Major New Features
DSPM Privilege Analysis for SMB On-Premises File Shares
Netskope One DSPM now extends privilege analysis to on-premises SMB file shares, addressing a critical blind spot in modern data security. Due to decades of organic growth and the complexity of nested folder structures and Active Directory groups, security teams have historically been unable to determine who has access to what on SMB shares. This release closes that gap with deep visibility into effective access, risky permissions, and identity-based exposure.
With SMB Privilege Analysis, security teams can:
- Detect sensitive files exposed org-wide via broad groups such as Everyone or Domain Users
- Identify ghost accounts — unresolved SIDs and disabled users — that retain access to sensitive files
- Surface high-risk users holding excessive access to sensitive data
- Detect broken inheritance at the folder level where a subfolder has been inadvertently opened up despite a secure parent tree
- Resolve nested group membership up to 5 levels deep and folder hierarchies up to 20 levels, providing accurate effective access mapping
Privilege Analysis is enabled by default when onboarding a new SMB data store and requires an LDAP connection to map permissions to human identities. For existing SMB shares, users can enable the toggle via Edit Data Store settings. The feature contributes a new Data Risk score and Stale User Risk Over-Privileged Data Store Risk rating to the overall data store risk rating, reinforcing Netskope’s leadership in on-premises data security.
Improvements and Updates
Ability to select profiles used to fetch unstructured snippets
Users can now select which DLP Profiles should be used when fetching snippets for unstructured files. By giving users control over which specific DLP profiles are applied vs. using all profiles currently-enabled in the DSPM Discovery Profile, this reduces the time required to fetch snippets and allows for ad-hoc re-inspection of existing sensitive files.

