The article provides guidance for customers currently using the Classic API Data Protection for GitHub. It outlines a clear process for migrating to the enhanced Next Generation API Data Protection, which offers improved performance and functionality. The migration involves key steps, including preparation, configuration updates, and verification, ensuring a smooth transition to the more advanced platform.
GitHub Integration on Non-Enterprise Editions
In the Classic platform, Netskope offered API-based integration with GitHub non-enterprise editions. With the Next Generation platform, GitHub integration requires the enterprise cloud edition.
Customers on the following editions will no longer be able to use API-based integration after migrating.
-
GitHub Free for user accounts
-
GitHub Pro
-
GitHub Free for organizations
-
GitHub Team
What You Need to Do?
-
Already on enterprise cloud edition? If your organization is already subscribed to the enterprise cloud edition and has our Next Generation API integration deployed, no action is required.
-
Planning to upgrade? If you are considering or in the process of upgrading to the enterprise cloud edition, please work with the GitHub account team. Once your license is upgraded, you can proceed and follow the migration steps for GitHub.
-
Not on enterprise cloud edition? If you are not on enterprise cloud edition today, review your GitHub licensing strategy before migrating to ensure continued API integration support. The Next Generation API Data Protection integration for GitHub is exclusive to the enterprise cloud edition.
Migration Steps
Here are the broad steps to migrate your classic GitHub instance to Next Generation.
-
Create a new Next Generation API Data Protection GitHub instance. To learn more: see sample video.
-
Disable the existing classic API Data Protection policies from Policies > API Data Protection > SAAS > Classic.

-
Create new policies on Next Generation API Data Protection from Policies > API Data Protection > SAAS > Next Gen. To learn more: see sample video.
-
Delete the existing classic API Data Protection policies from Policies > API Data Protection > SAAS > Classic.
Running Classic and Next Generation policies simultaneously can lead to unexpected behavior if legal hold or quarantine profiles exist on both platforms. Additionally, this setup risks upstream throttling due to rate limits, potentially interrupting all protections. Therefore, Netskope strongly discourages running Classic and Next Generation policies and legal hold/quarantine profiles concurrently. -
Go to Settings > Configure App Access > Classic. Select the GitHub app, click the instance and uncheck CASB API.

-
Delete the classic GitHub instance. To do so, navigate to Settings > Configure App Access > Classic, select the GitHub app, then click the Remove Instance icon to delete the app instance.

To learn more about the Next Generation API Data Protection feature matrix per cloud app, see Next Generation API Data Protection Feature Matrix per Cloud App.

