Here are the latest features, issues fixed, and other updates published between the golden releases 138.0.0 and 141.0.0. This is a consolidated list of items published in the release notes for versions between 138.0.0 and 141.0.0.
Use Release Notes widget for release notes related to a specific version.
Here is the list of the new features and enhancements between versions 138.0.0 and 141.0.0.
138.0.0
Enhanced Selection for Golden Monthly Releases
This enhancement focus on the Upgrade Client automatically to a specific Client version option in the Client Configuration profile to include all supported monthly and golden releases, specifically adding visibility and access to hotfix (dot) versions.
Benefits
- Granular Version Control: Provides administrators with the flexibility to pin users to a specific hotfix version (for example, 135.1.2) rather than just the major release.
- Operational Precision: Simplifies the upgrade workflow by listing all available and supported versions in the dropdown for precise version selection. To learn more, go to Upgrade Client to a Specific release version.
Devices WebUI Improvements
The webUI enhancements were introduced as a Beta feature in version 134.0.0. This is now available for all tenants.
In version 134.0.0, Netskope upgraded the device management page to a new version 2 (v2) for a better experience.
Supported minimum Client version: 134.0.0
To learn more, view Devices.
Support for ChromeOS 148
Netskope Client now supports ChromeOS version 148.
Supported minimum Client version: 138.0.0
To learn more, view Netskope Client Supported OS and Platform.
Pagination in Devices WebUI
With version 138.0.0, the Select All option supports upto 1000 devices on the Devices webUI.
To learn more, view Devices.
139.0.0
Support for FIPS-140-3 Compliance Requirements
Netskope introduces FIPS 140-3 Mode for the Netskope Client, enabling organizations in regulated industries to operate with federally validated cryptographic modules for all encryption, hashing, and key management operations.
With this release, administrators can configure the Netskope Client to operate in:
- Strict FIPS Mode: which permits only FIPS 140-3 validated algorithms, or
- Permissive FIPS Mode: where the Client prefers FIPS-validated cryptography but falls back to standard mode if initialization fails.
– This is only applicable for Internet Security Service.
Supported OS: Windows (Only 64-bit), macOS
Supported minimum Client version: 139.0.0
To learn more, view FIPS 140-3 Mode Support for Netskope Client.
Auto Re-enable Netskope Client
Netskope introduces an optional Auto Re-Enable Duration for the Allow disabling of all Client services together option in Netskope Client Configuration. Administrators can now configure a timer in the tenant webUI so that when a user disables all Client Services, the Netskope Client automatically re-enables all services after the configured duration — without requiring any manual action from the user or the administrator.
Previously, when a user disabled all Client Services, the services remained disabled until the administrator manually re-enabled them. This enhancement removes that dependency by automatically restoring protection after a set period, reducing administrative overhead and ensuring that security posture is reinstated within a defined time window.
Supported Operating Systems: Windows, macOS, Linux
Minimum Netskope Client Version: 139.0.0
To learn more, view Client Configuration.
Ability to Delete Devices
Administrators can now delete one or more devices directly from the Devices page in the Netskope webUI. When a device is deleted, Netskope automatically unenrolls the Client on the user’s machine. The unenrolled user receives a notification in the Netskope Client UI and must re-enroll to restore protected access.
Benefits:
- Accurate device inventory: Administrators can remove stale device entries left behind when employees leave the organization or devices change hands, keeping the Devices page accurate and audit-ready.
- Faster response to rogue device threats: Administrators can immediately remove and unenroll unauthorized devices that enrolled through compromised email invites or UPN enrollment, reducing the window of exposure without needing to contact Netskope Support.
- Cleaner audit exports: Organizations that export the Devices page for compliance or audit purposes get reliable data, free from stale or duplicate entries that previously caused incorrect coverage reporting.
- Self-service device lifecycle management: Administrators no longer need to raise a support ticket to remove devices. The delete operation is available directly in the UI, reducing operational overhead and response time.
Supported Operating Systems: Windows, macOS
Supported minimum Client version: 139.0.0
To learn more, view Devices.
