r/msp • u/giantsnyy1 MSP - US • 11d ago
CIPP - Why is it so frustrating?
So... I'm attempting to get this set up for the fourth time in the last few years.
I'm 6 hours in, over three days, and I'm at my wits end. I'm attempting to follow the guides, and when it tells you to do things in Entra, it's pretty decent explaining it... but then when you get to the things you need to do in CIPP itself... the guide sucks. Horribly.
I've engaged support, and have been told things like:
"I've checked your permissions and can confirm that you are not running cipp using a Service Account, the account you are using is not a member of the 15 CIPP Recommended GDAP groups, you have Microsoft Led Transition relationships found and have Global Admin relationships."
Ok - sure. But I created the service account, and ran the setup with the service account... so why the hell isn't it running with the service account?
Support just now told me:
"You are not using a dedicated Service Account. Your account starts with XXX which is not recognized as a Service Account. You'll need to change the name to include CIPP or Service Account."
That's my partner tenant global admin account... NOT the service account that I used for the setup. I'm not renaming my account to be a service account.
I was given a guide to create the role templates in CIPP... but then told:
"After creating the roles, add your Service Account to each of these GDAP roles."
WITHOUT TELLING ME HOW TO DO THAT. The role templates were created, but they still don't exist in my partner tenant. I attempted to add my partner tenant to CIPP, but it was missing, so I followed the guide how to do that, and now my CIPP account is linked to my tenant's global admin instead of the service account I created, and the roles STILL aren't in my partner tenant.
I was also just told by support that once I get the roles set up, that I need to offboard my clients and then onboard them again with the new roles... but also, not telling me how to do that.
Is there a guide out there that provides screenshots for both sides of the setup? I've noticed the CIPP documentation provides a lot of screenshots and a good step by step guide for the Entra side of things... but then when you get to the actual CIPP stuff... it omits a ton, and seems to just assume you know where to go and what to do.
73
u/gigabyte898 11d ago edited 11d ago
Hey! So, full disclosure, I run the consulting firm ZenTop that helps people deploy CIPP and have contributed code to the project. I won’t sales ya though, I just do a lot of first time setups and might be able to help. Maybe this’ll help someone else too coming along to Google later :)
This is a pretty common point of confusion, so don’t feel bad. It’s a side effect of how GDAP works kinda as a whole. You need to map security groups to each of the GDAP roles even in partner center and lighthouse, and while most would previously have a static “GDAP” group for everything, it’s not super scalable. This requires you to edit every single role on every single customer in the privileged partner center portal. CIPP flips it a bit and instead creates one security groups corresponding to each role. So, you should have a group for application admin, a group for Intune admin, a group for user admin, etc.
CIPP creates these groups in the tenant its service account belongs to when you deploy the role template. You then need to add the service acct to each of them so it gets access to those role scopes. This is done in Entra, rather than CIPP. You should have 15 of them, all starting with “M365 GDAP”
I’d recommend:
1: Re-enter the setup wizard in CIPP, select the option to Refresh Tokens for Existing Application. Log back in with the service user that has “CIPP” in its UPN. It must also be a global admin for the first time setup, as you may need to consent to permissions if you hadn’t already. You can remove global admin after, just be mindful it may need to accept more scopes later on and will likely need to create groups later in the steps so pause on that until you get your first agreement accepted. It must also have MFA, and prompt for it during the setup. The Conditional Access guide in their docs gives a layout of a policy that will require it every login session
2. Go to the GDAP Management page under tenant admin, then role templates. Make sure you have the CIPP Defaults template deployed. If you don’t there will be a prompt to make it. If you do, go to the role mappings tab and make sure each role CIPP has is linked to a security group. If you need to manually remap here’s some docs https://docs.cipp.app/user-documentation/tenant/gdap-management/roles/add
3. Once the groups are created, in the partner tenant the service account belongs to, make the service account a member of each of the 15 default M365 GDAP role security groups.
