GDAP: JIT Permissions for Safer Access
Identity
14. Dez 2025 17:24

GDAP: JIT Permissions for Safer Access

von HubSite 365 über Nick Ross [MVP] (T-Minus365)

MSP security: secure GDAP with PIM for Groups in Entra ID via Entra Admin for just in time access MFA audit trails

Key insights

  • Standing GDAP access
    Giving technicians 24/7 delegated rights is convenient but risky: one compromised account can expose every customer tenant, so remove always‑on access where possible.
  • PIM for Groups
    Use Entra Privileged Identity Management applied to security groups to require just‑in‑time (JIT) activation, MFA, approvals, and automatic expiration for elevated GDAP roles.
  • 3‑tier access model
    Organize partner roles into Tier 1, Tier 2, and Tier 3 templates to match support tasks; assign only required roles and set short, documented activation durations.
  • Least privilege
    Create GDAP relationships scoped to specific roles and time bounds, protect approver accounts, and avoid permanent Global Administrator delegation whenever possible.
  • Audit trails
    Log every elevation and session, link activations to support tickets, and monitor Partner Center or Lighthouse logs for visibility and post‑incident review.
  • Autoextend and licensing
    Inventory existing DAP/GDAP links, remove unnecessary DAPs, and use Autoextend cautiously; JIT policies and advanced controls require Entra ID P2 licensing.

Overview: A practical fix for always‑on partner access

In a recent YouTube video, Nick Ross [MVP] (T‑Minus365) demonstrates how managed service providers can replace risky standing privileges with time‑bound elevations. He argues that many MSPs still give technicians constant admin rights across customer tenants, which creates a broad attack surface if any account is compromised. Consequently, Ross shows how to use PIM for Groups in Entra ID together with GDAP to allow access only when needed and to capture approvals, MFA enforcement, and detailed audit trails.

What the video covers

Ross walks viewers through a clear, step‑by‑step process: creating a group, assigning roles, enabling PIM, and testing the activation flow. He also outlines a practical three‑tier access model—referred to as Tier 1, Tier 2, and Tier 3—and reviews field notes from real deployments. Moreover, the video highlights how partner tooling such as Partner Center and Microsoft 365 Lighthouse can be used to create GDAP security groups and optionally enable just‑in‑time policies during setup.

How PIM for Groups and JIT work together

At the core of the approach is the combination of GDAP and just‑in‑time elevation through group‑based PIM. In practice, partners mark specific security groups as eligible for GDAP roles so that members only activate elevated privileges when required, and those activations expire automatically. This method enforces multifactor authentication, approval workflows, and time limits, which together reduce standing access and increase traceability for support sessions.

Furthermore, Ross explains that logging and monitoring become essential parts of the model because every activation should link back to a support ticket or business justification. In short, elevating people rather than granting always‑on rights makes audits simpler and limits the blast radius of a compromised account. Equally important, this model depends on the partner having the right licensing—Entra ID P2 for some JIT features—so teams must weigh costs against security gains.

Implementation roadmap shown in the video

Ross lays out a high‑level sequence that starts with inventorying existing DAP and GDAP relationships and removing unnecessary standing privileges. Next, he recommends creating least‑privilege role templates for common tasks and placing users into PIM‑eligible groups that mirror those templates. Then the team configures PIM settings: maximum eligible duration, approver groups, MFA enforcement, and session timeouts, and finally applies the GDAP relationships to customer tenants with clear scope and expiration.

He also demonstrates testing the activation flow and notes practical items such as who should be an approver and how to record the purpose of access. Additionally, Ross touches on the Autoextend feature available in Partner Center, which can automatically renew low‑risk GDAP relationships but should be used cautiously for highly privileged roles. Therefore, partners should document when autoextend is acceptable and avoid it for global admin relationships to maintain strong controls.

Tradeoffs and operational challenges

Transitioning to JIT access improves security, yet it introduces operational complexity that teams must manage. For example, approvals add latency to urgent support tasks, so organizations must design an emergency access process that preserves security while avoiding service delays. Moreover, the need for Entra ID P2 licenses and properly protected approver accounts raises costs and administrative overhead, especially for smaller partners.

Scaling approval workflows across many customers presents another challenge because each tenant may need its own approvers, logging, and documentation. Consequently, partners must balance centralized control with customer consent and tenant‑specific policies, and consider automation where possible to reduce manual steps. Finally, the model increases the importance of comprehensive logging and correlation between support tickets and elevated sessions, which can be technically demanding to implement consistently.

Best practices and final takeaways

Ross emphasizes practical best practices: scope GDAP relationships narrowly, require customer consent, protect approver accounts strongly, and tie every elevation to an auditable ticket. He also suggests defining clear Tier 1, Tier 2, and Tier 3 role durations so teams know how long an activation should last for typical tasks and who needs immediate escalation rights. In addition, partners should test activation flows regularly and train staff on the emergency access process to avoid service disruptions.

In conclusion, the video provides a hands‑on playbook for replacing standing admin privileges with time‑bound, auditable access. While the approach requires investment in licensing, process design, and tooling, it reduces risk substantially and aligns partners with Microsoft’s recommended model for delegated access. Therefore, security‑minded MSPs should consider this JIT model as a practical step toward safer, more accountable customer operations.

Identity - GDAP: JIT Permissions for Safer Access

Keywords

GDAP security, GDAP just-in-time access, Just-in-Time permissions GDAP, Granular Delegated Admin Privileges, secure GDAP access, Azure AD just-in-time GDAP, manage GDAP JIT permissions, GDAP best practices