> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# CIPP API

> Manage your customers' Microsoft 365 tenants through your CIPP instance: users, mailboxes, quarantine, devices, security alerts and SharePoint access

It suits MSPs who manage their customers in [CIPP](https://cipp.app) and have not given Neo its own Microsoft access: the agent acts with the access your CIPP instance already has.

<Info>
  Automatically enabled when you configure CIPP permissions in your agent workflow.
</Info>

## What It Does

* **Users and groups:** find a user, read their groups, devices, MFA registration and sign-ins; revoke sessions, block or allow sign-in, remove MFA methods, set a password, edit or create a user, change group membership, restore a deleted user, offboard or delete a user
* **Mailboxes:** read mailbox details, permissions, rules, forwarding and out of office, and run a message trace; grant mailbox or calendar access, set out of office, set forwarding, convert to a shared mailbox, hide from the address list, turn on the archive, manage inbox rules, unblock a restricted sender
* **Email security:** list quarantined mail and release, deny or delete it; read spam, phishing and malware policies and transport rules; add and remove Tenant Allow/Block List entries
* **Devices:** read Intune and Autopilot devices, compliance, Defender state and apps; sync, restart, scan, lock, wipe or retire a device; disable or delete a device in Entra ID
* **Security and sign-ins:** read Defender alerts and incidents, sign-ins and Conditional Access policies; run a business email compromise check and contain the account; set an alert's status; dismiss user risk; change per-user MFA
* **SharePoint and Teams:** read sites, members, sharing and storage; add or remove site members and OneDrive access
* **Tenants:** find the customer's tenant, and read its domains, licences, service health and Secure Score
* **Passwords and keys** (a permission of its own): read a device's LAPS password or BitLocker / FileVault key, reset a password and read the new one, issue a Temporary Access Pass
* **Raw Graph and Exchange** (a permission of its own, every call approved): any Microsoft Graph read or Exchange `Get-` / `Search-` cmdlet, for a record nothing above covers

## Passwords, keys and raw requests

* **Passwords and keys reach an agent only through the Passwords & Keys group.** Turn it on for agents that hand credentials to your team, such as an internal chat agent a technician asks for a LAPS password. The agent delivers a secret the way your instructions say (an internal note, SMS), or by default through a one-time secure link; it never writes the secret into its answer or a customer-facing note. A password that another call reports, such as offboarding or account containment, is removed before the agent sees it.
* **Raw Graph and Exchange requests always ask a technician**, reads included, because a request can name any record CIPP can read, secrets included. Use them as a last resort; the other groups, or Neo's own [Microsoft 365 integration](/integrations/m365/intro), have a permission for each kind of record.

## What Neo never does through CIPP

* **Change every tenant at once.** Any POST sent to `AllTenants` is refused, a change or a message trace, so the agent acts in one customer's tenant at a time. A GET read may cover every tenant.
* **Change CIPP or tenant-wide configuration.** CIPP settings, standards, Conditional Access policies, Intune policies and GDAP stay with your technicians in CIPP.

## Permission Groups

| Group | Access levels | Covers |
| - | - | - |
| Tenants & Licences | Disabled, Read Only | Tenants, domains, licences, service health, Secure Score |
| Users & Groups | Disabled, Read Only, Read/Write | Users, groups, MFA registration, roles, sign-in logs, and the account changes above |
| Mailboxes | Disabled, Read Only, Read/Write | Mailboxes, permissions, rules, forwarding, out of office, message trace, shared mailboxes, contacts |
| Email Security | Disabled, Read Only, Read/Write | Quarantine, Tenant Allow/Block List, spam and phishing policies, transport rules |
| Devices | Disabled, Read Only, Read/Write | Intune and Autopilot devices, device actions, Entra ID devices |
| Security & Sign-ins | Disabled, Read Only, Read/Write | Defender alerts and incidents, sign-ins, Conditional Access, business email compromise, user risk, per-user MFA |
| SharePoint & Teams | Disabled, Read Only, Read/Write | Sites, members, OneDrive access, Teams |
| Passwords & Keys | Disabled, Read Only, Read/Write | Read Only reads LAPS passwords and BitLocker / FileVault keys; Read/Write also resets passwords and issues Temporary Access Passes |
| Raw Graph & Exchange | Disabled, Read/Write | Any Graph read or Exchange `Get-` / `Search-` cmdlet; every call asks a technician |

A device wipe, retire, passcode reset, or any device action other than sync, restart, Defender scan or signature update, local admin password rotation, rename, lock, locate or primary user change always asks a technician first, whatever the group's setting. So does deleting a device from Entra ID; disabling or enabling one follows the group.

### Access profiles

| Profile | What it does |
| - | - |
| Read Only | Reads everything except passwords and keys, changes nothing; raw requests off |
| Helpdesk | Mailbox changes and LAPS / BitLocker key reads on its own; account and device changes and password resets ask a technician first; read-only elsewhere; raw requests off |
| IT Admin | Users, mailboxes, devices, SharePoint and passwords on its own; email security and security changes (allow entries, MFA, user risk, alert status) and raw requests ask a technician first |
| Full Automation | Every supported change with no approval, except the device actions and device deletion above and raw requests |

## Setup

See [Connecting CIPP to Neo](/integrations/cipp/connecting-to-neo).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.