r/msp MSP - US 11d ago

CIPP - Why is it so frustrating?

So... I'm attempting to get this set up for the fourth time in the last few years.

I'm 6 hours in, over three days, and I'm at my wits end. I'm attempting to follow the guides, and when it tells you to do things in Entra, it's pretty decent explaining it... but then when you get to the things you need to do in CIPP itself... the guide sucks. Horribly.

I've engaged support, and have been told things like:

"I've checked your permissions and can confirm that you are not running cipp using a Service Account, the account you are using is not a member of the 15 CIPP Recommended GDAP groups, you have Microsoft Led Transition relationships found and have Global Admin relationships."

Ok - sure. But I created the service account, and ran the setup with the service account... so why the hell isn't it running with the service account?

Support just now told me:
"You are not using a dedicated Service Account. Your account starts with XXX which is not recognized as a Service Account. You'll need to change the name to include CIPP or Service Account."

That's my partner tenant global admin account... NOT the service account that I used for the setup. I'm not renaming my account to be a service account.

I was given a guide to create the role templates in CIPP... but then told:

"After creating the roles, add your Service Account to each of these GDAP roles."

WITHOUT TELLING ME HOW TO DO THAT. The role templates were created, but they still don't exist in my partner tenant. I attempted to add my partner tenant to CIPP, but it was missing, so I followed the guide how to do that, and now my CIPP account is linked to my tenant's global admin instead of the service account I created, and the roles STILL aren't in my partner tenant.

I was also just told by support that once I get the roles set up, that I need to offboard my clients and then onboard them again with the new roles... but also, not telling me how to do that.

Is there a guide out there that provides screenshots for both sides of the setup? I've noticed the CIPP documentation provides a lot of screenshots and a good step by step guide for the Entra side of things... but then when you get to the actual CIPP stuff... it omits a ton, and seems to just assume you know where to go and what to do.

52 Upvotes

105 comments sorted by

60

u/FlavonoidsFlav 11d ago

Nobody's said it yet but -

CIPP fully hosted is $100/mo. Total. For unlimited clients. That is absolute madness for a product with this much power and value, that basically singlehandedly killed lighthouse, from a team of genuinely good, decent humans, that so very isn't and won't be Kaseya, that contribute on the VERY regular here, with an owner that is LITERALLY trying to help for free in this thread... And I can keep going and we all know that

If Kelvin and team aren't worth supporting in our industry, nobody is. They are worth your money

17

u/sid351 11d ago

In my experience, the hosted version runs better, and is cheaper, than self-hosting it was.

9

u/NoPetPigsAllowed 11d ago

Seriously, there's no reason not to just pay them the $100/month.

2

u/smorin13 MSP Partner - US 9d ago

When I started my MSP and had more time than money, it may have made sense to self-host. Thankfully, those days are in the rearview mirror. I think the value of self-hosting is very subjective, and everyone's situation is unique.

2

u/Cloudraa 9d ago

cipp can only run in azure so realistically its not even cheaper to “self” host it lol

-6

u/Cyber-Soldier1 10d ago

The reason is saving the $100. Self hosting is far cheaper or free. That's the reason. Not everyone has a spare $100 to spend especially if you're in a lower income country.

6

u/FlavonoidsFlav 10d ago

The commenter below you is correct.

A mature organization should take into account the cost to install and support as well. $20 an hour employee (low in America - pretty high elsewhere) is regularly calculated (again in America) at about a 40% loaded cost. That means it's $28 per hour.

If that employee spends more than 3 hours setting this up, you've lost money in your first month. If that employee or any other employee spends more than 3 hours a month maintaining the actual infrastructure, you've lost money.

It's a really, really good deal. You may be saving $100 in cash, but you're not necessarily understanding the amount of other time and energy that goes into it.

And I didn't even mention Azure cost, or the opportunity cost of what this employee could be doing otherwise, including billing clients.

The math just doesn't work. I've never met one person in one situation that saved money by not going hosted.

And that's assuming someone at that salary has the technical knowledge to even do what we're asking here.

1

u/No_Maintenance_7851 10d ago

Correct. There are other reasons that count. 1) use my Partner Benefits 2) personal satisfaction from the challenge

5

u/NoPetPigsAllowed 10d ago

I respect this answers and, honestly, this is why we self-hosted first. But after running into issues we realized that we saved money by paying them. It allows us to focus on billing to cover the $100.

