Connect CIPP
CIPP (the CyberDrain Improved Partner Portal) is an open-source multi-tenant Microsoft 365 management portal for MSPs. Connecting CIPP to StackJack gives your AI assistant tools for Microsoft 365…
Written By Christopher Scaminaci
Last updated 6 days ago
CIPP (the CyberDrain Improved Partner Portal) is an open-source multi-tenant Microsoft 365 management portal for MSPs. Connecting CIPP to StackJack gives your AI assistant tools for Microsoft 365 users, tenants, groups, Intune device management, Exchange mailboxes, transport rules, conditional access, security, and CIPP standards through StackJack's MCP endpoint. See the generated CIPP tool reference for the current inventory, input schemas, plan tiers, and safety notes. (MCP, the Model Context Protocol, is the open standard that lets AI assistants like Claude, ChatGPT, and Copilot call your MSP tools securely.)
CIPP authenticates through Azure AD (Entra ID) client credentials, so this connector needs more fields than most: six values, all of which CIPP generates for you on one page.
Before you begin
- You need the Owner, co-owner, or Administrator role in StackJack to configure connectors.
- You need access to your CIPP instance's Integrations area (the ability to create CIPP-API clients).
- You need your CIPP instance's default Azure App Service URL — the one ending in
.azurewebsites.net. StackJack cannot connect through a custom domain (see the warning below). - Connecting a connector automatically activates it on the Free plan. You can upgrade to a paid plan at any time from the Connectors page — current pricing is shown in the portal.
Tip: The same steps below are always available in-app — open Connectors, find the CIPP card, and click How To Connect.
Step 1: Create an API client in CIPP
- In your CIPP instance, go to CIPP > Integrations > CIPP-API to open the API configuration page.
- Click Actions > Create New Client. Enter an app name (for example,
StackJack). - Enable the client. For least privilege, use Custom Roles to limit the API endpoints this client can call. Select only the read or write operations your StackJack workflows need.
- Optional: use Allowed IP Ranges to restrict the client to individual IPv4 or IPv6 addresses or CIDR ranges. Do this only after StackJack support gives you the current outbound addresses for your environment; guessing can lock the connector out.
- Submit the client and copy its Application Secret immediately to a secure temporary location.
- Click Actions > Save Azure Configuration so CIPP applies the API-client configuration to Azure. Wait for the page to refresh with the remaining values.
- Leave this page open — you'll copy six fields from it: API URL, Client ID, Secret, API Scope, Token URL, and Tenant ID.
CIPP's human portal roles and an API client's Custom Roles are separate permission systems. Do not assign broad human-role names on the assumption that they describe the API-client boundary.
Step 2: Add the credentials to StackJack
In the StackJack portal, go to Connectors and click Configure on the CIPP card.
Fill in the six fields, copying each from the CIPP API page:
StackJack field From CIPP Notes Instance URL API URL Must be the default *.azurewebsites.netaddress. The dialog shows a red warning and blocks saving if you enter a custom domain.Azure AD Tenant ID Tenant ID The Microsoft tenant hosting your CIPP deployment. Required. API Scope API Scope Looks like api://your-client-id/.default. You can leave it blank to auto-derive it from the Application ID.Token URL Token URL You can leave it blank to auto-derive it from the Tenant ID. Application ID Client ID The Azure app registration's client ID. Application Secret Secret Shown by CIPP after Save Azure Configuration. Click Save.
StackJack cross-checks your entries before saving and stops with a specific warning if something doesn't line up:
- The Instance URL must end in
.azurewebsites.net. - If you filled in a Token URL, the tenant inside it must match the Azure AD Tenant ID field. If they differ, fix one of them — or clear the Token URL to auto-derive it.
- If you filled in an API Scope, it must reference the Application ID. If it doesn't, correct it — or clear the API Scope to auto-derive it.
When you later re-open the dialog on a connected CIPP card, the stored Tenant ID, API Scope, and Token URL are re-loaded for editing; the Application Secret is never re-displayed.
What happens when you save
- Your credentials are stored encrypted in Azure Key Vault. They are never stored in StackJack's database.
- StackJack immediately test-calls CIPP to validate the credentials. CIPP validation can take up to a minute — CIPP runs on Azure Functions, and a cold instance needs time to wake up. Don't close the page early.
- If validation fails or times out, your credentials are still saved and you'll see a warning — validation retries automatically in the background.
- A Free plan subscription for CIPP is activated automatically if you don't already have one.
- If validation keeps failing (three consecutive definitive failures), StackJack auto-disables the connection, emails the tenant owner, and shows Re-enable and Update Credentials buttons on the card.
Troubleshooting
| Symptom | Likely cause and fix |
|---|---|
| Save is blocked with a URL warning | You entered a custom domain. Use the default *.azurewebsites.net App Service URL from the CIPP-API page. |
| Save is blocked with a "different tenant" warning | Your Token URL points at a different Azure AD tenant than the Tenant ID field. Recheck both against the CIPP-API page, or clear the Token URL to auto-derive it. |
| Save is blocked with an "API Scope does not reference the Application ID" warning | The scope belongs to a different app registration. Recheck it, or clear the API Scope to auto-derive it. |
| Validation times out | Usually an Azure Functions cold start. Wait, then click Re-test on the card — background validation also retries automatically. |
| Tools return 403 (forbidden) errors | Review the client under CIPP > Integrations > CIPP-API. Its Custom Roles may exclude the endpoint, its Allowed IP Ranges may exclude StackJack, the client may be disabled, or Save Azure Configuration may not have been run after a change. |
| Connection shows Invalid after working before | The Application Secret may have expired or been rotated, or the CIPP API client was removed. Create/copy fresh values in CIPP and click Update on the card. |
| Card shows Disabled | StackJack auto-disabled the credential after repeated failures. The card shows the exact error plus a recommended action — fix the cause, then click Re-enable (or Update Credentials first). |
Rotating the application secret
In CIPP > Integrations > CIPP-API, open the client's row menu and choose Reset Application Secret. Copy the replacement immediately, then use Update Credentials on the StackJack connector card and run Re-test. Plan the change as a coordinated rotation: the old secret stops working after CIPP resets it.
Disconnecting
Click Disconnect on the CIPP card to delete the stored credentials from Key Vault. Any AI tools using the connector stop working immediately.
⚠ Disconnecting does not cancel a paid plan — billing continues until you cancel it separately. The plan controls only appear while the connector is connected, so end the plan before disconnecting. On a paid connector that button reads Manage on Billing and opens this connector's removal dialog on the Billing page; a legacy website subscription still reads Cancel Plan. If you've already disconnected, save your credentials again to bring the plan controls back, then end the plan.
