-
Install the DLP on Demand appliance. For the detailed installation steps, see /en/dlpondemandconfig.
-
After the DLP on Demand appliance is successfully installed, access the Netskope AI Gateway Configuration Wizard using the CLI interface.
-
In the Netskope AI Gateway Configuration Wizard, select Configure Content Inspection Services.
-
In the Configure Content Inspection Services page, select Data Loss Prevention Service.

-
Data Loss Prevention Service page allows you to select any of the three options:
- Configure DLP Service Certificate <link>
- Configure DLP Service Host<link>
- Delete DLP Service Host Configuration<link>
Ensure you configure the DLP Service Certificate first.
Configure the DLP Service Certificate
-
In the Data Loss Prevention Service page, select Configure DLP Service Certificate.
-
In the Configure DLP Service Certificate page, copy the certificate from the DLPoD appliance and paste the Enter new certificate prompt. This is the certificate that is installed on the DLPoD appliance. For more details on certificate configuration DLPoD, see, /en/replacing-the-self-signed-certificate-on-your-appliance.
Ensure you copy the certificate within the header “—–BEGIN CERTIFICATE—–” and the footer “—–END CERTIFICATE—–”.
-
Press Enter to submit the certificate.
When the certificate is valid, the system displays the certificate details. If validation fails, press R to retry the configuration.
Configure the DLP Service Host
After successful installation of the DLP Service certificate, follow the steps below to configure the DLP service host.
-
In the Data Loss Prevention Service page, select Configure DLP Service Host.
-
In the Configure DLP Service Host page, under Enter new Host URL prompt, enter your DLP backend URL (for example:https://dlp.company.internal).

-
Press Enter to save the DLP service host.
This saved DLP service host facilitates the internal DLP integration.
Delete DLP Service Host Configuration
At any point of time if you wish to remove or reset the DLP host configuration, follow the steps below:
-
In the Data Loss Prevention Service page, select Delete DLP Service Host Configuration.
-
In the Delete host configuration page, Press y to confirm the deletion and n to cancel it.
Once the certificate is successfully installed and the host configurations is complete, the Netskope AIG facilitates the following automated workflow:
- The Netskope AIG validates the DLP backend using the stored certificate.
- The Netskope AIG directs DLP inspection requests to the configured host URL.
- Internal DLP integration transitions to an active and enabled state.

