Admin Relationships
Azure GDAP > Admin Relationships manages the delegated admin relationships that give your partner tenant administrative access to this organization’s Microsoft tenant. It covers the whole lifecycle — request, customer approval, role assignment, compliance checking and termination — rather than only showing which relationships exist.
What GDAP is, and why the relationship has a lifecycle
Section titled “What GDAP is, and why the relationship has a lifecycle”Granular Delegated Admin Privileges replaced the older DAP model, in which a partner held Global Administrator on every customer tenant by default. GDAP grants specific roles, to a specific security group, for a bounded period, and the customer must approve it.
That approval step is why relationships move through states instead of simply existing. Creating one in MSPControl does not grant access — it creates a request that somebody at the customer has to accept.
Statuses and what each one allows
Section titled “Statuses and what each one allows”The status drives which row actions are available. Only the actions valid for that state are clickable; the rest are greyed out.
| Status | Meaning | Actions available |
|---|---|---|
| Created | The relationship exists locally; no request has been sent | Make request, Delete |
| ApprovalPending | The request is with the customer, awaiting acceptance | Send reminder email, Copy invitation link, Terminate |
| Active | Approved and in force | Create/update access assignments, Terminate |
| Activating, Approved | Transitional, on the way to Active | — |
| Expiring, Expired | Reaching or past the end date | — |
| TerminationRequested, Terminating, Terminated | Being withdrawn, or already withdrawn | — |
Creating a relationship
Section titled “Creating a relationship”-
Click Create Admin Relationship.
-
Choose a Policy. The policy — defined under Settings > Policies > Azure GDAP Policy — supplies the partner name, the duration (up to 730 days), the tenant-level roles requested, and the per-security-group role assignments.
-
Confirm. The relationship is created in Created state; nothing has been sent to the customer yet.
-
Use Make Admin Relationship request on the row. This sends the approval invitation email to the customer and moves the relationship to ApprovalPending.
-
When the customer accepts, the relationship becomes Active.
Chasing an approval
Section titled “Chasing an approval”Two actions exist because customers rarely act on the first email:
- Send Customer Approval invitation reminder Email re-sends the invitation.
- Copy Approval invitation link to Clipboard copies the Microsoft admin-portal link so you can send it through a ticket, chat, or a phone call with someone who is looking at the screen.
Neither creates a second relationship. Use them instead of re-requesting, or the customer ends up with duplicate pending invitations and approves an arbitrary one.
Compliance and access assignments
Section titled “Compliance and access assignments”Compliance Status does not mean “valid” — it means matches the GDAP policy. MSPControl compares the relationship’s granted roles against the policy it was created from and shows Policy Compliant or Policy Non-Compliant.
A separate icon appears on Active rows whose security-group access assignments do not match the policy: Create/update Access Assignments according Policy. Running it pushes the policy’s group-to-role assignments to the relationship.
Filters
Section titled “Filters”| Filter | Effect |
|---|---|
| Only Active | Current access only |
| Only Created in Control Panel | Relationships MSPControl created, hiding any made directly in Partner Center |
| Only Policy Not-Compliant | The governance exceptions |
Details
Section titled “Details”Clicking the relationship name opens a panel with the status, start and end dates, the unified roles granted at tenant level, and each security group with its own assigned roles. This is the view to use during an access audit — the list shows whether a relationship exists, the panel shows what it actually grants.
The fleet-wide view
Section titled “The fleet-wide view”Settings > Azure GDAP > Admin Relationships shows the same data across every customer, with a Customer column added. It is the review screen: it can terminate a relationship, but not create, request, or repair one — those stay on the organization’s own page.
Related
Section titled “Related”- Azure GDAP Policy — what a policy defines
- Azure settings
- Hosted organizations