BeyondCorp Plugin for User Risk Exchange

BeyondCorp Plugin for User Risk Exchange

This document explains how to configure the BeyondCorp integration with the User Risk Exchange module of the Netskope Cloud Exchange platform.


To complete this configuration, you need:


  1. Obtain your BeyondCorp customer ID.
  2. Enable the Netskope Partner.
  3. Configure your service account
  4. Configure the BeyondCorp plugin.
  5. Configure User Risk Exchange Business Rules for the BeyondCorp plugin.
  6. Configure User Risk Exchange Actions for the BeyondCorp plugin.
  7. Validate the BeyondCorp plugin.

Click play to watch these videos.

Plugin Configuration
Plugin Demo

Get your Customer ID

  1. Log in to
  2. Go to Accounts > Account Settings (
  3. Copy your Customer ID.

Enable the Netskope Partner

  1. Log in to
  2. Go to Devices > Mobile & Endpoints > Settings > Third-party integrations (
  3. Click Security and MDM partners.
  4. Click Manage.
  5. Click Open Connection next to Netskope.
  6. The list should look like this:
  7. Click the close button (X) and enable the Netskope Partner.
  8. Click Save.

Configure your Service Account

  1. Log in to
  2. Go to Security > Access and data control > API Controls (
  3. Click Manage Domain Wide Delegation (
  4. Click Add New.
  5. Enter these values:
    • Client ID: Client ID from your Service Account JSON file.
    • OAuth scopes (comma-delimited):
  6. Click Authorize.

Configure the BeyondCorp Plugin

  1. In Cloud Exchange, go to Settings > Plugins.
  2. Search for and select the BeyondCorp plugin box.
  3. Enter a configuration name.
  4. For Sync Interval, leave the default.
  5. For Use System Proxy, enable this if a proxy is required for communication.
  6. Click Next.
  7. Enter your BeyondCorp Customer ID. Make sure that the Customer Id does not start with the letter “C”.
  8. Enter the email address of the user with administrator privileges.
  9. Enter the contents of the BeyondCorp Service Account JSON file.
  10. Click Save.

Configure Business Rules for the BeyondCorp Plugin

The business rules are to determine which information is used in the actions.

  1. Go to User Risk Exchange and click Business Rules.
  2. Click Create New Rule and enter a rule name.
  3. From the dropdowns, select a field, an operator, and a value. For example: Aggregate Score Grouping – Any in – medium.
  4. Click Save.

Configure Actions for the BeyondCorp Plugin

The actions are used with the business rules are to determine which information is used.

  1. Go to User Risk Exchange and click Actions.
  2. Click Add Action Configuration.
  3. Click the Business rule dropdown list and choose the appropriate Business rule.
  4. Select the Configuration dropdown list and choose BeyondCorp.
  5. Select Actions from the dropdown list and choose (Add to Group, Remove to Group or No Action).
    • Add to Group: When triggered, users are added to that group.
    • Remove to Group: When triggered, users are removed from that group.
    • No Action: This does not perform any actions on users.
  6. Click Save.

Validate the BeyondCorp Plugin

Validate in Cloud Exchange

When a user matches one of the configured business rules, the configured action would be performed on the user. In User Risk Exchange, go to Action Logs.


Validate in BeyondCorp

  1. In BeyondCorp, go to Devices > Mobile & endpoints > Devices (
  2. Click on one of the devices.
  3. Click Third-party services.
  4. The Compliance State, Health Score, and Netskope User Risk Scores can be seen on this page.
Share this Doc

BeyondCorp Plugin for User Risk Exchange

Or copy link

In this topic ...