EIDTNT-015: Privileged Partner Delegated Admin Access (GDAP)

Platform
Entra ID / M365
Category
Entra ID Tenant Configuration
Severity
High
Zero Trust pillar
Identity (weight 3)
Golden fixtures
5
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
original

What it checks

Granular Delegated Admin Privileges (GDAP) let a CSP or managed-services partner hold standing administrative roles in your tenant. This relationship is invisible in most day-to-day admin views, is rarely reviewed, and is a Kaseya-class propagation path: an attacker who compromises one partner inherits delegated administration in every downstream customer tenant at once. A partner relationship that carries a Tier-0 / high-impact directory role (Global Administrator, Privileged Role Administrator, Privileged/Authentication Administrator, Security Administrator, User/Password/Application/Cloud Application Administrator) is effectively an external set of keys to the kingdom. This check inventories active delegatedAdminRelationships and FAILS when any active relationship grants one of those privileged roles; it warns when non-privileged partner access exists so it can be confirmed and scoped, and passes only when there is no active partner delegated administration. Empty results are treated as 'no relationships' only when the collection succeeded — a failed call surfaces as Not Assessed, never as a clean pass.

Recommended value

No active GDAP relationship grants a privileged directory role; partner access is least-privilege, time-bound, and reviewed

Remediation

Review every active partner delegated admin (GDAP) relationship in Microsoft Entra admin center > Identity > External Identities > Cross-tenant access (Partner-led) and in the Microsoft 365 admin center > Settings > Partner relationships. For each relationship, remove Tier-0 / high-impact roles (Global Administrator, Privileged Role Administrator, Privileged Authentication Administrator, Security Administrator, User/Password/Application/Cloud Application Administrator) unless there is a documented, time-bound need. Replace standing privileged delegation with least-privilege roles, request just-in-time elevation through the partner's own PIM where possible, and terminate any relationship that is no longer required. Confirm the partner's own tenant enforces phishing-resistant MFA for the admins who exercise this access.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for EIDTNT-015
ScenarioExpected verdict
no-partnersPASS
not-assessedNot Assessed
privilegedFAIL
scopedWARN
terminated-onlyPASS

Framework mappings

NIST SP 800-53
AC-2, AC-3, AC-6, PS-7, SA-9
CIS M365 Benchmark
1.1.3