CIPP tools
cipp_ · 439 tools · Free 176 · Pro 263
Tenants
| Tool | What it does |
|---|---|
cipp_Pro · Write | Add a custom domain to a tenant via POST /api/AddDomain. |
cipp_Pro · Write | Add CIPP service principal permissions to partner tenant. |
cipp_Pro · Write | Multi-action tenant endpoint at POST /api/AddTenant. |
cipp_Pro · Write | Force CIPP to bypass its tenant cache on the next enumeration, via POST /api/ListTenants carrying the body key 'ClearCache' as a real JSON boolean true. |
cipp_Pro · Destructive | Run a domain action against a tenant via DELETE /api/ExecDomainAction. |
cipp_Pro · Write | Edit CIPP tenant configuration via POST /api/EditTenant. |
cipp_Pro · Write | Edit the default user-offboarding settings for a tenant via POST /api/EditTenantOffboardingDefaults. |
cipp_Pro · Destructive | Change CIPP's excluded-licences setting (a CIPP instance setting affecting licence reporting for EVERY tenant), via POST /api/ExecExcludeLicenses. |
cipp_Free · Read-only | Get organization profile information for a tenant including company name, address, technical contacts, and partner information. |
cipp_Free · Read-only | Get detailed information for a specific M365 tenant including organization info, license counts, and domain details. |
cipp_Free · Read-only | List pending application consent requests from users in the tenant awaiting admin approval. |
cipp_Free · Read-only | List CSP (Cloud Solution Provider) license subscriptions for a tenant including subscription name, quantity, and billing cycle. |
cipp_Free · Read-only | List all domains registered for a tenant including verification status, default domain flag, and DNS records. |
cipp_Free · Read-only | List the SKUs CIPP excludes from its licence reporting, via GET /api/ListExcludedLicenses (no parameters — this is a CIPP instance setting, not per-tenant). |
cipp_Free · Read-only | Look up external tenant information by domain or tenant ID. |
cipp_Free · Read-only | CIPP's licence report for a tenant: SKU name, total units, consumed units, and available units. |
cipp_Free · Read-only | List the OAuth application grants in a tenant. |
cipp_Free · Read-only | List current M365 service health status for a tenant. |
cipp_Free · Read-only | List tenant alignment status — how each tenant's configuration compares to the standards templates applied to it — via GET /api/ListTenantAlignment. |
cipp_Free · Read-only | List tenant onboarding status and progress via GET /api/ListTenantOnboarding. |
cipp_Free · Read-only | List all M365 tenants managed by this CIPP instance via POST /api/ListTenants. |
cipp_Pro · Destructive | Onboard a tenant to CIPP via POST /api/ExecOnboardTenant. |
cipp_Pro · Write | Clear CIPP's cached tenant-capabilities data for ONE tenant via GET /api/RemoveTenantCapabilitiesCache, forcing CIPP to re-evaluate that tenant's features and permissions on the next request. |
cipp_Pro · Destructive | Create an M365 organizational message in a tenant, TARGETED AT ONE ENTRA SECURITY GROUP, via GET /api/ExecSendOrgMessage. |
cipp_Pro · Destructive | Configure authentication method policies for a tenant via POST /api/SetAuthMethod. |
Users
| Tool | What it does |
|---|---|
cipp_Free · Write | Start OR poll a Business Email Compromise (BEC) background check for a specific user. |
cipp_Free · Read-only | Evaluate which conditional access policies would apply to a specific user, via GET /api/ListUserConditionalAccessPolicies. |
cipp_Free · Read-only | Get devices registered or owned by a specific user including device name, OS, compliance status, and last sync time. |
cipp_Free · Read-only | Get all group memberships for a specific user including security groups, distribution lists, and M365 groups. |
cipp_Free · Read-only | Get mailbox details for a specific user including mailbox type, size, forwarding rules, and archive status. |
cipp_Free · Read-only | Get per-user MFA status and configuration for a specific user including MFA state, default method, and registered methods. |
cipp_Free · Read-only | Get the profile photo for a specific user. |
cipp_Free · Read-only | Get recent sign-in log entries for a specific user including timestamp, IP address, location, app, and status. |
cipp_Free · Read-only | List users who have basic authentication (legacy auth) enabled. |
cipp_Free · Read-only | List soft-deleted users in the tenant recycle bin. |
cipp_Free · Read-only | List user accounts that have not signed in recently. |
cipp_Free · Read-only | List all users with their MFA registration status and methods. |
cipp_Free · Read-only | Get user count statistics for a tenant including total users, licensed users, guests, and disabled accounts. |
cipp_Free · Read-only | List all users in a tenant including display name, UPN, license status, and account enabled state. |
User Management
| Tool | What it does |
|---|---|
cipp_Pro · Write | Invite an external guest user to the tenant via POST /api/AddGuest. |
cipp_Pro · Write | Save a new Just-In-Time (JIT) admin template via POST /api/AddJITAdminTemplate. |
cipp_Pro · Write | Create a new user in the tenant via POST /api/AddUser. |
cipp_Pro · Write | Create multiple users in a tenant in bulk via POST /api/AddUserBulk. |
cipp_Pro · Write | Save a new-user-creation defaults template for a tenant via POST /api/AddUserDefaults. |
cipp_Pro · Destructive | Execute Business Email Compromise remediation actions on a user via POST /api/ExecBECRemediate. |
cipp_Pro · Destructive | Change license assignments for several users in one call via POST /api/ExecBulkLicense. |
cipp_Pro · Destructive | Clear the on-premises immutable ID (sourceAnchor) for a user via POST /api/ExecClrImmId. |
cipp_Pro · Destructive | Create a Temporary Access Pass (TAP) for a user via POST /api/ExecCreateTAP. |
cipp_Pro · Destructive | Change or delete a device registration in Azure AD / Entra ID via POST /api/ExecDeviceDelete. |
cipp_Pro · Destructive | Enable or disable a user account via POST /api/ExecDisableUser. |
cipp_Pro · Destructive | Dismiss a user's risk state in Azure AD Identity Protection via POST /api/ExecDismissRiskyUser. |
cipp_Pro · Write | Update an existing Just-In-Time (JIT) admin template via POST /api/EditJITAdminTemplate. |
cipp_Pro · Write | Edit properties of an existing user via PATCH /api/EditUser. |
cipp_Pro · Destructive | Add or remove email aliases (proxy addresses) for a user account via POST /api/EditUserAliases. |
cipp_Pro · Destructive | Enable or configure Just-In-Time (JIT) admin access for a user via POST /api/ExecJITAdmin. |
cipp_Free · Write | Look up Microsoft license SKU details by SKU IDs via POST /api/ExecLicenseSearch. |
cipp_Free · Read-only | List currently active Just-In-Time admin sessions via GET /api/ListJITAdmin. |
cipp_Free · Read-only | List available Just-In-Time admin templates. |
cipp_Free · Read-only | List saved new user creation default templates. |
cipp_Free · Read-only | List CIPP user settings configuration including default behaviors for user management operations. |
cipp_Free · Read-only | List the trusted and blocked senders configured for ONE user via GET /api/ListUserTrustedBlockedSenders. |
cipp_Pro · Destructive | Run a multi-step user offboarding workflow against POST /api/ExecOffboardUser. |
cipp_Free · Read-only | Get the status of queued CIPP offboarding jobs via GET /api/CIPPOffboardingJob. |
cipp_Pro · Write | Provision a OneDrive for Business site for a user via POST /api/ExecOnedriveProvision. |
cipp_Pro · Write | Create a OneDrive shortcut for a user to a SharePoint site via POST /api/ExecOneDriveShortCut. |
cipp_Pro · Destructive | Set or unset the password-never-expires flag for a user account via POST /api/ExecPasswordNeverExpires. |
