Major New Features
Smart Scan for S3 and SMB
Large data stores present a fundamental challenge for data security: the sheer volume of files makes comprehensive scanning impractical, leaving security teams with incomplete visibility and risk assessments they can’t fully trust. Netskope One DSPM addresses this with Smart Scan — an intelligent discovery engine that finds more sensitive data, faster, without scanning every file.
Smart Scan uses adaptive, metadata-driven clustering to organize files into groups based on characteristics like file name, file type, folder structure, and size. It then concentrates scanning where sensitive data is actually located, going deeper into high-risk areas and lighter on areas that show no risk. The result is a scan that consistently identifies at least 90% of all Entity Data Types (EDTs) in a data store — while scanning a fraction of the total files.
With Smart Scan, security teams can:
- Get a trustworthy risk picture across massive data stores — covering billions of files without waiting days for results or sacrificing accuracy
- See results as they happen — findings appear in the UI progressively as the scan runs, so teams can begin investigating risk before a scan completes
- Understand full exposure, not just what was scanned — Smart Scan extrapolates a high-confidence estimate of total sensitive file count and data size across the entire data store, giving a complete view of risk magnitude
- Rely on accuracy for small data stores — data stores with 10,000 files or fewer are always scanned in full automatically
Smart Scan is the default scanning mode for all new DSPM scans. In this release, Smart Scan is available for AWS S3 (IaaS) and SMB File Shares (On-Premises), with support for additional data store types planned in a future release.
Smart Scan for SaaS
For SaaS applications, identifying which files pose real risk has always been a challenge — with thousands of files across Google Drive, SharePoint, OneDrive, Box, and Dropbox, not all files are equal in terms of risk. Netskope One DSPM now applies Smart Scan to SaaS data stores, ensuring the files surfaced in DSPM are always the ones that matter most.
Rather than surfacing an arbitrary selection of files, Smart Scan for SaaS prioritizes files that contain sensitive data — those that have triggered a DLP match for content such as PII, financial data, credentials, or other policy-matched data types. These files are guaranteed to appear in DSPM first, giving security teams immediate visibility into their highest-risk content across SaaS applications.
Improvements and Updates
Domain User Authentication for SQL Server
SQL Server data stores now support Domain User authentication, allowing organizations that manage SQL Server access via Active Directory to connect their data stores to DSPM without requiring SQL-native authentication credentials.
Microsoft Teams Webhook: Updated Format Support
DSPM webhook validation has been updated to support the new Microsoft Teams webhook format. Organizations using Teams for DSPM alert notifications will continue to receive alerts without requiring changes to their existing webhook configuration.
S3 Inventory Configuration Toggle
Users can now enable or disable the S3 Inventory configuration directly from the Add/Edit Data Store workflow for S3 buckets. This provides finer control over how DSPM collects file metadata for large S3 data stores, allowing teams to optimize scan performance based on their environment and bucket configuration.
“Preparing Metadata” Scan Stage
During Smart Scan, the Data Store Inventory page now displays a “Preparing Metadata” scan stage while the clustering algorithm is processing file metadata prior to sampling. This gives users clear visibility into scan progress and reduces confusion when a scan appears to be in a holding state before results begin appearing.

