Skip to content
Notifications
Clear all

Anyone using Netskope with Office 365 for a 500-seat org?

6 Posts
6 Users
0 Reactions
23 Views
(@cloud_infra_rookie)
Noble Member
Joined: 4 months ago
Posts: 552
Topic starter   [#26953]

Hi everyone! I'm exploring SASE/SSE options for my company. We're about 500 users, all on Microsoft 365 (Teams, SharePoint, OneDrive, the usual suite).

We're currently using a traditional firewall with basic URL filtering, but it doesn't feel secure enough for all the cloud app traffic now. Netskope keeps coming up.

For those using it at a similar scale:
- How was the setup process for Office 365 specifically? Did you have to deploy clients to every device?
- Does it play nicely with Azure AD/Entra ID for policies?
- Any big surprises with performance or user impact, especially on Teams calls?

Just trying to understand the real-world admin experience before we dive deeper. Thanks! 😊



   
Quote
(@backend_latency_queen)
Honorable Member
Joined: 4 months ago
Posts: 613
 

>Does it play nicely with Azure AD/Entra ID for policies?

The integration is solid for policy assignment. You can sync user groups from Entra ID directly, which simplifies things. Where you need to be careful is with conditional access scenarios that rely on device compliance - the Netskope client can sometimes report device posture in a way that creates unexpected loops. Test those flows in a pilot group first.

On your performance question for Teams, there's a latency hit if your traffic steering isn't optimized. The client adds a hop. We saw about 8-12ms additional latency on media packets until we adjusted the regional steering settings. It wasn't a deal-breaker for us, but users in video calls with weak WiFi did notice occasional jitter.


sub-100ms or bust


   
ReplyQuote
(@darrenk)
Honorable Member
Joined: 3 months ago
Posts: 392
 

The user181 point about conditional access loops is real, we had that too. For setup, yes, you'll deploy the client to all devices, but their templated installer made it pretty smooth for us.

We didn't see the same latency hit they did on Teams, maybe we got lucky with our PoP location. But definitely plan for some tuning time on those regional settings to get it right.


dk


   
ReplyQuote
(@ginar)
Reputable Member
Joined: 3 months ago
Posts: 289
 

The biggest setup hurdle isn't the client deployment, it's the policy exceptions. Netskope will want to inspect everything, and Teams/SharePoint are insanely chatty. If you don't meticulously carve out the right subdomains and IPs for optimal routing, you'll tank performance. Their own documentation on this is a moving target, so prepare for a lot of trial and error.

And yes, you'll deploy a client to every device. That's the whole model. The real hidden cost is the ongoing management overhead of that client fleet. Version updates break things quietly, and your help desk becomes an endpoint troubleshooting team.


Trust but verify.


   
ReplyQuote
(@bookworm42)
Reputable Member
Joined: 3 months ago
Posts: 378
 

Good to see you're doing this research up front. At your scale, the points about Teams performance and conditional access loops are your two biggest risks.

I'd add one more critical thing for setup: you must create a separate, prioritized policy set for Microsoft 365 traffic before you turn on any broad inspection rules. If you don't, your initial rollout will be a flood of help desk tickets from users who can't access SharePoint or their OneDrive files. Their traffic gets decrypted, inspected, and reassembled, and if the policy engine isn't tuned for Microsoft's specific protocols first, it breaks.

The Entra ID sync works, but treat it as a one-way feed for user groups. Don't try to use Netskope as a conditional access decision point for device compliance - that's where the loops happen.



   
ReplyQuote
(@cloud_ops_learner)
Honorable Member
Joined: 4 months ago
Posts: 419
 

I'm looking at implementing Netskope too for a smaller setup. All these replies about Teams latency and conditional access loops are super helpful.

But I'm still fuzzy on something basic. You mentioned needing to carve out subdomains and IPs. Does that mean you're basically building a giant allow list for Office 365 traffic first, before any security policies kick in? Doesn't that defeat the purpose of inspecting the traffic? How do you find a balance?


Still learning


   
ReplyQuote