Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Data Loss Prevention
    Endpoint Data Loss Prevention

    Endpoint Data Loss Prevention

    Note

    Contact your Sales Representative to enable this feature for your account.

    Netskope Endpoint Data Loss Prevention (Endpoint DLP) provides data protection at the endpoint by utilizing Netskope’s cloud DLP capabilities. You can use Endpoint DLP to monitor and govern USB storage devices and printers connected to your endpoint. Endpoint DLP is an optional add-on capability to the Netskope Client and does not require deploying and managing a separate client or agent on the endpoint.

    With Endpoint DLP, you can create Device Control and Content Control policies. Device Control policies enable granular control over which devices are allowed and which users can access them. Whereas, Content Control policies enable the full use of the Netskope DLP engine to inspect and control data movement between an endpoint and a USB mass storage device or printer.

    Endpoint DLP allows you to manage and govern endpoints to prevent sensitive content from being transferred to USB storage devices, printers, Bluetooth, or network file share. You can:

    • Govern endpoint devices by creating device control, content control, and file origin policies.
    • Monitor endpoint activities and block or trigger alerts when users insert or remove USB storage devices, transfer sensitive files to USB storage devices, set up and configure printers, and print documents.
    • Respond to incidents and alert the user of their actions.
    • Coach the user through custom notification messages by allowing them to justify their actions or cancel them.

    See: Endpoint DLP Device and Content Control Policies

    Benefits

    Endpoint DLP provides the following benefits:

    • Minimizes resource utilization at the endpoint for a better user experience.
    • Inspects content for DLP violations for a stronger security posture.
    • Leverages the DLP policy framework to generate alerts and incidents.

    Requirements

    Endpoint DLP runs on Windows or macOS.

    If on Windows, Endpoint DLP requires Windows 10 or Windows 11 on 64-bit processors. Windows 11 Enterprise Multi-Session is not supported.

    Adobe Acrobat and Adobe Acrobat Reader on Windows are supported for versions supported by Adobe.

    If on macOS, Endpoint DLP requires macOS 14, 15, or 26 (Sonoma, Sequoia, Tahoe) running either on Intel x64 or Apple Silicon AND Full Disk Access.

    Ensure you do the following before configuring Endpoint DLP:

    • Provision users for the Netskope Client.
    • Enable Endpoint DLP for the Netskope Client configurations.

    Enabling Endpoint DLP on the Client for macOS

    Endpoint DLP on macOS requires Full Disk Access to function properly. Follow the following instructions to provide the process with Full Disk Access. If the client machine is not managed through an MDM profile, then the user must manually provide the Full Disk Access to the EPDLP client.

    For information regarding Full Disk Access, see Apple’s documentation regarding Controlling app access to files in macOS.

    MDM Deployments on macOS

    The Full Disk Access workflow is covered for the following MDM solutions:

    • JAMF
    • Workspace ONE (Formerly Airwatch)
    • Microsoft Intune
    • Kandji

    Common steps are:

    1. Install DLP on any test machine once.

    2. Open Terminal and run the following command:

    codesign -dr - /Library/Application\ Support/Netskope/EPDLP/Netskope\ Endpoint\ DLP.app

    3. This will generate the following output:

    Executable=/Library/Application Support/Netskope/EPDLP/Netskope Endpoint DLP.app/Contents/MacOS/Netskope Endpoint DLP
    designated => anchor apple generic and identifier "com.netskope.epdlp.client" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists */ or certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "24W52P9M7W")

    4. Copy the substring after the “designated =>” portion. For example,

    anchor apple generic and identifier "com.netskope.epdlp.client" and (certificate leaf[field.1.2.840.113635.100.6.1.9] /* exists */ or certificate 1[field.1.2.840.113635.100.6.2.6] /* exists */ and certificate leaf[field.1.2.840.113635.100.6.1.13] /* exists */ and certificate leaf[subject.OU] = "24W52P9M7W")

    JAMF

    See JAMF for more information.

    5. Open the JAMF Dashboard and navigate to Computer > Configuration and open the configuration that was created for NSclient.

    6. Search for Privacy Preference Policy Control.

    7. Use “com.netskope.epdlp.client” for Identifier, “Bundle ID” for Identifier Type and your copied substring in step 4 for Code Requirement.

    8. Select “SystemPolicyAllFiles” under APP OR SERVICE and “Allow” under Access.

    JAMFMDM.png

    9. Save the configuration profile

    Workspace ONE (Formerly Airwatch)

    See Deploy Client on macOS Using Workspace ONE for more information.

    5. Navigate to Resources > Profiles and Baselines > Profiles.

    6. Under Privacy Preferences, use “com.netskope.epdlp.client” for Identifier, “Bundle ID” for Identifier Type and your copied substring in step 4 for Code Requirement. Set System Policy All Files to “Allow”.

    WorkspaceONEFullDiskAccess1.png
    WorkspaceONEFullDiskAccess2.png

    Microsoft Intune

    See Deploy Client on macOS Using Intune for more information

    5. Navigate to Dashboard > Devices | macOS > Configuration Profiles.

    6. Create an Identifier with “com.netskope.epdlp.client”.

    7. Set Allowed to “True. Use “your copied substring in step 4 for Code Requirement and bundle ID” for Identifier Type . Set System Policy All Files to “Allow”.

    MDMIntune.png

    Kandji

    5. Navigate to Privacy Policy.

    6. use “com.netskope.epdlp.client” for Identifier, “Bundle ID” for Identifier Type and your copied substring in step 4 for Code Requirement. Set System Policy All Files to “Allow”.

    KandjiFDAMDM.png

    Full Disk Access Error

    If Full Disk Access is not enabled for the EPDLP client, the following error message may pop up after installing the EPDLP package through STAgent.pkg

    The Proceed button opens the Full Disk Access Settings in System Preferences to add and enable the EPDLP client.

    Enable the Full Disk Access to EPDLP client by adding and enabling “Netskope Endpoint DLP” in Full Disk Access settings.

    System Preferences -> Security & Privacy -> Privacy -> Full Disk Access

    Enabling Endpoint DLP

    Endpoint DLP is an add-on feature for the Netskope Client. To enable Endpoint DLP for the Netskope Client, contact your sales representative.

    Once enabled, ensure you do the following before configuring Endpoint DLP:

    • Provision users for the Netskope Client.
    • Enable Endpoint DLP for the Netskope Client configurations.

    Original File Access

    Similar to DLP incidents, when an EPDLP Incident is created, the original file that caused the incident will be available for download in WebUI.
    Note that this applies to only to DLP content scan incidents, and the “Forensics enabled” configuration must be enabled.

    .

    See the following links for more information on Original File Access: Enable a Forensic Profile and Downloading DLP files

    In this Topic
    • Endpoint Data Loss Prevention