Version: 1.0 | Last Updated: 02 June 2026 | Xzopia Limited (NI620366)
This document defines the standard GDAP (Granular Delegated Admin Privileges) role template
applied to all Xzopia-managed client tenants. Every new client relationship uses this exact
template — no ad-hoc role selection. Consistency ensures least-privilege, auditability, and
correct auto-extend behaviour.
Every client has exactly two GDAP relationships:
Why two relationships? Microsoft does not permit auto-extend on any GDAP relationship
that includes the Global Administrator role. Separating Global Admin into its own
short-lived relationship allows the operational relationship to auto-extend indefinitely,
removing the need for repeated customer approvals.
All five groups are created in the Xzopia partner tenant (not in client tenants).
Members are Xzopia staff. Role assignments propagate to all client tenants via GDAP.
GDAP-Xzopia-[Function]
GDAP-Xzopia-HelpdeskPurpose: Daily operations — password resets, user management, licence changes, support
tickets, MFA resets, shared mailbox management.
| Role | Reason |
|---|---|
| Helpdesk Administrator | Password resets for non-admin users |
| User Administrator | User/group creation, management, blocking |
| Authentication Administrator | MFA resets, authentication method management |
| License Administrator | Licence assignment and removal |
| Exchange Administrator | Mailbox management, shared mailboxes, transport rules |
| Service Support Administrator | Support ticket creation on behalf of customer |
| Directory Reader | Basic directory read for troubleshooting |
| Message Center Reader | Read Message Centre for service announcements |
| Groups Administrator | Add members/owners to groups |
| Security Reader | View security policies during troubleshooting |
| Guest Inviter | Invite B2B guest users |
| Printer Administration | Manage Universal Print configurations |
GDAP-Xzopia-TechnicalPurpose: Service configuration — Intune, SharePoint, Teams, device management, conditional
access review, desktop analytics.
| Role | Reason |
|---|---|
| Intune Administrator | Device policies, compliance, app deployment |
| SharePoint Administrator | Site permissions, storage, settings |
| Teams Administrator | Teams settings, policies, telephony |
| Exchange Administrator | Advanced mail flow, connectors, migration |
| Desktop Analytics Administrator | Endpoint analytics, hardware inventory |
| Printer Administration | Universal Print connector management |
| Authentication Administrator | Conditional access troubleshooting |
| Security Reader | Monitor security posture during technical work |
| Service Support Administrator | Escalate support tickets |
| Directory Reader | Directory read for technical diagnostics |
GDAP-Xzopia-SecurityCompliancePurpose: Security monitoring, compliance work, alerting. Relevant to Compliance Shield
(Phase 6) and Cyber Essentials assessments.
| Role | Reason |
|---|---|
| Security Administrator | Manage security policies, Defender settings |
| Compliance Administrator | Manage compliance policies, DLP, retention |
| Conditional Access Administrator | Create and modify CA policies |
| Security Reader | Read-only security monitoring across all services |
| Global Reader | Read-only view of all admin settings |
| Intune Administrator | Compliance policy visibility |
| Exchange Administrator | Mail flow security rules |
| Service Support Administrator | Open security-related support cases |
GDAP-Xzopia-BillingPurpose: Licence purchasing, subscription management, billing administration via Partner
Center and Microsoft 365 admin centre.
| Role | Reason |
|---|---|
| Billing Administrator | Subscription and billing management |
| License Administrator | Licence assignment and reporting |
| Domain Name Administrator | Domain verification and DNS management |
| Global Reader | Read billing and subscription details |
| User Administrator | User creation linked to licence onboarding |
| Service Support Administrator | Billing-related support tickets |
GDAP-Xzopia-GlobalAdmin (Break-Glass Only)Purpose: Emergency access for tasks that genuinely require Global Administrator. This group
should be empty by default. Add members only for the duration of a specific job, then remove.
| Role | Reason |
|---|---|
| Global Administrator | Break-glass only — tenant-level config, recovery tasks |
Important: This group is assigned to the separate 30-day Global Admin relationship,
not the primary operational relationship. Never assign Global Administrator to the primary
relationship.
When creating a new primary relationship in Partner Center, request all of the following
roles. This is the complete list covering Groups 1–4:
Total: 22 roles — no Global Administrator in this list.
| Setting | Primary Relationship | Global Admin Relationship |
|---|---|---|
| Duration | 730 days | 30 days |
| Auto-extend | Enabled | Disabled |
| Customer approval needed | Yes (initial only) | Yes (each creation) |
| Contains Global Admin | No | Yes |
| Roll-forward period | 6 months | N/A |
| Expiry notifications | Suppressed (auto-extends) | 30d, 7d, 1d before expiry |
Update this table after creating the groups in Entra ID.
| Group Name | Object ID |
|---|---|
| GDAP-Xzopia-Helpdesk | [populate after creation] |
| GDAP-Xzopia-Technical | [populate after creation] |
| GDAP-Xzopia-SecurityCompliance | [populate after creation] |
| GDAP-Xzopia-Billing | [populate after creation] |
| GDAP-Xzopia-GlobalAdmin | [populate after creation] |
Xzopia Limited (NI620366) | simon@xzopia.com | Bangor, Northern Ireland