This article outlines the common connectivity issues that can occur between SSPM and your integrated SaaS apps. It provides a clear list of SSPM error codes along with their corresponding remediation steps, helping you quickly identify the root cause and restore a healthy connection. Use these tables as your primary reference when diagnosing connectivity failures, permission gaps, or API-related errors across your SaaS integrations.
How to use the article?
This section contains two tables: SSPM Error Codes and Remediation Steps. Use them sequentially to find your fix.
-
Identify the Fix: In the SSPM Error Codes table, find your error and note the corresponding Remediation Code.
-
Apply the Fix: Refer to the Remediation Steps table, using the Remediation Code to locate and follow the instructions.
SSPM Error Codes and Remediation Steps
General
| Error Code | Error Log | Error Details | Remediation Code |
|---|---|---|---|
| ErGEN01 | Service Error | Unknown Service error encountered | RmGEN01 |
| ErGEN02 | Unknown API Error | Unknown API error encountered | RmGEN01 |
| ErGEN05 | This instance status is not active : ‘error’ | Instance is in error state | RmGEN02 |
| Remediation Code | Remediation Steps Summary |
|---|---|
| RmGEN01 | Contact Netskope Support |
| RmGEN02 | The instance is in an error state. If the time since the last scan exceeds twice the scheduled interval for the instance, regrant access to the instance to generate a new token. |
GitHub
| Error Code | Error Log | Error Details | Remediation Code |
|---|---|---|---|
| ErGH01 | This installation owned by the org suspended your access | Netskope GitHub App installation is suspended, leading to an error when attempting to fetch resources. | RmGH01 |
| ErGH02 | This installation has been suspended | This error occurs when the Netskope GitHub App installation is suspended, preventing the token from being refreshed. | RmGH01 |
| ErGH03 | Not Found for url: https://api.github.com/orgs/<org>/audit-log | The onboarded GitHub account is not an enterprise account, which prevents access to the audit log API. This inaccessibility may result in missed delete updates for some resources. | RmGH02 |
| ErGH04 | {“message”:”Not Found”,”documentation_url”:”https://docs.github.com/rest/reference/apps#create-an-installation-access-token-for-an-app”,”status”:”404″} | Github App installation was removed or reinstalled without regranting. | RmGH04 |
| ErGH05 | organization has an IP allow list enabled | IP allow list is enabled in the organization | RmGH05 |
| ErGH08 | We couldn’t respond to your request in time. | The API timed out, resulting in 504 errors. | RmGH06 |
| Remediation Code | Remediation Steps Summary |
|---|---|
| RmGH01 | – Login to the onboarded GitHub organization using an admin account. – Go to Settings > GitHub Apps. – Open the installed GitHub app named Introspection for GitHub. – Go to Configure and unsuspend the app. |
| RmGH02 | Ensure the GitHub account meets the prerequisites outlined in the Onboard GitHub Documentation. |
| RmGH04 | Install Netskope App as mentioned in Onboard GitHub and regrant the instance. |
| RmGH05 | The organization has IP whitelisting enabled. Follow steps mentioned in Onboard GitHub docs to whitelist Netskope IPs. |
| RmGH06 | Occasional API timeouts with the Graph API are a known limitation, often caused by extended processing time. If this timeout error continues, increase the instance scan interval to more than 30 minutes. Contact support if the issue persists even after this adjustment. |
Salesforce
| Error Code | Error Log | Error Details | Remediation Code |
|---|---|---|---|
| ErSF01 | expired access/refresh token | Refresh token is expired or revoked. New access token can not be generated using refresh token. | RmSF01 |
| ErSF02 | token validity expired | Refresh token is expired or revoked. New access token can not be generated using refresh token. | RmSF01 |
| ErSF03 | Metadata API requires ModifyMetadata permission | Modify Metadata Through Metadata API Functions Permission is missing. | RmSF02 |
| ErSF04 | API CURRENTLY DISABLED | API Enabled Permission is missing. | RmSF03 |
