Skip to main content
You connect CIPP once at the MSP level, then turn it on per agent.

1. Create an API client in CIPP

1

Open CIPP-API

In CIPP, open CIPP > Integrations and click CIPP-API.
2

Create the client

Click Actions > Create New Client and name it “Neo”. Turn Enabled on.
  • Role: a role that allows what you want Neo to do. CIPP’s readonly role is enough for an agent that only reads; an agent that makes changes needs editor or a custom role.
  • Allowed IP Ranges: leave it at Any, or add Neo’s IP addresses.
Submit the form and copy the Application Secret. CIPP shows it only once.
3

Save to Azure

Click Actions > Save to Azure. CIPP restarts, so give it a few minutes before the next step.
4

Copy the connection details

The CIPP-API page now shows the API URL and the Tenant ID. Copy them, and the client’s Application ID from the table.

2. Add the credential in Neo

1

Open Integrations

In the Neo Dashboard, open Integrations and find the CIPP card, under Identity & Workspace.
2

Save the credential

Paste the API URL, the Tenant ID, the Application ID and the Application Secret, and click Save. Neo signs in to Microsoft with them and lists your CIPP tenants before it saves, so a wrong value is rejected straight away with the reason. The Organization Mapping tab fills after the save, and again on each nightly PSA sync.
The API URL is the address on the CIPP-API page, like https://cippabcde.azurewebsites.net. The address you open CIPP in is a different one and does not work here.

3. Turn CIPP on per agent

Open the agent, go to the Integrations section, and configure the CIPP block. Pick an access profile, or set each area:

Example: unblock a user who is locked out

Give an agent that runs on your Microsoft 365 tickets the CIPP Helpdesk profile and instructions like these:
When a user cannot sign in, look the user up in CIPP. If sign-in is blocked, check the sign-in log for a reason. If there is no sign of compromise, allow sign-in again and add a note with what you found. If the sign-ins look suspicious, run a business email compromise check and assign the ticket to the security queue with the result.
With Helpdesk, the account change waits for a technician’s approval.

Troubleshooting