accessible by this service account. For example, if a page restriction prevents the service account from viewing a Confluence page, the page will not be scanned by Netskope.
– Do not use an Atlassian service account (the programmatic account type available in admin.atlassian.com) — these accounts lack an email inbox and cannot complete the OAuth authorization flow.
– If SSO is enforced, note that the account must be placed in a non-SSO authentication policy (requires Atlassian Guard).
– Ensure the account has a reachable email inbox, can log in interactively, is not tied to an individual employee, and holds the required global permissions.
Install the Netskope CASB API for Confluence App
The Netskope CASB API for Confluence app allows Netskope to integrate with the Atlassian Confluence webhook for supporting features like inventory and ongoing scan. In order to use webhook, this marketplace app requires the Read data from the host application permission.To install the app follow the instruction below:
-
Log in to your Atlassian Confluence site with a Confluence Administrator global permission account.
-
Access the app from:
-
Atlassian Jira Cloud Commercial: Netskope CASB API for Confluence
-
US FedRAMP: Netskope CASB API for Confluence
-
Canada Federal PBMM: Netskope CASB API for Confluence
-
-
Click Get it now.
-
Choose a site to install the app.
-
Click Install app.
-
You can verify the installation by navigating to Settings > Manage Apps and look for the Netskope CASB API for Confluence app.
Configure Netskope to Access your Atlassian Confluence account
To authorize Netskope to access your Atlassian Confluence account, follow the steps below:
-
Log in to the Netskope tenant UI and go to Settings > Configure App Access > Next Gen > CASB API.
-
Under Applications, select Confluence and click Setup CASB API Instance.
The Setup CASB API Instance window opens.
-
Under Site Domain, enter the fully-qualified domain name of the Atlassian account (example: mycompany.atlassian.net).
-
Under Administrator Email, enter the email address of the user who will receive an email notification when a policy violation or event triggers. This step is optional.
-
Under Instance Name, enter a name of the SaaS app instance. This step is optional and if left blank, Netskope will determine the name of the app instance post grant.
-
Click Grant Access.
You will be redirected to the Atlassian sign-in page.
-
Login with the Atlassian organization admin account.
-
Review the permissions requested.
To know more about the permissions, see Permissions Required for Confluence. -
On the Authorize for: drop-down list, select the site domain you entered in step 3.
-
Click Accept.
When the configuration results page opens, click Close.
Refresh your browser and you will see a green check icon next to the instance name.
You can receive audit events and alerts in Skope IT. To know more: Next Generation API Data Protection Skope IT Events.
Next, you can view the Next Generation API Data Protection Inventory page to get deep insights on various entities on your Atlassian Confluence site. For more information on the Inventory page, see Next Generation API Data Protection Inventory.
Next, you should configure a Next Generation API Data Protection policy. To do so, see Create a Next Generation API Data Protection Policy.

