Device Protection & Netskope for Mac
This guide explains how to configure your Netskope Steering Configuration so that Aikido Device Protection works reliably alongside Netskope.
These instructions are for macOS only! Applying these for Windows can cause issues.
Why This Is Needed
Device Protection inspects and protects software supply chain traffic, the connections your developers make to package registries (npm, PyPI, Maven, NuGet, Go) and developer tool marketplaces (Visual Studio, Cursor, Chrome Web Store), as well as Aikido's own protection services.
When both a corporate VPN/ZTNA and Aikido Device Protection attempt to steer or inspect the same traffic, the two can conflict, leading to unreliable behavior. To avoid this, you should configure VPN/ZTNA to bypass (exclude) the domains that Device Protection handles.
Steps
Log in to the Netskope Admin Console.
Navigate to Settings → Security Cloud Platform → Steering Configuration.
Click New Steering Configuration (do not edit the Default tenant config) and assign a new name e.g. "macOS tenant config".
Under Match Criteria, set OS Family = macOS (leave User Group/OU = Any, or scope it to the same group your Default config covers). This is what restricts the bypass to Macs.
Under Steered Traffic, mirror your Default config so Mac steering is unchanged. This typically includes All Traffic (HTTP/HTTPS and Non-web) and All Private App Segments.
Click the 3 dots for settings on the relevant Steering Configuration (Config) profile you want to modify. Open Edit Configuration → Traffic Steering and make sure "Bypass exception traffic at:" is set to Client.
After you've checked this, enter the profile.
Open the Exceptions tab.
Click New Exception → Domains.
Enter the domains listed below (one per line, or as supported by your version of the interface).
Save the configuration. Changes typically propagate in 1 hour.
Domains to Exclude
These are the domains Aikido Device Protection intercepts. Package registries and developer tool marketplaces are always intercepted. AI provider domains are only intercepted when AI Usage monitoring is enabled.
Only intercepted when AI Usage monitoring is enabled.
Last updated
Was this helpful?