Here are the latest features, issues fixed, and other updates published between the golden releases 129.0.0 and 132.0.0. This is a consolidated list of items published in the release notes for versions between 129.0.0 and 132.0.0.
Use Release Notes widget for release notes related to a specific version.
Here is the list of the new features and enhancements between versions 129.0.0 and 132.0.0.
129.0.0
Controlled General Availability of Device Classification Feature Improvements
This was earlier available as a Beta feature in version 127.0.0. With version 129.0.0, we are moving this feature as a Controlled Availability feature.
To learn more, view Device Classification.
Supported minimum Client version: 127.0.0
Support for Android 16
Netskope Client now supports Android 16 (Baklava).
To learn more: view Netskope Client OS and Platforms.
Secure Enrollment Services Toggle Option
With version 129.0.0, Secure Enrollment webUI under Settings > Security Cloud Platform > MDM Distribution now displays a separate toggle option for administrators to enable Secure Enrollment Services.
To learn more: Enrollment Token Management.
General Availability of Secure Enrollment Risk Acknowledgement Notification
The Secure Enrollment Enablement Notification message was displayed within the tenant webUI. This UI message was available as a Beta feature. With version 129.0.0, the message is displayed on the tenant UI for all tenants.

General Availability of Secure Configuration Services
Netskope Client Secure configuration is a new security enhancement that signs the Client Configuration by the user certificate to prevent any MITM compromises. This requires Secure Enrollment to be enabled globally as a prerequisite.
Secure Configuration Service Toggle Option
Administrators can now enable or disable the Secure Configuration Services option. It is mandatory to enable Secure Enrollment Services to enable the Secure Configuration Services option.

To learn more: Enrollment Token Management.
Supported minimum Client version: 123.0.0
Device Classification Certificate Check – User Private Key Verification Improvement
This was earlier as a Beta feature in version 127.0.0. With version 129.0.0, Non-Exportable Private Key under Certificates in the Device Classification webUI is available for all tenants.
Supported OS: Windows and macOS.
Supported minimum Client version:127.0.0
To learn more, view Device Classification.
New nsdiag Option for Master Password
Introduced a new nsdiag option --password to be used along with nsdiag -t disable command. This allows the user to specify master password as an argument to nsdiag for disabling Netskope Client.
For example : nsdiag -t disable --password <master password in plain-text>
To learn more: Using Netskope Client.
General Availability of WSLv2 Support
This was earlier available as a Beta feature in version 113.0.0 and it is now available as a GA feature.
systemd enable flag to warn users during the client install. If systemd is disabled, need to turn on the flag and reboot the distro.Supported minimum Client version: 113.0.0
To learn more: Netskope Client for Windows.
130.0.0
Embedded Mini-browser Support for Captive Portal Authentication
The Netskope Client UI now performs Captive Portal authentication using WebView2 embedded mini-browser when user is in a Captive Portal environment. This resolves two issues that caused captive portal authentication to fail on Windows machines:
-
Windows native captive portal detection can occur before Netskope Client detects captive portal. This blocks the captive portal detection URL if you do not configure a value in Captive Portal Detection Timeout (Minutes).
-
Some captive portal redirect URL(s) is blocked if you do not set the Captive Portal Detection Timeout.
Supported OS: Windows
Supported minimum Client version: 130.0.0
To learn more, view Captive Portal Detection Timeout.
Block Private IP address in Fail Close
Introduced a new feature to allow administrators to block RFC-1918 IP addresses/subnets when Netskope Client is in Fail-Close state. By default, RFC-1918 IP addresses/subnets are bypassed by Netskope Client in Fail-Close mode.
In order to block the RFC-1918 IP addresses/subnets, remove the steering exception for Local IP address range in Destination Location.
Supported minimum Client version: 130.0.0
On-Premises Detection using Egress IP address
Introduced a new option Egress IP for On-Premises detection. This can be configured under Tunnel Settings > On-premises Detection in the Client Configuration UI that enable administrators to detect location of users (On or Off-premises) using trusted egress public IP locations and subsequently control traffic steering.

To learn more: Netskope Client Configuration.
