
Microsoft Lighthouse GDAP Configuration
Software as a Service
NoCategory
Cloud & InfrastructureClients
Techstack
Purpose
Broad delegated admin access meant a single compromised account could reach far more than any one task required — a large, unnecessary risk sitting across every client tenant. The team needed access scoped tightly to the roles each job actually needs, without breaking the multi-tenant workflows they rely on daily.
Description
We replaced wide-open delegated access with tightly scoped admin relationships, mapping security groups to least-privilege roles for each client tenant. Every administrative role now carries only the permissions it needs, so a compromised account can reach far less while everyday management keeps running. Access is applied the same way across every managed tenant rather than granted wholesale. The result is a cleaner, auditable access model that stands up to a security review.
Results
- Least privilege
admin access scoped to exactly what each task needs
- Smaller blast radius
far less exposure if an admin account is compromised
- Every client
the same tight access model across all managed tenants
- Fully auditable
a clear record of who can do what


