Skip to content
Microsoft Lighthouse GDAP Configuration — Cloud & Infrastructure project by YenkoDev

Microsoft Lighthouse GDAP Configuration

Software as a Service

No

Category

Cloud & Infrastructure

Clients

Confidential

Techstack

Microsoft 365 LighthouseMicrosoft EntraAzure

Purpose

Broad delegated admin access meant a single compromised account could reach far more than any one task required — a large, unnecessary risk sitting across every client tenant. The team needed access scoped tightly to the roles each job actually needs, without breaking the multi-tenant workflows they rely on daily.

Description

We replaced wide-open delegated access with tightly scoped admin relationships, mapping security groups to least-privilege roles for each client tenant. Every administrative role now carries only the permissions it needs, so a compromised account can reach far less while everyday management keeps running. Access is applied the same way across every managed tenant rather than granted wholesale. The result is a cleaner, auditable access model that stands up to a security review.

Results

  • Least privilege

    admin access scoped to exactly what each task needs

  • Smaller blast radius

    far less exposure if an admin account is compromised

  • Every client

    the same tight access model across all managed tenants

  • Fully auditable

    a clear record of who can do what