General Availability of Device Tags for Steering and Classification
Device Tags feature was available as a Beta option in version 134.0.5. This is now available on a request basis from version 139.0.0.
Device tags facilitates administrators to define a tag for a device or group of devices that can be leveraged to add a tag-based steering policy or device classification rule.
Supported OS: Windows, macOS, Linux, iOS, and Android.
Supported minimum Client version (Windows and iOS):134.0.5
Supported minimum Client version for macoS, Linux, Android: 138.0.0
To learn more, view Devices.
General Availability of External Browser-Based Authentication
The external browser support for Netskope Client for Windows was available as Beta in version 137.0.1. This is now available for all tenants.
To learn more, External Browser-based Authentication.
Supported minimum Client version: 137.0.1
Support for ChromeOS 149
Netskope Client now supports ChromeOS version 149.
Supported minimum Client version: 139.0.0
To learn more, view Netskope Client Supported OS and Platform.
Support for RHEL 10
Netskope Client now supports Red Hat Enterprise Linux (RHEL) version 10.
Supported minimum Client version: 139.0.0
To learn more: Netskope Client Supported OS and Platform.
140.0.0
Client Support for Mobile in French (Canada)
The Netskope Client for iOS now displays its user interface in Canadian French (fr-CA).
This update helps organizations meet Quebec’s Bill 96 language requirements by letting end users view the Netskope Client interface in French instead of English.
Minimum Supported Client Version: 140.0.0
Supported OS: iOS
To learn more, view Multilingual Support For iOS.
New OS Support for Netskope Client
Netskope supports the following operating systems in version 140.0.0:
- Ubuntu 26.04
- Android 17
- ChromeOS 150
Minimum Supported Client Version: 140.0.0
To learn more, view Netskope Client Supported OS and Platforms.
General Availability of Enhanced Selection for Golden Monthly Releases
Enhanced Selection for Golden Monthly Releases was earlier available as a Beta option in version 138.0.0. This is now available for all tenants.
The Upgrade Client automatically to a specific Client version option in the Client Configuration profile to include all supported monthly and golden releases, specifically adding visibility and access to hotfix (dot) versions.
To learn more, view Upgrade Client to a Specific release version.
General Availability of Auto Re-enable Netskope Client
Auto Re-Enable Duration in Client Configuration was available as a Beta option in version 139.0.0. This is now available for all tenants.
Using this option, administrators can now configure a timer in the tenant webUI so that when a user disables all Client Services, the Netskope Client automatically re-enables all services after the configured duration — without requiring any manual action from the user or the administrator.
Supported Operating Systems: Windows, macOS, Linux
Minimum Netskope Client Version: 139.0.0
To learn more, view Auto Re-enable Duration.
140.1.0
General Availability of Ability to Delete Devices
Deleting devices directly from the webUI option was available as a Beta feature in version 139.0.0. This is now available for all tenants. When a device is deleted, Netskope automatically unenrolls the Client on the user’s machine. The unenrolled user receives a notification in the Netskope Client UI and must re-enroll to restore protected access.
Supported Operating Systems: Windows, macOS
Supported minimum Client version: 139.0.0
To learn more, view Devices.
141.0.0
Support for ChromeOS 151
Netskope Client now supports ChromeOS version 151.
Supported minimum Client version: 141.0.0
To learn more, view Netskope Client Supported OS and Platform.
Cloud Firewall(CFW) Support for Android & ChromeOS
Netskope Client now supports Cloud Firewall (CFW) and DNS Security modes on Android and ChromeOS, extending protection already available on Windows, Mac, iOS, and Linux.
With the All Traffic mode enabled in the Steering Configuration, these devices now steer non-web traffic including DNS traffic (DNS Security) to Netskope Cloud Firewall for policy enforcement, closing this gap.
