Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Netskope Client
    Netskope Client Deployment Options
    Omnissa Workspace ONE
    Deploy Client on macOS Using Omnissa Workspace ONE

    Deploy Client on macOS Using Omnissa Workspace ONE

    This article describes how to deploy Netskope Client on macOS devices using Omnissa Workspace ONE.

    Prerequisites

    • Administrators must possess proficient working knowledge of Omnissa Workspace ONE UEM.
    • Administrators must review Netskope Client Client Enrollment Methods to understand the Client User Enrollment methods available for their environment.
    • Import users into the Netskope tenant – see Provisioning Users for Netskope Client.
    • Download Netskope Root and Tenant Certificates and ensure the certificates are available when needed.
    • See Deploy Netskope Client via IdP when using IDP as the method of user enrollment.

    Supported Platforms and Enrollment Methods

    This article outlines the Netskope Client deployment instructions for the following user enrollment methods and supported platforms. User enrollment methods not documented here are not supported at this time.

    Enrollment MethodSingle UserMulti-User
    IDPYY
    PLISTYN

    Configuration Profile Setup

    Profiles manage the core configuration for Client installation. The following sections provide a detailed overview of how to configure these profiles effectively.

    Note: The following can be added to a New or Existing Profile as it aligns with your environment.

    Pre-Approve Network Extension

    The Netskope Client installs a network extension on macOS that requires administrator approval to function. Configure the following to pre-approve the network extension and suppress end-user notifications requesting approval.

    To configure:

    1. Go to Resources > Profiles & Baselines > Profiles.

    2. Click Add Profile from the Add dropdown options.

    3. Select Apple macOS from the platform list.

    4. Select Device Profile in Select Context and click Next.

    5. Enter a unique Profile name. For example, Netskope Client Configuration Profile.

    6. Start typing System in the search text box of the configuration profile.

    7. Expand System Extensions and click Add.

    8. Configure Allow Systems Extensions as follows:

      • Bundle Identifier: com.netskope.client.Netskope-Client.NetskopeClientMacAppProxy

      • Team Identifier: 24W52P9M7W

    9. Click Next.

      If the Next button is not available, remove empty configuration options from other headers. For example, Removable system extensions, Non Removable System extensions.

    10. Add the assignment details.

    11. Click Save & Publish.

    Approve Full Disk Access Permission

    The Netskope Client on macOS requires Full Disk Access permissions for various foundational functionalities. The following configuration approves these permissions and suppresses end-user notifications requesting approval.

    1. Go to Resources > Profiles & Baselines > Profiles.

    2. Click Add Profile from the Add dropdown options.

    3. Select Apple macOS from the platform list.

    4. Select Device Profile in Select Context and click Next.

    5. Enter a unique Profile name. For example, Netskope Client Configuration Profile.

    6. Start typing Privacy in the search text box of the configuration profile.

    7. Expand Privacy Preferences and click Add.

    8. Configure the following settings to allow access to a service or an app:

      • Bundle Identifier: com.netskope.client.Netskope-Client.NetskopeClientMacAppProxy

      • Team Identifier: Select Bundle ID.

      • Code Requirement:

        anchor apple generic and identifier "com.netskope.client.Netskope-Client.NetskopeClientMacAppProxy" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists */ or certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "24W52P9M7W")
      • Find System Policy All Files under Services section and select Allow.

    9. Click Next.

    10. Add the assignment details.

    11. Click Save & Publish.

    For Endpoint DLP, you can add the following Identifier and Code Requirement:
    – Identifier: com.netskope.epdlp.client
    – Code Requirement: anchor apple generic and identifier "com.netskope.epdlp.client" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists */ or certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "24W52P9M7W")
    To learn more: Enabling Endpoint DLP on the Netskope Client for macOS.

    Pre-Approve VPN Popup for App Proxy

    The Netskope Client installs a network extension on macOS that triggers updates to the device’s Network settings. The following configuration pre-approves these updates and suppresses end-user notifications requesting approval.

    1. Go to Resources > Profiles & Baselines > Profiles.

    2. Click Add Profile from the Add dropdown options.

    3. Select Apple macOS from the platform list.

    4. Select Device Profile in Select Context and click Next.

    5. Enter a unique Profile name. For example, Netskope Client Configuration Profile.

    6. Start typing VPN in the search text box of the configuration profile.

    7. Expand VPN and click Add.

    8. Configure the following settings to allow access to a service or an app:

      • Connection Name: Enter a descriptive name for the Connection Name.