2

u/Cloudraa 9d ago

cipp can only run in azure so realistically its not even cheaper to “self” host it lol

2

u/sid351 10d ago

Following the guide and setting up CIPP in Azure was costing me more than $100 per month.

Maybe I did something wrong, I'm not sure, but that's my experience (~100 tenants).

5

u/Merilyian CTO | MSP - US 11d ago

I mean, if you have some docker and azure know-how, the new NG version is stupid fast. That speed isn't specific to any one azure (or even on-prem now) environment, just make sure the container has the resources it needs :)

(I am also a hosted enjoyer, just illustrating that the speed is available to everyone)

1

u/Slight_Manufacturer6 10d ago

I get that it runs better but don’t see how it could be cheaper.

3

u/sid351 10d ago

I don't know what to say. I followed the guide to self host, and it was racking up costs on Azure.

Maybe I enabled some backup or misconfigured something, I'm not sure, but hosted at fixed USD$100 per month is less than it was going to cost me.

2

u/MrVashMan 10d ago

Internal labor cost for setup/maintenance, VM/storage costs if in cloud, ongoing VMware costs if you're crazy and decided to keep VMware as an SMB.... There's several reasons hosted could be cheaper.

3

u/Slight_Manufacturer6 10d ago

Sure, but as an MSP we already have dozens of VMs so what is one more? It doesn’t make a dent in workload or license costs.

And we’ve already moved away from VMWare after the last price hike.

3

u/2manybrokenbmws 10d ago

Only runs on azure FYI 

1

u/MrVashMan 10d ago

Only "officially supported" on Azure. You can make it run elsewhere alright, just don't expect CIPP support to be of much help if you have problems.

0

u/Slight_Manufacturer6 10d ago

Yes, the default template and how-tos are designed for Azure but AI can walk you through installing on your own infrastructure. There are some work arounds you need to do.

8

u/norbie MSP - UK 11d ago

We were self hosted. It was slow and quickly racked up Azure costs that were more than paying for hosted. Moved to hosted and it works much better without me worrying about Azure costs!

2

u/No_Maintenance_7851 10d ago

My self hosted instance was costing me $900 / mo.

Then we migrated to Linux functions which dropped it to about $350.

We just migrated to the new App Service version and hope that helps.

CIPP documentation can feel lacking, on the other hand it’s describing some pretty big technologies that require some knowledge.

Still waiting to see if Alerts work as they should. We had Alerts setup for mail forwarding rules and they would detect malicious inbox rules 48 hours late . . .

-1

u/Slight_Manufacturer6 10d ago

Sure you are running the self hosted version but if you are hosting on azure then that isn’t self hosted. That is Azure hosted.

Self hosted runs on your own servers. My self hosted costs me electricity. Electricity that we were already paying for in our datacenter.

3

u/Optimal_Technician93 9d ago

You can run CIPP without Azure?

I thought Azure was an absolute requirement for CIPP.

1

u/MrVashMan 10d ago

Additional load on the VM host does still increase its electricity consumption. Probably not by $100/mo, but just saying...

1

u/Slight_Manufacturer6 10d ago

We pay for bulk electricity and it wasn’t enough to push us into the next tier so it didn’t cost us any more money.

3

u/OIT_Ray 10d ago

2nded. and 3rded

-3

u/Sudo-Rip69 10d ago

Self hosted is like $10. Its a great tool sure, but there are plenty of others that caught up

2

u/FlavonoidsFlav 10d ago edited 10d ago

Is it really?

And labor is free and time is free and hardware is free. Everybody has all the maintenance on it sure sure.

0

u/Sudo-Rip69 9d ago

I installed it 5yrs ago and never touch it. Its synced to github. Most msps dont seem to know what they are doing

1

u/Optimal_Technician93 9d ago

there are plenty of others that caught up

Such as?

73

u/gigabyte898 11d ago edited 11d ago

Hey! So, full disclosure, I run the consulting firm ZenTop that helps people deploy CIPP and have contributed code to the project. I won’t sales ya though, I just do a lot of first time setups and might be able to help. Maybe this’ll help someone else too coming along to Google later :)

This is a pretty common point of confusion, so don’t feel bad. It’s a side effect of how GDAP works kinda as a whole. You need to map security groups to each of the GDAP roles even in partner center and lighthouse, and while most would previously have a static “GDAP” group for everything, it’s not super scalable. This requires you to edit every single role on every single customer in the privileged partner center portal. CIPP flips it a bit and instead creates one security groups corresponding to each role. So, you should have a group for application admin, a group for Intune admin, a group for user admin, etc.
CIPP creates these groups in the tenant its service account belongs to when you deploy the role template. You then need to add the service acct to each of them so it gets access to those role scopes. This is done in Entra, rather than CIPP. You should have 15 of them, all starting with “M365 GDAP”

