Conditional Access Policies
Conditional access policies can block partner accounts and apps from accessing the customer tenant. If you have a restrictive conditional access policy on a customer tenant, you need to ensure you have excluded the service providers or the service principal.
You can read about Microsofts recommendations for CA policies and GDAP here: GDAP frequently asked questions - Partner Center | Microsoft Learn
Recommendations
Your Partner Tenant
- Have a conditional access policy that applies to the service account you are using for Sync 365.
- Enforce multi factor authentication
- DO NOT have any trusted locations (The Microsoft Partner Center will block connections where MFA has not been used)
Customer Tenants
Exclude service provider users from ALL conditional access policies
- Log into conditional access policies in the customer tenant
- For each policy add an exclusion to "Users and Groups"
- Select: Guest or external users> Service provider users> Enter your partner tenant ID.
Related Articles
Gaining Access to Customer Azure Subscriptions (Indirect Partners)
As an indirect Microsoft partner, you don’t automatically receive access to your customer’s Azure subscriptions through Partner Center. However, you can still gain access by adding your partner tenant’s Admin Agent group (Or your GDAP security group) ...
Enable End User Self Service Portal (Direct CSP Only)
We have released Version 2 of our End User Portal. *Additional cost for end user portal applies Version 2 Features Grant access and different security levels to an end user for their company Provide access to internal staff for the end user portal - ...
Connectwise API Configuration
For initial setup, follow on in our Getting Started Guide Step 1: Prerequisites Ensure you have admin or user management permissions in ConnectWise Manage. If you self-host ConnectWise and restrict IP addresses or geolocations, make sure to whitelist ...
2 - Configure Microsoft 365 partner admin account
To access your tenant list and license details, you need to connect Sync 365 to your Microsoft Partner Center. We recommend creating a specific account (e.g.,S365@<yourtenant>) with Admin Agent permissions to your customer accounts. If you use custom ...
Azure Automated Billing - Initial Setup (Indirect CSP)
Overview As an Indirect CSP partner, you work through a distributor to access Microsoft services. This guide covers initial setup including vendor markup configuration to start using our Azure Automated Billing. Prerequisites PSA configured in Sync ...