Mizo Named Runner-Up in ConnectWise IT Nation PitchIT Competition 2025 Read the full press release

Microsoft 365 GDAP Setup Guide

Ask AI about this doc

Pick an assistant and ask your question — we'll send it along with a link to this article.

Purpose

This guide explains how to connect Mizo to your customer Microsoft 365 tenants using Granular Delegated Admin Privileges (GDAP). Mizo does not create GDAP relationships for you. You must already have active GDAP relationships in Partner Center; Mizo discovers them, validates roles, consents Mizo apps into the tenants you choose, and links those tenants to PSA companies.

What you need before starting

RequirementWhy
Microsoft Partner Center account with an MPN IDIdentifies your partner organization
Global Administrator on the partner tenant for the initial Mizo sign-inGrants Mizo the partner permissions listed in the wizard
Active GDAP relationship per customer tenant you want to connectMizo discovers tenants from active relationships (previously connected tenants that lose GDAP still appear so you can remove them)
A security group you belong to that holds Application Administrator (or Cloud Application Administrator / Global Administrator) on those customersRequired to consent Mizo apps into a customer tenant
Customer Conditional Access that allows delegated admin sign-inBlocks non-interactive Graph access if CA denies partner admins

Mizo uses centrally managed multi-tenant Entra apps. You do not register those apps yourself.


Section 1 – Prepare GDAP in Partner Center

Step 1: Confirm active GDAP relationships

  1. Sign in to Partner Center.
  2. Open Customers and review GDAP (delegated admin) relationships.
  3. For each customer you plan to connect in Mizo, confirm the relationship is active (not expired or pending).

Step 2: Assign Application Administrator to a security group you are in

  1. In Partner Center, open the GDAP relationship for the customer.
  2. Ensure a security group is assigned Application Administrator (Cloud Application Administrator or Global Administrator also satisfy Mizo’s check).
  3. Confirm your partner user account is a member of that security group.

If the role is only on a group you are not in, Mizo will show the tenant as missing Application Administrator even though the relationship exists.

Step 3: Check Conditional Access on customer tenants

Customer tenants must allow partner delegated admin access. If Conditional Access requires interactive MFA for every Graph call and blocks refresh-token / non-interactive access, connecting that tenant in Mizo can fail even when roles look correct.


Section 2 – Configure Microsoft 365 (GDAP) in Mizo

In the Mizo console: Integrations → Microsoft 365 (GDAP).

The wizard has three steps: Partner AuthenticationTenant SelectionCompany Matching.

Step 1: Partner Authentication

  1. Optionally enter a partner tenant domain hint (for example contoso.onmicrosoft.com) if you use several Microsoft accounts.
  2. Click Sign in with Microsoft and complete consent as Global Administrator of the partner tenant.
  3. Confirm the partner tenant domain and MPN ID appear after sign-in.

What this step does

  • Stores a refresh token so later wizard steps work without signing in again.
  • Reads your partner organization and Partner Center profile.
  • Does not write to any customer tenant.

Copy sign-in link is for when another Global Administrator must complete consent for you. The link works once and expires in about one hour—send it without opening it yourself.

Step 2: Tenant Selection

  1. Wait for Mizo to load active GDAP tenants and check Application Administrator coverage (shown in the table’s roles and status columns).
  2. Select the eligible tenants to connect.
  3. Choose Read-only (diagnostic app) or Read-write (diagnostic + resolution apps).
  4. Click Save and connect.
  5. Wait for each tenant’s connection status: Healthy or Error.

Use Refresh if Partner Center changes are not visible yet (forces a fresh discovery).

What this step does

  • Lists active GDAP relationships visible to the signed-in admin and checks whether a security group you belong to holds Application Administrator (or an accepted equivalent) on each tenant.
  • Consents the Mizo diagnostic app (and resolution app for read-write) into each selected customer via Partner Center / Graph.
  • Verifies credentials afterward.

Only tenants with Application Administrator can be connected. Other GDAP tenants remain listed but cannot be connected until roles are fixed. Previously connected tenants that lost App Admin or an active GDAP relationship stay listed (often as Error) and remain selectable so you can Remove them.

Step 3: Company Matching

  1. Link each healthy Microsoft tenant to one or more PSA companies.
  2. Review suggestions, accept or adjust links, then Save.

Unmatched tenants stay connected in Mizo; PSA-driven Microsoft 365 actions stay off until a company is linked.


Troubleshooting

Use the message you see in the Mizo console (wizard alerts, toast errors, or the tenant Status column).

