Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Enterprise Browser
    Enterprise Browser FAQs
    Microsoft Entra Set Up for Enterprise Browser

    Microsoft Entra Set Up for Enterprise Browser

    This article describes the steps to integrate Enterprise Browser authentication with Microsoft Entra. The overview flow is outlined below:

    1. Add the Netskope application in Microsoft
    2. Assign users or groups to the Netskope application
    3. Configure SAML in Microsoft Entra
      • 3a- Set the Subject NameID in the SAML Configuration
    4. Download the Microsoft SAML certificate
    5. Configure SAML proxy in Netskope
    6. Update the SAML Identity and ACS URL
    7. Test your SSO set up

    Add the Netskope Application in Microsoft

    Log in to your Microsoft account and navigate to Identity > Applications > Enterprise Applications > click New Application.

    In the Search Application bar, type Netskope User Authentication and click Create.

    Assign Users or Groups to the Netskope Application

    Navigate to Identity > Applications > Enterprise Applications > Netskope User Authentication.

    Click Assign users and groups.

    Select Add user/group.

    Click None Selected.

    Type the name of the group or user you want to assign to this app.

    Check the group/user name, and click Select.

    Click Assign.

    Configure SAML in Microsoft Entra

    Navigate to Identity > Enterprise applications > Netskope User Authentication.

    Click Single sign-on.

    Set the Subject NameID in the SAML Configuration

    There are several steps to this set up. Navigate to Attributes and Claims. Delete all default additional claims.

    Netskope RTP and Enterprise Browser Protection policies are applied based on user email address. Therefore it’s important that the Unique Name Identifier claim references the user.email field.

    This configuration still allows you to chose a different field name for sign on. Only change the Subject.NameID value that is being transmitted from EntraID to Netskope.

    Select the value to edit the Unique User Identifier (Name ID) field.

    Set the Source attribute to user.mail and click Save. This assigns user.mail as the claim value for Name ID. Click the x to close this section.

    Download the Microsoft SAML Certificate

    Download the certificate in Base64 format, and copy the Log in URL and Azure AD Identifier values. Save these values and enter these values in the Netskope Forward Proxy SAML settings page later.

    Configure SAML Proxy in Netskope

    Log in to Netskope and navigate to Settings > Security Cloud Platform > Forward Proxy > SAML.

    Click New Account.

    In New Account window configure the following options:
    1. Name: Choose a descriptive SSO name. It is possible to create several SSO entries in web UI.
    2. Access Method: check Enterprise Browser.
    3. IDP SSO URL: paste the URL you copied from Microsoft Entra → Identity → Applications → Enterprise applications → Netskope User Authentication → Single Sign-On → Set up Netskope User Authentication.

    4. IDP Entity ID: paste the ID you copied from Microsoft Entra → Identity → Applications → Enterprise applications → Netskope User Authentication → Single Sign-On → Set up Netskope User Authentication.
    5. IDP Certificate: Upload the Base-64 certificate that you downloaded from Microsoft Entra.

    After configuring these parameters, scroll down in the window to enable SSO.

    Update the SAML Identity and ACS URL

    After creating the SAML account in Netskope, copy the SAML Entity ID and SAML Proxy ACS URL. Save these URLs to paste them in your Microsoft Entra SSO configuration.

    Navigate to Settings > Security Cloud Platform > Forward Proxy > SAML > click Netskope Settings.

    Copy the SAML Entity ID and SAML Proxy ACS URLs.

    Navigate back to Microsoft Entra > Identity > Applications > Enterprise applications > Netskope User Authentication > Single Sign-On > Basic SAML Configuration.

    Click Edit and paste the Netskope SAML Entity ID and Netskope SAML Proxy ACS URLs.

    The SAML configuration is complete. Sign in to Netskope and configure the bypass list. The following domains need to be explicitly bypassed for Microsoft Entra SSO authentication.

    browser.events.data.microsoft.com
    autologon.microsoftazuread-sso.com
    autologon.microsoft-sso.com
    login.live.com
    login.microsoftonline.com
    login.microsoft.com
    aadcdn.msftauth.net
    aadcdn.msauth.net
    aadcdn.msftauthimages.net
    device.login.microsoftonline.com
    mysignins.microsoft.com
    nsauth-<tenant-name>.goskope.com

    SSO Testing

    To test your SSO configuration, log in to Netskope and navigate to Settings > Security Cloud Platform > Forward Proxy. Click the ellipsis … at the end of your SAML account entry and click Test.

    You will see a message similar to the following if your set up is successful.

    In this Topic
    • Microsoft Entra Set Up for Enterprise Browser