---
title: Auditing Delegated Admin Access Across Client Tenants | Datatechs Consulting
description: Everyone migrated to GDAP and almost nobody went back to trim the roles. Here is how to audit what your engineers actually hold across every tenant, and reduce it.
image: https://www.datatechs.co.uk/hubfs/datatechs-blog-gdap.png
---

[Skip to content](https://www.datatechs.co.uk/blog/auditing-delegated-admin-access-across-client-tenants#main-content)

[![Datatechs home](https://www.datatechs.co.uk/hs-fs/hubfs/Datatech%20Consulting%20Limited.png?width=2130&height=676&name=Datatech%20Consulting%20Limited.png "Datatechs home")](https://www.datatechs.co.uk) 

[![](https://www.datatechs.co.uk/hubfs/Datatech%20Consulting%20Limited%20-%20INVERT.png)](https://www.datatechs.co.uk/)

[Home](https://www.datatechs.co.uk/)

[Services](https://www.datatechs.co.uk/services)

[M365 Security Audit](https://www.datatechs.co.uk/audit) [Professional Services and Consultancy](https://www.datatechs.co.uk/services/professional-services) [IT Helpdesk and Support](https://www.datatechs.co.uk/services/it-helpdesk) [Managed Compliance](https://www.datatechs.co.uk/services/managed-compliance) [Power Platform](https://www.datatechs.co.uk/services/power-platform) [Azure and Cloud Infrastructure](https://www.datatechs.co.uk/services/azure-cloud-infrastructure)

[View all services →](https://www.datatechs.co.uk/services)

[Security Audit](https://www.datatechs.co.uk/audit)

[CIS M365 Benchmark](https://www.datatechs.co.uk/audit/cis-m365) [CIS Intune Benchmark](https://www.datatechs.co.uk/audit/cis-intune) [Cyber Essentials](https://www.datatechs.co.uk/audit/cyber-essentials)

[View the full audit →](https://www.datatechs.co.uk/audit)

[MSP Partners](https://www.datatechs.co.uk/msp-partners)

Resources

Free Downloads

[M365 Security Essentials Checklist](https://www.datatechs.co.uk/resources/m365-security-essentials) [Intune Security Essentials Checklist](https://www.datatechs.co.uk/resources/intune-security-essentials)

[About](https://www.datatechs.co.uk/about) [Blog](https://www.datatechs.co.uk/blog) 

[Contact Us](https://www.datatechs.co.uk/contact)

[Home](https://www.datatechs.co.uk/) [Services](https://www.datatechs.co.uk/services)

[M365 Security Audit](https://www.datatechs.co.uk/audit) [Professional Services and Consultancy](https://www.datatechs.co.uk/services/professional-services) [IT Helpdesk and Support](https://www.datatechs.co.uk/services/it-helpdesk) [Managed Compliance](https://www.datatechs.co.uk/services/managed-compliance) [Power Platform](https://www.datatechs.co.uk/services/power-platform) [Azure and Cloud Infrastructure](https://www.datatechs.co.uk/services/azure-cloud-infrastructure) 

[Security Audit](https://www.datatechs.co.uk/audit)

[CIS M365 Benchmark](https://www.datatechs.co.uk/audit/cis-m365) [CIS Intune Benchmark](https://www.datatechs.co.uk/audit/cis-intune) [Cyber Essentials](https://www.datatechs.co.uk/audit/cyber-essentials) 

[MSP Partners](https://www.datatechs.co.uk/msp-partners) Resources

[M365 Security Essentials Checklist](https://www.datatechs.co.uk/resources/m365-security-essentials) [Intune Security Essentials Checklist](https://www.datatechs.co.uk/resources/intune-security-essentials) 

[About](https://www.datatechs.co.uk/about) [Blog](https://www.datatechs.co.uk/blog) [Contact Us](https://www.datatechs.co.uk/contact)

[← Back to blog](https://www.datatechs.co.uk/blog)

Identity and Access · Compliance

# Auditing Delegated Admin Access Across Client Tenants

Marcus Harris · 4 September 2026

In this article

Microsoft forced everyone off DAP and onto GDAP, most of us did the migration under time pressure, and the fastest way through was to grant broad roles and move on. That was a reasonable call at the time. Very few people have been back since.

