These tools appear in your agent automatically once you configure Microsoft 365, Active Directory, or Exchange permissions on the workflow’s Integrations tab — there’s no separate toggle in the tool list. See Microsoft 365 integration for the permission model.
The Tools
In hybrid environments Neo routes each operation to the right place — for example, it makes the password change on-prem and triggers an Azure AD Connect sync so it propagates to the cloud. For hybrid tenants without AD Connect sync (“Hybrid (no AD Connect sync)” in Company Settings), Neo writes to both directories directly instead — same change, same values, applied to on-prem AD and Entra ID independently.
What Agents Can Do
User lifecycle
User lifecycle
Create, update, disable, enable, and delete users in Entra ID or on-prem Active Directory. Assign managers, set job titles and departments, and update user properties.
Passwords & security
Passwords & security
Reset passwords, unlock accounts, revoke sign-in sessions, reset MFA, and block or unblock sign-in. In hybrid environments, Neo makes the change on-prem and syncs it to the cloud automatically.
Licensing
Licensing
Assign and remove Microsoft 365 licenses, and look up friendly license names from SKU IDs. Read each subscription’s renewal or expiration date, status, trial flag, and seat total straight from Microsoft — including SKUs you did not buy through a marketplace. To add or remove license seats through a marketplace (Pax8, Partner Center, and others), see the dedicated Change License Seats and List License Subscriptions tools.Free and self-service SKUs publish no renewal date, and a subscription bought outside the tenant’s own purchase channel may not appear. Ask the agent to check the Microsoft 365 admin center for those.
Groups
Groups
Add and remove users from security groups, Microsoft 365 groups, distribution lists, and mail-enabled security groups. Search and list groups across Entra ID and on-prem AD.
Directory roles
Directory roles
Assign and remove Entra ID directory roles (Global Admin, Exchange Admin, User Admin, and so on) and view a user’s current role assignments.
Mailboxes
Mailboxes
Convert mailboxes to shared, create and delete shared mailboxes, configure delegation (full access, send-as, send-on-behalf), and set up or remove email forwarding. Works with Exchange Online and on-prem Exchange Server.
Conditional Access
Conditional Access
List, view, create, update, and delete Conditional Access policies. Destructive changes always require technician approval, regardless of workflow settings.
Devices
Devices
View user devices in Intune; remote wipe and retire mobile devices. Device deletion is always blocked for safety.
App registrations & OAuth governance
App registrations & OAuth governance
Review app registrations, service principals, and OAuth consent grants — app inventory, third-party app audits, client secret expiry checks. Create dedicated app registrations (for example, a send-only Mail.Send app for a notifications mailbox), and rotate client secrets on existing app registrations after the customer re-grants Neo access. Every write requires technician approval. Admin consent always stays with your technician — Neo prepares the consent link, a Global Admin clicks it. Client secret values are never exposed to the agent or written to ticket notes — when Neo creates a secret, the value is pushed to a one-time secure link (the same self-destructing link used for password resets) that the agent shares for retrieval.
On-prem Active Directory & Exchange Server
On-prem Active Directory & Exchange Server
Full AD and Exchange Server management via your RMM: user and computer accounts, organizational units, group operations, infrastructure queries, mailbox and recipient management, mail flow, and Entra Connect sync triggers.
Permissions & Safety
Each Microsoft integration is split into permission groups, and every group has an access level:
You can require technician approval on any permission group, and some destructive operations (deleting a user, wiping a device) always require approval even when the group doesn’t. A few operations (deleting a domain, deleting a device) are blocked entirely.
Quick-start profiles — Read Only, Helpdesk, IT Admin, Full Automation — configure every permission group at once.
Service Health is read only — Microsoft exposes no write for it — and a client company
connected before 3 September 2026 needs one Microsoft permission step before its first call
succeeds, which differs for direct-consent and GDAP companies. See Service
Health.
A group badged Coming Soon is not released: the Microsoft access behind it has not been granted
to Neo, so it stays Disabled and cannot be switched on. No group is in that state today. See
Coming Soon permission groups.
Test Mode
With test mode on, an agent reads Microsoft 365 and Active Directory exactly as it would on a real run. Looking up a user, listing groups, checking which licences you have left — all of it reaches your live tenant and returns real data, so the agent reasons from the same facts either way. PowerShell is the one exception. An Exchange or Active Directory script the agent writes itself does not run in test mode, even one that only reads. A script can change things in more ways than Neo can rule out from its text, so during a rehearsal Neo holds every script back rather than guess. The agent still reads through Microsoft Graph and the built-in Active Directory lookups, which is where most of what it needs comes from. What test mode holds back is every change: creating or updating a user, assigning a licence, editing group or role membership, mailbox and device changes, and every PowerShell script. A blocked Microsoft Graph change is recorded by its operation only, such as creating a user, never its values, because these requests can carry passwords and other secrets. Where Neo sends that record, and when it doesn’t, is set by Report test results via.Configure Microsoft 365 permissions
Full details on Graph, Active Directory, and Exchange permission groups, access levels, and quick-start profiles.
