Skip to main content
Connector guides

Connect CIPP

CIPP (the CyberDrain Improved Partner Portal) is an open-source multi-tenant Microsoft 365 management portal for MSPs. Connecting CIPP to StackJack gives your AI assistant tools for Microsoft 365…

Written By Christopher Scaminaci

Last updated 6 days ago

CIPP (the CyberDrain Improved Partner Portal) is an open-source multi-tenant Microsoft 365 management portal for MSPs. Connecting CIPP to StackJack gives your AI assistant tools for Microsoft 365 users, tenants, groups, Intune device management, Exchange mailboxes, transport rules, conditional access, security, and CIPP standards through StackJack's MCP endpoint. See the generated CIPP tool reference for the current inventory, input schemas, plan tiers, and safety notes. (MCP, the Model Context Protocol, is the open standard that lets AI assistants like Claude, ChatGPT, and Copilot call your MSP tools securely.)

CIPP authenticates through Azure AD (Entra ID) client credentials, so this connector needs more fields than most: six values, all of which CIPP generates for you on one page.

Before you begin

  • You need the Owner, co-owner, or Administrator role in StackJack to configure connectors.
  • You need access to your CIPP instance's Integrations area (the ability to create CIPP-API clients).
  • You need your CIPP instance's default Azure App Service URL — the one ending in .azurewebsites.net. StackJack cannot connect through a custom domain (see the warning below).
  • Connecting a connector automatically activates it on the Free plan. You can upgrade to a paid plan at any time from the Connectors page — current pricing is shown in the portal.

Tip: The same steps below are always available in-app — open Connectors, find the CIPP card, and click How To Connect.

Step 1: Create an API client in CIPP

  1. In your CIPP instance, go to CIPP > Integrations > CIPP-API to open the API configuration page.
  2. Click Actions > Create New Client. Enter an app name (for example, StackJack).
  3. Enable the client. For least privilege, use Custom Roles to limit the API endpoints this client can call. Select only the read or write operations your StackJack workflows need.
  4. Optional: use Allowed IP Ranges to restrict the client to individual IPv4 or IPv6 addresses or CIDR ranges. Do this only after StackJack support gives you the current outbound addresses for your environment; guessing can lock the connector out.
  5. Submit the client and copy its Application Secret immediately to a secure temporary location.
  6. Click Actions > Save Azure Configuration so CIPP applies the API-client configuration to Azure. Wait for the page to refresh with the remaining values.
  7. Leave this page open — you'll copy six fields from it: API URL, Client ID, Secret, API Scope, Token URL, and Tenant ID.

CIPP's human portal roles and an API client's Custom Roles are separate permission systems. Do not assign broad human-role names on the assumption that they describe the API-client boundary.

Step 2: Add the credentials to StackJack

  1. In the StackJack portal, go to Connectors and click Configure on the CIPP card.

  2. Fill in the six fields, copying each from the CIPP API page:

    StackJack fieldFrom CIPPNotes
    Instance URLAPI URLMust be the default *.azurewebsites.net address. The dialog shows a red warning and blocks saving if you enter a custom domain.
    Azure AD Tenant IDTenant IDThe Microsoft tenant hosting your CIPP deployment. Required.
    API ScopeAPI ScopeLooks like api://your-client-id/.default. You can leave it blank to auto-derive it from the Application ID.
    Token URLToken URLYou can leave it blank to auto-derive it from the Tenant ID.
    Application IDClient IDThe Azure app registration's client ID.
    Application SecretSecretShown by CIPP after Save Azure Configuration.
  3. Click Save.

StackJack cross-checks your entries before saving and stops with a specific warning if something doesn't line up:

  • The Instance URL must end in .azurewebsites.net.
  • If you filled in a Token URL, the tenant inside it must match the Azure AD Tenant ID field. If they differ, fix one of them — or clear the Token URL to auto-derive it.
  • If you filled in an API Scope, it must reference the Application ID. If it doesn't, correct it — or clear the API Scope to auto-derive it.

When you later re-open the dialog on a connected CIPP card, the stored Tenant ID, API Scope, and Token URL are re-loaded for editing; the Application Secret is never re-displayed.

What happens when you save

  • Your credentials are stored encrypted in Azure Key Vault. They are never stored in StackJack's database.
  • StackJack immediately test-calls CIPP to validate the credentials. CIPP validation can take up to a minute — CIPP runs on Azure Functions, and a cold instance needs time to wake up. Don't close the page early.
  • If validation fails or times out, your credentials are still saved and you'll see a warning — validation retries automatically in the background.
  • A Free plan subscription for CIPP is activated automatically if you don't already have one.
  • If validation keeps failing (three consecutive definitive failures), StackJack auto-disables the connection, emails the tenant owner, and shows Re-enable and Update Credentials buttons on the card.

Troubleshooting

SymptomLikely cause and fix
Save is blocked with a URL warningYou entered a custom domain. Use the default *.azurewebsites.net App Service URL from the CIPP-API page.
Save is blocked with a "different tenant" warningYour Token URL points at a different Azure AD tenant than the Tenant ID field. Recheck both against the CIPP-API page, or clear the Token URL to auto-derive it.
Save is blocked with an "API Scope does not reference the Application ID" warningThe scope belongs to a different app registration. Recheck it, or clear the API Scope to auto-derive it.
Validation times outUsually an Azure Functions cold start. Wait, then click Re-test on the card — background validation also retries automatically.
Tools return 403 (forbidden) errorsReview the client under CIPP > Integrations > CIPP-API. Its Custom Roles may exclude the endpoint, its Allowed IP Ranges may exclude StackJack, the client may be disabled, or Save Azure Configuration may not have been run after a change.
Connection shows Invalid after working beforeThe Application Secret may have expired or been rotated, or the CIPP API client was removed. Create/copy fresh values in CIPP and click Update on the card.
Card shows DisabledStackJack auto-disabled the credential after repeated failures. The card shows the exact error plus a recommended action — fix the cause, then click Re-enable (or Update Credentials first).

Rotating the application secret

In CIPP > Integrations > CIPP-API, open the client's row menu and choose Reset Application Secret. Copy the replacement immediately, then use Update Credentials on the StackJack connector card and run Re-test. Plan the change as a coordinated rotation: the old secret stops working after CIPP resets it.

Disconnecting

Click Disconnect on the CIPP card to delete the stored credentials from Key Vault. Any AI tools using the connector stop working immediately.

⚠ Disconnecting does not cancel a paid plan — billing continues until you cancel it separately. The plan controls only appear while the connector is connected, so end the plan before disconnecting. On a paid connector that button reads Manage on Billing and opens this connector's removal dialog on the Billing page; a legacy website subscription still reads Cancel Plan. If you've already disconnected, save your credentials again to bring the plan controls back, then end the plan.

CIPP tools

cipp_ · 439 tools · Free 176 · Pro 263

Tenants

ToolWhat it does
cipp_add_domain
Pro · Write
Add a custom domain to a tenant via POST /api/AddDomain.
cipp_add_spn
Pro · Write
Add CIPP service principal permissions to partner tenant.
cipp_add_tenant
Pro · Write
Multi-action tenant endpoint at POST /api/AddTenant.
cipp_clear_tenant_cache
Pro · Write
Force CIPP to bypass its tenant cache on the next enumeration, via POST /api/ListTenants carrying the body key 'ClearCache' as a real JSON boolean true.
cipp_delete_domain_action
Pro · Destructive
Run a domain action against a tenant via DELETE /api/ExecDomainAction.
cipp_edit_tenant
Pro · Write
Edit CIPP tenant configuration via POST /api/EditTenant.
cipp_edit_tenant_offboarding_defaults
Pro · Write
Edit the default user-offboarding settings for a tenant via POST /api/EditTenantOffboardingDefaults.
cipp_exec_exclude_licenses
Pro · Destructive
Change CIPP's excluded-licences setting (a CIPP instance setting affecting licence reporting for EVERY tenant), via POST /api/ExecExcludeLicenses.
cipp_get_organization
Free · Read-only
Get organization profile information for a tenant including company name, address, technical contacts, and partner information.
cipp_get_tenant_details
Free · Read-only
Get detailed information for a specific M365 tenant including organization info, license counts, and domain details.
cipp_list_app_consent_requests
Free · Read-only
List pending application consent requests from users in the tenant awaiting admin approval.
cipp_list_csp_licenses
Free · Read-only
List CSP (Cloud Solution Provider) license subscriptions for a tenant including subscription name, quantity, and billing cycle.
cipp_list_domains
Free · Read-only
List all domains registered for a tenant including verification status, default domain flag, and DNS records.
cipp_list_excluded_licenses
Free · Read-only
List the SKUs CIPP excludes from its licence reporting, via GET /api/ListExcludedLicenses (no parameters — this is a CIPP instance setting, not per-tenant).
cipp_list_external_tenant_info
Free · Read-only
Look up external tenant information by domain or tenant ID.
cipp_list_licenses
Free · Read-only
CIPP's licence report for a tenant: SKU name, total units, consumed units, and available units.
cipp_list_oauth_apps
Free · Read-only
List the OAuth application grants in a tenant.
cipp_list_service_health
Free · Read-only
List current M365 service health status for a tenant.
cipp_list_tenant_alignment
Free · Read-only
List tenant alignment status — how each tenant's configuration compares to the standards templates applied to it — via GET /api/ListTenantAlignment.
cipp_list_tenant_onboarding
Free · Read-only
List tenant onboarding status and progress via GET /api/ListTenantOnboarding.
cipp_list_tenants
Free · Read-only
List all M365 tenants managed by this CIPP instance via POST /api/ListTenants.
cipp_onboard_tenant
Pro · Destructive
Onboard a tenant to CIPP via POST /api/ExecOnboardTenant.
cipp_remove_tenant_capabilities_cache
Pro · Write
Clear CIPP's cached tenant-capabilities data for ONE tenant via GET /api/RemoveTenantCapabilitiesCache, forcing CIPP to re-evaluate that tenant's features and permissions on the next request.
cipp_send_org_message
Pro · Destructive
Create an M365 organizational message in a tenant, TARGETED AT ONE ENTRA SECURITY GROUP, via GET /api/ExecSendOrgMessage.
cipp_set_auth_method
Pro · Destructive
Configure authentication method policies for a tenant via POST /api/SetAuthMethod.

Users

ToolWhat it does
cipp_bec_check
Free · Write
Start OR poll a Business Email Compromise (BEC) background check for a specific user.
cipp_get_user_ca_policies
Free · Read-only
Evaluate which conditional access policies would apply to a specific user, via GET /api/ListUserConditionalAccessPolicies.
cipp_get_user_devices
Free · Read-only
Get devices registered or owned by a specific user including device name, OS, compliance status, and last sync time.
cipp_get_user_groups
Free · Read-only
Get all group memberships for a specific user including security groups, distribution lists, and M365 groups.
cipp_get_user_mailbox
Free · Read-only
Get mailbox details for a specific user including mailbox type, size, forwarding rules, and archive status.
cipp_get_user_mfa
Free · Read-only
Get per-user MFA status and configuration for a specific user including MFA state, default method, and registered methods.
cipp_get_user_photo
Free · Read-only
Get the profile photo for a specific user.
cipp_get_user_signin_logs
Free · Read-only
Get recent sign-in log entries for a specific user including timestamp, IP address, location, app, and status.
cipp_list_basic_auth_users
Free · Read-only
List users who have basic authentication (legacy auth) enabled.
cipp_list_deleted_users
Free · Read-only
List soft-deleted users in the tenant recycle bin.
cipp_list_inactive_accounts
Free · Read-only
List user accounts that have not signed in recently.
cipp_list_mfa_users
Free · Read-only
List all users with their MFA registration status and methods.
cipp_list_user_counts
Free · Read-only
Get user count statistics for a tenant including total users, licensed users, guests, and disabled accounts.
cipp_list_users
Free · Read-only
List all users in a tenant including display name, UPN, license status, and account enabled state.

User Management

ToolWhat it does
cipp_add_guest
Pro · Write
Invite an external guest user to the tenant via POST /api/AddGuest.
cipp_add_jit_admin_template
Pro · Write
Save a new Just-In-Time (JIT) admin template via POST /api/AddJITAdminTemplate.
cipp_add_user
Pro · Write
Create a new user in the tenant via POST /api/AddUser.
cipp_add_user_bulk
Pro · Write
Create multiple users in a tenant in bulk via POST /api/AddUserBulk.
cipp_add_user_defaults
Pro · Write
Save a new-user-creation defaults template for a tenant via POST /api/AddUserDefaults.
cipp_bec_remediate
Pro · Destructive
Execute Business Email Compromise remediation actions on a user via POST /api/ExecBECRemediate.
cipp_bulk_license
Pro · Destructive
Change license assignments for several users in one call via POST /api/ExecBulkLicense.
cipp_clear_immutable_id
Pro · Destructive
Clear the on-premises immutable ID (sourceAnchor) for a user via POST /api/ExecClrImmId.
cipp_create_tap
Pro · Destructive
Create a Temporary Access Pass (TAP) for a user via POST /api/ExecCreateTAP.
cipp_device_delete_identity
Pro · Destructive
Change or delete a device registration in Azure AD / Entra ID via POST /api/ExecDeviceDelete.
cipp_disable_user
Pro · Destructive
Enable or disable a user account via POST /api/ExecDisableUser.
cipp_dismiss_risky_user
Pro · Destructive
Dismiss a user's risk state in Azure AD Identity Protection via POST /api/ExecDismissRiskyUser.
cipp_edit_jit_admin_template
Pro · Write
Update an existing Just-In-Time (JIT) admin template via POST /api/EditJITAdminTemplate.
cipp_edit_user
Pro · Write
Edit properties of an existing user via PATCH /api/EditUser.
cipp_edit_user_aliases
Pro · Destructive
Add or remove email aliases (proxy addresses) for a user account via POST /api/EditUserAliases.
cipp_jit_admin
Pro · Destructive
Enable or configure Just-In-Time (JIT) admin access for a user via POST /api/ExecJITAdmin.
cipp_license_search
Free · Write
Look up Microsoft license SKU details by SKU IDs via POST /api/ExecLicenseSearch.
cipp_list_jit_admin
Free · Read-only
List currently active Just-In-Time admin sessions via GET /api/ListJITAdmin.
cipp_list_jit_admin_templates
Free · Read-only
List available Just-In-Time admin templates.
cipp_list_new_user_defaults
Free · Read-only
List saved new user creation default templates.
cipp_list_user_settings
Free · Read-only
List CIPP user settings configuration including default behaviors for user management operations.
cipp_list_user_trusted_blocked_senders
Free · Read-only
List the trusted and blocked senders configured for ONE user via GET /api/ListUserTrustedBlockedSenders.
cipp_offboard_user
Pro · Destructive
Run a multi-step user offboarding workflow against POST /api/ExecOffboardUser.
cipp_offboarding_job_status
Free · Read-only
Get the status of queued CIPP offboarding jobs via GET /api/CIPPOffboardingJob.
cipp_onedrive_provision
Pro · Write
Provision a OneDrive for Business site for a user via POST /api/ExecOnedriveProvision.
cipp_onedrive_shortcut
Pro · Write
Create a OneDrive shortcut for a user to a SharePoint site via POST /api/ExecOneDriveShortCut.
cipp_password_never_expires
Pro · Destructive
Set or unset the password-never-expires flag for a user account via POST /api/ExecPasswordNeverExpires.
cipp_patch_user
Pro · Destructive
Apply partial updates to a user record via PATCH /api/PatchUser.
cipp_per_user_mfa
Pro · Destructive
Enable, disable, or enforce per-user (legacy) MFA for a specific user via POST /api/ExecPerUserMFA.
cipp_remove_deleted_object
Pro · Destructive
Permanently remove a soft-deleted object from the tenant recycle bin via POST /api/RemoveDeletedObject.
cipp_remove_jit_admin_template
Pro · Destructive
Delete a Just-In-Time (JIT) admin template via POST /api/RemoveJITAdminTemplate.
cipp_remove_trusted_blocked_sender
Pro · Destructive
Remove an entry from a user's trusted or blocked senders list via POST /api/RemoveTrustedBlockedSender.
cipp_remove_user
Pro · Destructive
Delete a user from the tenant via POST /api/RemoveUser.
cipp_remove_user_default_template
Pro · Destructive
Remove a saved new-user defaults template via POST /api/RemoveUserDefaultTemplate.
cipp_reprocess_user_licenses
Pro · Write
Reprocess license assignments for a user to fix license provisioning errors or stale service plan states, via POST /api/ExecReprocessUserLicenses.
cipp_reset_mfa
Pro · Destructive
Reset MFA registration for a user via POST /api/ExecResetMFA, requiring them to re-register their authentication methods on next sign-in.
cipp_reset_password
Pro · Destructive
Reset a user's password via POST /api/ExecResetPass.
cipp_restore_deleted_user
Pro · Write
Restore a soft-deleted user from the tenant recycle bin via POST /api/ExecRestoreDeleted.
cipp_revoke_sessions
Pro · Destructive
Revoke all active sessions and refresh tokens for a user via POST /api/ExecRevokeSessions, forcing re-authentication on all devices.
cipp_send_push
Pro · Destructive
Send a test push notification to a user's registered Microsoft Authenticator MFA device via POST /api/ExecSendPush.
cipp_set_cloud_managed
Pro · Destructive
Set a directory object's on-premises sync behaviour via POST /api/ExecSetCloudManaged — CIPP PATCHes /beta/{users|groups|contacts}/{ID}/onPremisesSyncBehavior with {"isCloudManaged": <bool>}.
cipp_set_user_photo
Pro · Write
Set or remove the profile photo for a user via POST /api/ExecSetUserPhoto.

Groups

ToolWhat it does
cipp_add_group
Pro · Write
Create a new group in the tenant via POST /api/AddGroup.
cipp_add_group_template
Pro · Destructive
Save a group template for reuse via POST /api/AddGroupTemplate.
cipp_convert_group_to_team
Pro · Destructive
Convert an existing M365 group into a Microsoft Teams team via POST /api/AddGroupTeam.
cipp_delete_group
Pro · Destructive
Delete a group from a tenant via POST /api/ExecGroupsDelete.
cipp_edit_group
Pro · Write
Edit properties of an existing group via PATCH /api/EditGroup.
cipp_group_delivery_management
Pro · Destructive
Set whether a distribution or Microsoft 365 group accepts mail only from internal senders via POST /api/ExecGroupsDeliveryManagement (it writes RequireSenderAuthenticationEnabled).
cipp_group_hide_from_gal
Pro · Write
Show or hide a group in the Global Address List via POST /api/ExecGroupsHideFromGAL (it writes HiddenFromAddressListsEnabled).
cipp_list_group_sender_auth
Free · Read-only
Report whether external senders may email ONE group, via GET /api/ListGroupSenderAuthentication.
cipp_list_group_templates
Free · Read-only
List saved group templates.
cipp_list_groups
Free · Read-only
List all groups in a tenant including security groups, distribution lists, M365 groups, and mail-enabled security groups.
cipp_list_roles
Free · Read-only
List all directory roles in a tenant including role name, description, and assigned members.
cipp_remove_group_template
Pro · Destructive
Remove a saved group template via POST /api/RemoveGroupTemplate.

Mailboxes

ToolWhat it does
cipp_exec_mail_test
Free · Read-only
Run an Exchange Online mail-flow / connectivity diagnostic via GET /api/ExecMailTest.
cipp_get_calendar_permissions
Free · Read-only
Get calendar sharing permissions for a specific user's mailbox including delegate access levels and shared calendar settings.
cipp_get_contact_permissions
Free · Read-only
Get contacts folder sharing permissions for a specific user's mailbox.
cipp_get_mailbox_cas
Free · Read-only
Get Client Access Settings (CAS) for a specific mailbox including OWA, ActiveSync, POP, IMAP, and MAPI protocol enablement status.
cipp_get_mailbox_mobile_devices
Free · Read-only
Get mobile devices connected to a specific mailbox via ActiveSync or Outlook Mobile.
cipp_get_mailbox_permissions
Free · Read-only
Get permission assignments for a specific mailbox including Full Access, Send As, and Send on Behalf delegates.
cipp_get_mailbox_rules
Free · Read-only
Inbox rules for EVERY mailbox in a tenant, via GET /api/ListMailboxRules.
cipp_get_ooo
Free · Read-only
Get the out-of-office (automatic reply) settings for a specific user including internal/external messages and schedule.
cipp_list_exo_request
Free · Read-only
Run a read-only Exchange Online PowerShell cmdlet via POST /api/ListExoRequest and return its raw output.
cipp_list_global_address_list
Free · Read-only
List entries in ONE tenant's Global Address List (GAL) via GET /api/ListGlobalAddressList.
cipp_list_mailbox_forwarding
Free · Read-only
List mailbox forwarding configuration across the tenant via GET /api/ListMailboxForwarding.
cipp_list_mailbox_restores
Free · Read-only
List ONE tenant's pending and completed mailbox restore requests via GET /api/ListMailboxRestores.
cipp_list_mailboxes
Free · Read-only
List all mailboxes in a tenant including user, shared, and resource mailboxes.
cipp_list_quarantine_message
Free · Read-only
Retrieve ONE quarantined message via GET /api/ListMailQuarantineMessage.
cipp_list_restricted_users
Free · Read-only
List users who have been restricted from sending email due to suspected spam or compromise.
cipp_list_shared_mailbox_account_enabled
Free · Read-only
List the shared mailboxes in one tenant that still have sign-in enabled.
cipp_list_shared_mailbox_stats
Free · Read-only
List all shared mailboxes with usage statistics including size, item count, last activity date, and permission assignments.
cipp_list_user_mailbox_rules
Free · Read-only
Inbox rules for ONE mailbox, via GET /api/ListUserMailboxRules.

Mailbox Management

ToolWhat it does
cipp_add_shared_mailbox
Pro · Write
Create a new shared mailbox via POST /api/AddSharedMailbox.
cipp_convert_mailbox
Pro · Destructive
Convert a mailbox between types via POST /api/ExecConvertMailbox.
cipp_copy_for_sent
Pro · Write
Configure whether items sent on behalf of a mailbox by a delegate are also copied to the mailbox owner's Sent Items folder via POST /api/ExecCopyForSent.
cipp_edit_calendar_permissions
Pro · Write
Grant, change, or revoke a delegate's access to a mailbox's calendar folder via POST /api/ExecEditCalendarPermissions.
cipp_edit_mailbox_permissions
Pro · Destructive
Add or remove mailbox permissions (Full Access, Send As, Send on Behalf) on a mailbox via POST /api/ExecEditMailboxPermissions.
cipp_enable_archive
Pro · Destructive
Enable the online archive mailbox for a user via POST /api/ExecEnableArchive.
cipp_enable_auto_expanding_archive
Pro · Destructive
Enable auto-expanding archive for a mailbox via POST /api/ExecEnableAutoExpandingArchive.
cipp_exec_mailbox_mobile_devices
Pro · Destructive
Perform an admin action on a mailbox-attached mobile device via GET /api/ExecMailboxMobileDevices.
cipp_hide_from_gal
Pro · Write
Show or hide a mailbox from the Global Address List (GAL) via POST /api/ExecHideFromGAL.
cipp_hve_user
Pro · Destructive
Manage a High Volume Email (HVE) user account via POST /api/ExecHVEUser.
cipp_mailbox_restore
Pro · Destructive
Manage mailbox restore requests via POST /api/ExecMailboxRestore.
cipp_message_trace
Pro · Write
Trace email messages via POST /api/ListMessageTrace by sender, recipient, and date range.
cipp_modify_calendar_perms
Pro · Write
Modify calendar folder permissions via POST /api/ExecModifyCalPerms — the cmdlet-style batch alternative to cipp_edit_calendar_permissions.
cipp_modify_contact_perms
Pro · Write
Modify a mailbox owner's Contacts-folder permissions via POST /api/ExecModifyContactPerms (cmdlet-style batch).
cipp_modify_mailbox_perms
Pro · Destructive
Modify mailbox-level permissions via POST /api/ExecModifyMBPerms — the cmdlet-style batch alternative to cipp_edit_mailbox_permissions.
cipp_remove_mailbox_rule
Pro · Destructive
Remove a specific inbox rule from a mailbox via POST /api/ExecRemoveMailboxRule.
cipp_remove_restricted_user
Pro · Destructive
Unblock a user who has been restricted from sending email via POST /api/ExecRemoveRestrictedUser.
cipp_schedule_mailbox_vacation
Pro · Write
Schedule a mailbox-vacation workflow against POST /api/ExecScheduleMailboxVacation.
cipp_schedule_ooo_vacation
Pro · Write
Schedule a future out-of-office (auto-reply) window for one or more users via POST /api/ExecScheduleOOOVacation.
cipp_set_calendar_processing
Pro · Destructive
Configure calendar processing settings for a resource mailbox (room or equipment) via POST /api/ExecSetCalendarProcessing — auto-accept, booking window, conflict resolution, processing of external meeting messages, and so on.
cipp_set_email_forward
Pro · Destructive
Configure email forwarding for a mailbox via POST /api/ExecEmailForward.
cipp_set_litigation_hold
Pro · Destructive
Enable or disable litigation hold on a mailbox via POST /api/ExecSetLitigationHold.
cipp_set_mailbox_email_size
Pro · Write
Set the maximum send/receive message size for a mailbox via POST /api/ExecSetMailboxEmailSize.
cipp_set_mailbox_locale
Pro · Write
Set the language and regional settings for a mailbox via POST /api/ExecSetMailboxLocale.
cipp_set_mailbox_quota
Pro · Write
Set ONE storage quota threshold for a mailbox via POST /api/ExecSetMailboxQuota.
cipp_set_mailbox_rule
Pro · Destructive
Enable or disable an existing server-side inbox rule on a mailbox via POST /api/ExecSetMailboxRule.
cipp_set_ooo
Pro · Write
Configure out-of-office (automatic reply) settings for a mailbox via POST /api/ExecSetOoO with separate internal and external messages.
cipp_set_recipient_limits
Pro · Write
Set the maximum number of recipients per outbound email message for a mailbox via POST /api/ExecSetRecipientLimits.
cipp_set_retention_hold
Pro · Destructive
Enable or disable retention hold on a mailbox via POST /api/ExecSetRetentionHold.
cipp_start_managed_folder_assistant
Pro · Destructive
Start the Managed Folder Assistant for a mailbox via POST /api/ExecStartManagedFolderAssistant to immediately process retention policies and tags instead of waiting for the next automatic cycle.

Mailbox Retention

ToolWhat it does
cipp_delete_retention_policies
Pro · Destructive
Delete retention policies for a tenant via DELETE /api/ExecManageRetentionPolicies.
cipp_delete_retention_tags
Pro · Destructive
Delete retention tags for a tenant via DELETE /api/ExecManageRetentionTags.
cipp_set_mailbox_retention_policies
Pro · Destructive
Assign an Exchange Online retention policy to one or more mailboxes via POST /api/ExecSetMailboxRetentionPolicies.

Contacts & Resources

ToolWhat it does
cipp_add_contact
Pro · Write
Create a new mail contact in a tenant directory via POST /api/AddContact.
cipp_add_contact_template
Pro · Write
Create a new CIPP contact template via POST /api/AddContactTemplates.
cipp_add_equipment_mailbox
Pro · Write
Create a new equipment mailbox for a bookable resource (projector, vehicle, conference phone, etc.) via POST /api/AddEquipmentMailbox.
cipp_add_room_list
Pro · Write
Create a new room list (group of rooms by building/floor/location) via POST /api/AddRoomList.
cipp_add_room_mailbox
Pro · Write
Create a new room mailbox via POST /api/AddRoomMailbox.
cipp_deploy_contact_templates
Pro · Destructive
Bulk-deploy CIPP contact templates to create mail contacts across one or more tenants via POST /api/DeployContactTemplates.
cipp_edit_contact
Pro · Write
Edit an existing mail contact via POST /api/EditContact.
cipp_edit_contact_template
Pro · Write
Modify an existing CIPP contact template via POST /api/EditContactTemplates.
cipp_edit_equipment_mailbox
Pro · Write
Edit properties of an existing equipment mailbox via POST /api/EditEquipmentMailbox — display name, booking settings, calendar processing, location, and resource metadata.
cipp_edit_room_list
Pro · Write
Modify an existing room list via POST /api/EditRoomList — rename it, add/remove member rooms, change owners, or update its delivery settings.
cipp_edit_room_mailbox
Pro · Write
Edit properties of an existing room mailbox via POST /api/EditRoomMailbox — display name, capacity, booking settings, calendar processing, location, and accessibility.
cipp_list_contact_templates
Free · Read-only
List CIPP contact templates from the CIPP template store via GET /api/ListContactTemplates.
cipp_list_contacts
Free · Read-only
List all mail contacts in a tenant.
cipp_list_equipment
Free · Read-only
List all equipment mailboxes in a tenant.
cipp_list_room_lists
Free · Read-only
List room lists (groups of rooms) in a tenant.
cipp_list_rooms
Free · Read-only
List all room mailboxes in a tenant.
cipp_remove_contact
Pro · Destructive
Remove a mail contact via POST /api/RemoveContact.
cipp_remove_contact_template
Pro · Destructive
Permanently delete a CIPP contact template via POST /api/RemoveContactTemplates.

Transport & Spam

ToolWhat it does
cipp_add_connection_filter
Pro · Destructive
Configure a connection filter policy via POST /api/AddConnectionFilter.
cipp_add_connection_filter_template
Pro · Write
Save a connection filter policy as a reusable CIPP template via POST /api/AddConnectionFilterTemplate.
cipp_add_edit_transport_rule
Pro · Destructive
Add or edit a full Exchange transport rule via POST /api/AddEditTransportRule (the unified high-fidelity authoring endpoint, distinct from the thin cipp_add_transport_rule and cipp_edit_transport_rule).
cipp_add_ex_connector_template
Pro · Write
Save an Exchange connector configuration as a reusable CIPP template via POST /api/AddExConnectorTemplate.
cipp_add_exchange_connector
Pro · Destructive
Create a new Exchange connector for mail routing via POST /api/AddExConnector.
cipp_add_quarantine_policy
Pro · Destructive
Create a new quarantine policy via POST /api/AddQuarantinePolicy.
cipp_add_spam_filter
Pro · Destructive
Create a new spam filter (hosted content filter) policy AND its matching rule via POST /api/AddSpamFilter.
cipp_add_spam_filter_template
Pro · Write
Save a spam filter policy as a reusable CIPP template via POST /api/AddSpamFilterTemplate.
cipp_add_tenant_allow_block
Pro · Destructive
Add entries to the Tenant Allow/Block List via POST /api/AddTenantAllowBlockList.
cipp_add_transport_rule
Pro · Destructive
Create OR update an Exchange transport rule (mail flow rule) via POST /api/AddTransportRule — it is an UPSERT: CIPP runs Get-TransportRule per tenant and, when a rule whose Identity equals the parsed payload's 'name' already exists, runs Set-TransportRule against it instead of New-TransportRule.
cipp_add_transport_rule_template
Pro · Write
Save a transport (mail flow) rule as a reusable CIPP template via POST /api/AddTransportTemplate.
cipp_edit_anti_phishing_filter
Pro · Destructive
Enable or disable an anti-phishing RULE via POST /api/EditAntiPhishingFilter.
cipp_edit_exchange_connector
Pro · Destructive
Enable or disable an existing Exchange connector via POST /api/EditExConnector.
cipp_edit_malware_filter
Pro · Destructive
Enable or disable a malware filter RULE via POST /api/EditMalwareFilter.
cipp_edit_quarantine_policy
Pro · Destructive
Edit an existing quarantine policy via POST /api/EditQuarantinePolicy.
cipp_edit_safe_attachments_filter
Pro · Destructive
Enable or disable a Safe Attachments (ATP) RULE via POST /api/EditSafeAttachmentsFilter.
cipp_edit_spam_filter
Pro · Destructive
Enable or disable a spam filter (hosted content filter) RULE via POST /api/EditSpamFilter.
cipp_edit_transport_rule
Pro · Destructive
Enable or disable an existing Exchange transport rule via POST /api/EditTransportRule.
cipp_list_connection_filter_templates
Free · Read-only
List saved connection filter policy templates.
cipp_list_connection_filters
Free · Read-only
List connection filter policies for a tenant.
cipp_list_ex_connector_templates
Free · Read-only
List saved Exchange connector templates from the CIPP template store via GET /api/ListExConnectorTemplates.
cipp_list_exchange_connectors
Free · Read-only
List all Exchange connectors for a tenant including inbound and outbound connectors, their type, status, and routing configuration.
cipp_list_quarantine
Free · Read-only
List quarantined email messages for a tenant.
cipp_list_quarantine_policy
Free · Read-only
List quarantine policies for a tenant via POST /api/ListQuarantinePolicy.
cipp_list_spam_filter_templates
Free · Read-only
List saved spam filter policy templates.
cipp_list_spam_filters
Free · Read-only
List spam filter policies for a tenant including policy name, spam action thresholds, allowed/blocked senders, and content filtering settings.
cipp_list_tenant_allow_block
Free · Read-only
List one tenant's Tenant Allow/Block List entries (blocked and allowed senders, URLs and file hashes) via GET /api/ListTenantAllowBlockList.
cipp_list_transport_rules
Free · Read-only
List all Exchange transport rules (mail flow rules) for a tenant.
cipp_list_transport_rules_templates
Free · Read-only
List saved transport (mail flow) rule templates from the CIPP template store via GET /api/ListTransportRulesTemplates.
cipp_manage_quarantine
Pro · Destructive
Manage a quarantined message via POST /api/ExecQuarantineManagement.
cipp_remove_connection_filter_template
Pro · Destructive
Permanently delete a connection filter policy template from the CIPP template store via POST /api/RemoveConnectionfilterTemplate (note: 'Connectionfilter' lowercase 'f' in the URL — preserve the underlying CIPP path).
cipp_remove_ex_connector_template
Pro · Destructive
Permanently delete an Exchange connector template from the CIPP template store via POST /api/RemoveExConnectorTemplate.
cipp_remove_exchange_connector
Pro · Destructive
Remove an Exchange connector via POST /api/RemoveExConnector.
cipp_remove_quarantine_policy
Pro · Destructive
Remove a quarantine policy via POST /api/RemoveQuarantinePolicy.
cipp_remove_spam_filter
Pro · Destructive
Remove a spam filter rule and its policy via POST /api/RemoveSpamfilter (note: 'Spamfilter' lowercase 'f' in the URL — preserve the underlying CIPP path).
cipp_remove_spam_filter_template
Pro · Destructive
Permanently delete a spam filter policy template from the CIPP template store via POST /api/RemoveSpamfilterTemplate (note: 'Spamfilter' lowercase 'f' in the URL — preserve the underlying CIPP path).
cipp_remove_tenant_allow_block
Pro · Destructive
Remove entries from the Tenant Allow/Block List via POST /api/RemoveTenantAllowBlockList.
cipp_remove_transport_rule
Pro · Destructive
Remove an Exchange transport rule via POST /api/RemoveTransportRule.
cipp_remove_transport_rule_template
Pro · Destructive
Permanently delete a transport rule template from the CIPP template store via POST /api/RemoveTransportRuleTemplate.

Devices

ToolWhat it does
cipp_get_device_details
Free · Read-only
Get detailed information for a specific Intune device including hardware, OS version, compliance, and encryption status.
cipp_list_app_protection
Free · Read-only
List Intune app protection policies (MAM) for a tenant.
cipp_list_app_status
Free · Read-only
List Intune application install status across devices via GET /api/ListAppStatus (upstream POSTs Graph beta deviceManagement/reports/getDeviceInstallStatusReport).
cipp_list_apps
Free · Read-only
List Intune-managed applications for a tenant.
cipp_list_assignment_filter_templates
Free · Read-only
List saved Intune assignment-filter TEMPLATES (the reusable definitions, not tenant-deployed filters) via GET /api/ListAssignmentFilterTemplates.
cipp_list_assignment_filters
Free · Read-only
List Intune assignment filters (Graph beta deviceManagement/assignmentFilters) via GET /api/ListAssignmentFilters.
cipp_list_autopilot_configs
Free · Read-only
List Windows Autopilot deployment profiles and configuration settings for a tenant.
cipp_list_autopilot_devices
Free · Read-only
List all Windows Autopilot registered devices for a tenant.
cipp_list_compliance_policies
Free · Read-only
List Intune device compliance policies for a tenant.
cipp_list_defender_state
Free · Read-only
List Microsoft Defender for Endpoint device status for a tenant.
cipp_list_defender_tvm
Free · Read-only
List Microsoft Defender Threat & Vulnerability Management data for a tenant.
cipp_list_detected_app_devices
Free · Read-only
List Intune-managed devices that have a specific detected application installed (Graph beta deviceManagement/detectedApps/{AppID}/managedDevices) via GET /api/ListDetectedAppDevices.
cipp_list_detected_apps
Free · Read-only
List applications detected on Intune-managed devices for a tenant.
cipp_list_devices
Free · Read-only
List all Intune-managed devices for a tenant.
cipp_list_intune_intents
Free · Read-only
List Intune security-baseline and endpoint-protection intents — the legacy template-based policies — via GET /api/ListIntuneIntents, which reads Graph beta deviceManagement/Intents with $expand=settings,categories (so each intent carries its expanded settings and categories; these are NOT assignments).
cipp_list_intune_policies
Free · Read-only
List Intune device configuration policies for a tenant.
cipp_list_intune_reusable_setting_templates
Free · Read-only
List saved Intune reusable-setting TEMPLATES (the reusable definitions, not tenant-deployed reusable settings) via GET /api/ListIntuneReusableSettingTemplates.
cipp_list_intune_reusable_settings
Free · Read-only
List Intune reusable policy settings (Graph beta deviceManagement/reusablePolicySettings) via GET /api/ListIntuneReusableSettings.
cipp_list_intune_scripts
Free · Read-only
List Intune PowerShell and remediation scripts deployed to a tenant.
cipp_list_intune_templates
Free · Read-only
List saved Intune policy TEMPLATES (the reusable definitions, not tenant-deployed policies) via GET /api/ListIntuneTemplates.

Device Management

ToolWhat it does
cipp_add_assignment_filter
Pro · Write
Create a new Intune assignment filter via POST /api/AddAssignmentFilter.
cipp_add_assignment_filter_template
Pro · Write
Create a saved Intune assignment-filter TEMPLATE (the reusable definition, not a tenant-deployed filter) via POST /api/AddAssignmentFilterTemplate.
cipp_add_autopilot_config
Pro · Write
Create a Windows Autopilot deployment profile in one or more tenants via POST /api/AddAutopilotConfig.
cipp_add_autopilot_device
Pro · Write
Register one or more devices in Windows Autopilot via POST /api/AddAPDevice (Partner Center DeviceBatches).
cipp_add_defender_deployment
Pro · Destructive
Deploy a Microsoft Defender for Endpoint baseline to one or more tenants via POST /api/AddDefenderDeployment.
cipp_add_enrollment
Pro · Write
Create an Enrollment Status Page (ESP) / device enrollment configuration in one or more tenants via POST /api/AddEnrollment.
cipp_add_intune_reusable_setting
Pro · Write
DEPLOY a SAVED reusable-setting TEMPLATE into a tenant via POST /api/AddIntuneReusableSetting.
cipp_add_intune_reusable_setting_template
Pro · Write
Create a saved Intune reusable-setting TEMPLATE via POST /api/AddIntuneReusableSettingTemplate.
cipp_add_intune_template
Pro · Write
Create a saved Intune policy TEMPLATE via POST /api/AddIntuneTemplate.
cipp_add_policy
Pro · Destructive
Create OR OVERWRITE an Intune device configuration / compliance policy via POST /api/AddPolicy.
cipp_assign_autopilot_device
Pro · Destructive
Associate an Autopilot device with a user via POST /api/ExecAssignAPDevice (Graph UpdateDeviceProperties).
cipp_assign_policy
Pro · Destructive
Assign an Intune policy to groups, users, or all devices via POST /api/ExecAssignPolicy.
cipp_delete_assignment_filter
Pro · Destructive
Delete an Intune assignment filter via DELETE /api/ExecAssignmentFilter.
cipp_device_action
Pro · Destructive
Execute a remote action on an Intune device via POST /api/ExecDeviceAction.
cipp_device_passcode_action
Pro · Destructive
Execute a passcode-related action on an Intune device via POST /api/ExecDevicePasscodeAction.
cipp_edit_assignment_filter
Pro · Destructive
Edit an existing Intune assignment filter via POST /api/EditAssignmentFilter.
cipp_edit_intune_policy
Pro · Destructive
Rename and/or re-describe an existing Intune policy via POST /api/EditIntunePolicy.
cipp_edit_intune_script
Pro · Destructive
Edit an existing Intune PowerShell or remediation script via POST /api/EditIntuneScript.
cipp_edit_policy
Pro · Destructive
Rename and/or re-describe an ADMX group-policy configuration via POST /api/EditPolicy.
cipp_exec_bitlocker_search
Pro · Write
Look up BitLocker recovery keys via POST /api/ExecBitlockerSearch.
cipp_get_local_admin_password
Pro · Write
Retrieve the LAPS (Local Administrator Password Solution) password for a specific Intune device via POST /api/ExecGetLocalAdminPassword.
cipp_get_recovery_key
Pro · Write
Retrieve the BitLocker recovery key for a specific Intune device via POST /api/ExecGetRecoveryKey.
cipp_remove_assignment_filter_template
Pro · Destructive
Delete a saved Intune assignment-filter TEMPLATE via POST /api/RemoveAssignmentFilterTemplate.
cipp_remove_autopilot_config
Pro · Destructive
Remove a Windows Autopilot deployment profile via POST /api/RemoveAutopilotConfig.
cipp_remove_autopilot_device
Pro · Destructive
Remove a device from Windows Autopilot via POST /api/RemoveAPDevice.
cipp_remove_intune_reusable_setting
Pro · Destructive
Remove a reusable setting from a tenant's Intune via POST /api/RemoveIntuneReusableSetting.
cipp_remove_intune_reusable_setting_template
Pro · Destructive
Delete a saved Intune reusable-setting TEMPLATE via POST /api/RemoveIntuneReusableSettingTemplate.
cipp_remove_intune_script
Pro · Destructive
Remove an Intune PowerShell or remediation script via POST /api/RemoveIntuneScript.
cipp_remove_intune_template
Pro · Destructive
Delete a saved Intune policy TEMPLATE via POST /api/RemoveIntuneTemplate.
cipp_remove_policy
Pro · Destructive
Remove an Intune device configuration or compliance policy via POST /api/RemovePolicy.
cipp_rename_autopilot_device
Pro · Write
Rename an Autopilot device via POST /api/ExecRenameAPDevice.
cipp_set_autopilot_group_tag
Pro · Destructive
Set the group tag on an Autopilot device via POST /api/ExecSetAPDeviceGroupTag.
cipp_sync_autopilot
Pro · Write
Trigger a sync of all Windows Autopilot devices for a tenant via POST /api/ExecSyncAPDevices.
cipp_sync_dep
Pro · Write
Synchronize Apple Device Enrollment Program (DEP) devices for a tenant via POST /api/ExecSyncDEP.

Security

ToolWhat it does
cipp_add_ca_policy
Pro · Destructive
Create a Conditional Access policy for a tenant via POST /api/AddCAPolicy.
cipp_edit_ca_policy
Pro · Destructive
Modify an existing Conditional Access policy for a tenant via POST /api/EditCAPolicy.
cipp_list_anti_phishing
Free · Read-only
List anti-phishing filter policies for a tenant.
cipp_list_ca_changes
Free · Read-only
List recent changes to Conditional Access policies for a tenant.
cipp_list_ca_policies
Free · Read-only
List all Conditional Access policies for a tenant.
cipp_list_malware_filters
Free · Read-only
List malware filter policies for a tenant.
cipp_list_mdo_alerts
Free · Read-only
List Microsoft Defender for Office 365 alerts for a tenant.
cipp_list_named_locations
Free · Read-only
List named locations (IP ranges and countries) used in Conditional Access policies for a tenant.
cipp_list_safe_attachments
Free · Read-only
List Safe Attachments policies for a tenant.
cipp_list_safe_links
Free · Read-only
List Safe Links policies for a tenant.
cipp_list_security_alerts
Free · Read-only
List Microsoft 365 security alerts for a tenant.
cipp_list_security_incidents
Free · Read-only
List Microsoft 365 security incidents for a tenant.
cipp_set_mdo_alert
Pro · Destructive
Update a Microsoft Defender for Office 365 alert via POST /api/ExecSetMdoAlert — CIPP PATCHes Microsoft Graph beta /security/alerts_v2/{GUID} as the CIPP application.
cipp_set_security_alert
Pro · Destructive
Update a Microsoft 365 security alert via POST /api/ExecSetSecurityAlert.
cipp_set_security_incident
Pro · Destructive
Update a Microsoft 365 security incident via POST /api/ExecSetSecurityIncident — CIPP PATCHes Microsoft Graph beta /security/incidents/{GUID} as the CIPP application.

Conditional Access

ToolWhat it does
cipp_add_ca_template
Pro · Write
Save a Conditional Access policy as a CIPP template via POST /api/AddCATemplate.
cipp_add_named_location
Pro · Write
Create a Conditional Access named location via POST /api/AddNamedLocation.
cipp_exec_ca_check
Free · Read-only
Simulate ('what if') a Conditional Access evaluation via POST /api/ExecCACheck — read-only: no sign-in occurs and no policy is changed.
cipp_exec_ca_exclusion
Pro · Destructive
Manage Conditional Access user exclusions via POST /api/ExecCAExclusion — a WRITE that adds or removes a user's exclusion on a CA policy, and with 'vacation' schedules the add/remove pair as tasks.
cipp_exec_ca_service_exclusion
Pro · Destructive
Add the service-provider exception to a Conditional Access policy for a tenant via POST /api/ExecCAServiceExclusion — a WRITE that edits the named policy.
cipp_exec_named_location
Pro · Destructive
Modify or delete an existing Conditional Access named location via POST /api/ExecNamedLocation.
cipp_list_ca_templates
Free · Read-only
List all Conditional Access policy templates available in CIPP.
cipp_remove_ca_policy
Pro · Destructive
Delete a Conditional Access policy from a tenant via POST /api/RemoveCAPolicy (a Graph DELETE on the policy).
cipp_remove_ca_template
Pro · Destructive
Delete a Conditional Access policy template via POST /api/RemoveCATemplate.
ToolWhat it does
cipp_add_safe_links_from_template
Pro · Destructive
Deploy one or more Safe Links policy templates to one or more tenants in bulk via POST /api/AddSafeLinksPolicyFromTemplate.
cipp_add_safe_links_template
Pro · Write
Create a new Safe Links policy template in the CIPP template store via POST /api/AddSafeLinksPolicyTemplate.
cipp_create_safe_links_policy
Pro · Destructive
Create a new Defender for Office Safe Links policy + rule pair in a tenant via POST /api/ExecNewSafeLinksPolicy.
cipp_create_safe_links_template
Pro · Write
Create a NEW Safe Links policy template in the CIPP template store from the fields in this request via POST /api/CreateSafeLinksPolicyTemplate.
cipp_delete_safe_links_policy
Pro · Destructive
Permanently delete a Safe Links policy + rule pair from a tenant via POST /api/ExecDeleteSafeLinksPolicy.
cipp_edit_safe_links_policy
Pro · Destructive
Modify an existing Safe Links policy + rule pair via POST /api/EditSafeLinksPolicy.
cipp_edit_safe_links_template
Pro · Destructive
Replace the stored contents of an existing Safe Links policy template in CIPP via POST /api/EditSafeLinksPolicyTemplate.
cipp_list_safe_links_details
Free · Read-only
Get the full configuration of a specific Safe Links policy in a tenant via POST /api/ListSafeLinksPolicyDetails.
cipp_list_safe_links_template_details
Free · Read-only
Get the full configuration of a specific Safe Links policy template stored in CIPP via POST /api/ListSafeLinksPolicyTemplateDetails.
cipp_list_safe_links_templates
Free · Read-only
List all Safe Links policy templates available in CIPP.
cipp_remove_safe_links_template
Pro · Destructive
Permanently delete a Safe Links policy template from the CIPP template store via POST /api/RemoveSafeLinksPolicyTemplate.

Teams & SharePoint

ToolWhat it does
cipp_add_site
Pro · Write
Create a new SharePoint site via POST /api/AddSite.
cipp_add_site_bulk
Pro · Write
Create multiple SharePoint sites in bulk via POST /api/AddSiteBulk.
cipp_add_team
Pro · Write
Create a new Microsoft Team for a tenant via POST /api/AddTeam.
cipp_assign_teams_voice_number
Pro · Destructive
Assign a Teams phone number to a user or resource account — or set a number's emergency location — via POST /api/ExecTeamsVoicePhoneNumberAssignment.
cipp_delete_sharepoint_site
Pro · Destructive
Delete a SharePoint site via POST /api/DeleteSharepointSite.
cipp_get_sharepoint_quota
Free · Read-only
Get SharePoint Online storage quota and usage for a tenant.
cipp_get_sharepoint_settings
Free · Read-only
Get SharePoint Online tenant-level settings.
cipp_list_sharepoint_admin_url
Free · Read-only
Get the SharePoint admin center URL for ONE tenant via GET /api/ListSharepointAdminUrl.
cipp_list_site_members
Free · Read-only
List members of a SharePoint site via GET /api/ListSiteMembers.
cipp_list_sites
Free · Read-only
List SharePoint sites (or OneDrive usage accounts) for a tenant via GET /api/ListSites.
cipp_list_teams
Free · Read-only
List all Microsoft Teams for a tenant.
cipp_list_teams_activity
Free · Read-only
List Microsoft Teams activity reports for a tenant.
cipp_list_teams_lis_location
Free · Read-only
List ONE tenant's Teams Location Information Service (LIS) locations via GET /api/ListTeamsLisLocation.
cipp_list_teams_voice
Free · Read-only
List Microsoft Teams voice and telephony configuration for a tenant.
cipp_remove_teams_voice_number
Pro · Destructive
Remove a phone number assignment from a Teams user via POST /api/ExecRemoveTeamsVoicePhoneNumberAssignment.
cipp_set_sharepoint_member
Pro · Write
Add or REMOVE a user in a SharePoint site role via POST /api/ExecSetSharePointMember.
cipp_set_sharepoint_permissions
Pro · Destructive
Grant or revoke SITE COLLECTION ADMINISTRATOR rights on a OneDrive or SharePoint site via POST /api/ExecSharePointPerms.

Standards

ToolWhat it does
cipp_add_bpa_template
Pro · Write
Save a new Best Practice Analyzer template via POST /api/AddBPATemplate.
cipp_add_standards_template
Pro · Destructive
Create or REPLACE a reusable CIPP standards template via POST /api/AddStandardsTemplate.
cipp_deploy_standards
Pro · Destructive
Create or REPLACE a tenant's standards deployment via POST /api/AddStandardsDeploy.
cipp_drift_clone
Pro · Write
Clone a drift template into a new standards baseline via POST /api/ExecDriftClone.
cipp_list_bpa
Free · Read-only
List Best Practice Analyzer results for a tenant.
cipp_list_bpa_templates
Free · Read-only
List saved Best Practice Analyzer templates.
cipp_list_domain_analyser
Free · Read-only
Run detailed domain analysis for a tenant.
cipp_list_domain_health
Free · Read-only
Run ONE real-time DNS / email-security check against ONE domain via GET /api/ListDomainHealth.
cipp_list_standard_templates
Free · Read-only
List saved CIPP standard templates.
cipp_list_standards
Free · Read-only
List deployed CIPP standards for a tenant.
cipp_list_standards_compare
Free · Read-only
Compare a tenant's current configuration against the CIPP standards template.
cipp_list_tenant_drift
Free · Read-only
Detect configuration drift for a tenant.
cipp_remove_bpa_template
Pro · Destructive
Remove a saved Best Practice Analyzer template via POST /api/RemoveBPATemplate.
cipp_remove_standard
Pro · Destructive
Remove a tenant's deployed standards row via GET /api/RemoveStandard.
cipp_remove_standard_template
Pro · Destructive
Remove a saved CIPP standards template via POST /api/RemoveStandardTemplate.
cipp_run_bpa
Pro · Write
Queue a Best Practice Analyzer run for a tenant via POST /api/ExecBPA.
cipp_standard_convert
Pro · Destructive
Convert EVERY legacy standards row in the entire CIPP instance to the current StandardsTemplateV2 format via GET /api/ExecStandardConvert.
cipp_standards_run
Pro · Destructive
Trigger a CIPP standards ENFORCEMENT run via GET /api/ExecStandardsRun.
cipp_update_drift_deviation
Pro · Destructive
Update drift deviation statuses for a tenant, or clear that tenant's drift customizations, via POST /api/ExecUpdateDriftDeviation.

Audit

ToolWhat it does
cipp_add_alert
Pro · Destructive
Create (or REPLACE) an AUDIT-LOG alert rule via POST /api/AddAlert — a row in CIPP's WebhookRules table that fires when matching unified-audit-log events arrive.
cipp_exec_add_alert
Pro · Write
Raise a one-off CIPP notification via POST /api/ExecAddAlert — it fires CIPP's OWN configured notification channels and/or writes a CIPP log entry.
cipp_list_alerts
Free · Read-only
List the CIPP alerts queue via GET /api/ListAlertsQueue.
cipp_list_audit_log_searches
Free · Read-only
GET /api/ListAuditLogSearches — THREE unrelated views behind one endpoint, selected by 'type', each returning a DIFFERENT row shape.
cipp_list_audit_log_test
Free · Read-only
Test audit log availability and configuration.
cipp_list_audit_logs
Free · Read-only
List CIPP's ALERT-MATCHED audit records via GET /api/ListAuditLogs — NOT the Microsoft 365 unified audit log.
cipp_list_logs
Free · Read-only
List CIPP's own operation logs (errors, status messages, per-API activity) via GET /api/ListLogs — the post-write verification surface: after a CIPP write answers 200, check here whether the operation actually logged an error.
cipp_list_pending_webhooks
Free · Read-only
List webhook subscriptions that are pending validation or delivery via GET /api/ListPendingWebhooks.
cipp_list_signin_logs
Free · Read-only
List Azure AD sign-in logs for a tenant.
cipp_list_webhook_alerts
Free · Read-only
List configured webhook alert subscriptions.
cipp_remove_queued_alert
Pro · Destructive
Permanently delete one queued alert via POST /api/RemoveQueuedAlert.
cipp_search_audit_logs
Pro · Write
POST /api/ExecAuditLogSearch — TWO unrelated mechanisms behind one endpoint, selected by the 'Action' key.

GDAP

ToolWhat it does
cipp_add_gdap_role
Pro · Destructive
Create GDAP role→group mappings in your PARTNER tenant via POST /api/ExecAddGDAPRole.
cipp_approve_gdap_invite
Pro · Destructive
Kick off CIPP's sweep of RECENTLY ACTIVATED GDAP relationships via GET /api/ExecGDAPInviteApproved.
cipp_auto_extend_gdap
Pro · Write
Auto-extend an expiring GDAP relationship via POST /api/ExecAutoExtendGDAP.
cipp_delete_gdap_invite
Pro · Destructive
Revoke a pending GDAP invitation via DELETE /api/ExecGDAPInvite.
cipp_delete_gdap_relationship
Pro · Destructive
Delete a GDAP relationship via POST /api/ExecDeleteGDAPRelationship.
cipp_delete_gdap_role_mapping
Pro · Destructive
Delete a GDAP role mapping via POST /api/ExecDeleteGDAPRoleMapping.
cipp_delete_gdap_role_template
Pro · Destructive
Permanently delete a stored GDAP role template via DELETE /api/ExecGDAPRoleTemplate?Action=Delete.
cipp_list_gdap_access
Free · Read-only
List the access assignments of ONE GDAP relationship via GET /api/ListGDAPAccessAssignments: the security groups granted access through that relationship and the roles each group maps to.
cipp_list_gdap_invites
Free · Read-only
List pending GDAP relationship invitations across your partner tenant.
cipp_list_gdap_relationships
Free · Read-only
List the GDAP delegated admin relationships of your partner tenant via GET /api/ListGDAPRelationships: each relationship's id, customer tenant, requested roles, status, duration and expiry.
cipp_list_gdap_roles
Free · Read-only
List all GDAP (Granular Delegated Admin Privileges) roles available in your partner tenant.
cipp_list_partner_relationships
Free · Read-only
List partner relationships (DAP/GDAP) for a specific tenant.
cipp_patch_gdap_access_assignment
Pro · Destructive
Reconcile one GDAP relationship's access assignments against a stored GDAP role template, via PATCH /api/ExecGDAPAccessAssignment.
cipp_remove_gdap_ga_role
Pro · Destructive
Remove the Global Administrator role from a GDAP relationship via POST /api/ExecGDAPRemoveGArole.

Scheduler

ToolWhat it does
cipp_add_scheduled_item
Pro · Destructive
Create, edit, or immediately re-run a CIPP scheduled task via POST /api/AddScheduledItem.
cipp_list_scheduled_item_details
Free · Read-only
Get details for a single scheduled item via POST /api/ListScheduledItemDetails.
cipp_list_scheduled_items
Free · Read-only
List all scheduled tasks and jobs in CIPP.
cipp_remove_scheduled_item
Pro · Destructive
Remove a scheduled task from CIPP.
cipp_run_scheduler_billing
Pro · Destructive
Trigger an immediate scheduler billing run via GET /api/ExecSchedulerBillingRun.

Utility

ToolWhat it does
cipp_breach_search
Pro · Write
RUN a Have I Been Pwned breach search for a tenant via POST /api/ExecBreachSearch.
cipp_geoip_lookup
Free · Read-only
Look up geographic location information for an IP address via POST /api/ExecGeoIPLookup.
cipp_get_alerts
Free · Read-only
Get current CIPP system alerts and notifications.
cipp_get_queue_status
Free · Read-only
Read CIPP's own background-job queue via GET /api/ListCippQueue.
cipp_get_version
Free · Read-only
Get the current CIPP instance version and build information.
cipp_graph_request
Pro · Write
Execute a single custom Microsoft Graph API request against a tenant via GET /api/ListGraphRequest.
cipp_list_breaches_account
Free · Read-only
List known data breaches for ONE account or domain via GET /api/ListBreachesAccount.
cipp_list_breaches_tenant
Free · Read-only
List known data breaches associated with ONE tenant's domain via GET /api/ListBreachesTenant.
cipp_list_csp_sku
Free · Read-only
List the CSP (Cloud Solution Provider) SKUs and license offerings available to ONE tenant via GET /api/ListCSPsku.
cipp_list_users_and_groups
Free · Read-only
List ONE tenant's users and groups together for quick directory browsing via GET /api/ListUsersAndGroups.
cipp_manage_csp_license
Pro · Destructive
Add, change, remove, cancel or schedule the removal of Sherweb CSP license subscriptions via POST /api/ExecCSPLicense.
cipp_universal_search
Free · Read-only
Search across all CIPP data for a tenant including users, devices, groups, and policies.
cipp_universal_search_v2
Free · Read-only
Search CIPP's cached tenant data with the V2 search engine via GET /api/ExecUniversalSearchV2. At CIPP-API master @df3738d the endpoint searches ONE data type per call, chosen by 'type': Users (the default), Groups, Applications or Licenses.

