Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Netskope Client
    Netskope Client Deployment Options
    Netskope Client Enrollment
    Netskope Client Enrollment Using Email Invite

    Netskope Client Enrollment Using Email Invite

    The admin console sends email invitations to install the Netskope Client. The user can click the link in the email they received to download and install the Client (or the mobile profile) on their device.

     If you use the email invite option for iOS devices, ensure you follow the steps defined here to trust manually installed certificates. Email invites are time-bound and the intended user can use them.

    Supported OS

    Email enrollment is available for user enrollment of the Netskope Client installed in the following  end-user environments:

    • Windows
    • macOS
    • Linux
    • Android
    • iOS
    For iOS devices running versions after 12.1.3, Apple has changed how profile installations work. Apple has restricted automatic installation of profiles, that now requires additional steps. In such cases, for a new profile, end users must manually navigate to device settings to install the profile after clicking on the link in the email and downloading the profile. Netskope recommends updating the email invitation template to call the users’ attention to this important step. This change does not impact MDM-based configuration profile installation.
    – Reference: https://support.apple.com/en-us/HT209435
    – To enroll in the iOS beta program and try this experience, view https://appleseed.apple.com/

    Prerequisites

    • Import a user with a valid and accessible email into the tenant. To learn more, view Prerequisites to deploy Client through Email Invite.

    • Set up the user  account on the tenant before sending out the email invite. To learn more, view Provisioning Users for Netskope Client.

    • Installation of client requires administrator rights on the end-user devices.

    Advantages

    • The admin need not share any user authentication parameters for enrollment.

    • Send Email Invites for corporate and personal Email IDs.

    • Quick way to deploy for BYOD users.

    Disadvantages

    • The user requires admin rights to install the Client software.

    • Misuse of the Email by forwarding it to the unintended recipients.

    • Download installation package name contains the org key and the activation key (not secure).

    Netskope Client Deployment Using Email Invite

    The following sections describe how to deploy Netskope Client using email invite in different operating systems:

    Windows
    macOS
    Linux
    iOS
    Android and Chrome OS

    Create Email Invite for New Users

    Perform the following instructions in your (administrator account required) Netskope admin console to create the email invite:

    An email invite is single use and the invite is valid for seven days only, whichever happens first.
    1. Go to Settings > Security Cloud Platform > Netskope Client > Users.

    2. Click New Users.

    3. Enter the following in the New Users pop-up window:

      1. In User email address, enter comma separated email address if adding more than one user.

        In addition, to add bulk users you can upload a CSV file with the email address of all users. The CSV file entries must have this format: email, lastname, firstname. Last name and First name are optional.

      2. Select the Send email invite checkbox.

      3. Select one of the following in Client Version Options (Windows):

        • 64 bit

        • 32 bit

    4. Click Add.

    Create Email Invite for Existing Users

    Perform the following instructions in your (administrator account required) Netskope admin console to send email invite to an existing user:

    1. Go to Settings > Security Cloud Platform > Netskope Client > Users.

    2. Select the user (s) on the Users webUI.

    3. Click Send Invitation.

    4. In Send Client Invites, if you are using Windows OS, select one of the following in Client Version options (Windows):

      • 64 bit version

      • 32 bit version

    5. Click Send.

      The webUI displays Invite Successfully Sent confirmation box.

    Install Netskope Client Through Email Invite

    You can install Netskope Client using an email invitation sent from the Netskope Admin console.

    Email invites are time-bound and only the intended user can use them.

    After you receive the email:

    1. Check your email from Netskope Onboarding and click the link for Windows. 

    2. If you selected 64 bit Windows Client version in the Netskope tenant webUI, select Windows Client (64-bit) in the email. The email that you receive can contain a similar format as shown in the following screenshot.

    3. If you selected 32 bit Windows Client version in the Netskope tenant webUI, select Windows Client in the email. The email that you receive can contain a similar format as shown in the following screenshot.

    4. Click Download. 

      This downloads to your default location.

    5. Click the installer file.

    6. Follow the steps as displayed in the Install Netskope Client window.

    7. Once the installation is complete, you can see the Netskope Client running on your taskbar.

    All new installations that use the email invitation feature require the end user to approve the kernel extension. Users will see a message that guides them through the steps to grant approval.

    Note

    The system behavior presents the approval dialog in the Security > Privacy preferences pane for 30 minutes after the above alert is generated. No traffic is tunneled to Netskope unless this approval is granted if the client is installed manually via the email invitation method.

    Before you do a fresh installation of Netskope Client on macOS, do the following:

    1. Install Netskope Client as an admin user (A non-admin cannot approve KEXT).
    2. When the system blocks  KEXT during installation, users must approve the KEXT from System Preferences > Security > Privacy. In a few minutes, the Client will detect the approved KEXT.

    Create Email Invite For New Users

    Perform the following instructions in your (administrator account required) Netskope admin console to create the email invite:

    An email invite is single use and the invite is valid for 7 days only, whichever happens first.
    1. Go to Settings > Security Cloud Platform > Netskope Client > Users.

    2. Click New Users and enter the following in the New Users pop-up window:

      • User email address. Enter comma separated email address if adding more than one user.
        In addition, to add bulk users you can upload a CSV file with the email address of all users. The CSV file entries must have this format: email, lastname, firstname. Last name and First name are optional.

      • Select the Send email invite checkbox.

