Why Your MSP Shouldn’t Need Global Admin Access Anymore
Here is a question almost no business asks its managed service provider: “Do you have Global Admin access to our tenant, and if so, why?” Most companies never think to ask. Most MSPs never volunteer the answer. Yet Microsoft itself has spent the last several years actively moving partners away from exactly this model, replacing it with a scoped, time-bound alternative called GDAP, delivered in practice through a free portal called Microsoft 365 Lighthouse.
The reason is not theoretical. According to Microsoft’s own 2025 Digital Defense Report, identity-based attacks surged by 32% in just the first half of 2025, and more than 97% of identity attacks are password-based. A compromised credential is not a rare event, it is the most common way attackers get in. If that compromised credential happens to belong to an MSP holding standing Global Admin access, the damage is no longer contained to one company. It is every customer that MSP touches.
Here is what changed, why Microsoft made the change, and what to ask your MSP about it.
WHAT YOU WILL LEARN
- Why standing Global Admin access for MSPs became a serious security liability
- Exactly what GDAP (Granular Delegated Admin Privileges) changes, feature by feature
- How Microsoft 365 Lighthouse puts least-privilege access into practice
- How Cloud 9 Infosystems specifically implements this model, not just references it
THE SHORT VERSION
- According to Microsoft, identity-based attacks surged by 32% in the first half of 2025 alone, and over 97% of them are password-based, making compromised credentials a routine event, not an edge case.
- Under the older model, Delegated Admin Privileges (DAP), an MSP’s access defaulted to Global Administrator on a customer’s tenant, with no time limit and no restriction on what it could do.
- GDAP replaces that model with least-privileged, time-bound access, and Microsoft 365 Lighthouse is the free portal that puts GDAP into practice for MSPs managing many customers at once.
- Cloud 9 Infosystems runs on this exact model. This article explains both the Microsoft standard and specifically how we implement it.
The Access Model Most Businesses Never Think to Question
For years, the standard way an MSP connected to a customer’s Microsoft 365 or Azure environment was through a relationship called Delegated Admin Privileges, or DAP.
Under DAP, access defaulted to Global Administrator, with no expiration. Setting up a DAP relationship in Partner Center automatically granted the partner the Global Admin role on the customer’s tenant. That access had no time limit and no restriction on which actions it could perform. The partner could do anything a Global Admin could do, indefinitely, until someone manually removed the relationship.
That is a real, quantifiable security exposure, not a theoretical one. According to Microsoft’s 2025 Digital Defense Report, identity-based attacks surged by 32% in the first half of 2025 alone, and more than 97% of all identity attacks are password-based, meaning the vast majority of malicious sign-in attempts against any organization are large-scale password guessing, not sophisticated exploits. If an MSP’s own account or systems are compromised this way, and Microsoft’s own data says that outcome is common, every customer tenant connected through standing Global Admin access becomes reachable too.
One compromised MSP credential should never be a master key to every one of that MSP’s clients. Microsoft’s own attack data confirms that credential compromise is common. The question is whether your MSP’s access model turns a common event into a catastrophic one.
Microsoft’s fix for this exposure is GDAP, delivered in practice through Microsoft 365 Lighthouse, a free portal purpose-built for MSPs to manage customer tenants under exactly this least-privilege model. Both are covered in detail below. This is the same principle behind proactive, governed security we cover in our AI agent security and Zero Trust guide: access should be scoped to what is actually needed, not granted broadly for convenience.
GDAP vs. DAP: What Actually Changed, Feature by Feature
Microsoft’s answer to this problem is GDAP, Granular Delegated Admin Privileges, and the shift is not cosmetic. Here is exactly what changed, side by side.
|
Feature |
DAP (old model) |
GDAP (current model) |
|
Default role granted |
Global Administrator |
Lower, read-only access by default |
|
Access duration |
Indefinite, no expiration |
Time-bound, 30 to 730 days |
|
Scope of access |
Broad, full administrative control |
Granular, specific named roles |
|
Customer consent |
One-time relationship approval |
Explicit approval per role requested |
|
Access per customer |
Same broad access across all customers |
Access can be partitioned per customer |
|
Audit visibility |
Limited tracking of specific actions |
Actions tied to scoped roles, more auditable |
|
Blast radius if compromised |
Every connected customer tenant |
Contained to that specific customer and role |
According to Microsoft’s own documentation, GDAP is a security feature that provides partners with least-privileged access following the Zero Trust cybersecurity protocol. It lets a partner configure access that is both granular, scoped to specific roles and tasks, and time-bound, expiring automatically rather than persisting indefinitely.
