> ## Documentation Index
> Fetch the complete documentation index at: https://docs.msportal.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure Liongard Integration

> Connect your Liongard instance to MSPortal.ai to sync configuration audits, metrics, and detections for compliance reporting

This guide walks you through connecting your Liongard instance to MSPortal.ai using our streamlined setup wizard. Liongard is a configuration audit platform that continuously inspects your clients' IT environments. By integrating with MSPortal.ai, you can map Liongard metrics directly to compliance checks, bridging automated configuration audits with your compliance reporting workflow.

## Overview

The Liongard integration syncs configuration audit data into MSPortal, allowing you to:

* Import environments, systems, and inspectors from Liongard
* Sync configuration metrics and their current values across all clients
* Track security detections and anomalies
* **View per-device Liongard data** directly in the Device Detail panel with pass/fail/warning metrics and change history
* **Map individual metrics to MSPortal compliance checks** for automated audit evidence

<Info>
  The compliance metric mapping feature is what makes this integration especially powerful. Instead of manually assessing compliance checks, you can link them to live Liongard metrics that update automatically with every inspection cycle.
</Info>

<Info>
  The Liongard integration is currently in **Beta**. Core functionality is complete and available for all users. You will see a "Beta" badge on the Liongard card in the Integrations page.
</Info>

## Prerequisites

Before you begin, ensure you have:

* Active Liongard account with API access
* MSPortal.ai account with integration management permissions
* Companies already set up in MSPortal (from your PSA integration or manually created)

<Note>
  The Liongard integration maps environments to existing companies in MSPortal. Import your companies from your PSA integration first, or create them manually before setting up Liongard.
</Note>

***

## Part 1: Generate API Credentials in Liongard

Before connecting to MSPortal.ai, you need to create API credentials in your Liongard instance.

<Steps>
  <Step title="Log into Liongard">
    Access your Liongard Roar instance. Common instance names include region codes like `us1`, `us2`, `ca1`, `eu1`, but your instance may also have a custom name (e.g., `safari`). Your instance name is the subdomain in your Liongard URL:

    | Example Instance | URL                               |
    | ---------------- | --------------------------------- |
    | **us1**          | `https://us1.app.liongard.com`    |
    | **us2**          | `https://us2.app.liongard.com`    |
    | **ca1**          | `https://ca1.app.liongard.com`    |
    | **safari**       | `https://safari.app.liongard.com` |

    Check your browser's address bar when logged into Liongard to find your instance name.
  </Step>

  <Step title="Navigate to Access Keys">
    In the Liongard dashboard, go to **Admin** > **API** > **Access Keys**.
  </Step>

  <Step title="Create an Access Token">
    Click **Create**. Set the **Expiration Date** to **Unlimited**, then click **Generate**.

    <Warning>
      **Copy both the Access Key and Access Key Secret immediately!** These are only shown once and cannot be retrieved after you leave this page. Store both values securely for use in MSPortal.ai.
    </Warning>
  </Step>

  <Step title="Note Your Roar Instance Name">
    Identify your Liongard Roar instance name. This is the subdomain visible in your browser's address bar when logged into Liongard (e.g., `us1`, `ca1`, or a custom name like `safari`). You will need this when connecting in MSPortal.
  </Step>
</Steps>

### Required Information

Before proceeding to MSPortal, ensure you have the following:

| Information            | Description                                                                                            |
| ---------------------- | ------------------------------------------------------------------------------------------------------ |
| **Roar Instance Name** | Your Liongard instance name (e.g., `us1`, `safari`) or full URL (e.g., `https://us1.app.liongard.com`) |
| **Access Key ID**      | The API key identifier generated above                                                                 |
| **Access Key Secret**  | The API key secret generated above                                                                     |

***

## Part 2: MSPortal Setup Wizard

MSPortal.ai provides a guided 3-step wizard to connect and configure your Liongard integration.

### Starting the Wizard

<Steps>
  <Step title="Navigate to Integrations">
    In MSPortal.ai, go to **Settings > Integrations**.
  </Step>

  <Step title="Start Setup">
    Find the **Liongard** integration card and click **Configure** to launch the setup wizard.
  </Step>
</Steps>

***

### Step 1: Connect

Enter your Liongard API credentials to establish the connection.

