Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Microsoft is improving your visibility into Microsoft Support's read-only access to your data during the Microsoft 365 support case lifecycle. When you create a support request, you grant cross-tenant access to Microsoft Support to access the information needed to troubleshoot the issue. This access is time bound and uses least-privileged access, in accordance with Zero Trust Principles.
This article describes what you see in your Microsoft Entra audit logs when:
- A Microsoft 365 Support case is created
- A Microsoft Support engineer works on your case
- A Microsoft 365 Support case is closed
This article also lists who can create support cases and what permissions are granted to Microsoft Support engineers.
Note
This article is designed for enterprise admins and IT Pros.
If you're a business user and you need technical support, see Get support for Microsoft 365 for business.
If you're a home user and you need help, see Contact us.
What happens when a Microsoft 365 support case is created?
When a user who has an appropriate role creates a support case in the Microsoft 365 admin center, a special type of cross-tenant access policy resource must be created between your tenant and the Microsoft Support tenant. Only users who have one of the following roles can create the cross-tenant access policy that's needed for Microsoft Support to work on the case:
With the cross-tenant access policy in place, Microsoft Support can access the information that's needed and you can view details about their permission to access diagnostic data in your tenant. The cross-tenant access policy:
- Is restricted to the Microsoft Support tenant and the Microsoft 365 Support Engineer role.
- Appears in Microsoft Entra audit logs as created by the user who initiated the support case.
The level of access granted for the Microsoft Support tenant is captured as Delegated Admin Service Provider Constraints.
Microsoft Entra audit events are logged throughout the Microsoft 365 Support case lifecycle.
What audit events are logged during a Microsoft Support case lifecycle?
Audit events are logged when:
- A Microsoft 365 support case is opened and the cross-tenant access policy is created.
- A Microsoft Support engineer works on the support case.
- A Microsoft 365 support case is closed.
This article describes audit events during a Microsoft Support case. To learn more about Microsoft Entra audit logs, see the following articles:
Audit events during support case creation
When you create a support case, Microsoft Entra records the following audit events:
| Order | Event | Actor |
|---|---|---|
| 1 | If it doesn't already exist, Add a partner to cross-tenant access setting. Adds the Microsoft Support tenant with Tenant ID b4c546a4-7dac-46a6-a7dd-ed822a11efd3. |
Identity of the user who created the support case. |
| 2 | If it doesn't already exist, Adding allowed assignable roles. Adds the Microsoft 365 Support Engineer role only. |
Identity of the user who created the support case. |
Audit events when Microsoft Support works on your case
When a Microsoft Support engineer works on your support case, the following Microsoft Entra audit events are recorded:
| Order | Event | Actor |
|---|---|---|
| 1 | If it doesn't exist already, Add a Service Principal for the Microsoft Support tenant. Microsoft Entra GDAP application. |
|
| 2 | Add member to role. Group from Microsoft Support tenant is added to the Microsoft 365 Support Engineer role. |
|
Audit events during support case closure
When your support case is closed, the following Microsoft Entra audit events are recorded:
| Order | Event | Actor |
|---|---|---|
| 1 | Add a service principal. The Microsoft Entra GDAP application handles revocation. |
|
| 2 | Deleting allowed assignable roles. |
|
| 3 | Delete partner specific cross-tenant access setting. Removes the Microsoft Support tenant if there are no other active support cases or 30 days have elapsed since the most recent case was created. |
|
What is the Assist API application, and how do I find it in my tenant?
Assist API is a Microsoft-owned application with the Application ID 2b8844d8-6c87-4fce-97a0-fbec9006e140. In Microsoft Entra audit events, you can see the service principal ID of the Assist API application for your tenant. The service principal ID is unique to your tenant.
To find the service principal ID in your tenant, follow these steps:
Sign in to the Microsoft Entra admin center.
From the left navigation bar, select Entra ID to expand it, and then select Enterprise Apps.
In the Enterprise applications | All applications page, under Manage, select All applications.
