Forum Discussion

Thortonne's avatar
Thortonne
Copper Contributor
Dec 12, 2025

Using GDAP with Purview Roles for Search and Purge

I'm facing an issue that I believe may be related to how my current employer has set up GDAP, but I am struggling to get a solid answer on the solution to the issue as it's not clear if the problem is simply a limitation through GDAP or something not configured correctly.

 

Scenario: We have a GDAP relationship set up with 20+ clients that provides us with Entra roles such as Security Operator, User Administrator, etc. Various Entra roles to perform common tasks as an MSP

We are currently unable to perform email purges using Explorer in Defender or Purview, as the role required appears to be only assignable to a user account or group that exists in the tenant in question, and as we are acting through GDAP, there is no account or group to give that role to.

On the back of this, I have several questions/requests:

  1. Should a GDAP relationship also create some group or guest/external user that roles of this nature can be assigned to?
  2. Is there something specific we need to do through our GDAP configuration to allow us to search and purge emails?
No RepliesBe the first to reply

Resources