Share via

Global admin access

Denise Talbot 0 Reputation points
2026-03-20T15:27:13.5233333+00:00

My CSP is refusing to grant customer Global Admin access to my own tenant and is preventing me from switching CSPs

Microsoft Security | Microsoft Entra | Other
0 comments No comments

1 answer

Sort by: Most helpful
  1. Q&A Assist
    2026-03-20T15:27:36.9433333+00:00
    AI generated content. This question contains an answer created with AI from Q&A Assist. Learn more

    A CSP partner cannot legitimately prevent a customer from having Global Administrator access to their own tenant or from changing partners. The tenant owner always retains the right to control admin privileges and partner relationships.

    From the Microsoft guidance:

    1. Delegated admin privileges (DAP/GDAP) are optional and revocable
      • When a CSP relationship is established, the partner can receive delegated admin privileges (DAP) or granular delegated admin privileges (GDAP) to manage the tenant.
      • These privileges are granted by the customer and can be reviewed and removed. Microsoft explicitly recommends customers regularly review partner admin access because it includes powerful roles like Global Administrator.
      • DAP/GDAP does not transfer ownership of the tenant to the partner; it only grants admin access that the customer can revoke.
    2. Customer control and security considerations
      • Documentation emphasizes that giving a partner Global Administrator permissions presents a security risk and should be limited.
      • This implies the customer is expected to be able to control who has Global Administrator, including partners, and to remove or limit those rights when needed.
    3. If locked out or blocked from admin access
      • If the partner has effectively locked the customer out (for example, by being the only Global Administrator or refusing to promote a customer user to Global Administrator), this is treated as a tenant lockout scenario.
      • In such cases, the tenant owner or an existing Global Administrator must work directly with Microsoft Support (Data Protection / Tenant Recovery) to restore appropriate admin access.
      • For tenant lockout and admin recovery scenarios (for example, no usable Global Administrator, or partner blocking access), Microsoft directs the tenant owner/GA to contact Microsoft 365 for business support by phone so Microsoft can verify ownership and help restore access.
    4. Practical next steps
      • If any customer user still has Global Administrator or sufficient admin rights, that user can:
        • Review and remove partner delegated admin privileges (DAP/GDAP) if appropriate.
        • Ensure at least one internal user is a Global Administrator.
      • If no internal Global Administrator exists or the CSP is refusing to cooperate, the tenant owner should:
        • Contact Microsoft 365 for business support by phone and clearly state that:
          • This is a tenant lockout / admin access issue.
          • The CSP is the only Global Administrator and is refusing to grant customer Global Admin access or blocking changes.
        • Work with Microsoft’s Data Protection / Tenant Recovery team to re-establish customer-controlled Global Administrator access.

    Once customer-controlled Global Administrator access is restored and partner DAP/GDAP is adjusted or removed, the customer can proceed with changing CSPs through normal commercial and subscription-migration processes.


    References:

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.