First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Authorization step · Microsoft CSP partner relationship

You’ve been asked to authorize IT Partner. Here’s what that means — and what it doesn’t.

Someone at your organization is onboarding with us, and the next step is authorizing IT Partner as your Microsoft 365 partner (CSP). Authorization by itself grants no access to anything inside your tenant — admin access is a separate, scoped grant you approve explicitly. This page answers the three questions you should ask anyone sending a request like this: who are you, why do you need it, and what exactly can — and can’t — you do with it.

Act 01 · Who we are

The company behind the request.

IT Partner LLCo365hq.com
EntityUS company, registered in Delaware. US-based engineers, US jurisdiction, US contracts.
StandingMicrosoft Solutions Partner since 2006 — all six solution-area designations, verifiable in Microsoft’s own partner directory.
PeopleFounder-led. Mike takes every first call himself; the engineers who hold access are named employees, not a rotating queue.
Scale1,100+ organizations under management — the same delegated-access mechanism you’re being asked for, running quietly for two decades.
Act 02 · Why we ask for this

Authorization connects us. Access is granted separately — and scoped.

The button below establishes a CSP partner relationship — Microsoft’s mechanism for saying IT Partner may sell and support Microsoft 365 for your organization. By itself it opens no door: no mail, no files, no settings. To actually fix things, we separately request GDAP — granular delegated admin privileges — in plain English, a scoped, expiring set of admin roles that you approve explicitly. Without that second grant, every fix means asking you for screenshots and passwords nobody should ever share.

What the delegated roles are for

  • Microsoft support tickets — we open and run them on your behalf, with Microsoft seeing us as your delegated admin.
  • Configuration fixes — mail flow, sharing policies, device enrollment; changed at the source instead of over your shoulder.
  • License management — assigning and right-sizing what you already buy.
  • Security monitoring — alerts, sign-in anomalies, patch posture; the boring vigilance you’re paying for.

What you’ll see when you accept

The real screens, so nothing feels unexpected.

1

The authorize button below

It leads to a Microsoft page — check the address bar: microsoft.com, not ours.

2

Microsoft’s own consent screen

It shows exactly what’s being authorized — the partner relationship and, when delegated roles are requested, the exact roles and their expiration. Read it — it should match our published policy.

3

Confirmation in your admin center

The relationship appears under Settings → Partner relationships, where you can inspect — or end — it anytime.

Consent happens on microsoft.com, never on our site — and we never ask for your password. Anyone who does isn’t us.
Act 03 · What it does and doesn’t do

The exact shape of the access.

Authorization alone gives us no access inside your tenant. When you also grant delegated roles (GDAP) so we can support you, this is their exact shape.

What this access does

Expires on a date Microsoft enforces.Time-bound by the platform itself — not a promise from us, a property of the grant.
Starts with no access at all.Day one we see only the subscriptions and software we provision to your tenant — nothing else. Any admin access is requested separately, time- and role-scoped, and you approve it.
Logs every action in your tenant’s audit log.Under our named accounts — your log, on your side, readable by you without asking us.
Escalates only per-task.If a fix needs a higher role, we request it for that task, time-bound, and it expires with the task.

What it doesn’t do

No access to your passwords.The mechanism has no way to see them; we have no reason to ask.
No standing Global Admin.The keys-to-everything role is not in the starter set and never held permanently.
Can’t read mail or files beyond the granted roles.The roles are support-scoped; the full list is public.
No billing or purchase changes without your written approval.Spending your money requires your yes, in writing, every time.
The exit, clearly marked

You can revoke our permissions yourself, in one click, anytime. No phone call, no notice period. And if you leave us entirely, we contractually guarantee approval of the CSP transfer to your next partner.

Microsoft 365 Admin Center → Settings → Partner relationships → Remove roles

This page persuades; the policy specifies. Read the exact roles, in writing, at /gdap-access →

The actual button

Ready? Authorize IT Partner in your tenant.

This opens Microsoft’s own consent flow on microsoft.com — you’ll see exactly what’s being authorized before anything takes effect. Authorization alone grants no access inside your tenant; delegated roles are requested — and approved by you — separately.

Authorize on microsoft.com Reversible at any moment, by you. One click revokes our permissions; leaving entirely is a CSP transfer we’re contractually bound to approve, per Microsoft’s published transfer workflow ↗ — so it doesn’t depend on our goodwill.

Questions before you click accept?

Thirty minutes with Mike — the founder, not a sales rep — before anything is granted. Skeptical in-house IT especially welcome; bring hard questions.

Asked before every grant
Yes — completely, on two fronts. Permissions: one click in Admin Center → Settings → Partner relationships revokes our admin permissions instantly — the authorization itself remains, but we can no longer act in your tenant. Subscriptions: we contractually guarantee approval of CSP subscription transfers to any new partner, following Microsoft’s documented transfer process — and once all your subscriptions have moved, we remove the authorization entirely.
Only what the granted roles allow — they’re support-scoped, not content-scoped, and every role is listed at /gdap-access. Anything beyond them is technically impossible with this grant, not just against policy.
You revoke our permissions (one click), your new partner sends a CSP transfer request, and we approve it — that approval is contractually guaranteed, per Microsoft's documented process. Once everything has transferred, we remove the authorization. Your tenant, your data, nothing to give back.
Named engineers on our staff, from our secured accounts, MFA enforced. Their actions land in your audit log under their names — you can check who did what without asking us.