One-Time Password-Based Client Disable For MacOS
Netskope introduced One-Time Password Disable Option for Netskope Client Windows in version 118.0.0. With this version, Netskope now supports One-Time Password for MacOS.
Admins have to configure this first on the tenant UI under the option Allow disabling of Internet Security in Settings > Security Cloud Platform > Client Configuration > Tamperproof.
Supported OS: MacOS, Windows (Already supported)
Supported minimum Client version: 130.0.0
To learn more: Client Configuration.
Support for Debian 12
Netskope Client for Linux now extends its support for Debian 12 (Bookworm).
To learn more: Netskope Supported OS and Platform.
Supported minimum Client version: 130.0.0
English Language Support For Netskope Client UI
With version 130.0.0, the Netskope Client UI for Windows is displayed in a language selected in Windows display language under Settings> Time & Language > Language. If the administrator wants to display Netskope Client UI in English, select the option: English in Windows display language.

To learn more: Multi-Lingual Support for Windows.
Supported minimum Client version: 130.0.0
General Availability of Device Classification Feature Improvements
This was earlier available as a Controlled General Availability feature in version 129.0.0. With version 130.0.0, this feature is available for all tenants.
To learn more, view Device Classification.
Supported minimum Client version: 129.0.0
Battery Utilization Improvement: Netskope Client for iOS
Introduced a VPN profile option TerminateOnSleepThreshold with integer value in seconds.
When an iOS device wakes up from the sleep mode, the Netskope Client checks the sleep time and if it is above the specified value in seconds, it gets terminated immediately. This is controlled by iOS on-demand rules logic based on network activity and as a result our extension is not running at all during device inactivity periods. This saves significant amount of battery charge.
Supported OS: iOS
Supported minimum Client version: 130.0.0
To learn more, view Microsoft Intune.
Android App Persistence
Introduced Android App Persistence feature that automatically restarts Netskope Client within 15 minutes after periodically checking the status of the Client app. With this feature, if Netskope Client app is killed by battery optimization or the application crash, Netskope Client will automatically restart within 15 minutes.
Supported OS: Android
Supported minimum Client version: 130.0.
131.0.0
Netskope Client Support for New OS Versions
Netskope now supports the following OS versions:
- macOS Tahoe (version 26)
- iOS version 26
To learn more: Netskope Client Supported OS and Platforms.
Terminate Netskope Client Debug Mode
Previously, Netskope Client continued to collect information until the administrator executes the command nsdiag -b stop to terminate Debug Mode.
With this release, Netskope Client can stop the debug mode automatically and collect the required information after the specified duration set using the -t [duration of time in minutes] parameter when initiating debug mode.
To learn more, view Debug Mode.
Supported minimum Client version: 131.0.0
On-Prem Detection WebUI Modification
Netskope is relocating the On-Prem Detection setting from Netskope Client > Client Configuration to Traffic Steering > Steering Configuration in this release. This change aims to:
-
Enhance the ease of use for this option.
-
Mitigate configuration management complexities arising from mismatches between the Client and Steering configurations due to misaligned Organization Units or User Groups.
-
Support multiple On-prem configurations per steering policy (maximum 3).

To learn more, view Enable Dynamic Steering.
Supported minimum Client version: 131.0.0
Windows 64-bit Client Support
Netskope upgraded the Client architecture from 32-bit to 64-bit. This enhancement allows the Netskope Client to utilize the native 64-bit capabilities of the operating system; which improves the traffic forwarding performance and adherence to compliance standards.
Supported minimum Client version: 131.0.0
Cert-pinned Apps Decryption: OpenSSL support
The OpenSSL library support by the Netskope cert-pinned applications decryption capability will allow us to decrypt traffic from x64 DevTools like AWS CLI, azure CLI, gcloud CLI and others and apply RTP policies.
Supported minimum Client version: 131.0.0
Controlled General Availability for One-Time Password-Based Client Disable For MacOS
Netskope introduced One-Time Password Disable option for macOS in version 130.0.0 as a Beta feature.
Admins have to configure this first on the tenant UI under the option Allow disabling of Internet Security in Settings > Security Cloud Platform > Client Configuration > Tamperproof.
