Netskope Client provides various hardening options to ensure its smooth operation. This document provides insights into the hardening features of the Netskope Client installed on Windows and macOS devices. To learn the supported versions, view Supported OS and Platforms.
By using the Client hardening options, you can prevent users with elevated permissions from altering Client files and services and ensure that the full functionality of security features Netskope offers is available to you.
The Netskope Client installs on end user devices as a non-intrusive application that facilitates a seamless user experience and steers configured end user traffic to Netskope Cloud. By design, the Netskope Client establishes a tunnel to Netskope Cloud by choosing the nearest POP (data center). This ensures the following:
-
Configured traffic from the Client is steered via an optimal path to connect to Netskope POP.
-
The complete benefits of Netskope security services are available to the customers.
Depending on an organization’s IT policy, end users may or may not have administrative rights on their respective system. An end user with administrative privileges has access and controls to alter the default configuration of the Client and its services installed on their devices. This can affect the normal functioning of the Netskope Client and may be detrimental to the organizations’ security policies.
Netskope Client Hardening Options
You can use the following hardening options to ensure the Netskope Client operates smoothly on end user devices running Windows and macOS:
- Tamperproofing
- Configuration Encryption
- Protect Client configuration and resources
Tamperproofing Netskope Client
The Client configuration includes the following tamperproof options.
-
Disable or enable Client.
-
Password protection to prevent unauthorized uninstallation of the Client.
-
Block all traffic if the Client tunnel is not established.
To learn more, view Tamperproof.
Client Configuration Encryption
The Client configuration files generated in the admin configuration and downloaded by the client can be encrypted. To learn more, view Client Configuration.
Protect Client Configuration And Resources
When you enable this option, it prevents users with elevated permissions from altering any sub-part (files, folders, and process) of the Netskope Client installation. It prevents users from modifying, renaming, or deleting Netskope processes, folders, files, and registry keys. To learn more, view Protect Client Configuration and resources.

