Creating a GDAP relationship

Steve Barsamian 0 Reputation points
2026-05-05T13:26:01.86+00:00

when creating a gdap relationship, are the security groups created automatically based on Entra roles - or do they need to be added manually? Copilot seems to suggest they are created automatically but I'm doubtful.

Microsoft Partner Center | Other
0 comments No comments

1 answer

Sort by: Oldest
  1. AI answer

    2026-05-05T13:26:13.2966667+00:00

    Security groups for GDAP are not created automatically based on Microsoft Entra roles. They must be created and managed manually in the partner tenant, and then roles are assigned to those groups.

    Key points:

    1. Manual creation of security groups
      • For GDAP, partners create their own security groups (for example, “Azure Managers”) in Microsoft Entra ID.
      • These groups are then used in GDAP relationships to control which partner users get which roles and access.
      • This is explicitly described where partners are instructed to “Create a security group, assign approved roles, and then assign partner tenant users to that security group.”
    2. Roles are assigned to security groups, not the other way around
      • GDAP works by assigning Microsoft Entra roles (Directory Reader, Global Reader, etc.) to security groups, and then associating those groups with the customer via the GDAP relationship.
      • Roles do not auto-generate groups; instead, existing groups are selected and roles are applied to them.
    3. Special case: Microsoft-led transition
      • In the Microsoft-led DAP→GDAP transition, Microsoft uses predefined CSP security groups (Admin Agents, Helpdesk Agents) and automatically assigns a set of Microsoft Entra roles to those existing groups.
      • Even here, the roles are added to predefined groups; the documentation does not state that new groups are created automatically per role.
    4. Indirect resellers and other partners
      • Indirect resellers, indirect providers, and direct-bill partners all create GDAP relationship requests and must ensure that “security groups created in partner tenant with partner users are selected” and that “the desired Microsoft Entra roles are assigned to the security group.”

    Therefore, when creating a GDAP relationship, expect to:

    1. Create or choose security groups in the partner tenant.
    2. Assign Microsoft Entra roles to those groups.
    3. Use those groups in the GDAP relationship. Roles do not automatically create new security groups.

    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.