cipp_Pro · Destructive | Apply partial updates to a user record via PATCH /api/PatchUser. |
cipp_Pro · Destructive | Enable, disable, or enforce per-user (legacy) MFA for a specific user via POST /api/ExecPerUserMFA. |
cipp_Pro · Destructive | Permanently remove a soft-deleted object from the tenant recycle bin via POST /api/RemoveDeletedObject. |
cipp_Pro · Destructive | Delete a Just-In-Time (JIT) admin template via POST /api/RemoveJITAdminTemplate. |
cipp_Pro · Destructive | Remove an entry from a user's trusted or blocked senders list via POST /api/RemoveTrustedBlockedSender. |
cipp_Pro · Destructive | Delete a user from the tenant via POST /api/RemoveUser. |
cipp_Pro · Destructive | Remove a saved new-user defaults template via POST /api/RemoveUserDefaultTemplate. |
cipp_Pro · Write | Reprocess license assignments for a user to fix license provisioning errors or stale service plan states, via POST /api/ExecReprocessUserLicenses. |
cipp_Pro · Destructive | Reset MFA registration for a user via POST /api/ExecResetMFA, requiring them to re-register their authentication methods on next sign-in. |
cipp_Pro · Destructive | Reset a user's password via POST /api/ExecResetPass. |
cipp_Pro · Write | Restore a soft-deleted user from the tenant recycle bin via POST /api/ExecRestoreDeleted. |
cipp_Pro · Destructive | Revoke all active sessions and refresh tokens for a user via POST /api/ExecRevokeSessions, forcing re-authentication on all devices. |
cipp_Pro · Destructive | Send a test push notification to a user's registered Microsoft Authenticator MFA device via POST /api/ExecSendPush. |
cipp_Pro · Destructive | Set a directory object's on-premises sync behaviour via POST /api/ExecSetCloudManaged — CIPP PATCHes /beta/{users|groups|contacts}/{ID}/onPremisesSyncBehavior with {"isCloudManaged": <bool>}. |
cipp_Pro · Write | Set or remove the profile photo for a user via POST /api/ExecSetUserPhoto. |
Groups
| Tool | What it does |
|---|---|
cipp_Pro · Write | Create a new group in the tenant via POST /api/AddGroup. |
cipp_Pro · Destructive | Save a group template for reuse via POST /api/AddGroupTemplate. |
cipp_Pro · Destructive | Convert an existing M365 group into a Microsoft Teams team via POST /api/AddGroupTeam. |
cipp_Pro · Destructive | Delete a group from a tenant via POST /api/ExecGroupsDelete. |
cipp_Pro · Write | Edit properties of an existing group via PATCH /api/EditGroup. |
cipp_Pro · Destructive | Set whether a distribution or Microsoft 365 group accepts mail only from internal senders via POST /api/ExecGroupsDeliveryManagement (it writes RequireSenderAuthenticationEnabled). |
cipp_Pro · Write | Show or hide a group in the Global Address List via POST /api/ExecGroupsHideFromGAL (it writes HiddenFromAddressListsEnabled). |
cipp_Free · Read-only | Report whether external senders may email ONE group, via GET /api/ListGroupSenderAuthentication. |
cipp_Free · Read-only | List saved group templates. |
cipp_Free · Read-only | List all groups in a tenant including security groups, distribution lists, M365 groups, and mail-enabled security groups. |
cipp_Free · Read-only | List all directory roles in a tenant including role name, description, and assigned members. |
cipp_Pro · Destructive | Remove a saved group template via POST /api/RemoveGroupTemplate. |
Mailboxes
| Tool | What it does |
|---|---|
cipp_Free · Read-only | Run an Exchange Online mail-flow / connectivity diagnostic via GET /api/ExecMailTest. |
cipp_Free · Read-only | Get calendar sharing permissions for a specific user's mailbox including delegate access levels and shared calendar settings. |
cipp_Free · Read-only | Get contacts folder sharing permissions for a specific user's mailbox. |
cipp_Free · Read-only | Get Client Access Settings (CAS) for a specific mailbox including OWA, ActiveSync, POP, IMAP, and MAPI protocol enablement status. |
cipp_Free · Read-only | Get mobile devices connected to a specific mailbox via ActiveSync or Outlook Mobile. |
cipp_Free · Read-only | Get permission assignments for a specific mailbox including Full Access, Send As, and Send on Behalf delegates. |
cipp_Free · Read-only | Inbox rules for EVERY mailbox in a tenant, via GET /api/ListMailboxRules. |
cipp_Free · Read-only | Get the out-of-office (automatic reply) settings for a specific user including internal/external messages and schedule. |
cipp_Free · Read-only | Run a read-only Exchange Online PowerShell cmdlet via POST /api/ListExoRequest and return its raw output. |
cipp_Free · Read-only | List entries in ONE tenant's Global Address List (GAL) via GET /api/ListGlobalAddressList. |
cipp_Free · Read-only | List mailbox forwarding configuration across the tenant via GET /api/ListMailboxForwarding. |
cipp_Free · Read-only | List ONE tenant's pending and completed mailbox restore requests via GET /api/ListMailboxRestores. |
cipp_Free · Read-only | List all mailboxes in a tenant including user, shared, and resource mailboxes. |
cipp_Free · Read-only | Retrieve ONE quarantined message via GET /api/ListMailQuarantineMessage. |
cipp_Free · Read-only | List users who have been restricted from sending email due to suspected spam or compromise. |
cipp_Free · Read-only | List the shared mailboxes in one tenant that still have sign-in enabled. |
cipp_Free · Read-only | List all shared mailboxes with usage statistics including size, item count, last activity date, and permission assignments. |
cipp_Free · Read-only | Inbox rules for ONE mailbox, via GET /api/ListUserMailboxRules. |
Mailbox Management
| Tool | What it does |
|---|---|
cipp_Pro · Write | Create a new shared mailbox via POST /api/AddSharedMailbox. |
cipp_Pro · Destructive | Convert a mailbox between types via POST /api/ExecConvertMailbox. |
cipp_Pro · Write | Configure whether items sent on behalf of a mailbox by a delegate are also copied to the mailbox owner's Sent Items folder via POST /api/ExecCopyForSent. |
cipp_Pro · Write | Grant, change, or revoke a delegate's access to a mailbox's calendar folder via POST /api/ExecEditCalendarPermissions. |
cipp_Pro · Destructive | Add or remove mailbox permissions (Full Access, Send As, Send on Behalf) on a mailbox via POST /api/ExecEditMailboxPermissions. |
cipp_Pro · Destructive | Enable the online archive mailbox for a user via POST /api/ExecEnableArchive. |
cipp_Pro · Destructive | Enable auto-expanding archive for a mailbox via POST /api/ExecEnableAutoExpandingArchive. |
cipp_Pro · Destructive | Perform an admin action on a mailbox-attached mobile device via GET /api/ExecMailboxMobileDevices. |
cipp_Pro · Write | Show or hide a mailbox from the Global Address List (GAL) via POST /api/ExecHideFromGAL. |
cipp_Pro · Destructive | Manage a High Volume Email (HVE) user account via POST /api/ExecHVEUser. |
cipp_Pro · Destructive | Manage mailbox restore requests via POST /api/ExecMailboxRestore. |
cipp_Pro · Write | Trace email messages via POST /api/ListMessageTrace by sender, recipient, and date range. |
cipp_Pro · Write | Modify calendar folder permissions via POST /api/ExecModifyCalPerms — the cmdlet-style batch alternative to cipp_edit_calendar_permissions. |
cipp_Pro · Write | Modify a mailbox owner's Contacts-folder permissions via POST /api/ExecModifyContactPerms (cmdlet-style batch). |
cipp_Pro · Destructive | Modify mailbox-level permissions via POST /api/ExecModifyMBPerms — the cmdlet-style batch alternative to cipp_edit_mailbox_permissions. |
cipp_Pro · Destructive | Remove a specific inbox rule from a mailbox via POST /api/ExecRemoveMailboxRule. |
cipp_Pro · Destructive | Unblock a user who has been restricted from sending email via POST /api/ExecRemoveRestrictedUser. |
