Connecting your Microsoft 365 account to your CloudRadial tenant allows you to pull in users and set up various data flows that give users more visibility into their 365 account. The new gold standard will become GDAP (Granular Delegated Admin Privileges). This will be a new way that Microsoft Partners will be required to request consent to access their customer accounts, as well as any third-party applications. You'll now need to provide Admin Application Consent in order to connect customer tenants with their Microsoft 365.
GDAP: Connecting Tenants to Microsoft 365 Now Requires Consent – CloudRadial
- Microsoft Graph Permissions Requested
- Connecting Partner Company to Microsoft 365
- Connecting your Client's Companies to Microsoft 365
- Checking App Permissions in Microsoft 365
- Troubleshooting Microsoft 365 Sync Issues
Microsoft Graph Permissions Requested
- AuditLog.Read.All
- Calendars.Read
- CallRecordPstnCalls.Read.All
- CallRecords.Read.All
- DeviceManagementConfiguration.Read.All
- Directory.Read.All
- Domain.Read.All
- Reports.Read.All
- SecurityEvents.Read.All
- ServiceMessage.Read.All
- SharePointTenantSettings.Read.All
-
User.Read.All
The permission User.ReadWrite.All is optional in the list of permissions. Without this permission, users will not be able to update their Office 365 details from within CloudRadial.
Connecting Partner Company to Microsoft 365
- Navigate to Partner > Clients
- Click your Partner Company
- Select the Microsoft 365 Tab
- You will see the options to tie your client's tenant to CloudRadial from here using the Global Administrator account from your tenant in Microsoft 365
- Click Connect Microsoft 365
-
Review the permissions requested then proceed.
Connecting your Client's Companies to Microsoft 365
- Navigate to Partner > Clients
- Click +Add at the top right
- Fill out all the relevant information but leave Microsoft 365 Tenant Identifier blank
- Click Submit
- Select the Client company > Microsoft 365 tab
- You will see the options to tie your client's tenant to CloudRadial from here using the Global Administrator account from your customer's tenant in Microsoft 365
!!!DO NOT USE YOUR OWN GLOBAL ADMIN ACCOUNT!!!
- First select Administrative Access Application allows for that company's Office 365 data to flow into CloudRadial
- Second select User Login Access Application allows users to use their Office 365 credentials to log into CloudRadial
- Under the Details tab Click Sync
It should look like the below image if successful under the Microsoft 365 tab:Note: It may show Unauthorized until a successful sync has occurred.
Checking App Permissions in Microsoft 365
Once you have tied in the proper access in CloudRadial, you will want to confirm the appropriate access from within Microsoft 365 to ensure no interruptions occur.
- Login to the customer's tenant https://portal.azure.com/
- Go to Azure Active Directory
- Click Enterprise Applications
- Check for these two permissions
- CloudRadial (User Logins)
- CloudRadial (Admins)
The data from Microsoft will now be flowing into the relevant areas of CloudRadial.
They will now also have access to log into CloudRadial using their Microsoft
365 credentials. Setup is complete - simply repeat the ID entry steps for any
existing clients or for new clients added to the portal.
Troubleshooting Microsoft 365 Sync Issues
After completing the setup steps above, your Microsoft 365 sync jobs should run successfully. If you encounter issues - particularly partial sync failures - the following troubleshooting steps can help.
Partial Sync Job Failures
A partial sync failure occurs when some data syncs successfully but other portions fail. This can happen when:
- Permissions were not fully granted - If you skipped or missed a permission during the PowerShell script setup, some data types may fail to sync while others succeed. Re-run the PowerShell script and verify all permissions listed above are granted in Azure AD.
- Credential or token expiration - Microsoft 365 tokens can expire or become invalid if your partner tenant password changes or MFA settings are updated. Navigate to Partner Integrations Microsoft 365 and re-enter your credentials to refresh the connection.
- Tenant-level restrictions - Some Microsoft 365 tenants have conditional access policies or security defaults that block third-party application access. Check your Azure AD Conditional Access policies to ensure CloudRadial's enterprise application is not being blocked.
- Delegated admin access changes - If GDAP relationships have been modified or expired, the sync may partially fail for affected customer tenants. Verify your GDAP relationships are active and include the required roles.
Comments
2 comments
Just followed this through. The AppId came out blank which was disappointing, After trying to trouble shoot the script I just logged into o365 admin and found the AppId for the graph application and pasted that in. It worked :)
Hi Duncan,
I don't see this in my 365 admin. Do you know what page it's on? Thanks
Article is closed for comments.