Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Netskope Client
    Netskope Client Golden Release Updates
    Golden Release Updates Between 132.0.0 and 135.0.0

    Golden Release Updates Between 132.0.0 and 135.0.0

    Here are the latest features, issues fixed, and other updates published between the golden releases 132.0.0 and 135.0.0. This is a consolidated list of items published in the release notes for versions between 132.0.0 and 135.0.0.

    Use Release Notes widget for release notes related to a specific version.

    What’s New
    Fixed Issues
    Known Issues

    Here is the list of the new features and enhancements between versions 132.0.0 and 134.0.0.

    132.0.0

    General Availability of One-Time Password-Based Client Disable For MacOS

    Netskope introduced One-Time Password Disable Option for Netskope Client for macOS in version 130.0.0.

    With version 132.0.0, the feature is now available for all tenants.

    Even though this feature is available for all tenants, it is enabled on a request-basis. Contact Netskope support to enable this for your tenant.

    Supported minimum Client version: 130.0.0

    Support for ChromeOS 141

    Netskope Client now supports ChromeOS 141

    To learn more, view Netskope Client Supported OS and Platform.

    Supported minimum Client version: 132.0.0

    General Availability of Embedded Mini-browser Support for Captive Portal Authentication

    Embedded Mini-browser Support for Captive Portal Authentication was available as a Beta feature in version 130.0.0. This is now available for all tenants.

    Supported OS: Windows

    Supported minimum Client version: 130.0.0

    Although this feature is available for all tenants, it is enabled only on request. Contact Netskope support to enable it for your tenant.

    Support for Omnissa Horizon

    Netskope Client now extends its support for Omnissa Horizon.

    Supported OS: Windows 11, Windows Server 2019

    Supported minimum Client version: 132.0.0

    This feature is currently in Beta. It is validated only for persistent VDI environments. Admins can directly download and validate the latest version of Netskope Client. There is no need to contact Netskope Support.

    To learn more: view Omnissa Horizon.

    133.0.0

    Enforce Enrollment for Netskope Client

    Mandating user enrollment ensures all end-user traffic follows security policies, preventing bypass of controls by ignoring Client enrollment. This enforces compliance immediately after Netskope Client installation, especially in managed environments. Enforcing enrollment blocks users from accessing any internet-based web traffic.

    Supported minimum Client version: 133.0.0

    To learn more: view Enforce Enrollment for Netskope Client.

    This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature for your tenant.

    Controlled GA of Windows 64-bit Client Support

    In version 131.0.0, Netskope upgraded the Client architecture from 32-bit to 64-bit. This was available as a beta feature and now with version 133.0.0, this is now available as a Controlled GA feature.

    In version 133.0.0, Netskope enhanced the webUI option by allowing users to choose between 32-bit and 64-bit Windows architectures. This update applies specifically when upgrading the Netskope Client or when sending email invitations to new users. This improvement provides greater flexibility and ensures compatibility with different Windows system architectures during these processes.

    The flexibility to choose between 32-bit and 64-bit Windows architecture is also available while adding new users and sending emails with Netskope Client invitations to one or more groups.

    Supported minimum Client version: 131.0.0

    To learn more, view Netskope Client Support for 64-Bit.

    This is a controlled General Availability feature. Contact Netskope Support or your Sales Representative to enable this feature for your tenant.

    Google Advertising ID for Android Devices

    Introducing the ability to display Google Advertising ID (GAID) under the Device Serial Number and Unique Device ID in the Devices page for Android devices. This helps with better device details correlation between MDM and Netskope Devices page.

    Supported minimum Client version: 133.0.0

    To learn more, see Google Advertising ID (GAID) for Android devices.

    Support for ChromeOS 142

    Netskope Client now supports ChromeOS 142.

    Supported minimum Client version: 133.0.0

    To learn more, view Netskope Client Supported OS and Platform.

    General Availability of Support for Omnissa Horizon

    Netskope introduced support for Ominssa Horizon as Beta in version 132.0.0. This feature is now Generally Available. Admins can directly download and use the latest version of Netskope Client. It is validated only for persistent VDI environments.