Supported OS: MacOS, Windows (Already supported)
Supported minimum Client version: 130.0.0
To learn more: Client Configuration.
General Availability of Block Private IP address in Fail Close
The feature to allow administrators to block RFC-1918 IP addresses/subnets when Netskope Client is in Fail-Close state was earlier available as a Beta feature in version 130.0.0. This is now available for all tenants.
Supported minimum Client version: 130.0.0
132.0.0
General Availability of One-Time Password-Based Client Disable For MacOS
Netskope introduced One-Time Password Disable Option for Netskope Client for macOS in version 130.0.0.
With version 132.0.0, the feature is now available for all tenants.
Supported minimum Client version: 130.0.0
Support for ChromeOS 141
Netskope Client now supports ChromeOS 141
To learn more, view Netskope Client Supported OS and Platform.
Supported minimum Client version: 132.0.0
General Availability of Embedded Mini-browser Support for Captive Portal Authentication
Embedded Mini-browser Support for Captive Portal Authentication was available as a Beta feature in version 130.0.0. This is now available for all tenants.
Supported OS: Windows
Supported minimum Client version: 130.0.0
Support for Omnissa Horizon
Netskope Client now extends its support for Omnissa Horizon.
Supported OS: Windows 11, Windows Server 2019
Supported minimum Client version: 132.0.0
To learn more: view Omnissa Horizon.
Here is the list of fixed issues between versions 129.0.0 and 132.0.0.
| Issue Number | Description |
|---|---|
| 129.0.0 | |
| 679477 | Fixed an issue where the user experienced intermittent disconnection issues with the Netskope Client in Linux devices, affecting both NPA and Internet Security traffic. The issue caused connectivity loss for a few minutes at random times during the day. |
| 679420 | Fixed a P-DEM issue where the Netskope icon in Network Path Latency was getting displayed on the underlay Dashboard. The issue occurred due to the data from the Polaris Route Control was being sent to P-DEM inadvertently. With the fix, the Polaris Route Control data is not sent to P-DEM. |
| 671884 | Fixed an issue where the Device page displayed incorrect Client status after uninstalling the Netskope Client in macOS devices. The issue occurred when the feature flag to encrypt the branding file was enabled. With this fix, the uninstall status is displayed correctly even when the feature flag to encrypt the branding file is enabled. |
| 671659 | Fixed an issue with Netskope Client for iOS where the Client app did not work when the DNS resolver is IPv6 LinkLocal address. For example, when the device connects to internet through hotspot from another iPhone or iPad. |
| 693785 | Fixed an issue where wrong steering configurations were assigned when there are duplicate records for the same user. |
| 660522 | Windows AV check implementation depends on Windows security centre (WSC) APIs. Fixed an issue where the WSC service took time to get enabled when the system is rebooted. This led to Device Classification AV evaluation failure and the Client going to unmanaged state. With this fix, the Client uses the cached DC status from the previous evaluation until the WSC service comes up. Once the AV status change is detected the DC evaluation will happen again. |
| 701750 | Fixed an issue related to Secure Congifuration API response to prevent API response tampering. This fix is now backported and available in versions 126.0.9 and 123.0.15. |
| 680392 | Fixed an issue that the Netskope Client app for iOS did not work in IPv6 only network. |
| 680385 | Fixed an issue on Netskope Client for macOS devices where users reported DHCP failures on macOS 15.5 with Client version 126.0.0 or later. Exclude DHCP traffic to eliminate the issue in the macOS versions. If the users encounter this issue, they must reboot to bring the device back to normal and then upgrade to the latest version of Netskope Client. |
| 670199 | Fixed an issue where the Last Event Time column displayed on the Devices webUI, randomly displayed “55 years ago”. |
| 129.1.4 | |
| 726602 | Fixed an issue where the Netskope Client tunnel was not getting connected automatically after the device comes out of the standby or sleep mode. Note: The fix is released as part of mainstream release version 131.0.0 and is backported to version 129.1.4. |
| 747635 | Fixed a crash issue for Netskope Client for Windows where Netskope Client failed to query “owner process of current TCP connections“. Whenever Netskope Client attempts to query the connection owner using API, it failed leading to possible buffer over reads. Note: The fix is released as part of mainstream release version 131.0.0 and is backported to version 129.1.4. |
