Skip to main content
GDAP (Granular Delegated Admin Privileges) lets MSPs consent to the Neo app across customer tenants centrally, without requiring an admin in each customer tenant to complete the consent flow manually.
With GDAP, you consent to the Neo app on behalf of your customers — no admin action needed in each tenant. Once connected, Neo operates in the tenant through app-only access, the same as Direct Consent for day-to-day automations. One difference today: resetting an admin’s password requires the optional Privileged Authentication Administrator grant (see Recommended roles) — ordinary-user resets work either way.

How it works

  1. Your MSP has an existing GDAP relationship with a customer tenant that includes two things: a role that can consent the Neo app — Application Administrator or Cloud Application Administrator — and a role that can grant app permissions and assign roles — Privileged Role Administrator, Global Administrator, or Partner Tier2 Support (included in Microsoft Lighthouse’s default relationships). Neither one covers both steps: Privileged Role Administrator alone cannot consent the app, and Cloud Application Administrator alone cannot grant Graph app roles
  2. In the Neo Dashboard, you configure which permission categories Neo should request (e.g., User Management, Security, Email) — see M365 Permissions
  3. You use your GDAP access to consent the Neo app in the customer tenant — no customer admin involvement needed
  4. Neo grants only the permissions matching your selected categories — nothing more

Prerequisites

Before connecting customer tenants via GDAP, ensure:
  1. You have active GDAP relationships with your customer tenants in Partner Center. If you don’t have GDAP set up yet, follow Microsoft’s GDAP guide first.
  2. Your GDAP relationships include the right roles — at minimum Application Administrator (so Neo can consent its app; Cloud Application Administrator or Global Administrator work too), Privileged Role Administrator (so Neo can provision; Global Administrator or Partner Tier2 Support work too, and Lighthouse default relationships already include Tier2), and Exchange Administrator. Because relationships can’t be edited after creation, create new ones with the full recommended role set.
  3. The account you connect Neo with is in a group assigned those roles — a relationship including a role isn’t enough; the connected account’s security group must carry it. See Make sure your connected account can provision.
  4. You have admin access to your MSP’s partner tenant (the Entra ID tenant enrolled in CSP).

Neo acts in each customer tenant app-only — through its own application, using the Microsoft Graph permissions you pick in your M365 permission profile. Neo itself only needs the roles it uses to set that up, plus the ones it assigns to its own app — the three in the first table below. Beyond those three, we suggest creating your relationships with the full role set below. It covers the ground MSPs most commonly automate with Neo — identity, authentication, security, devices, Exchange, Teams, SharePoint. Include the full set up front — a GDAP relationship cannot be edited after creation, and adding a role later means creating a new relationship and re-approving it in every customer tenant.

Required by Neo

Suggested for the relationship

We suggest all of these. Neo doesn’t strictly need them to provision, but they cover the day-to-day MSP work customers put Neo on — password resets, MFA, device actions, security response, collaboration admin.
Extra roles on the relationship don’t widen Neo’s access by themselves. Neo does user, license, group, device, and Conditional Access work through the application permissions in your permission profile — granted to Neo’s app during setup — not through directory roles. Relationship roles bound what your connected account (and Neo’s setup steps) can do; the permission profile bounds what Neo’s app can do.
Leave Global Administrator out of the relationship. A relationship containing it is not eligible for GDAP auto-extend, so it hard-expires and takes your access with it. Application Administrator + Privileged Role Administrator cover everything Neo would use Global Administrator for.

Make sure your connected account can provision

GDAP assigns roles to a security group, so the account you connect Neo with must be a member of a group that carries both a consent-capable role — Application Administrator, Cloud Application Administrator, or Global Administrator — and a provisioning-capable role — Privileged Role Administrator, Global Administrator, or Partner Tier2 Support — on your relationships. A relationship including the roles isn’t enough on its own: if the connected account’s group isn’t assigned them, provisioning fails for that customer even though the relationship looks complete.
This is the most common cause of a customer that won’t connect. Adding the role to the relationship but not to the access assignment for your connected account’s group leaves it failing exactly as before — check both.
This is why “no per-customer admin consent needed” holds only when your connected account already has both roles across your relationships. If Neo flags customers as “needs a provisioning role” or “needs access assignment” after you connect, the connected account’s group is missing a role on those relationships. To fix it, edit the access assignments in Microsoft Lighthouse or Partner Center — add the missing role to the group your connected account is in, or reconnect Neo with an account that’s already in a group that has it. Don’t hand-edit these in Entra for Lighthouse-managed relationships (LHSetup / MLT_): Lighthouse overwrites manual changes, so they drift back.