    Supported OS: Windows 11 and Windows Server 2019

    Supported minimum Client version: 132.0.0

    To learn more: view Omnissa Horizon.

    CRL Check Validation for macOS

    Certificate Revocation List (CRL) Check validation was previously available for Device Classification on Windows. Netskope now extends support to macOS in version 133.0.0.

    The CRL contains digital certificates revoked by the issuing CA before their expiration date; these certificates are no longer trusted. If a certificate is revoked, the posture (device classification) check fails.

    Supported OS: macOS (from 133.0.0) Windows (from 122.1.0)

    Supported minimum Client version: 133.0.0

    To learn more: view Device Classification for macOS.

    Support for macOS is a Beta feature. Contact Netskope Support or your sales representative to enable this feature for your tenant.

    134.0.0

    Netskope Client Integration with Imprivata

    Netskope Client now supports integration with Imprivata for new Netskope Client installations.

    Healthcare professionals use Imprivata extensively to allow fast seamless access by various personnel to shared workstations. Imprivata is used as the IDP/SSO to authenticate doctors and nurses to allow them to access confidential patient records with appropriate privileges. Imprivata logins are abstract from the OS logins and Netskope Client needs to integrate with Imprivata agent to learn the logged in user information to apply related relevant Netskope policies. This enforces differentiated policies for doctors and nurses and less reliability on the Windows OS login for Netskope policies.

    Supported OS: Windows

    To learn more, view Netskope Client Integration with Imprivata.

    Supported minimum Client version: 134.0.0

    This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature for your tenant.

    Data Center Pinning Improvements

    Enhanced the Data Center Pinning functionality with the following:

    • Administrative Control: Admins can now control which user groups/OUs within the organization can perform Data Center Pinning.

    • Maximum duration for Data Center Pinning: Admins can now configure max. duration for which a user can remain pinned to a Data Center.

    • Extract information for Data Center Pinned users: Admins can see which users are manually pinned to a POP in exported Devices data.

    To learn more, view Data Center Pinning.

    Supported minimum Client version: 134.0.0

    This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature for your tenant.

    Support for ChromeOS 143 and 144

    Netskope Client now supports ChromeOS versions 143 and 144.

    Supported minimum Client version: 134.0.0

    To learn more, view Netskope Client Supported OS and Platform.

    Improve Tamper Proof in Netskope Client for MacOS

    Added the following security improvements in Netskope Client for macOS:

    • Verify and monitor Client executables code signatures, file system path, ownership and permissions at process launch time and over its lifetime.

    • Abort process on launch if verification fails.

    Supported minimum Client version: 134.0.0

    This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature for your tenant.

    DNS Steering Exception for TLD

    This feature allows administrators to define DNS steering exceptions for internal TLDs (for example, *.local, *.internal) as well as public TLDs, ensuring that DNS queries for configured wildcard TLDs are not steered to Netskope and are instead sent directly to internal resolvers.

    This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature for your tenant.

    Devices WebUI Improvements

    Upgraded the device management page to a new version 2 (v2) for a better experience.

    Supported minimum Client version: 134.0.0

    To learn more, view Devices.

    This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature for your tenant.

    Controlled GA of On-Premises Detection Using Egress IP Address

    On-Premises Detection using Egress IP address was introduced as a Beta feature in version 130.0.0. This is now available as Controlled GA feature.

    In version 130.0.0, introduced a new option Egress IP for On-Premises detection. This can be configured under Tunnel Settings > On-premises Detection in the Client Configuration UI that enable administrators to detect location of users (On or Off-premises) using trusted egress public IP locations and subsequently control traffic steering.

    Supported minimum Client version: 130.0.0

    To learn more: Netskope Client Configuration.

    This is a controlled General Availability feature. Contact Netskope Support or your Sales Representative to enable this feature for your tenant.

