MSP Auto Onboarding

Summary

The INKY auto-onboarding was designed and created with MSPs in mind to provide an easy way to deploy INKY to the MSP’s customers. You will find this to be an easy 3 stage process for your convenience. Starting with License Registration followed by License Redemption and then Tenant Installation. You should be able to complete start to finish within 15 minutes!

Note: This deployment is for O365 customers only!

Please reach out to your INKY account team to have your account setup to support this functionality.

Requirements:

  • The MSP team needs to be elevated to a PARTNER ACCOUNT.

  • The admin performing the deployment must have INKY SUPER ADMIN access for the MSP – ALL TEAMS account

  • The admin performing the deployment must have Global Admin rights in O365

  • The new account can only be setup on the INKY US grid at this time.

STAGE 1: License Registration

Step 1: Open a browser and go to INKY Partner Center

Step 2: Log in using your INKY Admin single-sign-on authentication

Step 3: License Registration is done by clicking Generate License

image-20240916-143156.png
  • Pick the products that you are installing in addition to INKY Phish Fence

  • Domain: (required) Enter the primary domain of the M365 tenant as domain.com

    • All subdomains, secondary domains, and m365 domains will be populated in INKY during the installation

  • Team Label: (required) Enter the Team Label that you would like to see as a child team

Step 4: Generate License Key

image-20240916-143551.png
Generate License Key will move from grayed to pink when all info is entered

You will then be provided with a License Key and URL

STAGE 2: License Redemption

Step 1: Take the copied link provided and paste into a new private/incognito browser

Click Continue

Step 2: You will now log into the CUSTOMER’S O365 tenant with your Global Admin account

Click Sign in

Step 3: Accept the O365 prompt for Admin consent for INKY to configure read access for Directory Sync in the customer’s O365 tenant

Step 4: Consent to Remediation API Access via the Graph API:

Step 5: Consent to Exchange PowerShell Permissions:

STAGE 3: Tenant Installation

Step 1: Click the ‘start’ button to begin the install

Step 2: Review results of INKY install

Once ready, click the Continue

 Step 3: User Notification is always key to avoid deployment confusion when end users see changes in their day-to-day operations. This next screen provides you with options to download documentation to help you make the announcement to your organization of the changes to come once you begin to add more members to the IPW Group in O365.

The ‘start processing messages is set to 30 minutes by default. This will provide ample time to set the tenant into silent mode after installation. Instructions are below for post-installation tasks.

You can now click ‘continue’ to proceed.

 Step 4: INKY will give a line-by-line progress of the installation in this window:

Congratulations, Installation is now completed successfully!

Step 5: Post-installation you will want to place the tenant into Silent Mode. You will do that by clicking Visit Dashboard at the end of the installation.

In the Dashboard go to Admin Center → Markup and opt the tenant into Silent Mode:

Optional (recommended): Add the INKY macro-SPF record to the clients' DNS:

exists:%{i}._spf.inkyphishfence.com

This record will authenticate all INKY transactions between M365 and the INKY Security Cloud

Again, for any assistance please reach out to your account team or open a support ticket by sending an email to Support@Inky.com.