Azure Granular Delegated Admin Privileges Setup
Granular Delegated Admin Privileges setup is currently in beta. The setup option is available in the Spotto portal, but Microsoft access validation, subscription discovery, and scan enablement still depend on the partner and customer access being ready.
Use this setup guidance when an MSP or CSP partner is preparing to connect customer Azure environments through Microsoft Partner Center instead of creating a separate Spotto service principal in every customer tenant.
With this model:
- The partner creates and maintains the GDAP relationship in Microsoft Partner Center.
- The customer approves the requested delegated roles in Microsoft 365 admin center.
- The partner assigns the approved roles to a partner security group.
- Spotto stores a partner authorization profile in the partner root company.
- Each customer company stores its own GDAP cloud account, scan history, subscriptions, and findings.
When To Use GDAP
Use GDAP when all of these are true:
- You are an MSP or CSP partner managing Azure customers through Partner Center.
- The customer has approved a GDAP relationship with your partner tenant.
- Your partner security group has the Microsoft Entra roles needed for the customer workloads you want Spotto to analyze.
- Azure subscription access is available through the customer's CSP/Azure Plan relationship or through Azure RBAC that the customer has assigned.
- The customer tenant has granted the required Spotto application consent for the GDAP flow.
Use Automatic Azure Connect, PowerShell Script, Terraform Module, or Manual Azure Portal Setup instead when the customer wants a dedicated service principal in their own tenant or when there is no Partner Center GDAP relationship.
GDAP is not a shortcut around customer approval. The customer remains in control of the relationship, delegated roles, and any Azure RBAC assignments required for their subscriptions.
Who Does What
| Person | Responsibility |
|---|---|
| Partner admin | Creates the GDAP relationship request in Partner Center, chooses the duration and roles, sends the approval link to the customer, and assigns approved roles to a partner security group. |
| Customer global admin | Reviews and approves the GDAP relationship request in Microsoft 365 admin center. |
| Azure subscription owner or user access admin | Confirms any required Azure RBAC access for the customer's subscriptions. |
| Spotto admin in the partner root company | Authorizes the partner profile with Microsoft and creates one GDAP cloud account per customer company. |
Before You Start
Collect these values before opening Spotto:
- Partner tenant ID.
- Customer tenant ID.
- GDAP relationship ID from Partner Center.
- Partner security group ID for the group assigned to the relationship.
- Confirmation that the relationship is active and has access assignments.
- Confirmation that the customer subscriptions Spotto should scan are visible through the delegated access path.
If the customer uses CSP billing, also review CSP Billing Prerequisites. Billing visibility can depend on partner-side Azure Usage visibility in addition to delegated access.
Confirm You Can Test GDAP
Partner IDs, an associated partner ID, or Microsoft AI Cloud Partner Program membership do not by themselves mean you can create GDAP relationships. Confirm that the partner tenant can manage customers in Partner Center before using this Spotto setup path.
Check these items in Microsoft Partner Center:
- Sign in using the partner tenant that owns the customer relationship.
- Confirm the account has an active customer-management program, such as CSP, reseller, or advisor capability.
- Confirm your user has the partner role needed to manage customer admin relationships, such as Admin agent.
- Open Customers and confirm the test customer is listed or can be created.
- Open the customer's Admin relationships area and confirm you can request a new GDAP relationship.
- After the customer approves the relationship, confirm you can assign the approved roles to a partner security group.
If you cannot see customers, cannot request an admin relationship, or cannot assign roles to a partner security group, the tenant is not ready to test GDAP in Spotto. Use one of the dedicated service-principal setup paths until a Partner Center admin enables the required partner capability and access.
Microsoft Partner Center Setup
Complete these steps in Microsoft Partner Center before creating the Spotto customer cloud account.
- Sign in to Partner Center as an admin agent.
- Create or select the customer.
- Request a GDAP relationship with the customer.
- Choose the Microsoft Entra roles needed for the customer workload.
- Send the approval request to the customer.
- Ask the customer global admin to approve the request.
- After approval, open the admin relationship and add the partner security group.
- Assign the approved roles to that security group.
- For CSP/Azure Plan subscription access, confirm the Azure management security group is nested under Admin Agents, or confirm the customer has assigned explicit Azure RBAC access for the subscriptions Spotto should read.
- Wait until the access assignment is active.
- Copy the GDAP relationship ID and assigned partner security group ID for the Spotto setup step.
Microsoft's reference pages:
- Obtain granular admin permissions to manage a customer's service
- Customer approval of partner GDAP request
- Grant granular permissions to security groups
- Workloads supported by GDAP
GDAP role assignments in Partner Center are not the same thing as Azure subscription RBAC. For Azure resource scans, confirm the delegated user path can read the customer's subscriptions and that any required Azure RBAC or billing visibility settings are in place.
