Skip to content
Notifications
Clear all

Why is Netskope blocking legitimate cloud storage apps?

1 Posts
1 Users
0 Reactions
0 Views
(@auditor_abby)
Estimable Member
Joined: 4 months ago
Posts: 111
Topic starter   [#9308]

We're evaluating Netskope for our CASB rollout, and during the POC it's consistently flagging legitimate cloud storage applications as high-risk. This is happening with both sanctioned apps like our enterprise Box tenant and unsanctioned but common apps like pCloud. The traffic is being blocked under the "Cloud Storage - High Risk" policy.

Our initial review shows:
* The activity is coming from managed corporate devices with our client certificate installed.
* Users are authenticated via SAML to these services.
* The data being uploaded is non-sensitive project files (confirmed via DLP preview logs).

This creates an operational issue where we either have to whitelist entire application categories—defeating the purpose of granular control—or constantly adjust policies based on helpdesk tickets.

Has anyone else dealt with this? I need to understand if this is a configuration issue on our end or a known limitation with their application database and risk scoring. Specifically:

* What criteria is Netskope using to classify these as high risk? Is it solely based on the *category* without factoring in user, device, or data context?
* Are there log fields or specific API calls I should be auditing to see the exact trigger?
* Is there a way to build an exception policy that considers user identity and data classification, not just the app instance?

Our compliance framework requires us to log the justification for any blocking rule, and "the vendor's database says so" isn't going to hold up. I need to see the actual logic.


Where is your SOC 2?


   
Quote