
This Solution Guide covers the comprehensive integration between Netskope and Microsoft. Topics include the various integration points where Netskope and Microsoft exchange the necessary data and API commands to execute required workflows for security practitioners. Note that this document does not include information on how to configure Netskope to securely enable Microsoft applications, either with API Protection, Real-time protection with or without steering or SSL bypass for inspection (this does cover setting up SMTP-based email), or CSPM/SSPM settings.
Netskope SD-WAN integrations with Advanced Microsoft Entra SSE
This guide provides a detailed walkthrough for deploying a Python script as a secure, timer-triggered Azure Function. This function automatically creates and synchronizes IPsec tunnels and BGP configurations between your Netskope SD-WAN fabric and Microsoft’s Entra Internet Access service, running every five minutes to ensure continuous, up-to-date connectivity.
Alternatively, you can leverage a template to perform the deployment without the need for the python script.
Automating Netskope One SD-WAN and Microsoft Entra SSE Integration
Sending Alerts and Events to Microsoft Sentinel using the Codeless Connector Platform
Netskope now offers a native integration with Microsoft Sentinel via the Codeless Connector Framework (originally named Codeless Connector Platform), allowing organizations to seamlessly extract all event and alert logs generated in Netskope from the Netskope RESTful API interface for use by Microsoft’s cloud-native SIEM, Sentinel.
This integration simplifies log shipping and provides a scalable, cost-efficient solution by eliminating the need for additional infrastructure like Cloud Exchange. Security teams can now gain comprehensive data insights within Microsoft Sentinel, enabling effortless setup at no additional cost (beyond Azure data storage). This direct connection empowers SOC teams with readily available Netskope data, allowing them to focus on incident response and policy changes rather than infrastructure management.
Sending Alerts and Events to Microsoft Sentinel using the Codeless Connector Platform
Netskope Event, Alert, and Web Transaction Log Streaming to Microsoft Sentinel
Netskope now offers a native integration with Microsoft Sentinel via the Microsoft Codeless Connector Framework (originally named Codeless Connector Platform), enabling organizations to use Netskope log streaming to write Netskope Web Transaction Logs into Microsoft’s cloud-native SIEM in near real-time via Azure blob storage.
Netskope log streaming pushes logs to a customer’s Storage Blob Container. When a new file (containing Web Transactions or Netskope Alerts and Events) is written, Event Grid is notified and sends the blob URI to a storage queue. Scuba workers (Microsoft Sentinel CCF Connectors) then pull data from this queue and ingest it into a Data Collection Rule, making the Netskope Web Transactions and Events logs available in a single Log Analytics table within Sentinel.
Integrate Web Transactions from Netskope Log Streaming to Microsoft Sentinel
Microsoft Purview Information Protection and Netskope DRM
Microsoft Purview Information Protection (MPIP), previously called Microsoft Information Protection (MIP), allows Netskope to read sensitivity labels on both unencrypted and encrypted files and webmail for data at rest and in motion. This enables Netskope to detect sensitive data and take action based on its Purview classification.
Additionally, MPIP’s write functionality, which is available for API Data Protection, allows Netskope to classify files that are either unlabeled or already have a label. This means it can scan content for sensitivity, and then apply or update the correct label, which is particularly useful for ensuring all files within an organization are properly classified for compliance purposes.
Microsoft Purview Information Protection and Netskope DRM
Netskope One and Microsoft Purview DLP
Netskope One for Microsoft Purview DLP is an integration that extends Microsoft Purview’s data loss prevention (DLP) capabilities. It allows organizations to use their existing Purview policies to monitor and control sensitive data that is in transit, including data shared with AI platforms, on unsanctioned cloud services, or in social media forms. By directing all network traffic through Netskope, for Netskope to then surface previously missing data to Purview for discovery and classification, the solution expands Purview’s visibility beyond applications and endpoints to include all network traffic, providing a more comprehensive view of data in motion.
Netskope One for Microsoft Purview DLP
Azure LogStreaming v1.0.0 Plugin for Log Shipper
This document explains how to set up the Azure LogStreaming v1.0.0 plugin with the Netskope Cloud Exchange platform’s Log Shipper module. This enables Log Shipper to work with logs streamed to Azure blog storage using Netskope Log Streaming service. The plugin is designed to extract the various types of Netskope data, including alerts, events, and WebTx logs, from Azure containers by using a Microsoft Azure storage account’s storage queue for extraction and further forwarding to other systems using other Log Shipper plugins.
Azure LogStreaming Plugin for Log Shipper
Microsoft Defender Cloud Apps Plugin for Log Shipper
This integration enables the transmission of events generated by Netskope to Microsoft Cloud App Security for further analysis and reporting.
Microsoft Defender Cloud Apps Plugin for Log Shipper
Microsoft Azure Sentinel Plugin for Log Shipper
Microsoft Azure Sentinel plugin for Log Shipper enables the ingestion of Netskope events and alerts into an Azure Sentinel tenant.
Microsoft Azure Sentinel Plugin for Log Shipper
Microsoft Azure Monitor Plugin for Log Shipper
Microsoft Azure Monitor Plugin for Log Shipper plugin allows you to send log data from Netskope Cloud Exchange to Azure Monitor.
Microsoft Azure Monitor Plugin for Log Shipper
Microsoft Azure Storage Plugin for Log Shipper
Microsoft Azure Cloud Storage plugin allows pushing the WebTx data and creating blobs inside the container in Azure Blob Storage.
