How to Fix GDAP Partner Access Error on Customer SharePoint Sites
Question details
A partner with working Granular Delegated Admin Privileges (GDAP) is unable to access a customer's shared SharePoint site.
- Product
- Microsoft SharePoint
- Device & OS
- not provided
- Scenario
- Attempting to access a customer's shared SharePoint site as a partner using an account that holds GDAP roles.
- Observed behavior
- The user receives an access error preventing them from viewing the customer's SharePoint content, even though sharing works perfectly for non-partner email addresses.
Before troubleshooting, ensure you have the contact information for the customer's tenant administrator, as resolving this cross-tenant permission issue may require their assistance to adjust access rights.
Remove Account from GDAP Role Group
Resolve the intentional Microsoft design limitation by temporarily removing your account from the group that provides GDAP roles.
By design, users assigned Granular Delegated Admin Privileges (GDAP) roles cannot work with guest accounts. Consequently, you are blocked from accessing a customer's SharePoint tenant content as a guest if your active account holds a GDAP role. Removing the role resolves this conflict.
Log in to your partner admin center where your tenant roles and security groups are managed.
Find the specific security group that assigns GDAP roles to your partner account.
Select your user account from the group's member list and click 'Remove' to revoke the GDAP roles.
Wait a few minutes for the changes to propagate, then click the customer's shared SharePoint link again to verify access.
Re-invite the Guest Account via Customer Admin
Coordinate with the customer's IT administrator to refresh your guest permissions if removing the GDAP role is not possible or didn't fully resolve the cache.
Try WPS Office for Seamless Document Collaboration
If complex cross-tenant permissions and GDAP role limitations are slowing down your workflow, consider WPS Office. It provides a lightweight, highly compatible alternative for sharing and collaborating on documents without rigid tenant restrictions.
- 1. Visit the WPS Website: Go to the official WPS Office website to locate the free download package for your operating system.
- 2. Download the Software: Click on the 'Free Download' button to save the installation file securely to your local drive.
- 3. Install and Share: Run the installer, set up your account, and easily share your created documents without worrying about tenant barriers.

Frequently Asked Questions
Can a partner user have both GDAP roles and a guest account?
No. By Microsoft's design, users with Granular Delegated Admin Privileges (GDAP) roles cannot operate as guest accounts in a customer's tenant. The roles conflict with standard cross-tenant guest access policies.
Why does sharing work with non-partner email addresses?
Non-partner email addresses are not linked to a partner tenant holding administrative (GDAP) roles. Therefore, Microsoft treats them as standard external guest users, allowing them to access the shared SharePoint site without any permission conflicts.
How can I bypass the GDAP role restriction for SharePoint?
The most effective method is to remove your user account from the security group that grants you GDAP roles. Once removed, you can interact with the customer's SharePoint environment as a regular guest.
Why should I test SharePoint access in an InPrivate or Incognito window?
Using an InPrivate or Incognito window prevents your browser from automatically using cached credentials from other Microsoft 365 sessions. This ensures that you are logging in strictly with the refreshed guest permissions.




