Skip to main content
You connect Hornetsecurity once at the MSP level, then turn it on per agent.

1. Create an API access token

1

Sign in as a partner admin

Sign in to the Hornetsecurity Control Panel as an admin at your partner level, so the token reaches every client. A token acts as the user who created it and sees what that user sees.
2

Create the token

Open User settings in the top-right menu, then the API Token tab, and click Create token. Give it a name, set an expiry if you want one, and copy the token.

2. Add the token in Neo

1

Open Integrations

In the Neo Dashboard, open Integrations and find the Hornetsecurity 365 Total Protection card, under Security.
2

Save the token

Paste the token without the Token prefix and click Save. Neo checks it against Hornetsecurity before saving, so a wrong or expired token is rejected straight away.

3. Turn Hornetsecurity on per agent

Open the agent, go to the Integrations section, and configure the Hornetsecurity block.

Pick an access profile

Read Only

Search email and look up clients. Nothing is released or changed.

Helpdesk

Release held email with technician approval, and edit allow and deny lists.

Full Automation

Release held email and edit allow and deny lists without approval. Deleting email still waits on a technician.

Or set each area by hand

Safety controls

  • Deleting email always waits on a technician. It cannot be undone. This holds whatever the agent’s automation level or profile.
  • Threats are not released on the agent’s own judgement. The agent releases a threat only when a technician asked for that exact email, and Hornetsecurity itself may refuse the release for your account.
  • Only what the job needs. Neo sends only email search and actions, allow and deny lists, and client, mailbox and domain lookups. Token management, backup, e-learning and every other Control Panel area are unreachable, and so is delivery to Hornetsecurity’s support desk.
  • Path safety. Suspicious URL paths (anything containing .., for example) are rejected before they reach Hornetsecurity.

If Hornetsecurity refuses Neo’s requests

Disconnecting Hornetsecurity

In the Neo Dashboard, open Integrations, select the Hornetsecurity card, click Disconnect and confirm. Neo removes the token from Key Vault. Agents that use Hornetsecurity stop working until you connect it again.

Security

  • The token lives in Azure Key Vault. It is never stored in plaintext.
  • All traffic goes over HTTPS to cp.hornetsecurity.com.
  • Write access is opt in per agent and per area.