Blog Post
How Granular Delegated Admin Privileges (GDAP) allows Sentinel customers to delegate access
Any concrete date for when this will be rolling out? Some of our more eager customers are getting frustrated that we still manage their Sentinel implementations via the Azure Portal primarily 😅
Access via GDAP gives me the temporary user that can't see Log Analytics Workspaces and the delegated permissions via Lighthouse don't cover the Entra ID permissions required to manage it from the Defender Portal (or am i missing something else?)
This is now in public preview
- Jordan MillsApr 17, 2026Brass Contributor
It seems to be broken. Attempts to send an invitation just return an immediate error:
Failed to send invitation request
Failed to send governance invitation.
- SaggieApr 17, 2026
Microsoft
Hey Jordan,
Have you enabled governance invitations in Microsoft Entra Admin Center for the MSSP tenant (Home tenant)?
By default, this option is disabled to eliminate the risk of actors spamming tenants with invitations.
More info here:
Configure delegated access with governance relationships for multitenant organizations - Unified security operations | Microsoft Learn- Jordan MillsApr 17, 2026Brass Contributor
Nope I had not. It looks like that was missing. But there seems to be a bug in the template creation flow. The list of groups to select from when creating a template is empty and nothing comes up when searching.