Configure Microsoft 365 Partner Admin Account

2 - Configure Microsoft 365 partner admin account

To access your tenant list and license details, you need to connect Sync 365 to your Microsoft Partner Center. 

We recommend creating a specific account (e.g.,S365@<yourtenant>) with Admin Agent permissions  to your customer accounts.
If you use custom security groups to apply your GDAP permissions, this account will need to be in one that has Application Administrator and Global Reader permissions.

Important: The Partner Center account used for Sync 365 consent must have Assists your customers as: Admin Agent enabled in Partner Center.

Accounts set as Sales Agent or Helpdesk Agent cannot grant the required Sync 365 application consent, even if the account has GDAP Application Administrator permissions. If the account is not an Admin Agent, Partner Center may return a 403 Forbidden error during application consent.

Free GDAP tool: If you need to create a new GDAP relationship or rebuild one with the correct roles, use the free Sync 365 GDAP Builder. This can help when the relationship is missing, expired, assigned to the wrong security group, or does not include the required roles for Sync 365.

Once you have an account that can access your customer tenants via the Partner Center, you can grant consent to Sync 365  to automate your Microsoft 365 billing.

Step 1: Create or Use an Admin Account

If you already have an account to use, skip to Step 2  below.

To assign an account the proper permissions, refer to the Microsoft Partner Center Permissions Overview, or follow these steps:

  1. Log in to the Partner Center using an account with Global Admin rights.

  2. Click the settings cog in the top right and select Account Settings.

  3. Select User Management on the left.

  4. Choose the user you want to assign permissions to.

  5. Set the permission for "Assists your customers as"  to Admin Agent  

  6. Update the account.

  7. Log in to the Partner Center in an incognito browser window to verify that the account has MFA (Multi-Factor Authentication)  enabled. The account must prompt for MFA on login; otherwise, it will be rejected by the Microsoft Partner Center.

  8. Verify Access: Ensure you can see the customer list with this account. Also, add this service account to the relevant GDAP Security Groups  (which must have at least Global Reader  and Application Administrator  permissions or higher).

    1. The account should be able to access the customer's Azure AD and see the users and licenses.

Step 2: Connect the account to Sync 365

After preparing the Microsoft Partner account and customer access above, connect it from the welcome wizard or the integration settings.

From the first-sign-in wizard

  1. In Step 2: Connect Microsoft Partner Account, select Grant Partner Center Consent.
  2. Choose Direct for your direct Microsoft CSP relationship, or Indirect when you work through a distributor.
  3. Sign in with the prepared Microsoft Partner account and complete the MFA and consent prompts. Your administrator may need to approve the application if consent is restricted in your organisation.
  4. Return to Sync 365 and allow the initial tenant and licence retrieval to finish. Do not refresh while the initial-retrieval banner asks you to wait.

The Microsoft Partner connection step in the setup wizard.

Direct and Indirect choices for Microsoft Partner consent.

If you have already left the wizard

Open Company > Delegated Admin, which takes you to Microsoft Partner account integration settings. Select Add > Grant Partner Center Consent and follow the same Direct/Indirect and Microsoft sign-in process.

Check the connection before continuing

Confirm that the account appears in the Microsoft connections and that customer tenants become available. A successful sign-in alone does not confirm that the account can retrieve every customer's licence data.

If the connection fails or tenants are missing, check the Admin Agent setting, the MFA sign-in, and the account's membership of the relevant GDAP security groups. Follow the prerequisites above and the GDAP overview.

If you return to the dashboard or integrations page instead of the next wizard step, use Continue setup > Add billing profile to resume the current setup flow.

Microsoft Direct CSP

If you are a Direct CSP  with Microsoft, we will detect this during the initial run.

  1. If successful, your user will be marked as a Direct CSP, and you will gain access to features such as:

    • Using subscription IDs  from your Partner Center.

    • Software subscriptions to map to licenses

    • An end-user self-service portal  (note: additional charges may apply when added to a customer tenant).

By following these steps, you will successfully connect Sync 365 to your Microsoft Partner Center, allowing for efficient license management and automated billing. 

If you run into issues, double-check your permissions, MFA settings, and GDAP relationship. You can use the free Sync 365 GDAP Builder if the GDAP relationship needs to be created or rebuilt.

Microsoft GDAP permissions and the Partner Center Admin Agent setting are typically the main causes for issues here.

Continue to Configure Billing Profiles