Overview
This article explains how to integrate Netskope DSPM (also known as Netskope One DSPM) with supported Software-as-a-Service (SaaS) applications using Cloud Access Security Broker (CASB). This integration enables DSPM to connect to your SaaS apps, scan for sensitive data, and analyze data exposure and access risk .
If you want to learn more about analyzing the risk posture after enablement, see Analyze SaaS Data Exposure and Access.
Prerequisites:
Before enabling the integration, ensure you meet the following requirements:
- Subscription: You must have a Netskope DSPM for SaaS Professional subscription or a DSPM upgrade for Managed SaaS.
- Supported Applications: This integration currently supports Salesforce (SFDC), Box, Microsoft 365 OneDrive, SharePoint, and Google Drive.
- CASB Onboarding: The SaaS applications must already be onboarded as Next Generation API Data Protection instances within your Netskope CASB.
- Administrator Rights: You must use RBAC v3 to manage administrator rights for your Netskope tenant.
- Limitations
Be aware of the following system behaviors and scanning restrictions:- File Size Limits: DSPM for SaaS applications relies on Netskope DLP scanning and inherits its file size limits.
- Default Limit: Files larger than 32 MB are not scanned for sensitive content and therefore do not appear in DSPM SaaS inventory or classification views.
- Advanced Scanning: Customers who have Advanced File Scanning (large file support) enabled can scan files up to 128 MB.
- Skipped Files: Any file that exceeds the configured DLP file size limit is skipped by the scan, even if it exists in the SaaS application.
- Initial Scan Limits: The initial smart scan for data stores is limited to a maximum of 400 files per data store.
- Visibility: Data visibility and access analysis may be restricted depending on the specific SaaS application’s configuration and the API permissions granted during the CASB onboarding.
- Pending Features: Some advanced features, such as the analysis of “ghost sites” (sites with no active users) and the detection of suspended users with access to sensitive data, are planned for future releases.
- File Size Limits: DSPM for SaaS applications relies on Netskope DLP scanning and inherits its file size limits.
Enable DSPM Integration for Cloud Apps
You can enable DSPM for supported applications like Google Drive, Salesforce, Box, OneDrive, and SharePoint. This lets DSPM scan and classify data stored in these platforms.
To enable DSPM, follow these instructions in the Netskope One console:
-
Go to Settings > Configure App Access > Next Gen.
-
Click on an onboarded app instance (e.g., sharepoint.com).
-
Turn on the DSPM toggle.
-
Click the “Edit DLP profiles” link to view and customize the DLP profiles for this app instance.
-
Review the predefined DLP profiles.
- You can select or deselect profiles to meet your compliance needs (e.g., deselect GDPR if it is not required for a specific instance). This selection is app-instance specific.

-
Click Save
Enabling DSPM triggers an initial scan of your data. You can expect initial scan results to begin populating in the DSPM UI within a few hours. After this, DSPM rescans your data on an ongoing basis to maintain an up-to-date security posture.
Disable DSPM Integration for Cloud Apps
To disable DSPM for a SaaS application, follow these instructions:
- In the Netskope One console, go to Settings > Configure App Access > Next Gen.
- Click on the onboarded app instance.
- Turn the DSPM toggle off.
- Click Disable.
This action will stop future scanning and data integration for that application within DSPM.