Select the Application Type == filter.
In the Application type window, select All Applications from the dropdown, and then select Apply.
In the Search by application name or object ID search box, search for the Application ID
2b8844d8-6c87-4fce-97a0-fbec9006e140.Your unique service principal ID is displayed.
What level of access does Microsoft Support have in my tenant?
The level of access is captured as Delegated Admin Service Provider Constraints, using the Microsoft 365 Support Engineer role. To see the read permissions that are granted, see Microsoft Entra built-in roles: Microsoft 365 Support Engineer.
Note
Use the Microsoft 365 Support Engineer role only for Microsoft Support cases. Don't assign this role to other users in your organization.
For more information, see the following articles:
- What's new in Microsoft Entra RBAC documentation.
- Roles not shown in the Microsoft Entra admin center.
- Microsoft 365 Support Engineer role.
What information can Microsoft Support access?
Microsoft Support accesses only the information needed to troubleshoot and resolve your support case. Depending on the nature of your support request, the data that Microsoft Support can access falls under the categories listed in the following table:
| Category | Type Of Data | Examples |
|---|---|---|
| Support data | All data provided to Microsoft by the customer as part of a customer engagement to obtain support services. |
|
| Account data | Contact, billing, purchase, payment, and license information. |
|
| System metadata | Data generated in the course of running the service. |
|
| Organization information | Data that can be used to identify a particular tenant, deployment, or organization (generally configuration or usage data). |
|
| Customer data | Data that directly identifies or could be used to identify the authenticated user of a Microsoft service. |
|
| Pseudonymous identifiers | An identifier created by Microsoft tied to the user of a Microsoft service. |
|
How long does Microsoft Support have access to tenant data?
Microsoft Support loses access to your tenant data when the support tenant is removed from your cross-tenant access settings. This process is automated and directly linked to the lifecycle of support cases within your tenant.
If a case is open for more than 30 days, access is revoked automatically, provided there aren't any other, newer cases opened. You can restore access by opening a new support case or reopening a closed case.
You can revoke access at any time by deleting the Microsoft Support tenant partner in your cross-tenant access settings. To remove the Microsoft Support tenant, which is listed as Office 365 with Tenant ID
b4c546a4-7dac-46a6-a7dd-ed822a11efd3, see Cross-tenant access settings: Remove an organization.Caution
If you revoke access manually, Microsoft Support loses the ability to help resolve your support cases.
What happens when a support case is closed?
When a support case is closed, Microsoft checks if there are any other active support cases open. If there are no other active support cases, Microsoft initiates the access revocation process, which includes multiple steps.
How long is diagnostic data retained in Microsoft systems?
Microsoft retains diagnostic data related to your support case for up to 28 days after collection. After this period, Microsoft deletes the data.
For information about how Microsoft protects your data, see Privacy and data management overview.
Who can create support cases?
Roles to create a support case and a cross-tenant access policy resource
Users assigned the following roles can create a support case and the cross-tenant access policy resource needed for the case:
Roles to create a support case only
Users assigned one of the following roles can create a support case, but they can't create a cross-tenant policy resource:
- Application Administrator
- Authentication Administrator
- Authentication Policy Administrator
- Azure Information Protection Administrator
- Billing Administrator
- Cloud Application Administrator
- Compliance Administrator
- Compliance Data Administrator
- Desktop Analytics Administrator
- Dynamics 365 Administrator
- Exchange Administrator
- Fabric Administrator
- Global Secure Access Administrator
- Groups Administrator
- Helpdesk Administrator
- Hybrid Identity Administrator
- Insights Administrator
- Intune Administrator
- Office Apps Administrator
- Power Platform Administrator
- Privileged Authentication Administrator
- Security Operator
- Service Support Administrator
- SharePoint Administrator
- Skype for Business Administrator
- Teams Communications Administrator
- Teams Telephony Administrator
- User Administrator
- Windows 365 Administrator
For more information about roles in Microsoft Entra ID, see Support least privileged roles.