Major New Features
New On-Prem Deployment Option for DSPM Sidecars
To benefit customers who prefer the ability to manage sidecars as virtual machines instead of containers, DSPM sidecars are now packaged in the Open Virtualization Archive (OVA) format for deployment in compatible VMWare VSphere hypervisors.
Improvements and Updates
AWS Infrastructure Onboarding Improvements
To reduce friction when onboarding infrastructure, the following changes have been made starting with the Add AWS Infrastructure Connection flow (both for adding accounts and organizations)
The following changes were made to the CloudFormation template and Terraform scripts:
- The CloudFormation template and Terraform scripts have been reorganized to better-group permissions by the in-application capability they control. This way, if you wish to not provide the DSPM application with permission to any specific capability, it is easy to select & remove the relevant permissions without affecting the others
- In addition, the CloudFormation template and Terraform scripts have been documented inline to explain each permission grouping, so it is clear why Netskope is requesting the permissions
- Our online documentation has been updated to reflect the same reorganization and documentation of permissions. So if you choose not to grant Netskope access for a capability today but change your mind in the future, we now provide clear, easy instructions on how to add back the missing permissions to your CloudFormation or Terraform stacks
Within the application itself, changes were made to the Add Infrastructure Connection UI:
- Cleared explanations are now available on the Capabilities tab, so you understand which each toggle does. Where supporting documentation is available, links are now shown to relevant articles on docs.netskope.com.
- When you finalize & submit your Infrastructure Connection request, the UI will check your service account’s health and provide feedback if any expected permissions are missing
SMB Connection Improvements
Previously, only IPv4 addresses were acceptable as endpoint values for SMB connections. Now you DSPM will accept public hostnames for the endpoint (for example, example.us-west-2.compute.amazonaws.com).
In addition, special character support has been added for SMB file share / mount names. The following valid characters can now be used: ! @ # $ % & ' _ - . ~ ( ) { }

