Skip to main content
It suits MSPs who manage their customers in CIPP and have not given Neo its own Microsoft access: the agent acts with the access your CIPP instance already has.
Automatically enabled when you configure CIPP permissions in your agent workflow.

What It Does

  • Users and groups: find a user, read their groups, devices, MFA registration and sign-ins; revoke sessions, block or allow sign-in, remove MFA methods, set a password, edit or create a user, change group membership, restore a deleted user, offboard or delete a user
  • Mailboxes: read mailbox details, permissions, rules, forwarding and out of office, and run a message trace; grant mailbox or calendar access, set out of office, set forwarding, convert to a shared mailbox, hide from the address list, turn on the archive, manage inbox rules, unblock a restricted sender
  • Email security: list quarantined mail and release, deny or delete it; read spam, phishing and malware policies and transport rules; add and remove Tenant Allow/Block List entries
  • Devices: read Intune and Autopilot devices, compliance, Defender state and apps; sync, restart, scan, lock, wipe or retire a device; disable or delete a device in Entra ID
  • Security and sign-ins: read Defender alerts and incidents, sign-ins and Conditional Access policies; run a business email compromise check and contain the account; set an alert’s status; dismiss user risk; change per-user MFA
  • SharePoint and Teams: read sites, members, sharing and storage; add or remove site members and OneDrive access
  • Tenants: find the customer’s tenant, and read its domains, licences, service health and Secure Score
  • Passwords and keys (a permission of its own): read a device’s LAPS password or BitLocker / FileVault key, reset a password and read the new one, issue a Temporary Access Pass
  • Raw Graph and Exchange (a permission of its own, every call approved): any Microsoft Graph read or Exchange Get- / Search- cmdlet, for a record nothing above covers

Passwords, keys and raw requests

  • Passwords and keys reach an agent only through the Passwords & Keys group. Turn it on for agents that hand credentials to your team, such as an internal chat agent a technician asks for a LAPS password. The agent delivers a secret the way your instructions say (an internal note, SMS), or by default through a one-time secure link; it never writes the secret into its answer or a customer-facing note. A password that another call reports, such as offboarding or account containment, is removed before the agent sees it.
  • Raw Graph and Exchange requests always ask a technician, reads included, because a request can name any record CIPP can read, secrets included. Use them as a last resort; the other groups, or Neo’s own Microsoft 365 integration, have a permission for each kind of record.

What Neo never does through CIPP

  • Change every tenant at once. Any POST sent to AllTenants is refused, a change or a message trace, so the agent acts in one customer’s tenant at a time. A GET read may cover every tenant.
  • Change CIPP or tenant-wide configuration. CIPP settings, standards, Conditional Access policies, Intune policies and GDAP stay with your technicians in CIPP.

Permission Groups

A device wipe, retire, passcode reset, or any device action other than sync, restart, Defender scan or signature update, local admin password rotation, rename, lock, locate or primary user change always asks a technician first, whatever the group’s setting. So does deleting a device from Entra ID; disabling or enabling one follows the group.

Access profiles

Setup

See Connecting CIPP to Neo.