    General Availability of Windows 64-bit Client Support

    In version 133.0.0, Netskope Client support for Windows 64 bit was available as a Controlled GA feature. In version 134.0.0, this is now available for all tenants. The webUI option that allows users to choose between 32-bit and 64-bit Windows architectures is also available for all tenants with 134.0.0.

    Supported minimum Client version: 131.0.0

    To learn more, view Netskope Client Support for 64-Bit.

    For email invite (Windows 64 bit), view Email Invite.

    134.0.5

    Device Tags for Steering Configuration and Device Classification

    Introducing device tags with this release, that facilitates administrators to define a tag for a device or group of devices and that can be leveraged to add a tag-based steering policy or device classification rule.

    Supported OS: Windows and iOS

    Supported minimum Client version: 134.0.5

    To learn more, view Devices.

    This is a Beta feature. Contact Netskope Support team or your Sales Representative to enable this feature for your tenant.

    x86_64 Support for ChromeOS

    Netskope now includes native x86_64 CPU support for Netskope Client on ChromeOS. This enhancement resolves client app crashes or freezing on ChromeOS version 138 and boosts the overall performance of the Chromebook devices.

    135.0.0

    General Availability of On-Premises Detection using Egress IP address

    On-Premises Detection using Egress IP address was available as a Controlled-GA feature in version 134.0.0. This is now available for all tenants.

    To learn more: Netskope Client Configuration.

    Since this feature is available in a controlled manner, contact your Sales Representative or Support to enable this feature for your tenant.

    Supported minimum Client version: 130.0.0

    General Availability of Enforce Enrollment for Netskope Client

    Mandating user enrollment was available as a Beta feature in version 133.0.0. With this release, this is available for all tenants.

    To learn more: view Enforce Enrollment for Netskope Client.

    Since this feature is available in a controlled manner, contact your Sales Representative or Support to enable this feature for your tenant.

    Supported minimum Client version: 133.0.0

    General Availability of Data Center Selection or Pinning option

    The Data Pinning was available asa Beta feature in version 127.1.0. With this release, this is available for all tenants.

    This feature enables users to manually pin to a Point of Presence (POP) using the nsdiag command.

    To learn more, view Data Center Pinning In Netskope Client.

    Supported OS: Windows, MacOS, and Linux.

    Since this feature is available in a controlled manner, contact your Sales Representative or Support to enable this feature for your tenant.

    Supported minimum Client version: 127.1.0

    Support for ChromeOS 145

    Netskope Client now supports ChromeOS versions 145.

    Supported minimum Client version: 135.0.0

    To learn more, view Netskope Client Supported OS and Platform.

    Here is the list of fixed issues in this release.

    Issue NumberDescription
    132.0.0
    756104Fixed an issue where SkopeIT application logs showed the DHCP IP as the source instead of the machine IP. With this fix, Netskope Client sends only the machine IP when the tunnel is established for SkopeIT event reporting.
    746099Fixed an issue where Netskope Client maintains tunnel connections while the system network is active in sleep mode, reducing tunnel disconnections.


    Note


    Contact Netskope Support to prevent the Netskope Client from disconnecting the tunnel during sleep.


    739968Fixed an issue that caused the Netskope Client to download the incorrect exception list whenever the Netskope Client tried to download the Netskope Client Configuration and the exception list simultaneously.
    747670Fixed an issue on Netskope Client for Windows where the process run as an administrator collects logs from the ProgramData log folder after clicking the Save Logs in Netskope Client UI. With this fix, on Windows, if the current process is running as administrator, and not in session 0, Client collects current logs from user %appdata% log folder
    769140While disabling Netskope Client from the tenant webUI, Netskope Client at times failed to download supportability parameters. Thus the Client status did not get updated as expected.
    The issue occurred due to large number of requests being generated. This impacted the Client management operations and caused the Netskope Client to not update its status. Netskope fixed this issue by increasing the capacity to serve the API requests.
    132.0.7
    784831Parent process ID retrieval is slow during a failed close state while using Windows OS API. Optimized the API usage to mitigate the issue.
    753636, 783149Fixed a synchronization issue between write packet thread and diver global configuration setting thread.
    792233Fixed an issue in displaying following metrics on DEM dashboard.


