Here are the latest features, issues fixed, and other updates published between the golden releases 135.0.0 and 138.0.0. This is a consolidated list of items published in the release notes for versions between 135.0.0 and 138.0.0.
Use Release Notes widget for release notes related to a specific version.
Here is the list of the new features and enhancements between versions 135.0.0 and 138.0.0.
135.0.0
General Availability of On-Premises Detection Using Egress IP Address
On-Premises Detection using Egress IP address was available as a Controlled-GA feature in version 134.0.0. This is now available for all tenants.
To learn more: Netskope Client Configuration.
Supported minimum Client version: 130.0.0
General Availability of Enforce Enrollment for Netskope Client
Mandating user enrollment was previously available as a Beta feature in version 133.0.0. With this release, the feature is now available for all tenants.
To learn more: Enforce Enrollment for Netskope Client.
Supported minimum Client version: 133.0.0
General Availability of Data Center Selection or Pinning Option
Data Pinning was previously available as a Beta feature in version 127.1.0. With this release, the feature is now available for all tenants.
This feature enables to manually pin to a Point of Presence (POP) using the nsdiag command.
To learn more: Data Center Pinning In Netskope Client.
Supported OS: Windows, MacOS, and Linux.
Supported minimum Client version: 127.1.0
Support for ChromeOS 145
Netskope Client now supports ChromeOS version 145.
Supported minimum Client version: 135.0.0
To learn more: Netskope Client Supported OS and Platform.
Support for RHEL 9.6
Netskope Client now supports Red Hat Enterprise Linux (RHEL) version 9.6.
Supported minimum Client version: 135.0.0
To learn more: Netskope Client Supported OS and Platform.
Monitoring and Automatic Restart of Netskope Client Services
This release introduces a service monitor: stAgentSvcMon, a new mechanism within Netskope Client Agent Service designed to monitor the operational status of the stAgentSVC service. Prior to version 135.0.0, the stAgentSVC agent service lacked an automatic restart capability when it ceased operation due to an issue. With the implementation of this new service, the service monitor can now oversee and automatically restart the agent services, including those deliberately stopped by an administrator. This monitor verifies the running status of Agent Service every 60 seconds and initiates an automatic restart if the stAgentSVC service status is registered as stopped.
Zone Selection Based on User Identity
Introducing Zone Selection feature in Client Configuration. Using this option, the administrator can select China Elite zone in the Client Configuration.
To learn more, view Zone Selection Based on User Identity.
Supported minimum Client version: 135.0.0
136.0.0
Secure Enrollment Token Expiration Email Notification
Token expiration Email notification automates email alerts for tenant administrators to notify them when Secure Enrollment tokens are approaching their expiration date. With the implementation of this feature, it helps protect against Netskope Client installation failures caused by expired tokens.

Administrators can configure notification settings on the MDM page. Once enabled, Netskope Client identifies tokens nearing expiration and triggers automated emails 30, 15, 7, and 1 day(s) before the token expires. To prevent unnecessary noise, notifications only trigger if Secure Enrollment is enforced and cease immediately once a token has expired.
To learn more: Email Notification.
Granular Fail-Close Control
This feature allows administrators to granularly enable or disable the Fail-Close setting based on a user’s location, specifically distinguishing between on-premises and off-premises environments.
Along with the new Fail-Close enhancements, Netskope has:
-
Reduced User Disruption: Introduced an optional “Show notification after” setting (30–120 seconds) delays Fail-Close alerts to prevent pop-ups during transient network issues, such as switching between Wi-Fi networks
-
Decoupled Settings: Removes previous dependencies, enabling independent management of options such as password-protected uninstallation and service disabling, regardless of Fail-Close status.
Fail Close with Dynamic Steering

Fail Close without Dynamic Steering

To learn more: Fail Close (Check Step 7 in section: Creating Steering Configuration From Version 124.0.0).
With this release, it moves the Fail-Close configuration from the general Client Configuration to Steering Configuration within the web UI.
Supported minimum Client version: 136.0.0
Custom Device Identity Keys for iOS
This enhancement closes the visibility gap by allowing IT and security teams to match devices in the Netskope Web UI with known assets in their MDM or help desk systems.
-
Faster Incident Response: Provides human-readable device names and accurate serial numbers, which simplifies auditing and speeds up troubleshooting.
