Last Updated on August 7, 2025 by Arnav Sharma
Microsoft is committed to providing enhanced security practices across its platforms. As part of this effort, the company is facilitating a transition from Delegated Admin Privileges (DAP) to Granular Delegated Admin Privileges (GDAP) for the management of Azure, Microsoft 365, and other cloud resources, marking a shift in how DAP permissions are assigned and managed. This change offers benefits for all involved—Microsoft, different Microsoft partners, and customers, fostering a more secure and manageable environment. partners, and customers.
DAP and GDAP: An Overview
- DAP (Delegated Admin Privileges): Traditionally, Cloud Solution Providers (CSPs), indirect resellers, and other Microsoft partners used DAP to manage their customers’ services. DAP provided partners with global administrator access across a customer’s entire tenant.
- GDAP (Granular Delegated Admin Privileges): GDAP is a more refined permissions model. Instead of broad administrative access, GDAP allows partners to assign specific roles and permissions for precise tasks required to manage customer environments.
Why is Microsoft Transitioning from DAP to GDAP?
The move from DAP to GDAP is fundamentally about security. DAP’s extensive permissions posed unnecessary security risks. With GDAP, monitoring is enhanced, including default GDAP reporting. partners and Microsoft work together to establish a “least privilege” model, minimizing potential attack surfaces and vulnerabilities.
Key Points:
- Transition to GDAP as Soon as Possible: It’s imperative for partners to proactively transition their existing DAP relationships to GDAP. Microsoft is phasing out support for DAP.
- Create GDAP Relationships: Microsoft Partners should prioritize using GDAP for all new customer relationships. The process is straightforward via the Microsoft Partner Center.
- Use Microsoft 365 Lighthouse: For multi-tenant management, use Microsoft 365 Lighthouse to leverage GDAP relationships effectively.
- GDAP Security: GDAP is inherently more secure due to its granular permissions model compared to the widespread privileges of DAP.
The DAP to GDAP Transition Process
- Create a GDAP Relationship: Partners initiate the process in the Partner Center. The customer receives a request to accept a GDAP relationship request.
- GDAP Takes Precedence Over DAP: Once a GDAP relationship is established, new DAP relationships are also considered for future adjustments. GDAP permissions take precedence, enhancing security controls.
- Remove DAP: Microsoft recommends that partners remove DAP relationships after moving customers from DAP to GDAP. This can be done in the Partner Center or with the GDAP bulk migration tool.
- Microsoft will remove the DAP relationship if no additional activity takes place within 30 days after the partner has established a new GDAP relationship.
GDAP’s Advantages
- Enhanced Security: Limits potential cyber-attack surfaces while still providing partners with the necessary level of access.
- Improved Role Assignment: GDAP simplifies role management, using the principle of least privilege to prevent inadvertent security compromises.
- Customer Trust: GDAP ensures customers that partners only have the permissions required to perform authorized tasks, relying on the stringent application of new DAP relationships and permissions.
Important Considerations
- Microsoft will stop granting DAP for new customer environments. Existing DAP relationships may be subject to additional Microsoft service restrictions.
- Microsoft’s transition from DAP to GDAP includes Azure, Microsoft 365, Dynamics 365, and Microsoft Power Platform.
The Shift from DAP to GDAP: Conclusion
The move to GDAP aligns with Microsoft’s commitment to securing its cloud solutions. While requiring adjustment for partners, GDAP provides significantly improved security compared to DAP. Here’s what Microsoft partners need to do:
- Create GDAP relationships whenever possible and migrate from DAP
- Use GDAP as the default administration model for customer tenants.
- Enable a ‘least privilege’ security model to better protect customer resources.
I help organisations secure their cloud infrastructure and stay ahead of evolving cyber threats. Microsoft MVP and Certified Trainer, author of Mastering Azure Security, and founder of arnav.au — a platform for practical Cloud, Cybersecurity, DevOps and AI content.
Frequently Asked Questions
DAP (Delegated Admin Privileges) provides partners with broad global administrator access across an entire customer tenant, while GDAP (Granular Delegated Admin Privileges) allows partners to assign specific roles and permissions for precise tasks only. GDAP follows a 'least privilege' model, minimizing unnecessary access and reducing security risks compared to DAP's extensive permissions.
Microsoft is transitioning to GDAP primarily for security reasons. DAP's extensive permissions posed unnecessary security risks and created larger attack surfaces for potential vulnerabilities. GDAP's granular permissions model, combined with enhanced monitoring and reporting, provides a more secure environment that aligns with modern security best practices.
Partners should proactively migrate existing DAP relationships to GDAP through the Microsoft Partner Center. Once a GDAP relationship is established, it takes precedence over DAP. Microsoft will automatically remove the DAP relationship if no additional activity occurs within 30 days after establishing a new GDAP relationship, though partners can also manually remove DAP relationships using the Partner Center or bulk migration tool.
No, Microsoft will stop granting DAP for new customer environments. All new customer relationships should use GDAP instead, which can be initiated through the Microsoft Partner Center. Additionally, existing DAP relationships may be subject to additional Microsoft service restrictions as the company phases out DAP support.
Partners can create and manage GDAP relationships through the Microsoft Partner Center, where customers receive and accept GDAP relationship requests. For multi-tenant management, Microsoft 365 Lighthouse is recommended to leverage GDAP relationships effectively and simplify role management across multiple customer environments.