Spotto Partner Access And Consent
Granular Delegated Admin Privileges setup is currently in beta, including the approval handoff link described on this page.
Use this page when someone asks what they are approving. It covers the Microsoft approval you grant in your own partner tenant, the separate approval each customer grants in their own tenant, and how to pass either approval to a Global Administrator who does not use Spotto.
This page is written so you can send it to a customer's security reviewer as-is.
What Approving The Partner Profile Grants
When a partner admin selects Authorize Profile during GDAP setup, Microsoft shows a consent screen for the Spotto application. Approving it grants four permissions in your own partner tenant.
| Permission on the consent screen | What Spotto can do with it | Why it is needed |
|---|---|---|
Sign you in and read your profile (User.Read) | Read the signed-in partner user's own name, email, and user ID | Identifies which partner user authorized the profile |
Read organization information (Organization.Read.All) | Read your own partner tenant's details, such as tenant ID and verified domains | Confirms the profile was authorized against the partner tenant you typed in, not a different tenant |
Read all delegated admin relationships (DelegatedAdminRelationship.Read.All) | Read the status, roles, duration, and access assignments of GDAP relationships your partner tenant already has | Checks that a customer relationship is still active before a scan runs |
Maintain access to data you have given it access to (offline_access) | Keep the approved session alive between scans | Lets scheduled scans run without a partner admin signing in every hour |
All four are delegated permissions: Spotto acts as the partner user who approved, and can never do more than that user could do themselves. All four are read-only. All four are Microsoft Graph only.
What Approving The Partner Profile Does Not Grant
Approving the partner profile does not grant any of the following:
- No Azure access at all. No subscriptions, no resources, no costs, no Azure RBAC. Azure access is a completely separate grant, described in How Azure Access Actually Works.
- No access to any customer tenant. These four permissions apply to your partner tenant only.
- No write access anywhere. Spotto cannot create, change, approve, extend, or terminate a GDAP relationship, and cannot change roles, groups, or assignments.
- No access to mail, files, Teams, calendars, or end-user content.
- No standing access. Removing the enterprise application in your partner tenant, or removing the profile in Spotto, ends it.
Approving the partner profile is not consent on behalf of your customers. Every customer tenant requires its own separate approval inside that customer's tenant.
What Is Still Required Before Spotto Can Read One Customer
After the partner profile is approved, Spotto still cannot read a single customer tenant until all of the following are true for that customer:
- An active GDAP relationship exists between your partner tenant and that customer, approved by that customer.
- A partner security group is assigned to that relationship with the approved roles.
- A Global Administrator or Cloud Application Administrator has granted the Spotto application consent inside that customer's own tenant.
- A Spotto admin has configured a cloud account for that customer with its tenant ID, relationship ID, and security group ID.
- A Spotto admin has explicitly selected which subscriptions Spotto may read. Spotto only stores the subscriptions chosen on that screen.
Any customer can end this at any time by removing the delegated admin relationship in Microsoft 365 admin center, or by removing the Spotto application consent in their own tenant.
About "Read All Delegated Admin Relationships"
On the Microsoft consent screen, DelegatedAdminRelationship.Read.All is displayed as Read all delegated admin relationships. That wording reads broader than what it does, so it is worth stating plainly.
What is accurate:
- It applies only to your own partner tenant's delegated admin relationships. It cannot read another partner's relationships.
- It returns relationship metadata only: the customer tenant, relationship status, requested roles, duration, and access assignments. It does not return customer data, resources, costs, or user content.
- It is read-only. It cannot create, modify, approve, extend, or terminate a relationship.
- Spotto only ever looks up the specific relationship IDs a partner admin has entered in Spotto. There is no "list every relationship" call in the product.
- Microsoft Graph does not currently offer a narrower, per-relationship version of this permission. Reading the status of one relationship requires this permission, so this is the least-privileged option Microsoft makes available.
What we will not claim: the permission itself is tenant-wide, so the limit to specific relationship IDs is a property of how Spotto is built, not something Microsoft enforces on the token. The strong guarantee is the one above it: this permission grants no access to any customer tenant, and no Azure access. Reading a customer's environment requires that customer's own consent inside their own tenant.
