Netskope Enterprise Browser support for Device Posture Checking and Device Classification for Desktop enables administrators to assign customer-defined Device Classification labels to unmanaged (BYOD) and contractor devices—without requiring the Netskope Client to be installed. These labels can then be used to drive zero-trust access and browser controls based on device risk.
This feature includes:
- Customer-defined Device Classification labels for Enterprise Browser: Create classification rules and labels based on posture signals collected by Enterprise Browser (Windows and macOS).
- Use classifications in policy enforcement:
- Real-time Protection (RTP) policies for Enterprise Browser traffic: Apply access controls based on customer-defined Device Classification labels.
- Enterprise Browser Protection Policies: Apply browser controls based on the device’s risk classification.



Key Posture Signals Supported (examples)
- OS Version: Minimum required operating system levels (Windows & macOS).
- Anti-Virus (AV) & Firewall (FW): Verification that local security software is present and active.
- Processes & Files: Detection of specified running processes or the existence of specific files (requires full path).
- Registry & Certificates: Advanced checks for registry keys or specific local certificates.
- AD Domain: Verification of Active Directory domain membership.
Considerations include:
- Managed/Unmanaged device classification is not yet supported as a condition for RTP policies (Access Method = EB) or Enterprise Browser Protection Policies in this scope—only customer-defined Device Classification labels are supported.
- RTP scope limitation: Device Classification is supported in RTP for Web and SaaS destinations only; it is not supported for RTP for Private Segments.
- OPSWAT Compliance is not currently supported for Enterprise Browser and will be evaluated as false if configured in a Device Classification rule for EB.
- Policy usage visibility: The “policies attached to Device Classification” list does not include RTP policies where Access Method = Enterprise Browser, or Enterprise Browser Protection Policies, even if those policies are using the label.

