Skip to main content

Spotto Partner Access And Consent

Beta

Granular Delegated Admin Privileges setup is currently in beta, including the approval handoff link described on this page.

Use this page when someone asks what they are approving. It covers the Microsoft approval you grant in your own partner tenant, the separate approval each customer grants in their own tenant, and how to pass either approval to a Global Administrator who does not use Spotto.

This page is written so you can send it to a customer's security reviewer as-is.

When a partner admin selects Authorize Profile during GDAP setup, Microsoft shows a consent screen for the Spotto application. Approving it grants four permissions in your own partner tenant.

Permission on the consent screenWhat Spotto can do with itWhy it is needed
Sign you in and read your profile (User.Read)Read the signed-in partner user's own name, email, and user IDIdentifies which partner user authorized the profile
Read organization information (Organization.Read.All)Read your own partner tenant's details, such as tenant ID and verified domainsConfirms the profile was authorized against the partner tenant you typed in, not a different tenant
Read all delegated admin relationships (DelegatedAdminRelationship.Read.All)Read the status, roles, duration, and access assignments of GDAP relationships your partner tenant already hasChecks that a customer relationship is still active before a scan runs
Maintain access to data you have given it access to (offline_access)Keep the approved session alive between scansLets scheduled scans run without a partner admin signing in every hour

All four are delegated permissions: Spotto acts as the partner user who approved, and can never do more than that user could do themselves. All four are read-only. All four are Microsoft Graph only.

What Approving The Partner Profile Does Not Grant

Approving the partner profile does not grant any of the following:

  • No Azure access at all. No subscriptions, no resources, no costs, no Azure RBAC. Azure access is a completely separate grant, described in How Azure Access Actually Works.
  • No access to any customer tenant. These four permissions apply to your partner tenant only.
  • No write access anywhere. Spotto cannot create, change, approve, extend, or terminate a GDAP relationship, and cannot change roles, groups, or assignments.
  • No access to mail, files, Teams, calendars, or end-user content.
  • No standing access. Removing the enterprise application in your partner tenant, or removing the profile in Spotto, ends it.
important

Approving the partner profile is not consent on behalf of your customers. Every customer tenant requires its own separate approval inside that customer's tenant.

What Is Still Required Before Spotto Can Read One Customer

After the partner profile is approved, Spotto still cannot read a single customer tenant until all of the following are true for that customer:

  1. An active GDAP relationship exists between your partner tenant and that customer, approved by that customer.
  2. A partner security group is assigned to that relationship with the approved roles.
  3. A Global Administrator or Cloud Application Administrator has granted the Spotto application consent inside that customer's own tenant.
  4. A Spotto admin has configured a cloud account for that customer with its tenant ID, relationship ID, and security group ID.
  5. A Spotto admin has explicitly selected which subscriptions Spotto may read. Spotto only stores the subscriptions chosen on that screen.

Any customer can end this at any time by removing the delegated admin relationship in Microsoft 365 admin center, or by removing the Spotto application consent in their own tenant.

About "Read All Delegated Admin Relationships"

On the Microsoft consent screen, DelegatedAdminRelationship.Read.All is displayed as Read all delegated admin relationships. That wording reads broader than what it does, so it is worth stating plainly.

What is accurate:

  • It applies only to your own partner tenant's delegated admin relationships. It cannot read another partner's relationships.
  • It returns relationship metadata only: the customer tenant, relationship status, requested roles, duration, and access assignments. It does not return customer data, resources, costs, or user content.
  • It is read-only. It cannot create, modify, approve, extend, or terminate a relationship.
  • Spotto only ever looks up the specific relationship IDs a partner admin has entered in Spotto. There is no "list every relationship" call in the product.
  • Microsoft Graph does not currently offer a narrower, per-relationship version of this permission. Reading the status of one relationship requires this permission, so this is the least-privileged option Microsoft makes available.

What we will not claim: the permission itself is tenant-wide, so the limit to specific relationship IDs is a property of how Spotto is built, not something Microsoft enforces on the token. The strong guarantee is the one above it: this permission grants no access to any customer tenant, and no Azure access. Reading a customer's environment requires that customer's own consent inside their own tenant.

