Version: 1.0 | Last Updated: 02 June 2026 | Xzopia Limited (NI620366)
This runbook covers the day-to-day and periodic management of Xzopia's GDAP relationships
across 70+ client tenants. Read alongside docs/gdap-role-template.md for the role
definitions and group architecture.
Partner Center URL: https://partner.microsoft.com/dashboard/v2/customers/expiringgranularrelationships
Expiring Relationships URL: https://partner.microsoft.com/dashboard/v2/customers/expiringgranularrelationships
Xzopia-Primary-[ClientShortName] (must be unique, visible to customer).docs/gdap-role-template.md.Subject: Microsoft Admin Access — Action Required
Hi [Name],
As part of our ongoing service management we're updating our admin access permissions to
use Microsoft's latest security model (GDAP — Granular Delegated Admin Privileges).
This replaces the broader legacy access with specific, time-limited permissions.
To approve, please click the link below and sign in with your Microsoft 365 Global Admin
account. The process takes about 60 seconds.
[PASTE APPROVAL LINK]
If you have any questions please reply to this email or call us on [phone].
Thanks,
[Your name] | Xzopia Limited
Once the customer approves the relationship:
GDAP-Xzopia-Helpdesk → assign: Helpdesk Administrator, User Administrator,GDAP-Xzopia-Technical → assign: Intune Administrator, SharePoint Administrator,GDAP-Xzopia-SecurityCompliance → assign: Security Administrator, ComplianceGDAP-Xzopia-Billing → assign: Billing Administrator, License Administrator,Note: Role assignments do not require customer action — only the initial relationship
approval requires the customer's involvement.
Only create this when a specific task genuinely requires Global Administrator.
Xzopia-GlobalAdmin-[ClientShortName]-[YYYYMMDD] (include date so it's traceable).GDAP-Xzopia-GlobalAdmin group in Entra ID ifLog every Global Admin relationship in the client's record in ITFlow, including:
date created, reason, date terminated, who had access.
For relationships that exist but have auto-extend disabled (and contain no Global Admin role):
Note: You cannot enable auto-extend on relationships that include Global Administrator.
Those relationships must be handled via the two-relationship architecture — create a new
primary relationship (no Global Admin, auto-extend on) and a separate Global Admin
relationship (short-duration, no auto-extend).
Run this audit quarterly, or any time a client reports access issues.
Red flags that require immediate action:
Run on the first Monday of each month. Takes approximately 15 minutes.
Step 1 — Expiry review
Visit: https://partner.microsoft.com/dashboard/v2/customers/expiringgranularrelationships
Review any relationships showing within 60 days of expiry. Confirm auto-extend is on.
For any that show auto-extend disabled and Global Admin present, plan a new relationship
request within the next 2 weeks.
Step 2 — New client check
Any clients onboarded since last month — confirm both primary and Global Admin relationships
are created, security groups assigned, and auto-extend enabled on the primary.
Step 3 — Group membership check
In Entra ID (partner tenant), confirm GDAP-Xzopia-GlobalAdmin is empty unless a specific
active task requires it. Remove any members who no longer need break-glass access.
Step 4 — Access test
Pick 3 client tenants at random and confirm Partner Center shows all 4 security groups
assigned. Test one role-gated action per tenant (e.g. view users in M365 admin centre).
Step 5 — Log
Record the date of the check and any actions taken in ITFlow under the GDAP maintenance
task. Flag anything that needs follow-up.
When a client relationship ends:
| Resource | URL |
|---|---|
| Partner Center Customers | https://partner.microsoft.com/commerce/customers/list |
| Expiring GDAP Relationships | https://partner.microsoft.com/dashboard/v2/customers/expiringgranularrelationships |
| GDAP Role Guidance (Microsoft) | https://learn.microsoft.com/en-us/partner-center/customers/gdap-least-privileged-roles-by-task |
| GDAP FAQ (Microsoft) | https://learn.microsoft.com/en-us/partner-center/customers/gdap-faq |
| Auto-Extend Documentation | https://learn.microsoft.com/en-us/partner-center/customers/expiring-gdap-relationships-and-auto-extend-gdap |
| Xzopia Entra ID (Partner Tenant) | https://entra.microsoft.com |
Xzopia Limited (NI620366) | simon@xzopia.com | Bangor, Northern Ireland