logo
search
Permission & Access Issues

How to Fix GDAP Partner Access Error on Customer SharePoint Sites

Maira MehtabMaira Mehtab Sep 21, 2026 869 views

Question details

A partner with working Granular Delegated Admin Privileges (GDAP) is unable to access a customer's shared SharePoint site.

Product
Microsoft SharePoint
Device & OS
not provided
Scenario
Attempting to access a customer's shared SharePoint site as a partner using an account that holds GDAP roles.
Observed behavior
The user receives an access error preventing them from viewing the customer's SharePoint content, even though sharing works perfectly for non-partner email addresses.
Before you start

Before troubleshooting, ensure you have the contact information for the customer's tenant administrator, as resolving this cross-tenant permission issue may require their assistance to adjust access rights.

Solution 1Recommended

Remove Account from GDAP Role Group

Resolve the intentional Microsoft design limitation by temporarily removing your account from the group that provides GDAP roles.

By design, users assigned Granular Delegated Admin Privileges (GDAP) roles cannot work with guest accounts. Consequently, you are blocked from accessing a customer's SharePoint tenant content as a guest if your active account holds a GDAP role. Removing the role resolves this conflict.

1
Access the Admin Center

Log in to your partner admin center where your tenant roles and security groups are managed.

2
Locate the GDAP Security Group

Find the specific security group that assigns GDAP roles to your partner account.

3
Remove Your Account

Select your user account from the group's member list and click 'Remove' to revoke the GDAP roles.

4
Test SharePoint Access

Wait a few minutes for the changes to propagate, then click the customer's shared SharePoint link again to verify access.

Access Restored: Once the GDAP role conflict is removed, your account will be recognized as a standard guest, allowing full access to the shared site.
Free Microsoft Office alternative

Try WPS Office for Seamless Document Collaboration

If complex cross-tenant permissions and GDAP role limitations are slowing down your workflow, consider WPS Office. It provides a lightweight, highly compatible alternative for sharing and collaborating on documents without rigid tenant restrictions.

  1. 1. Visit the WPS Website: Go to the official WPS Office website to locate the free download package for your operating system.
  2. 2. Download the Software: Click on the 'Free Download' button to save the installation file securely to your local drive.
  3. 3. Install and Share: Run the installer, set up your account, and easily share your created documents without worrying about tenant barriers.
Collaborate on documents seamlessly without facing complex cross-tenant permission errors.Fully compatible with Microsoft Office formats, including Word, Excel, and PowerPoint.Lightweight architecture ensures it runs smoothly on almost any desktop or mobile device.Familiar, easy-to-use user interface requiring zero learning curve for rapid deployment.Free to download and use for all your essential office tasks and document creation.
microsoft office alternative - wps office

Frequently Asked Questions

Can a partner user have both GDAP roles and a guest account?

No. By Microsoft's design, users with Granular Delegated Admin Privileges (GDAP) roles cannot operate as guest accounts in a customer's tenant. The roles conflict with standard cross-tenant guest access policies.

Why does sharing work with non-partner email addresses?

Non-partner email addresses are not linked to a partner tenant holding administrative (GDAP) roles. Therefore, Microsoft treats them as standard external guest users, allowing them to access the shared SharePoint site without any permission conflicts.

How can I bypass the GDAP role restriction for SharePoint?

The most effective method is to remove your user account from the security group that grants you GDAP roles. Once removed, you can interact with the customer's SharePoint environment as a regular guest.

Why should I test SharePoint access in an InPrivate or Incognito window?

Using an InPrivate or Incognito window prevents your browser from automatically using cached credentials from other Microsoft 365 sessions. This ensures that you are logging in strictly with the refreshed guest permissions.