When ordering CSP products for your own use through the Marketplace, SoftwareOne requires specific Granular Delegated Admin Privileges (GDAP) to effectively provision or manage these products in your Microsoft tenant.
The following table outlines the GDAP roles that SoftwareOne requires to establish a relationship. It also describes what each role enables.
Service – Microsoft Azure
Directory reader​
Service – Microsoft 365 Business, Enterprise, & Apps (Charity, Commercial, and Education)
Service – Microsoft Dynamics 365 (Charity, Commercial, and Education)
If you are a SoftwareOne Partner purchasing , your customers must approve a GDAP relationship request that includes the roles listed in the following table:
To learn more about GDAP and its importance, see .
The GDAP admin relationship is established with the following configuration:
Once the GDAP relationship is in place, its duration is set to 2 years by default. When the relationship is about to expire, it's automatically extended for an additional 180 days.
Can read basic directory information.
Global reader
Can read everything that a Global Administrator can, but cannot update anything.
Service support administrator​
Can read service health information and manage support tickets.
Billing administrator
Performs common billing-related tasks, like updating payment information.
Cloud application administrator
Creates and manages all aspects of enterprise applications and application registrations.
Attack simulation administrator
Can create and manage all aspects of attack simulation campaigns.
Authentication administrator​
Can access to view, set and reset authentication method information for any non-admin user.
Authentication administrator​
Can access to view, set and reset authentication method information for any non-admin user.
Billing administrator
Performs common billing-related tasks like updating payment information.
Directory readers ​
Global reader
Can read everything that a Global Administrator can, but cannot update anything.
Billing administrator
Can perform billing-related tasks, such as updating payment information.
Directory writers
displayName
Microsoft Tenant Name + 'admin relationship'
duration
P2Y
autoExtendDuration
Billing administrator
Performs common billing-related tasks like updating payment information.
Compliance administrator
Can read and manage compliance configuration and reports in Microsoft Entra ID and Microsoft 365.
Directory readers ​
Can read basic directory information. Commonly used to grant directory read access to applications and guests.
Domain name administrator ​
Manages domain names in cloud and on-premises.
Exchange administrator ​
Manages all aspects of the Exchange product.
Global reader ​
Can read everything that a Global Administrator can, but not update anything.
Groups administrator ​
Can create and manage groups, create and manage group settings like naming and expiration policies. Can also view group activity and audit reports.
Hybrid identity administrator ​
Manages Active Directory to Microsoft Entra cloud provisioning, Microsoft Entra Connect, pass-through authentication (PTA), password hash synchronization (PHS), seamless single sign-on (seamless SSO), and federation settings. Does not have access to manage Microsoft Entra Connect Health.
Intune administrator ​
Manages all aspects of the Intune product.
License administrator
Manages product licenses on users and groups.
Network administrator
Manages network locations and reviews enterprise network design insights for Microsoft 365 Software as a Service applications.
Fabric administrator (PowerBI) ​
Manages all aspects of the Fabric and Power BI products.
Power platform administrator
Can create and manage all aspects of Microsoft Dynamics 365, Power Apps and Power Automate.
Security administrator ​
Can read security information and reports, and manage configuration in Microsoft Entra ID and Office 365.
Service support administrator ​
Can read service health information and manage support tickets.
SharePoint administrator ​
Manages all aspects of the SharePoint service.
Skype for business administrator
Manages all aspects of the Skype for Business product.
Teams administrator
Manages the Microsoft Teams service.
User administrator
Manages all aspects of users and groups, including resetting passwords for limited admins.
Windows 365 administrator
Can create and manage security groups but does not have administrator rights over Microsoft 365 groups.
Cloud application administrator
Creates and manages all aspects of enterprise applications and application registrations.
Conditional access administrator
Manages Conditional Access capabilities.
Can read basic directory information. Commonly used to grant directory read access to applications and guests.
Global reader
Can read everything that a Global Administrator can, but not update anything.
Groups administrator ​
Creates and manages groups and creates and manages group settings like naming and expiration policies. Can also view group activity and audit reports.
License administrator
Manages product licenses on users and groups.
Fabric administrator (PowerBI) ​
Manages all aspects of the Fabric and Power BI products.
Power platform administrator​
Can create and manage all aspects of Microsoft Dynamics 365, Power Apps and Power Automate.
Service support administrator ​
Can read service health information and manage support tickets.
User administrator
Manages all aspects of users and groups, including resetting passwords for limited admins.
Cloud application administrator
Grants the ability to create and manage all aspects of enterprise applications and application registrations.
Dynamics 365 administrator​
Manages all aspects of the Dynamics 365 product.
Can read basic directory information. Commonly used to grant directory read access to applications and guests.
Cloud application administrator
Can create and manage all aspects of enterprise applications and application registrations.
License administrator
Manages product licenses for users and groups.
Service support administrator
Can read service health information and manage support tickets.
180 days
SoftwareOne requires Granular Delegated Administrative Privileges (GDAP) in your tenant to manage your Microsoft products and services. Without these privileges, we are unable to provide all the services associated with your purchase.
