"Granular Delegated Administrator Privileges" (GDAP) is a security feature introduced by Microsoft that provides Partners with less privileged access following the Zero Trust cybersecurity protocol. This less privileged access must be explicitly granted to Partners by their Customers. For more information please review the official Microsoft article: Granular delegated admin privileges (GDAP) introduction - Partner Center | Microsoft Learn
The new GDAP capability will replace the more basic "Delegated Administrator Privileges" (DAP), and will allow TD SYNNEX and your company to set up granular and time-limited access to your customers' workloads, meaning that both of us will be better able to address security concerns and regulatory requirements from Customers.
TD SYNNEX has been working to implement the Microsoft's new security model for CSP Customers and has moved automatically all your customers currently in DAP into GDAP, however for new tenants or where GDAP has expired, relationship has to be established.
Access Requirements for Technical Support
Customer shall grant TD SYNNEX the necessary access to the affected Microsoft environment to enable the proper delivery of the Services. This includes, but is not limited to, accepting the Granular Delegated Administrator Privileges (GDAP) relationship and assigning the following minimum roles:
Global Reader – Required to allow TD SYNNEX to read all information within the End Customer's directory, without making any modifications.
Service Support Administrator – Required to permit TD SYNNEX to access service health information and manage support tickets for the End Customer.
-
Directory Reader – Required to provide access to directory objects necessary for support operations.
Additionally, Customer shall ensure that TD SYNNEX management domains are excluded from any Conditional Access Policies that could restrict access. These roles and exclusions are essential for TD SYNNEX to perform diagnostics and provide support.
Failure to grant or maintain the required access means TD SYNNEX will be unable to provide support.
For additional guidance, please refer to the official Microsoft documentation:
Please note that currently, only Partners have the authority to establish the GDAP relationship and grant us access to the customer's workload. If you happen to be the Administrator User of the tenant, you can accept the GDAP access request on behalf of the customer.
If the GDAP relationship has not been established before submitting the Support Request, our support team will guide you to follow the instructions provided in the below User Guide.
GDAP - StreamOne® Ion User Guide
Once you have completed the necessary process, please inform the support team, they will be able to resume troubleshooting for the Support Request that was raised.
Should you encounter any technical issues during the process, or you need assistance on how to set-up our own GDAP environment, please reach out to your TD SYNNEX Sales representative.