CIPP is currently a Pilot integration available to selected tenants. If you don’t see the CIPP card in Settings > Integrations, contact support@msportal.ai. The pilot secures and validates the API connection; data sync features build on this connection.
Prerequisites
- A CIPP instance with the CIPP-API integration enabled
- MSPortal.ai integration management permission
Part 1: Create CIPP API Credentials
1
Open CIPP API Settings
In CIPP, go to Integrations > CIPP-API.
2
Create or Select an API Client
Create or select an enabled API client.
3
Copy the Credentials
Copy the API URL, Tenant ID, Application ID, Application Secret, and API Scope.
Part 2: Connect in MSPortal
1
Open the Setup Page
Go to Settings > Integrations, find the CIPP card, and click Configure.
2
Enter Your Credentials
Fill in the fields:
3
Test the Connection
Click Test Connection. On success you’ll see Connection Verified: Microsoft issued an access token for this CIPP API client.
4
Connect
Click Connect to save. Credentials are stored only in Vault.
Part 3: Map Companies
After connecting, MSPortal discovers the Microsoft 365 tenants managed in CIPP. Map each tenant to the matching MSPortal company so security, Intune, and Microsoft 365 data appears in the correct customer context.1
Wait for Tenant Discovery
Tenant discovery can take a few minutes after the connection is created. The page checks automatically while the initial sync runs.
2
Map Tenants to Companies
Select the matching company for each tenant, or use quick match to pair tenants and companies by name. Tenants whose Microsoft tenant ID matches an existing Microsoft 365 connection are mapped automatically.
3
Continue
Click Next. Saving the mappings starts a full data sync for the mapped tenants.
Data is only stored and shown for tenants that are mapped to a company. Unmapped tenants are listed for mapping but their data stays out of every page and report.
Part 4: Review
The Review step confirms your data coverage before you finish setup:- Tenants mapped and Synced records counters
- Healthy datasets, Security coverage, and Intune coverage indicators
- Start full sync to run a synchronization on demand
Part 5: Data
The Data step is your admin console for everything CIPP is syncing:- Summary cards for mapped tenants, synced records, and security, Intune, and critical item counts
- Dataset coverage showing every dataset by category, with any sync issues flagged
- Record explorer to search and filter every synced record, including the full source payload from the CIPP API
Managing the Connection
- To update credentials later, re-open the setup page, enter the new values, click Retest Connection, then Save Changes.
- To disconnect, click the remove button and confirm. This removes the connection and its stored Vault credentials and cannot be undone.
- Users without integration management permission see the connection read-only.
Troubleshooting
Related Resources
Integrations Overview
Explore all available integrations
Microsoft 365
Manage Microsoft 365 across your clients