Skip to content
Notifications
Clear all

Help: Netskope's Cloud Registry is missing half our AWS accounts. Support is slow.

3 Posts
3 Users
0 Reactions
27 Views
(@jasonk)
Estimable Member
Joined: 3 months ago
Posts: 65
Topic starter   [#15815]

Hey everyone, hoping to get some advice or see if others are hitting the same wall. We’ve been rolling out Netskope more broadly for our cloud security posture, and I’ve hit a major snag with the Cloud Registry.

The setup seemed straightforward—connected our AWS organization, expected to see all linked accounts populate. But it’s only discovering about half of them. The missing ones aren’t new or special; they’re standard member accounts that should be visible. I’ve double-checked the IAM cross-account role and the SCPs, and everything looks correct on the AWS side.

So far, my experience with support has been… slow. A lot of back-and-forth asking for the same screenshots and logs, with no real root cause or ETA on a fix. It’s been over a week.

Has anyone else dealt with this? I’m curious about:
* Any specific gotchas in the connector config I might have missed?
* Whether there’s a delay or sync cycle that isn’t documented well?
* If you found a workaround to force a full re-scan or manual addition?

Really eager to get this working properly. The visibility gap is a big problem for our compliance checks. Thanks in advance for any insights!



   
Quote
(@davek)
Reputable Member
Joined: 2 months ago
Posts: 281
 

I've seen this exact issue before, and the culprit is usually one of two things that aren't obvious in the initial config. Since you've validated the cross-account role and SCPs, I'd look next at the Service Control Policies on the *Organizational Units* where the missing accounts reside. A Deny on `organizations:ListAccounts` or `organizations:DescribeAccount` at the OU level would explain the partial discovery.

On the Netskope side, there's a known but poorly documented throttle in their API polling for large organizations. If you have more than 100 accounts, the initial sync can fail silently for batches of accounts. The workaround isn't manual addition, but to trigger a full re-onboarding of the connector. You'll need to delete the cloud connector in the Netskope UI and recreate it, which forces a fresh inventory pull.

Have you checked the Cloud Registry activity logs for specific error codes? Look for entries like `FailedToAssumeRole` or `AccessDeniedListingAccounts` - they sometimes appear only for the failed accounts, not as a global connector error.


CPU cycles matter


   
ReplyQuote
(@cloud_watcher_99)
Prominent Member
Joined: 4 months ago
Posts: 668
 

Great point about the OU-level SCPs. That one's bitten me with other tools before, too, because you're so focused on the root org policy.

I can second the throttle issue with larger orgs, but I'd warn that deleting and recreating the connector isn't always a clean reset. Last time I did that, it orphaned some historical data and we had to open a ticket to prune the old inventory anyway. Might be better to ask support to manually bump the API rate limit for your tenant first, if you can get them to move faster.

Did your missing accounts ever show up after a re-onboard, or did you have to get the throttle adjusted?


cost first, then scale


   
ReplyQuote