cipp_Pro · Write | Schedule a mailbox-vacation workflow against POST /api/ExecScheduleMailboxVacation. |
cipp_Pro · Write | Schedule a future out-of-office (auto-reply) window for one or more users via POST /api/ExecScheduleOOOVacation. |
cipp_Pro · Destructive | Configure calendar processing settings for a resource mailbox (room or equipment) via POST /api/ExecSetCalendarProcessing — auto-accept, booking window, conflict resolution, processing of external meeting messages, and so on. |
cipp_Pro · Destructive | Configure email forwarding for a mailbox via POST /api/ExecEmailForward. |
cipp_Pro · Destructive | Enable or disable litigation hold on a mailbox via POST /api/ExecSetLitigationHold. |
cipp_Pro · Write | Set the maximum send/receive message size for a mailbox via POST /api/ExecSetMailboxEmailSize. |
cipp_Pro · Write | Set the language and regional settings for a mailbox via POST /api/ExecSetMailboxLocale. |
cipp_Pro · Write | Set ONE storage quota threshold for a mailbox via POST /api/ExecSetMailboxQuota. |
cipp_Pro · Destructive | Enable or disable an existing server-side inbox rule on a mailbox via POST /api/ExecSetMailboxRule. |
cipp_Pro · Write | Configure out-of-office (automatic reply) settings for a mailbox via POST /api/ExecSetOoO with separate internal and external messages. |
cipp_Pro · Write | Set the maximum number of recipients per outbound email message for a mailbox via POST /api/ExecSetRecipientLimits. |
cipp_Pro · Destructive | Enable or disable retention hold on a mailbox via POST /api/ExecSetRetentionHold. |
cipp_Pro · Destructive | Start the Managed Folder Assistant for a mailbox via POST /api/ExecStartManagedFolderAssistant to immediately process retention policies and tags instead of waiting for the next automatic cycle. |
Mailbox Retention
| Tool | What it does |
|---|---|
cipp_Pro · Destructive | Delete retention policies for a tenant via DELETE /api/ExecManageRetentionPolicies. |
cipp_Pro · Destructive | Delete retention tags for a tenant via DELETE /api/ExecManageRetentionTags. |
cipp_Pro · Destructive | Assign an Exchange Online retention policy to one or more mailboxes via POST /api/ExecSetMailboxRetentionPolicies. |
Contacts & Resources
| Tool | What it does |
|---|---|
cipp_Pro · Write | Create a new mail contact in a tenant directory via POST /api/AddContact. |
cipp_Pro · Write | Create a new CIPP contact template via POST /api/AddContactTemplates. |
cipp_Pro · Write | Create a new equipment mailbox for a bookable resource (projector, vehicle, conference phone, etc.) via POST /api/AddEquipmentMailbox. |
cipp_Pro · Write | Create a new room list (group of rooms by building/floor/location) via POST /api/AddRoomList. |
cipp_Pro · Write | Create a new room mailbox via POST /api/AddRoomMailbox. |
cipp_Pro · Destructive | Bulk-deploy CIPP contact templates to create mail contacts across one or more tenants via POST /api/DeployContactTemplates. |
cipp_Pro · Write | Edit an existing mail contact via POST /api/EditContact. |
cipp_Pro · Write | Modify an existing CIPP contact template via POST /api/EditContactTemplates. |
cipp_Pro · Write | Edit properties of an existing equipment mailbox via POST /api/EditEquipmentMailbox — display name, booking settings, calendar processing, location, and resource metadata. |
cipp_Pro · Write | Modify an existing room list via POST /api/EditRoomList — rename it, add/remove member rooms, change owners, or update its delivery settings. |
cipp_Pro · Write | Edit properties of an existing room mailbox via POST /api/EditRoomMailbox — display name, capacity, booking settings, calendar processing, location, and accessibility. |
cipp_Free · Read-only | List CIPP contact templates from the CIPP template store via GET /api/ListContactTemplates. |
cipp_Free · Read-only | List all mail contacts in a tenant. |
cipp_Free · Read-only | List all equipment mailboxes in a tenant. |
cipp_Free · Read-only | List room lists (groups of rooms) in a tenant. |
cipp_Free · Read-only | List all room mailboxes in a tenant. |
cipp_Pro · Destructive | Remove a mail contact via POST /api/RemoveContact. |
cipp_Pro · Destructive | Permanently delete a CIPP contact template via POST /api/RemoveContactTemplates. |
Transport & Spam
| Tool | What it does |
|---|---|
cipp_Pro · Destructive | Configure a connection filter policy via POST /api/AddConnectionFilter. |
cipp_Pro · Write | Save a connection filter policy as a reusable CIPP template via POST /api/AddConnectionFilterTemplate. |
cipp_Pro · Destructive | Add or edit a full Exchange transport rule via POST /api/AddEditTransportRule (the unified high-fidelity authoring endpoint, distinct from the thin cipp_add_transport_rule and cipp_edit_transport_rule). |
cipp_Pro · Write | Save an Exchange connector configuration as a reusable CIPP template via POST /api/AddExConnectorTemplate. |
cipp_Pro · Destructive | Create a new Exchange connector for mail routing via POST /api/AddExConnector. |
cipp_Pro · Destructive | Create a new quarantine policy via POST /api/AddQuarantinePolicy. |
cipp_Pro · Destructive | Create a new spam filter (hosted content filter) policy AND its matching rule via POST /api/AddSpamFilter. |
cipp_Pro · Write | Save a spam filter policy as a reusable CIPP template via POST /api/AddSpamFilterTemplate. |
cipp_Pro · Destructive | Add entries to the Tenant Allow/Block List via POST /api/AddTenantAllowBlockList. |
cipp_Pro · Destructive | Create OR update an Exchange transport rule (mail flow rule) via POST /api/AddTransportRule — it is an UPSERT: CIPP runs Get-TransportRule per tenant and, when a rule whose Identity equals the parsed payload's 'name' already exists, runs Set-TransportRule against it instead of New-TransportRule. |
cipp_Pro · Write | Save a transport (mail flow) rule as a reusable CIPP template via POST /api/AddTransportTemplate. |
cipp_Pro · Destructive | Enable or disable an anti-phishing RULE via POST /api/EditAntiPhishingFilter. |
cipp_Pro · Destructive | Enable or disable an existing Exchange connector via POST /api/EditExConnector. |
cipp_Pro · Destructive | Enable or disable a malware filter RULE via POST /api/EditMalwareFilter. |
cipp_Pro · Destructive | Edit an existing quarantine policy via POST /api/EditQuarantinePolicy. |
cipp_Pro · Destructive | Enable or disable a Safe Attachments (ATP) RULE via POST /api/EditSafeAttachmentsFilter. |
cipp_Pro · Destructive | Enable or disable a spam filter (hosted content filter) RULE via POST /api/EditSpamFilter. |
cipp_Pro · Destructive | Enable or disable an existing Exchange transport rule via POST /api/EditTransportRule. |
cipp_Free · Read-only | List saved connection filter policy templates. |
cipp_Free · Read-only | List connection filter policies for a tenant. |
cipp_Free · Read-only | List saved Exchange connector templates from the CIPP template store via GET /api/ListExConnectorTemplates. |
cipp_Free · Read-only | List all Exchange connectors for a tenant including inbound and outbound connectors, their type, status, and routing configuration. |
cipp_Free · Read-only | List quarantined email messages for a tenant. |
cipp_Free · Read-only | List quarantine policies for a tenant via POST /api/ListQuarantinePolicy. |
cipp_Free · Read-only | List saved spam filter policy templates. |
cipp_Free · Read-only | List spam filter policies for a tenant including policy name, spam action thresholds, allowed/blocked senders, and content filtering settings. |
cipp_Free · Read-only | List one tenant's Tenant Allow/Block List entries (blocked and allowed senders, URLs and file hashes) via GET /api/ListTenantAllowBlockList. |
cipp_Free · Read-only | List all Exchange transport rules (mail flow rules) for a tenant. |
