Microsoft GDAP: onboard M365 clients the right way
If you manage Microsoft 365 for clients, Granular Delegated Admin Privileges (GDAP) is the modern consent model. Dual-Strike XISEM Microsoft GDAP onboarding path connects Entra ID and M365 telemetry without legacy DAP surprises.
Route: Settings → Integrations → Microsoft · Support wiki → GDAP onboarding
Why GDAP matters
• Broad permanent admin — Time-bound, least-privilege roles
• Hard to audit — Explicit relationship in Partner Center
• Security pushback from clients — Industry-standard MSP pattern
XISEM surfaces fed by GDAP Gateway
Once GDAP relationship is active and the Gateway is configured:
• Entra sign-ins and risky user signals
• Conditional Access intelligence (evaluation context, not enforcement)
• MIP join/move/leave correlation with HR/PSA when available
• Compliance identity and access controls
• COBRA² identity drift rules
Onboarding checklist (public)
1. Establish GDAP in Microsoft Partner Center with agreed roles
2. In Dual-Strike XISEM, add Microsoft integration for the client org
3. Complete admin consent flow (client approves)
4. Validate sign-in events appear in Asset/identity timelines within 24h
5. Enable CA intelligence and identity detections incrementally
Client conversation script
“We request GDAP with specific Entra roles for 730 days, aligned to what Dual-Strike XISEM needs for identity correlation and compliance reporting — not global permanent admin.”
Adjust duration and roles to your contract.
Troubleshooting (operator-facing)
• No sign-ins: consent scope or GDAP relationship expired — re-check Partner Center
• Partial tenant: guest users vs. member users filter in identity views
• Multi-tenant MSP: ensure correct client org selected in console scope
Related: Conditional Access intelligence post · MIP NHI governance deep dive
Link: dual-strike.com · Request demo for GDAP walkthrough
No tenant IDs or internal consent URLs — configure per client in-console.