    • Active Device Count by POP

    • Active Device Count by POP Per Hour

    132.0.13
    801565, 786556Fixed an issue for Netskope Client for Windows where the Client tunnel kept disconnecting or the Client services stopped.


    Note


    The fix is released as part of release version 133.0.4 and is backported to version 132.0.13.


    820999Fixed an issue where Netskope Client upgrade failed when updating 64-bit packages on Windows Server.

    Note


    The fix is released as part of release version 133.0.4 and is backported to version 132.0.13.


    781465, 726698Changing the registry value ProductID in HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion on a Windows device may cause an inter-process communication (IPC) failure between the Netskope Client processes stagentsvc and stagentUI due to mismatched encryption keys. The fix involves regenerating encryption keys for all Netskope Client processes when this issue occurs.

    Note


    The fix is released as part of release version 133.0.0 and is backported to version 132.0.13.


    795746, 777162, 778724Fixed nsconfig.json corruption issue, which prevented user certificate decryption when steering hardening and secure configuration validation were enabled. A corrupted nsconfig.json can be restored with the latest configuration if a successful download occurred. This requires the user certificate when steering hardening and secure config validation are enabled.

    Additionally, when the client generates a default nsconfig.json due to corruption, all feature-flagged values will be lost, preventing user certificate decryption and causing config download failures.

    Note


    The fix is released as part of release version 133.0.0 and is backported to version 132.0.13.


    133.0.0
    784777The issue occurred because TCP port reuse did not fully clean up the old session. The new session's first attempt triggered the port cleanup, causing failure and requiring a reconnect. This change ensures proper cleanup of the old session and no longer affects new sessions on the reused port.
    777432Fixed an issue where the Netskope Client UPN enrollment failed when Secure Configuration and Secure UPN were both enabled due to user certificate renewal, revocation, or a missing user certificate. This issue affected both single and multiple user setups.
    781045In the Web UI, the admin can enter a message in the user notification template. This message appears in the UI notification dialog at the Client endpoint. Previously, if the admin included a 'mailto url' in the user notification message, Netskope Client removed all spaces from the 'mailto url' and appended unwanted characters to the message's end. This issue is now fixed by preserving all spaces within the 'mailto url' and removing unwanted characters from the end.
    795746Fixed nsconfig.json corruption issue which prevented user certificate decryption when steering hardening and secure configuration validation were enabled. A corrupted nsconfig.json can be restored with the latest configuration if a successful download occurred. This requires the user certificate when steering hardening and secure config validation is enabled.

    Additionally, when the Client generates a default nsconfig.json due to corruption, all feature-flagged values will be lost, preventing user certificate decryption and causing config download failures.
    792144Adding more than one iOS link to email invite template leads to invalid App Store link. This issue is addressed by adding support for multiple iOS links in the email invitation.
    762198Fixed an issue with search results for user groups in Steering Configuration. Previously, when an admin searched for a user group using a specific keyword, the webUI displayed only 50 results and placed exact match group names at the bottom or middle of the list. This fix ensures the webUI places exact match group names at the top of the search results. For example, if a user searches using the keyword “admin”:

    • Before fix the search results will be in the following order:


      • db_admin

      • system_admin

      • user_administration

      • admin

      • administrators

      • admin_group


    • After fix the search results will be in the following order:


      • admin

      • administrators

      • admin_group

      • db_admin

      • system_admin

      • user_administration

    783149Fixed an issue where the users experienced Netskope Client disconnections and fail close state remained enabled. This led to frequent Internet Security tunnel disconnections and users are forced to reboot their system again.

    Note


    The fix is released as part of release version 133.0.0 and is backported to version 129.1.6.


    785026, 750658The Netskope Client captive portal feature now accommodates HTTP redirection using the meta refresh element.

