Microsoft 365 GDAP Setup Guide
Purpose
This guide explains how to connect Mizo to your customer Microsoft 365 tenants using Granular Delegated Admin Privileges (GDAP). Mizo does not create GDAP relationships for you. You must already have active GDAP relationships in Partner Center; Mizo discovers them, validates roles, consents Mizo apps into the tenants you choose, and links those tenants to PSA companies.
What you need before starting
| Requirement | Why |
|---|---|
| Microsoft Partner Center account with an MPN ID | Identifies your partner organization |
| Global Administrator on the partner tenant for the initial Mizo sign-in | Grants Mizo the partner permissions listed in the wizard |
| Active GDAP relationship per customer tenant you want to connect | Mizo discovers tenants from active relationships (previously connected tenants that lose GDAP still appear so you can remove them) |
| A security group you belong to that holds Application Administrator (or Cloud Application Administrator / Global Administrator) on those customers | Required to consent Mizo apps into a customer tenant |
| Customer Conditional Access that allows delegated admin sign-in | Blocks non-interactive Graph access if CA denies partner admins |
Mizo uses centrally managed multi-tenant Entra apps. You do not register those apps yourself.
Section 1 – Prepare GDAP in Partner Center
Step 1: Confirm active GDAP relationships
- Sign in to Partner Center.
- Open Customers and review GDAP (delegated admin) relationships.
- For each customer you plan to connect in Mizo, confirm the relationship is active (not expired or pending).
Step 2: Assign Application Administrator to a security group you are in
- In Partner Center, open the GDAP relationship for the customer.
- Ensure a security group is assigned Application Administrator (Cloud Application Administrator or Global Administrator also satisfy Mizo’s check).
- Confirm your partner user account is a member of that security group.
If the role is only on a group you are not in, Mizo will show the tenant as missing Application Administrator even though the relationship exists.
Step 3: Check Conditional Access on customer tenants
Customer tenants must allow partner delegated admin access. If Conditional Access requires interactive MFA for every Graph call and blocks refresh-token / non-interactive access, connecting that tenant in Mizo can fail even when roles look correct.
Section 2 – Configure Microsoft 365 (GDAP) in Mizo
In the Mizo console: Integrations → Microsoft 365 (GDAP).
The wizard has three steps: Partner Authentication → Tenant Selection → Company Matching.
Step 1: Partner Authentication
- Optionally enter a partner tenant domain hint (for example
contoso.onmicrosoft.com) if you use several Microsoft accounts. - Click Sign in with Microsoft and complete consent as Global Administrator of the partner tenant.
- Confirm the partner tenant domain and MPN ID appear after sign-in.
What this step does
- Stores a refresh token so later wizard steps work without signing in again.
- Reads your partner organization and Partner Center profile.
- Does not write to any customer tenant.
Copy sign-in link is for when another Global Administrator must complete consent for you. The link works once and expires in about one hour—send it without opening it yourself.
Step 2: Tenant Selection
- Wait for Mizo to load active GDAP tenants and check Application Administrator coverage (shown in the table’s roles and status columns).
- Select the eligible tenants to connect.
- Choose Read-only (diagnostic app) or Read-write (diagnostic + resolution apps).
- Click Save and connect.
- Wait for each tenant’s connection status: Healthy or Error.
Use Refresh if Partner Center changes are not visible yet (forces a fresh discovery).
What this step does
- Lists active GDAP relationships visible to the signed-in admin and checks whether a security group you belong to holds Application Administrator (or an accepted equivalent) on each tenant.
- Consents the Mizo diagnostic app (and resolution app for read-write) into each selected customer via Partner Center / Graph.
- Verifies credentials afterward.
Only tenants with Application Administrator can be connected. Other GDAP tenants remain listed but cannot be connected until roles are fixed. Previously connected tenants that lost App Admin or an active GDAP relationship stay listed (often as Error) and remain selectable so you can Remove them.
Step 3: Company Matching
- Link each healthy Microsoft tenant to one or more PSA companies.
- Review suggestions, accept or adjust links, then Save.
Unmatched tenants stay connected in Mizo; PSA-driven Microsoft 365 actions stay off until a company is linked.
Troubleshooting
Use the message you see in the Mizo console (wizard alerts, toast errors, or the tenant Status column).
