Objective
In accordance with the FedRAMP Rev. 5 Mandatory Balance Improvement Release (BIR) Secure Configuration Guide, the objective of this document is to effectively communicate the security impact of common Netskope tenant configuration settings to new and current agency customers. The following article addresses all FedRAMP Required elements of the Secure Configuration Guide. This process supplements the Customer Responsibilities Matrix and other existing materials in the Netskope FedRAMP High authorization package ID FR2105946715.
Recommended Security Configuration
- Required: Instructions on how to securely access, configure, operate, and decommission top-level administrative accounts that control enterprise access to the entire cloud service offering.Customers should refer to the following sections of the Netskope Knowledge Portal for best practices to securely access, configure, and operate their Netskope tenant:
- Secure Tenant Configuration and Hardening outlines the security configuration available in tenant UI and how those can be used to harden the security of UI.
References for secure access and decommissioning of accounts include:
- Single Sign On for Administrators
- Multi-Factor Authentication for Netskope Admins
- Change Access for an Admin Account
- Set log In Attempts
- Set Idle Timeout
- IP Allowlisting
- Disallow Concurrent Logins by an Admin
- Set Password Expiration
- RBAC Role Assignment for Netskope personnel
- To Disable Access for Netskope Support
- Required: Explanations of security-related settings that can be operated only by top-level administrative accounts and their security implications.
Top-level administrative accounts are referred to as Netskope Tenant Admins.Delegated Admins are accounts with fewer privileges than Tenant Admins. They are able to View and Manage specific areas of the Netskope Tenant, but are restricted from accessing or modifying configuration settings in Admins and Advanced Settings.Customers should refer to the following sections of the Netskope Knowledge Portal for an explanation of the security-related settings that can be operated by Netskope Tenant Admins, and for a summary of operations by predefined roles and privileges:
Refer to the SSP Appendix D – User Guide, which includes the references and instructions mentioned in this article.

