Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Netskope Client
    Netskope Client Golden Release Updates
    Golden Release Updates Between 135.0.0 and 138.0.0

    Golden Release Updates Between 135.0.0 and 138.0.0

    Here are the latest features, issues fixed, and other updates published between the golden releases 135.0.0 and 138.0.0. This is a consolidated list of items published in the release notes for versions between 135.0.0 and 138.0.0.

    Use Release Notes widget for release notes related to a specific version.

    What’s New
    Fixed Issues
    Known Issues

    Here is the list of the new features and enhancements between versions 135.0.0 and 138.0.0.

    135.0.0

    General Availability of On-Premises Detection Using Egress IP Address

    On-Premises Detection using Egress IP address was available as a Controlled-GA feature in version 134.0.0. This is now available for all tenants.

    To learn more: Netskope Client Configuration.

    Since this feature is available in a controlled manner, contact your Sales Representative or Support to enable this feature for your tenant.

    Supported minimum Client version: 130.0.0

    General Availability of Enforce Enrollment for Netskope Client

    Mandating user enrollment was previously available as a Beta feature in version 133.0.0. With this release, the feature is now available for all tenants.

    To learn more: Enforce Enrollment for Netskope Client.

    Since this feature is available in a controlled manner, contact your Sales Representative or Support to enable this feature for your tenant.

    Supported minimum Client version: 133.0.0

    General Availability of Data Center Selection or Pinning Option

    Data Pinning was previously available as a Beta feature in version 127.1.0. With this release, the feature is now available for all tenants.

    This feature enables to manually pin to a Point of Presence (POP) using the nsdiag command.

    To learn more: Data Center Pinning In Netskope Client.

    Supported OS: Windows, MacOS, and Linux.

    Since this feature is available in a controlled manner, contact your Sales Representative or Support to enable this feature for your tenant.

    Supported minimum Client version: 127.1.0

    Support for ChromeOS 145

    Netskope Client now supports ChromeOS version 145.

    Supported minimum Client version: 135.0.0

    To learn more: Netskope Client Supported OS and Platform.

    Support for RHEL 9.6

    Netskope Client now supports Red Hat Enterprise Linux (RHEL) version 9.6.

    Supported minimum Client version: 135.0.0

    To learn more: Netskope Client Supported OS and Platform.

    Monitoring and Automatic Restart of Netskope Client Services

    This release introduces a service monitor: stAgentSvcMon, a new mechanism within Netskope Client Agent Service designed to monitor the operational status of the stAgentSVC service. Prior to version 135.0.0, the stAgentSVC agent service lacked an automatic restart capability when it ceased operation due to an issue. With the implementation of this new service, the service monitor can now oversee and automatically restart the agent services, including those deliberately stopped by an administrator. This monitor verifies the running status of Agent Service every 60 seconds and initiates an automatic restart if the stAgentSVC service status is registered as stopped. 

    Since this feature is available in a controlled manner, contact your Sales Representative or Support to enable this feature for your tenant.

    Zone Selection Based on User Identity

    Introducing Zone Selection feature in Client Configuration. Using this option, the administrator can select China Elite zone in the Client Configuration.

    To learn more, view Zone Selection Based on User Identity.

    Supported minimum Client version: 135.0.0

    This is currently in Beta and is available only for tenants with the elite China license. Contact Netskope Support to enable this feature for your tenant.

    136.0.0

    Secure Enrollment Token Expiration Email Notification

    Token expiration Email notification automates email alerts for tenant administrators to notify them when Secure Enrollment tokens are approaching their expiration date. With the implementation of this feature, it helps protect against Netskope Client installation failures caused by expired tokens.

    Administrators can configure notification settings on the MDM page. Once enabled, Netskope Client identifies tokens nearing expiration and triggers automated emails 30, 15, 7, and 1 day(s) before the token expires. To prevent unnecessary noise, notifications only trigger if Secure Enrollment is enforced and cease immediately once a token has expired.

    Allows administrators to specify up to 25 email addresses to receive these critical notifications.

    To learn more: Email Notification.

    This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature for your tenant.

    Granular Fail-Close Control

    This feature allows administrators to granularly enable or disable the Fail-Close setting based on a user’s location, specifically distinguishing between on-premises and off-premises environments.