cipp_Free · Read-only | List saved transport (mail flow) rule templates from the CIPP template store via GET /api/ListTransportRulesTemplates. |
cipp_Pro · Destructive | Manage a quarantined message via POST /api/ExecQuarantineManagement. |
cipp_Pro · Destructive | Permanently delete a connection filter policy template from the CIPP template store via POST /api/RemoveConnectionfilterTemplate (note: 'Connectionfilter' lowercase 'f' in the URL — preserve the underlying CIPP path). |
cipp_Pro · Destructive | Permanently delete an Exchange connector template from the CIPP template store via POST /api/RemoveExConnectorTemplate. |
cipp_Pro · Destructive | Remove an Exchange connector via POST /api/RemoveExConnector. |
cipp_Pro · Destructive | Remove a quarantine policy via POST /api/RemoveQuarantinePolicy. |
cipp_Pro · Destructive | Remove a spam filter rule and its policy via POST /api/RemoveSpamfilter (note: 'Spamfilter' lowercase 'f' in the URL — preserve the underlying CIPP path). |
cipp_Pro · Destructive | Permanently delete a spam filter policy template from the CIPP template store via POST /api/RemoveSpamfilterTemplate (note: 'Spamfilter' lowercase 'f' in the URL — preserve the underlying CIPP path). |
cipp_Pro · Destructive | Remove entries from the Tenant Allow/Block List via POST /api/RemoveTenantAllowBlockList. |
cipp_Pro · Destructive | Remove an Exchange transport rule via POST /api/RemoveTransportRule. |
cipp_Pro · Destructive | Permanently delete a transport rule template from the CIPP template store via POST /api/RemoveTransportRuleTemplate. |
Devices
| Tool | What it does |
|---|---|
cipp_Free · Read-only | Get detailed information for a specific Intune device including hardware, OS version, compliance, and encryption status. |
cipp_Free · Read-only | List Intune app protection policies (MAM) for a tenant. |
cipp_Free · Read-only | List Intune application install status across devices via GET /api/ListAppStatus (upstream POSTs Graph beta deviceManagement/reports/getDeviceInstallStatusReport). |
cipp_Free · Read-only | List Intune-managed applications for a tenant. |
cipp_Free · Read-only | List saved Intune assignment-filter TEMPLATES (the reusable definitions, not tenant-deployed filters) via GET /api/ListAssignmentFilterTemplates. |
cipp_Free · Read-only | List Intune assignment filters (Graph beta deviceManagement/assignmentFilters) via GET /api/ListAssignmentFilters. |
cipp_Free · Read-only | List Windows Autopilot deployment profiles and configuration settings for a tenant. |
cipp_Free · Read-only | List all Windows Autopilot registered devices for a tenant. |
cipp_Free · Read-only | List Intune device compliance policies for a tenant. |
cipp_Free · Read-only | List Microsoft Defender for Endpoint device status for a tenant. |
cipp_Free · Read-only | List Microsoft Defender Threat & Vulnerability Management data for a tenant. |
cipp_Free · Read-only | List Intune-managed devices that have a specific detected application installed (Graph beta deviceManagement/detectedApps/{AppID}/managedDevices) via GET /api/ListDetectedAppDevices. |
cipp_Free · Read-only | List applications detected on Intune-managed devices for a tenant. |
cipp_Free · Read-only | List all Intune-managed devices for a tenant. |
cipp_Free · Read-only | List Intune security-baseline and endpoint-protection intents — the legacy template-based policies — via GET /api/ListIntuneIntents, which reads Graph beta deviceManagement/Intents with $expand=settings,categories (so each intent carries its expanded settings and categories; these are NOT assignments). |
cipp_Free · Read-only | List Intune device configuration policies for a tenant. |
cipp_Free · Read-only | List saved Intune reusable-setting TEMPLATES (the reusable definitions, not tenant-deployed reusable settings) via GET /api/ListIntuneReusableSettingTemplates. |
cipp_Free · Read-only | List Intune reusable policy settings (Graph beta deviceManagement/reusablePolicySettings) via GET /api/ListIntuneReusableSettings. |
cipp_Free · Read-only | List Intune PowerShell and remediation scripts deployed to a tenant. |
cipp_Free · Read-only | List saved Intune policy TEMPLATES (the reusable definitions, not tenant-deployed policies) via GET /api/ListIntuneTemplates. |
Device Management
| Tool | What it does |
|---|---|
cipp_Pro · Write | Create a new Intune assignment filter via POST /api/AddAssignmentFilter. |
cipp_Pro · Write | Create a saved Intune assignment-filter TEMPLATE (the reusable definition, not a tenant-deployed filter) via POST /api/AddAssignmentFilterTemplate. |
cipp_Pro · Write | Create a Windows Autopilot deployment profile in one or more tenants via POST /api/AddAutopilotConfig. |
cipp_Pro · Write | Register one or more devices in Windows Autopilot via POST /api/AddAPDevice (Partner Center DeviceBatches). |
cipp_Pro · Destructive | Deploy a Microsoft Defender for Endpoint baseline to one or more tenants via POST /api/AddDefenderDeployment. |
cipp_Pro · Write | Create an Enrollment Status Page (ESP) / device enrollment configuration in one or more tenants via POST /api/AddEnrollment. |
cipp_Pro · Write | DEPLOY a SAVED reusable-setting TEMPLATE into a tenant via POST /api/AddIntuneReusableSetting. |
cipp_Pro · Write | Create a saved Intune reusable-setting TEMPLATE via POST /api/AddIntuneReusableSettingTemplate. |
cipp_Pro · Write | Create a saved Intune policy TEMPLATE via POST /api/AddIntuneTemplate. |
cipp_Pro · Destructive | Create OR OVERWRITE an Intune device configuration / compliance policy via POST /api/AddPolicy. |
cipp_Pro · Destructive | Associate an Autopilot device with a user via POST /api/ExecAssignAPDevice (Graph UpdateDeviceProperties). |
cipp_Pro · Destructive | Assign an Intune policy to groups, users, or all devices via POST /api/ExecAssignPolicy. |
cipp_Pro · Destructive | Delete an Intune assignment filter via DELETE /api/ExecAssignmentFilter. |
cipp_Pro · Destructive | Execute a remote action on an Intune device via POST /api/ExecDeviceAction. |
cipp_Pro · Destructive | Execute a passcode-related action on an Intune device via POST /api/ExecDevicePasscodeAction. |
cipp_Pro · Destructive | Edit an existing Intune assignment filter via POST /api/EditAssignmentFilter. |
cipp_Pro · Destructive | Rename and/or re-describe an existing Intune policy via POST /api/EditIntunePolicy. |
cipp_Pro · Destructive | Edit an existing Intune PowerShell or remediation script via POST /api/EditIntuneScript. |
cipp_Pro · Destructive | Rename and/or re-describe an ADMX group-policy configuration via POST /api/EditPolicy. |
cipp_Pro · Write | Look up BitLocker recovery keys via POST /api/ExecBitlockerSearch. |
cipp_Pro · Write | Retrieve the LAPS (Local Administrator Password Solution) password for a specific Intune device via POST /api/ExecGetLocalAdminPassword. |
cipp_Pro · Write | Retrieve the BitLocker recovery key for a specific Intune device via POST /api/ExecGetRecoveryKey. |
cipp_Pro · Destructive | Delete a saved Intune assignment-filter TEMPLATE via POST /api/RemoveAssignmentFilterTemplate. |
cipp_Pro · Destructive | Remove a Windows Autopilot deployment profile via POST /api/RemoveAutopilotConfig. |
cipp_Pro · Destructive | Remove a device from Windows Autopilot via POST /api/RemoveAPDevice. |
cipp_Pro · Destructive | Remove a reusable setting from a tenant's Intune via POST /api/RemoveIntuneReusableSetting. |
cipp_Pro · Destructive | Delete a saved Intune reusable-setting TEMPLATE via POST /api/RemoveIntuneReusableSettingTemplate. |
cipp_Pro · Destructive | Remove an Intune PowerShell or remediation script via POST /api/RemoveIntuneScript. |