Step 1 – Partner Authentication
| What you see | Likely cause | What to do |
|---|---|---|
| Partner sign-in failed or was cancelled | Consent cancelled, wrong account, or browser blocked the popup | Retry with the partner Global Admin account; allow popups; try the copyable sign-in link |
| Could not start Microsoft sign-in | Temporary API / URL generation failure | Retry; if it persists, contact Mizo support |
| Sign-in link copy error | Clipboard / browser permission | Copy again, or use Sign in with Microsoft on the admin’s machine |
| Partner authentication expired / incomplete. Sign in again… | Partner refresh token revoked or rejected by Microsoft for the partner tenant | Click Sign in with Microsoft again; revoke old app grants in Entra only if you intend to reset access |
| Signed out unexpectedly after a failed tenant connect | Older Mizo builds cleared partner auth on customer-tenant errors | Sign in again; current builds keep partner auth when only a customer connection fails |
Step 2 – Tenant Selection / Connect
| What you see | Likely cause | What to do |
|---|---|---|
| Could not load GDAP tenants… | Discovery or auth failure | Click Refresh; sign in again (step 1) if needed |
| No tenants have Application Administrator via GDAP | No customer grants App Admin to a group you belong to | In Partner Center, add App Admin (or accepted equivalent) to a group that includes your user, request/update the relationship, then Refresh |
| Tenant status shows missing roles / Application Administrator | Role on another group, relationship pending/expired, or discovery cache stale | Fix group membership / relationship; click Refresh |
| You belong to the group in Partner Center but Mizo still shows missing roles | Group assignment not yet effective, or you signed in with a different user | Confirm the signed-in account’s UPN; wait for GDAP propagation; Refresh |
| Tenant is no longer in an active GDAP relationship for the signed-in partner user | Previously connected tenant is outside the discovered active set (or connect was attempted for one that is) | Confirm relationship status in Partner Center; Refresh; Remove the row in Mizo if you no longer need it |
| Application Administrator is not granted on this tenant via GDAP | Connect attempted without App Admin | Fix roles in Partner Center, Refresh, then connect again |
| No Partner Center customer found for this Microsoft tenant | Partner Center customer directory has no matching customer for that Entra tenant | Confirm the customer exists under your MPN in Partner Center; wait for sync; contact Mizo if the GUID is correct in both places |
| Microsoft 365 GDAP token refresh failed (400) / (401) | Microsoft rejected a customer-tenant token request (not necessarily a dead partner sign-in) | Stay signed in; check GDAP App Admin, CA policies, and that delegated admin access works for that customer; retry connect; if it keeps failing, send Mizo the approximate time and tenant name so support can read the Entra error code |
| AADSTS65001 / consent_required for the Mizo GDAP Partner app | The partner app was not yet consented into the customer tenant before Mizo requested a delegated token there | Retry connect — Mizo CPV-consents the partner app first. If it persists right after consent, wait a minute for Microsoft to propagate the grant and reconnect that tenant |
| Microsoft 365 GDAP CPV consent failed (400) — “Invalid application id” | Partner Center consent was requested for an application other than the signed-in Mizo partner app | Retry connect on a current Mizo build; if it persists, contact Mizo support with the tenant name and time |
| CPV / application consent failed (other 4xx) | Partner Center rejected consent for that customer | Confirm App Admin GDAP; check the customer’s status in Partner Center; retry |
| Microsoft 365 GDAP could not confirm application permissions in the customer tenant | The Graph application permissions were requested for the Mizo apps, but Microsoft did not report them back as granted | Reconnect that tenant; confirm the customer has not blocked app role assignments, and that App Admin is still granted via GDAP |
| A tenant shows Healthy but Microsoft 365 actions fail for the first few minutes | Newly granted application permissions take a few minutes to become usable (Graph reports Authorization_IdentityNotFound or Authorization_RequestDenied until then) | Wait a few minutes and retry the action. If it still fails after ~15 minutes, confirm the Mizo apps appear under the customer’s Enterprise applications and check Conditional Access |
| Connected N; M failed / connection Error | Per-tenant failure; other tenants may still be healthy | Open the row’s error text and use this table; fix that tenant and reconnect only it |
Step 3 – Company Matching
| What you see | Likely cause | What to do |
|---|---|---|
| Could not load / save company matching | API or permission issue | Retry; confirm you have full access to Integrations |
| Same PSA company linked to more than one tenant | Duplicate mapping | Remove the duplicate before saving |
| No suggestions / unmatched tenants | Names/domains do not overlap enough | Link companies manually; unmatched is allowed |
General
| Symptom | What to do |
|---|---|
| Changes in Partner Center not visible in Mizo | Use Refresh on step 2 (forces fresh discovery); allow time for Microsoft GDAP propagation |
| Need to switch partner admin account | Sign out, then sign in with the other Global Admin |
| Want to disconnect a customer without removing GDAP | Select the tenant(s) and Remove in step 2 — this only disconnects in Mizo (works for Healthy and Error connections) |
Privacy and security notes
- Partner sign-in stores an encrypted refresh token in your Mizo tenant database so wizard steps and reconnects do not require constant interactive login.
- Sign out in Mizo only ends the partner admin session (refresh token). It does not remove apps already consented into customer tenants, and it does not stop diagnostic or resolution agents on tickets for customers that were already connected. To stop ticket access for a customer, Remove that tenant in step 2 and/or remove the Mizo apps from that customer’s Enterprise applications in Entra ID.
- App consent into a customer tenant happens only when you explicitly connect that tenant in step 2.