Step 1 – Partner Authentication

What you seeLikely causeWhat to do
Partner sign-in failed or was cancelledConsent cancelled, wrong account, or browser blocked the popupRetry with the partner Global Admin account; allow popups; try the copyable sign-in link
Could not start Microsoft sign-inTemporary API / URL generation failureRetry; if it persists, contact Mizo support
Sign-in link copy errorClipboard / browser permissionCopy again, or use Sign in with Microsoft on the admin’s machine
Partner authentication expired / incomplete. Sign in again…Partner refresh token revoked or rejected by Microsoft for the partner tenantClick Sign in with Microsoft again; revoke old app grants in Entra only if you intend to reset access
Signed out unexpectedly after a failed tenant connectOlder Mizo builds cleared partner auth on customer-tenant errorsSign in again; current builds keep partner auth when only a customer connection fails

Step 2 – Tenant Selection / Connect

What you seeLikely causeWhat to do
Could not load GDAP tenants…Discovery or auth failureClick Refresh; sign in again (step 1) if needed
No tenants have Application Administrator via GDAPNo customer grants App Admin to a group you belong toIn Partner Center, add App Admin (or accepted equivalent) to a group that includes your user, request/update the relationship, then Refresh
Tenant status shows missing roles / Application AdministratorRole on another group, relationship pending/expired, or discovery cache staleFix group membership / relationship; click Refresh
You belong to the group in Partner Center but Mizo still shows missing rolesGroup assignment not yet effective, or you signed in with a different userConfirm the signed-in account’s UPN; wait for GDAP propagation; Refresh
Tenant is no longer in an active GDAP relationship for the signed-in partner userPreviously connected tenant is outside the discovered active set (or connect was attempted for one that is)Confirm relationship status in Partner Center; Refresh; Remove the row in Mizo if you no longer need it
Application Administrator is not granted on this tenant via GDAPConnect attempted without App AdminFix roles in Partner Center, Refresh, then connect again
No Partner Center customer found for this Microsoft tenantPartner Center customer directory has no matching customer for that Entra tenantConfirm the customer exists under your MPN in Partner Center; wait for sync; contact Mizo if the GUID is correct in both places
Microsoft 365 GDAP token refresh failed (400) / (401)Microsoft rejected a customer-tenant token request (not necessarily a dead partner sign-in)Stay signed in; check GDAP App Admin, CA policies, and that delegated admin access works for that customer; retry connect; if it keeps failing, send Mizo the approximate time and tenant name so support can read the Entra error code
AADSTS65001 / consent_required for the Mizo GDAP Partner appThe partner app was not yet consented into the customer tenant before Mizo requested a delegated token thereRetry connect — Mizo CPV-consents the partner app first. If it persists right after consent, wait a minute for Microsoft to propagate the grant and reconnect that tenant
Microsoft 365 GDAP CPV consent failed (400) — “Invalid application id”Partner Center consent was requested for an application other than the signed-in Mizo partner appRetry connect on a current Mizo build; if it persists, contact Mizo support with the tenant name and time
CPV / application consent failed (other 4xx)Partner Center rejected consent for that customerConfirm App Admin GDAP; check the customer’s status in Partner Center; retry
Microsoft 365 GDAP could not confirm application permissions in the customer tenantThe Graph application permissions were requested for the Mizo apps, but Microsoft did not report them back as grantedReconnect that tenant; confirm the customer has not blocked app role assignments, and that App Admin is still granted via GDAP
A tenant shows Healthy but Microsoft 365 actions fail for the first few minutesNewly granted application permissions take a few minutes to become usable (Graph reports Authorization_IdentityNotFound or Authorization_RequestDenied until then)Wait a few minutes and retry the action. If it still fails after ~15 minutes, confirm the Mizo apps appear under the customer’s Enterprise applications and check Conditional Access
Connected N; M failed / connection ErrorPer-tenant failure; other tenants may still be healthyOpen the row’s error text and use this table; fix that tenant and reconnect only it

Step 3 – Company Matching

What you seeLikely causeWhat to do
Could not load / save company matchingAPI or permission issueRetry; confirm you have full access to Integrations
Same PSA company linked to more than one tenantDuplicate mappingRemove the duplicate before saving
No suggestions / unmatched tenantsNames/domains do not overlap enoughLink companies manually; unmatched is allowed

General

SymptomWhat to do
Changes in Partner Center not visible in MizoUse Refresh on step 2 (forces fresh discovery); allow time for Microsoft GDAP propagation
Need to switch partner admin accountSign out, then sign in with the other Global Admin
Want to disconnect a customer without removing GDAPSelect the tenant(s) and Remove in step 2 — this only disconnects in Mizo (works for Healthy and Error connections)

Privacy and security notes

  • Partner sign-in stores an encrypted refresh token in your Mizo tenant database so wizard steps and reconnects do not require constant interactive login.
  • Sign out in Mizo only ends the partner admin session (refresh token). It does not remove apps already consented into customer tenants, and it does not stop diagnostic or resolution agents on tickets for customers that were already connected. To stop ticket access for a customer, Remove that tenant in step 2 and/or remove the Mizo apps from that customer’s Enterprise applications in Entra ID.
  • App consent into a customer tenant happens only when you explicitly connect that tenant in step 2.