To configure Zendesk for the Next Generation API Data Protection, follow the instructions below.
Prerequisite
-
The Zendesk administrator user role is required to grant access to Netskope.
This user account is required after the grant. Do not delete or downgrade the account.
Netskope recommends to create a dedicated service account (with Zendesk administrator role) exclusively for the Netskope integration. Deleting or downgrading this service account will break the integration with Netskope. Creating a dedicated service account will ensure that the integration with Netskope will not break due to an exiting employee, and consequently a deactivation of the account.
If you must delete or downgrade the account, initiate a re-grant with an alternative Zendesk administrator user role. -
If you have guest or external users in your SaaS environment belonging to domains considered internal, you must set the appropriate internal domains for Netskope to classify exposure accurately. To set up internal domains, follow this article.
Configure Netskope to Access your Zendesk Account
To authorize Netskope to access your Zendesk account, follow the steps below:
-
Log in to the Netskope tenant UI and go to Settings > Configure App Access > Next Gen > CASB API.
-
Under Apps, select Zendesk and click Setup CASB API Instance.
The Setup Instance window opens.
-
Under Zendesk Domain, enter the fully-qualified Zendesk domain URL (example: company.zendesk.com).
-
Under Administrator Email, enter the email address of the user who will receive an email notification when a policy violation or event triggers. This step is optional.
-
Under Instance Name, enter a name of the SaaS app instance. This step is optional and if left blank, Netskope will determine the name of the app instance post grant.
-
Click Grant Access.
You will be redirected to the Zendesk sign-in page.
-
Enter the Zendesk administrator username and password.
This user account is required after the grant. Do not delete or downgrade the account.
Netskope recommends to create a dedicated service account (with Zendesk administrator role) exclusively for the Netskope integration. Deleting or downgrading this service account will break the integration with Netskope. Creating a dedicated service account will ensure that the integration with Netskope will not break due to an exiting employee, and consequently a deactivation of the account.
If you must delete or downgrade the account, initiate a re-grant with an alternative Zendesk administrator user role. -
Review the permissions requested and click Allow.
The Netskope CASB API application asks for “Read all user data” permission because Zendesk does not provide specific scope to retrieve ticket activities. -
After accepting the permissions, you will be redirected to the successful result page. Click Close.
Refresh your browser, and you should see a green check icon next to the instance name.
You can receive audit events and alerts in Skope IT. To know more: Next Generation API Data Protection Skope IT Events.

