Before you start
This is an MSP staff task requiring integration-management permission and authorized vendor credentials. This provider is available only when enabled for your MSP tenant. If its setup page is unavailable, check availability with your MSPortal administrator. Company users do not configure this connection. In CIPP, configure an enabled CIPP-API client with read access to the required reporting areas and intended tenants. Use the CIPP client setup and authentication instructions. Apply the client configuration in CIPP, including its Azure configuration when required. Copy CIPP API URL, Tenant ID, Application ID, Application secret and API scope from that client. Use its actual API scope rather than inventing one from a tenant name.Test and save
- Open Settings > Integrations, find CIPP, and open setup for the intended connection.
- Enter the five fields from the configured CIPP API client.
- Select Test Connection. Check both authentication and CIPP authorization errors.
- Select Create Integration to save a new connection, or Save connection for tested changes to an existing connection.

MSP example: connection form before credentials are submitted.
Map companies
- Review the discovered CIPP tenants and default domains.
- Select the correct MSPortal company, or review Quick Match suggestions.
- Check selected records and pending links before Import Selected applies them. The wizard also saves pending mappings as part of its mapping navigation.
- Verify the resulting saved links. Removing a saved link is immediate; clearing a pending link discards only that draft.
Review coverage
Open Review to inspect discovered/mapped tenants, synced records, healthy/running datasets, security coverage, Intune coverage and dataset issues. Use Start full sync only when you intend to request fresh provider data; a started message is not a completed sync. If only one tenant is returned when you expect more, review the CIPP client’s allowed tenants and role. An authorization failure for one dataset does not invalidate data from datasets that succeeded, but it does mean coverage is incomplete. Use View Microsoft 365 posture for the reporting view and Manage company mappings to correct scope.Inspect data
Data opens the CIPP data explorer, including dataset coverage, sync issues and synchronized records. Some entries expose detailed provider payloads; use the intended company and dataset filters before investigating a record. Missing or failed data is not a passing security result.Maintain the connection
Reopen the specific connection to update its API client values. Test the revised values and choose Save connection. Existing masked secrets are not displayed in clear text. A saved verified indicator is not evidence of a fresh retest. The disconnect confirmation removes the connection, synchronized CIPP data and stored credentials. It does not disable or revoke the CIPP API client itself.Troubleshooting
Frequently asked questions
Does a successful token test prove full reporting coverage?
Does a successful token test prove full reporting coverage?
No. Review CIPP tenant scope and each dataset result. Authentication and dataset authorization are separate.
Why does CIPP show only one tenant?
Why does CIPP show only one tenant?
Check the API client’s allowed tenants and role. AllTenants read access is needed for the intended portfolio scope.
Are failed datasets treated as healthy?
Are failed datasets treated as healthy?
No. They represent missing coverage. Successful datasets can still be available independently.
Does Start full sync mean the data is ready?
Does Start full sync mean the data is ready?
No. Review completion and dataset errors after the background work runs.
Can Company users configure the CIPP API client?
Can Company users configure the CIPP API client?
No. This is an MSP integration-management task; Company reporting is governed separately by scope and permissions.