
In a recent YouTube video, Nick Ross [MVP] (T‑Minus365) demonstrates how managed service providers can replace risky standing privileges with time‑bound elevations. He argues that many MSPs still give technicians constant admin rights across customer tenants, which creates a broad attack surface if any account is compromised. Consequently, Ross shows how to use PIM for Groups in Entra ID together with GDAP to allow access only when needed and to capture approvals, MFA enforcement, and detailed audit trails.
Ross walks viewers through a clear, step‑by‑step process: creating a group, assigning roles, enabling PIM, and testing the activation flow. He also outlines a practical three‑tier access model—referred to as Tier 1, Tier 2, and Tier 3—and reviews field notes from real deployments. Moreover, the video highlights how partner tooling such as Partner Center and Microsoft 365 Lighthouse can be used to create GDAP security groups and optionally enable just‑in‑time policies during setup.
At the core of the approach is the combination of GDAP and just‑in‑time elevation through group‑based PIM. In practice, partners mark specific security groups as eligible for GDAP roles so that members only activate elevated privileges when required, and those activations expire automatically. This method enforces multifactor authentication, approval workflows, and time limits, which together reduce standing access and increase traceability for support sessions.
Furthermore, Ross explains that logging and monitoring become essential parts of the model because every activation should link back to a support ticket or business justification. In short, elevating people rather than granting always‑on rights makes audits simpler and limits the blast radius of a compromised account. Equally important, this model depends on the partner having the right licensing—Entra ID P2 for some JIT features—so teams must weigh costs against security gains.
Ross lays out a high‑level sequence that starts with inventorying existing DAP and GDAP relationships and removing unnecessary standing privileges. Next, he recommends creating least‑privilege role templates for common tasks and placing users into PIM‑eligible groups that mirror those templates. Then the team configures PIM settings: maximum eligible duration, approver groups, MFA enforcement, and session timeouts, and finally applies the GDAP relationships to customer tenants with clear scope and expiration.
He also demonstrates testing the activation flow and notes practical items such as who should be an approver and how to record the purpose of access. Additionally, Ross touches on the Autoextend feature available in Partner Center, which can automatically renew low‑risk GDAP relationships but should be used cautiously for highly privileged roles. Therefore, partners should document when autoextend is acceptable and avoid it for global admin relationships to maintain strong controls.
Transitioning to JIT access improves security, yet it introduces operational complexity that teams must manage. For example, approvals add latency to urgent support tasks, so organizations must design an emergency access process that preserves security while avoiding service delays. Moreover, the need for Entra ID P2 licenses and properly protected approver accounts raises costs and administrative overhead, especially for smaller partners.
Scaling approval workflows across many customers presents another challenge because each tenant may need its own approvers, logging, and documentation. Consequently, partners must balance centralized control with customer consent and tenant‑specific policies, and consider automation where possible to reduce manual steps. Finally, the model increases the importance of comprehensive logging and correlation between support tickets and elevated sessions, which can be technically demanding to implement consistently.
Ross emphasizes practical best practices: scope GDAP relationships narrowly, require customer consent, protect approver accounts strongly, and tie every elevation to an auditable ticket. He also suggests defining clear Tier 1, Tier 2, and Tier 3 role durations so teams know how long an activation should last for typical tasks and who needs immediate escalation rights. In addition, partners should test activation flows regularly and train staff on the emergency access process to avoid service disruptions.
In conclusion, the video provides a hands‑on playbook for replacing standing admin privileges with time‑bound, auditable access. While the approach requires investment in licensing, process design, and tooling, it reduces risk substantially and aligns partners with Microsoft’s recommended model for delegated access. Therefore, security‑minded MSPs should consider this JIT model as a practical step toward safer, more accountable customer operations.
GDAP security, GDAP just-in-time access, Just-in-Time permissions GDAP, Granular Delegated Admin Privileges, secure GDAP access, Azure AD just-in-time GDAP, manage GDAP JIT permissions, GDAP best practices