Delegated administration

With a Partner licence and a GDAP relationship, CloudSergeant switches into a customer's tenant and manages it as your partner account — no second sign-in, and no credentials of theirs.

What you need

  • A Partner licence. This is the one capability the two CloudSergeant plans differ by — see Licences. On a Tenant licence the switcher is visible but explains that it needs a Partner licence, and the customer list is never even fetched.
  • A GDAP relationship with the customer, containing the roles you intend to use. Being Global Administrator in your own tenant carries no weight in theirs.
  • Admin consent for the app in your own tenant, plus a one-time consent in each customer tenant.

Switching tenant

The tenant picker sits at the bottom of the navigation pane. Open it, type to filter — by name, domain or tenant id, so a GUID pasted out of a portal URL works — and press Enter or click to switch. Every Microsoft call then targets that tenant, and a caution banner across the top names the customer you are working in.

Each customer row shows its domain next to its name, which is what tells two similarly-named customers apart. If a domain cannot be read the row falls back to the tenant id rather than showing nothing.

The first switch into a tenant asks for consent

The customer tenant has to approve the app once. CloudSergeant first checks silently, then lets you either sign in as that tenant's Global Administrator or copy a tenant-specific link to send them. The copied flow finishes on a CloudSergeant confirmation page; return to the desktop afterwards and it verifies the permission directly with Microsoft. Later switches into the same tenant are silent.

Switching clears everything cached for the previous tenant, so no list, picker or card can carry one customer's data into another. Returning to your own tenant works the same way.

Tenants (GDAP)

A searchable version of the tenant switcher popup above — same list, same Switch action, as a full page instead of a small popup. It shows one row per customer with an active relationship; if a customer happens to have more than one active relationship at once (see Relationships below), only the one lasting longest is shown, matching what the switcher popup already offers. A Relationships column jumps to the Relationships page below, filtered to that customer. It only works from your own (home) tenant — a notice tells you to switch back if you're inside a customer tenant — and a Refresh button re-reads every GDAP relationship from Microsoft.

Relationships (GDAP)

The full lifecycle management of your own GDAP relationships: create one, finalize it and copy the approval link for the customer, edit a draft, turn auto-extend on or off, request termination, create a replacement, delete a draft, and assign approved roles to partner security groups. Unlike Tenants (GDAP) and the switcher popup, this page deliberately shows every lifecycle state — draft, pending the customer's approval, active, termination requested, and expired or terminated — not only active ones.

Creating a relationship lets you name it, pick the customer (from a known list or by tenant ID), set a duration of 1–730 days, choose whether it auto-extends, and pick which admin roles you're requesting. Which actions are offered depends on the relationship's current state: Edit and Delete draft only on a draft; Finalize (and copy the approval link) only on a draft; Copy approval link again while approval is pending; auto-extend and Create replacement only once active; Terminate only while active.

Active means locked, except for auto-extend

Once a relationship is active, Microsoft itself locks its name, customer, duration and requested roles — nothing here can change them. To change any of those, use Create replacement: it creates a brand-new relationship rather than editing the active one, and the original has to stay in place until the replacement is approved and active. That transition is also the one case where a customer legitimately has more than one active relationship at once.

  • A draft grants nothing. Creating one is not itself a grant of access — it only takes effect once it is finalized and the customer approves it.
  • Terminating ends delegated access, not the reseller relationship. The confirmation says so.
  • Approved roles still need assigning to your security groups. After a customer approves a relationship, open it and choose Assign security group. CloudSergeant offers only security-enabled groups from your partner tenant and only roles the customer approved on that relationship. Existing assignments are shown on the same card; use its Refresh action to follow a new assignment from pending to active.

Requires the same DelegatedAdminRelationship.ReadWrite.All scope as Tenants (GDAP), and likewise only works from your own tenant.

