How to Set Up GDAP Access for a Microsoft 365 Support Partner
Question details
The user needs to configure Granular Delegated Admin Privileges (GDAP) to grant a support provider limited administrative access to their Microsoft 365 tenant.

- Product
- Microsoft 365
- Device & OS
- not provided
- Scenario
- Setting up limited administrative permissions for an external support provider like IONOS.
- Observed behavior
- The user needs to securely approve and manage a GDAP relationship request initiated by their Microsoft partner.
Ensure you have Global Administrator privileges in your Microsoft 365 admin center before attempting to approve any GDAP relationship requests.
Approve a GDAP Request via Microsoft 365 Admin Center
Use this standard method to review and approve a GDAP relationship request initiated by your support provider.
Granular Delegated Admin Privileges (GDAP) ensure that external partners only receive the exact administrative roles they need to assist you, rather than full global admin rights.
Contact your Microsoft support partner or provider (such as IONOS) and ask them to initiate a GDAP relationship request.
Once the request is sent, log in to the Microsoft 365 admin center using your Global Administrator credentials.
Click the link provided in the partner's request email to review the specific admin roles and duration being requested.
Click to approve the relationship request in the portal, ensuring you only grant the minimum permissions required for the provider to support your tenant.

Set Up GDAP Access Using Microsoft 365 Lighthouse
Use this method if your organization and partner manage multi-tenant access through Microsoft 365 Lighthouse.
Looking for a simpler alternative to Microsoft 365?
Managing Microsoft 365 tenant permissions and enterprise administration can be highly complex. If you are looking for a powerful, easy-to-use office suite without the overhead of enterprise IT management, WPS Office is an excellent choice. It offers robust document, spreadsheet, and presentation tools in a single lightweight application.

Frequently Asked Questions
What is a GDAP relationship in Microsoft 365?
Granular Delegated Admin Privileges (GDAP) is a security feature that allows organizations to provide external partners or support providers with limited, time-bound access to their Microsoft 365 tenant, ensuring they only have the permissions necessary to perform their specific tasks.
Who can initiate a GDAP request?
The GDAP relationship request must be initiated by the Microsoft partner or support provider (such as IONOS or a managed service provider). The customer then reviews and approves the request from within their Microsoft 365 admin center.
How long does a GDAP relationship last?
GDAP relationships are strictly time-bound. The exact duration is specified during the request process and cannot exceed two years. Once the relationship expires, the partner loses access and a new request must be submitted if continued support is needed.