cipp_Pro · Destructive | Delete a saved Intune policy TEMPLATE via POST /api/RemoveIntuneTemplate. |
cipp_Pro · Destructive | Remove an Intune device configuration or compliance policy via POST /api/RemovePolicy. |
cipp_Pro · Write | Rename an Autopilot device via POST /api/ExecRenameAPDevice. |
cipp_Pro · Destructive | Set the group tag on an Autopilot device via POST /api/ExecSetAPDeviceGroupTag. |
cipp_Pro · Write | Trigger a sync of all Windows Autopilot devices for a tenant via POST /api/ExecSyncAPDevices. |
cipp_Pro · Write | Synchronize Apple Device Enrollment Program (DEP) devices for a tenant via POST /api/ExecSyncDEP. |
Security
| Tool | What it does |
|---|---|
cipp_Pro · Destructive | Create a Conditional Access policy for a tenant via POST /api/AddCAPolicy. |
cipp_Pro · Destructive | Modify an existing Conditional Access policy for a tenant via POST /api/EditCAPolicy. |
cipp_Free · Read-only | List anti-phishing filter policies for a tenant. |
cipp_Free · Read-only | List recent changes to Conditional Access policies for a tenant. |
cipp_Free · Read-only | List all Conditional Access policies for a tenant. |
cipp_Free · Read-only | List malware filter policies for a tenant. |
cipp_Free · Read-only | List Microsoft Defender for Office 365 alerts for a tenant. |
cipp_Free · Read-only | List named locations (IP ranges and countries) used in Conditional Access policies for a tenant. |
cipp_Free · Read-only | List Safe Attachments policies for a tenant. |
cipp_Free · Read-only | List Safe Links policies for a tenant. |
cipp_Free · Read-only | List Microsoft 365 security alerts for a tenant. |
cipp_Free · Read-only | List Microsoft 365 security incidents for a tenant. |
cipp_Pro · Destructive | Update a Microsoft Defender for Office 365 alert via POST /api/ExecSetMdoAlert — CIPP PATCHes Microsoft Graph beta /security/alerts_v2/{GUID} as the CIPP application. |
cipp_Pro · Destructive | Update a Microsoft 365 security alert via POST /api/ExecSetSecurityAlert. |
cipp_Pro · Destructive | Update a Microsoft 365 security incident via POST /api/ExecSetSecurityIncident — CIPP PATCHes Microsoft Graph beta /security/incidents/{GUID} as the CIPP application. |
Conditional Access
| Tool | What it does |
|---|---|
cipp_Pro · Write | Save a Conditional Access policy as a CIPP template via POST /api/AddCATemplate. |
cipp_Pro · Write | Create a Conditional Access named location via POST /api/AddNamedLocation. |
cipp_Free · Read-only | Simulate ('what if') a Conditional Access evaluation via POST /api/ExecCACheck — read-only: no sign-in occurs and no policy is changed. |
cipp_Pro · Destructive | Manage Conditional Access user exclusions via POST /api/ExecCAExclusion — a WRITE that adds or removes a user's exclusion on a CA policy, and with 'vacation' schedules the add/remove pair as tasks. |
cipp_Pro · Destructive | Add the service-provider exception to a Conditional Access policy for a tenant via POST /api/ExecCAServiceExclusion — a WRITE that edits the named policy. |
cipp_Pro · Destructive | Modify or delete an existing Conditional Access named location via POST /api/ExecNamedLocation. |
cipp_Free · Read-only | List all Conditional Access policy templates available in CIPP. |
cipp_Pro · Destructive | Delete a Conditional Access policy from a tenant via POST /api/RemoveCAPolicy (a Graph DELETE on the policy). |
cipp_Pro · Destructive | Delete a Conditional Access policy template via POST /api/RemoveCATemplate. |
Safe Links
| Tool | What it does |
|---|---|
cipp_Pro · Destructive | Deploy one or more Safe Links policy templates to one or more tenants in bulk via POST /api/AddSafeLinksPolicyFromTemplate. |
cipp_Pro · Write | Create a new Safe Links policy template in the CIPP template store via POST /api/AddSafeLinksPolicyTemplate. |
cipp_Pro · Destructive | Create a new Defender for Office Safe Links policy + rule pair in a tenant via POST /api/ExecNewSafeLinksPolicy. |
cipp_Pro · Write | Create a NEW Safe Links policy template in the CIPP template store from the fields in this request via POST /api/CreateSafeLinksPolicyTemplate. |
cipp_Pro · Destructive | Permanently delete a Safe Links policy + rule pair from a tenant via POST /api/ExecDeleteSafeLinksPolicy. |
cipp_Pro · Destructive | Modify an existing Safe Links policy + rule pair via POST /api/EditSafeLinksPolicy. |
cipp_Pro · Destructive | Replace the stored contents of an existing Safe Links policy template in CIPP via POST /api/EditSafeLinksPolicyTemplate. |
cipp_Free · Read-only | Get the full configuration of a specific Safe Links policy in a tenant via POST /api/ListSafeLinksPolicyDetails. |
cipp_Free · Read-only | Get the full configuration of a specific Safe Links policy template stored in CIPP via POST /api/ListSafeLinksPolicyTemplateDetails. |
cipp_Free · Read-only | List all Safe Links policy templates available in CIPP. |
cipp_Pro · Destructive | Permanently delete a Safe Links policy template from the CIPP template store via POST /api/RemoveSafeLinksPolicyTemplate. |
Teams & SharePoint
| Tool | What it does |
|---|---|
cipp_Pro · Write | Create a new SharePoint site via POST /api/AddSite. |
cipp_Pro · Write | Create multiple SharePoint sites in bulk via POST /api/AddSiteBulk. |
cipp_Pro · Write | Create a new Microsoft Team for a tenant via POST /api/AddTeam. |
cipp_Pro · Destructive | Assign a Teams phone number to a user or resource account — or set a number's emergency location — via POST /api/ExecTeamsVoicePhoneNumberAssignment. |
cipp_Pro · Destructive | Delete a SharePoint site via POST /api/DeleteSharepointSite. |
cipp_Free · Read-only | Get SharePoint Online storage quota and usage for a tenant. |
cipp_Free · Read-only | Get SharePoint Online tenant-level settings. |
cipp_Free · Read-only | Get the SharePoint admin center URL for ONE tenant via GET /api/ListSharepointAdminUrl. |
cipp_Free · Read-only | List members of a SharePoint site via GET /api/ListSiteMembers. |
cipp_Free · Read-only | List SharePoint sites (or OneDrive usage accounts) for a tenant via GET /api/ListSites. |
cipp_Free · Read-only | List all Microsoft Teams for a tenant. |
cipp_Free · Read-only | List Microsoft Teams activity reports for a tenant. |
cipp_Free · Read-only | List ONE tenant's Teams Location Information Service (LIS) locations via GET /api/ListTeamsLisLocation. |
cipp_Free · Read-only | List Microsoft Teams voice and telephony configuration for a tenant. |
cipp_Pro · Destructive | Remove a phone number assignment from a Teams user via POST /api/ExecRemoveTeamsVoicePhoneNumberAssignment. |
cipp_Pro · Write | Add or REMOVE a user in a SharePoint site role via POST /api/ExecSetSharePointMember. |
cipp_Pro · Destructive | Grant or revoke SITE COLLECTION ADMINISTRATOR rights on a OneDrive or SharePoint site via POST /api/ExecSharePointPerms. |
Standards
| Tool | What it does |
|---|---|
cipp_Pro · Write | Save a new Best Practice Analyzer template via POST /api/AddBPATemplate. |
cipp_Pro · Destructive | Create or REPLACE a reusable CIPP standards template via POST /api/AddStandardsTemplate. |
cipp_Pro · Destructive | Create or REPLACE a tenant's standards deployment via POST /api/AddStandardsDeploy. |
cipp_Pro · Write | Clone a drift template into a new standards baseline via POST /api/ExecDriftClone. |
cipp_Free · Read-only | List Best Practice Analyzer results for a tenant. |
cipp_Free · Read-only | List saved Best Practice Analyzer templates. |
cipp_Free · Read-only | Run detailed domain analysis for a tenant. |
cipp_Free · Read-only | Run ONE real-time DNS / email-security check against ONE domain via GET /api/ListDomainHealth. |
cipp_Free · Read-only | List saved CIPP standard templates. |