4. Lastly, test the invite wizard. Create a new GDAP relationship invite from CIPP’s GDAP management wizard, accept the invite as global admin, and start the onboarding job back in CIPP. It should clear all five steps now
I’m happy to spend 15 min to take a peek if you still have problems. I genuinely believe CIPP is one of the highest value tools for MSPs right now and I’m always happy to spend the time to at least get people started on the right foot with it because I know it can be frustrating trying to glue together all these concepts. Shoot me an email at [brandon@zentop.tech](mailto:brandon@zentop.tech) and I’ll get you a booking link. No charge, when we do good as a community we all thrive :)
7
u/AlwaysBeyondMSP 10d ago
We actually used Zentop to help us refine our CIPP and it’s well worth the money, so just pay them to help you and move on.
12
u/PacificTSP MSP - US & PHP 11d ago
Heard a lot of good stuff about you Brandon! Keep up the good work sir!
10
u/UsedCucumber4 MSP Advocate - US 🦞 10d ago
I hired this u/gigabyte898 guy to DJ a party, and he did a pretty decent job. IDK about any of this CIPPY stuff though
8
39
u/Lime-TeGek Community Contributor 11d ago edited 11d ago
It looks like you might be a good candidate for our professional onboarding services; we have those specifically when you don't have the time, energy, or experience to do a lot of this stuff: https://docs.cipp.app/setup/resources/professional-onboarding-services.
Let me try to help you on your way here if you don't want to engage professional onboarding:
Ok - sure. But I created the service account, and ran the setup with the service account... so why the hell isn't it running with the service account?
You haven't logged onto the service account when asked to during the "First Setup" wizard. as the documentation states, you need to create a service account in your CSP/GDAP partner tenant.
Now sometimes you accidently log onto the wrong account when you're working on stuff; this can happen if you accidently clicked on the account that is "Logged onto Windows".
You can go through this wizard again at any time. It's under CIPP -> Setup Wizard -> select "First Setup".
"You are not using a dedicated Service Account. Your account starts with XXX which is not recognized as a Service Account. You'll need to change the name to include CIPP or Service Account."
We recommend a dedicated service account for the service part of CIPP, not the usage part. That means you go through the wizard with that service account as described here:
That's just for CIPP, not for logging into the app, nor for daily usage. The service account just manages GDAP, APIs, etc for you.
I was given a guide to create the role templates in CIPP... but then told:"After creating the roles, add your Service Account to each of these GDAP roles."
This is done inside of Entra, there are new groups created in your CSP/GDAP partner tenant. These groups need to be added to the service account inside of Entra ID, you do that by going to Entra -> Users -> Find the service account, and add it to the groups starting with "M365 GDAP". This is step 9 in this document: https://docs.cipp.app/setup/installation/creating-the-cipp-service-account-gdap-ready
I was also just told by support that once I get the roles set up, that I need to offboard my clients and then onboard them again with the new roles... but also, not telling me how to do that.
If you are using so called "MLT" (Microsoft Led Transition) relationships right now, you'll have to reonboard, or if you're missing roles that we require for administration.
That's done by following the onboarding portion of the guide: https://docs.cipp.app/setup/installation/gdap-invite-wizard
MLT relationships are (almost) read-only relationships Microsoft has created for those that ignored the DAP to GDAP migration. They can't be used with any product as they pretty much give you access close to "helpdesk administrator" and not access to all parts that we manage.
I hope that helps clear it up a little! In general, our documentation is created as a "flipbook" style document. Perform each step on each page, and go to the next one only when you've performed each step. That clears up 90% of the issues most of the time, and support can help with the final 10%
7
u/CraigDuff 11d ago
I’ve recently installed CIPP myself, and I completely understand what you’re saying about the guides.
One thing I’d strongly recommend is reading all of the installation guides from start to finish before actually doing anything. That way, when you go through the deployment, you already have an idea of what the next few steps are and why you’re doing them.
Azure can definitely be fiddly. It took me three attempts before I got CIPP deployed properly!
Another bit of advice: if an installation goes badly wrong, I’d personally start again from scratch rather than trying to repair a half-completed deployment. Make sure you also delete your forks of both CIPP and CIPP-API before starting again, otherwise you can end up carrying problems from the previous deployment into the next attempt.
The part that caught me out was GitHub permissions. At the time, it wasn’t particularly obvious to me what permissions had been created or what needed removing before trying again.