This is a post about going back. It is also, quietly, the thing a security-conscious client will eventually ask you about, and it is much better to have the answer ready than to assemble it during a due diligence questionnaire.

---

## What the migration left behind

Three patterns turn up repeatedly.

**Global Administrator on every relationship.** It was the path of least resistance and it works for everything, so it got used for everything. The result is that an engineer resetting a password holds the same rights as one rebuilding an identity architecture.

**Standing rather than eligible.** Roles assigned permanently to the security group, active at three in the morning on a Sunday whether or not anyone is working.

**Relationships that auto-extend.** Set once, renewing indefinitely, including for clients who left two years ago. Worth checking that list on its own.

**Where to find it**partner.microsoft.com › Customers › Customer list › Admin relationships

None of this is negligence. It is what happens when a deadline lands and the tooling is new. But an engineer's compromised account currently inherits every one of those rights, across every tenant, instantly.

---

## What good looks like

![Diagram contrasting a day-to-day account holding standing Global Admin against the target model: a day-to-day account with no roles, a separate dedicated admin account, and PIM eligible roles activated on demand with approval and a time limit](https://www.datatechs.co.uk/hubfs/datatechs-diagram-gdap-tiers.png)

Same engineer, same job. The difference is whether the rights are switched on when nobody is using them.

The target is that nothing is standing. An engineer signs in as themselves with no privilege, activates the role the task needs, and it drops away afterwards. Global Administrator activation requires approval from a second person.

That sounds like friction. In practice most work needs Exchange Administrator or User Administrator, both of which can self-activate in seconds, and Global Administrator turns out to be needed once a fortnight rather than daily.

---

## Audit what you actually hold

Start with the relationships themselves. This enumerates every GDAP relationship on your partner tenant and the roles inside each one.

```
Connect-MgGraph -Scopes "DelegatedAdminRelationship.Read.All"

Get-MgTenantRelationshipDelegatedAdminRelationship -All |
  Where-Object Status -eq "active" |
  ForEach-Object {
      $rel = $_
      $roles = (Get-MgTenantRelationshipDelegatedAdminRelationshipAccessAssignment `
                  -DelegatedAdminRelationshipId $rel.Id -All).AccessContainer
      [pscustomobject]@{
          Customer   = $rel.Customer.DisplayName
          Status     = $rel.Status
          Created    = $rel.CreatedDateTime
          Ends       = $rel.EndDateTime
          AutoExtend = $rel.AutoExtendDuration
          RoleCount  = ($rel.AccessDetails.UnifiedRoles).Count
          Roles      = ($rel.AccessDetails.UnifiedRoles.RoleDefinitionId | 
                        ForEach-Object { (Get-MgDirectoryRoleTemplate -DirectoryRoleTemplateId $_).DisplayName }) -join "; "
      }
  } | Sort-Object RoleCount -Descending | Export-Csv .\gdap-audit.csv -NoTypeInformation
```

Sort by `RoleCount` descending and the problem tenants are at the top. Look for anything carrying Global Administrator, and anything with an `AutoExtend` value on a customer you no longer serve.