<Steps>
  <Step title="Enter Instance URL">
    Enter your Liongard Roar instance name. You can enter either:

    * Just the instance name (e.g., `us1`, `ca1`, `safari`)
    * The full URL (e.g., `https://us1.app.liongard.com`)

    MSPortal will automatically resolve the full URL if you enter only the instance name. Your instance name is the subdomain in your Liongard URL (e.g., the **us1** in `https://us1.app.liongard.com` or **safari** in `https://safari.app.liongard.com`).
  </Step>

  <Step title="Enter API Credentials">
    Fill in the following fields:

    | Field                 | Description                      |
    | --------------------- | -------------------------------- |
    | **Access Key ID**     | Your Liongard API key identifier |
    | **Access Key Secret** | Your Liongard API key secret     |

    <Note>
      Your credentials are stored securely using encrypted vault storage. They are never exposed in logs or API responses.
    </Note>
  </Step>

  <Step title="Test Connection">
    Click **Test Connection** to verify your credentials. You'll see a green "Connection successful" message when the test passes.

    If the connection fails:

    * Verify your Instance URL matches your Liongard region exactly
    * Check that your Access Key ID and Access Key Secret are copied correctly without extra spaces
    * Ensure the API key has not been revoked or expired
    * Confirm your Liongard account has API access enabled
  </Step>

  <Step title="Create Integration">
    Once the connection test passes, click **Create Integration** to save your credentials and proceed.
  </Step>
</Steps>

***

### Step 2: Map Environments

Map Liongard environments to your MSPortal companies. This determines which audit data syncs to which company.

<Steps>
  <Step title="Wait for Initial Sync">
    After creating the integration, MSPortal begins syncing your environments from Liongard. This may take a few minutes depending on the number of environments.

    <Info>
      If no environments appear, wait a few minutes and check back. The initial sync runs in the background.
    </Info>
  </Step>

  <Step title="Use Quick Match (Recommended)">
    Click **Quick Match** to automatically match Liongard environments to MSPortal companies based on name similarity.

    Quick Match uses a confidence threshold to find likely matches. Review the results and adjust any incorrect mappings.

    <Tip>
      Quick Match saves significant time when you have many environments with similar names in both systems. Start here, then manually adjust any mismatches.
    </Tip>
  </Step>

  <Step title="Manual Mapping">
    For environments that weren't automatically matched:

    1. Find the environment in the list
    2. Click the **Select company** dropdown in the "Mapped To" column
    3. Search for and select the correct MSPortal company

    To remove a mapping, click the **X** button next to the company badge.
  </Step>

  <Step title="Review Inspector Types">
    As environments sync, you will see the inspector types discovered in your Liongard instance. These represent the different integration connectors Liongard uses to audit your clients' systems (e.g., Active Directory, Microsoft 365, Firewall inspectors).
  </Step>

  <Step title="Filter Environments">
    Click the summary cards above the list to filter the view:

    * **Total Items** - Show all synced environments
    * **Mapped** - Show only environments linked to companies
    * **Unmapped** - Show environments that still need mapping
  </Step>

  <Step title="Proceed">
    Once you've mapped the environments you need, click **Next** to continue.

    <Warning>
      Only data from mapped environments will sync to MSPortal. You can return to add more mappings at any time.
    </Warning>
  </Step>
</Steps>

***

### Step 3: Configure

Review and configure which data types to sync, and set up compliance metric mapping.

<Steps>
  <Step title="Review Synced Data">
    The Configure step displays counts for each data type as they sync from Liongard:

    | Data Type         | Description                               |
    | ----------------- | ----------------------------------------- |
    | **Environments**  | Customer environments mapped to companies |
    | **Inspectors**    | Integration connectors and their types    |
    | **Systems**       | Monitored assets and infrastructure       |
    | **Metrics**       | Configuration audit data points           |
    | **Metric Values** | Current metric readings with status       |
    | **Detections**    | Security findings and anomalies           |
  </Step>

  <Step title="Sync Data">
    If no data has synced yet, click **Sync All Data** to trigger an initial sync from your mapped environments. The sync runs in the background and may take several minutes.
  </Step>

  <Step title="Complete Setup">
    Click **Complete Setup** to finish the wizard and return to the Integrations page.
  </Step>
</Steps>

***

## Part 3: Map Metrics to Compliance Checks

This is the key feature of the Liongard integration. After the initial sync completes, you can map individual Liongard metrics to MSPortal compliance checks with custom evaluation rules, creating a direct link between automated configuration audits and your compliance reporting.

### Accessing the Metrics Page

Navigate to **Settings > Compliance > Metrics**. This dedicated tab shows all synced metrics from your Liongard instance with options to browse by metric or by device.

