> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neoagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Overview

> What the CIPP integration brings to your Neo Agent setup

[CIPP](https://cipp.app) (the CyberDrain Improved Partner Portal) manages the Microsoft 365 tenants of an MSP's customers from one place. Connect it to Neo and your agents can work Microsoft 365 tickets in those tenants through CIPP: unblock a user, reset MFA, grant mailbox access, release quarantined mail, check a suspicious sign-in, sync a device.

<Info>
  CIPP connects once per MSP, with an API client you create in your own CIPP instance. Every agent you enable uses it, with permissions you control per agent.
</Info>

## What Neo can do with CIPP

<CardGroup cols={2}>
  <Card title="Users & Groups" icon="users">
    Find a user, revoke sessions, block or allow sign-in, reset MFA, set a password, change group membership, onboard and offboard.
  </Card>

  <Card title="Mailboxes" icon="envelope">
    Trace a missing email, grant mailbox or calendar access, set out of office or forwarding, convert a mailbox to shared.
  </Card>

  <Card title="Email Security" icon="shield">
    Find quarantined mail and release it, and manage Tenant Allow/Block List entries.
  </Card>

  <Card title="Devices" icon="laptop">
    Check a device's compliance and Defender state, and sync, restart or scan it.
  </Card>

  <Card title="Security & Sign-ins" icon="user-shield">
    Read Defender alerts and sign-ins, run a business email compromise check and contain the account.
  </Card>

  <Card title="SharePoint & Teams" icon="share-nodes">
    Give a user access to a site or a departed user's OneDrive.
  </Card>
</CardGroup>

See [CIPP API](/agents/tools/m365/cipp-api) for the full list, and for what Neo never does through CIPP.

## CIPP or Neo's own Microsoft 365 connection

Neo can also reach your customers' tenants with its own access, through [GDAP](/integrations/m365/gdap). Use CIPP when your team already manages customers there and you would rather not grant Neo a second route. An agent can use either one.

## Your customers are mapped automatically

Neo matches your CIPP tenants to the companies in your PSA and keeps the mapping on the CIPP card's **Organization Mapping** tab, refreshed on each PSA metadata sync.

Matching starts with the Microsoft 365 tenant id: a CIPP tenant with the same tenant id Neo has on a company is an exact match. Then comes the tenant's domain against the company's website, then the name. Last comes an AI match for the long tail.

**A tenant id or name match, or one you confirm, is handed straight to your agents**, so they act in the right customer's tenant without looking it up. A domain or AI match is not handed to your agents automatically. It shows on the Organization Mapping tab, where you can confirm or correct it.

## Next steps

<Card title="Connect CIPP" icon="plug" href="/integrations/cipp/connecting-to-neo">
  Create an API client in CIPP and save it in Neo.
</Card>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.