EIDTNT-015: Privileged Partner Delegated Admin Access (GDAP)
- Platform
- Entra ID / M365
- Category
- Entra ID Tenant Configuration
- Severity
- High
- Zero Trust pillar
- Identity (weight 3)
- Golden fixtures
- 5
- Branch coverage
- Observed: fixtures prove the verdicts they exercise
- Provenance
- original
What it checks
Granular Delegated Admin Privileges (GDAP) let a CSP or managed-services partner hold standing administrative roles in your tenant. This relationship is invisible in most day-to-day admin views, is rarely reviewed, and is a Kaseya-class propagation path: an attacker who compromises one partner inherits delegated administration in every downstream customer tenant at once. A partner relationship that carries a Tier-0 / high-impact directory role (Global Administrator, Privileged Role Administrator, Privileged/Authentication Administrator, Security Administrator, User/Password/Application/Cloud Application Administrator) is effectively an external set of keys to the kingdom. This check inventories active delegatedAdminRelationships and FAILS when any active relationship grants one of those privileged roles; it warns when non-privileged partner access exists so it can be confirmed and scoped, and passes only when there is no active partner delegated administration. Empty results are treated as 'no relationships' only when the collection succeeded — a failed call surfaces as Not Assessed, never as a clean pass.
Recommended value
No active GDAP relationship grants a privileged directory role; partner access is least-privilege, time-bound, and reviewed
Remediation
Review every active partner delegated admin (GDAP) relationship in Microsoft Entra admin center > Identity > External Identities > Cross-tenant access (Partner-led) and in the Microsoft 365 admin center > Settings > Partner relationships. For each relationship, remove Tier-0 / high-impact roles (Global Administrator, Privileged Role Administrator, Privileged Authentication Administrator, Security Administrator, User/Password/Application/Cloud Application Administrator) unless there is a documented, time-bound need. Replace standing privileged delegation with least-privilege roles, request just-in-time elevation through the partner's own PIM where possible, and terminate any relationship that is no longer required. Confirm the partner's own tenant enforces phishing-resistant MFA for the admins who exercise this access.
Fixture-proven verdicts
Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.
| Scenario | Expected verdict |
|---|---|
| no-partners | PASS |
| not-assessed | Not Assessed |
| privileged | FAIL |
| scoped | WARN |
| terminated-only | PASS |
Framework mappings
- NIST SP 800-53
- AC-2, AC-3, AC-6, PS-7, SA-9
- CIS M365 Benchmark
- 1.1.3