Skip to content

Admin Relationships

Azure GDAP > Admin Relationships manages the delegated admin relationships that give your partner tenant administrative access to this organization’s Microsoft tenant. It covers the whole lifecycle — request, customer approval, role assignment, compliance checking and termination — rather than only showing which relationships exist.

What GDAP is, and why the relationship has a lifecycle

Section titled “What GDAP is, and why the relationship has a lifecycle”

Granular Delegated Admin Privileges replaced the older DAP model, in which a partner held Global Administrator on every customer tenant by default. GDAP grants specific roles, to a specific security group, for a bounded period, and the customer must approve it.

That approval step is why relationships move through states instead of simply existing. Creating one in MSPControl does not grant access — it creates a request that somebody at the customer has to accept.

The status drives which row actions are available. Only the actions valid for that state are clickable; the rest are greyed out.

Status Meaning Actions available
Created The relationship exists locally; no request has been sent Make request, Delete
ApprovalPending The request is with the customer, awaiting acceptance Send reminder email, Copy invitation link, Terminate
Active Approved and in force Create/update access assignments, Terminate
Activating, Approved Transitional, on the way to Active
Expiring, Expired Reaching or past the end date
TerminationRequested, Terminating, Terminated Being withdrawn, or already withdrawn
  1. Click Create Admin Relationship.

  2. Choose a Policy. The policy — defined under Settings > Policies > Azure GDAP Policy — supplies the partner name, the duration (up to 730 days), the tenant-level roles requested, and the per-security-group role assignments.

  3. Confirm. The relationship is created in Created state; nothing has been sent to the customer yet.

  4. Use Make Admin Relationship request on the row. This sends the approval invitation email to the customer and moves the relationship to ApprovalPending.

  5. When the customer accepts, the relationship becomes Active.

Two actions exist because customers rarely act on the first email:

  • Send Customer Approval invitation reminder Email re-sends the invitation.
  • Copy Approval invitation link to Clipboard copies the Microsoft admin-portal link so you can send it through a ticket, chat, or a phone call with someone who is looking at the screen.

Neither creates a second relationship. Use them instead of re-requesting, or the customer ends up with duplicate pending invitations and approves an arbitrary one.

Compliance Status does not mean “valid” — it means matches the GDAP policy. MSPControl compares the relationship’s granted roles against the policy it was created from and shows Policy Compliant or Policy Non-Compliant.

A separate icon appears on Active rows whose security-group access assignments do not match the policy: Create/update Access Assignments according Policy. Running it pushes the policy’s group-to-role assignments to the relationship.

Filter Effect
Only Active Current access only
Only Created in Control Panel Relationships MSPControl created, hiding any made directly in Partner Center
Only Policy Not-Compliant The governance exceptions

Clicking the relationship name opens a panel with the status, start and end dates, the unified roles granted at tenant level, and each security group with its own assigned roles. This is the view to use during an access audit — the list shows whether a relationship exists, the panel shows what it actually grants.

Settings > Azure GDAP > Admin Relationships shows the same data across every customer, with a Customer column added. It is the review screen: it can terminate a relationship, but not create, request, or repair one — those stay on the organization’s own page.