      • Connection Type: Select Custom SSL.

      • Identifier: com.netskope.client.Netskope-Client

      • Server:  Enter your VPN server name from the Netskope UI. For example, gateway-<tenant-URL>.

    9. Click Next.

    10. Add the assignment details.

    11. Click Save & Publish.

      Prevent Disabling of System Extensions in macOS 15 (Sequoia)

      Netskope recommends adding two optional deployment parameters, Prevent Disabling of System Extensions and Restrict App Proxy Removal, to manage user permissions regarding System Extensions in macOS 15 (Sequoia) and above. These controls prevent the user from removing the specified system extension.

      To configure:

      1. Go to Resources > Profiles & Baselines > Profiles.

      2. Click Add Profile from the Add dropdown options.

      3. Select Apple macOS from the platform list.

      4. Select Device Profile in Select Context and click Next.

      5. Enter a unique Profile name. For example, Netskope Client Configuration Profile.

      6. Start typing System in the search text box of the configuration profile.

      7. Expand System Extensions and click Add.

      8. Configure Allow Systems Extensions as follows:

        • Bundle Identifier: com.netskope.client.Netskope-Client.NetskopeClientMacAppProxy

        • Team Identifier: 24W52P9M7W

      9. Configure Non Removable From UI System Extensions as follows:

        • Bundle Identifier: com.netskope.client.Netskope-Client.NetskopeClientMacAppProxy

        • Team Identifier: 24W52P9M7W

      10. Click Next.

      11. Add the assignment details.

    12. Click Save & Publish.

      Restrict App Proxy Removal

      Netskope recommends adding two optional deployment parameters Prevent Disabling of System Extensions and Restrict App Proxy Removal to manage user permissions regarding System Extensions in macOS 15 (Sequoia) and above. These controls prevent the removal of the specified system extension by the user.

      1. Go to Resources > Profiles & Baselines > Profiles.

      2. Click Add Profile from the Add dropdown options.

      3. Select Apple macOS from the platform list.

      4. Select Device Profile in Select Context and click Next.

      5. Enter a unique Profile name. For example, Netskope Client Configuration Profile.

      6. Start typing Restrictions in the search text box of the configuration profile.

      7. Expand Restrictions and click Add.

      8. Toggle Restrict System Preferences to enabled under Preferences

      9. Select DISABLE SELECTED ITEMS

      10. Find Network and select checkbox

      11. Click Next.

    13. Add the assignment details.

    14. Click Save & Publish.

      Push Netskope Root and Tenant Certificates

      Provide additional trust to end users by pushing certificates during client installation. Before you can push the root and tenant certificates, ensure that you do the following:

      1. Download root and tenant certificates from Netskope Certificates page.
        1. Login to Netskope tenant admin console with admin credentials.Go to Settings > Manage > Certificates > SIGNING CA. The certificate download options are displayed in the Certificate Setup section.
      2. Convert the downloaded certificates to .cer format by renaming the .pem files to .cer.

      Perform the following steps to add certificates to Omnissa Workspace ONE:

      1. Go to Resources > Profiles & Baselines > Profiles.

      2. Click Add Profile from the Add dropdown options.

      3. Select Apple macOS from the platform list.

      4. Select Device Profile in Select Context and click Next.

      5. Enter a unique Profile name. For example, Netskope Client Configuration Profile.

      6. Start typing Credentials in the search text box of the configuration profile.

      7. Expand Credentials and click Add.

      8. Enter the following details:

        • Credential Source: Select Upload.

        • Credential Name: It auto-populates the name after uploading the certificate.

        • Certificate: Click Choose File > Browse for the rootcaCert.cer file you downloaded from the Netskope tenant.

      9. Click Attach Certificate.

        Once you click Attach Certificate, the webUI displays the uploaded certificate details such as validity, thumbprint, and so on.

      10. Click +Add to add another certificate.

      11. Click Choose File > Browse for the caCert.cer file you downloaded from the Netskope tenant.

    15. Click Attach Certificate.

      The webUI now displays two Credentials tabs in your Credentials payload.

    16. Click Next.

    17. Add the assignment details.

    18. Click Save & Publish.

    Deploy Email from Workspace ONE User Profile to Device

    For a PLIST user enrollment, you must deploy the Plist file to the endpoint in advance. This file must contain the user’s email attribute that must be sourced from an email variable within the Workspace Sensor.

    Perform the following steps to add the Plist file:

    Use this section only if you are using PLIST mode for user enrollment.
    1. Log into your Workspace One admin console.

