← All Roles

Customer Delegated Admin Relationship Administrator

Enabled
Versionv1
Date Added2026-06-21
CategorysecurityAndCompliance
Assignment Modeallowed
Built-inYes
Template IDfc8ad4e2-40e4-4724-8317-bcda7503ecbf

Description

Manage all aspects of granular delegated admin privileges (GDAP) relationships in a customer tenant.

Details

Assign the Customer Delegated Admin Relationship Administrator role to users who need to do the following tasks:

  • Accept a granular delegated admin privileges (GDAP) relationship from a partner for their tenant.
  • List and view GDAP relationships with partners.
  • Terminate a GDAP relationship with a partner.

Directory Actions2

  • microsoft.commerce.tenantRelationships/customerDelegatedAdminPrivileges/allProperties/allTasks
  • microsoft.office365.webPortal/allEntities/standard/read

Graph API Permissions13

Microsoft do not provide a direct mapping between Directory actions and Graph API permissions, despite this being necessary for delegated (interactive) access. MSAdminRoles.com has meticulously compiled a list of the Graph API permissions that each built-in admin role enables you to utilise. Please note this listing is not 100% accurate. Graph API permissions and Entra RBAC operate as two independent authorisation planes and do not map to each other on a one-to-one basis.

  • Directory.Read.All
  • TenantGovernance-Invitation.Read.All
  • TenantGovernance-Invitation.ReadWrite.All
  • TenantGovernance-PolicyTemplate.Read.All
  • TenantGovernance-PolicyTemplate.ReadWrite.All
  • TenantGovernance-RelatedTenant.Read.All
  • TenantGovernance-RelatedTenant.ReadWrite.All
  • TenantGovernance-Relationship.Read.All
  • TenantGovernance-Relationship.ReadWrite.All
  • TenantGovernance-Request.Read.All
  • TenantGovernance-Request.ReadWrite.All
  • TenantGovernance-Setting.Read.All
  • TenantGovernance-Setting.ReadWrite.All