GDAP (Granular Delegated Admin Privileges) is the permission model Microsoft requires partners like Loopia to use when managing a customer’s Microsoft 365 tenant on their behalf, replacing the older, broader Delegated Admin Privileges (DAP) model. This article explains what GDAP is, why it needs renewing, and what to do when it expires.
Why GDAP exists
Under the older DAP model, a partner such as Loopia had almost unrestricted admin access to a customer’s whole Microsoft 365 tenant, indefinitely. GDAP replaces that with narrower, named permissions (for example, just user and licence management) that Microsoft automatically expires after a set period \u2013 usually up to 2 years, though Loopia’s connection is renewed more frequently as part of routine account maintenance.
In practice, this means Loopia only has access to the specific things needed to support your Microsoft 365 service, and that access has to be actively renewed rather than lasting forever by default.
Why the connection can lapse
A few things can cause the GDAP connection to expire or need renewing:
- The permission period Microsoft granted has simply run out.
- The built-in admin account’s password has expired or was reset outside the normal renewal flow.
- Microsoft revoked or changed partner relationships during a security or policy update on their side.
What happens if it lapses
If the GDAP connection lapses, Loopia can no longer manage your Microsoft 365 licences, users or settings from the Loopia Customer Zone until it is renewed. Your existing mailboxes, files and data are not affected \u2013 only Loopia’s ability to administer the account on your behalf.
Renewing the connection
See Restore access to admin user and renew GDAP connection for the step-by-step process.
More information
For Microsoft’s own explanation of GDAP, see Microsoft’s GDAP overview.