Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    User Provisioning and Authentication
    Unified User Management

    Unified User Management

    The Unified User Management UI provides administrators with a centralized, intuitive interface to manage users and groups across the Netskope platform. It consolidates all key identity and access management functions—such as user creation, group administration, and enterprise account management—into one unified experience. With advanced filtering, RBAC-based control, and enterprise account visibility, administrators can efficiently oversee user provisioning and access across tenants, Active Directory importers, and SCIM clients.

    Important Considerations for User and Group Synchronization

    While the Netskope UI allows for direct management of user and group memberships, organizations utilizing automated synchronization services like SCIM or Directory Importer must be aware of the following limitations and risks:

    • Data Sync Conflicts – If a SCIM client or Directory Importer is actively running, any manual edits to user attributes or group memberships made directly in the UI may be overwritten during the next synchronization cycle. This can cause data in Netskope to become out of sync with your Identity Provider (IdP).

    • Deployment and Policy Impact – Manually altering user accounts in the UI can have significant, unintended consequences. It can potentially disrupt Netskope Client deployments, impact NPA Pre-Logon/NPA VDI user configurations, or break policy evaluations that rely on those user identities for enforcement.

    Access Control and Best Practice – It is strongly recommended that organizations restrict edit access for user and group data to qualified advanced administrators only. Utilize Role-Based Access Control (RBAC) to ensure regular administrators are granted view-only permissions. This practice helps prevent unintended updates and ensures proper oversight and data integrity across the platform.

    Key Features of User Management UI

    • Centralized Management – Manage users and groups from a unified interface.

    • Search and Filtering – Apply filters, sorting, and pagination to locate users or groups based on attributes such as group membership, OU, or custom fields.

    • Group Management – Create, rename, delete, and manage user groups efficiently.

    • Detailed Attribute View – Access key user and group details such as provisioning method, custom fields, and basic metadata (creation and last edited information).

    User Management UI Components

    The User Management page includes multiple interactive sections designed to simplify user and group administration.

    To access the user management UI:

    • In the tenant WebUI, go to Settings > Security Cloud Platform.

    • Under End User Provisioning, click User Management.

    Mini Dashboard

    The mini-dashboard ( 1 ) displays summary metrics and allows quick navigation. Clicking an item opens the corresponding list view in the table below.

    At the top of the UI, the summary metrics are defined as:

    • Total Users: Total number of unique email addresses.

    • Enterprise Accounts Enabled: Total number of active usernames/UPNs (User Principal Name)

    • Enterprise Accounts Disabled – The total number of inactive usernames / UPNs.

    • Total User Groups – The total number of user groups.

    • Total OUs – The total number of organizational units

      The data table in each of the tabs (Users or User Groups) can be customized to display specific columns. To customize columns, scroll horizontally to the end of the table and click the gear icon and select Customize columns.

    Filters

    Filters ( 2 ) can be applied on any tab to refine search results. You can apply a single filter or chain multiple filters for granular data exploration. Column-level filters are supported for specific attributes.

    Enterprise User Accounts

    Enterprise accounts are identified by a unique user identifier defined in the AD domain or IdP—typically the UPN in Active Directory or the userName in SCIM.

    When user and group information syncs to Netskope, the Netskope SCIM server assigns a SCIM ID to each enterprise account. Multiple UPNs or usernames may share the same email address, and such accounts are treated as a single user record.

    In the classic UI, only the email address was displayed. The Unified UI adds the ability to view and manage individual UPNs and related enterprise accounts for each email.

    For Enterprise Accounts, the Unified UI allows you to:

    • View and switch between different enterprise accounts associated with a single email address.

    • Access user details including email, username/UPN, and direct group memberships.

    • Add or remove users from direct groups. Indirect groups (parent groups) are automatically reflected through hierarchy.

    • Edit user information such as name or email for enterprise-linked records.

    RBAC and Data Scope Control

    Role-Based Access Control (RBAC) is integrated into the Unified User Management system.

    Admins with RBAC v3 data-scope permissions can view only users and groups that fall within their assigned scope. However, when a data scope is defined, modifying user group information or sending invitations is not supported..

    Users Tab

    The Users tab lists all provisioned users in the tenant and provides administrators with full visibility into user attributes and access controls.

    The following are the default columns:

    • Email & Name – Displays the user’s email and full name.

    • Username / UPN – The unique identifier for the user (User Principal Name).

    • Status – Indicates whether the user is provisioned and enabled.

    • Direct Group Membership – Lists groups that the user is directly assigned to.

    • Provision Method – The method used to provision the user.

    • Last Edited – Shows when the user record was last updated.

    Adding a New User

    Select Add New User and enter the following:

    1. Username

    2. Email Address

    3. Direct Group Membership

    4. Select Send Email Invitation and click Save

    Custom attributes and Organizational Units (OUs) are displayed as read-only fields and cannot be edited in the UI.

    User Groups Tab

    The User Groups tab displays all user groups in the tenant. Click a group name to view all members of that group.

    Default columns in the User Groups list are:

    • Group Name

    • Number of Users – This is number of direct members and does not count indirect members.

    • Provisioning Method – The provisioning method used for adding users to the group.

    Columns can be customized using the gear icon in the last column. To edit or delete a user group, click the ellipsis ( … ) icon in the last column and select the appropriate action.

    For more granular information, click Lookup Entire Membership link.

    Adding a New User Group

    Click the New User Group button and enter the following:

    1. User Group Name

    2. Direct Member (one or more users)

    3. Click Save.

    In this Topic
    • Unified User Management