cipp_Free · Read-only | List deployed CIPP standards for a tenant. |
cipp_Free · Read-only | Compare a tenant's current configuration against the CIPP standards template. |
cipp_Free · Read-only | Detect configuration drift for a tenant. |
cipp_Pro · Destructive | Remove a saved Best Practice Analyzer template via POST /api/RemoveBPATemplate. |
cipp_Pro · Destructive | Remove a tenant's deployed standards row via GET /api/RemoveStandard. |
cipp_Pro · Destructive | Remove a saved CIPP standards template via POST /api/RemoveStandardTemplate. |
cipp_Pro · Write | Queue a Best Practice Analyzer run for a tenant via POST /api/ExecBPA. |
cipp_Pro · Destructive | Convert EVERY legacy standards row in the entire CIPP instance to the current StandardsTemplateV2 format via GET /api/ExecStandardConvert. |
cipp_Pro · Destructive | Trigger a CIPP standards ENFORCEMENT run via GET /api/ExecStandardsRun. |
cipp_Pro · Destructive | Update drift deviation statuses for a tenant, or clear that tenant's drift customizations, via POST /api/ExecUpdateDriftDeviation. |
Audit
| Tool | What it does |
|---|---|
cipp_Pro · Destructive | Create (or REPLACE) an AUDIT-LOG alert rule via POST /api/AddAlert — a row in CIPP's WebhookRules table that fires when matching unified-audit-log events arrive. |
cipp_Pro · Write | Raise a one-off CIPP notification via POST /api/ExecAddAlert — it fires CIPP's OWN configured notification channels and/or writes a CIPP log entry. |
cipp_Free · Read-only | List the CIPP alerts queue via GET /api/ListAlertsQueue. |
cipp_Free · Read-only | GET /api/ListAuditLogSearches — THREE unrelated views behind one endpoint, selected by 'type', each returning a DIFFERENT row shape. |
cipp_Free · Read-only | Test audit log availability and configuration. |
cipp_Free · Read-only | List CIPP's ALERT-MATCHED audit records via GET /api/ListAuditLogs — NOT the Microsoft 365 unified audit log. |
cipp_Free · Read-only | List CIPP's own operation logs (errors, status messages, per-API activity) via GET /api/ListLogs — the post-write verification surface: after a CIPP write answers 200, check here whether the operation actually logged an error. |
cipp_Free · Read-only | List webhook subscriptions that are pending validation or delivery via GET /api/ListPendingWebhooks. |
cipp_Free · Read-only | List Azure AD sign-in logs for a tenant. |
cipp_Free · Read-only | List configured webhook alert subscriptions. |
cipp_Pro · Destructive | Permanently delete one queued alert via POST /api/RemoveQueuedAlert. |
cipp_Pro · Write | POST /api/ExecAuditLogSearch — TWO unrelated mechanisms behind one endpoint, selected by the 'Action' key. |
GDAP
| Tool | What it does |
|---|---|
cipp_Pro · Destructive | Create GDAP role→group mappings in your PARTNER tenant via POST /api/ExecAddGDAPRole. |
cipp_Pro · Destructive | Kick off CIPP's sweep of RECENTLY ACTIVATED GDAP relationships via GET /api/ExecGDAPInviteApproved. |
cipp_Pro · Write | Auto-extend an expiring GDAP relationship via POST /api/ExecAutoExtendGDAP. |
cipp_Pro · Destructive | Revoke a pending GDAP invitation via DELETE /api/ExecGDAPInvite. |
cipp_Pro · Destructive | Delete a GDAP relationship via POST /api/ExecDeleteGDAPRelationship. |
cipp_Pro · Destructive | Delete a GDAP role mapping via POST /api/ExecDeleteGDAPRoleMapping. |
cipp_Pro · Destructive | Permanently delete a stored GDAP role template via DELETE /api/ExecGDAPRoleTemplate?Action=Delete. |
cipp_Free · Read-only | List the access assignments of ONE GDAP relationship via GET /api/ListGDAPAccessAssignments: the security groups granted access through that relationship and the roles each group maps to. |
cipp_Free · Read-only | List pending GDAP relationship invitations across your partner tenant. |
cipp_Free · Read-only | List the GDAP delegated admin relationships of your partner tenant via GET /api/ListGDAPRelationships: each relationship's id, customer tenant, requested roles, status, duration and expiry. |
cipp_Free · Read-only | List all GDAP (Granular Delegated Admin Privileges) roles available in your partner tenant. |
cipp_Free · Read-only | List partner relationships (DAP/GDAP) for a specific tenant. |
cipp_Pro · Destructive | Reconcile one GDAP relationship's access assignments against a stored GDAP role template, via PATCH /api/ExecGDAPAccessAssignment. |
cipp_Pro · Destructive | Remove the Global Administrator role from a GDAP relationship via POST /api/ExecGDAPRemoveGArole. |
Scheduler
| Tool | What it does |
|---|---|
cipp_Pro · Destructive | Create, edit, or immediately re-run a CIPP scheduled task via POST /api/AddScheduledItem. |
cipp_Free · Read-only | Get details for a single scheduled item via POST /api/ListScheduledItemDetails. |
cipp_Free · Read-only | List all scheduled tasks and jobs in CIPP. |
cipp_Pro · Destructive | Remove a scheduled task from CIPP. |
cipp_Pro · Destructive | Trigger an immediate scheduler billing run via GET /api/ExecSchedulerBillingRun. |
Utility
| Tool | What it does |
|---|---|
cipp_Pro · Write | RUN a Have I Been Pwned breach search for a tenant via POST /api/ExecBreachSearch. |
cipp_Free · Read-only | Look up geographic location information for an IP address via POST /api/ExecGeoIPLookup. |
cipp_Free · Read-only | Get current CIPP system alerts and notifications. |
cipp_Free · Read-only | Read CIPP's own background-job queue via GET /api/ListCippQueue. |
cipp_Free · Read-only | Get the current CIPP instance version and build information. |
cipp_Pro · Write | Execute a single custom Microsoft Graph API request against a tenant via GET /api/ListGraphRequest. |
cipp_Free · Read-only | List known data breaches for ONE account or domain via GET /api/ListBreachesAccount. |
cipp_Free · Read-only | List known data breaches associated with ONE tenant's domain via GET /api/ListBreachesTenant. |
cipp_Free · Read-only | List the CSP (Cloud Solution Provider) SKUs and license offerings available to ONE tenant via GET /api/ListCSPsku. |
cipp_Free · Read-only | List ONE tenant's users and groups together for quick directory browsing via GET /api/ListUsersAndGroups. |
cipp_Pro · Destructive | Add, change, remove, cancel or schedule the removal of Sherweb CSP license subscriptions via POST /api/ExecCSPLicense. |
cipp_Free · Read-only | Search across all CIPP data for a tenant including users, devices, groups, and policies. |
cipp_Free · Read-only | Search CIPP's cached tenant data with the V2 search engine via GET /api/ExecUniversalSearchV2. At CIPP-API master @df3738d the endpoint searches ONE data type per call, chosen by 'type': Users (the default), Groups, Applications or Licenses. |
Diagnostics
| Tool | What it does |
|---|---|
cipp_Pro · Read-only | Query Application Insights telemetry for the CIPP backend via GET /api/ExecAppInsightsQuery. |
cipp_Free · Read-only | Start a CIPP database cache SYNC via GET /api/ExecCIPPDBCache. |
cipp_Pro · Write | Clone a CIPP template (CA, standards, alert, etc.) via POST /api/ExecCloneTemplate. |
cipp_Pro · Write | Refresh CSP Vendor (CPV) consent and permissions across managed tenants via GET /api/ExecCPVRefresh. |
cipp_Pro · Destructive | Delete a saved Graph Explorer preset via DELETE /api/ExecGraphExplorerPreset. |
cipp_Pro · Write | Generate SAS-signed URLs to download CIPP application logs via POST /api/ExecCippLogsSas. |
cipp_Pro · Read-only | Read CIPP Durable Functions state via GET /api/ExecDurableFunctions. |
cipp_Pro · Destructive | Edit a stored CIPP template (CA, standards, alert, Intune, etc.) via POST /api/ExecEditTemplate. |
cipp_Free · Read-only | List the NinjaOne extension processing queue via GET /api/ExecExtensionNinjaOneQueue. |
