EIDTNT-015: Privileged Partner Delegated Admin Access (GDAP)
- Plataforma
- Entra ID / M365
- Categoría
- Entra ID Tenant Configuration
- Severidad
- High
- Pilar de Zero Trust
- Identity (peso 3)
- Fixtures de referencia
- 5
- Cobertura de ramas
- Observada: los fixtures prueban los veredictos que ejercitan
- Procedencia
- original
Qué comprueba
Granular Delegated Admin Privileges (GDAP) let a CSP or managed-services partner hold standing administrative roles in your tenant. This relationship is invisible in most day-to-day admin views, is rarely reviewed, and is a Kaseya-class propagation path: an attacker who compromises one partner inherits delegated administration in every downstream customer tenant at once. A partner relationship that carries a Tier-0 / high-impact directory role (Global Administrator, Privileged Role Administrator, Privileged/Authentication Administrator, Security Administrator, User/Password/Application/Cloud Application Administrator) is effectively an external set of keys to the kingdom. This check inventories active delegatedAdminRelationships and FAILS when any active relationship grants one of those privileged roles; it warns when non-privileged partner access exists so it can be confirmed and scoped, and passes only when there is no active partner delegated administration. Empty results are treated as 'no relationships' only when the collection succeeded — a failed call surfaces as Not Assessed, never as a clean pass.
Valor recomendado
No active GDAP relationship grants a privileged directory role; partner access is least-privilege, time-bound, and reviewed
Remediación
Review every active partner delegated admin (GDAP) relationship in Microsoft Entra admin center > Identity > External Identities > Cross-tenant access (Partner-led) and in the Microsoft 365 admin center > Settings > Partner relationships. For each relationship, remove Tier-0 / high-impact roles (Global Administrator, Privileged Role Administrator, Privileged Authentication Administrator, Security Administrator, User/Password/Application/Cloud Application Administrator) unless there is a documented, time-bound need. Replace standing privileged delegation with least-privilege roles, request just-in-time elevation through the partner's own PIM where possible, and terminate any relationship that is no longer required. Confirm the partner's own tenant enforces phishing-resistant MFA for the admins who exercise this access.
Veredictos probados con fixtures
Cada veredicto de esta tabla está probado por un fixture de referencia en la suite de pruebas que valida el módulo. La tabla se deriva de la última ejecución en verde; no puede editarse a mano.
| Escenario | Veredicto esperado |
|---|---|
| no-partners | PASS |
| not-assessed | Not Assessed |
| privileged | FAIL |
| scoped | WARN |
| terminated-only | PASS |
Mapeos a marcos de referencia
- NIST SP 800-53
- AC-2, AC-3, AC-6, PS-7, SA-9
- CIS M365 Benchmark
- 1.1.3