Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Netskope Client
    Netskope Client Deployment Options
    ManageEngine Endpoint Central
    Deploy Netskope Client with Endpoint Central on MacOS

    Deploy Netskope Client with Endpoint Central on MacOS

    This document describes the instructions for the silent deployment of  Netskope Client using Endpoint Central on MacOS devices.

    Prerequisites

    • Install Endpoint Central agent installed in MacOS devices.

    • Download the desired version of the Netskope Client installer for MacOS (Golden Release is recommended). Refer Support to download the file.

    • Download the Root and Intermediate certificates from your tenant. To download the Root and Intermediate certificates, go to Settings > Manage > Certificates > Signing CA.

    • Download the script NetskopeEndpointCentral.mobileconfig from the Support portal and make the following changes in the script:

      • #LINES 12 – 33: Replace with contents of rootCaCert file. Do not copy BEGIN or END lines

      • #LINES 53 – 78: Replace with contents of caCert file. Do not copy BEGIN or END lines

      • #LINE 83: Replace with <tenantname>.goskope.com. For example, ca.netskopecorp.goskope.com.

      • #LINE 133: Replace with gateway-<tenantname>.goskope.com. For example, gateway-netskopecorp.goskope.com.

    • Download the preinstall script ns-preinstall-endpointcentral.sh from the Support portal and make the following changes in the script:

      • #LINE 14: Replace with the correct addon-<tenantname>.goskope.com domain.

      • #LINE 15: Replace with the correct ORGID from your tenant.

      To get the ORGID and tenant name, view Client Deployment Parameters.
    • The MacOS system with active network connectivity.

      • Connection to distribution server (On-premises or Endpoint Central Cloud (depending on configuration).

      • Internet required for Direct Connection to Endpoint Central Cloud.

    Supported Environments

    Supported OS: MacOS Ventura or later

    – Netskope does not recommend UPN-based for any MacOS platform. This mode requires active connectivity to the Active Directory environment during install. Without it, the installation will complete in a corrupted state and will not activate – even if the system can reach Active Directory after the install.
    – Silent installation is recommended for Multi-user MacOS systems with IDP based enrollment.

    Deployment Procedure

    Refer to the following sections to deploy Netskope Client using Endpoint Central.

    Create Application Package

    To create an application package:

    1. Login to Endpoint Central Cloud Instance at https://endpointcentral.manageengine.com

    2. Navigate to Software Deployment > Packages.

    3. Click Add Package and select Mac from the dropdown menu.

    4. Enter the following details:

      • Package Name: For example, Netskope Client for MacOS

      • License Type: Select Commercial

      • In the Installation tab, browse and upload the package file downloaded from the Support portal in Upload Files.

    5. Click Add Package.

    Create Configuration Profile For Silent Install

    To create the configuration profile:

    1. Navigate to Mobile Device Management from the top menu.

    2. Click on Management > Profiles.

    3. Click +Create Profile >  macOS.

    4. This navigates to Create macOS Profile.

    5. Enter the Profile name. For example, Netskope MacOS Pre-Reqs.

    6. Click Continue. 

    7. This navigates to Configure Profile.

    8. On the left-hand panel, scroll down and click Custom Configuration.

    9. In the Custom Configuration profile , click Browse and upload the NetskopeEndpointCentral.mobileconfig file that you downloaded and edited previously.

    10. Click Save.

    11. Click Publish.

    12. On the left-hand panel, click Groups & Devices.

    13. Click the name of the device group you wish to target.

    14. Click Action on the far right and choose Associate Profile from the dropdown options.

    15. Choose your Prerequisite Profile and click Associate.

    16. Confirm the presence of the configuration profile on your MacOS device.

    Configure the Preinstall Script

    To configure the preinstall script:

    1. Navigate to Configurations from the top menu.

    2. Click All Configurations.

    3. Click +Create Configuration.

    4. Select Mac from the dropdown options.

    5. Hover over Custom Script and select the Computer Configuration option.

    6. Enter the Name for the script. For example, Netskope Pre-Install for MacOS.

    7. In Execute Script from / Run, choose Repository.

    8. In Script Name , click the Create / Modify Script link. This launches a new window.

      1. Click +Add Script.

      2. In Script Name, browse and upload the preinstall script.

      3. In Platform, select Mac.

      4. Click Add.

    9. Confirm the script is now listed in the repository then close the new tab to return to the previous screen.

    10. Click in the Script Name box and you can select the newly uploaded script.

    11. In Frequency, you can optionally enable logging for troubleshooting.

    12. In Define Target, define the target workstations where you want to deploy the configuration. To define a target, view Defining Targets.

    13. Click Deploy.

    In this Topic
    • Deploy Netskope Client with Endpoint Central on MacOS