Customer Agreement and GDAP Approval
Microsoft has introduced Granular Delegated Admin Privileges (GDAP) to give organizations more control and security when granting partners access to their Microsoft 365 environments. Unlike the older delegated admin model, GDAP ensures partners only get the permissions they truly need — for a limited time — while customers retain full visibility.
As organizations continue to strengthen their security posture, Microsoft has introduced Granular Delegated Admin Privileges (GDAP) to provide a more secure and controlled way for partners to manage customer environments.
GDAP allows Microsoft partners to access only the specific Microsoft 365 resources required to perform their services. Access is granted with limited permissions and for a defined period, improving security while giving customers greater visibility and control over partner access.
To establish the partner relationship, customers must review and approve the GDAP invitation sent by the partner.
When a partner sends a GDAP invitation, the customer receives an email containing a secure invitation link.
After selecting the invitation link, the customer is redirected to the Microsoft 365 Admin Center, where they can review the requested permissions and approve the partner relationship.
Customers accept the partner agreements and approve the role permission.
Step 1: Review Partner Agreements and Access
After opening the invitation link:
At this stage, Microsoft validates the request and confirms the partner relationship details.

Step 2: Verify the Partner Relationship
Once verification is successful:
This step ensures that the relationship is being established with the intended Microsoft partner organization.


Step 3: Approve Partner Roles
The customer is redirected to the Approve Partner Roles page in the Microsoft 365 Admin Center.
During this stage:

Step 4: Review and Accept Access Permissions
Customers must carefully review the access levels being requested.
Key points to verify:
Once reviewed, select the option to approve the requested permissions.

Step 5: Accept the Partner Relationship
Before finalizing the process:
Microsoft will then create the GDAP relationship between the customer tenant and the partner organization.

Step 6: Verify the Partner Relationship
After acceptance:

Step 7: Global Administrator Verification
Users with the Global Administrator role can view additional details about the GDAP relationship, including:
This provides complete visibility and control over delegated administrative access.

Benefits of GDAP
GDAP provides several security and operational advantages:

By accepting the GDAP invitation and approving the requested permissions in the Microsoft 365 Admin Center, customers can securely grant partners the access required to support and manage their Microsoft 365 environment.
GDAP ensures that access is limited, controlled, and transparent, allowing organizations to maintain strong security standards while enabling trusted partners to deliver ongoing support and services. Customers retain full visibility and control over all delegated permissions throughout the lifecycle of the partner relationship.