1. Create an API client in CIPP
1
Open CIPP-API
In CIPP, open CIPP > Integrations and click CIPP-API.
2
Create the client
Click Actions > Create New Client and name it “Neo”. Turn Enabled on.
- Role: a role that allows what you want Neo to do. CIPP’s
readonlyrole is enough for an agent that only reads; an agent that makes changes needseditoror a custom role. - Allowed IP Ranges: leave it at Any, or add Neo’s IP addresses.
3
Save to Azure
Click Actions > Save to Azure. CIPP restarts, so give it a few minutes before the next step.
4
Copy the connection details
The CIPP-API page now shows the API URL and the Tenant ID. Copy them, and the client’s Application ID from the table.
2. Add the credential in Neo
1
Open Integrations
In the Neo Dashboard, open Integrations and find the CIPP card, under Identity & Workspace.
2
Save the credential
Paste the API URL, the Tenant ID, the Application ID and the Application Secret, and click Save. Neo signs in to Microsoft with them and lists your CIPP tenants before it saves, so a wrong value is rejected straight away with the reason. The Organization Mapping tab fills after the save, and again on each nightly PSA sync.
The API URL is the address on the CIPP-API page, like
https://cippabcde.azurewebsites.net. The address you open CIPP in is a different one and does not work here.3. Turn CIPP on per agent
Open the agent, go to the Integrations section, and configure the CIPP block. Pick an access profile, or set each area:Example: unblock a user who is locked out
Give an agent that runs on your Microsoft 365 tickets the CIPP Helpdesk profile and instructions like these:When a user cannot sign in, look the user up in CIPP. If sign-in is blocked, check the sign-in log for a reason. If there is no sign of compromise, allow sign-in again and add a note with what you found. If the sign-ins look suspicious, run a business email compromise check and assign the ticket to the security queue with the result.With Helpdesk, the account change waits for a technician’s approval.