Connecting customer tenants via GDAP

Setup lives under Integrations → GDAP in the Neo Dashboard, which walks you through it as a checklist. Work top to bottom:
1

Connect GDAP

Click Connect and sign in with your Secure App Model service account. Check Consent on behalf of your organization (this needs a Global Administrator) so Neo can act through your GDAP relationships. If that box is missed, the checklist flags it — just Reconnect.Once connected, the checklist shows which account is connected. To switch to a different account, click Reconnect and sign in as the new one.
2

Grant the Partner Center permission

A Global Administrator grants Neo the Partner Center permission: use Copy consent link, open it as a Global Admin, approve, then Recheck. This lets Neo tell which of your customers are CSP-reachable.
3

Choose permission categories

Set the default permission categories Neo requests in each tenant (User Management, Security, Email, …) — see M365 Permissions. You can override them per company later.
4

Map customer tenants

Click Find tenants from GDAP to review the customer tenants Neo discovered from your relationships and apply the matches. This grows the pool of companies eligible to connect.For a company Neo could not match, open the Companies page and click Map GDAP tenant on its row, then pick the customer tenant by name. The row’s Connect via GDAP button appears once the tenant is mapped and the customer is CSP-reachable.
5

Provision

Click Connect all eligible to provision every tenant-mapped company at once, or connect one at a time from End Companies (Connect via GDAP on a company). Watch live per-company progress in the provisioning-run panel.
Once a company is connected, its M365 Access shows “via GDAP”. To remove Neo’s access later, disconnect the company. If several PSA companies map to the same Microsoft tenant, connecting one connects them all — Neo’s access belongs to the tenant. Every one of those companies shows “Connected”. The opposite case — one customer that owns two Microsoft tenants — needs one company per tenant: see Customers with more than one Microsoft tenant.

Disconnecting a company

Disconnecting removes Neo’s app from the customer tenant and revokes Neo’s access.
1

Open the company in End Companies

Navigate to https://dashboard.neoagent.io/end-companies and select the company.
2

Disconnect

Click Disconnect. Neo removes the Neo Azure Automations app from the customer tenant and marks the company as not connected.
3

Check the other companies on that tenant

If other PSA companies map to the same Microsoft tenant, they lose access too, and all of them show Not connected. Disconnect one company only when you want Neo out of the whole tenant.
Disconnecting needs an active GDAP relationship — that’s how Neo reaches the tenant to remove the app. If the relationship has lapsed, reconnect GDAP first and then disconnect, or have an admin remove the Neo Azure Automations app in the customer tenant manually.

Disconnecting GDAP entirely

This clears your stored GDAP connection so Neo stops managing GDAP and can no longer reach customer tenants through the relationship. Use it to switch the connected account or turn GDAP off.
1

Open Integrations → GDAP

Go to Integrations → GDAP in the Neo Dashboard.
2

Disconnect

Click Disconnect GDAP and confirm.
This does not remove Neo from customers you’ve already connected — that access is app-only and stays in place. To remove it, disconnect each company (which needs an active relationship, so do it before disconnecting GDAP), or have an admin remove the Neo Azure Automations app in each tenant manually.
To reconnect, follow Connecting customer tenants via GDAP again.

When a GDAP relationship lapses

A lapsed or expired GDAP relationship does not cut off Neo’s existing access — Neo keeps operating in already-connected tenants. A lapse only stops connecting new customers and adding permissions to connected ones. To fully remove Neo’s access from a tenant, disconnect the company while the relationship is still active.

Troubleshooting

GDAP relationships have a maximum duration of 730 days. An expired relationship does not remove Neo’s existing access — connected tenants keep working — but it blocks connecting new customers and adding permissions. Create a new relationship in Partner Center with the same roles, then reconnect via the Neo Dashboard. To remove Neo’s access from a tenant entirely, disconnect the company.