Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Netskope Client
    Netskope Client Deployment Options
    Netskope Client Enrollment
    Enrollment Token Management

    Enrollment Token Management

    This document provides guidance on the token management for the secure enrollment service. The secure enrollment service have two tokens which are listed as below: 

    • Authentication token: This token is used to create an authentication parameter for the users when Netskope Client is deployed to use User Principal Name (UPN) or NPA Prelogon as user identifiers on the systems. This token is mandatorily required to be configured and pushed on the end machine when Netskope Client is using UPN and/or NPA Prelogon.

    • Encryption token: This token is used to encrypt the enrollment configuration files on top of TLS on the communication channel. If enabled and enforced, this token is required to be present on the end user machines in both UPN and idP mode of enrollment. 

      This token is optional and can be enabled based on your requirements.

    To create the authentication and encryption tokens, navigate to Settings > Security Cloud Platform > Netskope Client > MDM Distribution > Secure Enrollment.

    With version 129.0.0, Netskope separated the following:

    • Secure enrollment Service enablement.

    • Creation and enforcement of secure enrollment token(s). 

    Secure Enrollment is available since version 116.1.0.

    This allows you to:

    • Enable secure enrollment using the Secure enrollment service toggle option. 

    • Generate and enforce the secure enrollment token(s) using the “Create Tokenset” option.

     It is mandatory to push authentication token for UPN  and encryption token (if generated) for UPN and IDP on the end machine before enabling secure enrollment service to avoid enrollment issues.

    With the two-token support, administrators can:

    • Create two sets of authentication and encryption tokens using Create Token Set. It is optional to create the Encryption token.

    • Delete a token set after selecting the unenforcing the token set. You cannot delete a token set if the tokens are already enforced for Client deployment.

    • Extend the token expiration date according to the options set on the webUI. The webUI displays N/A in the Expiration Date column if the tokens are not enforced. For more details, refer Enforce Tokens.

    Create New Token Set

    Click Create TokenSet to create a new token set on the webUI. Once you add another token set, the webUI displays only the authentication token. Adding Encryption tokens are optional and you can leverage the +Add Token option to create the encryption tokens. 

    You can use these tokens in the commands or scripts used during Netskope Client deployment. Refer to the following webUI options that can help you in operationalizing token(s):

    • Copy token: Use this option to copy the authentication or encryption tokens with a simple mouse click.

    • Show/Hide token:  Tokens are generated in a hidden state by default. Use the Show/Hide option to view them.

    • Delete token: Delete a token when it is not in an enforced state.

    Add Encryption Token

    Since adding an encryption token is an optional task, administrators must create them manually. Click + Add Token  displayed in the Encryption Token column.

    Always  Add encryption token before enforcing the tokens.

    Enable Secure Enrollment Service

    Secure enrollment is a mechanism to enforce the strict authentication of Netskope Client Enrollment. Use this option to ensure Netskope Client enrollments are authenticated and secure.

     Netskope advise enabling this feature to avoid any enrollment issues. This feature resolves the security vulnerability issue that Netskope has already communicated in Netskope Security Advisory: NSKPSA-2024-001.

    Enforce Token

    Use this option to enforce Netskope Client installation using secure enrollment token(s). To enable token enforcement, click the ellipsis(…) and select Enforce.

    – Ensure to enable the Secure Enrollment Service option before enforcing tokens.
    – Ensure to Enforce your token(s) to take effect. Enforce each token set independently.

    Use Do Not Enforce Option to disable the Enforce feature.

    Token Expiry

    After you click Enforce, you can set the token expiration details in Add Expiration For Token(s). Select an Expiration Date from the following options displayed in the dropdown:

    • 7 days from today

    • 30 days from today

    • 60 days from today

    • 90 days from today (Default option)

    • 180 days from today

    • 365 days from today

    Click Save to apply the expiration date. The saved date is then displayed in the Expiration Date column. Meanwhile, use the edit (pencil icon) to change or modify the expiration date.

    Email Notification

    The Secure Enrollment tokens expiration email notification feature ensures that administrators receive timely alerts before their secure enrollment tokens expire. The Netskope Client enrollment can fail if administrators allow a token expiration time to lapse without extending it. Using these automated reminders, the service helps maintain seamless Client deployment and prevents administrative oversights that could lead to service disruptions.

    To enable this option, navigate to Settings > Security Cloud Platform > Netskope Client > MDM Distribution. Locate the setting to notify when a token will expire soon under Secure Enrollment.

    In Notify administrators when tokens expire, add email addresses of the administrators who must receive these alerts. You can add a maximum of 25 email addresses. No email notifications are sent after a token has already expired.

    Verify that Secure Enrollment is enforced. Email notifications trigger only if you have enforced Secure Enrollment. This prevents any unintended email flows.

    Once configured, the service automatically sends email notifications at the following intervals before a token expires:

    • 30 days

    • 15 days

    • 7 days

    • 1 day

    Delete Token Set

    Administrators can delete the token set only if the tokens are not enforced. If the tokens are enforced, disable it first and then delete the tokens. The Delete option is grayed-out when the tokens are enforced.

    Secure Configuration Service

    Netskope Client Secure Configuration is a security enhancement that ensures the integrity of the Client configurations downloaded using APIs by Netskope Client against any tampering attacks and scenarios like MITM.

    • Prerequisite: Enable Secure Enrollment Service before enabling Secure Configuration Service.

    • Supported Netskope Client version: 123.0.0 or later

    Enable Secure Configuration Service

    To enable this option, toggle Secure Configuration Service to keep the status as Enabled.

    Disabling Secure Enrollment service can automatically disable Secure Configuration Service.
    For versions prior to 123.0.0, Netskope Client might fail to download Client Configuration and also fail to report Client status events in the Devices page after you enable Secure Enrollment Services and Secure Configuration Service.
    In this Topic
    • Enrollment Token Management