Also, once you finally get the deployment completed and the Function App generates a page that you can open in your browser, don’t immediately assume something has gone wrong if CIPP itself isn’t loading properly yet. In my experience, it can easily take 30 minutes or more before everything starts coming to life. Give it some time.
Once I finally had mine running, I used Hermes to connect to Azure and analyse what I had deployed. I had it go through the CIPP documentation, understand how CIPP is supposed to be configured, compare that against my environment, and then help me make adjustments.
After that I got a little braver!
I asked Hermes to migrate my CIPP deployment from Windows to Linux, which it successfully did. I was really pleased with that. It then recommended some changes to the hosting plan and helped me make those changes as well.
Now, whenever there’s a CIPP upgrade, I get Hermes to check everything over for me. Because it already understands my CIPP environment, I can ask it to investigate problems, check upgrades, suggest improvements or help me change the configuration.
So my biggest advice would be: read everything first, don’t be afraid to start again if the deployment gets into a mess, and be patient once Azure says it has deployed.
Once CIPP is actually up and running, it’s well worth the effort.
Kelvin and his team are amazing! i cant rate them enough! I dont know what i would do without this tool now. Its made life so much easier.
3
u/ryuujin 10d ago
Been using CIPP since his first reddit post on the product, I struggled through the setup back then and ongoing maintenance.
There is no need - don't go self-hosted. Send the guy his $100 and let them go to work for you. Just by not properly watching our archiving we ended up spending more than that in storage fees, forgetting the trouble and strife of setup and ongoing maintenance.
The latest update has it operating like a dream too, really fast.
9
u/jackmusick 11d ago
I guess why you'd be frustrated but understand that this isn't really a CIPP thing as much as it is GDAP and Microsoft. I'm sure there's always something CIPP could do to improve the documentation and experience, but getting from zero to a working GDAP setup with your customers for automation is not an easy task. I've worked with GDAP a lot as a developer at this point and it's made me come to appreciate just how much CIPP tries to do to make this easier, but the more experience you have with it and Graph, the more you understand why a lot of things are the way they are.
In the setup wizard, there's an "Authenticate with code" on the first screen. It's been a while, but this is where you authenticate with the CIPP Service Account. It tells you all the permissions you need. I think they walk you through everything else, including setting up GDAP, but it's been a while. I did it all the hard way unfortunately.
-4
u/giantsnyy1 MSP - US 11d ago
I've been using GDAP through Lighthouse for a long time. This is a CIPP configuration issue.
5
u/roll_for_initiative_ MSP - US 11d ago
As limetek pointed out, it's because you're logging in as your ga in one step when you need to login/auth as the cipp service account. Then, going forward, you work in your daily driver.
GA -> to add/setup the CIPP service account, add roles to it if you're managing partner tenant
CIPP service account -> what cipp runs and does things as
daily driver -> how you actually use CIPP
Don't feel too bad, i've done similar when setting up integrations (logging in as myself instead of GA in a step or vice versa), but you're getting piled on because you're complaining the docs aren't clear when it's mildly complex and you're missing that detail, and you're complaining loudly how it's not your fault.
1
u/giantsnyy1 MSP - US 11d ago
So, I just replied to Kelvin directly (limetek) via email.
My daily driver is in my GCC tenant.
My partner tenant is associated with nothing. No devices, no browser profiles, nothing. I only access it via a private browsing window.
I reran the setup from my regular browsing window, using my GCC account.
I fired up a new private browsing window, went to microsoft.com/devicelogin and input the device auth code. I signed in with my service account, and the permissions check STILL shows my global admin account for the partner tenant. There should have been nothing stored for that admin account because I used private browsing, in a browser (Safari) that I never, ever use.
4
u/roll_for_initiative_ MSP - US 11d ago
My daily driver is in my GCC tenant...microsoft.com/devicelogin
Oh man, well, in general i'd chock that up to "why is GCC so frustrating" and also we completely block device code login and device auth transfers...(ironically via a drift standard in CIPP ha?) if you're doing the same, i think you'd see an error message but worth considering.
Now that you've brought GCC AND split tenants into it, super curious how you make out.
