Skip to main content
Connect CIPP to bring supported Microsoft 365, security and Intune reporting into the appropriate company context. The wizard offers Connect, Map companies, Review and Data.

Before you start

This is an MSP staff task requiring integration-management permission and authorized vendor credentials. This provider is available only when enabled for your MSP tenant. If its setup page is unavailable, check availability with your MSPortal administrator. Company users do not configure this connection. In CIPP, configure an enabled CIPP-API client with read access to the required reporting areas and intended tenants. Use the CIPP client setup and authentication instructions. Apply the client configuration in CIPP, including its Azure configuration when required. Copy CIPP API URL, Tenant ID, Application ID, Application secret and API scope from that client. Use its actual API scope rather than inventing one from a tenant name.

Test and save

  1. Open Settings > Integrations, find CIPP, and open setup for the intended connection.
  2. Enter the five fields from the configured CIPP API client.
  3. Select Test Connection. Check both authentication and CIPP authorization errors.
  4. Select Create Integration to save a new connection, or Save connection for tested changes to an existing connection.
Cipp connection form with blank credential fields and test and save controls

MSP example: connection form before credentials are submitted.

A token alone does not prove every CIPP dataset is accessible. The client’s CIPP role controls tenant and endpoint access. For portfolio reporting, it needs the intended AllTenants read scope; a restricted role can leave some datasets unavailable.

Map companies

  1. Review the discovered CIPP tenants and default domains.
  2. Select the correct MSPortal company, or review Quick Match suggestions.
  3. Check selected records and pending links before Import Selected applies them. The wizard also saves pending mappings as part of its mapping navigation.
  4. Verify the resulting saved links. Removing a saved link is immediate; clearing a pending link discards only that draft.
Creating a company from mapping creates a real company immediately. Its association still needs to be saved. Avoid duplicate companies by checking existing records first.

Review coverage

Open Review to inspect discovered/mapped tenants, synced records, healthy/running datasets, security coverage, Intune coverage and dataset issues. Use Start full sync only when you intend to request fresh provider data; a started message is not a completed sync. If only one tenant is returned when you expect more, review the CIPP client’s allowed tenants and role. An authorization failure for one dataset does not invalidate data from datasets that succeeded, but it does mean coverage is incomplete. Use View Microsoft 365 posture for the reporting view and Manage company mappings to correct scope.

Inspect data

Data opens the CIPP data explorer, including dataset coverage, sync issues and synchronized records. Some entries expose detailed provider payloads; use the intended company and dataset filters before investigating a record. Missing or failed data is not a passing security result.

Maintain the connection

Reopen the specific connection to update its API client values. Test the revised values and choose Save connection. Existing masked secrets are not displayed in clear text. A saved verified indicator is not evidence of a fresh retest. The disconnect confirmation removes the connection, synchronized CIPP data and stored credentials. It does not disable or revoke the CIPP API client itself.

Troubleshooting

Frequently asked questions

No. Review CIPP tenant scope and each dataset result. Authentication and dataset authorization are separate.
Check the API client’s allowed tenants and role. AllTenants read access is needed for the intended portfolio scope.
No. They represent missing coverage. Successful datasets can still be available independently.
No. Review completion and dataset errors after the background work runs.
No. This is an MSP integration-management task; Company reporting is governed separately by scope and permissions.