Integrations/CIPP (CyberDrain Improved Partner Portal)
M365 INTEGRATION

Microsoft 365 tickets, worked through your CIPP.

Neo acts in your customers' Microsoft 365 tenants through your own CIPP instance: unblock a user, reset MFA, grant mailbox access, release quarantined mail, check a suspicious sign-in.

01Capabilities

What Neo does with CIPP (CyberDrain Improved Partner Portal).

01
USERS

Account fixes

Revokes sessions, blocks or allows sign-in, resets MFA, sets a password, changes group membership, and runs onboarding and offboarding.

02
MAILBOXES

Mailboxes and mail flow

Traces a missing email, grants mailbox or calendar access, sets out of office or forwarding, converts a mailbox to shared, and releases quarantined mail.

03
SECURITY

Sign-ins and alerts

Reads Defender alerts and sign-ins, runs a business email compromise check, and can contain the account.

02Workflows

Concrete work Neo handles in CIPP (CyberDrain Improved Partner Portal).

LOCKED OUT

Unblock a user

Neo looks the user up, checks the sign-in log for the reason, and allows sign-in again when there is no sign of compromise. With Helpdesk, a technician approves the change.

SUSPICIOUS SIGN-IN

Compromise check

When the sign-ins look suspicious, Neo runs a business email compromise check and assigns the ticket to your security queue with the result.

ACCESS

Mailbox and OneDrive access

A manager needs a mailbox, a calendar or a departed user's OneDrive. Neo grants the access in the right customer's tenant.

DEVICES

Device checks and actions

Neo checks a device's compliance and Defender state, then syncs, restarts or scans it. A wipe or retire always asks a technician first.

03Setup

Live in under an hour.

Connect, configure, go. No code, no long implementation.

01

Create an API client in CIPP

In CIPP, open Integrations > CIPP-API, create a client for Neo with the role it needs, and click Save to Azure. Copy the API URL, Tenant ID, Application ID and secret.

02

Save it in Neo and set access

Paste the four values in Neo. Neo signs in and lists your CIPP tenants before it saves. Then pick an access profile for each agent.

03

Go live

Confirm any suggested matches on the Organization Mapping tab. Your agents then work Microsoft 365 tickets in the right customer's tenant.

FAQ

Questions about the CIPP (CyberDrain Improved Partner Portal) integration.

What can Neo change through CIPP?+

Users, mailboxes, email security, devices, sign-in security and SharePoint access, as each agent's permissions allow. Neo never sends a change to every tenant at once. CIPP settings, standards, Conditional Access, Intune policies and GDAP stay with your technicians.

Which changes need technician approval?+

The access profile decides most of it. Helpdesk asks before account changes, device changes and password resets. A device wipe or retire, deleting a device from Entra ID, and every raw Graph or Exchange request always ask a technician first.

What credentials does Neo need?+

An API client you create in your own CIPP: its API URL, Tenant ID, Application ID and Application Secret. The client's CIPP role limits what Neo can do. The readonly role is enough for an agent that only reads. Changes need editor or a custom role.

How are CIPP tenants matched to PSA companies?+

Neo matches by Microsoft 365 tenant id first, then the tenant's domain against the company website, then the name, then AI. Tenant id and name matches go straight to your agents. Domain and AI matches wait on the Organization Mapping tab for you to confirm.

Ready to wire up CIPP (CyberDrain Improved Partner Portal)?

14-day free trial. No credit card. Live in under an hour, right inside your stack.