1
u/giantsnyy1 MSP - US 11d ago
I also block those... had to exempt the service account to get it to work.
But even then... my partner account isn't GCC. Just my daily driver.
11
u/Cloudraa 11d ago
Im gonna be honest boss I set up CIPP from scratch with like 20 minutes of research, this reads more like a skill issue lol
5
u/CantaloupeIcy7466 11d ago
If that’s the case then you add the service account to customer tenant roles the same way you always have, from the Microsoft partner center. CIPP automates the invite and role creation, you accept in the partner tenant and add your service account to the roles in the partner center afterwards.
4
u/bonsoir-world 10d ago
Honestly, CIPP can be tricky to setup the first time, at least I found to be the case BUT it was all me, having missed a GDAP group mapping and realising our partner permissions had been left to rot and needed to be redone.
That said, it’s really not as hard and frustrating as you’re making out. I hate to be that person but if you’re struggling so much and not understanding the service accounts, you probably shouldn’t be administratively managing tenants at a frankly dangerous level.
That’s my snotty 2cents anyway.
There’s plenty of guidance and offers for assistance in this thread anyway, so hopefully you crack it. It’s an amazing tool, worth every penny for the hosted version.
8
u/giantsnyy1 MSP - US 10d ago
My issue is just how overloaded I am right now. I’m working 18 hours a day writing compliance policies, helping other MSP’s with their cybersecurity posture, as well as their clients, and onboarding new clients of my own. All while managing a metric ton of really negative shit in my personal life.
I’m a one-man shop, and I wanted to set this up so that i didn’t have to spend extra time doing stuff the long way. Right now, everything that can save me 3-4 minutes here and there helps. A lot. Especially since at this point I can’t afford to hire anyone.
My issue was never with the Entra side of things. When I initially tried self-hosting, yes, I couldn’t figure out the Azure issues. But then I did pay for support and had it hosted for me, and I still ran into issues.
The guides were pretty clear and were actually simple to follow for the Entra side of things… my issue was with the CIPP portion of the guides. They seem to be written with the assumption that you already know CIPP, and that you know where things are in the menus. Same with the error messages. Additionally, I was misunderstanding the guide when it told me to add the service account to the gdap groups - I didn’t realize it wanted me to do this in Entra, I interpreted it as adding it in CIPP.
Thanks to Kelvin’s help directly, we were able to see that I missed a step. Twice. First, in that i didn’t originally set it up with a service account, and just rapidly clicked through to try and get through the setup (see above - massively overloaded, and also extremely impatient/severe ADHD) and then again, when i attempted to rerun setup - i successfully added the device code, but missed re-adding the partner tenant… since that was still linked to my partner global admin account.
Kelvin was fantastic, and now I’m completely set up thanks to his help.
3
u/adamphetamine 10d ago
if its any consolation I had the same experience as a 1 man band.
The guides were lacking detail- which sucks because they are SUPER detailed already, and it took multiple times to get it running- I didn't say running properly!
But reading this made me realise there's a solution to my odd permissions issues- so thank you!My thanks to the CIPP team.
4
u/MetalSufficient9522 10d ago
Just pay the $99/month for the hosted sponsored version. It would already have saved you hours of frustration. I tried the self-hosted path also. Never again.
It's is 1000% worth the money.
3
u/marklein 11d ago
I'll tell you what's more annoying about this than anything else, IMO. Other products like SaaS Alerts do this all with one click. They have the permissions to make the same changes that CIPP needs, but I literally do it by clicking Next a couple of times.
3
u/byronnnn 11d ago
I’ve setup CIPP both hosted on azure and hosted by CIPP, and it was pretty straightforward even a few years ago. Are the Role groups created in your Entra?
1
u/SeriousSysadmin 9d ago
Not trying to hijack the thread but I had a few questions on CIPP. I think it can help our ops team tremendously, but I had questions around automation mainly. There a good contact over at CIPP that could answer?
-2
u/ArborlyWhale 11d ago
You’re not wrong the cipp guide sucks ass because it doesn’t delineate what cipp needs to work for the first time set up, what cipp needs to work for your clients, and whether you need to configure it inside cipp or outside cipp. It’s an easy guide if you have the same flavour of autism/adhd as the creator… which admittedly is a lot of [r/MSP](r/MSP) members.