<Info>
  For the full guide on creating compliance checks from metrics, custom rule evaluation, and how the auto-sync works with compliance runs, see [Liongard Compliance Metrics](/user-guides/compliance/liongard-metrics).
</Info>

### Quick Start

<Steps>
  <Step title="Browse Metrics">
    Go to **Settings > Compliance > Metrics** to see all synced configuration audit data from Liongard. Use the Per Metric or Per Device tabs to find what you need.
  </Step>

  <Step title="Create a Compliance Check">
    Click any metric row, then click **Create Compliance Check** in the detail panel. Choose to use Liongard's native status or define custom rules with thresholds.
  </Step>

  <Step title="Add to a Compliance Run">
    Add the metric-linked check to a compliance run (directly or through a group). The sync will keep the assignment status current for active runs.
  </Step>
</Steps>

### Why Map Metrics to Compliance Checks?

<CardGroup cols={2}>
  <Card title="Automated Evidence" icon="robot">
    Liongard metrics provide continuous, automated evidence for compliance checks. No more manual assessments for configuration-based requirements.
  </Card>

  <Card title="Custom Rules" icon="sliders">
    Define threshold-based rules like "fail if password length is below 12" instead of relying on Liongard's native pass/fail.
  </Card>

  <Card title="Per-Device Tracking" icon="server">
    Each device gets its own compliance status based on its individual metric value, not a company-wide average.
  </Card>

  <Card title="Historical Snapshots" icon="clock-rotate-left">
    Completed compliance runs freeze as point-in-time snapshots. Start a new run to track ongoing changes.
  </Card>
</CardGroup>

***

## What Gets Synced

| Data Type         | Direction            | Description                               |
| ----------------- | -------------------- | ----------------------------------------- |
| **Environments**  | Liongard to MSPortal | Customer environments for company mapping |
| **Inspectors**    | Liongard to MSPortal | Integration connectors and their types    |
| **Systems**       | Liongard to MSPortal | Monitored assets and infrastructure       |
| **Metrics**       | Liongard to MSPortal | Configuration audit data points           |
| **Metric Values** | Liongard to MSPortal | Current metric readings with status       |
| **Detections**    | Liongard to MSPortal | Security findings and anomalies           |

***

## Part 4: Liongard Data on Devices

Once Liongard environments are mapped and data is synced, you can view Liongard configuration audit data directly on individual devices in the Devices module.

### Accessing the Liongard Tab

<Steps>
  <Step title="Open a Device">
    Navigate to **Devices** and click on any device to open the Device Detail panel.
  </Step>

  <Step title="Select the Liongard Tab">
    If Liongard has data for this device, a **Liongard** tab appears in the detail panel. Click it to view the device's configuration audit data.

    <Info>
      The Liongard tab only appears for devices that Liongard has inspected. MSPortal automatically matches devices to Liongard systems by name, IP address, or MAC address.
    </Info>
  </Step>
</Steps>

### What You See

The Liongard tab displays three main sections:

#### Summary Cards

At the top, summary cards show the overall health of the device's configuration metrics:

* **Passing** - Number of metrics with a passing status (green)
* **Failing** - Number of metrics with a failing status (red)
* **Warning** - Number of metrics with a warning status (orange)

Click any summary card to filter the metrics list to only that status.

#### System Overview

Shows the Liongard system name, environment, inspector type, and when the device was last inspected.

#### Configuration Metrics

Metrics are organized into two collapsible sections:

| Section               | Description                                                                      |
| --------------------- | -------------------------------------------------------------------------------- |
| **Security**          | Security-related metrics such as firewall status, encryption, MFA, and antivirus |
| **Inspected Metrics** | All other configuration metrics from the inspector                               |

Each metric row shows the metric name, current value, and pass/fail/warning status. Click a metric to expand it and see the previous value for comparison.

Use the **search bar** to filter metrics by name or value. Click **Expand/Collapse** to toggle all metric details at once.

#### Recent Changes

The Recent Changes section shows configuration change detections from Liongard. Each entry shows:

* The change description and inspector name
* When the change was detected
* A diff view showing what was added (+) or removed (-) in the configuration

Click any detection to expand and see the full change diff.

### How Device Matching Works

MSPortal automatically matches your imported devices to Liongard systems using multiple strategies:

1. **Direct link** - If the device was previously matched, it uses the stored link
2. **Name match** - Matches by device hostname or name within the same company
3. **IP/MAC fallback** - If no name match is found, attempts to match by IP address or MAC address

Once matched, the link is saved so future lookups are instant.

***

## Managing Your Integration

After setup, manage your integration from **Settings > Integrations**:

| Action             | Description                                                                                                                                                                                                               |
| ------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Configure**      | Re-open the setup wizard to modify settings, update credentials, or adjust environment mappings                                                                                                                           |
| **Import Devices** | Import Liongard systems into your MSPortal device inventory. Map inspector types to device types, enable auto-sync, and ignore categories you don't need. See [Import Devices](/user-guides/integrations/import-devices). |
| **Resync**         | Trigger a fresh sync of all data from Liongard                                                                                                                                                                            |
| **Delete**         | Available inside the Configure wizard -- permanently removes the integration                                                                                                                                              |

### Re-running the Wizard

You can return to any step of the setup wizard at any time:

