How to Restrict and Monitor MSP Access to Your Microsoft 365 Tenant
Retrospective: this article looks back at events from July 2021, written in 2026 with the benefit of hindsight.
Managed service providers often have broad administrative access to customer Microsoft 365 tenants. Here is how to restrict and monitor that access.
Step 1: Review partner relationships
In the Microsoft 365 admin center, go to Settings → Partner relationships. Note each partner and the type of admin relationship.
- Delegated admin privileges (DAP) — the legacy model that granted broad roles (often Global Administrator). Microsoft has been transitioning partners away from DAP.
- Granular delegated admin privileges (GDAP) — time-limited relationships with specific roles.
Remove any partner relationships you don't recognize or no longer need.
Step 2: Require least privilege through GDAP
Work with your MSP to define the specific Entra roles they need (for example, Helpdesk Administrator, Exchange Recipient Administrator) and a duration. Avoid Global Administrator unless absolutely required.
Step 3: Apply Conditional Access to partner access
Use cross-tenant access settings and Conditional Access for service provider users to require MFA (and ideally compliant devices or phishing-resistant MFA) when partner staff access your tenant.
Step 4: Review other MSP access
- RMM agents on devices (what can they deploy?).
- Applications the MSP added to your tenant.
- Accounts created for the MSP in your directory.
Step 5: Monitor
Alert on administrative actions by partner accounts, especially role changes, Conditional Access changes and mailbox permissions.
Step 6: Put it in the contract
Require MFA, background checks, incident notification, and a list of tools with access to your environment.
Verify
Review partner relationships and roles quarterly.
- Kaseya VSA (July 2021): Ransomware Delivered Through an MSP Tool Incident Teardowns
- Detecting MSP Supply Chain Attack: Sentinel and GuardDuty Detections Detection & Response
- CIO Brief: Your MSP Has Admin Rights — Are You Watching? CIO Briefings