Application Settings
View and amend the settings for your CIPP instance.
The General tab of the application settings brings together the instance-wide controls for your CIPP deployment: version information, password generation, DNS resolution, caching, backups, retention periods, and JIT admin limits. Each card operates independently and saves on its own, so there is no single submit action for the page.
Version
Shows the versions currently running, with the frontend and backend reported separately.
Frontend
The version of the CIPP web interface currently deployed.
Backend
The version of the CIPP API currently deployed.
Each version displays a tick when it is current, or a warning icon together with the newer version number when an update is available. Selecting Check For Updates re-queries both, which is worth doing after an upgrade rather than relying on a cached result.
The frontend and backend are versioned and deployed separately, so it is normal to see one flagged as out of date while the other is current during an upgrade. Both should match once the upgrade completes.
Password Style
Shows the password generation settings currently in effect, displayed as a chip summarising the type and length.
Classic
A randomised string of letters, numbers and symbols, sized by character count. The default is 14 characters.
Passphrase
Several random words joined by a separator, sized by word count. The default is 4 words. Passphrases are usually easier for end users to read out and retype.
Selecting Configure opens the Password Configuration page, where the type, length, character sets and separator are set.
If the card shows an error instead of the current setting, CIPP could not read the stored configuration. Open the configuration page and save the settings again to restore it.
DNS Resolver
Selects which public resolver CIPP uses, with Google and Cloudflare available. The active choice is shown as the filled button.
This resolver is used by the Domains Analyser and the Individual Domain Check only. It has no effect on any other DNS resolution CIPP performs, so changing it will not alter behaviour elsewhere in the application.
Cache
Clears the cached data CIPP holds, including the tenant list and analyser results.
Selecting Clear Cache opens a confirmation dialog with one option.
Only Clear the Tenant Cache
Limits the operation to the tenant cache, leaving other cached data intact. Leave this off to clear everything.
A full cache clear removes every cache table, including audit log entries that are queued but not yet processed. Those entries are lost, not reprocessed. Performance is also degraded until the caches rebuild, and personal preferences such as the selected theme are reset. Only clear the cache when support asks you to.
Backup
Covers the system configuration backups for your CIPP instance. Selecting Manage Backups opens the CIPP Backup page, where backups are taken, restored, and put on an automated daily schedule.
System backups exclude authentication information and extension configuration, so a restored instance still needs its SAM credentials and integration settings entered again.
Backup Retention
Sets how long backup files are kept before automatic deletion. The value applies to both CIPP system backups and tenant backups.
Days
The retention period in days. The minimum is 7 and the default is 30. Values below 7 are rejected.
Enter the number of days and select Save. Cleanup runs daily at 2:00 AM.
Log Retention
Sets how long CIPP log entries are kept before automatic deletion.
Days
The retention period in days. The minimum is 7, the maximum is 365, and the default is 90. Values outside that range are rejected.
Enter the number of days and select Save.
JIT Admin Settings
Caps how long a Just-In-Time admin account created through CIPP may remain active, which stops technicians from provisioning long-lived privileged accounts.
Maximum Duration (ISO 8601)
The longest duration a JIT admin account may be granted. Presets range from 1 hour to 30 days, and a custom ISO 8601 duration such as PT6H or P21D can be typed directly. Leave empty for no limit.
Select Save Settings to apply. The limit applies globally across all tenants, and any attempt to create a JIT admin account exceeding it is rejected.
Custom values must be valid ISO 8601 durations, so use forms such as PT1H, P1D or P28D. An invalid value prevents the card from saving.
Other Settings Tabs
The remaining application settings are grouped on their own tabs.
Customises the logo and brand colour applied to generated reports and documents.
Reviews and repairs the permissions held by the CIPP service principal.
Manages which tenants CIPP sees, including exclusions and refresh.
Provides direct links into the underlying Azure resources for your instance.
Configures where CIPP sends alerts, including email and webhook destinations.
Sets up partner webhooks so new tenants are onboarded automatically.
Manages licence exclusions used across reporting and alerting.
Enables and disables optional CIPP features.
Configures log forwarding to an external SIEM.
Feature Requests/Ideas
We value your feedback and ideas. Please raise any feature requests on GitHub.
Last updated
Was this helpful?