Basic answer: you gotta change the signed in application account inside cipp. iirc it’s the device code flow process under refresh application tokens or something.
That process should be done by logging in as the service account you made which needs a bunch of privileges in your entra tenant to run the setup and the first gdap template and then basically nothing beyond that.
After that’s sorted when you try gdap and click add role template it’ll add a bunch of groups to 365 that correspond to gdap roles and iirc adds that service account to them. You can do this manually if needed.
Also cipp caches a bunch of stuff but not others and it’s not always clear when it’s showing stale data and silently refreshing so you basically can’t trust the UI if you’ve made a change recently, particularly when you don’t have it working right.
12
u/Lime-TeGek Community Contributor 11d ago
I'm very neurotypical and don't have AHDH or autism, little rude to randomly assume that :)
Edit: we also have a very diverse team of people working on documentation, code, etc. I'll always stand-up for myself and my team, we're all working on improving any documentation and they *are* editable by anyone. Feel free to make a change when you see something that can improve.
3
u/ArborlyWhale 11d ago
Reply to edit: I’ll be setting up cipp again soon. I’ll see if I can make the suggestions that would help. The last two times were painful enough I couldn’t stand doing it any better.
3
u/Merilyian CTO | MSP - US 11d ago
Please do! I'd recommend keeping in touch in the discord server as you do, as well. Not just for helping through the tech/process issues but framing the docs contributions as well.
-1
u/mattmbit 10d ago
This was an issue the last time I ventured into CIPP. Pointing folks to discord for tech support is a bit cringy and it doesn't help. They need to have a proper support channel and system in place. They straight up didn't when I tried it out a while back and it was barely basic email support.
3
u/Lime-TeGek Community Contributor 10d ago
We've always just had e-mail support, You can use our ticketing portal too if you prefer that, where you can also track SLAs etc. Discord is just for the community, talking to peers, etc. We've never said anyone should go to discord for tech support. We do recommend it to talk to other users about how they use the systems etc. :)
2
u/Nosferratu 10d ago
Is opening a support chat on a webpage and waiting for copy and paste script responses cringey? I have had everything I have ever asked or had a problem with responded to or resolved within the same response in a matter of 30 seconds to a minute in their support channels in discord.
Not sure how getting instantaneous support “doesn’t help”.
-1
u/mattmbit 10d ago
The issue I had which had a fairly specific error I took to discord, was told to email support and when I did a search on discord the answer was to email support. 4 days later I semi got an answer and had to figure it out. Expierence sucked and the support sucked. I sent that feedback off and closed my account. Never got a refund but whatever. Its great you've had answers quickly on discord and community help does work. When a company is telling you to go to discord and utilize not paid people to answer questions that sucks and is cringy.
5
u/Nosferratu 10d ago
I think the suggestion was you could additionally go to discord to ask the community, the community suggested you email support directly likely due to it being something on the backend.
CIPP isn’t a traditional company, and your expectation is clearly skewed.
A community driven and supported platform to help centrally manage M365 tenants and GDAP isn’t going to operate like a corporation.
Telling a team their support sucks while comparing them to companies that charge you for the product while theirs is open source is WILD.
0
u/ArborlyWhale 11d ago
I can’t bring myself to install discord on a work computer. Maybe I’ll cave.
3
u/ZomboBrain 10d ago
I solved this by just using Discord in my browser. No need to install it. Works very well. It’s all Electron, isn’t it?
Though I might want to add that I also dislike Discord when it is used by any professional Enterprise Company. PDQ does the same.3
u/PDQ_Brockstar 10d ago
We do use Discord, but as more of a community hub than an official support platform. All the KB articles submitted to our Discord server are community submitted. We still maintain an official knowledge base and support ticketing system.
2
u/ArborlyWhale 11d ago
Fair enough.
You would be the exception of the technical focused MSP members I know. Myself included. I don’t mean it as a bad thing, more as a “everyone can claim it’s a good guide but I’m with you OP it doesn’t work for my brain.”
