Skip to main content
You connect Proofpoint Essentials once at the MSP level, then turn it on per agent.
The Proofpoint Essentials API signs in with an admin account’s username and password. There is no API key. Neo stores both in Azure Key Vault.

1. Create an admin account for Neo

1

Use a dedicated admin

In the Proofpoint Essentials console, create an admin account for Neo, so you can see its changes in the audit trail and revoke it on its own.Use a Channel Partner Admin at your partner level to give Neo access to every client organization. An Organization Admin reaches only its own organization.
2

Make it the service account

Proofpoint lets one admin account per organization be the service account, which is not billable and does not count toward licences.
3

Keep the login local

Neo signs in with the username and password on every call. If the account signs in through SSO or MFA and Neo’s login is refused, use a local admin account without them.

2. Add the login in Neo

1

Open Integrations

In the Neo Dashboard, open Integrations and find the Proofpoint Essentials card, under Security.
2

Enter your stack

Enter the stack your account is on. It is the first part of the address you sign in at: us2 in us2.proofpointessentials.com.
3

Save the login

Enter the admin username and password and click Save. Neo checks the login against Proofpoint before saving, so a wrong password or the wrong stack is rejected straight away. The Organization Mapping tab fills separately after the save, and again on each nightly PSA sync.

3. Turn Proofpoint Essentials on per agent

Each agent decides whether it uses Proofpoint Essentials and which areas it can touch. Open the agent, go to the Integrations section, and configure the Proofpoint Essentials block.

Pick an access profile

Read Only

Every area read only. The agent finds the organization, user and sender lists, and reports.

Helpdesk

Sender Lists and Users set to read and write. Everything else read only. Fits the “please let this sender through” ticket.

IT Admin

Every area read and write except Licensing & Products and Reporting & Billing.

Or set each area by hand

Safety controls

  • Quarantine is out of reach. Proofpoint’s published Essentials API document has no quarantine endpoint, and Neo sends only published operations, so no agent can release a message. The agent tells the user or technician how to release it.
  • Never allowed. Neo never deletes a client organization and never creates a login token that signs in as another user, whatever the agent is set to.
  • Always waits on a technician. Clearing a sender list; deleting a user, domain or DKIM key; setting a user’s password or admin role; creating a client organization; resetting the Azure AD sync; and every login, MFA or SSO change. This holds regardless of the agent’s automation level or the access profile you picked.
  • Licensing and billing are read only. Neo cannot buy a product or change a licence count.
  • Only published operations. Neo sends only the operations Proofpoint documents. Suspicious URL paths (anything containing .., for example) are rejected before they reach Proofpoint.

If Proofpoint refuses Neo’s requests

Until a 401 or 403 is fixed, agents that use Proofpoint Essentials report the failure on the ticket they were working. The rest of Neo keeps running.

Disconnecting Proofpoint Essentials

1

Open the integration

In the Neo Dashboard, open Integrations and select the Proofpoint Essentials card.
2

Disconnect

Click Disconnect and confirm. Neo removes the login from Key Vault. Agents that use Proofpoint Essentials stop working until you connect it again.
Your Organization Mapping is kept, including any mapping you set by hand, so reconnecting later picks up where you left off.

Security

  • The admin login lives in Azure Key Vault. It is never stored in plaintext.
  • All traffic to Proofpoint goes over HTTPS, to your stack’s proofpointessentials.com host.
  • Write access is opt in per agent and per area.