The default has fundamentally flipped. Microsoft’s Partner Center documentation states plainly that partners managing Azure no longer receive the Global Admin role on a customer’s tenant by default. Instead, they receive lower permissions to read a customer directory, and must be explicitly granted anything beyond that, scoped to the specific workload they are supporting.
Microsoft has been direct about why. Microsoft’s own GDAP guidance states that GDAP is replacing DAP “to ensure that we provide a more secure solution for our partners and customers,” and recommends that partners transition their customers to GDAP as soon as possible.
Not sure what level of access your current MSP holds in your environment?
In a free 30-minute consultation, Cloud 9 Infosystems will review exactly what access your current provider has, explain what a least-privilege model should look like, and show you how our own tenant access is structured.
How Microsoft 365 Lighthouse Puts This Into Practice
Knowing the rules changed is one thing. Seeing how a modern MSP actually operates under them is another.
Microsoft 365 Lighthouse is the practical expression of the GDAP model. It is Microsoft’s own multi-tenant management portal, built specifically for MSPs to secure and manage customer environments at scale, and it uses GDAP as its foundation rather than the older DAP model.
It replaces broad standing access with structured, auditable delegation. Through Lighthouse, an MSP requests specific, named roles, such as Security Administrator or Intune Administrator, rather than Global Admin. Those access assignments carry time-bound expiration, customers retain visibility and control over exactly what has been delegated, and every administrative action taken by the MSP is tracked in audit logs.
It also standardizes security, not just access. Lighthouse applies a default security baseline built for small and medium-sized businesses, so tenant configurations follow a consistent, Microsoft-recommended standard rather than varying by which technician happens to set up a given customer.
This is precisely the operational discipline we outlined in What Makes a Modern MSP? 6 Signs to Look For in 2026: connected platforms, documented process, and centralized visibility are only trustworthy if the access underneath them is actually scoped and accountable. GDAP and Lighthouse are what make that trust verifiable rather than assumed.
How Cloud 9 Infosystems Specifically Implements This Model
Most MSPs will tell you they follow Microsoft’s security recommendations. Here is specifically what that means in how Cloud 9 Infosystems operates, not just what we reference.
We hold Microsoft’s highest managed services designation, and it requires exactly this discipline. Cloud 9 is a Microsoft Azure Expert Managed Services Provider, a designation held by fewer than 1% of Microsoft partners globally and awarded only after a rigorous, audit-based review of governance model, technical practices, and customer outcomes. As a Tier-1 Cloud Solution Provider procuring directly from Microsoft, we operate under the same access framework Microsoft audits every Azure Expert MSP against.
Every customer relationship we manage runs on GDAP, not DAP. We do not request Global Admin as a default. Access is requested per workload, whether that is Microsoft Entra ID, Intune, Exchange Online, or a specific Azure subscription, and scoped to what that engagement actually requires.
Access is time-bound and reviewed on a defined cadence, not left standing indefinitely. Role assignments carry expiration dates in line with Microsoft’s guidance, and we proactively renew or revoke access rather than letting relationships persist by default.
Our Security, Compliance & Governance pillar is built around this same standard. Identity and access management across Azure and Microsoft 365, Microsoft’s Zero Trust framework implementation, and audit reporting for frameworks like SOC 2 and HIPAA are core to how we operate every customer environment, detailed on our managed services page.
We will show you the specifics, not just describe them. Any prospective or current client can ask to see exactly what roles we hold in their tenant, when that access expires, and what the audit trail shows. That transparency is the actual test of whether a least-privilege model is real or just a talking point.
What This Means for Choosing (or Reevaluating) Your MSP
You do not need to understand the technical details of GDAP to ask the right question. You need to know what a good answer sounds like.
Ask your MSP directly what access they hold in your tenant today. A specific answer, naming particular roles, an expiration date, and a documented approval, is a good sign. A vague answer, or one that amounts to “we have full access so we can help you faster,” is worth pushing on.
Ask whether that access is time-bound or standing. Under Microsoft’s current guidance, and given Microsoft’s own data on how routinely identity credentials are compromised, there is no good reason for an MSP to hold indefinite, unrestricted access to your environment in 2026.
Ask how access is scoped per workload. A provider managing your email security should not necessarily also hold administrative rights over your device management or your Azure subscriptions, unless that is the actual scope of the engagement.
