Published on: October 16, 2025
We are excited to announce our Netskope One Private Access release updates! Find the latest features, issues fixed, and other updates in this release for Netskope One Private Access below.
Release Highlights
These are the highlights for this release:
Private Access Cloud
-
Private Applications across multiple Netskope tenants for macOS.
Publisher
-
Dynamic Reconnection Based on Relative Latency
-
Browser Access AnyApp RDP/SSH Enhancements.
Local Broker
-
Support pre-built Ubuntu 22.04 VM Hyper-V image for Local Brokers. Learn more.
Private Access Cloud Release Notes
Here are the latest updates with the Netskope Private Access UI.
New Features and Enhancements
Private Applications Across Multiple Netskope Tenants for macOS
Users can now access Private Applications across multiple Netskope tenants, such as from a managed service provider, partner or third-party organizations, without needing to unenroll or uninstall the Netskope Client for up to 20 different tenants. With a simple switch in the Client UI, users can toggle between their primary and partner tenants in one click.
Key Capabilities:
-
Multi-Tenant Access: Seamlessly switch between partner organizations to access authorized private resources.
-
Client UI Enhancements: View current tenant details and a submenu listing all available partner tenants.
-
No Reinstallation Required: Eliminates the need to unenroll/reinstall the Netskope Client when switching tenants.
Use Case Example: Ideal for users working with suppliers, contractors, or joint ventures that also utilize Netskope, ensuring secure access to partner-hosted private applications without disruption.
Supported OS: macoS, Windows (supported from 125.0.0)
Supported minimum Client version: 125.0.0 (Windows), 131.0.0 (macOS)
Dynamic Reconnection Based on Relative Latency
The Publisher will now periodically re-evaluate its connection to find the best-performing Point of Presence (PoP). This intelligent, dynamic reconnection ensures your system consistently uses the fastest and most reliable path available, improving overall performance and resilience against network degradation. This feature can be enabled in the Publisher Wizard.
Supported minimum Publisher version: 131.0.0
Fixed Issues
| Issue Number | Description |
|---|---|
| 722716 | When cloning a Client configuration, Prelogon settings will be reset (Prelogon checkbox will be unchecked). |
| 722908 | Resolved a network routing issue that affected private application connections in environments with multiple local brokers. Some connections were incorrectly routed during failover scenarios, resulting in intermittent connection failures and sessions with no data transfer. This fix ensures consistent connectivity to private applications in multi-broker environments, improving reliability particularly during automatic failover events. |
| 733159 | When the Publisher Name contains characters like ‘#’, the Create App action for Discovered Apps in SkopeIT > Private Apps fails. Reserved characters such as ‘#’ were not encoded, causing them to be removed from the URL when fetching Publisher details. The fix encodes special characters like ‘#’ in the request. |
| 733552 | Resolved an issue where stale policies could be incorrectly applied to traffic after their parent policy group was deleted. In certain cases, private application policies created through our API were incorrectly processed for DLP traffic due to structural discrepancies. The fix ensures proper policy classification and prevents deleted or orphaned policies from affecting traffic evaluation, resulting in more accurate and predictable policy enforcement. |
| 746325 | Resolved an issue in China support-enabled tenants where NPA certificates stored incorrectly caused NPA gateway tunnel establishment to fail due to certificate verification errors. |
Known Issues
| Issue Number | Description |
|---|---|
| 731748 | The Toggle button for the Status is currently broken due to regression. Until it’s fixed, customers are advised to click on the pencil icon and toggle the status from the Edit Publisher Update Profile panel. |
Publisher Release Notes
Here are the latest updates with the Netskope Private Access Publisher.
New Features and Enhancements
Updated Kernel Versions
| Platform | Kernal Version |
|---|---|
| OVA VHDX AMI VHD | 5.15.0-156-generic 6.8.0-1034-azure 6.5.0-1024-aws 6.8.0-1034-azure |
SHA Hash for Publisher Images
| Image Type | SHA256 |
|---|---|
| OVA | 0e3f56467ec03cf4d494c82a143e0bec191bbf3245813e2ba66c17782498cc9d |
| VHDX | a23f1dd417e95743ead97ab6d5dd7ac76be72b4f2873a96c1a98cdec63bfeded |
OVA/VHDX Hosting on the Alicloud
OVA hosting on the AliCloud: https://npa-ova.oss-cn-shenzhen.aliyuncs.com/latest/NetskopePrivateAccessPublisher.ova
VHDX hosting on the AliCloud: https://npa-ova.oss-cn-shenzhen.aliyuncs.com/latest/NetskopePrivateAccessPublisher.vhdx
Browser Access AnyApp RDP/SSH Enhancements
- Enhanced RDP authentication: AnyApp RDP now defaults to Any as the authentication method. This expands RDP authentication to support Active Directory domain integration and improves handling, ensuring more reliable connections for organizations using AD domain.
- Clipboard controls: Clipboard controls for RDP and SSH sessions allow precise management of data transfer between local and remote sessions. Organizations can configure clipboard access with these options:
- Full clipboard access (copy and paste)
- No clipboard access (block copy and paste).
Existing BA AnyApp tenants keep their current clipboard settings (disabled by default). New tenants have full clipboard enabled by default. To change this, contact Netskope support.
- Non-English keyboard support: Remote sessions now support multiple keyboard layouts in RDP sessions, letting international users keep their preferred configurations. This ensures consistent typing between local and remote environments worldwide. Notice that the local and remote must use the same keyboard language.
- Improved user interface: The RDP experience with Browser Access (BA) AnyApp features a more intuitive interface with clearer login instructions, visible session information (including Private App name and user details), and improved navigation and scrolling.
Improved Troubleshooter mTLS Check to Stitcher
Enhanced the troubleshooting process for mTLS checks related to the stitcher component.
Configure Daily Time Window when the Auto-reconnect is Active
Introduced a feature to configure a daily time window for auto-reconnect functionality. Users can now set specific times for when the auto-reconnect will be active.
Fixed Issues
| Issue Number | Description |
|---|---|
| 728329 | This fix resolves connection failures in GSLB fallback blocks after GSLB resolution, enhancing reliability for Clients and Publishers. |
Local Broker Release Notes
Here are the latest updates with the Netskope Private Access Local Broker.
New Features and Enhancements
Support pre-built Ubuntu 22.04 VM image for Hyper-V
NPA Local Broker now supports a pre-built Ubuntu 22.04 image in Hyper-V (VHDX) format