    3. Click Add.

    Create Email Invite For Existing Users

    Perform the following instructions in your (administrator account required) Netskope admin console to send email invite to an existing user:

    1. Go to Settings > Security Cloud Platform > Netskope Client > Users.

    2. Select the user (s) on the Users webUI.

    3. Click Send Invitation.

      The webUI displays a Send Client Invite confirmation box.

    4. Click Send.

    Install Netskope Client Through Email Invite

    You can install Netskope Client using an email invitation sent from the Netskope Admin console.

    Email invites are time-bound and only the intended user can use them.

    After you receive the email:

    1. Check your email from Netskope Onboarding and click the link for Mac Client.

    2. Click Download. This downloads to your default location.

    3. Click the installer file.

    4. Follow the steps as displayed in the Install Netskope Client window.

    5. Once the installation is complete, you can see the Netskope Client running on your taskbar.

    To learn more about the installation process for Netskope Client for Linux using Email ID, view Install and Enroll by Email ID. 

    Deployments through an email invite is a two step process:

    • iOS Profile link: This installs tenant certificates on the device. They are necessary for SSL Decrypt related functionality. This profile contains only certificates.
    • iOS Client link: Helps to find the Client in the App Store and enroll it after installation.
    – iOS Client in the email is a one time installation only link. You will receive an error message Email Invitation Expired the second time you attempt to use the link after installing Netskope Client.
    – If you are unable to see the link to download Netskope Client for iOS in the email invite, use the default email template that includes the link to download Netskope Client for iOS. 

    After you receive the email:

    1. Check your email from Netskope Onboarding and click iOS Profile to install the profile with certificates to your iOS device.
      iOSClient_EmailInvite_102.png
    2. Click Allow for the pop-up This website is trying to download a configuration profile. Do you want to allow this?
      iOS_AllowConfigs_102.png
    3. Close the pop-up after the profile is downloaded.
    4. In your iOS device, go to Settings app > General and tap Profile Downloaded. The profile consists of the root and tenant certificates.
      iOS_InstallProfile_102.png
    5. Tap Install in the upper-right corner. Follow the installation instructions displayed on the screen.
    6. Go to Settings > General > About > Certificate Trust Settings.
    7. Tap to enable the option Enable Full Trust to Root Certificates.
      iOS_CertTrustSettings_102.png
    8. Click Continue to close the warning.
    9. Click the iOS Client link in the email invite.
      iOS_Emailinvite_102.png
    10. This opens a page with two links and perform the following steps:
      iOS_InstallClientApp_102.png
      1. Click Install to download Netskope Client from Apple Store to iOS devices. Perform the following instructions:
        1. Click Allow to add VPN configurations.
          iOS_AllowVPNConfigs_102.png
        2. Wait for the Client enrollment.
      2. Click Download iOS configurations to complete the enrollment process.
      3. Follow the enrollment steps as displayed on your screen.
        iOS_Enrollmentprocess_102.png
    11. After completing the enrollment steps, go to VPN & Device Management.
    12. Check whether VPN displays the Connected status to ensure the successful installation of the iOS configuration profile.
      iOS_VerifyVPNConnected_102.png

    You can install Netskope Client using the email invitation sent from the admin console.

    After you receive the email:

    1. Check your email from Netskope Onboarding and click Android Client.

    2. Follow the instructions on your screens to install Netskope Client from Google Play Store.

    3. Click Install.

    4. After you install, Click Open.

    5. Click Allow for notifications.

    6. The app opens after it completes downloading the configurations.

      Support for Chromebook

      To install Netskope client in Chromebook, use the following procedure to install the Netskope root CA cert in Chrome OS cert store.

      Ensure that you have purchased additional Chromebook management licence for the Google admin account.
      Cert pinned app domains are bypassed in Netskope Android App

      Enroll Chromebook to Google Managed Account

      1. Power on the Chromebook and follow the on-screen instructions until you see the sign-in screen. Don’t sign in yet. If you see the enrollment screen instead of the sign-in screen, go to step 4.
      2. If you’re enrolling a Chromebook tablet, tap Email or phone. Then, tap the More option (three vertical dots).
      3. Switch to full layout to open the on-screen keyboard.
      4. Choose an option to get to the enrollment screen:
        1. Press Ctrl+Alt+E.
        2. Click More options  > Enterprise enrollment 

        Note

        This option is not available on Chromebook tablets.

      5. Enter the username and password from your Google admin welcome letter or for a Google Account that has the permissions to enroll. If prompted, enter the asset ID and location and click Next.
      6. When you get a confirmation message that the device is successfully enrolled, click Done.

    Configure Google Admin Account

    1. Sign in to your Google admin account console.
    2. Click Device Management.
    3. On the left, click Network and click Certificates.
    4. [Optional] On the left, choose the organizational unit to add the certificate.

      Note

      The top-level organization is selected by default to give all users (including those in sub-organizations) access to any added certificates.

    5. Click Add Certificate. Choose the certificate file to upload and click Open.
    6. [Optional] If the certificate is used as a root CA for an SSL-inspecting web filter or to allow the browser to validate the full digital certificate chain of servers, check the Use this certificate as an HTTPS certificate authority box.
    7. Click Save and then Done to confirm.

    Deploy the Certificate to Chrome Devices

    Enroll the Chromebook to the organization’s Google account. Chrome devices will authenticate to Google and receive the SSL certificate. The pushed certificate applies to all enrolled Chrome devices.

    The admin sends an invitation email to the Chromebook user and the user must click the Android app link to install the Android app in Chromebook.

    ChromeOS devices use the same Netskope Client app as Android devices.

    In this Topic
    • Netskope Client Enrollment Using Email Invite