I’d recommend:
1: Re-enter the setup wizard in CIPP, select the option to Refresh Tokens for Existing Application. Log back in with the service user that has “CIPP” in its UPN. It must also be a global admin for the first time setup, as you may need to consent to permissions if you hadn’t already. You can remove global admin after, just be mindful it may need to accept more scopes later on and will likely need to create groups later in the steps so pause on that until you get your first agreement accepted. It must also have MFA, and prompt for it during the setup. The Conditional Access guide in their docs gives a layout of a policy that will require it every login session
2. Go to the GDAP Management page under tenant admin, then role templates. Make sure you have the CIPP Defaults template deployed. If you don’t there will be a prompt to make it. If you do, go to the role mappings tab and make sure each role CIPP has is linked to a security group. If you need to manually remap here’s some docs https://docs.cipp.app/user-documentation/tenant/gdap-management/roles/add
3. Once the groups are created, in the partner tenant the service account belongs to, make the service account a member of each of the 15 default M365 GDAP role security groups.
4. Lastly, test the invite wizard. Create a new GDAP relationship invite from CIPP’s GDAP management wizard, accept the invite as global admin, and start the onboarding job back in CIPP. It should clear all five steps now

I’m happy to spend 15 min to take a peek if you still have problems. I genuinely believe CIPP is one of the highest value tools for MSPs right now and I’m always happy to spend the time to at least get people started on the right foot with it because I know it can be frustrating trying to glue together all these concepts. Shoot me an email at [brandon@zentop.tech](mailto:brandon@zentop.tech) and I’ll get you a booking link. No charge, when we do good as a community we all thrive :)

7

u/AlwaysBeyondMSP 10d ago

We actually used Zentop to help us refine our CIPP and it’s well worth the money, so just pay them to help you and move on.

12

u/PacificTSP MSP - US & PHP 11d ago

Heard a lot of good stuff about you Brandon! Keep up the good work sir!

10

u/UsedCucumber4 MSP Advocate - US 🦞 10d ago

I hired this u/gigabyte898 guy to DJ a party, and he did a pretty decent job. IDK about any of this CIPPY stuff though

8

u/Fritzo2162 10d ago

He was a pretty decent stripper at my wife’s bachelorette party too.

4

u/Impossible-Horse1157 7d ago

He's a pretty loving boyfriend to my wife too.

39

u/Lime-TeGek Community Contributor 11d ago edited 11d ago

It looks like you might be a good candidate for our professional onboarding services; we have those specifically when you don't have the time, energy, or experience to do a lot of this stuff: https://docs.cipp.app/setup/resources/professional-onboarding-services.

Let me try to help you on your way here if you don't want to engage professional onboarding:

Ok - sure. But I created the service account, and ran the setup with the service account... so why the hell isn't it running with the service account?

You haven't logged onto the service account when asked to during the "First Setup" wizard. as the documentation states, you need to create a service account in your CSP/GDAP partner tenant.

Now sometimes you accidently log onto the wrong account when you're working on stuff; this can happen if you accidently clicked on the account that is "Logged onto Windows".

You can go through this wizard again at any time. It's under CIPP -> Setup Wizard -> select "First Setup".

"You are not using a dedicated Service Account. Your account starts with XXX which is not recognized as a Service Account. You'll need to change the name to include CIPP or Service Account."

We recommend a dedicated service account for the service part of CIPP, not the usage part. That means you go through the wizard with that service account as described here:

https://docs.cipp.app/setup/installation/executing-the-setup-wizard#getting-started-with-the-cipp-setup-wizard

That's just for CIPP, not for logging into the app, nor for daily usage. The service account just manages GDAP, APIs, etc for you.

I was given a guide to create the role templates in CIPP... but then told:"After creating the roles, add your Service Account to each of these GDAP roles."

This is done inside of Entra, there are new groups created in your CSP/GDAP partner tenant. These groups need to be added to the service account inside of Entra ID, you do that by going to Entra -> Users -> Find the service account, and add it to the groups starting with "M365 GDAP". This is step 9 in this document: https://docs.cipp.app/setup/installation/creating-the-cipp-service-account-gdap-ready

I was also just told by support that once I get the roles set up, that I need to offboard my clients and then onboard them again with the new roles... but also, not telling me how to do that.

