> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Connecting CIPP to Neo

> Create a CIPP API client, save it in Neo and turn CIPP on for the agents that work Microsoft 365 tickets

You connect CIPP once at the MSP level, then turn it on per agent.

## 1. Create an API client in CIPP

<Steps>
  <Step title="Open CIPP-API">
    In CIPP, open **CIPP** > **Integrations** and click **CIPP-API**.
  </Step>

  <Step title="Create the client">
    Click **Actions** > **Create New Client** and name it "Neo". Turn **Enabled** on.

    * **Role:** a role that allows what you want Neo to do. CIPP's `readonly` role is enough for an agent that only reads; an agent that makes changes needs `editor` or a custom role.
    * **Allowed IP Ranges:** leave it at Any, or add [Neo's IP addresses](/integrations/ip-whitelisting).

    Submit the form and copy the **Application Secret**. CIPP shows it only once.
  </Step>

  <Step title="Save to Azure">
    Click **Actions** > **Save to Azure**. CIPP restarts, so give it a few minutes before the next step.
  </Step>

  <Step title="Copy the connection details">
    The CIPP-API page now shows the **API URL** and the **Tenant ID**. Copy them, and the client's **Application ID** from the table.
  </Step>
</Steps>

## 2. Add the credential in Neo

<Steps>
  <Step title="Open Integrations">
    In the Neo Dashboard, open **Integrations** and find the CIPP card, under Identity & Workspace.
  </Step>

  <Step title="Save the credential">
    Paste the API URL, the Tenant ID, the Application ID and the Application Secret, and click **Save**. Neo signs in to Microsoft with them and lists your CIPP tenants before it saves, so a wrong value is rejected straight away with the reason. The **Organization Mapping** tab fills after the save, and again on each nightly PSA sync.
  </Step>
</Steps>

<Note>
  The API URL is the address on the CIPP-API page, like `https://cippabcde.azurewebsites.net`. The address you open CIPP in is a different one and does not work here.
</Note>

## 3. Turn CIPP on per agent

Open the agent, go to the Integrations section, and configure the CIPP block. Pick an access profile, or set each area:

| Area | Notes |
| - | - |
| **Tenants & Licences** | Read only. Lets the agent find the customer's tenant. |
| **Users & Groups** | Account changes: sessions, sign-in, MFA, passwords, groups, onboarding and offboarding. |
| **Mailboxes** | Mailbox and calendar access, out of office, forwarding, message trace. |
| **Email Security** | Quarantine and the Tenant Allow/Block List. |
| **Devices** | Intune device actions. A wipe or retire, and deleting a device from Entra ID, always ask a technician first. |
| **Security & Sign-ins** | Defender alerts, sign-ins, business email compromise checks and containment. |
| **SharePoint & Teams** | Site membership and OneDrive access. |
| **Passwords & Keys** | LAPS passwords, BitLocker keys, password resets and Temporary Access Passes. Turn it on only for agents whose answers go to your team. |
| **Raw Graph & Exchange** | Any Graph read or Exchange cmdlet, as a last resort. Every call asks a technician. |

## Example: unblock a user who is locked out

Give an agent that runs on your Microsoft 365 tickets the CIPP **Helpdesk** profile and instructions like these:

> When a user cannot sign in, look the user up in CIPP. If sign-in is blocked, check the sign-in log for a reason. If there is no sign of compromise, allow sign-in again and add a note with what you found. If the sign-ins look suspicious, run a business email compromise check and assign the ticket to the security queue with the result.

With Helpdesk, the account change waits for a technician's approval.

## Troubleshooting

| Error on save | Fix |
| - | - |
| Microsoft refused the secret | Reset the client's secret in CIPP and paste the new one. |
| Microsoft does not know the API scope of this client | In Entra ID, open the CIPP API client's app registration, open **Expose an API**, and add the Application ID URI (the default is fine). |
| CIPP did not accept the token (HTTP 401) | Check the client is enabled, click **Save to Azure**, wait a few minutes and save again. |
| CIPP refused the client (HTTP 403) | Give the client's role permission to read tenants, and set Allowed IP Ranges to Any or add Neo's addresses. |


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.