Customer Tenant Consent
Each customer tenant must separately approve the Spotto application before validation can pass. Until it does, Spotto shows Customer application consent is missing and the Application consent check is Blocked.
Two people can grant it:
| Who grants it | What they need | Effect on your GDAP roles |
|---|---|---|
| Your partner admin, acting through the delegated relationship | To be in the assigned GDAP security group and under Admin Agents, with Cloud Application Administrator or Application Administrator among the approved GDAP roles | Cloud Application Administrator must be included in the relationship when it is first requested |
| The customer's own Global Administrator, in their own tenant | A Global Administrator account in the customer tenant. No Spotto login is needed if you send them an approval handoff link | Cloud Application Administrator is not needed in the GDAP relationship |
Decide which of these two you will use before you request the GDAP relationship. Roles cannot be added to a relationship after the customer approves it, so if you might ever need to grant consent yourself, Cloud Application Administrator has to be in the original request.
Hand The Approval To A Global Administrator
Microsoft approvals need an administrator, and that person is often not the person doing the Spotto setup. Rather than blocking setup or borrowing an admin account, Spotto can generate a shareable approval link.
The link works for both approvals: your partner tenant approval, and a customer tenant approval.
Generate And Send The Link
- In Spotto, open the GDAP setup screen.
- For the partner approval, switch to the partner root company and open the authorization profile.
- For a customer approval, switch to that customer company and open its GDAP cloud account setup.
- Select Create approval link for a partner-tenant approval, or Create customer approval link for a customer-tenant approval.
- Confirm the tenant shown is the tenant that should approve.
- Copy the generated link.
- Send it to the Global Administrator by your normal channel, such as email or a ticket.
What The Administrator Sees
- They open the link. No Spotto account or login is required.
- Spotto shows a summary page first: the application requesting access, the tenant being approved, the exact permission list, and who requested the approval.
- They select the option to continue and sign in with their own Microsoft account.
- Microsoft shows its own consent screen. They approve there.
- Microsoft returns them to Spotto with a confirmation.
Spotto records that consent was granted, the tenant, and the time. Return to Spotto and select Validate GDAP Access again.
What The Link Does And Does Not Do
| Property | Behaviour |
|---|---|
| Login required to open it | No. That is the point of the link. |
| Login required to create it | Yes. Creating a link requires a Spotto admin in the relevant company. |
| Reuse | Single-use. Once used, the link stops working. |
| Expiry | The link expires automatically. Generate a new one if it lapses. |
| Tenant | Fixed at creation. If the administrator signs in to a different tenant, the approval is rejected. |
| Credentials returned to Spotto | None. Microsoft returns only a confirmation that consent was granted. No password, no token, and no sign-in session reaches Spotto. |
| Audit | Spotto records who created the link and who completed it separately. |
Treat the link as sensitive while it is unused. Anyone holding it can open the approval page, but they still cannot approve anything without signing in as an administrator of the named tenant and passing Microsoft's own consent screen.
Who Does What
| Person | Responsibility |
|---|---|
| Spotto admin in the partner root company | Creates the authorization profile, generates approval links, and configures each customer cloud account |
| Partner Global Administrator | Approves the four Graph permissions in the partner tenant, once |
| Customer Global Administrator | Approves the GDAP relationship, and grants the Spotto application consent in the customer tenant unless the partner does it through the relationship |
| Customer security reviewer | Reviews this page, the requested GDAP roles, and any Azure RBAC the customer assigns |
Questions Customers Ask
Does approving this give Spotto access to our Azure bill or our virtual machines? No. The partner approval grants no Azure access whatsoever. Azure access is granted separately, per customer, and is described in How Azure Access Actually Works.
Can our partner read other customers' data through this? The partner approval covers the partner's own tenant only, and each customer's data requires that customer's own approval inside their own tenant.
Can we revoke it? Yes. A customer can remove the delegated admin relationship in Microsoft 365 admin center, or remove the Spotto application consent in their own tenant. A partner can remove the Spotto enterprise application in the partner tenant. Scans stop when access is removed.
Does Spotto keep our passwords? No. Approval flows happen on Microsoft's own sign-in pages, and the approval handoff link is specifically built so that Microsoft returns a confirmation only, with no credentials.