| ErSF05 | Bad_OAuth_Token | Not authorized to access Salesforce APIs and restricted to retrieve the data. | RmSF04 |
| ErSF06 | INVALID_TYPE: Cannot use: OmniInteractionConfig in this organization | OmniInteractionConfig is available only if the org has the Omnistudio platform license. | RmSF05 |
| ErSF07 | sObject type * is not supported | The API is unable to query the sObject Type due to a lack of necessary permissions. | RmSF06 |
| ErSF08 | INSUFFICIENT_ACCESS | Required permissions are missing. | RmSF06 |
| ErSF09 | No_Access | Required permissions are missing. | RmSF06 |
| ErSF10 | sObject type is not supported. INVALID_TYPE | Required permissions are missing. | RmSF06 |
| ErSF11 | REQUEST_LIMIT_EXCEEDED | Rate limit reached due to non-enterprise salesforce account. | RmSF07 |
| ErSF12 | INVALID_SESSION_ID: This session is not valid for use with the API | The current refresh token is not valid anymore. | RmSF01 |
| ErSF15 | INVALID_TYPE: Cannot use: Network in this organization | Network resource is available only if the org has enabled Digital Experiences. | RmSF08 |
| ErSF16 | INVALID_TYPE: Cannot use: CustomSite in this organization | CustomSite resource is available only if the org has registered the Salesforce Site Domain. | RmSF09 |
| ErSF17 | upstream connect error or disconnect/reset before headers | The current refresh token is not valid anymore. | RmSF10 |
| ErSF18 | We are down for maintenance | The current refresh token is not valid anymore. | RmSF10 |
| ErSF19 | Bad_Id | The current refresh token is not valid anymore. | RmSF10 |
| Remediation Code | Remediation Steps Summary |
|---|---|
| RmSF01 | – Re-grant access to the onboarded Salesforce instance. – Configure the Salesforce instance to set a longer refresh token expiry time, as mentioned in Onboard Salesforce documentation, to prevent the need for frequent re-granting of access. |
| RmSF02 | – Ensure the user account used for granting the SSPM instance has the Modify Metadata Through Metadata API Functions permission. – Refer Permissions Required for Salesforce to confirm that the permissions listed are correctly applied. |
| RmSF03 | – Ensure the user granting the SSPM instance has the “API Enabled” permission. – Refer Permissions Required for Salesforce to confirm that the permissions listed are correctly applied. |
| RmSF04 | Ensure uninterrupted and consistent scans by disabling the Lock sessions setting. |
| RmSF05 | – Ensure Organization has the OmniStudio platform license and related add-on and user licenses. – Ensure Omnistudio Metadata API is enabled. |
| RmSF06 | Ensure all the Permissions Required for Salesforce are correctly applied. |
| RmSF07 | Onboard an enterprise edition salesforce account to avoid rate limit error. |
| RmSF08 | Ensure permission “Create and Set Up Experiences” is given and Digital Experiences is enabled |
| RmSF09 | Ensure Salesforce Sites is registered. |
| RmSF10 | Re-grant access to the onboarded Salesforce instance. |
Google Workspace
| Error Code | Error Log | Error Details | Remediation Code |
|---|---|---|---|
| ErGW01 | Not Authorized to access this resource/api | The Google Workspace user account utilized to grant instance access is missing the necessary Super Admin role. | RmGW01 |
| ErGW02 | You are not authorized to read activity records | The Google Workspace user account utilized to grant instance access is missing the necessary Super Admin role. | RmGW01 |
| ErGW03 | Request had insufficient authentication scopes | The Netskope service account is missing the necessary OAuth scopes. | RmGW02 |
| Remediation Code | Remediation Steps Summary |
|---|---|
| RmGW01 | Onboard GoogleWorkspace instance with super admin account. |
| RmGW02 | Follow Grant Scopes to the Netskope Service Account procedure to provide required scopes in case they were revoked. |
ServiceNow
| Error Code | Error Log | Error Details | Remediation Code |
|---|---|---|---|
| ErSN01 | User is unauthorized to access table | ServiceNow user used for granting instance permissions lacks the admin role. | RmSN01 |
| ErSN02 | Failed API level ACL Validation | The necessary application access scope has not been correctly configured for the required ServiceNow tables. | RmSN02 |
