ThreatLocker uses a single API key per MSP. Connect it once and every agent you enable can use it, with permissions you control per agent.
What Neo can do with ThreatLocker
Computers
Search computers and computer groups, check online status, and manage maintenance mode windows.
Applications
Search applications and application files ThreatLocker has observed running or being blocked across managed computers.
Approval Requests
Find pending software-approval requests and approve or deny them — the “an app won’t run” workflow. Approving or denying always waits on a technician.
Policies
View and, with technician approval, edit allowlist policies, Config Manager policies, and network access policies.
Why connect ThreatLocker
- The approval queue stops waiting on a human to notice it. An agent can watch for pending approval requests and hand a technician a ready decision instead of the technician finding it themselves.
- Endpoint security context inside ticket work. Any ticket agent can check whether a computer is online, what’s currently blocked, or what policy applies before touching anything.
- Approving software and editing policies always requires a technician’s sign-off, no matter how automated the rest of the agent is — this is by design, not a limitation you need to work around.
How agents reach ThreatLocker
When you enable any ThreatLocker permission group on an agent, Neo automatically adds the ThreatLocker tool to that agent’s toolbox. There is nothing extra to install and no toolbox tweaking needed. The agent uses the API URL and key you saved in the dashboard, and every call stays inside the areas and access levels you allowed.Where to go next
Connecting ThreatLocker to Neo
Setup steps for the API URL and key, per-agent access levels, and the safety controls that stay in place.