What works in a customer tenant

Your partner account Partner licence + GDAP DIRECTORY + TENANT CONFIG MAILBOX CONTENT + ONEDRIVE FILES — BLOCKED Customer tenant users · groups · devices · roles mailbox settings & permissions OneDrive settings · Defender security SECOND SIGN-IN AS A TENANT USER → mailbox + OneDrive files
IllustrationGDAP reaches tenant configuration, not mailbox content or a OneDrive's file plane.
Availability in a delegated customer tenant.
FeatureIn a customer tenantNeeds in the relationship
Users, Groups, Devices, Roles, Subscriptions Yes A directory-reader role to see them; the relevant administrator role to change them
Mailboxes — settings, addresses, forwarding, permissions Yes Exchange Administrator
Contacts Yes Exchange Administrator
Restricted senders Yes through GDAP Global Reader or Security Reader to view; Security Administrator or Global Administrator to unblock
Microsoft 365 quarantine Yes through GDAP Security Reader or Global Reader to view; Security Administrator or Global Administrator to release or delete
Search Yes Whatever the sources need — it degrades per source rather than failing
OneDrive list Yes Reports Reader, SharePoint Administrator or Global Reader
OneDrive quota, sharing and lock settings Yes, through SharePointThe site URL must come from the report or be safely owner-verified SharePoint AllSites.FullControl + SharePoint Administrator
Add a OneDrive site collection administrator Yes, without the existing list SharePoint AllSites.FullControl + SharePoint Administrator; verify the result in the customer's SharePoint admin center
Mailbox Cleanup, Copy / Move, Export / Import Separate sign-in onlyUse a customer-tenant user that can open the mailbox No GDAP role; the separately signed-in account needs owner or Full Access rights
OneDrive Copy / Move, Export / Import, filtered Cleanup Separate sign-in onlyUse a customer-tenant user that can open the drive No GDAP role; the separately signed-in account needs existing file access
Read or empty a OneDrive recycle bin NoHome tenant and primary sign-in only The personal-site SharePoint endpoint refuses GDAP and the secondary-login path is not used
Share OneDrive files, including during a user delete No The file plane is not grantable by GDAP; add a site collection administrator from the OneDrive card instead

Defender security through GDAP

Restricted senders and Quarantine are Defender security data, not ordinary mailbox-folder content. CloudSergeant therefore uses the selected customer's current GDAP identity, matching the access path available to appropriately assigned partners in the Microsoft Defender portal. The GDAP group needs Security Reader or Global Reader to view these lists, and Security Administrator or Global Administrator to unblock senders or act on quarantined messages.

The page uses the selected customer-tenant GDAP session directly and has no separate customer account sign-in. If Microsoft refuses the request, CloudSergeant reports the Defender permissions needed by the current partner identity.

See Exchange — Restricted senders for the remediation checklist and bulk unblocking, and Exchange — Quarantine for bulk release and permanent deletion.

Why OneDrive is only partly available

OneDrive spans two Microsoft access planes. SharePoint's tenant-admin endpoint accepts a delegated partner with SharePoint Administrator, so CloudSergeant can read and change quota, sharing and lock settings and can add a site collection administrator. The usage report also works through Graph when the relationship contains a report-reading role.

The OneDrive site and files themselves do not accept that partner identity. CloudSergeant therefore does not attempt to read Graph drive details, list the site's existing administrators or share its files in a customer tenant. The page remains useful and explains those individual omissions where they appear. See OneDrive through GDAP for the full table.

The OneDrive file tools use the same deliberate escape hatch as the mailbox tools: sign in separately as a customer-tenant user that can already open the drive. That session-only token reaches the file plane as that user, not as the GDAP partner. Copy / Move, Export / Import and filtered Cleanup work this way; recycle-bin emptying remains home-tenant only because it uses the personal site's SharePoint endpoint. See OneDrive Tools in a customer tenant.

The usage-report list and the live settings card are separate capabilities. A list row can show daily storage figures while its site URL is empty. CloudSergeant safely resolves the normal URL through SharePoint and verifies its owner; an exceptional conflict-suffixed URL must come from a later Microsoft report and is never guessed.

Why mailbox content is not available

This is the question the product gets asked most, and the answer is architectural rather than a gap in the roadmap.

Mailbox content — the actual messages — is reachable only as the mailbox's owner or as a principal with Full Access to it. No administrative role grants access to someone else's mail. That is Microsoft's model, not CloudSergeant's, and it is the same reason an Exchange Administrator cannot read a user's inbox in Outlook.

In a customer tenant your partner account is a foreign principal. It has no mailbox there, and it cannot be a delegate of one. So there is no identity for a content operation to run as. Reaching across tenants that way would require application-level permissions consented per customer — an app-only path with standing access to every mailbox, which is exactly the design this product avoids.

The partner-token path is therefore disabled in a customer tenant and says why. The wizard remains useful through the explicit second-sign-in route below.

The way through

Use the second sign-in on the wizard's mailbox step and sign in as a user of that tenant who can already open the mailbox — its owner, or someone with Full Access. Those credentials are session-only: the tokens are never written to disk and are dropped when you sign out, switch tenant or start over. This needs no grant and no GDAP role, because it is simply that person using the tool.

Things worth knowing

  • A refusal tells you what the relationship is missing. When an operation is denied, the app lists what it needed, the roles the relationship actually granted you, and what looks absent — so you can ask the customer for the right role rather than guessing.
  • Losing delegation mid-session returns you home. If the Partner licence stops being valid while you are inside a customer tenant, the session drops back to your own tenant rather than continuing in a state it can no longer justify.
  • Nothing about the customer reaches us. The customer's tenant id and name never leave your machine, and the tenant list is fetched from Microsoft, not from CloudSergeant. See Privacy.
  • Switching back to your own tenant works even without a mailbox. A licence-less administrator has no mailbox of their own; the switch reports that plainly and completes rather than failing.