Connect one source, then verify one client
- Open Integrations and add the intended product. Give the connection a name that identifies its account, controller or region.
- Enter the fields for that product below. Obtain credentials through the vendor administrator responsible for the intended account; a field list does not grant API entitlement or permissions.
- Review the saved connection outcome, then use Clients & sites to discover and explicitly assign the correct source records. Compare identifiers as well as names.
- For evidence sources, use Sync now, inspect Sync history, and check one client’s source and observation time. Directory sources instead use Import clients and Refresh client records.
- Compare the available observations with the control’s requirements before running checks.
Choose your product
Mimecast
Mimecast
Use an API 2.0 application in the intended account. Protection/features describe the email-security service; they do not prove SPF, DKIM or DMARC are correctly configured.Map: One Mimecast accountCode per connection.
Available observations: Mail protection provider, Mail protection feature.
Proofpoint Essentials
Proofpoint Essentials
Use an Essentials administrator credential, the partner primary domain and correct regional shard. Domains are mapping identifiers here; review links after a primary-domain change. This is not the enterprise Proofpoint product API.Map: Each organization primary domain. A primary-domain change requires reviewing the mapping.
Available observations: Mail protection provider, Mail protection feature.
Pax8
Pax8
The current Alignr form exposes Client ID and Client secret, but Pax8 requires third-party platforms to use delegated OAuth and says partner API credentials must not be shared with them. Do not enter a partner credential to work around this requirement. Confirm an approved delegated integration is available with Alignr support before connecting. The current connector’s licence, purchased-seat and renewal observations describe its implementation; they do not establish that production onboarding is ready.Map: Each Pax8 company UUID.
Available observations: Licence or entitlement, Purchased seats, Next licence renewal.Use the vendor’s current instructions for credential preparation: Pax8 authentication.
Microsoft Partner Center
Microsoft Partner Center
Use the Partner Center application credentials for customer subscriptions. This connector does not grant delegated Microsoft Graph access or report each user’s assigned licence. Use Microsoft client connections for identity assessments.Map: Each customer Microsoft tenant GUID.
Available observations: Licence or entitlement, Purchased seats, Next licence renewal.
Ingram Micro
Ingram Micro
Use the SimpleAPI credentials, subscription key, actual API URL and marketplace code from your account. This connector reports licence presence and renewal; it does not supply purchased or assigned seat counts.Map: Each Ingram customer platform ID.
Available observations: Licence or entitlement, Next licence renewal.
CloudBlue Connect
CloudBlue Connect
Use a Connect API token for the customer accounts to inspect. This connector reports purchased reservation quantities, not assigned-user seats or a guessed renewal date.Map: Each customer tier-account ID (TA-…), excluding reseller tier accounts.
Available observations: Licence or entitlement, Purchased seats.