You can use the templates to customize different notification pages shown to the users, plus use your company logo so it appears in all the pages. The templates help you guide your users when you:
- Customize block and alert user notifications
- Customize email notifications
- Add custom images
You can create new templates, use the default templates, and preview templates by clicking Policies and scrolling down to the Templates section. Select the type of template you want to create. After creating these templates, you can use them in your policies. You can further customize the template by adding justifications, text, configure action buttons, and redirect users to specific URLs. You can also customize templates by adding variables, when available.
User Notification Template
On the User Notifications page, you can configure individual user notification templates as well as global settings for all templates. The global user notification settings include notification delivery method and mute intervals.
Configuring User Notification Templates
User notification templates enable you to block a user action and/or send an alert to the user. These templates can be customized to provide specific information and options in an alert or block notification. You can use the following queries with the “neq” operator to view all justification reasons and types: justification_reason and justification_type. To learn more, see Skope IT Query Language. You can also provide a description box for users to provide a justification. Optionally, you can make the justification text optional.
There are also options for users to include, stop, or proceed after providing a justification. In addition, you can use the Insert button to add Netskope template variables and custom images.
Tip
When the justification options are disabled, the user can dismiss the notification or let the page time out. When the user lets the page time out, the generated alert for the blocked transaction lists “Notification timed out. Canceling the activity” in the Justification Reason field.
- Go to Policies > Templates > User Notifications. Click New Template.

- In the template creation window, choose and configure the options you want to customize the template. The Template Name, Title, and Message fields are required.
Note that some options (i.e., Message, Subtitle, and Redirect end users to the following URL automatically) have variables that are selectable from a dropdown list. You can use these variables to provide more context information with the notification.
User Notification Template Variables
The following table lists the available variables for user notification templates.
| Variable Name | Message Value |
|---|---|
| Activity | {{x-cs-app-activity}} |
| Application | {{x-cs-app}} |
| Application Category | {{x-cs-app-category}} |
| Application Session ID | {{x-cs-session-id}} |
| Categories | {{x-policy-categories}} |
| Date | {{date}} |
| Destination IP | {{x-policy-dst-ip}} |
| FQDN | {{cs-host}} |
| From User | {{x-cs-app-from-user}} |
| Groups | {{x-c-authz-groups}} |
| HTTP Referer | {{cs-referer}} |
| Instance ID | {{x-cs-app-instance-id}} |
| Malware Name | {{x-tp-malware-name}} |
| Matched Categories | {{x-policy-categories-matched}} |
| Object Name | {{x-cs-app-object-name}} |
| OU | {{x-c-authz-ou}} |
| Policy Name | {{x-policy-name}} |
| POP | {{x-s-dp-name}} |
| Primary Category | {{x-category}} |
| Source IP | {{x-policy-src-ip}} |
| Time | {{time}} |
| Transaction ID | {{x-transaction-id}} |
| URI Path | {{x-cs-uri-path}} |
| URI Port | {{cs-uri-port}} |
| URI Query | {{cs-uri-query}} |
| URI Scheme | {{cs-uri-scheme}} |
| URL | {{x-cs-url}} |
| URL Reorganization Link | {{x-url-recat}} |
| User | {{x-c-authn-user}} |
- (Optional) Note that this feature is only applicable if the notification delivery method is Client. To learn more, see Configuring Global User Notification Settings.
You can select the Override the global notification settings checkbox to configure a separate mute interval for the user notification template. Click Edit Override to configure how long repeat notifications are suppressed after the initial notification. You can choose from 1 minute to 48 hours.
- (Optional) Note that this feature is only applicable if the notification delivery method is Client and the policy action is Block. You can select the Disable Client Notification checkbox to disable showing notifications to users.
- To translate the notification in a specific language, enable the Localization toggle and select a language from the dropdown list. Localization is based on the browser LOCALE settings.

- Select Import to get a sample template that you can use to upload further customized notification messages.

- Click Sample Template to download a template, customize it, and then upload it by dragging and dropping it, or clicking Select File.