    Along with the new Fail-Close enhancements, Netskope has:

    • Reduced User Disruption: Introduced an optional “Show notification after” setting (30–120 seconds) delays Fail-Close alerts to prevent pop-ups during transient network issues, such as switching between Wi-Fi networks

    • Decoupled Settings: Removes previous dependencies, enabling independent management of options such as password-protected uninstallation and service disabling, regardless of Fail-Close status.

    Fail Close with Dynamic Steering

    Fail Close without Dynamic Steering

    To learn more: Fail Close (Check Step 7 in section: Creating Steering Configuration From Version 124.0.0).

    With this release, it moves the Fail-Close configuration from the general Client Configuration to Steering Configuration within the web UI.

    Supported minimum Client version: 136.0.0

    This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature for your tenant.

    Custom Device Identity Keys for iOS

    This enhancement closes the visibility gap by allowing IT and security teams to match devices in the Netskope Web UI with known assets in their MDM or help desk systems.

    • Faster Incident Response: Provides human-readable device names and accurate serial numbers, which simplifies auditing and speeds up troubleshooting.

    • Asset Alignment: Replaces self-generated Unique Device IDs and “N/A” serial number labels with actual organizational asset identifiers.

    To incorporate these improvements, Netskope introduces two new optional VPN profile keys that administrators can populate through their MDM platform (e.g., Jamf, Microsoft Intune) when pushing profiles to iOS devices.

    To learn more: Custom Device Identity Keys for iOS (Check Steps 6 > Custom Device Identity Key-Value Pairs for iOS).

    General Availability of Steering Configuration WebUI Enhancements

    The enhanced Match Criteria capabilities was available as a Beta feature in version 124.0.0. This is now available for all tenants.

    Netskope introduced two new capabilities under Match Criteria in the Steering Configuration on the webUI:

    • OS Family: Differentiate steering profiles based on different operating systems(Windows, MacOS, Linux, Android, and iOS). This option provides flexibility in configuring steering profiles by choosing the OS type as match criteria.
    • User Group/ OU: With 124.0.0, Netskope added ability to select multiple User Groups/OUs while configuring Steering profiles.

    To learn more: Steering Configuration.

    Supported minimum Client version: 124.0.0

    General Availability of Netskope Client Integration with Imprivata

    Netskope Client integration with Imprivata was available as a Beta option in version 134.0.0. With version 136.0.0, Imprivata integration is available for all tenants.

    Healthcare professionals use Imprivata extensively to allow fast seamless access by various personnel to shared workstations. Imprivata is used as the IDP/SSO to authenticate doctors and nurses to allow them to access confidential patient records with appropriate privileges. Imprivata logins are abstract from the OS logins and Netskope Client needs to integrate with Imprivata agent to learn the logged in user information to apply related relevant Netskope policies. This enforces differentiated policies for doctors and nurses and less reliability on the Windows OS login for Netskope policies.

    Supported OS: Windows

    To learn more, view Netskope Client Integration with Imprivata.

    Supported minimum Client version: 134.0.0

    General Availability of CRL Check Validation for MacOS

    Certificate Revocation List (CRL) Check validation was available for Device Classification on macOS as a Beta option in version 133.0.0. This is now available for all tenants.

    The CRL contains digital certificates revoked by the issuing CA before their expiration date; these certificates are no longer trusted. If a certificate is revoked, the posture (device classification) check fails.

    Supported OS: macOS (from 133.0.0) Windows (from 122.1.0)

    To learn more: view Device Classification for macOS.

    Supported minimum Client version: 133.0.0

    Support for ChromeOS 146

    Netskope Client now supports ChromeOS version 146.

    To learn more, view Netskope Client Supported OS and Platform.

    Supported minimum Client version: 136.0.0

    137.0.1

    Here is the list of the new features and enhancements.

    External Browser-Based Authentication

    Netskope Client for Windows now supports browser-based IdP authentication using the default system browser instead of embedded WebView2 browser.

    To learn more, External Browser-based Authentication.

    Supported minimum Client version: 137.0.1

    This feature is currently in Beta and is available on all tenants.

    Enhanced iOS Log Collection

    The Netskope Client for iOS app now includes a diagnostic log sharing feature that lets administrators export logs anytime, even during enrollment failures or configuration delays, without IT or MDM administrator assistance.

    Benefits

    • Faster Troubleshooting: Accelerates support ticket resolution by allowing admins to send logs directly to the Netskope tenant with a single tap.