Each customer tenant must separately approve the Spotto application before validation can pass. Until it does, Spotto shows Customer application consent is missing and the Application consent check is Blocked.

Two people can grant it:

Who grants itWhat they needEffect on your GDAP roles
Your partner admin, acting through the delegated relationshipTo be in the assigned GDAP security group and under Admin Agents, with Cloud Application Administrator or Application Administrator among the approved GDAP rolesCloud Application Administrator must be included in the relationship when it is first requested
The customer's own Global Administrator, in their own tenantA Global Administrator account in the customer tenant. No Spotto login is needed if you send them an approval handoff linkCloud Application Administrator is not needed in the GDAP relationship
important

Decide which of these two you will use before you request the GDAP relationship. Roles cannot be added to a relationship after the customer approves it, so if you might ever need to grant consent yourself, Cloud Application Administrator has to be in the original request.

Microsoft approvals need an administrator, and that person is often not the person doing the Spotto setup. Rather than blocking setup or borrowing an admin account, Spotto can generate a shareable approval link.

The link works for both approvals: your partner tenant approval, and a customer tenant approval.

  1. In Spotto, open the GDAP setup screen.
    • For the partner approval, switch to the partner root company and open the authorization profile.
    • For a customer approval, switch to that customer company and open its GDAP cloud account setup.
  2. Select Create approval link for a partner-tenant approval, or Create customer approval link for a customer-tenant approval.
  3. Confirm the tenant shown is the tenant that should approve.
  4. Copy the generated link.
  5. Send it to the Global Administrator by your normal channel, such as email or a ticket.

What The Administrator Sees

  1. They open the link. No Spotto account or login is required.
  2. Spotto shows a summary page first: the application requesting access, the tenant being approved, the exact permission list, and who requested the approval.
  3. They select the option to continue and sign in with their own Microsoft account.
  4. Microsoft shows its own consent screen. They approve there.
  5. Microsoft returns them to Spotto with a confirmation.

Spotto records that consent was granted, the tenant, and the time. Return to Spotto and select Validate GDAP Access again.

PropertyBehaviour
Login required to open itNo. That is the point of the link.
Login required to create itYes. Creating a link requires a Spotto admin in the relevant company.
ReuseSingle-use. Once used, the link stops working.
ExpiryThe link expires automatically. Generate a new one if it lapses.
TenantFixed at creation. If the administrator signs in to a different tenant, the approval is rejected.
Credentials returned to SpottoNone. Microsoft returns only a confirmation that consent was granted. No password, no token, and no sign-in session reaches Spotto.
AuditSpotto records who created the link and who completed it separately.
caution

Treat the link as sensitive while it is unused. Anyone holding it can open the approval page, but they still cannot approve anything without signing in as an administrator of the named tenant and passing Microsoft's own consent screen.

Who Does What

PersonResponsibility
Spotto admin in the partner root companyCreates the authorization profile, generates approval links, and configures each customer cloud account
Partner Global AdministratorApproves the four Graph permissions in the partner tenant, once
Customer Global AdministratorApproves the GDAP relationship, and grants the Spotto application consent in the customer tenant unless the partner does it through the relationship
Customer security reviewerReviews this page, the requested GDAP roles, and any Azure RBAC the customer assigns

Questions Customers Ask

Does approving this give Spotto access to our Azure bill or our virtual machines? No. The partner approval grants no Azure access whatsoever. Azure access is granted separately, per customer, and is described in How Azure Access Actually Works.

Can our partner read other customers' data through this? The partner approval covers the partner's own tenant only, and each customer's data requires that customer's own approval inside their own tenant.

Can we revoke it? Yes. A customer can remove the delegated admin relationship in Microsoft 365 admin center, or remove the Spotto application consent in their own tenant. A partner can remove the Spotto enterprise application in the partner tenant. Scans stop when access is removed.

Does Spotto keep our passwords? No. Approval flows happen on Microsoft's own sign-in pages, and the approval handoff link is specifically built so that Microsoft returns a confirmation only, with no credentials.