This page contains the latest FAQs and best practices for Enterprise Browser (EB) version 1.0.
- What are the installation prerequisites?
- Which IdP/SSO providers do you support?
- Can I use the Enterprise Browser with the Netskope Client?
- How can I resolve performance issues or slow loading times?
- What steps should I take if a web site or application doesn’t function as expected?
- Why am I experiencing compatibility issues with certain enterprise tools?
- How does NewEdge POP selection work?
What are the installation prerequisites?
Before initiating installation, there are prerequisites that you must complete. To learn more: Netskope Enterprise Browser Installation and Troubleshooting
Which IdP/SSO providers do you support?
Enterprise Browser relies on SAML Forward Proxy configuration for SAML assertion upon user authentication. Any SAML 2.0 IdP/SSO is supported. The following guides are available which include Netskope specific set up steps.
- Okta Set Up for Enterprise Browser
- PingIdentity Set Up for Enterprise Browser (PingOne)
- Microsoft Entra Set Up for Enterprise Browser
Can I use the Enterprise Browser with the Netskope Client?
The main use case for EB is unmanaged devices, both solutions can work together with the proper configuration. The following procedure allows Netskope to set an exception to EB as a Certificate Pinned Application and bypass the traffic to EB at the Netskope Client level.
Define App Definition Certificate Pinned Apps
1. Navigate to Settings > Security Cloud Platform > Traffic Steering > App Definition > Certificate Pinned Apps tab.

2 Click the New Certificate Pinned App button. Create a single certificate pinned app to cover Windows and MacOS browser and updater processes. Both ‘browser’ and ‘updater’ processes are required.

Enter the following:
- Application Name – Netskope Enterprise Browser
- Platform – Mac
- Platform Mac Definition – Netskope Enterprise Browser, netskopebrowserupdater
- Platform – Windows
- Platform Windows Definition – nsbrowser.exe, updater.exe
Configuration Setting to use Enterprise Browser and Netskope Client
1. Navigate to Settings > Security Cloud Platform > Traffic Steering > Steering Configuration. The Steering Configuration page displays.

2. Select the configuration to updated (e.g. Default tenant config). Click the ellipses to open the Edit Configuration page.

3. From the Bypass exception traffic at dropdown > select Client.

Set Up Enterprise Browser Bypass
1 Navigate to Settings > Security Cloud Platform > Traffic Steering > Steering Configuration > click the ellipses > View Exceptions.

2 The Exceptions tab displays. Click the New Exception dropdown > Certificate Pinned Applications.

3 The New Exception window displays.

Enter the following:
- Certificate Pinned App = field – start typing or scroll to search for the certificate pinned app you created (i.e. Netskope Enterprise Browser) in the Define App Definition Certificate Pinned Apps section above.
- Custom App Domains – type * (wildcard) to bypass all domains.
- Actions – select the Bypass radio button.
- Notes – optional but you can add notes which appear in the list page.
How can I resolve performance issues or slow loading times?
Try the following:
- Check your internet connection, browse the same web sites with an additional browser, verify if you still encounter performance issues or slow loading times.
- Close any unnecessary applications consuming system resources.
- Verify that no enterprise-level restrictions or firewalls are causing delays.
What steps should I take if a web site or application doesn’t function as expected?
- Verify that you have connectivity to other web sites and the Enterprise Browser is properly working for other cases.
- Use an alternative browser to identify if the issue is with the non-functioning web site or application is browser-specific.
Why am I experiencing compatibility issues with certain enterprise tools?
Compatibility issues may arise due to specific configurations. Verify that you have access with your usual access method but not with the Enterprise Browser and review the policy settings to ensure there are no conflicts with the Enterprise Browser permissions.
How does NewEdge POP selection work?
It helps to think about what Netskope has to do in order to locate the optimal DC. Given that endpoints need to establish a TLS connection(s) to a DC in the NewEdge Security Cloud, they have to discover where to connect before initiating any connections.
NewEdge POP Selection for clientless access methods like Enterprise Browser rely on DNS resolution for optimal NewEdge POP selection location, which may differ from the NewEdge POP selection when Netskope Client is enabled and running in the Endpoint.