    This fix addresses scenarios where the content attribute was not set to "0" or where apostrophes were used instead of double quotes.
    781465Changing the registry value ProductID in HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion on a Windows device may cause an inter-process communication (IPC) failure between the Netskope Client processes stAgentsvc and stagentUI due to mismatched encryption keys. The fix involves regenerating encryption keys for all Netskope Client processes when this issue occurs.
    765691Proxy detection relies on impersonating as an active user. In a multi-user scenario, such as Virtual Desktop Infrastructure (VDI), users may be in a disconnected state instead of being actively connected. A disconnected state indicates that users remain logged in but are not actively engaged. The proxy detection process should account for disconnected users, as their tunnels may still be active. This fix enables the impersonation of disconnected users as well.
    756815Fixed multiple issues regarding the auto-upgrade schedule:

    • Scheduled Auto-upgrade on Daily schedule will wait until the next nearest occurrence of scheduled time.

    • Scheduled Auto-upgrade on Weekly schedule will wait until the next nearest occurrence of the closest scheduled day(s) and time.

    • Scheduled Monthly schedule will wait until the next nearest occurrence of the closest scheduled week, day, and time.

    133.0.4
    801565, 786556Fixed an issue for Netskope Client for Windows where the Client tunnel kept disconnecting or the Client services stopped.


    Note


    The fix is released as part of release version 133.0.4 and is backported to version 132.0.13.


    820999Fixed an issue where Netskope Client upgrade failed when updating 64-bit packages on Windows Server.


    Note


    The fix is released as part of release version 133.0.4 and is backported to versions 132.0.13.


    133.1.0
    832690Fixed an issue where the One Time Password (OTP) feature failed on macOS devices because the Client Configuration webUI in version 133.0.0 showed an incorrect Netskope Client status.
    134.0.0
    795413Fixed an issue where Netskope Client does not support Captive Portal detection when HTTP response contained multiple HTML meta tags.
    840031Fixed an issue where Netskope Client for Linux crashed unexpectedly during the enrollment process. This specific crash occurred when users attempted to enroll the Client using the Identity Provider (IDP) mode.
    846555Fixed an issue where the Netskope Client for Linux installation used the /tmp folder. The install.sh command failed due to noexec permissions in /tmp. This fix directs the installation to use an alternate location.
    851222Fixed an issue where the Netskope Client connected to an on-premise network remained on-premises even after moving to off-premises. The status stayed on-premises until restarting the Netskope services.
    841829Fixed an issue where the device was categorized as unmanaged in the Devices webUI after adding the Device Classification rule for antivirus (AV). The issue occurred since Netskope Client did not convert the AV name string using the necessary UTF-8 method.
    846563Fixed an issue where the Netskope Client upgrade failed in Windows due to the missing installer cache. This issue is addressed by registering a backup source for the installer.
    835106, 761930With this fix, Netskope updated the system's limit for the maximum array size supported by the "clients" parameter in the Devices page API v2. The new stable maximum size is now set to 100 entries for optimal performance. Sending an API request for the Devices page with more than 100 entries within the "clients" parameter now results in an error response.
    824828The fix addresses an issue where the Custom antivirus (AV) check in Device Classification for Windows failed on endpoints with Trend Micro Apex One. This caused devices to be wrongly classified as "Unmanaged," despite the antivirus being installed and active.
    803728Fixed an issue in Netskope Client for iOS where the tunneling connection disrupted when the DNS-resolved address changed rapidly in CASB or Per-App VPN mode.
    798635Fixed an issue where inserting or removing smart card triggered a Device Classification check in Windows. This fix checks if the Smart Card option is enabled in at least one Certificate rule and starts the smart card monitor thread only if it does.
    728913Fixed an issue where the device classification check failed on macOS devices during certificate check with the “Check UPN” option enabled. UPN Check in non-AD domain-joined devices failed due to the UPN retrieved from Kerberos API did not match with the value in the certificate’s Subject Alternative Name (SAN) field. Use email as fallback for non-AD joined macOS devices.


    Note


    Contact Support to use email for UPN Check in Device Classification.