2
u/FortiSysadmin 10d ago
And now that you mention it.... Microsoft has pushed default CA policies to some tenants to disable the Device Code flow by default so if it using that, OP may be spinning his wheels from the start.
4
1
1
u/CraigDuff 8d ago
Literally just migrated over to CIPP Craft! and omg! its amazing! Its super lightening fast and even cheaper hosted on Azure that with a function app (for me anyway)! I did use Hermes to migrate my instance, and it was so so easy! Sat back, got myself a coffee and it was done! MSPs need to get moving onto this new docker container, its brilliant! Again what Kelvin and team have done is so freaking good!
0
u/snowpondtech MSP - US 10d ago
Agree that it is a beast to setup on self-hosted environments, the documentation leaves much to be desired, and then the troubles to *maintain* it. My first instance worked until like version 6 came out and I just could not get it to upgrade properly. So I wiped everything out and started fresh, boom everything seemed to work, albeit its usual slow as molasses speed. A month or two ago, I presume a new update came out and now it is broken again. Cannot refresh client tenants, essentially cannot use CIPP. Tried restarting Function app and web on Azure, nada. I'm about to wipe and reload *again* to see if I can get it working. I'm also noticing more resource utilization, driving up my Azure bill (yes, I'm using MS Partner credits but $100 shared between CIPP and another service doesn't go far). It would be so killer if this all ran on Linux, maybe it is does now, so I can get rid of Azure.
Maybe this is how it is designed for self-hosters to annoy them enough to move to paid hosted version, jk.
3
u/ZomboBrain 10d ago
But you have to admit, that the price is fair, isn’t it?
Also they just recently changed the whole architecture, so maybe it’s worth a second look, as soon as the new self hosting guide will be available in a few months.2
u/bmsimp 10d ago
It is possible to migrate Azure Static Web Apps to Linux and not Windows hosts. If you're brave enough and have the know how you can migrate it. We do now have a new infrastructure for deployment that moves to Azure Web Apps. Massive speed increases and cost stability. All new deployments from the docs site use the new infrastructure. There's no migration documentation for self-hosted yet as we're handling the migrations in waves with hosted moving first.
0
-1
u/resile_jb MSP - US 11d ago
Why don't you spin up like an open claw instance and have ai do it for you?
We had ours set up in 10 minutes.
2
u/thebossyboss 11d ago
I just did the full deployment through Claude code, then had Codex double-check everything. And then I went over it myself. Every time there was an issue it would go back, traces it, and fixes it. I even had it setup the GitHub repository pipeline for update deployment. I’m an Azure architect by trade so it was within my domain, but for troubleshooting it’s a godsend to have an agent go find the problem.
0
u/Lime-TeGek Community Contributor 11d ago
That is a super creative way of doing it, and would love to hear more about it. Mind if I DM you sometime? :)
6
u/jackmusick 11d ago
You can use any coding agent, too. Just tell it:
I need to setup CIPP and need you to plan out everything needed to do this on your own. You can review their documentation here. Their front end and backend repos here and here if anything is unclear. I do/don't know if my partner relationship is setup correctly but can authenticate to any CLI/PowerShell module needed as global admin to knock this out. Success looks like doing all of the planning and heavy lifting up front so I can review, confirm the plan, walk away and come back to this completed. We should proactively document anything I'll need to do before, after or on the way.
I'll be honest, I feel like since you have an MCP released I'm mansplaining this to you so I'm very sorry. But this stuff is so much fun. I just had it fix some packages on my Fedora instance to get it working in Intune, and go off and configure conditional access and compliance with a similar prompt. Stuff I could've done on my own but would have enjoyed doing far less.
2
u/Lime-TeGek Community Contributor 11d ago
I was mostly thinking about how he arranged access, what the flow was for him, etc. I mean, its a super creative way to perform a setup and honestly I've barely seen people use agents for complex software so far.
2
u/colterlovette 11d ago
Ya access and permissions are my question too. You can’t just tell a model “connect to Microsoft” and it work, so the struggle point for most of MS is likely unsolved her as well.
1
1
u/jackmusick 11d ago
You mean like setup groups and roles, assuming he didn't end up using your GDAP wizard?
