This topic covers the steps to deploy Netskope Client for iOS mobile devices using IBM MaaS360.
Prerequisites
-
Download Netskope Root and Tenant Certificates and ensure the certificates are available when needed.
-
In the Netskope UI, go to Settings > Security Cloud Platform > Netskope Client > MDM Distribution. On MDM Distribution page, scroll down to Create VPN Configuration section to find your Organization ID.

-
User accounts provisioned within the MDM/EMM platform must match with those provisioned with the Netskope tenant.
Setting up Netskope Client
Setting up Netskope Client for iOS devices with IBM MaaS360 includes the following mandatory steps:
Deployment of Trusted Root Netskope Certificate Profile
To upload the Intermediate and Root certificates:
-
In the IBM MaaS360 console, go to Security > Policy.
-
Click Add Policy.
Or, you can also edit an existing policy.
-
Provide the following details:
-
Click Continue.
It navigates to the policy page where you can configure settings, add assignments, and review changes.
-
Expand Advanced Settings under Configure Settings.
-
Click Certificates.

-
Click Edit at the top-right corner of your screen.
-
Select the checkbox for Configure Trust or Credential Certificates on the Device.
-
Click Trust or CA Certificates > Netskope Root Certificate.
-
Provide the certificate name.
-
Click + icon to upload Netskope Root certificate.
-
Click Save.

-
Click the refresh icon on the right and select the uploaded certificate name from the dropdown.
-
Repeat the process for uploading and selecting the Intermediate certificate.
-
Assign the appropriate policies to user/device groups and click Next.
-
Review the policy.
-
Click Publish.
Push VPN Profile Configuration
To provide a seamless Netskope Client deployment in IBM MaaS360, you need to create a VPN profile controlled through security policies. You can either create a new security policy or a VPN profile to an existing policy. To learn more, view Create Security Policy.
To add a VPN profile in a security policy:
-
In the IBM MaaS360 console, go to Security > Policy.
-
Select an existing policy.
The policy details page is displayed.
-
From Configure Settings > Device Settings, select VPN.

-
Click Edit at the top-right of your screen to configure the settings.
-
Select Custom SSL from the list of dropdown options.
-
Enter a VPN Connection Name and provide the configuration details:
-
Identifier: com.netskope.Netskope
-
Host Name of the VPN Server: gateway-<tenant>.goskope.com
-
User Authentication Type: Select Password.
-
VPN on Demand Dictionary Rule: OnDemandEnabled
-
Custom Data 1: OrgKey=<ORG-ID TOKEN>
-
Custom Data 2: AddonHost=addon-<TENANT>.goskope.com
-
Custom Data 3: UserEmail=%email%
-
Custom Data 4: ForcedDisabledSteering=true
Add Custom Data 4 if the deployment requires NPA only traffic steering. -
Bundle Identifier: com.netskope.Netskope

-
-
Assign the appropriate policies to user/device groups and click Next.
-
Review the policy.
-
Click Publish.
Add Security Policy
The following section describes the steps to add appropriate iOS policies in the IBM MaaS360 console.
To add a security policy:
-
Go to Devices > Groups.
-
Choose the desired policy and click More..
-
Click Change Policy.
-
Select an appropriate iOS policy from the list of dropdown items.
-
Click Submit.
Add Netskope Client App
The following section describes the steps to add the application from iTunes App in the IBM MaaS360 console.
To add Netskope Client:
-
In the IBM MaaS360 console, go to Apps > Catalog.
-
In the App Catalog page, click Add > iOS > iTunes App Store App.
-
The iTunes App Store App window is displayed. In the App field, search for Netskope Client.
-
Click the Netskope Client app to select.
-
Click Add to add Netskope Client to the App Catalog.

Distribute and Assignment
This section describes the steps to distribute and assign Netskope Client app to devices in a group after adding NS Client to the App Catalog. To learn more, view Deploy Apps to Devices.
To distribute and assign NS Client:




