CIPP Inspector Summary

Summary

PropertyValue
Production StatusPreview
CategoryCloud
DiscoversOne child launchpoint per managed Microsoft 365 tenant, mapped to that Customer's Liongard Environment

Description

The CIPP Inspector monitors a Partner's self-hosted CIPP (CyberDrain Improved Partner Portal) instance and every Microsoft 365 tenant that instance manages. The parent enumerates the managed tenants and reports the health of the GDAP delegated-admin relationships that grant access to them; each child reports one managed tenant's Microsoft Secure Score, license utilization, Conditional Access policies, standards compliance, MFA coverage, users, inactive accounts, and open Microsoft 365 Defender security incidents.

Asset Mapping: No asset mappings ship with this Inspector.


Data View Information

Parent Overview Table

  • CIPP Instance Overview
    • Total Managed Tenants
    • GDAP Relationships
    • GDAP Relationships Expiring Soon
    • Discovered Child Count

Parent Data Tab Headers

  • Overview
  • Tenants — 4 columns
  • GDAP Relationships — 5 columns

Child Overview Table

  • Tenant Overview
    • Tenant Name
    • Secure Score Percentage
    • License SKUs
    • Conditional Access Policies (Total / Enabled)
    • Standards Non-Compliant
    • Total Users
    • MFA Coverage Percentage
    • Inactive Accounts
    • Open Security Incidents

Child Data Tab Headers

  • Overview
  • Licenses — 4 columns
  • Conditional Access — 5 columns
  • Standards — 4 columns
  • Users — 5 columns
  • MFA — 4 columns
  • Inactive Accounts — 3 columns
  • Security Incidents — 5 columns

Metrics

MetricDescription
CIPP: Total Managed TenantsTotal M365 tenants managed by this CIPP instance. Tenants whose record carries no usable default domain name are counted here but cannot become child launchpoints, so this can exceed the number of children.
CIPP: GDAP RelationshipsTotal delegated admin (GDAP) relationships with Customer tenants.
CIPP: GDAP Relationships Expiring SoonDelegated admin relationships expiring within 30 days, including any already expired. An expired GDAP relationship removes CIPP's — and this Inspector's — access to that tenant.
CIPP: Tenant DomainsDefault domain names of all managed tenants, used for new/removed tenant detection.
CIPP: Secure Score PercentageMicrosoft Secure Score for this tenant, as a percentage of the maximum achievable score.
CIPP: License SKUsNumber of distinct Microsoft 365 license SKUs assigned to this tenant.
CIPP: Conditional Access PoliciesTotal Conditional Access policies configured for this tenant.
CIPP: Conditional Access Policies EnabledConditional Access policies currently in the enabled state (excludes report-only and disabled).
CIPP: Standards Non-CompliantCIPP Standards currently reporting a non-compliant state for this tenant.
CIPP: Total UsersTotal Entra ID users in this tenant.
CIPP: Users Without MFAUsers whose legacy per-user MFA state is not enabled or enforced. This reads Entra's per-user MFA setting, not MFA registration.
CIPP: MFA Coverage PercentagePercentage of reported users whose legacy per-user MFA state is enabled or enforced. Not MFA registration coverage.
CIPP: Inactive AccountsUser accounts with no sign-in activity in the last 180 days.
CIPP: Open Security IncidentsMicrosoft 365 Defender security incidents not in a resolved or closed state.

Actionable Alerts

RuleTriggerSeverity
CIPP | Secure Score Below ThresholdSecure Score Percentage drops below 50%High
CIPP | MFA Coverage Below ThresholdMFA Coverage Percentage drops below 90%High
CIPP | Open Security Incidents ChangedOpen Security Incidents count changesHigh
CIPP | Users Without MFA ChangedUsers Without MFA count changesMedium
CIPP | Conditional Access Policy Count ChangedConditional Access Policies count changesMedium
CIPP | Conditional Access Enabled Count ChangedConditional Access Policies Enabled count changesMedium
CIPP | Standards Non-Compliant ChangedStandards Non-Compliant count changesMedium
CIPP | GDAP Relationship Expiring SoonGDAP Relationships Expiring Soon rises above 0Medium
CIPP | Inactive Account Count ChangedInactive Accounts count changesLow
CIPP | Tenant Added or RemovedTenant Domains (the set of managed tenants) changesLow

All alerts ship disabled and can be enabled per your thresholds.


Did this page help you?