With GDAP, you consent to the Neo app on behalf of your customers — no admin action needed in each tenant. Once connected, Neo operates in the tenant through app-only access, the same as Direct Consent for day-to-day automations. One difference today: resetting an admin’s password requires the optional Privileged Authentication Administrator grant (see Recommended roles) — ordinary-user resets work either way.
How it works
- Your MSP has an existing GDAP relationship with a customer tenant that includes two things: a role that can consent the Neo app — Application Administrator or Cloud Application Administrator — and a role that can grant app permissions and assign roles — Privileged Role Administrator, Global Administrator, or Partner Tier2 Support (included in Microsoft Lighthouse’s default relationships). Neither one covers both steps: Privileged Role Administrator alone cannot consent the app, and Cloud Application Administrator alone cannot grant Graph app roles
- In the Neo Dashboard, you configure which permission categories Neo should request (e.g., User Management, Security, Email) — see M365 Permissions
- You use your GDAP access to consent the Neo app in the customer tenant — no customer admin involvement needed
- Neo grants only the permissions matching your selected categories — nothing more
Prerequisites
Before connecting customer tenants via GDAP, ensure:- You have active GDAP relationships with your customer tenants in Partner Center. If you don’t have GDAP set up yet, follow Microsoft’s GDAP guide first.
- Your GDAP relationships include the right roles — at minimum Application Administrator (so Neo can consent its app; Cloud Application Administrator or Global Administrator work too), Privileged Role Administrator (so Neo can provision; Global Administrator or Partner Tier2 Support work too, and Lighthouse default relationships already include Tier2), and Exchange Administrator. Because relationships can’t be edited after creation, create new ones with the full recommended role set.
- The account you connect Neo with is in a group assigned those roles — a relationship including a role isn’t enough; the connected account’s security group must carry it. See Make sure your connected account can provision.
- You have admin access to your MSP’s partner tenant (the Entra ID tenant enrolled in CSP).
Recommended roles
Neo acts in each customer tenant app-only — through its own application, using the Microsoft Graph permissions you pick in your M365 permission profile. Neo itself only needs the roles it uses to set that up, plus the ones it assigns to its own app — the three in the first table below. Beyond those three, we suggest creating your relationships with the full role set below. It covers the ground MSPs most commonly automate with Neo — identity, authentication, security, devices, Exchange, Teams, SharePoint. Include the full set up front — a GDAP relationship cannot be edited after creation, and adding a role later means creating a new relationship and re-approving it in every customer tenant.Required by Neo
Suggested for the relationship
We suggest all of these. Neo doesn’t strictly need them to provision, but they cover the day-to-day MSP work customers put Neo on — password resets, MFA, device actions, security response, collaboration admin.Extra roles on the relationship don’t widen Neo’s access by themselves. Neo does user, license, group, device, and Conditional Access work through the application permissions in your permission profile — granted to Neo’s app during setup — not through directory roles. Relationship roles bound what your connected account (and Neo’s setup steps) can do; the permission profile bounds what Neo’s app can do.
Make sure your connected account can provision
GDAP assigns roles to a security group, so the account you connect Neo with must be a member of a group that carries both a consent-capable role — Application Administrator, Cloud Application Administrator, or Global Administrator — and a provisioning-capable role — Privileged Role Administrator, Global Administrator, or Partner Tier2 Support — on your relationships. A relationship including the roles isn’t enough on its own: if the connected account’s group isn’t assigned them, provisioning fails for that customer even though the relationship looks complete. This is why “no per-customer admin consent needed” holds only when your connected account already has both roles across your relationships. If Neo flags customers as “needs a provisioning role” or “needs access assignment” after you connect, the connected account’s group is missing a role on those relationships. To fix it, edit the access assignments in Microsoft Lighthouse or Partner Center — add the missing role to the group your connected account is in, or reconnect Neo with an account that’s already in a group that has it. Don’t hand-edit these in Entra for Lighthouse-managed relationships (LHSetup / MLT_): Lighthouse overwrites manual changes, so they drift back.