    2. Go to Resources > Sensors.

    3. Click Add > macOS.

    4. On the New Sensor window, provide Name and Description in the General section.

    5. Click Next.

    6. In the Details section, select the following:

      • Language: Bash

      • Execution Context: System

      • Response Data Type: String

      • Code:

        #!/bin/bash
        emailPrefFile="/Library/Managed Preferences/com.netskope.plist"
        if [ -f "$emailPrefFile" ];
        then
            echo "exists"
            echo "plist exists" > /tmp/plist.txt
        else
            /usr/libexec/PlistBuddy -c "add email string $userMail" com.netskope.plist
            cp com.netskope.plist /Library/Managed\ Preferences/
        echo "added"
        fi
    7. In the Variables section, create a variable to be used in the script during execution. Add userMail and select {EmailAddress} in the Key and Value fields respectively. You can add other variable names. However, ensure to add the same variable name as provided in the ‘bash’ script.

      Non-domain-PushEmail-Variables-101.png

    8. Click Save.

      Once deployed, the administrator sees the file: com.netskope.plist under directory: /Library/ManagedPreferences/ on the macOS device. This file must contain the user’s email address. If the email address is not in the Plist file, then review the WorkspaceOne console to ensure you assign an email address to the user. To learn more, view Collect Data with Sensors in macOS and seek assistance from Omnissa Workspace One support when required.

    Deploy Netskope Pre-install Script and Client Package

    The administrator can add the Netskope Client script and packages along with the instructions to run the script on the device. To learn more, view Deploy Internal macOS Applications.

    1. Go to Resources > Apps > Native > Internal.

    2. Select Add > Add Application.

    3. In Add Application, click Upload to add the Netskope package file.

    4. Click Save.

    5. Click Continue.

    6. Select Full Storage Management in Deployment Type

    7. Upload the meta data file (.plist). To create a metadata file, download and install Omnissa Workspace ONE UEM Admin Assistant Tool to your macOS computer. To learn more, view Generate Metadata.

    8. Click Continue.

      This navigates to Add Application.

    9. Under Details, you can review the details and make modifications, if necessary.

    10. Click Scripts.

    11. UnderInstall Scripts,add Pre-Install Script that runs before the installation process. Choose one of the following scripts according to your requirements:

      PLIST
      IDP

      If you are using PLIST mode for enrollment, add the following script in the Pre-Install Script field.

