Generic MSSP framework in the Microsoft ecosystem
Let’s familiarize ourselves with Microsoft partnership models and basics. Microsoft partners can have different permission types depending on the partnership model that is used. Some of these permission types grant quite wide permissions to the customer environments. The full list of different permission types for partners can be found in the Microsoft Learn article at the following link: https://packt.link/APXTm. Some of these permissions are outlined in the following list:
- Delegated Administration Privileges (DAP)
These are for partners that manage services for your organization or school. In Microsoft Entra ID, the partner has a Global Administrator permission.
DAP has had issues from a security point of view in the past and nowadays Microsoft does not grant DAP for new customer creation. Instead, GDAP is granted when a new customer tenant is created.
- Granular Delegated Admin Privileges (GDAP)
These are the same as...