Connecting customer tenants via GDAP
Setup lives under Integrations → GDAP in the Neo Dashboard, which walks you through it as a checklist. Work top to bottom:1
Connect GDAP
Click Connect and sign in with your Secure App Model service account. Check Consent on behalf of your organization (this needs a Global Administrator) so Neo can act through your GDAP relationships. If that box is missed, the checklist flags it — just Reconnect.Once connected, the checklist shows which account is connected. To switch to a different account, click Reconnect and sign in as the new one.
2
Grant the Partner Center permission
A Global Administrator grants Neo the Partner Center permission: use Copy consent link, open it as a Global Admin, approve, then Recheck. This lets Neo tell which of your customers are CSP-reachable.
3
Choose permission categories
Set the default permission categories Neo requests in each tenant (User Management, Security, Email, …) — see M365 Permissions. You can override them per company later.
4
Map customer tenants
Click Find tenants from GDAP to review the customer tenants Neo discovered from your relationships and apply the matches. This grows the pool of companies eligible to connect.For a company Neo could not match, open the Companies page and click Map GDAP tenant on its row, then pick the customer tenant by name. The row’s Connect via GDAP button appears once the tenant is mapped and the customer is CSP-reachable.
5
Provision
Click Connect all eligible to provision every tenant-mapped company at once, or connect one at a time from End Companies (Connect via GDAP on a company). Watch live per-company progress in the provisioning-run panel.
Disconnecting a company
Disconnecting removes Neo’s app from the customer tenant and revokes Neo’s access.1
Open the company in End Companies
Navigate to
https://dashboard.neoagent.io/end-companies and select the company.2
Disconnect
Click Disconnect. Neo removes the Neo Azure Automations app from the customer tenant and marks the company as not connected.
3
Check the other companies on that tenant
If other PSA companies map to the same Microsoft tenant, they lose access too, and all of them show Not connected. Disconnect one company only when you want Neo out of the whole tenant.
Disconnecting GDAP entirely
This clears your stored GDAP connection so Neo stops managing GDAP and can no longer reach customer tenants through the relationship. Use it to switch the connected account or turn GDAP off.1
Open Integrations → GDAP
Go to Integrations → GDAP in the Neo Dashboard.
2
Disconnect
Click Disconnect GDAP and confirm.
When a GDAP relationship lapses
A lapsed or expired GDAP relationship does not cut off Neo’s existing access — Neo keeps operating in already-connected tenants. A lapse only stops connecting new customers and adding permissions to connected ones. To fully remove Neo’s access from a tenant, disconnect the company while the relationship is still active.GDAP vs Direct Consent
Troubleshooting
Consent fails for a customer tenant
Consent fails for a customer tenant
- Verify the GDAP relationship is Active in Partner Center
- Ensure the relationship includes a role that can consent the app — Application Administrator, Cloud Application Administrator, or Global Administrator. Privileged Role Administrator alone is not enough for this step, and its absence is what produces a Partner Center
403 Forbidden - Ensure the relationship also includes a role that can grant app permissions and assign roles — Privileged Role Administrator, Global Administrator, or Partner Tier2 Support
- Confirm the account you connected is in a group assigned those roles — a relationship that includes them but doesn’t assign them to your account’s group still fails. See Make sure your connected account can provision
- Check that the GDAP relationship hasn’t expired (maximum duration is 730 days). An expired relationship with no active replacement produces
Unable to initialize the authorization contextinstead of a403
Neo can't perform actions after GDAP consent
Neo can't perform actions after GDAP consent
- Verify the GDAP relationship includes the required operational roles (e.g., Exchange Administrator for mailbox operations)
- Check the company permissions in the Neo Dashboard — missing roles will show as unavailable operations
GDAP relationship expired
GDAP relationship expired
GDAP relationships have a maximum duration of 730 days. An expired relationship does not remove Neo’s existing access — connected tenants keep working — but it blocks connecting new customers and adding permissions. Create a new relationship in Partner Center with the same roles, then reconnect via the Neo Dashboard. To remove Neo’s access from a tenant entirely, disconnect the company.