Then check which of your own security groups map to those roles, because that is where the actual humans are:

```
Get-MgTenantRelationshipDelegatedAdminRelationship -All |
  Where-Object Status -eq "active" |
  ForEach-Object {
    $c = $_.Customer.DisplayName
    Get-MgTenantRelationshipDelegatedAdminRelationshipAccessAssignment `
      -DelegatedAdminRelationshipId $_.Id -All |
      ForEach-Object {
        [pscustomobject]@{
          Customer = $c
          GroupId  = $_.AccessContainer.AccessContainerId
          Group    = (Get-MgGroup -GroupId $_.AccessContainer.AccessContainerId -EA 0).DisplayName
          Roles    = ($_.AccessDetails.UnifiedRoles.RoleDefinitionId).Count
        }
      }
  } | Group-Object Group |
      Select-Object Name, Count, @{n="Tenants";e={($_.Group.Customer) -join ", "}}
```

That second query is the uncomfortable one. It tells you how many client tenants each of your internal groups reaches, and therefore what a single compromised engineer account is worth.

---

## Reducing it without breaking delivery

Do this per role, not per tenant, or you will be at it for weeks.

**Work out what each team actually uses.** Sign-in and audit logs over 90 days will tell you which roles were genuinely exercised. Most helpdesk work resolves to a very short list: User Administrator, Helpdesk Administrator, Exchange Recipient Administrator.

**Create tiered groups on your partner tenant.** A tier for helpdesk, a tier for engineers, a tier for architects. Map each to the minimum roles that tier needs, not to what is convenient.

**Add a new GDAP relationship with the reduced role set.** You cannot edit the roles in an existing relationship, so this is a create-and-cut-over rather than an edit. Run both briefly, confirm the new one covers the work, then terminate the old.

**Make Global Administrator eligible rather than active.** Through PIM on your partner tenant, with approval required and a two hour maximum. Two hours is the right number for a business of most sizes: long enough for real work, short enough that nobody leaves it on.

**Where to find it**entra.microsoft.com › Identity governance › Privileged Identity Management › Microsoft Entra roles › Settings

**Terminate relationships for former clients.** Trivial, and the first thing an auditor asks about.

---

## The report worth producing

Once the audit runs cleanly, it becomes something you can put in front of a client rather than just a cleanup exercise.

Four numbers do most of the work: how many people at your company can reach their tenant, which roles they hold, whether those roles are standing or activated on demand, and whether activation is logged. Clients rarely ask, and the ones who do are usually the better clients.

Being able to answer it in a paragraph, with evidence, is a genuine differentiator when you are being compared against someone who cannot.

---

## Where to start

Run the first query. If it comes back with Global Administrator on most relationships and no expiry dates, that is the normal result of a rushed migration and not a crisis.

Pick the three tenants with the most sensitive data and fix those first. The rest can follow at whatever pace the delivery schedule allows.

Topics: [Identity and Access](https://www.datatechs.co.uk/blog/tag/identity-and-access) [Compliance](https://www.datatechs.co.uk/blog/tag/compliance)

Share this article

[LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https://www.datatechs.co.uk/blog/auditing-delegated-admin-access-across-client-tenants) [X (Twitter)](https://x.com/intent/post?url=https://www.datatechs.co.uk/blog/auditing-delegated-admin-access-across-client-tenants&text=)

M

Marcus Harris

## Keep reading

[![](https://www.datatechs.co.uk/hs-fs/hubfs/datatechs-blog-ca-baseline.png?width=640&height=360&name=datatechs-blog-ca-baseline.png)](https://www.datatechs.co.uk/blog/deploying-a-conditional-access-baseline-to-any-tenant)

Microsoft 365 Security

### [Deploying a Conditional Access Baseline to Any Tenant](https://www.datatechs.co.uk/blog/deploying-a-conditional-access-baseline-to-any-tenant)

11 September 2026 

[Read more →](https://www.datatechs.co.uk/blog/deploying-a-conditional-access-baseline-to-any-tenant)

[![](https://www.datatechs.co.uk/hs-fs/hubfs/datatechs-blog-tenant-sprawl.png?width=640&height=360&name=datatechs-blog-tenant-sprawl.png)](https://www.datatechs.co.uk/blog/six-global-admins-and-audit-logging-off-inheriting-a-three-year-old-tenant)

