Skip to main content
Category: Microsoft 365 Administration · View source ↗
Connectors: IT Glue Hudu Role: Security & Compliance Owner, MSP Owner / Leadership Outcome: Risk & Compliance When to use: GDAP is the MSP’s own privileged access, so this review points the least-privilege lens inward — which client tenants the MSP can touch, with which roles, granted to which people, expiring when. Use for periodic (quarterly/semiannual) review of the MSP’s delegated access across all managed tenants, a GDAP expiry warning or access to a client tenant that suddenly stopped working, “what can we actually do in <client>‘s tenant?” (audit/insurance/client-security-review), or after MSP staff changes to confirm role-group membership still matches who should hold client access. The two failure modes are opposite and both real — over-broad roles nobody remembers granting, and an expiry nobody tracked that cuts access during an incident. Run it: as an on-demand review across every client tenant the MSP touches — you compile the dated artifact and prepare remediation, a technician exports from Partner Center and executes changes (not a Flow: no schedule trigger, and changes need a human at the console).

Prompt