Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Digital Experience Management
    Settings

    Settings

    Customers have the ability to tailor DEM configuration settings for different users, groups, and a multitude of other attributes. The new feature can be found on the Settings page of your Digital Experience Management (DEM) tenant.

    This service allows you to configure and manage the following DEM related settings:

    • General Settings
    • Network Path Probes
    To access the Settings page, you must enable the required Role-Based Access Control (RBAC) permissions.

    Permissions

    The Settings page is displayed in your tenant’s left navigation menu under the DEM section if you have a subscription for P-DEM Professional. Additionally, the currently logged-in user must have the Role-Based Access Control (RBAC) permission enabled.

    How to Enable RBAC-V2 for Settings

    To enable the correct permissions for the DEM Settings page with RBAC-V2:

    1. In your Netskope tenant, go to Settings  > Administration > Administration & Roles.
    2. To view the RBAC settings for a specific user, click the ellipse icon located on the far-right of the row for the selected user.
    3. Then, select View to open the “View Role” page which contains the RBAC settings options for the selected user. 
    4. You will be taken to the “View Role” page for the selected user.
    5. On the “View Role” page, scroll down to the “Page Permissions” section.
    6. Click the dropdown carrot icon to expand the Digital Experience Management section.
    7. Ensure the permissions for the DEM Settings page are set to “View” or “Manage”.

    How to Enable RBAC-V3 for Settings

    To enable the correct permissions for the DEM User Overview page with RBAC-V3, please do the following:

    1. In your Netskope tenant, go to Settings > Administration > Administration & Roles.
    2. Select a specific user to view the permissions for that user.
    3. Ensure the permissions for the DEM User Overview page are set to “View” or “Manage”.

    About Settings

    The DEM Settings page gives you access to features that enable you to configure DEM-related settings.

    Please ensure that the client is on version 118 or higher before turning on P-DEM for the clients.
    If a user has the DEM service disabled, no telemetry data will be collected.

    Go to Digital Experience Management > Settings to view this page.

    General Settings

    This page gives you the ability to view and manage the general settings for DEM. You can enable and disable the DEM service for selected users by utilizing the tools in this section.

    DEM Service Settings

    The DEM Service Settings configuration tool enables you to control which users can have access to the DEM Service. You can select from a wide range of criteria to enable or disable the DEM Service for selected users.

    Enable the DEM Service for All Users

    You can use this configuration option to enable or disable the DEM service for all users. 

    1. Go to DEM > Settings and click on the General tab.
    2. Click the Edit button for the “DEM Service” section.
    1. The “DEM Service Settings” window will open.
    2. To edit, click the Status toggle to change the toggle from “disabled” to “enabled”.
    1. The status will be enabled for all users. A selection of criteria options to enable the DEM Service and a query preview will appear in the DEM Service Settings window.
    2. To enable the DEM Service for all users, click the Save button. 
    The DEM Service is set to “disabled” by default.

    Enable the DEM Service Status for Selected Categories of Users

    You can use this configuration option to enable the DEM service for specific users.

    1. Go to DEM > Settings and click on the General tab.
    2. Click the Edit button for the “DEM Service” section.
    3. The “DEM Service Settings” window will open.
    4. To edit, click the Status toggle to change the toggle from “disabled” to “enabled”.
    5. The status will be enabled for all users, and a selection of criteria options to enable the DEM Service will appear in the “DEM Service Settings” window.
    1. Make selections from the following categories to create the criteria for which users will have the DEM Service enabled:
      • User: Select from users, user group, and organization unit.
      • OS: Select from windows and Mac.
      • Device Classification: Select from managed, unmanaged, and not configured.
    You can select all of the Users/OS/Device Classifications in a category, or a subset within a category.
    1. You can use the “Query Preview” section to preview the query.
    2. To enable the DEM Service for the users that you have selected, click the Save button.

    Disable the DEM Service Status for Specific Users

    You can use this configuration option to disable the DEM service for specific users by selecting the exclusion criteria.

    1. Go to the “DEM Service Settings” window.
    2. To view the “Add Exclusion Criteria” dropdown tab, ensure that the “Status” toggle is set to “enabled”.
    3. Click the  “Add Exclusion Criteria” dropdown tab to view the following exclusion criteria options:
      • User
      • OS
      • Classification
    4. Click on a criteria option to expand the criteria selection field.
    1. Use the selected exclusion criteria fields to select the users, OS, and device classifications that you want to exclude from the DEM service.
    1. If you are selecting more than one exclusion criteria, choose whether you want the exclusion criteria to match “ANY” or “ALL” of the selected criteria by choosing from the following two options:
      • ANY: One or more of the selected criteria must be matched for a selection to be excluded from having the DEM Service enabled.
      • ALL: All of the selected criteria must be matched for a selection to be excluded from having the DEM Service enabled.
    1. DEM will be enabled for all users except for the ones specified in the exclusion criteria.
    2. You can use the “Query Preview” section to preview the query.
    3. Click the Save button to save your selections.
    The exclusion criteria selections take precedence over the criteria selections in the section to enable the DEM Service. For example, the DEM Service will be disabled for a user who has the DEM Service enabled, if that user matches one or more of the exclusion criteria.

