Views:
You can chain Netskope with TrendAI Vision One™ AI Secure Access to add AI-specific inspection and access control to your existing Netskope deployment. Configure Netskope to forward generative AI (GenAI) traffic — for example, traffic destined for Claude, Gemini, or OpenAI applications — to TrendAI Vision One™ AI Secure Access for inspection and policy enforcement. Netskope continues to handle and inspect all other general web traffic.
End users authenticate with TrendAI Vision One™ through the standard browser-based authentication flow (treated as a roaming, default proxy case) when their GenAI traffic is forwarded.
Before you begin, ensure the following are in place:
  • An identity provider (IdP) integration — Microsoft Entra ID (Azure AD) or an equivalent SAML/OIDC-compatible IdP — connected to both your Netskope tenant and TrendAI Vision One™. This is required for user authentication when traffic is intercepted by the Internet Access Gateway.
  • A Netskope tenant with an active inline CASB/SWG license and traffic steering in place (Netskope One Client, IPsec/GRE tunnel, or Explicit Proxy).
  • The Zero Trust Secure Access – Internet Access service activated in TrendAI Vision One™.
  • Administrative access to both the Netskope and TrendAI Vision One™ consoles.

Procedure

  1. In the Netskope tenant, configure an upstream proxy pointing to the TrendAI Vision One™ Internet Access Gateway.
    1. Go to SettingsSecurity Cloud PlatformUpstream Proxy, and click Add Proxy.
    2. Enter a Proxy Name (for example, ZTSA-IAG).
    3. For Host, enter proxy.ztsa-iag.trendmicro.com.
    4. For Port, enter 80.
    5. For Type, select HTTP Proxy.
    6. Click Save.
  2. Download the TrendAI Vision One™ cloud gateway certificate.
    See Deploying the built-in CA certificate for the download procedure. Download the cloud_gateway.cer certificate.
  3. Rename the downloaded certificate file so that it has a .pem extension (for example, cloud_gateway.pem).
    The file contents do not change; only the extension is required for the Netskope import process.
  4. In the Netskope tenant, import the certificate as a trusted certificate authority (CA).
    1. Go to SettingsSecurity Cloud PlatformCertificate Management, and click the Trusted CA tab.
    2. Click Add Certificate.
    3. Enter a descriptive name, for example ZTSA-IAG Root CA.
    4. Upload the renamed .pem file.
    5. Click Save.
    Note
    Note
    If the certificate is not trusted, Netskope displays SSL errors when forwarding HTTPS traffic to the upstream proxy because it cannot verify the proxy's certificate during the TLS handshake.
  5. In the Netskope tenant, create a policy to forward generative AI (GenAI) traffic to the upstream proxy.
    1. Go to PoliciesReal-time Protection, and click New Policy.
    2. Set the policy type to Forward to Proxy.
    3. Under Source, select the users, user groups, or organizational units to include in the policy.
    4. Under Destination, select one of the following match criteria:
      • Category: select the built-in Generative AI category to match traffic for all supported GenAI applications. Netskope automatically adds new AI applications to this category.
      • Cloud App: select individual applications, such as ChatGPT, Google Gemini, or Microsoft Copilot, for more precise control.
      • App Instance: apply the policy to a specific instance of an application, for example a sanctioned corporate account versus a personal account.
    5. Under Action, select Forward to Proxy and choose the upstream proxy you configured in Step 1.
    6. Name the policy, set the policy order, and click Save.
  6. Verify the integration.
    1. From a device with traffic steered through Netskope, open a browser and go to a GenAI site, for example https://chatgpt.com.
    2. When the TrendAI Vision One™ Internet Access Gateway intercepts the request and prompts for authentication, sign in with your corporate credentials through the configured identity provider.
    3. Confirm that you are redirected to the destination site and access is granted.

Next steps

Create or confirm your AI Secure Access rules so that TrendAI Vision One™ can enforce inspection and access control policy on the forwarded traffic. See Creating an AI Service Access rule.