-
Asset Alignment: Replaces self-generated Unique Device IDs and “N/A” serial number labels with actual organizational asset identifiers.
To incorporate these improvements, Netskope introduces two new optional VPN profile keys that administrators can populate through their MDM platform (e.g., Jamf, Microsoft Intune) when pushing profiles to iOS devices.
To learn more: Custom Device Identity Keys for iOS (Check Steps 6 > Custom Device Identity Key-Value Pairs for iOS).
General Availability of Steering Configuration WebUI Enhancements
The enhanced Match Criteria capabilities was available as a Beta feature in version 124.0.0. This is now available for all tenants.
Netskope introduced two new capabilities under Match Criteria in the Steering Configuration on the webUI:
- OS Family: Differentiate steering profiles based on different operating systems(Windows, MacOS, Linux, Android, and iOS). This option provides flexibility in configuring steering profiles by choosing the OS type as match criteria.
- User Group/ OU: With 124.0.0, Netskope added ability to select multiple User Groups/OUs while configuring Steering profiles.
To learn more: Steering Configuration.
Supported minimum Client version: 124.0.0
General Availability of Netskope Client Integration with Imprivata
Netskope Client integration with Imprivata was available as a Beta option in version 134.0.0. With version 136.0.0, Imprivata integration is available for all tenants.
Healthcare professionals use Imprivata extensively to allow fast seamless access by various personnel to shared workstations. Imprivata is used as the IDP/SSO to authenticate doctors and nurses to allow them to access confidential patient records with appropriate privileges. Imprivata logins are abstract from the OS logins and Netskope Client needs to integrate with Imprivata agent to learn the logged in user information to apply related relevant Netskope policies. This enforces differentiated policies for doctors and nurses and less reliability on the Windows OS login for Netskope policies.
Supported OS: Windows
To learn more, view Netskope Client Integration with Imprivata.
Supported minimum Client version: 134.0.0
General Availability of CRL Check Validation for MacOS
Certificate Revocation List (CRL) Check validation was available for Device Classification on macOS as a Beta option in version 133.0.0. This is now available for all tenants.
The CRL contains digital certificates revoked by the issuing CA before their expiration date; these certificates are no longer trusted. If a certificate is revoked, the posture (device classification) check fails.
Supported OS: macOS (from 133.0.0) Windows (from 122.1.0)
To learn more: view Device Classification for macOS.
Supported minimum Client version: 133.0.0
Support for ChromeOS 146
Netskope Client now supports ChromeOS version 146.
To learn more, view Netskope Client Supported OS and Platform.
Supported minimum Client version: 136.0.0
137.0.1
Here is the list of the new features and enhancements.
External Browser-Based Authentication
Netskope Client for Windows now supports browser-based IdP authentication using the default system browser instead of embedded WebView2 browser.
To learn more, External Browser-based Authentication.
Supported minimum Client version: 137.0.1
Enhanced iOS Log Collection
The Netskope Client for iOS app now includes a diagnostic log sharing feature that lets administrators export logs anytime, even during enrollment failures or configuration delays, without IT or MDM administrator assistance.
Benefits
-
Faster Troubleshooting: Accelerates support ticket resolution by allowing admins to send logs directly to the Netskope tenant with a single tap.
-
Reduced User Friction: Simplifies the process for administrators who no longer need to have joint sessions with the MDM specialists.
To learn more, view Log Collection.
User Coaching on iOS NSClient
User Coaching notification is now supported on Netskope Client for iOS.
You can configure Real-Time Policies to create rules for actions like login attempts and edits. When a user tries an action configured in a Real-Time Policy, they receive in-app notifications restricting permission to perform it. After the administrator gets these notifications, they can Allow, Block, or Report a false positive with justification.

To learn more, view User Alerts for iOS.
Supported minimum Client version: 137.0.1
To learn more, view Netskope Client for iOS.
Device Tags for Steering Configuration and Device Classification in macOS, Linux, and Android
Device Tags is now supported for macOS, Linux, Android platforms. This was earlier available for Windows and iOS in version 134.0.5. Device Tags facilitates administrators to define a tag for a device or group of devices and that can be leveraged to add a tag-based steering policy or device classification rule.
Supported OS: macOS, Linux, and Android (137.0.1), Windows and iOS (134.0.5)
Supported minimum Client version: 137.0.1 (for macOS, Linux, and Android)
To learn more, view Devices.
