Skip to main content
Neo integrates with Microsoft 365, Active Directory, and Exchange to automate the full spectrum of identity, mailbox, and security operations — across cloud, on-prem, and hybrid environments. Connect once, and your AI agents can handle everything from password resets to full user onboarding and offboarding.

What Neo Can Do

Create, update, disable, enable, and delete users in Entra ID or on-prem Active Directory. Assign managers, update job titles and departments, and manage user properties — all from a single agent.
Reset passwords (including require password change at next sign-in — see re-granting access for tenants connected before June 2026), unlock accounts, revoke sign-in sessions, reset MFA, and manage authentication methods. Block and unblock user sign-in. In hybrid environments, Neo makes changes on-prem and triggers Azure AD Connect sync automatically — or, for hybrid tenants without AD Connect sync, applies the same change to both directories directly.
Assign and remove Microsoft 365 licenses. Look up friendly license names from SKU IDs. Works with direct Microsoft licensing, Pax8, and Partner Center.
Add and remove users from security groups, Microsoft 365 groups, distribution lists, and mail-enabled security groups. Search and list groups across Entra ID and on-prem AD. In hybrid environments, Neo automatically routes group operations to the correct directory.
Assign and remove Entra ID directory roles (Global Admin, Exchange Admin, User Admin, etc.). View a user’s current role assignments.
Convert mailboxes to shared, create new shared mailboxes, and delete shared mailboxes. Set up and remove email forwarding. Configure mailbox delegation (full access, send-as, send-on-behalf). Works with Exchange Online and on-prem Exchange Server.
Grant and revoke full access, send-as, and send-on-behalf permissions. Add and remove recipient permissions. View current mailbox permission assignments.
List, view, create, update, and delete Conditional Access policies. Destructive operations always require technician approval regardless of workflow settings.
View user devices in Intune. Remote wipe and retire mobile devices. Device deletion is always blocked for safety.
Full AD management via RMM: user and computer management, organizational units, group operations, infrastructure queries, and Entra Connect sync triggers.
All Exchange operations work on-prem too: mailbox management, permissions, recipients and contacts, distribution groups, mail flow and transport rules, address lists and policies, compliance and auditing.
Need an operation that’s not listed? Let us know — we add new capabilities regularly.

Granular Permission Controls

Every agent workflow has its own permission configuration. You control exactly what the agent can and cannot do — per integration, per operation category.

Microsoft Graph

14 permission groups covering users, groups, licensing, security, roles, devices, conditional access, domains, mail, audit logs, security operations, SharePoint & OneDrive, Teams & chats, and app registrations

Active Directory

6 permission groups covering users, groups, computers, OUs, infrastructure, and Entra Connect sync

Exchange

7 permission groups covering mailboxes, permissions, recipients, distribution groups, mail flow, address lists, and compliance
Each permission group has three access levels: You can also require technician approval for any permission group — the agent will pause and wait for a technician to approve before executing write operations.
Built-in safety guardrails: Some destructive operations (like deleting a user or wiping a device) always require technician approval, even if the permission group doesn’t have it enabled. Every write in the Applications group (app registrations, client secrets, consent grants) requires approval the same way. Other operations (like deleting a domain) are blocked entirely.
Quick-start profiles let you configure all permission groups at once:

Service Health

Service Health is read only, and it is the one permission group with no Write level: Microsoft exposes no write for service health. Turning it on lets an agent read Microsoft 365 service health, open incidents, and Message Center announcements for that client company — so it can tell a user “Microsoft has an open incident affecting Exchange” instead of troubleshooting a fault that is not yours. A client company that connected to Neo before 3 September 2026 needs one extra step. Service Health needs two Microsoft permissions that Neo did not ask for until then, and adding a permission to our app never grants it to a tenant retroactively. So the first Service Health call for an older company fails, and the agent tells you why. What fixes it depends on how that company was connected:
  • Direct admin consent — open Companies and use the ⋯ actions menu → Reinitialize application access on that company. It re-runs the same Microsoft consent screen, which now asks for both permissions. A company that is not connected yet shows Grant access instead, and that covers it the same way.
  • GDAP — a GDAP company’s permissions come from your GDAP permissions selection rather than a consent screen, so there is no per-company button for it. Check that selection includes both permissions (the default set does), then ask us to re-provision the company.
Companies you connect from now on include both permissions. So do companies Neo provisions through your GDAP relationship — unless you have saved a narrowed GDAP permissions selection, in which case add them there first.

”Coming Soon” permission groups

A permission group badged Coming Soon and greyed out is one we have built the controls for but have not released. The Microsoft access behind it has not been granted to Neo, so every call it would cover fails — for every customer, in every tenant. No group is in this state today; Service Health was the last one, released on 3 September 2026. If you meet one in a future release, you cannot switch it on, and working around it does not help:
  • The quick-start profiles leave it Disabled, and both the dashboard and the API refuse to set it any higher.
  • Re-consenting or re-authorizing your Microsoft 365 connection does not help. A tenant admin can only consent to the permissions Neo’s app asks for, and an unreleased group is one we do not ask for yet.
  • If an agent of yours has one enabled from an older configuration, its calls have been failing. Set the group back to Disabled on that row. Neo also refuses those calls and tells the agent why, so it stops spending its run on them.
Ask us if you want a Coming Soon group prioritized. We will tell you where it stands rather than give you a date we cannot keep.

Works Everywhere

Neo supports cloud, on-prem, and hybrid Microsoft environments — configured independently per client company. Identity provider and mailbox provider are configured separately — you can mix and match. For example, on-prem AD with Exchange Online, or Entra ID with on-prem Exchange Server.

Connect Cloud Tenants

Two ways to connect Neo to customer Microsoft 365 tenants:

GDAP

CSP partners can consent to Neo on behalf of customers using existing GDAP access.

Direct Consent

A tenant admin in each customer tenant consents to the Neo app directly.

Customers With More Than One Microsoft Tenant

A company record holds one Microsoft tenant ID, and Neo works in the tenant set on the company attached to the ticket. A customer that runs two tenants — after an acquisition, or a group that never merged its directories — needs one company per tenant.
1

Give each tenant its own company in your PSA

Neo’s companies map one-to-one onto PSA companies, so the second tenant needs a company of its own in your PSA — a child company or a site works.
2

Set the tenant ID on each company

On Companies, open each one and set Microsoft Tenant ID of the company to that tenant’s GUID.
3

Connect each company

Grant access per company, with GDAP or Direct Consent. Connecting one of them does not reach the other tenant.
The ticket decides which tenant Neo acts in. If tickets for both tenants land on a single company, Neo only ever acts in the tenant set on that company — so split the tickets the way you split the companies.
The reverse needs no extra setup: several companies may share one tenant ID, which is the normal shape for a group with one PSA company per site. Connect any one of them and they all show connected, because the access belongs to the tenant.

Connect On-Prem Environments

On-prem

Connect on-premises Active Directory and Exchange environments via RMM.
Hybrid environments: Configure as on-prem — Neo executes operations on your domain controller and Azure AD Connect syncs changes to the cloud. If both directories exist but nothing syncs between them, set the company’s identity provider to “Hybrid (no AD Connect sync)” instead — Neo then applies each identity change to both on-prem AD and Entra ID directly. See which hybrid type to pick.