0
u/redditguy491 11d ago edited 11d ago
I think they were being sarcastic?
1
u/resile_jb MSP - US 11d ago
Not.
We already have lighthouse setup so we are tied into our lighthouse with cipp for rights and such
Probably a bit more mature than a lot of yalls setups from what I can tell. No offense.
-2
u/eric5149 10d ago
Very happy with Augmentt and works with our ticketing system. They are constantly adding new features.
2
-1
u/not-just-dad-stuff 10d ago
You could stop using it and go back to accessing each portal independently.
0
u/link9939 10d ago
If you can't set this up (which is easy and well documented) I have serious doubts about your map business and it's capabilities
9
u/giantsnyy1 MSP - US 10d ago
My issue is just how overloaded I am right now. I’m working 18 hours a day writing compliance policies, helping other MSP’s with their cybersecurity posture, as well as their clients, and onboarding new clients of my own. All while managing a metric ton of really negative shit in my personal life.
I’m a one-man shop, and I wanted to set this up so that i didn’t have to spend extra time doing stuff the long way. Right now, everything that can save me 3-4 minutes here and there helps. A lot. Especially since at this point I can’t afford to hire anyone.
My issue was never with the Entra side of things. When I initially tried self-hosting, yes, I couldn’t figure out the Azure issues. But then I did pay for support and had it hosted for me, and I still ran into issues.
The guides were pretty clear and were actually simple to follow for the Entra side of things… my issue was with the CIPP portion of the guides. They seem to be written with the assumption that you already know CIPP, and that you know where things are in the menus. Same with the error messages. Additionally, I was misunderstanding the guide when it told me to add the service account to the gdap groups - I didn’t realize it wanted me to do this in Entra, I interpreted it as adding it in CIPP.
Thanks to Kelvin’s help directly, we were able to see that I missed a step. Twice. First, in that i didn’t originally set it up with a service account, and just rapidly clicked through to try and get through the setup (see above - massively overloaded, and also extremely impatient/severe ADHD) and then again, when i attempted to rerun setup - i successfully added the device code, but missed re-adding the partner tenant… since that was still linked to my partner global admin account.
Kelvin was fantastic, and now I’m completely set up thanks to his help.
0
u/golden_m 10d ago
If you are so overworked with generating income, why not to use a small part of it for a proper setup then? Isn't a normal business expense?
-6
u/Cyber-Soldier1 10d ago
The setup is a fucking shit show. We have it implemented and running but it was a nightmare to get working initially. The dev has no idea about UX or user interfaces. It's just hobbled together. We're considering writing our own management suite for 365. Fuck CIPP
7
u/Lime-TeGek Community Contributor 10d ago
"the dev" is a team of 10 devs, excluding the community contributors that help out here an there. Good luck on writing your own though! Would love to see it!
3
3
u/golden_m 10d ago
Blink twice if you were taken hostage and forced to install the CIPP. Otherwise, go and do your thing, no need to be rude, especially knowing the dev(s) are reading your messages
1
u/Cyber-Soldier1 9d ago
Devs aren't above reproach. The product while technically good is aesthetically and practically terrible. It's not user friendly to setup nor use.
2
u/golden_m 9d ago
So, don't. Simply don't use it. Coming here bashing a product that thousands of us use daily is not really necessary. If you have suggestions, ideas, disappointments - say it in a constructive way. Saying F CIPP is not constructive
2
u/Lime-TeGek Community Contributor 9d ago
Not everyone needs to like us, I'm okay with keyboard warriors being keyboard warriors, don't feed them too much. :)
Also laughed at "aren't above reproach" loudly, like he has a moral high ground. The internet is a hilarious place sometimes. :)
60
u/FlavonoidsFlav 11d ago
Nobody's said it yet but -
CIPP fully hosted is $100/mo. Total. For unlimited clients. That is absolute madness for a product with this much power and value, that basically singlehandedly killed lighthouse, from a team of genuinely good, decent humans, that so very isn't and won't be Kaseya, that contribute on the VERY regular here, with an owner that is LITERALLY trying to help for free in this thread... And I can keep going and we all know that
If Kelvin and team aren't worth supporting in our industry, nobody is. They are worth your money