    Monitored Applications

    You can use this feature to select and edit up to 10 monitored applications from 50 SaaS applications, NPA hosts, or a combination of both.

    The list can be edited at any time.

    Configure Monitored Applications

    1. Go to Digital Experience Management > Settings and click on the General tab.
    2. Click the Edit button in the Monitored Applications section of the page.
    1. Search for the applications of your choice by typing an application name in the search field or by scrolling through the list of 50 applications.
      1. SaaS applications: For SaaS applications select from the list of 50 applications to start monitoring.
      2. Private applications: Private applications shows a list of all the private applications hosts that are configured in your tenant, select the hosts you want to monitor. DEM will monitor the traffic from all DEM-monitored users to the configured NPA hosts. Please note that all configured ports against the selected hosts will be monitored in DEM.You can also see the application name against the host on the selection screen.
    Wild cards and subnets are not supported for private applications.
    1. Make your selection of up to 10 applications in combination of SaaS applications and/or npa hosts.
    2. Click the Save button to save your selection of applications.Please allow a few hours for data to reflect on the user overview screen once you have configured the NPA host.
    You can edit the applications at anytime.

    Configure Private Applications with Publisher DNS Enabled

    When configuring monitoring for private applications with Publisher DNS enabled, select only the FQDN. You do not need to select resolved IP addresses shown in the list —DEM will automatically monitor all resolved IPs by default. DNS traffic performance will be shown against the FQDN while user traffic performance will be shown against the resolved IP addresses on the user details page.

    Network Path Probes

    The Network Path Probes section enables you to define the monitoring policies for users with the DEM service. These policies determine the data collected and the frequency of collection to meet your specific monitoring needs.

    About Network Path Probes

    The Network Path Probes section enables you to define the monitoring policies for users with DEM.

    A. Network Path Probes Tab: This tab will take you to the Network Path Probes configuration section of the Settings page.

    B. New Network Path Probes Button: Clicking this button will open the “New Network Path Probe” window where you can create a new probe.

    C. Probe Name: The name of the probe.

    D. Source: The selections that have been made for the user, user groups, and OUs.

    E. Devices: The OS and devices that have been selected.

    F. Status: Whether the probe is enabled or disabled.

    G. Handle Icon: You can click and hold the handle icon to drag and drop a row.

    H. Order Number: A specific probes place on the ordered list of probes on the Network Path Probes subpage.

    I. Ellipse Icon: You can click the ellipse icon to view the following additional options for a selected probe:

    • Disable: Select this option to disable the probe.
    • Edit: Select this option to edit the probe.
    • Delete: Select this option to delete the probe.
    • (move): Select this option to move the probe.

    J. Page Number Tool: This number displays the page that you are viewing on the Network Path Probes subpage. When available, you can click the arrows to view additional pages.

    K. Rows Per Page: Use this tool to change the number of rows you can view per page.

    L. Edit Icon: Clicking the edit icon at the bottom of the page will open the “Default Network Path Probe” window. You can edit the following settings in this window:

    • Enable or disable the “Process Info Collection” settings by using the Enabled/Disabled toggles. 
    • Change the frequency of data collection by selecting from the list of options in minutes.
    No telemetry data will be collected for users who have the DEM Service disabled. 

    Configure a New Network Path Probe

    You can create a new policy for Network Path Probes to tailor monitoring specifically to individual users, user groups, or devices based on criteria such as management status and OS. This customized policy allows you to set specific monitoring parameters that override the default settings. You can configure a new probe by following these steps:

    1. Click the New Network Path Probe button.
    2. The “New Network Path Probe” configuration window will open.
    3. Make the following selections to configure a new probe:
      • Network Path Probe Name: Enter the name for the new probe.
      • Probe Status: Use the toggle to enable or disable the probe.
      • Network Path and Device Health Collection: Use the toggle to enable or disable this feature.
      • Process Info Collection: Use the toggle to enable or disable this feature.
      • Frequency (minutes): Select the frequency of data collection by selecting from the list of options in minutes.
      • Users and Devices: Select the users and devices that you want to be monitored:
        • User: All users will be monitored by default. Select specific users by using the users search field if you only want to monitor specific users.
        • OS: All OS will be monitored by default. To monitor a subset of OS, select Windows or Mac from the OS search field.
        • Device Classification: All device classifications will be monitored by default. Select from managed, unmanaged, and not configured in the device classification search field if you want to monitor devices with specific classifications. 
    4. Click the Save button to create the new probe.
    You can create a maximum of 30 Network Path Probes.

    Edit an Existing Network Path Probe

    To edit an existing probe follow these steps:

    1. Select the probe you want to edit by clicking the ellipse icon in the row for that probe.
    2. A small options menu will open.
    3. Click Edit.
    4. The “Edit Network Path Probe” window will open.
    5. Edit the probe by changing the settings in the window.
    6. Click the Save button to save the changes to the probe.
    In this Topic
    • Settings