The Proofpoint Essentials API signs in with an admin account’s username and password. There is no API key. Neo stores both in Azure Key Vault.
1. Create an admin account for Neo
1
Use a dedicated admin
In the Proofpoint Essentials console, create an admin account for Neo, so you can see its changes in the audit trail and revoke it on its own.Use a Channel Partner Admin at your partner level to give Neo access to every client organization. An Organization Admin reaches only its own organization.
2
Make it the service account
Proofpoint lets one admin account per organization be the service account, which is not billable and does not count toward licences.
3
Keep the login local
Neo signs in with the username and password on every call. If the account signs in through SSO or MFA and Neo’s login is refused, use a local admin account without them.
2. Add the login in Neo
1
Open Integrations
In the Neo Dashboard, open Integrations and find the Proofpoint Essentials card, under Security.
2
Enter your stack
Enter the stack your account is on. It is the first part of the address you sign in at:
us2 in us2.proofpointessentials.com.3
Save the login
Enter the admin username and password and click Save. Neo checks the login against Proofpoint before saving, so a wrong password or the wrong stack is rejected straight away. The Organization Mapping tab fills separately after the save, and again on each nightly PSA sync.
3. Turn Proofpoint Essentials on per agent
Each agent decides whether it uses Proofpoint Essentials and which areas it can touch. Open the agent, go to the Integrations section, and configure the Proofpoint Essentials block.Pick an access profile
Read Only
Every area read only. The agent finds the organization, user and sender lists, and reports.
Helpdesk
Sender Lists and Users set to read and write. Everything else read only. Fits the “please let this sender through” ticket.
IT Admin
Every area read and write except Licensing & Products and Reporting & Billing.
Or set each area by hand
Safety controls
- Quarantine is out of reach. Proofpoint’s published Essentials API document has no quarantine endpoint, and Neo sends only published operations, so no agent can release a message. The agent tells the user or technician how to release it.
- Never allowed. Neo never deletes a client organization and never creates a login token that signs in as another user, whatever the agent is set to.
- Always waits on a technician. Clearing a sender list; deleting a user, domain or DKIM key; setting a user’s password or admin role; creating a client organization; resetting the Azure AD sync; and every login, MFA or SSO change. This holds regardless of the agent’s automation level or the access profile you picked.
- Licensing and billing are read only. Neo cannot buy a product or change a licence count.
- Only published operations. Neo sends only the operations Proofpoint documents. Suspicious URL paths (anything containing
.., for example) are rejected before they reach Proofpoint.
If Proofpoint refuses Neo’s requests
Until a
401 or 403 is fixed, agents that use Proofpoint Essentials report the failure on the ticket they were working. The rest of Neo keeps running.
Disconnecting Proofpoint Essentials
1
Open the integration
In the Neo Dashboard, open Integrations and select the Proofpoint Essentials card.
2
Disconnect
Click Disconnect and confirm. Neo removes the login from Key Vault. Agents that use Proofpoint Essentials stop working until you connect it again.
Security
- The admin login lives in Azure Key Vault. It is never stored in plaintext.
- All traffic to Proofpoint goes over HTTPS, to your stack’s
proofpointessentials.comhost. - Write access is opt in per agent and per area.
