Multi-CloudHow-To & HardeningRetrospectives

How to Restrict and Monitor MSP Access to Your Microsoft 365 Tenant

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2021, written in 2026 with the benefit of hindsight.

Managed service providers often have broad administrative access to customer Microsoft 365 tenants. Here is how to restrict and monitor that access.

Step 1: Review partner relationships

In the Microsoft 365 admin center, go to Settings → Partner relationships. Note each partner and the type of admin relationship.

  • Delegated admin privileges (DAP) — the legacy model that granted broad roles (often Global Administrator). Microsoft has been transitioning partners away from DAP.
  • Granular delegated admin privileges (GDAP) — time-limited relationships with specific roles.

Remove any partner relationships you don't recognize or no longer need.

Step 2: Require least privilege through GDAP

Work with your MSP to define the specific Entra roles they need (for example, Helpdesk Administrator, Exchange Recipient Administrator) and a duration. Avoid Global Administrator unless absolutely required.

Step 3: Apply Conditional Access to partner access

Use cross-tenant access settings and Conditional Access for service provider users to require MFA (and ideally compliant devices or phishing-resistant MFA) when partner staff access your tenant.

Step 4: Review other MSP access

  • RMM agents on devices (what can they deploy?).
  • Applications the MSP added to your tenant.
  • Accounts created for the MSP in your directory.

Step 5: Monitor

Alert on administrative actions by partner accounts, especially role changes, Conditional Access changes and mailbox permissions.

Step 6: Put it in the contract

Require MFA, background checks, incident notification, and a list of tools with access to your environment.

Verify

Review partner relationships and roles quarterly.

restrict msp access microsoft 365Kaseya2021

More on this story