Microsoft 365 Security

### [Six Global Admins and Audit Logging Off: Inheriting a Three-Year-Old Tenant](https://www.datatechs.co.uk/blog/six-global-admins-and-audit-logging-off-inheriting-a-three-year-old-tenant)

28 August 2026 

[Read more →](https://www.datatechs.co.uk/blog/six-global-admins-and-audit-logging-off-inheriting-a-three-year-old-tenant)

[![](https://www.datatechs.co.uk/hs-fs/hubfs/datatechs-blog-email-auth.png?width=640&height=360&name=datatechs-blog-email-auth.png)](https://www.datatechs.co.uk/blog/spf-dkim-and-dmarc-across-client-tenants-without-breaking-their-mail)

Microsoft 365 Security

### [SPF, DKIM and DMARC Across Client Tenants Without Breaking Their Mail](https://www.datatechs.co.uk/blog/spf-dkim-and-dmarc-across-client-tenants-without-breaking-their-mail)

14 August 2026 

[Read more →](https://www.datatechs.co.uk/blog/spf-dkim-and-dmarc-across-client-tenants-without-breaking-their-mail)

GET IN TOUCH

## Looking for help with your Microsoft 365 environment?

Our team works with small and mid-sized organisations to secure, audit, and manage their Microsoft 365 configuration. No jargon, no unnecessary overhead.

[Book a discovery call](https://www.datatechs.co.uk/book-a-call)[View our services →](https://www.datatechs.co.uk/services)

[![Datatechs](https://www.datatechs.co.uk/hs-fs/hubfs/Datatech%20Consulting%20Limited%20-%20INVERT.png?height=56&name=Datatech%20Consulting%20Limited%20-%20INVERT.png)](https://www.datatechs.co.uk/)

Microsoft 365 security and compliance for organisations and MSPs.

Services

- [M365 Security Audit](https://www.datatechs.co.uk/audit)
- [Professional Services](https://www.datatechs.co.uk/services/professional-services)
- [IT Helpdesk and Support](https://www.datatechs.co.uk/services/it-helpdesk)
- [Managed Compliance](https://www.datatechs.co.uk/services/managed-compliance)
- [Power Platform](https://www.datatechs.co.uk/services/power-platform)
- [Azure and Cloud Infrastructure](https://www.datatechs.co.uk/services/azure-cloud-infrastructure)

Resources

- [Blog](https://www.datatechs.co.uk/blog)
- [M365 Security Checklist](https://www.datatechs.co.uk/resources/m365-security-essentials)

Company

- [About](https://www.datatechs.co.uk/about)
- [MSP Partners](https://www.datatechs.co.uk/msp-partners)
- [Contact](https://www.datatechs.co.uk/contact)
- [Book a call](https://www.datatechs.co.uk/book-a-call)

Contact

- [hello@datatechs.co.uk](mailto:hello@datatechs.co.uk)
- United Kingdom

© 2026 Datatechs Consulting Limited. Registered in England and Wales, company number 16868376. Registered office: Belmont Suite, Paragon Business Park, Chorley New Road, Horwich, Bolton, BL6 6HG.

[Privacy Policy](https://www.datatechs.co.uk/privacy-policy) [Terms](https://www.datatechs.co.uk/terms)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Marcus Harris",
    "url" : "https://www.datatechs.co.uk/blog/author/marcus-harris"
  },
  "dateModified" : "2026-09-18T08:36:12.439Z",
  "datePublished" : "2026-09-04T08:00:00.000Z",
  "headline" : "Auditing Delegated Admin Access Across Client Tenants",
  "image" : [ "https://www.datatechs.co.uk/hubfs/datatechs-blog-gdap.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.datatechs.co.uk/blog/auditing-delegated-admin-access-across-client-tenants",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.datatechs.co.uk/hubfs/Datatech%20Consulting%20Limited.png"
    }
  }
}
```