| 130.0.0 | |
| 669129 | Fixed an issue where the Netskope Client UI did not populate the User Email and Organization fields in a multi-user environment, as it failed to read the branding file from %APPDATA%\Netskope\STAgent. Fixed this issue by reading the branding file path from dps.json in the event of any failure in reading branding file by clientUI process. |
| 704508 | During the Private Access re-authentication using IDP (in an embedded Webview2 browser), when a user press the Shift+Enter or Control+Enter keys accidentally on the keyboard, the Netskope Client opens a new IDP window that leads to the re-authentication failure. This issue occurred because the Netskope Client cannot handle a new window request. This issue is now fixed. |
| 707515 | Fixed an issue where users were unable to login to Google Workspace since domain com.google.android.gms is set as Bypass in the Certificate Pinned Application exception. With this fix, Client removes com.google.android.gms from Android specific Bypass list. In case of any Android FOTA update with the Netskope Client enabled, configure a Certificate Pinned Application for com.google.android.gms and proceed with the update. Remove com.google.android.gms after the FOTA update. |
| 710784 | Whenever an administrator enables the feature to bypass all the existing TCP connections, Netskope Client will send the existing connections directly to the destination even when the tunnel is established. This fix was introduced to address the Citrix VDI remote access issue. Note: Use this feature flag with caution as it overrides the default behavior of sending the existing connections to Netskope Cloud. |
| 726488 | The fix provided for the previous issue number: 710784 caused a longpoll connection issue with Netskope Client. This issue can affect the real-time policies and DEM Synthetic probing. This longpoll issue is now fixed. |
| 725384 | Fixed an issue where the throughput value was non-zero in the UI even after the tunnel was brought down. To fix this issue, Netskope sets the throughput value as 0 if tunnel is brought down while sending the event to UI. |
| 131.0.0 | |
| 748332 | Fixed an issue where the webUI stopped updating the Client status when DEM Client Status Telemetry was disabled. |
| 729324, 731174 | Fixed an issue affecting Windows devices where enabling the Protect Client configuration and resources option led to Netskope Client driver denying READ permissions for third-party processes. This restriction caused third-party applications to hang Netskope Client processes indefinitely. Note: Contact Netskope Support to allow READ permissions when the Protect Client configuration and resources option is enabled on Windows devices. |
| 729025 | Fixed an interoperability issue in Netskope Client for macOS explicitly bound to the stf0 interface. |
| 718773 | Fixed an issue where users were able to access Netskope Configuration files through the Save Logs option when the Protect Client configuration and resources option is enabled. This can lead to the tampering of the branding file. With this fix, access to configuration files through “Save Logs” is now blocked. |
| 726784 | Fixed an issue where administrators were able to see duplicate entries of devices in the Devices page after upgrading to version 126.0.0.2387. |
| 726602 | Fixed an issue where the Netskope Client tunnel was not getting connected automatically after the device comes out of the standby or sleep mode. |
| 747635 | Fixed a crash issue for Netskope Client for Windows where Netskope Client failed to query “owner process of current TCP connections“. Whenever Netskope Client attempts to query the connection owner using API, it failed leading to possible buffer over reads. |
| 729176 | Fixed a high CPU usage issue that may occur when Netskope Client with the web steering mode is installed on a server, such as a domain controller, that handles a large number of incoming non-web TCP connections. |
| 728123 | Fixed an issue where tenant administrators with view permissions on the Devices page can see the one-time password (OTP) password in the API response. With this fix, OTP passwords are no longer visible to users with view-only permission. |
| 751112 | Fixed an issue where NPA services got disabled unexpectedly due to configuration issues in Netskope Client for Linux. |
| 132.0.0 | |
| 756104 | Fixed an issue where SkopeIT application logs displayed the DHCP IP instead of the machine IP as the source. Netskope Client sends only the machine IP when the tunnel is established for SkopeIT event reporting. |
| 746099 | Fixed an issue where Netskope Client maintains tunnel connections while the system network is active in sleep mode, reducing tunnel disconnections. Note: Contact Netskope Support to prevent the Netskope Client from disconnecting the tunnel during sleep. |