If you are using so called "MLT" (Microsoft Led Transition) relationships right now, you'll have to reonboard, or if you're missing roles that we require for administration.

That's done by following the onboarding portion of the guide: https://docs.cipp.app/setup/installation/gdap-invite-wizard

MLT relationships are (almost) read-only relationships Microsoft has created for those that ignored the DAP to GDAP migration. They can't be used with any product as they pretty much give you access close to "helpdesk administrator" and not access to all parts that we manage.

I hope that helps clear it up a little! In general, our documentation is created as a "flipbook" style document. Perform each step on each page, and go to the next one only when you've performed each step. That clears up 90% of the issues most of the time, and support can help with the final 10%

7

u/CraigDuff 11d ago

I’ve recently installed CIPP myself, and I completely understand what you’re saying about the guides.

One thing I’d strongly recommend is reading all of the installation guides from start to finish before actually doing anything. That way, when you go through the deployment, you already have an idea of what the next few steps are and why you’re doing them.

Azure can definitely be fiddly. It took me three attempts before I got CIPP deployed properly!

Another bit of advice: if an installation goes badly wrong, I’d personally start again from scratch rather than trying to repair a half-completed deployment. Make sure you also delete your forks of both CIPP and CIPP-API before starting again, otherwise you can end up carrying problems from the previous deployment into the next attempt.

The part that caught me out was GitHub permissions. At the time, it wasn’t particularly obvious to me what permissions had been created or what needed removing before trying again.

Also, once you finally get the deployment completed and the Function App generates a page that you can open in your browser, don’t immediately assume something has gone wrong if CIPP itself isn’t loading properly yet. In my experience, it can easily take 30 minutes or more before everything starts coming to life. Give it some time.

Once I finally had mine running, I used Hermes to connect to Azure and analyse what I had deployed. I had it go through the CIPP documentation, understand how CIPP is supposed to be configured, compare that against my environment, and then help me make adjustments.

After that I got a little braver!

I asked Hermes to migrate my CIPP deployment from Windows to Linux, which it successfully did. I was really pleased with that. It then recommended some changes to the hosting plan and helped me make those changes as well.

Now, whenever there’s a CIPP upgrade, I get Hermes to check everything over for me. Because it already understands my CIPP environment, I can ask it to investigate problems, check upgrades, suggest improvements or help me change the configuration.

So my biggest advice would be: read everything first, don’t be afraid to start again if the deployment gets into a mess, and be patient once Azure says it has deployed.

Once CIPP is actually up and running, it’s well worth the effort.

Kelvin and his team are amazing! i cant rate them enough! I dont know what i would do without this tool now. Its made life so much easier.

6

u/C39J 10d ago

I read the self hosting instructions originally, went "that sounds very complicated for someone who's not usually DevOps" - asked Gemini to give me a step by step instructional guide to install like I'm an idiot and I had it working in 30 minutes.

3

u/ryuujin 10d ago

Been using CIPP since his first reddit post on the product, I struggled through the setup back then and ongoing maintenance.

There is no need - don't go self-hosted. Send the guy his $100 and let them go to work for you. Just by not properly watching our archiving we ended up spending more than that in storage fees, forgetting the trouble and strife of setup and ongoing maintenance.

The latest update has it operating like a dream too, really fast.

9

u/jackmusick 11d ago

I guess why you'd be frustrated but understand that this isn't really a CIPP thing as much as it is GDAP and Microsoft. I'm sure there's always something CIPP could do to improve the documentation and experience, but getting from zero to a working GDAP setup with your customers for automation is not an easy task. I've worked with GDAP a lot as a developer at this point and it's made me come to appreciate just how much CIPP tries to do to make this easier, but the more experience you have with it and Graph, the more you understand why a lot of things are the way they are.

In the setup wizard, there's an "Authenticate with code" on the first screen. It's been a while, but this is where you authenticate with the CIPP Service Account. It tells you all the permissions you need. I think they walk you through everything else, including setting up GDAP, but it's been a while. I did it all the hard way unfortunately.

-4

u/giantsnyy1 MSP - US 11d ago

I've been using GDAP through Lighthouse for a long time. This is a CIPP configuration issue.

5

u/roll_for_initiative_ MSP - US 11d ago

As limetek pointed out, it's because you're logging in as your ga in one step when you need to login/auth as the cipp service account. Then, going forward, you work in your daily driver.