| ErSN03 | acces_denied | Refresh token is expired or revoked. New access token can not be generated using refresh token. | RmSN03 |
| ErSN04 | Access restricted | IP restrictions are enabled in the instance. | RmSN04 |
| ErSN05 | Transaction cancelled: maximum execution time exceeded | API response limit is reached. | RmSN05 |
| Remediation Code | Remediation Steps Summary |
|---|---|
| RmSN01 | – Ensure the user has an admin role. – Refer Access Required for ServiceNow to confirm that the permissions listed are correctly applied. |
| RmSN02 | Follow Enable ServiceNow Table Permissions procedure. |
| RmSN03 | To update the Refresh Token Lifespan for the Netskope application in ServiceNow: – Log in to your ServiceNow account with administrator privileges. – In the left navigation panel, search for “System OAuth” and select Application Registry. – Click on the application that was created for Netskope. – Increase the Refresh Token Lifespan. The recommended value is 31,536,000 seconds (1 year). – Refer Configure ServiceNow API Access for detailed instructions. |
| RmSN04 | – Add Netskope IP address to allow API calls from SSPM service. – Refer Onboarding ServiceNow to configure IP Address Access Controls in your ServiceNow instance. |
| RmSN05 | Adjust the “Maximum Duration (seconds)” to 120 in System Definition > Transaction Quota Rules > REST Table API request timeout and Re-grant the instance. |
Microsoft 365
| Error Code | Error Log | Error Details | Remediation Code |
|---|---|---|---|
| ErM36501 | Token permissions do not match required set of permissions | Token Permissions do not match required set permissions for Graph API call. | RmM36501 |
| ErM36502 | Intune permissions are not part of the graph access token | Netskope Security Posture Management (SPM) is unable to list Intune resources because the graph access token is missing the necessary permissions. | RmM36501 |
| ErM36504 | Request not applicable to target tenant | Intune license is not present for Microsoft account. | RmM36502 |
| ErM36505 | Your tenant is not licensed for this feature | Intune license is not present for Microsoft account. | RmM36502 |
| ErM36506 | Authorization_IdentityNotFound | Token is not valid. | RmM36501 |
| ErM36507 | Authentication_MSGraphPermissionMissing | Required Permission is missing. | RmM36501 |
| ErM36508 | Authentication_RequestFromNonPremiumTenantOrB2CTenant | Neither tenant is B2C or tenant does not have premium license. | RmM36503 |
| ErM36509 | Intune SKU is not part of customer service plan | Intune license is not present for Microsoft account. | RmM36502 |
| ErM36510 | https://graph.microsoft.com/beta/deviceManagement/deviceConfigurations, .+ {“error”:{“code”:”UnknownError”,”message”:”{\”ErrorCode\”:\”Forbidden | The Intune license is not present or the required Intune permissions are not granted. | RmM36502 |
| ErM36511 | “code”:”AuthenticationError”,”message”:”AADSTS500014 | Netskope service principal is not present in the Microsoft account | RmM36501 |
| Remediation Code | Remediation Steps Summary |
|---|---|
| RmM36501 | Re-grant access to the onboarded Microsoft 365 instance. |
| RmM36502 | Enable INTUNE_A license in Microsoft account to list Intune resources. If the error continues after the license is enabled, regrant access to the Microsoft 365 instance. |
| RmM36503 | Accessing User sign-in reports requires a Microsoft Entra ID P1 or P2 license. Ensure the tenant is licensed with a Microsoft Entra ID P1 license. |
Workday
| Error Code | Error Log | Error Details | Remediation Code |
|---|---|---|---|
| ErWD01 | The task submitted is not authorized | The requirements outlined on the instance setup page must be met by both the Domain Security Policy linked to the Security Group and the scope assigned to the API client for integration. If these do not align, an error will occur. | RmWD01 |
| ErWD02 | allBusinessProcessTypes is inaccessible | RmWD02 | |
| ErWD03 | allDomains is inaccessible | RmWD03 | |
| ErWD04 | allSecurityGroups is inaccessible | RmWD04 | |
| ErWD05 | allWorkdayAccounts is inaccessible | RmWD05 | |
| ErWD06 | allIntegrationSystemsAudited is inaccessible | RmWD06 | |
| ErWD07 | permission denied | RmWD07 |
