GDAP Request

A GDAP request encapsulates the directory roles requested and the security groups to which they need to be assigned.

Creating a GDAP Request

GDAP Requests can created directly or via a GDAP template. The latter approach provides a convenient way to create GDAP requests using a predefined set of parameters and is the generally recommended approach.

Creating from a Template

  1. Navigate to the Provider Management area and click on GDAP Request. Then click the + New From Template button on the ribbon.
  1. Search the template using the search box and select the required template. Then click the Add button.
  1. Fill in the required fields
FieldDescription
GDAP TemplateThis is pre-populated with the template selected in the previous step.
NameProvide a friendly name for the GDAP request.
CustomerSelect the customer for which this GDAP request is being created.
TenantSelect the tenant for which this GDAP request is being created. This dropdown will present a list of tenants filtered by the selected Customer.
Auto-RenewThis is pre-populated based on the template.
Duration (Days)This is pre-populated based on the template.
  1. The role mapping control is also preset with the configuration specified on the selected GDAP template. The remaining fields (Start Date, Expiry Date, Microsoft ID and Acceptance Link) should appear blank and locked. These will get automatically populated as the GDAP request progresses.
  2. Click Save.

📘

GDAP Requests are created by default in the Draft state. At the point, the request is local only and not submitted to Microsoft or to the end customer for approval. All changes are allowed.

  1. Once the GDAP request is successfully created, it must be Submitted to continue the GDAP workflow. This can be done in bulk from the GDAP list OR by opening a single GDAP record form. In both cases, click the Submit button to create the GDAP request in Partner Center.
  1. Once the GDAP request is successfully submitted, status of the request changes to Approval Pending. The following fields are also populated.
FieldDescription
Microsoft IDThe unique identifier from Microsoft for this GDAP request.
Acceptance LinkThe acceptance link that customers must click to see and complete the acceptance workflow for this GDAP request.

📘

Once a GDAP request is submitted, the Directory Roles are locked. While the security groups can be added / removed and assignments for the already specified roles can be altered; new Directory Roles cannot be added. For additional roles, new GDAP requests must be created.

❗️

Work 365 does not automatically email customers, the acceptance link, upon GDAP request submission. It is recommended that partners create Power Automate flows, triggered on the status change of the GDAP request to `Approval Pending' to trigger emails.

Creating without a template

  1. The process to create an independent GDAP request is very similar to creating one from a Template. On the GDAP request list, click the arrow next to the + New From Template button and select the + New option.
  1. This opens the same form as the previous step, but without a pre-selected GDAP template or pre-populated fields. Follow steps #3 from the previous section to complete creation of a GDAP request.