      #!/bin/bash
      ####
      # ws1_netskope_pre-install.sh
      # WorkspaceOne Pre-install script used to prepare macOS devices for the Netskope client. This script has support for secure enrollment.
      # You will need to set the following parameters:
      #
      # TENANT - This should be to addon-YOUR TENANT.goskope.com
      # ORGID - You can obtain your Organization ID from your tenant (Settings > Security Cloud Platform > MDM Distrubtion)
      # EMAIL - This value will be fetched from com.netskope.plist file which will be created by ws1_netskope_sensor.sh script
      # enrollencryptiontoken - encryption token on Secure Enrollment page if enabled &amp; enforced
      # enrollauthtoken - authentication token on Secure Enrollment page if enabled &amp; enforced
      #
      ##
      TENANT=addon-&lt;tenant>
      ORGID=&lt;org_key>
      EMAIL=`defaults read /Library/Managed\ Preferences/com.netskope.plist email`
      enrollauthtoken=&lt;auth_token>
      enrollencryptiontoken=&lt;encryption_token>
      TEMP_BRANDING_DIR="/tmp/nsbranding"
      TEMP_ENROLLMENT_TOKEN_FILE="$TEMP_BRANDING_DIR/enroll.conf"
      if [ ! -d $TEMP_BRANDING_DIR ]; then
       mkdir -p $TEMP_BRANDING_DIR
      fi
      NSINSTPARAM_JSON_FILE="${TEMP_BRANDING_DIR}/nsinstparams.json"
      echo "{\"TenantHostName\": \"$TENANT\", \"Email\": \"$EMAIL\", \"OrgKey\": \"$ORGID\"}" > "${NSINSTPARAM_JSON_FILE}"
      Create_Json() {
          if [[ -f "$TEMP_ENROLLMENT_TOKEN_FILE" ]]; then
              rm "$TEMP_ENROLLMENT_TOKEN_FILE"
          fi  
          local a=$1
          local b=$2
          if ! [[ "$a" =~ ^[a-fA-F0-9]{32}$ ]] &amp;&amp; [[ "$a" != "0" ]]; then
              echo "Invalid auth token: must be 32 hexadecimal characters"
              return 1
          fi  
          if ! [[ "$b" =~ ^[a-fA-F0-9]{32}$ ]] &amp;&amp; [[ "$b" != "0" ]]; then
              echo "Invalid encryption token: must be 32 hexadecimal characters"
              return 1
          fi  
          echo "{" > $TEMP_ENROLLMENT_TOKEN_FILE
          if [[ "$a" != "0" &amp;&amp; "$b" != "0" ]]; then
              echo "\"enrollauthtoken\": \"$a\"," >> $TEMP_ENROLLMENT_TOKEN_FILE
              echo "\"enrollencryptiontoken\": \"$b\"" >> $TEMP_ENROLLMENT_TOKEN_FILE
          elif [[ "$a" == "0" &amp;&amp; "$b" != "0" ]]; then
              echo "\"enrollencryptiontoken\": \"$b\"" >> $TEMP_ENROLLMENT_TOKEN_FILE
          elif [[ "$b" == "0" &amp;&amp; "$a" != "0" ]]; then
                echo "\"enrollauthtoken\": \"$a\"" >> $TEMP_ENROLLMENT_TOKEN_FILE
          else
               echo "Unsupported use case"
          fi  
          echo "}" >> $TEMP_ENROLLMENT_TOKEN_FILE
          chmod 700 "$TEMP_ENROLLMENT_TOKEN_FILE"
          echo "enroll.conf created with provided tokens."
      }
      if [[ "$enrollencryptiontoken" != "0" || "$enrollauthtoken" != "0" ]]; then
          echo "Using secure enrollment"
          Create_Json "$enrollauthtoken" "$enrollencryptiontoken"
      else
          echo "Not using secure enrollment"
          if [[ -f "$TEMP_ENROLLMENT_TOKEN_FILE" ]]; then
              rm "$TEMP_ENROLLMENT_TOKEN_FILE"
          fi
      fi
      – Replace  lines 19, 20, 24, and 25 with values from your tenant. Refer to Client Deployment Parameters to learn more about where to find these values in the Netskope Admin Console.
      – Ensure not to add any space while adding values.
      – If no secure enrollment token is enabled, add 0 as the token value. For example, if encryption token is not enabled in your tenant, then add enrollencryptiontoken=0

      If you are using IDP enrollment method for single-user mode, add the following script in the Pre-Install Script field:

      #!/bin/bash
      set -euo pipefail
      
      # Workspace ONE Pre-install script for IDP mode to prepare macOS devices for the Netskope client.
      # Supports Secure Enrollment. Requires DOMAIN, TENANT_NAME, and optionally enroll tokens.
      # ===== USER CONFIGURATION =====
      DOMAIN="&lt;tenant domain>"        # e.g., eu.goskope.com
      TENANT_NAME="&lt;tenant_name>"     # e.g., nsclient
      REQ_EMAIL=true                  # true or false
      perusermode=0		            # 1 for enabling per-user mode
      enrollauthtoken=0		     # Always 0 in IDP mode
      enrollencryptiontoken=0        # 32-character hex or 0 if secure enrollment not enabled
      # ==============================
      
      # Validate required inputs
      if[["$DOMAIN"=="&lt;tenant_domain>"||"$TENANT_NAME"="&lt;tenant_name>"];then
      echo "[ERROR] Please configure DOMAIN and TENANT_NAME before running this script."
      exit 1
      fi
      
      # Paths
      TEMP_BRANDING_DIR="/tmp/nsbranding"
      TEMP_ENROLLMENT_TOKEN_FILE="$TEMP_BRANDING_DIR/enroll.conf"
      IDPCONFIG_JSON_DIR="/Library/ApplicationSupport/Netskope/STAgent"
      IDPCONFIG_JSON_FILE="$IDPCONFIG_JSON_DIR/nsidpconfig.json"
      NSUSERCONFIG_JSON_FILE="$IDPCONFIG_JSON_DIR/nsuserconfig.json"
      