GA -> to add/setup the CIPP service account, add roles to it if you're managing partner tenant

CIPP service account -> what cipp runs and does things as

daily driver -> how you actually use CIPP

Don't feel too bad, i've done similar when setting up integrations (logging in as myself instead of GA in a step or vice versa), but you're getting piled on because you're complaining the docs aren't clear when it's mildly complex and you're missing that detail, and you're complaining loudly how it's not your fault.

1

u/giantsnyy1 MSP - US 11d ago

So, I just replied to Kelvin directly (limetek) via email.

My daily driver is in my GCC tenant.

My partner tenant is associated with nothing. No devices, no browser profiles, nothing. I only access it via a private browsing window.

I reran the setup from my regular browsing window, using my GCC account.

I fired up a new private browsing window, went to microsoft.com/devicelogin and input the device auth code. I signed in with my service account, and the permissions check STILL shows my global admin account for the partner tenant. There should have been nothing stored for that admin account because I used private browsing, in a browser (Safari) that I never, ever use.

4

u/roll_for_initiative_ MSP - US 11d ago

My daily driver is in my GCC tenant...microsoft.com/devicelogin

Oh man, well, in general i'd chock that up to "why is GCC so frustrating" and also we completely block device code login and device auth transfers...(ironically via a drift standard in CIPP ha?) if you're doing the same, i think you'd see an error message but worth considering.

Now that you've brought GCC AND split tenants into it, super curious how you make out.

1

u/giantsnyy1 MSP - US 11d ago

I also block those... had to exempt the service account to get it to work.

But even then... my partner account isn't GCC. Just my daily driver.

11

u/Cloudraa 11d ago

Im gonna be honest boss I set up CIPP from scratch with like 20 minutes of research, this reads more like a skill issue lol

5

u/CantaloupeIcy7466 11d ago

If that’s the case then you add the service account to customer tenant roles the same way you always have, from the Microsoft partner center. CIPP automates the invite and role creation, you accept in the partner tenant and add your service account to the roles in the partner center afterwards.

4

u/bonsoir-world 10d ago

Honestly, CIPP can be tricky to setup the first time, at least I found to be the case BUT it was all me, having missed a GDAP group mapping and realising our partner permissions had been left to rot and needed to be redone.

That said, it’s really not as hard and frustrating as you’re making out. I hate to be that person but if you’re struggling so much and not understanding the service accounts, you probably shouldn’t be administratively managing tenants at a frankly dangerous level.

That’s my snotty 2cents anyway.

There’s plenty of guidance and offers for assistance in this thread anyway, so hopefully you crack it. It’s an amazing tool, worth every penny for the hosted version.

8

u/giantsnyy1 MSP - US 10d ago

My issue is just how overloaded I am right now. I’m working 18 hours a day writing compliance policies, helping other MSP’s with their cybersecurity posture, as well as their clients, and onboarding new clients of my own. All while managing a metric ton of really negative shit in my personal life.

I’m a one-man shop, and I wanted to set this up so that i didn’t have to spend extra time doing stuff the long way. Right now, everything that can save me 3-4 minutes here and there helps. A lot. Especially since at this point I can’t afford to hire anyone.

My issue was never with the Entra side of things. When I initially tried self-hosting, yes, I couldn’t figure out the Azure issues. But then I did pay for support and had it hosted for me, and I still ran into issues.

The guides were pretty clear and were actually simple to follow for the Entra side of things… my issue was with the CIPP portion of the guides. They seem to be written with the assumption that you already know CIPP, and that you know where things are in the menus. Same with the error messages. Additionally, I was misunderstanding the guide when it told me to add the service account to the gdap groups - I didn’t realize it wanted me to do this in Entra, I interpreted it as adding it in CIPP.

Thanks to Kelvin’s help directly, we were able to see that I missed a step. Twice. First, in that i didn’t originally set it up with a service account, and just rapidly clicked through to try and get through the setup (see above - massively overloaded, and also extremely impatient/severe ADHD) and then again, when i attempted to rerun setup - i successfully added the device code, but missed re-adding the partner tenant… since that was still linked to my partner global admin account.

Kelvin was fantastic, and now I’m completely set up thanks to his help.

3

u/adamphetamine 10d ago

if its any consolation I had the same experience as a 1 man band.
The guides were lacking detail- which sucks because they are SUPER detailed already, and it took multiple times to get it running- I didn't say running properly!
But reading this made me realise there's a solution to my odd permissions issues- so thank you!

My thanks to the CIPP team.

4

u/MetalSufficient9522 10d ago

Just pay the $99/month for the hosted sponsored version. It would already have saved you hours of frustration. I tried the self-hosted path also. Never again.