| 739968 | Fixed an issue that caused the Netskope Client to download the incorrect exception list whenever the Netskope Client tried to download the Netskope Client Configuration and the exception list simultaneously. |
| 747670 | Fixed an issue on Netskope Client for Windows where the process run as an administrator collects logs from the ProgramData log folder after clicking the Save Logs in Netskope Client UI. With this fix, on Windows, if the current process is running as administrator, and not in session 0, Client collects current logs from user %appdata% log folder |
| 769140 | While disabling Netskope Client from the tenant webUI, Netskope Client at times failed to download supportability parameters. Thus the Client status did not get updated as expected. The issue occurred due to large number of requests being generated. This impacted the Client management operations and caused the Netskope Client to not update its status. Netskope fixed this issue by increasing the capacity to serve the API requests. |
Here is the list of known issues between versions 129.0.0 and 132.0.0
| Issue Number | Description |
|---|---|
| 129.0.0 | |
| 684014 | When an IDP user is disabled, Netskope Client did not get disabled promptly. |
| 466448 | With Protect Client configuration and resources enabled, MSI re-run to update the secure enrollment tokens will not work. You can use nsdiag to update the secure enrollment tokens. |
| 129.1.0 | |
| 684014 | When an IDP user is disabled, Netskope Client did not get disabled promptly. |
| 466448 | With Protect Client configuration and resources enabled, MSI re-run to update the secure enrollment tokens will not work. You can use nsdiag to update the secure enrollment tokens. |
| 130.0.0 | |
| 684014 | When an IDP user is disabled, Netskope Client did not get disabled promptly. |
| 466448 | With Protect Client configuration and resources enabled, MSI re-run to update the secure enrollment tokens will not work. You can use nsdiag to update the secure enrollment tokens. |
| 130.1.0 | |
| 726784 | If the nsconfig.json file is not available on a device, the nsdeviceuid is generated using a legacy method. This can result in a unique situation where, once nsconfig.json becomes available, the device might have two different nsdeviceuid values. This scenario is considered a corner case. To mitigate, uninstall and reinstall the Netskope Client. |
| 684014 | When an IDP user is disabled, Netskope Client did not get disabled promptly. |
| 466448 | With Protect Client configuration and resources enabled, MSI re-run to update the secure enrollment tokens will not work. You can use nsdiag to update the secure enrollment tokens. |
| 131.0.0 | |
| 746099 | During sleep transitions, macOS can be delayed by long-running processes/daemons ( for example, CrowdStrike) that are slow to acknowledge power-management events. As the system continues to retry, the Netskope Client tunnel can repeatedly disconnect and reconnect. |
| 739968 | When the Netskope Client tries to download the Netskope Client Configuration and the exception list simultaneously, the Netskope Client failed to download the correct exception list. |
| 684014 | When an IDP user is disabled, Netskope Client did not get disabled promptly. |
| 131.1.0 | |
| 746099 | During sleep transitions, macOS can be delayed by long-running processes/daemons ( for example, CrowdStrike) that are slow to acknowledge power-management events. As the system continues to retry, the Netskope Client tunnel can repeatedly disconnect and reconnect. |
| 739968 | When the Netskope Client tries to download the Netskope Client Configuration and the exception list simultaneously, the Netskope Client failed to download the correct exception list. |
| 684014 | When an IDP user is disabled, Netskope Client did not get disabled promptly. |
| 132.0.0 | |
| 684014 | When an IDP user is disabled, Netskope Client did not get disabled promptly. |
| 755879 | The DNS tunneling feature available in Windows 11 is part of Windows Sub-System for Linux (WSL). This handles DNS requests directly within the WSL environment. The Linux instances running inside WSL doesn’t send DNS requests through NAT to the host anymore. This causes the Netskope Client to not intercept the requests through routing. As a workaround, disable the DNS tunneling in the .wslconfig on your host, shutdown and restart the WSL Linux instance. For instructions to disable DNS Tunneling feature, view Netskope Client for Linux. |
| 770428 | When editing a device classification rule with an Encryption check, the screen freezes after deleting another criterion. |

