The access we ask for. Published, so you can hold us to it.
Partner access to your Microsoft 365 tenant runs on Microsoft’s GDAP model — granular, time-bound roles that you approve. This page states our standing policy. When we send you an actual GDAP request, it must match what’s written here; if it doesn’t, ask us why before approving.
Our default request
When you connect with us as your Microsoft partner, our default request is Microsoft’s standard starter GDAP relationship— the baseline, largely read-only role set Microsoft proposes when a new partner relationship is created. It lets us see enough to advise you (directory objects, service health, licensing state) without the ability to change your environment. We do not request Global Administrator as a standing role — not by default, not “to make things easier.”
When a task needs more
Real work sometimes needs real permissions — a migration needs Exchange administration; an Intune rollout needs device management. When that happens, we send an additional, task-scoped GDAP request: the specific roles the task needs, for a bounded duration, which you approve in your own admin center and can revoke at any time. When the engagement ends, the elevated roles end with it.
How to verify this
Read Microsoft’s own description of the model (GDAP introduction), then compare any request we send you against this page. Your admin center shows every role we hold and when it expires — you never have to take our word for it. This policy is fact SE-01 in our public facts register.