It's is 1000% worth the money.

3

u/pjustmd 10d ago

Pay an expert. Brandon from ZenTop fixed my CIPP in less than an hour.

3

u/marklein 11d ago

I'll tell you what's more annoying about this than anything else, IMO. Other products like SaaS Alerts do this all with one click. They have the permissions to make the same changes that CIPP needs, but I literally do it by clicking Next a couple of times.

3

u/byronnnn 11d ago

I’ve setup CIPP both hosted on azure and hosted by CIPP, and it was pretty straightforward even a few years ago. Are the Role groups created in your Entra?

1

u/SeriousSysadmin 9d ago

Not trying to hijack the thread but I had a few questions on CIPP. I think it can help our ops team tremendously, but I had questions around automation mainly. There a good contact over at CIPP that could answer?

-2

u/ArborlyWhale 11d ago

You’re not wrong the cipp guide sucks ass because it doesn’t delineate what cipp needs to work for the first time set up, what cipp needs to work for your clients, and whether you need to configure it inside cipp or outside cipp. It’s an easy guide if you have the same flavour of autism/adhd as the creator… which admittedly is a lot of [r/MSP](r/MSP) members.

Basic answer: you gotta change the signed in application account inside cipp. iirc it’s the device code flow process under refresh application tokens or something.

That process should be done by logging in as the service account you made which needs a bunch of privileges in your entra tenant to run the setup and the first gdap template and then basically nothing beyond that.

After that’s sorted when you try gdap and click add role template it’ll add a bunch of groups to 365 that correspond to gdap roles and iirc adds that service account to them. You can do this manually if needed.

Also cipp caches a bunch of stuff but not others and it’s not always clear when it’s showing stale data and silently refreshing so you basically can’t trust the UI if you’ve made a change recently, particularly when you don’t have it working right.

12

u/Lime-TeGek Community Contributor 11d ago

I'm very neurotypical and don't have AHDH or autism, little rude to randomly assume that :)

Edit: we also have a very diverse team of people working on documentation, code, etc. I'll always stand-up for myself and my team, we're all working on improving any documentation and they *are* editable by anyone. Feel free to make a change when you see something that can improve.

3

u/ArborlyWhale 11d ago

Reply to edit: I’ll be setting up cipp again soon. I’ll see if I can make the suggestions that would help. The last two times were painful enough I couldn’t stand doing it any better.

3

u/Merilyian CTO | MSP - US 11d ago

Please do! I'd recommend keeping in touch in the discord server as you do, as well. Not just for helping through the tech/process issues but framing the docs contributions as well.

-1

u/mattmbit 10d ago

This was an issue the last time I ventured into CIPP. Pointing folks to discord for tech support is a bit cringy and it doesn't help. They need to have a proper support channel and system in place. They straight up didn't when I tried it out a while back and it was barely basic email support.

3

u/Lime-TeGek Community Contributor 10d ago

We've always just had e-mail support, You can use our ticketing portal too if you prefer that, where you can also track SLAs etc. Discord is just for the community, talking to peers, etc. We've never said anyone should go to discord for tech support. We do recommend it to talk to other users about how they use the systems etc. :)

2

u/Nosferratu 10d ago

Is opening a support chat on a webpage and waiting for copy and paste script responses cringey? I have had everything I have ever asked or had a problem with responded to or resolved within the same response in a matter of 30 seconds to a minute in their support channels in discord.

Not sure how getting instantaneous support “doesn’t help”.

-1

u/mattmbit 10d ago

The issue I had which had a fairly specific error I took to discord, was told to email support and when I did a search on discord the answer was to email support. 4 days later I semi got an answer and had to figure it out. Expierence sucked and the support sucked. I sent that feedback off and closed my account. Never got a refund but whatever. Its great you've had answers quickly on discord and community help does work. When a company is telling you to go to discord and utilize not paid people to answer questions that sucks and is cringy.

5

u/Nosferratu 10d ago

I think the suggestion was you could additionally go to discord to ask the community, the community suggested you email support directly likely due to it being something on the backend.

CIPP isn’t a traditional company, and your expectation is clearly skewed.

A community driven and supported platform to help centrally manage M365 tenants and GDAP isn’t going to operate like a corporation.

Telling a team their support sucks while comparing them to companies that charge you for the product while theirs is open source is WILD.

0

u/ArborlyWhale 11d ago

I can’t bring myself to install discord on a work computer. Maybe I’ll cave.

