> ## Documentation Index
> Fetch the complete documentation index at: https://docs.raidenhq.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get started as an MSSP partner

> Create your MSSP management account, add customer tenants, and connect their Microsoft 365 environments. Complete setup takes about 10 minutes.

This guide walks you through creating your MSSP management account, adding customer tenants, and connecting their Microsoft 365 environments. The entire setup takes around 10 minutes.

<Info>
  **Early access** — You are using an early access build of RAIDEN. Features are fully functional but some UI polish is still being completed. If you hit anything unexpected, contact your RAIDEN onboarding contact directly.
</Info>

## Before you start

You will need:

* **RAIDEN MSSP partner code** — provided during your partner onboarding. Contact [support@raidenhq.com](mailto:support@raidenhq.com) to apply
* **Customer information** — organisation names and billing email addresses for each customer you want to add
* **Microsoft 365 Global Admin access** (per customer) — needed when connecting each customer's M365 tenant. This can be done by the customer themselves or by you on their behalf

***

## Setup steps

<Steps>
  <Step title="Create your MSSP account">
    1. Navigate to [https://account.raidenhq.com/signup/mssp](https://account.raidenhq.com/signup/mssp)
    2. Fill in the MSSP signup form:
       * **Full name** — Your name
       * **Business email** — Your work email (becomes your MSSP admin login)
       * **Password** — Minimum 8 characters
       * **MSSP organisation name** — Your MSP's company name. RAIDEN uses this to create your management subdomain (e.g. `secureco.raidenhq.com`)
       * **MSSP partner code** — The code provided to you
    3. Click **Create MSSP account**

    You will be automatically redirected to the MSSP Onboarding Wizard.
  </Step>

  <Step title="Add your customers (Onboarding Wizard)">
    The onboarding wizard is a three-step flow that helps you set up your MSSP account and add your first customers. You can skip it at any time using the "Skip to Dashboard" button.

    **Step 2a — Welcome**

    A quick orientation explaining what RAIDEN MSSP provides:

    * Centralised dashboard to monitor all customer tenants
    * One-click impersonation to investigate threats in any customer's environment
    * Health summary across your entire customer portfolio

    Click **Next: Add Customers** to continue.

    **Step 2b — Add Customers**

    There are two ways to add customers:

    **Option A — Inline Form**

    Add customers one at a time using the built-in form:

    1. Enter the **Organisation name** (required), **Billing email** (required), and optional **Alias** (a short internal nickname)
    2. Click the **+** button to add another row
    3. Repeat for each customer
    4. Click **Submit & Review** when ready

    **Option B — CSV Import**

    For bulk onboarding, click **Switch to CSV mode** and paste a list in this format:

    ```
    organization_name,email,alias
    Acme Corp,admin@acme.com,acme
    Contoso Ltd,security@contoso.com,contoso
    Fabrikam Inc,it@fabrikam.com,
    ```

    Rules:

    * Comma-separated or tab-separated
    * Header row is optional (lines starting with "organization" are skipped)
    * Alias column is optional
    * Up to 50 customers per batch

    Click **Submit & Review** when ready. RAIDEN creates all customer tenants in a single batch operation.

    **Step 2c — Review & Launch**

    After submission you will see a results summary:

    * **Successfully created** — Each customer with a "Copy Invite Link" button. Share this link with your customer so they can sign up and connect their M365 tenant.
    * **Failed** — Any items that could not be created (e.g. duplicate organisation name). You can fix these later from the MSSP dashboard.

    Click **Go to Dashboard** to access your MSSP portfolio view.
  </Step>

  <Step title="Customer M365 connection">
    Each customer needs to connect their Microsoft 365 environment. There are two ways to do this:

    **Option A — Customer self-service**

    Share the invite link from the Review step. The customer visits the link, creates their account, and follows the standard M365 connection flow (see [Getting Started — Quick start](/getting-started)).

