Embracing Microsoft's GDAP Changes: A Comprehensive Guide for MSPs using Liongard
Microsoft’s GDAP changes are making waves in the MSP space! Don’t get caught in the wake.

Embracing Microsoft's GDAP Changes: A Comprehensive Guide for MSPs using Liongard

There’s a significant milestone coming up on Monday, May 22, for Microsoft’s transition to?GDAP, or Granular Delegated Admin Permissions. This initiative requires Managed Service Providers (MSPs), who manage their clients through the Microsoft Partner Center, to establish GDAP relationships. These relationships provide the opportunity to assign more granular permission levels to each client, but these changes also affect the 3rd party applications and systems you rely on.

This imminent GDAP shift will affect the operation of Liongard's Microsoft Inspectors suite because the foundational Microsoft Graph API, on which our Inspectors rely, has been modified to require GDAP in the partner's Microsoft Partner Center.

To learn more about these requirements...

1) We put together a?comprehensive resource?that will help our partners get ahead on the necessary work before these changes impact Liongard's inspectors.

2) We also created a?video playlist?with the necessary information to ensure the smooth transition to GDAP:

Update Microsoft Cloud Service Inspectors for Granular Delegated Admin Privileges "How To" Video


Configure GDAP Tenant Relationships to Enable Liongard’s Microsoft Inspectors "How To" Video


Will you be affected?

GDAP relationship setup is only required for those Microsoft accounts associated to current Liongard Microsoft Parent Inspectors where you’re using a Multi-Tenant setup. A Multi-Tenant setup means you use a Microsoft account to manage your customer relationships via the Microsoft Partner Center.

If your GDAP relationships in the Microsoft Partner Center aren’t properly set up before Microsoft’s planned transition on 5/22, Liongard’s Microsoft Cloud Inspectors will stop working, and you’ll lose these critical benefits, among others:

  • Reconciling cloud licenses and active managed users vs billed to collect 100% of revenue.
  • Ability to document and audit Active Directory Domain and Forest details, e.g. role holders, LDAP details, and policies.
  • Automated documentation with IT Glue and Hudu.
  • Auditing users for appropriate group memberships (privileged groups, critical groups) and alert for changes.

Key Takeaways

  • Microsoft will begin forcibly transitioning users from DAP to GDAP on May 22nd, necessitating a new version of our Microsoft Cloud Inspectors suite.
  • Liongard Partners managing multiple clients through the Microsoft Partner Center will need to perform certain tasks on the Microsoft side (detailed here).
  • After completing these tasks, Partners must reauthenticate their Microsoft Cloud Parent Inspectors.
  • To assist with this transition, we created a dedicated?resource page?and?video playlist?to help our Partners get ready for the switch.

If you run into any issues, we are here to help!

Feel free to?schedule some time with your account manager?to answer any questions!

Not yet a Liongard Partner?

Check out the videos our Education team put together to help our Partners navigate and understand these complicated changes to the Microsoft Partner Center’s permissions structure.

Geoff Wasley

Director, Automation & Development at Visory

1 年

Your recommended solution is to create a new GDAP relationship with each client giving the AdminAgents security group the global administrator role. Doesn’t this go against everything Microsoft wants to accomplish with granular delegated access? Seems a little excessive for inspectors that should just be reading data…

回复
Angela W.

HubSpot Certified Marketer | WYRE Technology

1 年

Forwarding this to our tech people—THANK YOU for putting all this together in one place!

要查看或添加评论,请登录

Liongard的更多文章

社区洞察

其他会员也浏览了