The Bottom Line for Businesses Working With an MSP
Standing Global Admin access made sense when convenience mattered more than the threat landscape did. That tradeoff no longer holds. Microsoft’s own attack data shows identity compromise is common and accelerating, and Microsoft has rebuilt its own partner access model in direct response, around least privilege and time-bound scope.
The right question is not whether your MSP is trustworthy in the abstract. It is whether the access they hold in your environment today is something they could explain, justify, and show you in five minutes. If it is not, that is worth a conversation before it becomes a real incident.
Microsoft Resources Referenced in This Article
- Extortion and ransomware drive over half of cyberattacks (Microsoft Digital Defense Report 2025) (Microsoft On the Issues)
- Granular delegated admin privileges (GDAP) introduction (Microsoft Learn)
- GDAP frequently asked questions (Microsoft Learn)
- Overview of Microsoft 365 Lighthouse (Microsoft Learn)
- Microsoft 365 Lighthouse requirements (Microsoft Learn)
Frequently Asked Questions
Why shouldn't my MSP have Global Admin access to my tenant?
Standing Global Admin access means an MSP can perform any administrative action in your environment indefinitely, with no time limit. According to Microsoft’s 2025 Digital Defense Report, more than 97% of identity attacks are password-based, and identity attacks surged 32% in the first half of 2025 alone, so a compromised MSP credential is a realistic, common event, not a rare one. If that credential holds Global Admin, every customer tenant connected through that access becomes exposed.
What is GDAP?
GDAP stands for Granular Delegated Admin Privileges. According to Microsoft, it is a security feature that gives partners least-privileged, time-bound access to a customer’s specific workloads, following Zero Trust principles, replacing the older Delegated Admin Privileges (DAP) model that defaulted to standing Global Admin access.
What is the actual difference between DAP and GDAP?
DAP granted Global Administrator by default, with no expiration and broad access across every connected customer. GDAP scopes access to specific named roles, requires explicit customer consent per role, expires automatically between 30 and 730 days, and can be partitioned per customer, so a compromised relationship with one client does not expose every other client.
Does GDAP mean my MSP has less ability to help me?
No. GDAP scopes access to what a task actually requires, such as Helpdesk Administrator or Intune Administrator roles, rather than removing an MSP’s ability to do its job. A well-run MSP will request exactly the access needed for the services they provide, and nothing more.
What is Microsoft 365 Lighthouse?
Microsoft 365 Lighthouse is Microsoft’s own multi-tenant management portal for MSPs, built on the GDAP access model. It lets partners manage and secure customer tenants at scale using scoped, time-bound access, standardized SMB security baselines, and centralized, auditable visibility across every customer environment.
How does Cloud 9 Infosystems specifically implement least-privilege access?
Cloud 9 requests GDAP access scoped per workload rather than Global Admin by default, applies time-bound role assignments reviewed on a defined cadence, and will show any customer the specific roles held in their tenant and the audit trail of activity. This is audited as part of our Microsoft Azure Expert MSP designation, held by fewer than 1% of Microsoft partners globally.
Want to Know Exactly What Access Your MSP Holds in Your Environment?
Most businesses have never actually reviewed this. Cloud 9 Infosystems will walk you through what a least-privilege, GDAP-based access model looks like, and how it compares to what your current provider has in place today.
Recent Posts

Why Your MSP Shouldn’t Need Global Admin Access Anymore
Why should your MSP have Global Admin access? Explore Microsoft GDAP and Microsoft 365 Lighthouse, and learn how least-privilege, time-bound access strengthens security across Azure and Microsoft 365 environments and reduces credential risk.

Agentic AI in the Enterprise: Moving Beyond Copilot to Intelligent Workflows
Explore how Agentic AI moves enterprise AI beyond Copilot into intelligent workflows. Learn how AI agents automate business processes, connect Microsoft platforms, improve decisions, and scale securely with governance, data, and human oversight.

What Makes a Modern MSP? 6 Signs Smart Businesses Look For in 2026
Discover the six signs of a modern managed service provider (MSP), from connected platforms and AI-powered workflows to smarter routing, documentation, knowledge management, and continuous improvement for reliable IT outcomes for businesses in 2026.
Join Us on the Journey to Transforming Futures - Contact Us!
Schedule a meeting with our experts or fill out the form for a free assessment of your environment today!
*Cloud 9 reserves the right for free assessment eligibility.