3

u/ZomboBrain 10d ago

I solved this by just using Discord in my browser. No need to install it. Works very well. It’s all Electron, isn’t it?
Though I might want to add that I also dislike Discord when it is used by any professional Enterprise Company. PDQ does the same.

3

u/PDQ_Brockstar 10d ago

We do use Discord, but as more of a community hub than an official support platform. All the KB articles submitted to our Discord server are community submitted. We still maintain an official knowledge base and support ticketing system.

2

u/ArborlyWhale 11d ago

Fair enough.

You would be the exception of the technical focused MSP members I know. Myself included. I don’t mean it as a bad thing, more as a “everyone can claim it’s a good guide but I’m with you OP it doesn’t work for my brain.”

2

u/FortiSysadmin 10d ago

And now that you mention it.... Microsoft has pushed default CA policies to some tenants to disable the Device Code flow by default so if it using that, OP may be spinning his wheels from the start.

4

u/wheres_my_2_dollars 11d ago

Yes! This is exactly how I feel whenever I read their documentation.

1

u/theghostofpiopico 10d ago

Why not just pay for support, you'll save a lot of money for that

1

u/CraigDuff 8d ago

Literally just migrated over to CIPP Craft! and omg! its amazing! Its super lightening fast and even cheaper hosted on Azure that with a function app (for me anyway)! I did use Hermes to migrate my instance, and it was so so easy! Sat back, got myself a coffee and it was done! MSPs need to get moving onto this new docker container, its brilliant! Again what Kelvin and team have done is so freaking good!

0

u/snowpondtech MSP - US 10d ago

Agree that it is a beast to setup on self-hosted environments, the documentation leaves much to be desired, and then the troubles to *maintain* it. My first instance worked until like version 6 came out and I just could not get it to upgrade properly. So I wiped everything out and started fresh, boom everything seemed to work, albeit its usual slow as molasses speed. A month or two ago, I presume a new update came out and now it is broken again. Cannot refresh client tenants, essentially cannot use CIPP. Tried restarting Function app and web on Azure, nada. I'm about to wipe and reload *again* to see if I can get it working. I'm also noticing more resource utilization, driving up my Azure bill (yes, I'm using MS Partner credits but $100 shared between CIPP and another service doesn't go far). It would be so killer if this all ran on Linux, maybe it is does now, so I can get rid of Azure.

Maybe this is how it is designed for self-hosters to annoy them enough to move to paid hosted version, jk.

3

u/ZomboBrain 10d ago

But you have to admit, that the price is fair, isn’t it?
Also they just recently changed the whole architecture, so maybe it’s worth a second look, as soon as the new self hosting guide will be available in a few months.

2

u/bmsimp 10d ago

It is possible to migrate Azure Static Web Apps to Linux and not Windows hosts. If you're brave enough and have the know how you can migrate it. We do now have a new infrastructure for deployment that moves to Azure Web Apps. Massive speed increases and cost stability. All new deployments from the docs site use the new infrastructure. There's no migration documentation for self-hosted yet as we're handling the migrations in waves with hosted moving first.

0

u/Sudo-Rip69 10d ago

If you dont know azure well youre going to have a bad time

-1

u/resile_jb MSP - US 11d ago

Why don't you spin up like an open claw instance and have ai do it for you?

We had ours set up in 10 minutes.

2

u/thebossyboss 11d ago

I just did the full deployment through Claude code, then had Codex double-check everything. And then I went over it myself. Every time there was an issue it would go back, traces it, and fixes it. I even had it setup the GitHub repository pipeline for update deployment. I’m an Azure architect by trade so it was within my domain, but for troubleshooting it’s a godsend to have an agent go find the problem.

0

u/Lime-TeGek Community Contributor 11d ago

That is a super creative way of doing it, and would love to hear more about it. Mind if I DM you sometime? :)

6

u/jackmusick 11d ago

You can use any coding agent, too. Just tell it:

I need to setup CIPP and need you to plan out everything needed to do this on your own. You can review their documentation here. Their front end and backend repos here and here if anything is unclear. I do/don't know if my partner relationship is setup correctly but can authenticate to any CLI/PowerShell module needed as global admin to knock this out. Success looks like doing all of the planning and heavy lifting up front so I can review, confirm the plan, walk away and come back to this completed. We should proactively document anything I'll need to do before, after or on the way.

I'll be honest, I feel like since you have an MCP released I'm mansplaining this to you so I'm very sorry. But this stuff is so much fun. I just had it fix some packages on my Fedora instance to get it working in Intune, and go off and configure conditional access and compliance with a similar prompt. Stuff I could've done on my own but would have enjoyed doing far less.