Diagnostics

ToolWhat it does
cipp_app_insights_query
Pro · Read-only
Query Application Insights telemetry for the CIPP backend via GET /api/ExecAppInsightsQuery.
cipp_cipp_db_cache
Free · Read-only
Start a CIPP database cache SYNC via GET /api/ExecCIPPDBCache.
cipp_clone_template
Pro · Write
Clone a CIPP template (CA, standards, alert, etc.) via POST /api/ExecCloneTemplate.
cipp_cpv_refresh
Pro · Write
Refresh CSP Vendor (CPV) consent and permissions across managed tenants via GET /api/ExecCPVRefresh.
cipp_delete_graph_explorer_preset
Pro · Destructive
Delete a saved Graph Explorer preset via DELETE /api/ExecGraphExplorerPreset.
cipp_download_cipp_logs
Pro · Write
Generate SAS-signed URLs to download CIPP application logs via POST /api/ExecCippLogsSas.
cipp_durable_functions
Pro · Read-only
Read CIPP Durable Functions state via GET /api/ExecDurableFunctions.
cipp_edit_template
Pro · Destructive
Edit a stored CIPP template (CA, standards, alert, Intune, etc.) via POST /api/ExecEditTemplate.
cipp_extension_ninja_one_queue
Free · Read-only
List the NinjaOne extension processing queue via GET /api/ExecExtensionNinjaOneQueue.
cipp_list_admin_portal_licenses
Free · Read-only
List the low-friction trial license allotments visible from the M365 admin portal for a tenant via GET /api/ListAdminPortalLicenses (camelCase 'tenantFilter' query, required).
cipp_list_api_test
Free · Read-only
Run the CIPP API self-test via GET /api/ListApiTest.
cipp_list_azure_ad_connect_status
Free · Read-only
Get ONE tenant's Entra Connect (Azure AD Connect) status via GET /api/ListAzureADConnectStatus: whether directory sync is on, the sync interval, password hash sync and pass-through authentication settings, the last sync time, and the directory objects currently in a sync error state.
cipp_list_backup
Pro · Read-only
List CIPP backup snapshots via GET /api/ExecListBackup.
cipp_list_check_ext_alerts
Free · Read-only
List the extension (external system) alerts CIPP has recorded for one tenant, newest first, via GET /api/ListCheckExtAlerts.
cipp_list_custom_data_mappings
Free · Read-only
List CIPP custom-data-mapping definitions via GET /api/ListCustomDataMappings.
cipp_list_db_cache
Free · Read-only
List ONE tenant's CIPP database cache contents via GET /api/ListDBCache.
cipp_list_diagnostics_presets
Pro · Read-only
List saved diagnostic query presets via GET /api/ListDiagnosticsPresets.
cipp_list_directory_objects
Free · Read-only
Resolve Entra ID directory objects by ID for a tenant via POST /api/ListDirectoryObjects.
cipp_list_extension_cache_data
Free · Read-only
Read CIPP extension cache data for a tenant via POST /api/ListExtensionCacheData.
cipp_list_extensions_config
Free · Read-only
List CIPP extension configurations via GET /api/ListExtensionsConfig.
cipp_list_feature_flags
Free · Read-only
List CIPP feature flags via GET /api/ListFeatureFlags.
cipp_list_function_parameters
Free · Read-only
List the parameter schema for a CIPP function via GET /api/ListFunctionParameters.
cipp_list_function_stats
Free · Read-only
List CIPP function execution statistics via GET /api/ListFunctionStats.
cipp_list_generic_test_function
Free · Read-only
Run the CIPP generic test function via GET /api/ListGenericTestFunction.
cipp_list_graph_explorer_presets
Free · Read-only
List saved Graph Explorer query presets via GET /api/ListGraphExplorerPresets.
cipp_list_halo_clients
Free · Read-only
List HaloPSA clients visible to CIPP via GET /api/ListHaloClients.
cipp_list_ip_whitelist
Free · Read-only
List CIPP's allowed IP ranges via GET /api/ListIPWhitelist.
cipp_list_known_ip_db
Free · Read-only
List the CIPP known-IP database for a tenant via GET /api/ListKnownIPDb.
cipp_list_notification_config
Pro · Read-only
Read the CIPP notification configuration via GET /api/ListNotificationConfig.
cipp_partner_webhook
Pro · Destructive
Configure Microsoft Partner Center webhook delivery via POST /api/ExecPartnerWebhook.
cipp_set_cipp_auto_backup
Pro · Write
Enable or disable CIPP automatic backups via POST /api/ExecSetCIPPAutoBackup.
cipp_set_package_tag
Pro · Write
Tag a CIPP package (e.g., for app deployments) via POST /api/ExecSetPackageTag.
cipp_set_user_bookmarks
Pro · Write
Persist a CIPP UI user's bookmarks via POST /api/ExecUserBookmarks.
cipp_user_settings
Pro · Write
Save a CIPP UI user's app settings via POST /api/ExecUserSettings.

Analytics

ToolWhat it does
cipp_add_test_report
Pro · Destructive
Create OR UPDATE a CIPP test report definition via POST /api/AddTestReport — this endpoint is an UPSERT, not a create.
cipp_all_tenant_bpa
Pro · Read-only
Get Best Practice Analyzer results across all managed tenants.
cipp_all_tenant_compliance
Pro · Read-only
Get the device compliance summary across all managed tenants via GET /api/ListAllTenantDeviceCompliance, read from Microsoft 365 Lighthouse's managed-tenant compliance data.
cipp_all_tenant_secure_score
Pro · Write
WRITE — acknowledge or resolve ONE Microsoft Secure Score control for a tenant via POST /api/ExecUpdateSecureScore.
cipp_bulk_graph_request
Pro · Read-only
Run many Microsoft Graph READS for one tenant in a single batched call via POST /api/ListGraphBulkRequest.
cipp_delete_test_report
Pro · Destructive
Delete a CIPP test report definition via POST /api/DeleteTestReport.
cipp_get_secure_score
Pro · Read-only
Read a tenant's Microsoft Secure Score via GET /api/ListGraphRequest with Endpoint=security/secureScores.
cipp_list_available_tests
Free · Read-only
List the full catalogue of CIPP tests that can be selected for a report via GET /api/ListAvailableTests.
cipp_list_secure_score_control_profiles
Pro · Read-only
Read the Microsoft Secure Score control profile catalog via GET /api/ListGraphRequest with Endpoint=security/secureScoreControlProfiles.
cipp_list_test_reports
Free · Read-only
List saved CIPP test report definitions via GET /api/ListTestReports.
cipp_list_tests
Free · Read-only
List the results of a test run for a tenant via POST /api/ListTests.
cipp_offboard_tenant
Pro · Destructive
Offboard a customer tenant via PATCH /api/ExecOffboardTenant.
cipp_run_domain_analyser
Pro · Write
Start domain analysis for ONE tenant via POST /api/ExecDomainAnalyser.
cipp_run_test
Pro · Write
Trigger a tenant test run via POST /api/ExecTestRun.

Application Approvals

ToolWhat it does
cipp_add_multi_tenant_app
Pro · Write
Queue a multi-tenant enterprise-app deployment via POST /api/ExecAddMultiTenantApp.
cipp_create_app_template
Pro · Write
Capture an existing app in a source tenant as a reusable app-approval template via POST /api/ExecCreateAppTemplate.
cipp_delete_app_approval_template
Pro · Destructive
Delete an application approval template via DELETE /api/ExecAppApprovalTemplate, body-carried.
cipp_delete_app_permission_template
Pro · Destructive
Delete an application permission-set template via DELETE /api/ExecAppPermissionTemplate, body-carried.
cipp_exec_app_approval
Free · Read-only
Build the per-tenant Microsoft admin-consent links for an application, via GET /api/ExecAppApproval.
cipp_exec_application
Pro · Destructive
Edit or delete an application object / service principal via PATCH /api/ExecApplication.
cipp_exec_service_principals
Pro · Destructive
List, get, or create service principals in the PARTNER tenant via GET /api/ExecServicePrincipals (the parameters travel in the query string; there is no request body and no tenantFilter — the endpoint always acts on the partner tenant).
cipp_list_app_approval_templates
Free · Read-only
List all application approval templates in CIPP.

Applications

ToolWhat it does
cipp_add_choco_app
Pro · Write
Queue a Chocolatey package for Intune deployment via POST /api/AddChocoApp — a CROSS-TENANT fan-out that writes one row per target tenant into CIPP's 'apps' queue table.
cipp_add_msp_app
Pro · Write
Queue an RMM/MSP agent installer for Intune deployment via POST /api/AddMSPApp — a CROSS-TENANT fan-out that writes one 'Not Deployed yet' row per target tenant into CIPP's 'apps' queue table.
cipp_add_office_app
Pro · Destructive
Deploy Microsoft 365 Apps (Office) to Intune via POST /api/AddOfficeApp — a CROSS-TENANT fan-out.
cipp_add_store_app
Pro · Write
Queue a Microsoft Store (winget-source) application for Intune deployment via POST /api/AddStoreApp — a CROSS-TENANT fan-out that writes one 'Not Deployed yet' row per target tenant into CIPP's 'apps' queue table.
cipp_add_win32_script_app
Pro · Write
Queue a Win32 script-based application for Intune deployment via POST /api/AddWin32ScriptApp — a CROSS-TENANT fan-out that writes one 'Not Deployed yet' row per target tenant into CIPP's 'apps' queue table.
cipp_assign_app
Pro · Destructive
Assign an existing Intune application to users, groups, or devices in a tenant via POST /api/ExecAssignApp.
cipp_exec_app_upload
Pro · Write
Upload an application package to Intune.
cipp_list_application_queue
Free · Read-only
List queued application deployments across tenants.
cipp_list_apps_repository
Free · Read-only
Search a Chocolatey-style (NuGet v2) package feed for deployable application definitions via POST /api/ListAppsRepository.
cipp_list_potential_apps
Free · Read-only
Search a public package source for deployable applications via POST /api/ListPotentialApps.
cipp_remove_app
Pro · Destructive
Permanently remove an Intune-managed application from a tenant via POST /api/RemoveApp.
cipp_remove_queued_app
Pro · Destructive
Cancel a pending deployment in the CIPP application queue via POST /api/RemoveQueuedApp before it processes.
cipp_sync_vpp
Pro · Write
Trigger a sync of Apple Volume Purchase Program (VPP) tokens for a tenant via POST /api/ExecSyncVPP.