Customer Delegated Admin Relationship Administrator
Enabled
Description
Manage all aspects of granular delegated admin privileges (GDAP) relationships in a customer tenant.
Details
Assign the Customer Delegated Admin Relationship Administrator role to users who need to do the following tasks:
- Accept a granular delegated admin privileges (GDAP) relationship from a partner for their tenant.
- List and view GDAP relationships with partners.
- Terminate a GDAP relationship with a partner.
Directory Actions2
microsoft.commerce.tenantRelationships/customerDelegatedAdminPrivileges/allProperties/allTasksmicrosoft.office365.webPortal/allEntities/standard/read
Graph API Permissions13
Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.
Directory.Read.AllTenantGovernance-Invitation.Read.AllTenantGovernance-Invitation.ReadWrite.AllTenantGovernance-PolicyTemplate.Read.AllTenantGovernance-PolicyTemplate.ReadWrite.AllTenantGovernance-RelatedTenant.Read.AllTenantGovernance-RelatedTenant.ReadWrite.AllTenantGovernance-Relationship.Read.AllTenantGovernance-Relationship.ReadWrite.AllTenantGovernance-Request.Read.AllTenantGovernance-Request.ReadWrite.AllTenantGovernance-Setting.Read.AllTenantGovernance-Setting.ReadWrite.All