CIPP Standards & BPA

SkillMonitoring & ops

CIPP's tenant-baseline enforcement model: the Report/Alert/Remediate standards modes and how to roll them out, on-demand standards evaluation, Best Practice Analyser reports, and SPF/DKIM/DMARC domain health results with their remediation actions.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the CIPP Standards & BPA skill

What this skill tells your AI

The instructions your AI receives, as published by wyre-ai/msp-claude-plugins in msp-claude-plugins/cipp/cipp/skills/standards/SKILL.md and read by ahel’s review.

Standards are CIPP's mechanism for declaring "this is what every tenant we manage should look like" and continuously enforcing it. The Best Practice Analyser (BPA) is the read side — it shows you where current tenant state diverges from CIPP's recommended baseline. Domain health is a complementary check focused on email authentication.

Anti-triggers

  • Drift against an Inforcer baseline — Inforcer and CIPP both say "baseline", "drift", and "secure score" but measure different things against different templates; a tenant can be CIPP-compliant and Inforcer-drifted at once. Use inforcer-baseline-alignment.
  • Inspecting Conditional Access policies — CA policies are not CIPP standards and do not appear in BPA output; use cipp-security.
  • Triaging what an Alert-mode standard actually raised — the queue those alerts land in is cipp-alerts.
  • Drift measured across more than the CIPP-managed estate — the cross-vendor method for comparing tenants to a baseline and deciding what to remediate is compliance-pack-standards-drift; this skill is the CIPP standards engine it reads.

Tools

cipp_list_standards

cipp_list_standards(tenantFilter='contoso.onmicrosoft.com')

Returns the list of standards configured for the tenant: which standards are enabled, what action each takes (Report, Alert, Remediate), and current compliance status. Use tenantFilter='allTenants' for a portfolio-wide view.

cipp_run_standards_check

cipp_run_standards_check(tenantFilter='contoso.onmicrosoft.com')

Triggers an on-demand standards evaluation. CIPP runs this on a schedule, but force a fresh run after deploying a new standard or remediating a finding to confirm the fix took.

cipp_list_bpa

cipp_list_bpa(tenantFilter='contoso.onmicrosoft.com')

Returns the latest Best Practice Analyser report — every CIPP-recommended check with Pass/Fail/Warn status across categories (Security, Identity, Mail, SharePoint, Teams, Intune). The most useful single call for tenant health.

cipp_list_domain_health

cipp_list_domain_health(tenantFilter='contoso.onmicrosoft.com')

Per-domain SPF, DKIM, DMARC, MX, and DNSSEC results. Run for any tenant where mail authentication is suspect or before/after migrating mail.

Standards model

A "standard" in CIPP has three modes:

ModeBehavior
ReportCheck only; show in BPA
AlertCheck + raise alert when out of compliance
RemediateCheck + auto-fix when out of compliance

The progression for an MSP rolling out a new baseline is typically ReportAlertRemediate over weeks, with the longest dwell in Alert to validate that auto-remediation will be safe.

Workflow patterns

Tenant health snapshot

bpa = cipp_list_bpa(tenantFilter)
fails = [check for check in bpa if check['status'] == 'Fail']
domain = cipp_list_domain_health(tenantFilter)
broken_dmarc = [d for d in domain if d.get('dmarcPass') is not True]

A tenant with > 5 BPA failures or any broken DMARC needs a remediation plan, not just a report.

Standards drift detection

all_tenants_standards = cipp_list_standards(tenantFilter='allTenants')

Compare the standards each tenant has enabled against the MSP's master baseline list. Tenants missing a baseline standard usually mean the standard was deployed after the tenant onboarded and never backfilled.

Pre-change validation

Before you change a tenant's identity or mail config:

  1. cipp_list_bpa — capture current state
  2. Make the change
  3. cipp_run_standards_check to force a fresh evaluation
  4. cipp_list_bpa again — diff against pre-change capture

Domain health interpretation

ResultMeaningAction
SPF: missingNo SPF record at allAdd v=spf1 include:spf.protection.outlook.com -all
SPF: too many lookupsRecord exceeds 10-DNS-lookup limitFlatten or consolidate include: directives
DKIM: not configuredDefault DKIM signing disabledEnable in Defender / Exchange Admin
DMARC: p=noneReporting only, no enforcementMove to p=quarantine after monitoring
DMARC: missingNo DMARC recordAdd v=DMARC1; p=none; rua=mailto:dmarc@... to start

Caveats

  • BPA results reflect the last scheduled run; run cipp_run_standards_check for fresh data.
  • Standards Remediate mode can change tenant configuration without an additional confirmation — scope carefully and stage Alert first.
  • Domain health doesn't catch every email-auth issue (it doesn't validate ARC, BIMI, MTA-STS) — for full mail forensics, supplement with external tools.

Signals

GitHub stars
45
Forks
24
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
cipp-standards
Source
github.com/wyre-ai/msp-claude-plugins