Microsoft 365 tickets, worked through your CIPP.
Neo acts in your customers' Microsoft 365 tenants through your own CIPP instance: unblock a user, reset MFA, grant mailbox access, release quarantined mail, check a suspicious sign-in.
What Neo does with CIPP (CyberDrain Improved Partner Portal).
Account fixes
Revokes sessions, blocks or allows sign-in, resets MFA, sets a password, changes group membership, and runs onboarding and offboarding.
Mailboxes and mail flow
Traces a missing email, grants mailbox or calendar access, sets out of office or forwarding, converts a mailbox to shared, and releases quarantined mail.
Sign-ins and alerts
Reads Defender alerts and sign-ins, runs a business email compromise check, and can contain the account.
Concrete work Neo handles in CIPP (CyberDrain Improved Partner Portal).
Unblock a user
Neo looks the user up, checks the sign-in log for the reason, and allows sign-in again when there is no sign of compromise. With Helpdesk, a technician approves the change.
Compromise check
When the sign-ins look suspicious, Neo runs a business email compromise check and assigns the ticket to your security queue with the result.
Mailbox and OneDrive access
A manager needs a mailbox, a calendar or a departed user's OneDrive. Neo grants the access in the right customer's tenant.
Device checks and actions
Neo checks a device's compliance and Defender state, then syncs, restarts or scans it. A wipe or retire always asks a technician first.
Live in under an hour.
Connect, configure, go. No code, no long implementation.
Create an API client in CIPP
In CIPP, open Integrations > CIPP-API, create a client for Neo with the role it needs, and click Save to Azure. Copy the API URL, Tenant ID, Application ID and secret.
Save it in Neo and set access
Paste the four values in Neo. Neo signs in and lists your CIPP tenants before it saves. Then pick an access profile for each agent.
Go live
Confirm any suggested matches on the Organization Mapping tab. Your agents then work Microsoft 365 tickets in the right customer's tenant.
Questions about the CIPP (CyberDrain Improved Partner Portal) integration.
What can Neo change through CIPP?+
Users, mailboxes, email security, devices, sign-in security and SharePoint access, as each agent's permissions allow. Neo never sends a change to every tenant at once. CIPP settings, standards, Conditional Access, Intune policies and GDAP stay with your technicians.
Which changes need technician approval?+
The access profile decides most of it. Helpdesk asks before account changes, device changes and password resets. A device wipe or retire, deleting a device from Entra ID, and every raw Graph or Exchange request always ask a technician first.
What credentials does Neo need?+
An API client you create in your own CIPP: its API URL, Tenant ID, Application ID and Application Secret. The client's CIPP role limits what Neo can do. The readonly role is enough for an agent that only reads. Changes need editor or a custom role.
How are CIPP tenants matched to PSA companies?+
Neo matches by Microsoft 365 tenant id first, then the tenant's domain against the company website, then the name, then AI. Tenant id and name matches go straight to your agents. Domain and AI matches wait on the Organization Mapping tab for you to confirm.
Ready to wire up CIPP (CyberDrain Improved Partner Portal)?
14-day free trial. No credit card. Live in under an hour, right inside your stack.