Skip to main content
You connect OpenText Secure Cloud once at the MSP level, then turn it on per agent. You need three values from Secure Cloud: a Client ID, a Client secret and a Refresh token.

1. Generate the credentials in Secure Cloud

1

Sign in as a partner administrator

Sign in to OpenText Secure Cloud with a user that has the partner administrator role. The user you authorize with in step 3 is the user Neo acts as.
2

Generate a Client ID and Client secret

Go to Partner Services > Partner Integrations > API credentials management and click Generate credentials. Copy the Client ID and the Client secret. Secure Cloud shows the secret only once. A partner can hold at most 20 credentials.
3

Authorize and copy the refresh token

On the same page, choose Actions > Authorize with credentials in your user’s row. Enter the Client ID and the Client secret, choose Secure Cloud IDP, and click Continue. Copy the Refresh token.
Enter the refresh token in Neo only. A Secure Cloud refresh token works once. Each time Neo connects, Secure Cloud returns a new token and Neo stores it in place of the old one. If another tool or script uses the same token, one of the two stops working, and you must authorize again in Secure Cloud.

2. Save the credentials in Neo

1

Open Integrations

In the Neo Dashboard, open Integrations → OpenText Secure Cloud, under Cloud Marketplace.
2

Enter the values

Paste the Client ID, Client Secret and Refresh Token. To let agents reach your Webroot sites and endpoints, also enter the GSM Keycode: the parent keycode of your Webroot Global Site Manager console, from Settings > Subscription in the GSM console. Leave it blank if you do not use Webroot. Click Save.Neo exchanges the refresh token with Secure Cloud before it saves. A wrong Client ID or secret, or a token that was already used, is refused on the spot.

Keep the connection alive

A refresh token expires after 14 days without use. Neo maps your Secure Cloud customers to PSA companies after each PSA sync, and that run renews the token, so an account whose PSA keeps syncing stays connected. If Secure Cloud refuses the token, for example after 14 days without a sync or after someone used the same token elsewhere, Neo shows an action item in your inbox and emails your admin. Authorize again in Secure Cloud, as in Authorize and copy the refresh token above, and save the new refresh token in Neo.
The Webroot console areas need a Secure Cloud user with access to your GSM console. If the user has none, or loses it later, Neo keeps the Secure Cloud areas connected, and the Webroot areas return a 403. Neo checks which areas the user can reach when you save the connection, so after you give the user more access, save the connection again.

3. Turn OpenText Secure Cloud on per agent

Each agent decides whether it uses OpenText Secure Cloud and which areas it can touch. Open the agent, go to the Integrations section, and configure the OpenText Secure Cloud block.

Pick an access profile

Read Only

Every area read only. The agent looks up customers, users, licences, charges and Webroot endpoints, and never changes anything.

Helpdesk

Customers & Users and Webroot Endpoints & Groups read and write, each change with technician approval. Everything else read only.

IT Admin

Every writable area read and write. The agent manages users, licences, orders, sites and endpoints on its own. Admins and roles, DNS Protection mappings and event subscriptions wait on a technician, as do the changes listed under Full Automation.

Full Automation

Every supported write runs with no approval. Only admin and role changes, changing an endpoint’s keycode, uninstalling or deactivating Webroot on endpoints, suspending or deactivating a site, and cancelling a product wait on a technician.

Or set each area by hand

Safety controls

  • You set the approvals. Each area has its own approval setting, so an agent can assign a licence or scan an endpoint on its own, or ask a technician first.
  • Admin access, keycode changes and removing protection always wait on a technician. Every Admins & Roles change, changing an endpoint’s keycode, uninstalling or deactivating Webroot on endpoints, suspending or deactivating a site, and cancelling a product need approval whatever the agent’s automation level. This is not a setting you can turn off.
  • Seat quantities stay with you. Neo refuses a change to a subscription’s seat quantity. The agent tells the technician what to change in Secure Cloud.
  • Endpoint actions name their targets. Webroot applies a site-level command, move, policy change or deactivation with an empty endpoint list to every endpoint of the site. Neo refuses one that does not list the endpoints.
  • Only documented operations. Neo sends only the operations in the Unity API reference, each with its own method, and refuses any other call.
  • Console sign-in links stay in Webroot. Neo never reads the console links that sign their holder in to the Webroot console.
  • Path safety. Neo rejects suspicious URL paths (anything that contains .., for example) before they reach OpenText.

If OpenText refuses Neo’s requests

Disconnecting OpenText Secure Cloud

1

Open the integration

In the Neo Dashboard, open Integrations and select the OpenText Secure Cloud card.
2

Disconnect

Click Disconnect and confirm. Neo removes the credentials from Key Vault and stops using its cached access token.
Neo keeps your Organization Mapping, including any mapping you set by hand, so a later reconnect continues from the same state. Agents that use OpenText Secure Cloud stop working until you connect it again.

Security

  • The Client secret and the refresh token are stored in Azure Key Vault, never in plaintext.
  • All traffic to OpenText goes over HTTPS, to unityapi.webrootcloudav.com only.
  • Write access is opt-in per agent.