    • Reduced User Friction: Simplifies the process for administrators who no longer need to have joint sessions with the MDM specialists.

    To learn more, view Log Collection.

    User Coaching on iOS NSClient

    User Coaching notification is now supported on Netskope Client for iOS.

    You can configure Real-Time Policies to create rules for actions like login attempts and edits. When a user tries an action configured in a Real-Time Policy, they receive in-app notifications restricting permission to perform it. After the administrator gets these notifications, they can Allow, Block, or Report a false positive with justification.

    This feature is available for all tenants.

    To learn more, view User Alerts for iOS.

    Supported minimum Client version: 137.0.1

    To learn more, view Netskope Client for iOS.

    Device Tags for Steering Configuration and Device Classification in macOS, Linux, and Android

    Device Tags is now supported for macOS, Linux, Android platforms. This was earlier available for Windows and iOS in version 134.0.5. Device Tags facilitates administrators to define a tag for a device or group of devices and that can be leveraged to add a tag-based steering policy or device classification rule.

    Supported OS: macOS, Linux, and Android (137.0.1), Windows and iOS (134.0.5)
    Supported minimum Client version: 137.0.1 (for macOS, Linux, and Android)

    To learn more, view Devices.

    This is a Beta feature. Contact Netskope Support or your sales representative to enable this feature for your tenant.

    Support for ChromeOS 147

    Netskope Client now supports ChromeOS version 147.

    Supported minimum Client version: 137.0.0

    To learn more, view Netskope Client Supported OS and Platform.

    New DEMAgent Service

    A new DEMAgent service will be installed as a part of the 137.0.1 Netskope Client version for Windows platforms. The service will only be active and registered if the Netskope tenant has the DEMAgent BETA flag active. If the BETA flag is active the DEMAgent.exe child process of the Netskope Client will be visible on the endpoint.

    General Availability of Secure Enrollment Token Expiration Email Notification

    Secure Enrollment token expiration was introduced as a Beta feature in version 136.0.0. The option will now be available for all tenants.

    Token expiration Email notification automates email alerts for tenant administrators to notify them when Secure Enrollment tokens are approaching their expiration date. With the implementation of this feature, it helps protect against Netskope Client installation failures caused by expired tokens.

    To learn more: Email Notification.

    General Availability of On-Prem Detection WebUI Modification

    In version 131.0.0, the On-Premises Detection was moved from Netskope Client > Client Configuration to Traffic Steering > Steering Configuration. This webUI update was available only as a Beta option. This is now available for all tenants.

    The change was done to:

    • Enhance the ease of use for this option.

    • Mitigate configuration management complexities arising from mismatches between the Client and Steering configurations due to misaligned Organization Units or User Groups.

    • Support multiple On-prem configurations per steering policy (maximum 3).

    Prerequisites:

    •  Enable Dynamic Steering

    • Provide Match Criteria in Steering Configuration

    Supported minimum Client version: 131.0.0

    To learn more, view Enable Dynamic Steering.

    General Availability of Zone Selection Based on User Identity

    This feature was available as Beta in version 135.0.0. This will be now available for all tenants.

    Using the Zone Selection option, the administrator can select China Elite zone in the Client Configuration.

    To learn more, view Zone Selection Based on User Identity.

    Supported minimum Client version: 135.0.0

    138.0.0

    Enhanced Selection for Golden Monthly Releases

    This enhancement focus on the Upgrade Client automatically to a specific Client version option in the Client Configuration profile include all supported monthly and golden releases, specifically adding visibility and access to hotfix (dot) versions.

    Benefits

    • Granular Version Control: Provides administrators with the flexibility to pin users to a specific hotfix version (for example, 135.1.2) rather than just the major release.
    • Operational Precision: Simplifies the upgrade workflow by listing all available and supported versions in the dropdown for precise version selection.

    To learn more, view Upgrade Client to a Specific release version.

    This is currently a Beta feature. Contact Netskope Support to enable this for your tenant.

    Pagination in Devices WebUI

    With version 138.0.0, the Select All option supports upto 1000 devices on the Devices webUI.

    Devices WebUI Improvements

    The webUI enhancements were introduced as a Beta feature in version 134.0.0. This is now available for all tenants.

    In version 134.0.0, Netskope upgraded the device management page to a new version 2 (v2) for a better experience.