Microsoft Azure Storage Plugin for Log Shipper
Microsoft Office 365 Endpoints Plugin for Threat Exchange
Microsoft Office 365 Endpoints Plugin for the Threat Exchange module in the Netskope Cloud Exchange platform is used to fetch URLs. Integrating this data into Cloud Exchange and a Netskope tenant allows for its automatic synchronization into web categories of our URL service. These categories are then utilized in SSL decryption policies, Real-time Protection policies, and SAML authentication bypass.
Microsoft Office 365 Endpoints Plugin for Threat Exchange
Microsoft Defender for Cloud Apps Plugin for Threat Exchange
Microsoft Defender for Cloud Apps allows for sharing of sanctioned URLs with Netskope Cloud Exchange and different other platforms. This allows you to leverage the threat intelligence to better protect your organization from cyberattacks.
Microsoft Defender for Cloud Apps Plugin for Threat Exchange
Microsoft Defender for Endpoint Plugin for Threat Exchange
Microsoft Defender ATP plugin integration with the Threat Exchange module of the Netskope Cloud Exchange platform allows for sharing of file hashes with Netskope. This allows you to leverage the threat intelligence to better protect your organization from cyberattacks.
Microsoft Defender for Endpoint Plugin for Threat Exchange
Azure AD Plugin for User Risk Exchange
Azure AD plugin for User Risk Exchange in the Netskope Cloud Exchange platform integration enables seeing multiple connected systems’ risk values for individual users and groups. The Microsoft Azure AD Risk Exchange plugin fetches users and their respective score and perform actions on them. Supported record types include Users.when users’ risk scores change, so that you can quickly respond to any potential threats.
Azure AD Plugin for User Risk Exchange
Microsoft Teams Plugin for Ticket Orchestrator
Microsoft Teams integration with the Ticket Orchestrator module of the Netskope Cloud Exchange platform allows you to send the generated alerts from different integration to Microsoft Teams with the required details.
Microsoft Teams Plugin for Ticket Orchestrator
Netskope Single Sign On with Entra ID
Netskope Single Sign On (SSO) with Microsoft is a simple and effective way to improve the security, efficiency, and manageability of your Netskope environment. By integrating Netskope with Microsoft, you can centralize user management and provide your users with a seamless login experience.
Cloud Exchange SSO with Entra ID
Cloud Exchange SSO with Microsoft is a simple and effective way to improve the security, efficiency, and manageability of your Cloud Exchange environment. By integrating Cloud Exchange with Microsoft, you can centralize user management and provide your users with a seamless login experience.
Cloud Exchange SSO with Entra ID
Netskope Azure CSPM
Netskope Azure CSPM is a cloud security posture management (CSPM) solution that helps organizations improve their security posture in Microsoft Azure. It provides continuous visibility into Azure resources and configuration, and helps organizations identify and remediate security risks.
Netskope SMTP Proxy with Microsoft O365 Exchange
Netskope SMTP Proxy with Microsoft O365 Exchange is a solution that allows organizations to scan and filter outbound email traffic before it reaches Microsoft Exchange. This can help to protect organizations from data breaches, malware infections, and other email security threats.
Netskope SMTP Proxy with Microsoft O365 Exchange
Microsoft and Netskope SSE Coexistence
Using both Microsoft and Netskope SSE solutions in tandem can provide a comprehensive and layered approach to securing an organization’s network, data, and cloud applications. Organizations can benefit from a more holistic and adaptive security approach.
Microsoft and Netskope SSE Coexistence
Netskope API Data Protection for Microsoft Office 365 Outlook
Using Netskope API Data Protection for your Microsoft Office 365 Outlook app helps organizations protect their sensitive data in Outlook. It uses APIs to scan Outlook emails and attachments for policy violations, such as the presence of sensitive data or the sharing of data with unauthorized individuals.
Netskope API Data Protection for Microsoft Office 365 Outlook
Netskope Next Generation API Data Protection for Microsoft 365 OneDrive
Netskope Next Generation API Data Protection for Microsoft 365 OneDrive helps organizations protect their sensitive data in OneDrive. It uses APIs to scan OneDrive files for policy violations, such as the presence of sensitive data or the sharing of data with unauthorized individuals.
Netskope Next Generation API Data Protection for Microsoft 365 OneDrive
Netskope Next Generation API Data Protection for Microsoft 365 Sharepoint
Netskope Next Generation API Data Protection for Microsoft 365 Sharepoint helps organizations protect their sensitive data in OneDrive. It uses APIs to scan OneDrive files for policy violations, such as the presence of sensitive data or the sharing of data with unauthorized individuals.
Netskope Next Generation API Data Protection for Microsoft 365 Sharepoint
Netskope Next Generation API Data Protection for Microsoft 365 Teams
Netskope Next Generation API Data Protection for Microsoft 365 Teams helps organizations protect their sensitive data in Teams. It uses APIs to scan Teams messages and attachments for policy violations, such as the presence of sensitive data or the sharing of data with unauthorized individuals
Netskope Next Generation API Data Protection for Microsoft 365 Teams
Netskope Next Generation API Data Protection for Microsoft 365 Yammer
Netskope Next Generation API Data Protection for Microsoft 365 Yammer helps organizations protect their sensitive data in Yammer. It uses APIs to scan Yammer messages, post and attachments for policy violations, such as the presence of sensitive data or the sharing of data with unauthorized individuals
Microsoft Viva Engage (formerly Yammer) for the Next Generation API Data Protection