| Remediation Code | Remediation Steps Summary |
|---|---|
| RmWD01 | Follow procedure to add Domain Security Policy to Security Group and make sure all permissions required for Workday are added. |
| RmWD02 | – Add Business Process Administration Domain Security Policy in Security Group with View Only access. Refer Domain Security Policy to Security Group procedure. – Follow Register an API Client for Integrations in Workday steps to add required scopes to API Client. |
| RmWD03 | – Add Security Activation, Security Configuration, and Drive Administrator Domain Security Policy in Security Group with View Only access. Refer Domain Security Policy to Security Group procedure. – Follow Register an API Client for Integrations in Workday steps to add required scopes to API Client. |
| RmWD04 | – Add Security Activation and Security Configuration Domain Security Policy in Security Group with View Only access. Refer Domain Security Policy to Security Group procedure. – Follow Register an API Client for Integrations in Workday steps to add required scopes to API Client. |
| RmWD05 | – Add Workday Accounts, Security Configuration, Security Administration, Security Activation, Purge Person Data Domain Security Policy in Security Group with View Only access. Refer Domain Security Policy to Security Group procedure. – Follow Register an API Client for Integrations in Workday steps to add required scopes to API Client. |
| RmWD06 | – Add Integration Reports, Integrations: EIBs Domain Security Policy in Security Group with View Only access. Refer Domain Security Policy to Security Group procedure. – Follow Register an API Client for Integrations in Workday steps to add required scopes to API Client. |
| RmWD07 | – Add Workday Query Language Domain Security Policy in Security Group with View and Modify access. Refer Domain Security Policy to Security Group procedure. – Follow Register an API Client for Integrations in Workday steps to add required scopes to API Client. |
Box
| Error Code | Error Log | Error Details | Remediation Code |
|---|---|---|---|
| ErBox01 | Error Box API access is forbidden for url:https://api.box.com | Required permissions are missing. | RmBox01 |
| Remediation Code | Remediation Steps Summary |
|---|---|
| RmBox01 | Re-grant access to the Box instance to apply updated permissions. |
Okta
| Error Code | Error Log | Error Details | Remediation Code |
|---|---|---|---|
| ErOkta01 | You do not have permission to perform the requested action | Required permissions are missing. | RmOkta01 |
| ErOkta02 | Invalid token provided | Required permissions are missing. | RmOkta01 |
| Remediation Code | Remediation Steps Summary |
|---|---|
| RmOkta01 | – Create an API Token in Okta, as mentioned in Onboard Okta. – Refer Roles Required for Okta to confirm that the permissions listed are correctly applied. |
Zoom
| Error Code | Error Log | Error Details | Remediation Code |
|---|---|---|---|
| ErZoom01 | Invalid refresh token | Refresh token is expired. Need re-authentication of instance. | RmZoom01 |
| ErZoom02 | Only available for Paid | Operation Log API is only reachable for Paid Zoom accounts. | RmZoom02 |
| ErZoom03 | Access to the Zoom REST API has been denied for this user | The user account utilized to grant instance access lacks the necessary permissions. | RmZoom03 |
| ErZoom04 | Invalid access token, does not contain scopes | Permission is missing. | RmZoom03 |
| ErZoom05 | Invalid Token! | Permission is missing. | RmZoom03 |
| ErZoom06 | No permission | Permission is missing. | RmZoom03 |
| Remediation Code | Remediation Steps Summary |
|---|---|
| RmZoom01 | Re-grant access to the onboarded Zoom instance. |
| RmZoom02 | Onboard the Paid Zoom Account. |
| RmZoom03 | Create the user as mentioned in Onboard Zoom documentation. Use this user to subsequently grant access to the instance. |
Jira
| Error Code | Error Log | Error Details | Remediation Code |
|---|---|---|---|
| ErJira01 | Unauthorized; scope does not match | Required Permissions are missing | RmJira01 |
| Remediation Code | Remediation Steps |
|---|---|
| RmJira01 | Regrant access to the Jira instance to apply permissions of Netskope app. |