    Supported minimum Client version: 134.0.0

    To learn more, view Devices.

    Here is the list of fixed issues between versions 135.0.0 and 138.0.0.

    Issue NumberDescription
    135.0.0
    872456Fixed an issue causing Netskope Client to crash when more than 3000 domain exceptions were added in the Steering Configuration.
    842447Fixed an issue where Netskope Client crashed, removing the user certificate and secure enrollment tokens. This required redeployment and re-enrollment of tokens. The issue was caused by a corrupt nsconfig.json file.
    873979In multi-user environments where the Secure Configuration option was enabled, the Netskope Client could lose access to user certificates during specific user sessions. This prevented the Client from downloading its configuration from the Cloud, causing it to remain in a disabled state.

    Fixed this issue and the Client can now properly handle user certificates even when the Secure Configuration option is enabled in a multi-user environment. As a result, the Netskope Client can consistently download configurations and remain enabled.
    849841Fixed an issue that occurred while adding Exception for Domains in Default Steering profile resulted in the exception being added to existing Domains Exception list instead of creating a new entry.
    135.1.4
    906096Fixed an issue where the Netskope Client for Windows failed to re-enroll when upgrading from the 64-bit version (134.0.0) to the 64-bit version (135.0.0) using the MSI installer.

    The issue resulted from the inadvertent removal of enrollment tokens from the Windows registry during the upgrade process. The fix implements installer modifications and a new backup/restore mechanism to ensure that the enrollment tokens are preserved during the upgrade.

    Note: The fix is released as part of release version 135.1.4 and is backported to version 132.0.23.

    918295Fixed an issue where Netskope Client did not capture DNS traffic sent over non-global DNS servers in Web or Cloud mode. With this fix, Netskope Client now monitor non-global DNS queries.
    135.1.10
    954726Fixed an issue where the administrator received email about log collection status every five minutes. With this fix, whenever the administrator requests for the logs from the Devices webUI using Collect Logs, the administrator receives only one email notification after the log collection is completed.
    951409Fixed following issues:

    • Where the installation monitor services stopped during Client upgrade. The Netskope Client could not complete the upgrade process due to issues in the monitor services.

    • Where the Netskope Client failed to gather correct data from the registry whenever the administrator upgraded the Client from 32-bit to 64-bit and vice versa.

    • Where the Netskope Client monitor services delayed the system shutdown and reboot processess in Windows.

    • Where an incorrect upgrade monitor binary paths were added in registry during Client upgrade.


    135.1.13
    918451Fixed an issue where Egress IP detection for On-Premises failed when the Client did not reconnect to the tunnel after switching from Off-Prem to On-Prem.

    Note: This was fixed in 136.0.0 and backported to version 135.1.13
    136.0.0
    918131Fixed an intermittent tunnel disconnection in a multi-user VDI environment caused by simultaneous user logins delaying the tunnel connection.
    906435Fixed a GSLB connection steering issue on Android and ChromeOS that blocked GSLB traffic. Now, GSLB traffic bypasses the Netskope Client tunnel on these platforms.
    925894Fixed an issue where Netskope Client installation failed intermittently on Windows Amazon Workspaces.

    EC2/AWS Workspaces instances and other server environments often lack the Smart Card service, causing the absence of winscard.dll. This can cause immediate process failure on Windows devices.
    924382Fixed an issue where an incorrect enterprise policy was created for Firefox when the policy is modified by Netskope Client service (stAgentSvc).
    918451Fixed an issue where Egress IP detection for On-Premises failed when the Client did not reconnect to the tunnel after switching from Off-Prem to On-Prem.
    906271Fixed an issue where Netkope Client for iOS devices crashed while operating in the CASB or Per-App VPN mode.
    880058Fixed an issue where device sleep and wake cycles sometimes disabled Netskope Client for macOS.
    136.1.5
    979110Fixed an issue where the configd in macOS, a system daemon responsible for managing network configurations, system settings, and state change, crashed after the device comes out of the sleep or wake cycle.
    137.0.1
    948106Fixed an issue causing Netskope Client for Linux to crash when more than 10000 domain exceptions were added in the Steering Configuration.
    961429Fixed an issue where Netskope Client prompted the user to enter a password after selecting Disable All Client Services even when there was no Master Password configured in the Client Configuration.
    960369Fixed an issue where upgrading Netskope Client from version 129.0.0 to 132.0.0 left stAgentSvc at version 129.0.0. The problem occurred because a previous upgrade was interrupted abruptly.
    815908Fixed an issue where the username in logs would incorrectly display the previous user after a new user logged into the same machine.

