Partner Access allows users to access Private Applications across multiple Netskope tenants (such as Managed Service Providers, partners, third-party organizations, or multi-tenant organizations) without needing to unenroll or uninstall the Netskope Client, or leveraging clientless access through a browser.
A Partner Tenant is defined as the external tenant from which a end-user might be able to connect to. Users can seamlessly switch between their Primary Tenant and authorized Partner Tenants via the Netskope Client UI.
Key Benefits
- Multi-tenant access: Seamlessly switch between partner organizations to access authorized private resources.
- No re-installation required: Eliminates the need to unenroll/reinstall the Netskope Client when switching tenants.
- Unified Security: While accessing a Partner’s private apps, Internet Security policies remain enforced by the Primary Tenant.
Prerequisites
Before configuring Partner Access, please review the following requirements:
- Supported OS: Windows, macOS.
- Enrollment Method: Prelogon and VDI tunnel users are unsupported in partner tenants.
- Steering: Dynamic Steering configuration is not supported in partner tenants. Ensure partner users are matched to a steering configuration without Dynamic Steering in the partner tenant.
- Partner Requirements: The Partner Tenant must have a Forward SAML proxy configured for Client enrollment and must provide the appropriate authentication credentials to the user.
Upcoming Enhancements
In Netskope Client version R134, we will introduce the following improvements:
- Secure Configuration Service: Currently partner tenants that utilize the Secure Configuration Service to encrypt the Netskope Configuration are not supported. In the next software release, we will introduce support for Secure Configuration Service, which requires administrators to share an Encryption Token with end-users in order to store, read, and write the encrypted configuration.
- MacOS External Browser Support: We will introduce support for the External Browser in MacOS for clients that are installed with the appropriate install parameters in the next software version. This means the Netskope Client will authenticate partner tenants in the same way as the primary tenant.
Availability: This feature is currently in Controlled General Availability. Contact Netskope Support or your Sales Representative to enable this feature for your tenant.

