Integrations/ThreatLocker
SECURITY INTEGRATION

"The app won't run", answered from the ticket.

Neo finds the pending ThreatLocker approval request behind a ticket and hands a technician a ready decision. It also checks computers, applications and policies during ticket work.

01Capabilities

What Neo does with ThreatLocker.

01
APPROVALS

Software requests, ready to decide

Neo finds pending Application, Elevation and Storage Control requests and approves or denies them. A technician signs off on every decision.

02
CONTEXT

Computers and applications

Neo searches computers and computer groups, checks online status, and looks up the applications ThreatLocker saw run or block across the fleet.

03
POLICIES

Policies, with sign-off

Neo reads allowlist, Config Manager and network access policies. It edits them only after a technician approves.

02Workflows

Concrete work Neo handles in ThreatLocker.

APP BLOCKED

The "app won't run" ticket

Neo finds the pending request behind the ticket, with the computer and the application it is for, and prepares the decision for a technician.

QUEUE

Approval queue, watched

An agent watches for pending approval requests and hands a technician a ready decision, so nobody has to find the request first.

PRE-CHECK

Check before you touch

Any ticket agent can check if a computer is online, what is blocked on it, and which policy applies before it changes anything.

MAINTENANCE

Maintenance mode windows

Neo manages maintenance mode windows on computers. You decide if these changes run on their own or wait for a technician.

03Setup

Live in under an hour.

Connect, configure, go. No code, no long implementation.

01

Connect ThreatLocker

Copy your Portal API URL from the ThreatLocker Help menu and create an API user with an Auth Key. Save both in Neo, and Neo checks the key before it stores it.

02

Check the organization mapping

Neo matches your ThreatLocker organizations to your PSA companies. Review the result on the Organization Mapping tab and correct any organization by hand.

03

Set access per agent

Pick Read Only, Helpdesk, IT Admin or Full Automation, or set each area yourself. Neo adds the ThreatLocker tool to every agent you enable.

FAQ

Questions about the ThreatLocker integration.

What can Neo change in ThreatLocker?+

Computers, applications, policies and approval requests, as far as you allow per agent. Organizations is always read only. Neo uses it only to scope calls to the right customer.

Does approving software need a technician?+

Yes. Approving or denying a request and editing a policy always wait on a technician, whatever the agent's automation level. Under Full Automation, only computer and application changes run on their own.

What credentials does Neo need?+

Your Portal API URL and the Auth Key of an API user. Give the API user the highest access level any agent needs, plus read only on Organizations for company mapping. If your portal restricts API access by country, permit the United States.

How are ThreatLocker organizations mapped to PSA companies?+

Neo matches each organization to a PSA company by name. The result shows on the Organization Mapping tab, where you can map or re-map an organization by hand. Your mapping survives every sync.

Ready to wire up ThreatLocker?

14-day free trial. No credit card. Live in under an hour, right inside your stack.