      # Create required directories
      mkdir -p "$TEMP_BRANDING_DIR"
      mkdir -p "$IDPCONFIG_JSON_DIR"
      
      echo "[INFO] Writing IDP config to $IDPCONFIG_JSON_FILE"
      cat &lt;&lt;EOF> "$IDPCONFIG_JSON_FILE"
      {
       "serviceProvider": {
         "domain": "$DOMAIN",
         "tenant": "$TENANT_NAME"
       },
       "requestEmail": "$REQ_EMAIL"
      }
      EOF
      # Handle per-user mode if enabled
      if[["$perusermode"-eq1]];then
      echo " [INFO] Per-user mode enabled, writing $NSUSERCONFIG_JSON_FILE"
      cat &lt;&lt;EOF>"$NSUSERCONFIG_JSON_FILE"
      {
       "nsUserConfig": {
         "enablePerUserConfig": "true",
         "configLocation": "~/Library/Application Support/Netskope/STAgent",
         "token": "",
         "host": "",
         "autoupdate": "true"
       }
      }
      EOF
      fi
      
      # Function: Create enrollment token file
      Create_Json(){
      local auth_token="$1"
      localencryption_token="$2"  
      # Remove old file
      rm -f "$TEMP_ENROLLMENT_TOKEN_FILE"
      # Validate tokens
      if![["$auth_token"==~ ^[a-fA-F0-9]{32}$]]&amp;&amp;[["$auth_token"!="0"]
      ];then
      echo"[ERROR] Invalid auth token: must be 32 hexadecimal characters or 0"
      return 1
      fi
      if![["$encryption_token"=~ ^[a-fA-F0-9]{32}$]]&amp;&amp;[["$encryption_token"!="0"]];then
      echo "[ERROR] Invalid encryption token: must be 32 hexadecimal characters or 0"
      return 1
      fi
      
      echo
      "[INFO] Creating secure enrollment config at
      $TEMP_ENROLLMENT_TOKEN_FILE"
      {
      echo"{"
      [["$auth_token"!="0"]]&amp;&amp;echo" \"enrollauthtoken\":\"$auth_token\","
      [["$encryption_token"!="0"]]&amp;&amp;echo" \"enrollencryptiontoken\":\"$encryption_token\""
      echo"}"
      } > "$TEMP_ENROLLMENT_TOKEN_FILE"
      
      chmod 700 "$TEMP_ENROLLMENT_TOKEN_FILE"
      echo "[INFO] enroll.conf created successfully"
      }
      
      # Secure Enrollment Block
      if [["$enrollencryptiontoken"!="0"||"$enrollauthtoken"!="0"]];then
      echo "[INFO] Using secure enrollment"
      Create_Json "$enrollauthtoken" "$enrollencryptiontoken"
      else
      echo "[INFO] Not using secure enrollment"
      rm -f "$TEMP_ENROLLMENT_TOKEN_FILE"
      fi
      – Replace  line 7, 8, 9, 10, 11, and 12 with values from your tenant. Refer to Client Deployment Parameters to learn more about where to find these values in the Netskope Admin Console.
      – If the value given for REQ_EMAIL in “requestEmail”: “$REQ_EMAIL” is true, the SAML IDP URL where you need to enter the email address and navigate you to the OKTA login page. If the REQ_EMAIL value is false, then it directly navigates you to the OKTA login page.
    12. Click Save & Assign.

    13. Once you add an application to the console, start assigning devices to the application.

    14. Click the application that you added.

    15. Click the Assignment tab.

    16. Click Assign available on the right corner of the screen.

    17. Under Assignments, click Add Assignment.

    18. On the Assignment screen, perform the following:

      • Provide a Name for the assignment.

      • In Assignment Groups, select the desired group

    19. Click Create.

    20. Click Save.

    Verifying Client Installation

    Check the installation logs on the user’s machine in the /var/log/install.log folder. If the user configuration download script fails and the Netskope client installer is executed, the installer will exit and display the Configuration file missing, aborting installation! error message.

    Check Netskope Client Installation Status

    1. To verify the status of each device, go to Computer > Policies and click on the policy you created.

    2. Click the Logs button at the bottom to view the log files for each device and then click the Show button.

      Confirming the Netskope Client Extension Approval

      To confirm that the Netskope Client extension has been approved and the client is running, run the following command in your macOS terminal window:

      systemextensionsctl list

      The output should look like this:

      % systemextensionsctl list  
      1 extension(s)
      --- com.apple.system_extension.network_extension
      enabled active teamID bundleID (version) name [state]
      * * 24W52P9M7W com.netskope.client.Netskope-Client.NetskopeClientMacAppProxy (85.2.0.269/1) 
      NetskopeClientMacAppProxy [activated enabled]

      Additionally, inspect the system preferences and Network UI to confirm that Netskope Client extension is active.

    Uninstalling the Netskope Client

    See Uninstalling the Netskope Client for instructions on uninstalling the Netskope Client.

    In this Topic
    • Deploy Client on macOS Using Omnissa Workspace ONE