    **Option B — MSSP connects on behalf of the customer**

    If you have Global Admin credentials for the customer's M365 tenant:

    1. From the MSSP dashboard, click **Manage** on the customer row
    2. Use the **Impersonate** button to enter the customer's RAIDEN environment
    3. Navigate to the Microsoft 365 Connection page and follow the connection steps

    <Note>
      Impersonation sessions last 4 hours and are rate-limited to 60 per hour. All impersonation activity is logged to the audit trail.
    </Note>

    <Warning>
      **You may see an "Unverified publisher" warning from Microsoft.** This is expected and safe — RAIDEN is in early access and Microsoft publisher verification is in progress. Click **Accept** to continue.
    </Warning>
  </Step>

  <Step title="Manage your portfolio">
    Your MSSP dashboard at `yourslug.raidenhq.com/mssp` provides:

    | Feature                     | Description                                                                                                                |
    | --------------------------- | -------------------------------------------------------------------------------------------------------------------------- |
    | **Portfolio risk overview** | See all customers at a glance with their connection status, finding counts by severity, and overall health score           |
    | **Health summary**          | Aggregated view of critical, high, medium, and low findings across your entire customer base                               |
    | **One-click impersonation** | Click "Manage" on any customer to enter their RAIDEN environment and investigate threats, review cases, or manage settings |
    | **Add more customers**      | Use the "Add Customer" button to onboard additional tenants at any time — individually or in bulk                          |
  </Step>

  <Step title="What happens after connection">
    Once a customer's M365 is connected, RAIDEN works automatically:

    * **Audit log polling** — Continuous, per customer tenant. Identity events (sign-ins, MFA, OAuth consent) are polled on a faster cadence — roughly every 2 minutes — so attacks like adversary-in-the-middle and token theft surface quickly. Other event types poll on cadences tuned to their volume and risk
    * **Baseline learning** — 7–14 days to build user behavioural profiles
    * **Detection engine** — 269 detection and signal rules covering device code phishing, token theft, OAuth abuse, Teams impersonation, impossible travel, mailbox manipulation, and more
    * **Findings & cases** — Threats are surfaced as findings and grouped into cases. These are visible both in the customer's environment and in your MSSP dashboard summary
  </Step>
</Steps>

***

## Customer capacity

New MSSP accounts start on the **trial plan, which has no customer-tenant limit** — you can add and connect as many customers as you need to evaluate RAIDEN across your full portfolio. Higher plan tiers also carry their own capacity, and enterprise plans are uncapped.

If you ever see an unexpected "customer limit reached" message, your account plan is unrecognised and has fallen back to a small default. Contact [support@raidenhq.com](mailto:support@raidenhq.com) and we will correct the plan on your account.

***

## Next steps

1. **Send invite links** — Ensure every customer connects their M365 tenant so detections can begin
2. **Review early findings** — After the first few poll cycles, check for initial detections and tune (mark false positives, add VPN exclusions, etc.)
3. **Invite SOC team members** — Add analysts to your MSSP account from Settings
4. **Monitor the portfolio dashboard** — Check the health summary regularly for new critical findings across your customer base

***

## Cross-tenant intel propagation on true-positive closure

When an MSSP partner closes a case as a **True Positive** in one customer's environment, RAIDEN automatically propagates the relevant threat intelligence to all other tenants in the same MSSP fleet.

Specifically:

* The attacker's IP addresses, ASNs, and infrastructure indicators from the closed case are added to the fleet's shared threat intel feed
* Other tenant environments immediately benefit from these indicators — new sign-ins matching the same infrastructure will generate findings in those tenants without any manual configuration

This propagation is scoped to your MSSP fleet — indicators are not shared platform-wide or across MSP organisations. It applies only to confirmed true positives: false positive closures do not trigger propagation.

To trigger propagation, close the case with status **Closed — True Positive**. The propagation happens automatically within the next poll cycle (up to 2 minutes for identity content types).

***

## Getting help

Email [support@raidenhq.com](mailto:support@raidenhq.com) for support. Standard queries receive a response within 1 business day. For active compromise situations, include **URGENT** in the subject line.

When raising a support request, include:

* Your organisation name or MSSP slug (shown in **Settings → Account**)
* The Case or Alert ID if asking about a specific detection
* A brief description of what you expected to see and what you saw instead