Minimum Supported Client Version: 140.0.0
Here is the list of fixed issues between versions 138.0.0 and 141.0.0.
| Issue Number | Description |
|---|---|
| 138.0.0 | |
| 985967 | Fixed the following issues:
|
| 1000633 | In environments using EAM/Imprivata floating workstations, the Client now correctly terminates the previous licensed user's tunnel when a non-licensed user authenticates or when authentication is canceled. This prevents stale UPN tunnels from persisting across user switches and ensures that tunnels are only active for the appropriate licensed user. |
| 991833 | Fixed an issue that occurred when other steering methods such as IPSec is enabled along with Fail Close. In the event of any network switch, it can delay enabling Fail Close on the systems. |
| 988826 | Fixed an issue where Windows Client auto-upgrade failed when the stAgentSvc service remained unresponsive during tunnel reconnection with Digital Experience Management (DEM)/ Route Control Collection (RCC) enabled. The fix prevented new DEM monitoring tasks from starting during service shutdown by using stopping flags thereby reducing the risk of service hangs and upgrade failures. |
| 1002539 | Fixed an issue where devices were incorrectly displayed as "not configured" for Device Classification, even though all required checks were completed successfully. The devices now correctly reflect their classification status after all checks are completed. |
| 1017061 | Fixed an issue where the Netskope IP Ranges dialog (navigated via Settings > Security Cloud Platform > Netskope Client > Enforcement) incorrectly displayed [object Object] for Dedicated Egress IP. This occurred specifically on the Dedicated IP Ranges tab instead of showing the actual IP addresses. The dialog is now updated to present Data Centers and their corresponding IP ranges in a structured two-column table. Additionally, Copy functionality is now supported on a per-tab basis. |
| 138.0.2 | |
| 1015977 | Fixed a bypass-by-tunnel (includes "Bypass exception traffic at:Client" action in Steering Configuration and "Bypass by Tunnel Mode" in Certificate Pinned App exception) issue affecting the Microsoft Teams and Microsoft Intune Company portal applications. Previously, bypass-by-tunnel domains associated with Certificate Pinned Apps were not honored in dual-stack network environments. |
| 138.1.5 | |
| 1012336 | Fixed and issue with Netskope Client for macOS where the Private Access tunnel remained disconnected or stuck in reauthentication following network changes. This update ensures:
Note: This is backported to versions 135.1.20 and 132.0.28 |
| 138.1.10 | |
| 1036346 | Improved security for the captive portal pop-up message on Windows. The captive portal dialog now includes protections to prevent misuse by malicious Wi-Fi networks, such as blocking unauthorized downloads, preventing access to developer tools, and automatically closing the window when the network disconnects. Contact Netskope Support to enable the fix for your tenant. Note: This was fixed in version 140.0.0 and is getting back ported to version 138.1.10, 135.1.22, and 132.0.29. |
| 1107289 | Fixed an issue where the Netskope Client upgrade on Windows could fail or hang when Digital Experience Management (DEM) was enabled.Previously, when DEM was enabled, the Netskope Client service took more time to stop during an upgrade, causing the upgrade to fail. This occurred because DEM tasks did not stop promptly when the Client service was shutting down. With this fix, the Client service now shuts down properly and within the expected time, ensuring smooth client upgrades. Note: This was fixed in version 140.0.0 and is getting back ported to version 138.1.10 and 135.1.22. |
| 139.0.0 | |
| 1020103 | Fixed token verification failure during rotation where ignoring a Secure Enrollment token set caused enrollment failures (401) for clients holding a valid JWT signed with that token's material. Tokens now correctly remain in the verification pool during the transition window. Added a guardrail to prevent administrators from unenforcing the last enforced token set while Secure Enrollment is enabled. |
| 1017704 | Fixes an issue where Egress IP is not updated when steering method is set to None. |
| 996181 | Fixed an issue where the CPU usage displayed in Task Manager exceeded the value reported by Netskope Client on the DEM (Digital Experience Management) dashboard. The issue occurred because Netskope client measures CPU usage for the DEM dashboard using the "Processor Time" performance counter, while Task Manager uses the "Processor Utility" counter. On modern hardware with Intel Turbo Boost or AMD Precision Boost, these counters can report significantly different values for the same workload. |
| 1017061 | Resolved an issue where the Netskope IP Ranges dialog (Settings > Security Cloud Platform > Netskope Client > Enforcement) showed object Object instead of actual IP addresses on the Dedicated IP Ranges tab for Dedicated Egress IP (DEIP) tenants.The dialog now correctly displays each Data Center alongside its IP range in a two-column table, with per-tab Copy support. |
