Automatically enabled when you configure Proofpoint Essentials permissions in your agent workflow.
What It Does
- Find the client organization from the Organization Mapping, the requester’s email domain, or the list of organizations under your partner account
- Read and add to safe and block lists, for a whole organization, one user or one group
- Look up, create and update users and aliases
- Check a domain’s mail routing health, verify domains and manage DKIM keys
- Read and change filtering features, external-sender tagging and Azure AD user sync
- Read licence counts and mail flow statistics
What It Cannot Do
Neo sends only the operations in Proofpoint’s published Essentials API document, and that document has no quarantine endpoint. An agent cannot search for, read or release a held message. When a ticket asks for a release, the agent adds the sender if it may, and says that the held message must be released from the user’s quarantine digest email or in the Proofpoint Essentials console.How the agent adds a safe sender
The agent picks the narrowest entry that meets the request: the exact address rather than the whole domain, and the one user rather than the whole organization, unless the ticket or your custom instructions say otherwise. It never allows a whole public mail domain such asgmail.com.
Neo reads the list before and after every addition and restores any earlier entry the change removed. If an entry cannot be restored, the agent reports the list as it was, so a technician can restore it in the Proofpoint console. The agent never clears a list to remove one entry.
Permission Groups
Creating a login token that signs in as another user is never allowed.
