Major New Features
User Identity Enhancements
Our integration with Okta Universal Directory and Netskope One DSPM Employee Management has been enhanced to support the following capabilities.
Ability to synchronize Employees by Okta Groups
In prior versions, all employees within your Okta Universal Directory would be synced to Netskope One DSPM. Now you can limit the integration to specific Okta Groups, so that you can control which employees are synchronized to Netskope One DSPM.
Highlighting Un-Linked Database Users
You can configure your Okta / Netskope One DSPM employee field mappings to also provide us with an Expected User Name per employee. When mapped, Netskope One DSPM will automatically match Database Usernames we’ve discover while scanning your connected Data Stores to the Expected User Name . Any discovered Database Users that are not automatically matched are identifiable as “ghost users” — stale and potential threats which you can highlight and investigate further.
Manually Map Unlinked DB Users to Real Employees
By default, the same Database Usernames discovered when scanning your Data Stores are grouped and treated as the same Employee. However, we also allow you to manually link these in the event the same Employee has different Database Usernames configured on separate databases.
You can even map multiple Database Usernames-and-Data Store combinations to an individual Employee, if desired. When multiple Database Usernames are mapped to the same Employee, their Risk Scores and other information (privileges, queries, alerts, etc.) are aggregated in the User Assessment details screen.
In-Product Self-Service Upgrades
For our AMI deployment mode, you can now initiate upgrades from within the Netskope One DSPM UI itself. This is in addition to our current CLI method, but it permits customers lacking CLI access to control when to upgrade their instance.
When a new release is available, Super Admin will receive notifications via in-app banners and System Notification messages. The success/failure of the upgrade is also captured in the System Notifications.
Upgrades for a SaaS instance will continue to be managed by Netskope One DSPM as new releases become available.
Ingesting GCP Policy Tags
Netskope One DSPM now supports the ability to ingest GCP Policy Taxonomies and their Tag associations to GCP data store fields. These are associated to the respective Classification Fields within Netskope One DSPM’s Classification Management feature. With this capability, you can now quickly assess if any Sensitive Fields that must have a GCP Policy Tag is missing that business context, create Classification Policies which are future-proof, and be notified if new fields created in existing GCP data stores violated your business policies.
SAP HANA Support for Classification
We have expanded our connector coverage to SAP HANA. We can now classify sensitive data stored in your SAP HANA Cloud environment.