| 140.0.0 | |
| 1097851 | Fixed an issue where the Netskope Client on Windows crashed during On-Premises Detection. The app crashed because two detection processes tried to use the same shared data at the same time without proper coordination. This affected Clients on versions 135.0.0 and 138.0.0, causing temporary loss of traffic visibility and security enforcement until the Client restarted. |
| 1068088 | Fixed an issue on Windows where the Netskope Client reported 0 bytes for inbound and outbound traffic when monitoring AI application connections. This occurred because Windows released the connection data before the Client could read it when the application abruptly closed the connection. The Client now caches byte counts as a fallback. |
| 1064299 | Fixed an issue on macOS where the Netskope Client stayed disabled after upgrading to 138.0.0. The Client failed to read the user certificate because it attempted to access session data before a valid user session was established. A validation check now ensures a valid session exists before reading the certificate. If a valid user session does not exist, then it does not attempt to create a tunnel for that session. |
| 1059302 | Fixed an issue where the Netskope Client lost its user certificate during enrollment when certain certificate files were missing on disk. This caused authentication failures and required a reinstall to recover. The Client now preserves the existing certificate to maintain connectivity. |
| 1053272 | Fixed an issue on Windows where the Netskope Client could enter fail-close after a reboot when a system account signed in before the actual user. This could block traffic until the enrolled user signed in. |
| 1036346 | Improved security for the captive portal pop-up message on Windows. The captive portal dialog now includes protections to prevent misuse by malicious Wi-Fi networks, such as blocking unauthorized downloads, preventing access to developer tools, and automatically closing the window when the network disconnects. Contact Netskope Support to enable the fix for your tenant. |
| 1064301 | Fixed an issue where the Share dialog in Microsoft Office apps had an indefinite loading period for SharePoint users. The Netskope Client now makes the Office Share dialog send its SharePoint traffic through the Netskope tunnel, so SharePoint recognizes it as trusted traffic and the dialog opens as expected. |
| 1053204 | Fixed an issue where devices deployed from the same base image could share identical device IDs, causing incorrect device-to-user mapping in the DEM dashboard. As part of this, you can enable a new configuration option that lets the Netskope Client automatically detects and regenerates duplicate device IDs, ensuring each device is uniquely identified. This option is disabled by default; contact Netskope support to enable it for affected environments. |
| 1070921 | Fixed an issue where Netskope Client (stAgentSvc.exe) crashed intermittently on Windows endpoints during network policy updates, causing complete loss of internet connectivity. The crash was triggered by a race condition in the custom DNS port configuration when a steering policy reload coincided with active network traffic. Users experienced an "Internet Security has an error" message in the system tray and required a manual service restart or endpoint reboot to restore connectivity. This issue has been resolved by adding proper thread synchronization to the DNS steering configuration, preventing heap corruption during concurrent policy updates. |
| 973650 | Fixed an issue where custom application routing through BWAN tunnels stopped working on Linux platform after a tunnel reconnection. Previously, when the BWAN tunnel reconnected, DNS lookups for custom apps configured with domain names could fail, causing traffic to not route correctly. This has been resolved, and custom app routing now recovers seamlessly after tunnel reconnections. |
| 1022611 | Fixed an issue where Microsoft Self-Service Password Reset (SSPR) failed on Windows devices with Netskope Client installed. During a reboot, the Netskope Client incorrectly treated a built-in Windows system account as an active user session, triggering fail-close mode and blocking network traffic before login. This prevented SSPR from reaching Microsoft's servers. The Netskope Client now correctly ignores built-in system accounts during reboot, allowing SSPR to work as expected. |
| 1107289 | Fixed an issue where the Netskope Client upgrade on Windows could fail or hang when Digital Experience Management (DEM) was enabled.Previously, when DEM was enabled, the Netskope Client service took more time to stop during an upgrade, causing the upgrade to fail. This occurred because DEM tasks did not stop promptly when the Client service was shutting down. With this fix, the Client service now shuts down properly and within the expected time, ensuring smooth client upgrades. Note: This is fix is getting back ported to version 138.1.10 and 135.1.22. |
| 140.0.2 | |