cipp_Free · Read-only | List the low-friction trial license allotments visible from the M365 admin portal for a tenant via GET /api/ListAdminPortalLicenses (camelCase 'tenantFilter' query, required). |
cipp_Free · Read-only | Run the CIPP API self-test via GET /api/ListApiTest. |
cipp_Free · Read-only | Get ONE tenant's Entra Connect (Azure AD Connect) status via GET /api/ListAzureADConnectStatus: whether directory sync is on, the sync interval, password hash sync and pass-through authentication settings, the last sync time, and the directory objects currently in a sync error state. |
cipp_Pro · Read-only | List CIPP backup snapshots via GET /api/ExecListBackup. |
cipp_Free · Read-only | List the extension (external system) alerts CIPP has recorded for one tenant, newest first, via GET /api/ListCheckExtAlerts. |
cipp_Free · Read-only | List CIPP custom-data-mapping definitions via GET /api/ListCustomDataMappings. |
cipp_Free · Read-only | List ONE tenant's CIPP database cache contents via GET /api/ListDBCache. |
cipp_Pro · Read-only | List saved diagnostic query presets via GET /api/ListDiagnosticsPresets. |
cipp_Free · Read-only | Resolve Entra ID directory objects by ID for a tenant via POST /api/ListDirectoryObjects. |
cipp_Free · Read-only | Read CIPP extension cache data for a tenant via POST /api/ListExtensionCacheData. |
cipp_Free · Read-only | List CIPP extension configurations via GET /api/ListExtensionsConfig. |
cipp_Free · Read-only | List CIPP feature flags via GET /api/ListFeatureFlags. |
cipp_Free · Read-only | List the parameter schema for a CIPP function via GET /api/ListFunctionParameters. |
cipp_Free · Read-only | List CIPP function execution statistics via GET /api/ListFunctionStats. |
cipp_Free · Read-only | Run the CIPP generic test function via GET /api/ListGenericTestFunction. |
cipp_Free · Read-only | List saved Graph Explorer query presets via GET /api/ListGraphExplorerPresets. |
cipp_Free · Read-only | List HaloPSA clients visible to CIPP via GET /api/ListHaloClients. |
cipp_Free · Read-only | List CIPP's allowed IP ranges via GET /api/ListIPWhitelist. |
cipp_Free · Read-only | List the CIPP known-IP database for a tenant via GET /api/ListKnownIPDb. |
cipp_Pro · Read-only | Read the CIPP notification configuration via GET /api/ListNotificationConfig. |
cipp_Pro · Destructive | Configure Microsoft Partner Center webhook delivery via POST /api/ExecPartnerWebhook. |
cipp_Pro · Write | Enable or disable CIPP automatic backups via POST /api/ExecSetCIPPAutoBackup. |
cipp_Pro · Write | Tag a CIPP package (e.g., for app deployments) via POST /api/ExecSetPackageTag. |
cipp_Pro · Write | Persist a CIPP UI user's bookmarks via POST /api/ExecUserBookmarks. |
cipp_Pro · Write | Save a CIPP UI user's app settings via POST /api/ExecUserSettings. |
Analytics
| Tool | What it does |
|---|---|
cipp_Pro · Destructive | Create OR UPDATE a CIPP test report definition via POST /api/AddTestReport — this endpoint is an UPSERT, not a create. |
cipp_Pro · Read-only | Get Best Practice Analyzer results across all managed tenants. |
cipp_Pro · Read-only | Get the device compliance summary across all managed tenants via GET /api/ListAllTenantDeviceCompliance, read from Microsoft 365 Lighthouse's managed-tenant compliance data. |
cipp_Pro · Write | WRITE — acknowledge or resolve ONE Microsoft Secure Score control for a tenant via POST /api/ExecUpdateSecureScore. |
cipp_Pro · Read-only | Run many Microsoft Graph READS for one tenant in a single batched call via POST /api/ListGraphBulkRequest. |
cipp_Pro · Destructive | Delete a CIPP test report definition via POST /api/DeleteTestReport. |
cipp_Pro · Read-only | Read a tenant's Microsoft Secure Score via GET /api/ListGraphRequest with Endpoint=security/secureScores. |
cipp_Free · Read-only | List the full catalogue of CIPP tests that can be selected for a report via GET /api/ListAvailableTests. |
cipp_Pro · Read-only | Read the Microsoft Secure Score control profile catalog via GET /api/ListGraphRequest with Endpoint=security/secureScoreControlProfiles. |
cipp_Free · Read-only | List saved CIPP test report definitions via GET /api/ListTestReports. |
cipp_Free · Read-only | List the results of a test run for a tenant via POST /api/ListTests. |
cipp_Pro · Destructive | Offboard a customer tenant via PATCH /api/ExecOffboardTenant. |
cipp_Pro · Write | Start domain analysis for ONE tenant via POST /api/ExecDomainAnalyser. |
cipp_Pro · Write | Trigger a tenant test run via POST /api/ExecTestRun. |
Application Approvals
| Tool | What it does |
|---|---|
cipp_Pro · Write | Queue a multi-tenant enterprise-app deployment via POST /api/ExecAddMultiTenantApp. |
cipp_Pro · Write | Capture an existing app in a source tenant as a reusable app-approval template via POST /api/ExecCreateAppTemplate. |
cipp_Pro · Destructive | Delete an application approval template via DELETE /api/ExecAppApprovalTemplate, body-carried. |
cipp_Pro · Destructive | Delete an application permission-set template via DELETE /api/ExecAppPermissionTemplate, body-carried. |
cipp_Free · Read-only | Build the per-tenant Microsoft admin-consent links for an application, via GET /api/ExecAppApproval. |
cipp_Pro · Destructive | Edit or delete an application object / service principal via PATCH /api/ExecApplication. |
cipp_Pro · Destructive | List, get, or create service principals in the PARTNER tenant via GET /api/ExecServicePrincipals (the parameters travel in the query string; there is no request body and no tenantFilter — the endpoint always acts on the partner tenant). |
cipp_Free · Read-only | List all application approval templates in CIPP. |
Applications
| Tool | What it does |
|---|---|
cipp_Pro · Write | Queue a Chocolatey package for Intune deployment via POST /api/AddChocoApp — a CROSS-TENANT fan-out that writes one row per target tenant into CIPP's 'apps' queue table. |
cipp_Pro · Write | Queue an RMM/MSP agent installer for Intune deployment via POST /api/AddMSPApp — a CROSS-TENANT fan-out that writes one 'Not Deployed yet' row per target tenant into CIPP's 'apps' queue table. |
cipp_Pro · Destructive | Deploy Microsoft 365 Apps (Office) to Intune via POST /api/AddOfficeApp — a CROSS-TENANT fan-out. |
cipp_Pro · Write | Queue a Microsoft Store (winget-source) application for Intune deployment via POST /api/AddStoreApp — a CROSS-TENANT fan-out that writes one 'Not Deployed yet' row per target tenant into CIPP's 'apps' queue table. |
cipp_Pro · Write | Queue a Win32 script-based application for Intune deployment via POST /api/AddWin32ScriptApp — a CROSS-TENANT fan-out that writes one 'Not Deployed yet' row per target tenant into CIPP's 'apps' queue table. |
cipp_Pro · Destructive | Assign an existing Intune application to users, groups, or devices in a tenant via POST /api/ExecAssignApp. |
cipp_Pro · Write | Upload an application package to Intune. |
cipp_Free · Read-only | List queued application deployments across tenants. |
cipp_Free · Read-only | Search a Chocolatey-style (NuGet v2) package feed for deployable application definitions via POST /api/ListAppsRepository. |
cipp_Free · Read-only | Search a public package source for deployable applications via POST /api/ListPotentialApps. |
cipp_Pro · Destructive | Permanently remove an Intune-managed application from a tenant via POST /api/RemoveApp. |
cipp_Pro · Destructive | Cancel a pending deployment in the CIPP application queue via POST /api/RemoveQueuedApp before it processes. |
cipp_Pro · Write | Trigger a sync of Apple Volume Purchase Program (VPP) tokens for a tenant via POST /api/ExecSyncVPP. |
More in Connector guides
Connect Acronis Cyber Protect CloudConnect Action1Connect AddigyConnect AlertOpsStill need help? Ask the team