    684014Fixed an issue where the Netskope Client did not disable promptly after the user was disabled/ deleted in IDP.


    Note


    Contact Netskope Support to if the administrator wants to enable this fix for your tenant.



    848014Fixed an issue where graphs and tables for Site to POPs metrics showed inconsistent, inflated values in the DEM dashboard. The discrepancy occurred because the Netskope Client sent incorrect or excessive metric values to DEM.
    805334Fixed an interoperability issue that occurred with Netskope Client and VPN applications such as Citrix Secure Access and Cisco AnyConnect. The issue led to DNS resolution failures for internal and external domains.
    828189Fixed an issue where enabling steering On-Premises Detection Profile breaks if the tenant has many steering configurations in the webUI.
    840173Fixed an issue on the device page where hiding the "Internet Security Status" column unexpectedly disables the device enable/disable action button.
    810223When the admin creates a Client Configuration for the first time, the admin is given the option to apply the Configuration to either Organization Unit or User Group. This selection applies to the subsequent Client Configurations. Fixed an issue when admin searched for Client Configuration and received only one configuration in the search result, and when the admin tries to create a new Client Configuration, the admin can select Apply to “Organization Unit” or “User Group” which is not expected, and it caused the existing client configs to get deleted.
    825680Fixed an issue where the Default tenant config in the Steering Configuration webUI appeared under a different name, such as All Users.
    797625Fixed an issue where administrators could view device details on the Devices page in the web UI even if the device entry had an empty username or the device user is deleted.
    840031Fixed an issue where Netskope Client for Linux crashed unexpectedly during the enrollment process. This specific crash occurred when users attempted to enroll Client using the Identity Provider (IDP) mode.
    135.0.0
    872456Fixed an issue causing Netskope Client to crash when more than 3000 domain exceptions were added in the Steering Configuration.
    842447Fixed an issue where Netskope Client crashed, removing the user certificate and secure enrollment tokens. This required redeployment and re-enrollment of tokens. The issue was caused by a corrupt nsconfig.json file.
    873979In multi-user environments where the Secure Configuration option was enabled, the Netskope Client could lose access to user certificates during specific user sessions. This prevented the Client from downloading its configuration from the Cloud, causing it to remain in a disabled state.

    Fixed this issue and the Client can now properly handle user certificates even when the Secure Configuration option is enabled in a multi-user environment. As a result, the Netskope Client can consistently download configurations and remain enabled.
    849841Fixed an issue that occurred while adding Exception for Domains in Default Steering profile resulted in the exception being added to existing Domains Exception list instead of creating a new entry.

    Here is the list of known issues in this release.

    Issue NumberDescription
    132.0.0
    684014When an IDP user is disabled, Netskope Client did not get disabled promptly.
    755879The DNS tunneling feature available in Windows 11 is part of Windows Sub-System for Linux (WSL). This handles DNS requests directly within the WSL environment. The Linux instances running inside WSL doesn’t send DNS requests through NAT to the host anymore. This causes the Netskope Client to not intercept the requests through routing.

    As a workaround, disable the DNS tunneling in the .wslconfig on your host, shutdown and restart the WSL Linux instance. For instructions to disable DNS Tunneling feature, view Netskope Client for Linux.
    770428When editing a device classification rule with an Encryption check, the screen freezes after deleting another criterion.
    133.0.0
    761930The maximum array size for the “clients” parameter in Devices page with REST API v2 is 7000. Sending a request with more than 7000 entries for “clients” results in an error response. The workaround is to send API requests with not more than 7000 entries for the “clients” parameter.
    684014When an IDP user is disabled, Netskope Client did not get disabled promptly.
    133.1.0
    805334An interoperability issue occurred with Netskope Client and VPN applications such as Citrix Secure Access and Cisco AnyConnect. The issue led to DNS resolution failures for internal and external domains.
    134.1.0
    880058The Netskope Client for macOS disables intermittently during sleep, wake, or reboot. Rebooting the system resolves the issue.
    In this Topic
    • Golden Release Updates Between 132.0.0 and 135.0.0