- When finished, click Import.
- Click Save and Apply Changes.
Configuring Global User Notification Settings
On the User Notifications page, click the gear icon to open the Settings dialog box. In Settings, you can specify how to deliver the notification (by Client or Browser for Cloud Apps and Web Traffic). All user notification templates use these global settings.
Specify a Client or Browser method for both Cloud Apps and Web Traffic, and then enter the number of seconds (up to 600) that you want the pop-up notification to be shown to the user when you set User Alert or Block as a policy action. The default is 60 seconds. When finished, click Save.

(Optional) This feature is only applicable if the notification delivery method is Client. In the Mute tab, you can control how long repeat notifications are suppressed after the initial notification. The range is from 1 minute to 48 hours, and can be applied to action blocks or user alerts.
Important
Netskope Security Cloud blocks the user’s access based on the configured policy and the request URL without waiting for the response packet or the redirect from the website.
For example, a user tries to access http://www.box.com, but the server returns a 3xx redirect response with the Location header redirected to https://www.box.com. Netskope immediately blocks the user’s access without waiting for a response packet from https://www.box.com.
The notification for browse access (browse activity only) using websites is delivered within the browser regardless of the configured option on the Netskope UI.
For native app traffic, the notification popup is displayed through the Netskope client. In addition, for non-browse activities (e.g. upload, download, post, etc.) app/category block policy the notification popup is displayed based on the admin selected notification delivery mechanism.
Go to Settings > Mute to control how long repeat notifications are suppressed after the initial notification. Keep in mind that this is only applicable if you selected Client as the notification delivery method. The range is from 1 minute to 48 hours.
The following describes the suppression configuration options:
- For DLP and Threat Protection Policies, Block and User Alert both have a minimum mute time of 1 minute that can be extended up to 48 hours. This is applicable for both native apps and non-native apps.
- For Other Policies (non-DLP), refer to the table below for more information.
Native Apps Non-Native Apps Block 1 minute to 48 hours
(Default 1 Minute)Block 1 minute to 48 hours
(Default 1 Minute)User Alert 1 minute to 48 hours
(Default 30 Minutes)User Alert 1 minute to 48 hours
(Default 1 Minute)
Email Notification Template
You can use email notifications to let users know when they’ve triggered a policy violation.
To create an email notification template:
- Go to Policies > Email Notification.
- Click New Template and then Real-time Protection or API Date Protection for the policy violation type.

- In the Create Email Notification Template window:
- Template Name: Enter a name for the custom email template.
- Subject: Enter the title or subject of the email sent to users.
- Message: Enter HTML code to customize the email notification, or click Insert Variable to add variables to the notification. Depending on the type of policy violation, you can add the following variables:
- Real-time Protection
- Triggered policy name
- Admin Email
- Email Recipient
- Timestamp in UTC
- SMTP Recipients
- SMTP Message ID
- SMTP Message Size
- API Data Protection
- Create New
- Application name
- Activity performed
- Triggered policy name
- User Email/ File Owner
- Admin Email
- Policy action
- Application Instance
- File details
- Email Sender (Gmail and Microsoft Outlook only)
- Email Recipient (Gmail and Microsoft Outlook only)
- Email Type, Body or Attachment (Gmail and Microsoft Outlook only)
- Real-time Protection

- Click Save. Click Apply Changes to use this email notification in a policy.
- Click Apply Changes to use this email notification in a policy.
You can select this email notification template when configuring your Real-time Protection and API Data Protection policies.
Custom Images
Custom images, like your company logo, can be added using the Upload Custom Image window. These images can be added to all the other templates described in the following sections.
Acceptable logo sizes are:
- 48px for small
- 64px for medium
- 128px for large
This logo size is applicable only if the company logo/custom image height is greater than the selected size. If the original logo size is less than the selected size, it will display the original image. For example, if the uploaded image height is 55px and if the selected size is medium (64px), the system will display the original image only (55px). However, if the selected size is small (48px), the system will shrink the image and its size will be 48px.
Go to Policies > Templates > Custom Image. Click New Image, and then Select File to upload the image.
When finished, click Upload.
Single Sign-On
This template is available for Client Enforcement using single sign- on.
Client enforcement allows you to implement cloud security by making sure the user traffic is always steered through Netskope. You can implement client enforcement by integrating with single sign on or by using Netskope as the SAML proxy.
By default, when you are enforcing a client, users are automatically redirected to the download page to download and install the client.
You can also choose to show a custom page to the users to provide more information on the company security policy without redirecting them to the download page.