1. Go to **Settings > Integrations**
2. Click **Configure** on the Liongard card
3. Navigate between steps using the step indicators or Back/Next buttons

### Updating API Credentials

If you need to update your Liongard API credentials:

<Steps>
  <Step title="Open Integration Settings">
    Go to **Settings > Integrations** and click **Configure** on the Liongard card.
  </Step>

  <Step title="Enter New Credentials">
    On the Connect step, enter your new Roar instance name, Access Key ID, and Access Key Secret.
  </Step>

  <Step title="Test Connection">
    Click **Test Connection** to verify the new credentials work.
  </Step>
</Steps>

***

## Troubleshooting

<AccordionGroup>
  <Accordion title="Connection test fails">
    **Causes:**

    * Incorrect Roar instance name, Access Key ID, or Access Key Secret
    * API key has been revoked or expired
    * Liongard account does not have API access enabled

    **Solutions:**

    1. Verify your Roar instance name matches exactly what appears in your Liongard URL (e.g., `us1`, `ca1`, or your custom name)
    2. Check that your Access Key ID and Access Key Secret are copied exactly, without extra spaces
    3. Generate a new access token in Liongard (Admin > API > Access Keys) if the current one is expired
    4. Confirm your Liongard account has API access permissions
  </Accordion>

  <Accordion title="No environments appear in mapping step">
    **Causes:**

    * Initial sync still in progress
    * API key lacks read permissions

    **Solutions:**

    1. Wait a few minutes for the background sync to complete
    2. Click **Sync** to trigger a manual sync
    3. Verify your API key has the necessary read permissions in Liongard
  </Accordion>

  <Accordion title="Metrics not appearing on the Metrics page">
    **Causes:**

    * Metrics sync not yet complete
    * No environments have been mapped to companies
    * Metrics data type not enabled

    **Solutions:**

    1. Ensure at least one environment is mapped to a company
    2. Wait for the metrics sync to complete (this may take several minutes after initial setup)
    3. Verify that Metrics and Metric Values are enabled in the Configure step
  </Accordion>

  <Accordion title="Compliance checks not updating from mapped metrics">
    **Causes:**

    * Metric is not properly mapped to a compliance check
    * Metric values have not synced yet
    * The compliance check was created after the last sync

    **Solutions:**

    1. Navigate to the Metrics page and verify the mapping is in place
    2. Wait for the next sync cycle to update metric values
    3. Trigger a manual sync from the integration settings if needed
  </Accordion>

  <Accordion title="Missing data for some environments">
    **Causes:**

    * Environment is not mapped to a company
    * Inspectors are not configured for that environment in Liongard

    **Solutions:**

    1. Map the environment to a company in the wizard's Map step
    2. Verify that the environment has active inspectors configured in Liongard
  </Accordion>
</AccordionGroup>

***

## Best Practices

<CardGroup cols={2}>
  <Card title="Map Environments First" icon="sitemap">
    Always map your Liongard environments to companies before expecting data to flow. Only mapped environment data syncs to MSPortal.
  </Card>

  <Card title="Use Quick Match" icon="wand-magic-sparkles">
    Start with Quick Match for environment mapping, then manually adjust any incorrect matches. It saves significant time with large environment lists.
  </Card>

  <Card title="Prioritize Key Metrics" icon="bullseye">
    Focus your compliance metric mappings on high-value checks first, such as MFA status, backup verification, and firewall configuration metrics.
  </Card>

  <Card title="Review Regularly" icon="calendar-check">
    Periodically review the Metrics page to map newly discovered metrics as Liongard adds inspectors or your clients' environments change.
  </Card>
</CardGroup>

***

## Security and Privacy

* **Credential Storage**: Your Liongard API credentials are encrypted using vault storage and never exposed in logs or responses
* **Data Isolation**: All synced data is tenant-isolated and only visible to your organization
* **Read-Only Access**: MSPortal only requires read access to Liongard data; it never modifies your Liongard configuration

***

## Related Resources

* [Devices Module](/user-guides/devices/index) - Managing devices and viewing Liongard data in the device detail panel
* [Liongard Compliance Metrics](/user-guides/compliance/liongard-metrics) - Custom rules, per-device tracking, and auto-sync details
* [Compliance Module](/user-guides/compliance/index) - Manage compliance checks and assessments
* [Import Companies](/user-guides/integrations/import-companies) - General company import guide
* [Import Devices](/user-guides/integrations/import-devices) - Import Liongard systems as MSPortal devices
* [Clear and Resync Integrations](/user-guides/integrations/clear-and-resync-integrations) - Troubleshooting sync issues
* [Cork Integration](/user-guides/integrations/enable-cork-integration) - Another security-focused integration

## Need Help?

For assistance with the Liongard integration, contact [support@msportal.ai](mailto:support@msportal.ai).