Customer Approval Checklist
Send this checklist to the customer approver with the Microsoft approval link.
The customer should confirm:
- The partner name is correct.
- The requested roles match the agreed support or management scope.
- The relationship duration is expected.
- The approval request is for the correct customer tenant.
- The customer understands they can remove the relationship or delegated access later.
After approval, the customer can return to the partner. The partner still needs to assign the approved roles to the correct partner security group before Spotto can use the relationship.
Create The Partner Authorization Profile In Spotto
Create one partner authorization profile in the partner root company for each Spotto region where customer data will be scanned.
- In Spotto, switch to the partner root company.
- Open Connectors, then select Cloud Accounts.
- Select Add Cloud Account.
- Select Show More, then choose Granular Delegated Admin Privileges.
- In Authorization profile, create or select the partner profile.
- Enter a clear profile name, such as
Partner GDAP. - Enter the partner tenant ID.
- Select Create Profile.
- Select Authorize Profile.
- Sign in with the partner identity that is allowed to use the GDAP relationship.
- Approve the Microsoft authorization and return to Spotto.
The profile must show a ready status before customer GDAP cloud accounts can be saved.
Spotto stores the authorization profile and refresh tokens in the selected Spotto region. For example, a customer onboarded in the USA region uses the USA Spotto environment, callback URL, credential storage, and repositories. A customer onboarded in Europe uses the Europe environment and storage. Tokens are not shared across regions.
Create A Customer GDAP Cloud Account
Create a separate GDAP cloud account inside each customer company.
- In Spotto, switch to the customer company.
- Open Connectors, then select Cloud Accounts.
- Select Add Cloud Account.
- Select Show More, then choose Granular Delegated Admin Privileges.
- Select the ready partner authorization profile.
- Enter an account name that identifies the customer tenant.
- Enter the customer tenant ID.
- Enter the GDAP relationship ID from Partner Center.
- Enter the partner security group ID assigned to the approved GDAP roles.
- Open Optional GDAP Details only if you also want to record the access assignment ID.
- Select Validate GDAP Access.
- If the details are accepted, select Save and Start Scan.
Spotto validates the Microsoft and Azure access path before any recurring scan is allowed. When Microsoft returns a rotated refresh token, Spotto persists the new token so long-term scanning can continue without asking the partner to reauthorize every day.
What The First Scan Checks
The setup form checks that the selected profile is authorized and that the customer tenant, GDAP relationship, and partner security group values are present. A newly authorized profile can be used for its first customer validation immediately; customer validation status is tracked separately from partner authorization status.
Cloud-engine validation performs the deeper live checks, including:
- Whether the partner authorization can obtain Microsoft tokens.
- Whether the GDAP relationship is still active.
- Whether the security group and access assignment are usable.
- Whether the delegated access path can discover customer subscriptions.
- Whether Azure permissions and billing visibility are sufficient for the selected Spotto features.
If the first scan reports missing access, use Azure Cloud Account Permissions and Azure Cloud Account Troubleshooting to resolve the specific warning.
Ongoing Operation
After setup:
- Spotto scans GDAP customer cloud accounts only when validation passes and scheduled scanning is enabled for that account.
- Refresh tokens are stored encrypted and rotated when Microsoft returns a replacement token.
- Each customer company keeps its own cloud account, scan history, subscriptions, and findings.
- Each Spotto region keeps its own authorization callback URL, credentials, and token storage.
- If the customer removes the GDAP relationship or the partner removes the security group assignment, scans fail until access is restored.
Common Problems
| Symptom | Likely Cause | Fix |
|---|---|---|
| The profile cannot be selected for a customer account | The partner profile is not ready or the authorization failed | Reauthorize the profile from the partner root company. |
| Validate GDAP Access is unavailable | The partner profile is not authorized, or a required customer tenant, relationship, or security group value is missing | Complete the guidance shown below the button, then validate again. |
| The customer cloud account cannot be saved | Validation has not passed, or a required account value is missing | Re-check the account name, customer tenant ID, GDAP relationship ID, and partner security group ID. |
| First scan cannot find subscriptions | GDAP is active, but Azure subscription access is not available through delegated access or RBAC | Confirm CSP/Azure Plan access and Azure RBAC assignments for the customer subscriptions. |
| Billing data is missing | CSP Azure Usage visibility or Cost Management read access is incomplete | Review CSP Billing Prerequisites. GDAP billing export setup is not supported yet. |
| Scans stopped after working previously | The customer removed the GDAP relationship, the assignment expired, or Microsoft revoked the refresh token | Re-establish the GDAP relationship or reauthorize the Spotto partner profile. |