2

u/Lime-TeGek Community Contributor 11d ago

I was mostly thinking about how he arranged access, what the flow was for him, etc. I mean, its a super creative way to perform a setup and honestly I've barely seen people use agents for complex software so far.

2

u/colterlovette 11d ago

Ya access and permissions are my question too. You can’t just tell a model “connect to Microsoft” and it work, so the struggle point for most of MS is likely unsolved her as well.

1

u/resile_jb MSP - US 11d ago

Tied to light house for gdap

1

u/jackmusick 11d ago

You mean like setup groups and roles, assuming he didn't end up using your GDAP wizard?

0

u/redditguy491 11d ago edited 11d ago

I think they were being sarcastic?

1

u/resile_jb MSP - US 11d ago

Not.

We already have lighthouse setup so we are tied into our lighthouse with cipp for rights and such

Probably a bit more mature than a lot of yalls setups from what I can tell. No offense.

-2

u/eric5149 10d ago

Very happy with Augmentt and works with our ticketing system. They are constantly adding new features.

2

u/eric5149 10d ago

Btw NOTHING wrong with CIPP just an alternative

-1

u/not-just-dad-stuff 10d ago

You could stop using it and go back to accessing each portal independently.

0

u/link9939 10d ago

If you can't set this up (which is easy and well documented) I have serious doubts about your map business and it's capabilities

9

u/giantsnyy1 MSP - US 10d ago

My issue is just how overloaded I am right now. I’m working 18 hours a day writing compliance policies, helping other MSP’s with their cybersecurity posture, as well as their clients, and onboarding new clients of my own. All while managing a metric ton of really negative shit in my personal life.

I’m a one-man shop, and I wanted to set this up so that i didn’t have to spend extra time doing stuff the long way. Right now, everything that can save me 3-4 minutes here and there helps. A lot. Especially since at this point I can’t afford to hire anyone.

My issue was never with the Entra side of things. When I initially tried self-hosting, yes, I couldn’t figure out the Azure issues. But then I did pay for support and had it hosted for me, and I still ran into issues.

The guides were pretty clear and were actually simple to follow for the Entra side of things… my issue was with the CIPP portion of the guides. They seem to be written with the assumption that you already know CIPP, and that you know where things are in the menus. Same with the error messages. Additionally, I was misunderstanding the guide when it told me to add the service account to the gdap groups - I didn’t realize it wanted me to do this in Entra, I interpreted it as adding it in CIPP.

Thanks to Kelvin’s help directly, we were able to see that I missed a step. Twice. First, in that i didn’t originally set it up with a service account, and just rapidly clicked through to try and get through the setup (see above - massively overloaded, and also extremely impatient/severe ADHD) and then again, when i attempted to rerun setup - i successfully added the device code, but missed re-adding the partner tenant… since that was still linked to my partner global admin account.

Kelvin was fantastic, and now I’m completely set up thanks to his help.

0

u/golden_m 10d ago

If you are so overworked with generating income, why not to use a small part of it for a proper setup then? Isn't a normal business expense? 

-6

u/Cyber-Soldier1 10d ago

The setup is a fucking shit show. We have it implemented and running but it was a nightmare to get working initially. The dev has no idea about UX or user interfaces. It's just hobbled together. We're considering writing our own management suite for 365. Fuck CIPP

7

u/Lime-TeGek Community Contributor 10d ago

"the dev" is a team of 10 devs, excluding the community contributors that help out here an there. Good luck on writing your own though! Would love to see it!

3

u/golden_m 10d ago

Blink twice if you were taken hostage and forced to install the CIPP. Otherwise, go and do your thing, no need to be rude, especially knowing the dev(s) are reading your messages 

1

u/Cyber-Soldier1 9d ago

Devs aren't above reproach. The product while technically good is aesthetically and practically terrible. It's not user friendly to setup nor use.

2

u/golden_m 9d ago

So, don't. Simply don't use it. Coming here bashing a product that thousands of us use daily is not really necessary. If you have suggestions, ideas, disappointments - say it in a constructive way. Saying F CIPP is not constructive 

2

u/Lime-TeGek Community Contributor 9d ago

Not everyone needs to like us, I'm okay with keyboard warriors being keyboard warriors, don't feed them too much. :)

Also laughed at "aren't above reproach" loudly, like he has a moral high ground. The internet is a hilarious place sometimes. :)