GDAP (recommended addition to Phase 1)
GDAP, or Granular Delegated Admin Privileges, is the Microsoft model that lets partners access customer tenants with specific, time-bound admin roles rather than broad standing access. It replaced the older Delegated Admin Privileges (DAP) model to give customers least-privilege, auditable partner access.
Key Takeaways
- GDAP grants specific admin roles for a set time, not blanket access.
- It replaced DAP to improve security and least-privilege access.
- Partners manage GDAP relationships in Microsoft Partner Center.
- GDAP relationships expire and need active management to avoid access gaps.
What GDAP is
GDAP lets a partner request only the admin roles it needs on a customer tenant, for a defined period. When the period ends, access lapses unless renewed, which keeps partner access aligned to least-privilege security principles.
Why it matters for Microsoft CSPs
GDAP is now central to how partners support customers securely. Because relationships are time-bound, partners have to track and renew them, or risk losing the access they need to provision and support customers.
GDAP vs DAP
DAP granted broad, standing admin access to customer tenants. GDAP grants specific roles for a limited time, which is more secure but requires active management of each relationship.
How Work 365 supports this
Work 365 helps partners keep GDAP relationships visible and managed alongside billing and provisioning. See GDAP Manager.
Related terms: Microsoft Partner Center, CSP, Provisioning.
FAQ
What does GDAP stand for?
Granular Delegated Admin Privileges.
Why did Microsoft replace DAP with GDAP?
To move partners from broad standing access to least-privilege, time-bound access for better security.
Do GDAP relationships expire?
Yes. They are time-bound and need to be renewed to avoid losing access.

