Enabling/Disabling Delegated Administration Privileges (DAP) in MS services

It has come to our attention that delegating administration privileges (DAP) for Microsoft Services might pose a security concern for certain organizations. As such, we have added an option inside each Microsoft Cloud Services integration instance that allows you to choose when a Storefront user can or can’t delegate DAP rights depending on the organization’s needs.

 

Locating the “Enable DAP” Option


To locate the “Enable DAP“ option to either enable it or disable it, you must navigate to BSS Setup > System Options > Application SetUp > Microsoft Cloud Services and click on the Settings button. Then you must select the instance for which the DAP changes will take effect.

 

Enabling DAP


Once the BSS admin user sets the “Enable DAP” checkbox to true, the Storefront during the ordering process will display the DAP checkbox: “Include delegated administration privileges for Azure Active Directory and Office 365.“ where the Storefront user can delegate or not the admin privileges to the distributor or/and reseller.


Disabling DAP


Once the BSS admin user sets the “Enable DAP” checkbox to false, the Storefront during the ordering process will not display the DAP checkbox: “Include delegated administration privileges for Azure Active Directory and Office 365.“ and accordingly the delegation link is set by default to false, since no delegation of admin privileges occurs to the distributor or/and reseller.

 

Tenant Resellers


Concerning the Tenant Resellers, their organization’s DAP set-up option will not be displayed since its value is directly inherited from the Root organization.

 

Country Tenants


Concerning the Country Tenants, their organization’s DAP set-up option will be available for the admin user to define it. The DAP checkbox inherits its default value from the Root organization.

 

Standard Resellers


Concerning the Standard Resellers, the set-up of the Root organization dictates whether the DAP checkbox: “Include delegated administration privileges for Azure Active Directory and Office 365.“ will be displayed or not during the checkout process inside the standard reseller’s Storefront.