Support for ChromeOS 147
Netskope Client now supports ChromeOS version 147.
Supported minimum Client version: 137.0.0
To learn more, view Netskope Client Supported OS and Platform.
New DEMAgent Service
A new DEMAgent service will be installed as a part of the 137.0.1 Netskope Client version for Windows platforms. The service will only be active and registered if the Netskope tenant has the DEMAgent BETA flag active. If the BETA flag is active the DEMAgent.exe child process of the Netskope Client will be visible on the endpoint.
General Availability of Secure Enrollment Token Expiration Email Notification
Secure Enrollment token expiration was introduced as a Beta feature in version 136.0.0. The option will now be available for all tenants.
Token expiration Email notification automates email alerts for tenant administrators to notify them when Secure Enrollment tokens are approaching their expiration date. With the implementation of this feature, it helps protect against Netskope Client installation failures caused by expired tokens.
To learn more: Email Notification.
General Availability of On-Prem Detection WebUI Modification
In version 131.0.0, the On-Premises Detection was moved from Netskope Client > Client Configuration to Traffic Steering > Steering Configuration. This webUI update was available only as a Beta option. This is now available for all tenants.
The change was done to:
-
Enhance the ease of use for this option.
-
Mitigate configuration management complexities arising from mismatches between the Client and Steering configurations due to misaligned Organization Units or User Groups.
-
Support multiple On-prem configurations per steering policy (maximum 3).
Prerequisites:
-
Enable Dynamic Steering
-
Provide Match Criteria in Steering Configuration
Supported minimum Client version: 131.0.0
To learn more, view Enable Dynamic Steering.
General Availability of Zone Selection Based on User Identity
This feature was available as Beta in version 135.0.0. This will be now available for all tenants.
Using the Zone Selection option, the administrator can select China Elite zone in the Client Configuration.
To learn more, view Zone Selection Based on User Identity.
Supported minimum Client version: 135.0.0
138.0.0
Enhanced Selection for Golden Monthly Releases
This enhancement focus on the Upgrade Client automatically to a specific Client version option in the Client Configuration profile include all supported monthly and golden releases, specifically adding visibility and access to hotfix (dot) versions.
Benefits
- Granular Version Control: Provides administrators with the flexibility to pin users to a specific hotfix version (for example, 135.1.2) rather than just the major release.
- Operational Precision: Simplifies the upgrade workflow by listing all available and supported versions in the dropdown for precise version selection.
To learn more, view Upgrade Client to a Specific release version.
Pagination in Devices WebUI
With version 138.0.0, the Select All option supports upto 1000 devices on the Devices webUI.
Devices WebUI Improvements
The webUI enhancements were introduced as a Beta feature in version 134.0.0. This is now available for all tenants.
In version 134.0.0, Netskope upgraded the device management page to a new version 2 (v2) for a better experience.
Supported minimum Client version: 134.0.0
To learn more, view Devices.
Here is the list of fixed issues between versions 135.0.0 and 138.0.0.
Here is the list of known issues between versions 135.0.0 and 138.0.0.
| Issue Number | Description |
|---|---|
| 135.0.0 | |
| 880058 | The Netskope Client for macOS disables intermittently during sleep, wake, or reboot. Rebooting the system resolves the issue. |
| 135.1.4 | |
| 880058 | The Netskope Client for macOS disables intermittently during sleep, wake, or reboot. Rebooting the system resolves the issue. |
| 136.1.0 | |
| 961429 | Netskope Client prompted the user to enter a password after selecting Disable All Client Services even when there was no Master Password configured in the Client Configuration. |
| 137.1.3 | |
| 996181 | Netskope client measures CPU usage for the DEM dashboard using the "Processor Time" performance counter, while Task Manager uses the "Processor Utility" counter. On modern hardware with Intel Turbo Boost or AMD Precision Boost, these counters can report significantly different values for the same workload. As a result, CPU usage shown in Task Manager can exceed the value reported by the Netskope client on the DEM dashboard. |
| 138.0.0 | |
| 996181 | Netskope Client measures CPU usage for the DEM dashboard using the "Processor Time" performance counter, while Task Manager uses the "Processor Utility" counter. On modern hardware with Intel Turbo Boost or AMD Precision Boost, these counters can report significantly different values for the same workload. As a result, CPU usage shown in Task Manager can exceed the value reported by the Netskope client on the DEM dashboard. |