    With this fix, in a multi-user environment, Netskope ensures that only one long-poll connection exist per device, attributed to the most recently logged-in user, specifically when other steering methods (GRE/IPSec) are detected instead of client-based steering. This fix is currently available in a demand basis.

    Note: Contact Netskope Support to avail this fix for your tenant.
    956159Fixed an issue where Netskope Client incorrectly identified the system as multi-user, despite deployment in single-user mode. This caused failure to generate Device Health Metrics for that user.
    956138Fixed an issue where the device health event did not generate at the configured frequency. Now, DEM device health events are generated as configured as configured.
    917549The Netskope Client for Android kept searching for connectivity after the user disabled the network. The Client UI displayed the previous status and did not update to the latest tunnel data. This issue is fixed and now when the user disables the network, the GUI shows the status as disconnected.
    925885Fixed an issue where any admin could send crafted IOCTL (Input/Output Control) requests to the driver, disabling its protection mechanisms. This fix strengthens protection, preventing modifications to the driver’s configurations. No process can access the Netskope driver’s handle when “Protect Client configuration and resources” under “Tamperproof” is enabled.
    833920Fixed an issue where the users could not get the correct pinning status especially when the tunnel connection fails. With this fix, users can now get better information regarding the Data Centre pinning status status.

    940205Fixed a steering configuration issue where the Exceptions tab showed duplicate entries when navigating pages. This happened when multiple exceptions shared the same type across pages. The entries now display correctly on all pages.
    137.1.3
    977129Fixed a blank screen issue during IDP enrollment on Windows devices caused by high CPU usage.
    138.0.0
    985967Fixed the following issues:

    • When cloning an existing steering configuration, the webUI incorrectly using the original configuration's unique identifier for the cloned steering configuration. This led to an error when users tried to save specific enrollment exceptions for the new, copied configuration.

    • The performance when saving enrollment exceptions by optimizing the process of updating system data. Previously, in large environments, this update was causing a delay.

    1000633In environments using EAM/Imprivata floating workstations, the client now correctly tears down the previous licensed user’s tunnel when a non-licensed user authenticates or when authentication is canceled. This prevents stale UPN tunnels from persisting across user switches and ensures that tunnels are only active for the appropriate licensed user.
    991833Fixed an issue that occurred when other steering methods such as IPSec is enabled along with FailClose. In the event of any network switch, it can delay enabling Fail Close on the systems.
    988826Resolved an issue where Windows Client auto-upgrades could fail if the stAgentSvc service became unresponsive during tunnel reconnection with DEM/RCC enabled. The fix prevents new DEM monitoring tasks from starting during service shutdown by using atomic stopping flags, reducing the risk of service hangs and upgrade failures.

    Here is the list of known issues between versions 135.0.0 and 138.0.0.

    Issue NumberDescription
    135.0.0
    880058The Netskope Client for macOS disables intermittently during sleep, wake, or reboot. Rebooting the system resolves the issue.
    135.1.4
    880058The Netskope Client for macOS disables intermittently during sleep, wake, or reboot. Rebooting the system resolves the issue.
    136.1.0
    961429Netskope Client prompted the user to enter a password after selecting Disable All Client Services even when there was no Master Password configured in the Client Configuration.
    137.1.3
    996181Netskope client measures CPU usage for the DEM dashboard using the "Processor Time" performance counter, while Task Manager uses the "Processor Utility" counter. On modern hardware with Intel Turbo Boost or AMD Precision Boost, these counters can report significantly different values for the same workload. As a result, CPU usage shown in Task Manager can exceed the value reported by the Netskope client on the DEM dashboard.
    138.0.0
    996181Netskope Client measures CPU usage for the DEM dashboard using the "Processor Time" performance counter, while Task Manager uses the "Processor Utility" counter. On modern hardware with Intel Turbo Boost or AMD Precision Boost, these counters can report significantly different values for the same workload. As a result, CPU usage shown in Task Manager can exceed the value reported by the Netskope client on the DEM dashboard.

    In this Topic
    • Golden Release Updates Between 135.0.0 and 138.0.0