| 1117395 | Fixed an issue where Netskope Client AI Discovery did not detect MCP servers and extensions configured in Claude Desktop when installed from the Microsoft Store (MSIX package). The MSIX installer stores the Claude configuration files in an isolated location that the Netskope Client service could not access. This caused the MCP servers and extensions to appear unconfigured. With this fix, the Netskope Client now correctly discovers Claude Desktop's MCP servers and extensions, regardless of the installation method. |
| 141.0.0 | |
| 1086333 | Fixed an issue where Microsoft KM-TEST loopback traffic on Windows was steered by Netskope Client. Previously, the Netskope Client intercepted and steered traffic originating from virtual loopback adapters, such as the Microsoft KM-TEST Loopback Adapter, even when that traffic was configured to bypass Netskope. This affected applications that dynamically assign public IP addresses to a loopback interface, since a static IP-based bypass list wasn't feasible and certificate-pinning bypass didn't apply to browser-generated traffic. With this release, contact Netskope Support to request enablement to bypass Netskope Client steering for this traffic |
| 1105942 | Fixed an issue where the Netskope Client's AI network telemetry retained closed connections in the active session list, causing the list to grow unbounded over time. This resulted in inflated AI connection counts on the dashboard and increased memory usage on the endpoint. |
| 1105355 | Fixed an issue where the Netskope system extension was temporarily deactivated when the Intune MDM platform periodically reapplied the device's configuration profiles, and the Netskope Client (Host App) had no mechanism to detect this deactivation and automatically reactivate it. The Netskope Client now automatically detects this condition, requests reactivation, and restores the tunnel connection without requiring user intervention. |
| 1161458 | Fixed an issue where, after a device woke from sleep or modern standby mode, a communication issue between the Netskope Client UI and its background service caused the UI to incorrectly show the Internet Security tunnel as inactive. This could lead admins or end users to believe protection was off, even though the tunnel remained connected and traffic was still protected. With this release, the UI correctly reflects the Internet Security tunnel status after the device resumes from sleep or standby. Note: This fix is also getting back ported to 138.1.13 and 135.1.24 |
| 1112733 | Fixed the issue where, on Windows, the Netskope Client service sometimes took longer than 30 seconds to fully stop during an upgrade or uninstall, causing the installer to report a false service-stop failure even though the stAgent service was still shutting down normally. With this release, upgrades and uninstalls allow the Client service up to 90 seconds to shut down properly, preventing the false stop failures. Note: This fix is also getting back ported to 138.1.13 and 135.1.24 |
| 702008 | Fixed an issue where device posture was retained after reboot when Antivirus service fails to re-evaluate the device status. Previously, a device with a disabled or crashed Windows Security Center service (WSCSVC) could indefinitely retain a "managed" posture, because the Netskope Client kept relying on a continuously refreshed antivirus cache instead of re-evaluating the device's actual AV status. With this release, Client waits up to one hour after reboot for WSCSVC to start. If the service is still down once that window passes, the Client forces a AV check to re-evaluate the device status and moves the device to "unmanaged" if the check fails. |
| 1185817 | Fixed an issue where Android devices on cellular networks lost connectivity after upgrading to version 140.0.0. After upgrading the Netskope Client to version 140.0.0, Android devices connected to cellular data (IPv6-only networks) experienced service interruptions, including the inability to browse the internet or access applications. This issue did not affect devices connected to IPv4 only or dual stack Wi-Fi and cellular networks. |
| 964844 | Previously, in deployments where an endpoint had both a Machine VPN tunnel and a User VPN tunnel, the Netskope Client could establish its longpoll connection over the Machine VPN interface before the User VPN interface finished initializing after login. As a result, traffic sent over the User VPN interface could inherit a stale IP-to-user mapping, causing one user's traffic to be attributed to a different user and potentially granting access to sites or applications the actual user should not have been able to reach. This issue is fixed in this release. |
| 1021308 | Fixed an issue where a device tag that was actively used in a steering configuration's match criteria could be deleted via the API without any warning or error. This caused the steering rule to silently stop working, potentially routing device traffic to an unintended configuration. Tag deletion via the API is now blocked, ensuring that tags referenced in steering configurations can only be removed through the Netskope UI, which enforces the necessary checks. |
Here is the list of known issues between versions 138.0.0 and 141.0.0.
