CIPP connects once per MSP, with an API client you create in your own CIPP instance. Every agent you enable uses it, with permissions you control per agent.
What Neo can do with CIPP
Users & Groups
Find a user, revoke sessions, block or allow sign-in, reset MFA, set a password, change group membership, onboard and offboard.
Mailboxes
Trace a missing email, grant mailbox or calendar access, set out of office or forwarding, convert a mailbox to shared.
Email Security
Find quarantined mail and release it, and manage Tenant Allow/Block List entries.
Devices
Check a device’s compliance and Defender state, and sync, restart or scan it.
Security & Sign-ins
Read Defender alerts and sign-ins, run a business email compromise check and contain the account.
SharePoint & Teams
Give a user access to a site or a departed user’s OneDrive.
CIPP or Neo’s own Microsoft 365 connection
Neo can also reach your customers’ tenants with its own access, through GDAP. Use CIPP when your team already manages customers there and you would rather not grant Neo a second route. An agent can use either one.Your customers are mapped automatically
Neo matches your CIPP tenants to the companies in your PSA and keeps the mapping on the CIPP card’s Organization Mapping tab, refreshed on each PSA metadata sync. Matching starts with the Microsoft 365 tenant id: a CIPP tenant with the same tenant id Neo has on a company is an exact match. Then comes the tenant’s domain against the company’s website, then the name. Last comes an AI match for the long tail. A tenant id or name match, or one you confirm, is handed straight to your agents, so they act in the right customer’s tenant without looking it up. A domain or AI match is not handed to your agents automatically. It shows on the Organization Mapping tab, where you can confirm or correct it.Next steps
Connect CIPP
Create an API client in CIPP and save it in Neo.