After you have placed an order, you must accept our GDAP invitation. This invitation is provided as a URL on the order details page. When you select the link and log in as a Global Administrator, you are redirected to the Microsoft 365 admin center to complete the GDAP setup.
To accept a GDAP relationship request:
Open the Orders page.
Select the required purchase order.
On the General tab, select the GDAP URL.
Sign in to the Microsoft 365 admin center using an account that has Global Administrator permissions. You can use the Global Administrator credentials associated with the primary domain or tenant name stated in your purchase order.
Review the SoftwareOne partner information, then select Next.
Select the link for the Microsoft Customer Agreement and read the agreement.
Select the checkbox to acknowledge that you have read the agreement, then select Accept.
Return to your purchase order in the Marketplace and select Process to resume order processing.
Granular Delegated Admin Privileges (GDAP) is Microsoft's latest innovation in cloud security management, and it's transforming how organizations collaborate with service providers.
GDAP is a sophisticated security framework that allows you to grant SoftwareOne precisely controlled access to your Microsoft cloud environment. This ensures we can support your business needs while maintaining the highest security standards.
In today's digital landscape, traditional all-or-nothing access approaches no longer suffice. GDAP addresses this challenge by introducing a nuanced permission system that aligns with modern security best practices. By implementing role-based access control (RBAC), GDAP ensures that service providers like SoftwareOne can only access the specific resources needed to support your operations, nothing more. This granular control significantly reduces security risks while maintaining operational efficiency.
GDAP transforms your cloud security posture through several key advantages:
Enhanced and efficient support – GDAP empowers SoftwareOne’s support teams to respond to your technical needs faster, tackling incidents swiftly and with the precision your business deserves.
Precision-controlled access – Rest assured, our access is limited strictly to what’s necessary and only for as long as needed. You set the rules with flexible, time-bound control that can be revoked at your discretion. It’s support on your terms.
Ultimate flexibility – Maintain full command of your cloud environments, like Azure or Microsoft 365, by setting the boundaries for scope and access duration. With SoftwareOne, you’re always in control.
Streamlined issue resolution – GDAP accelerates our ability to resolve your issues, turning potential downtime into uptime and ensuring smooth, reliable operations that drive your success.
Enhanced compliance and security – As advocates of least-privileged access, GDAP ensures that our support activities align with stringent security protocols, reinforcing your trust in our commitment to safeguarding your cloud resources.
Seamless support aligned with your policies – GDAP enables us to adapt to your specific access controls, reinforcing your security policies and fostering a relationship built on trust and transparency.
GDAP implementation requires collaboration between your organization and SoftwareOne. Global administrators from your organization can approve GDAP relationships.
Operating without GDAP exposes your organization to several challenges:
Incomplete support capabilities – Unlock SoftwareOne’s full suite of capabilities and expertise by enabling GDAP, ensuring your platform and support configurations are fully optimized.
Delayed support response – Each support request requires manual access approval, potentially extending resolution times from minutes to hours.
Business continuity risks – During critical incidents, delays in granting access could lead to extended system downtimes.
Restricted support ability – Without GDAP, our teams face limitations in delivering prompt support, reducing the quality of service we are dedicated to providing.
Reduced operational efficiency – Continuously requesting access permissions takes time that could be spent solving your issues, impacting customer satisfaction, and the support experience.




This topic describes the key points to keep in mind when establishing a GDAP or a partner relationship request with SoftwareOne.
To establish a GDAP admin relationship, make sure that your primary domain name or tenant ID in the purchase order matches the details in the Microsoft 365 Admin Center or Microsoft Azure Management Portal.
There are a few ways you can verify your domain name and ID:
Using the Marketplace Platform – You can verify your domain name and ID by navigating to the Parameters tab on the order details page.
The domain name for existing cloud accounts is displayed in the Existing domain name field. For new cloud accounts, the Primary domain name field shows the domain name.
The tenant ID is displayed in the Fulfillment section.
Using Microsoft 365 Admin Center – You can verify your domain name and ID by signing in to and navigating to Settings > Domains. The domain name is displayed on the Domains page.
Using the Azure Portal – You can verify your domain name and ID by signing in to the and navigating to Entra ID > Overview. Your registered primary domain is displayed in the Name section.
To establish a successful partner and GDAP admin relationship, both SoftwareOne and your organization must operate within the same Microsoft-defined regional market.
For instance, SoftwareOne Brazil can only transact with customers in Brazil. For details on the CSP regions and markets, see the section in Microsoft's documentation.
The SoftwareOne region applicable to your order is also listed in your purchase order in the Marketplace Platform. To verify, open the details page of your order and select the Details tab. The References section displays the region.
You can also verify your organization's region in the Microsoft 365 Admin Center. To do this, sign in to the admin center and navigate to Settings > Org Settings > Organization Information. The name is displayed in the Country or region field.
The user setting up the partner and GDAP admin relationship must meet the following requirements for their primary domain or tenant:
Role – Global Administrator
User type – Member
User principal name – Must have no reference to 'external'
Identity – Must match the tenant’s name for the partnership