| Issue Number | Description |
|---|---|
| 138.0.0 | |
| 996181 | Netskope Client measures CPU usage for the DEM dashboard using the "Processor Time" performance counter, while Task Manager uses the "Processor Utility" counter. On modern hardware with Intel Turbo Boost or AMD Precision Boost, these counters can report significantly different values for the same workload. As a result, CPU usage shown in Task Manager can exceed the value reported by the Netskope client on the DEM dashboard. |
| 138.1.0 | |
| 1022611 | After a Windows reboot, such as during self-service password reset, Windows may sign in with the WsiAccount (a system-managed local account created automatically by Windows for the "Web sign-in" feature) before the enrolled user signs in; if Dynamic Steering is disabled, Netskope Client can trigger Fail Close without connecting the tunnel and block all traffic. As a workaround, enable Dynamic Steering to keep traffic flowing until the enrolled user signs in and the tunnel connects. |
| 973650 | In Ubuntu 24.04, FQDN-based custom app traffic via Borderless WAN (BWAN) failed to resolve DNS correctly on Linux devices when the Netskope Client was enabled, causing connectivity issues for custom applications with domain-based routing. As a workaround, disable Netskope Client when using BWAN FQDN-based custom apps, or use an IP-based custom app or rule instead of a domain-based one until an updated client is available. |
| 855973 | During VPN or network changes, Netskope Client may temporarily switch from All Web mode to Cloud Apps Only mode when on-premises detection has not completed, which can interrupt web access. |
| 139.0.0 | |
| 1022611 | After a Windows reboot, such as during self-service password reset, Windows may sign in with the WsiAccount (a system-managed local account created automatically by Windows for the "Web sign-in" feature) before the enrolled user signs in; if Dynamic Steering is disabled, Netskope Client can trigger Fail Close without connecting the tunnel and block all traffic. As a workaround, enable Dynamic Steering to keep traffic flowing until the enrolled user signs in and the tunnel connects. |
| 973650 | In Ubuntu 24.04, FQDN-based custom app traffic via Borderless WAN (BWAN) failed to resolve DNS correctly on Linux devices when the Netskope Client was enabled, causing connectivity issues for custom applications with domain-based routing. As a workaround, disable Netskope Client when using BWAN FQDN-based custom apps, or use an IP-based custom app or rule instead of a domain-based one until an updated client is available. |
| 855973 | During VPN or network changes, Netskope Client may temporarily switch from All Web mode to Cloud Apps Only mode when on-premises detection has not completed, which can interrupt web access. |
| 140.0.0 | |
| 855973 | During VPN or network changes, Netskope Client may temporarily switch from All Web mode to Cloud Apps Only mode when on-premises detection has not completed, which can interrupt web access. |
| 140.1.0 | |
| 1105355 | When an MDM profile reconciliation occurs, the Netskope system extension is temporarily deactivated and needs to be reactivated by the Netskope Client (Host App). The Netskope Client currently has no mechanism to detect this deactivation and automatically reactivate the system extension. As a result, the tunnel cannot be re-established and traffic remains unprotected until the Netskope Client process is restarted. |
| 1071547 | On iOS devices, the Netskope Client may stop fetching configuration updates automatically after the device wakes from sleep. Users may see an "Update Available" message but the Client will not apply it on its own.As a workaround, open the Netskope Client app in your iOS device and manually tap Update Configuration to apply the latest configuration. |
| 141.0.0 | |
| 1071547 | On iOS devices, the Netskope Client may stop fetching configuration updates automatically after the device wakes from sleep. Users may see an "Update Available" message but the Client will not apply it on its own. As a workaround, open the Netskope Client app in your iOS device and manually tap Update Configuration to apply the latest configuration. |

