Integrations

Anonymous

Partner-Center (GDAP) Authorization Mode for Microsoft 365/Intune Integrations
Beyond per-customer App Registrations, we’d like Hudu to support an alternative authorization model that connects once to our Microsoft Partner Center tenant and leverages existing GDAP relationships to access customer environments. This mirrors how N-Central and other MSP tools operate: authorize once at the partner level, then enumerate and scope access to customers via GDAP. Goals • Eliminate repetitive, error-prone per-customer App Registration steps. • Use our partner.microsoft.com context (Partner Center APIs) + GDAP to securely access each customer tenant. • Let Hudu simply link customers to the corresponding Partner Center / tenant IDs—no separate app setup per client. Desired functionality 1. Single partner authorization • Connect Hudu to the partner tenant (Entra ID) once, using a standardized Hudu app profile. • Store tokens/credentials securely; surface expiry dates and renewal reminders in Hudu. 2. Customer discovery & mapping • Enumerate customer tenants from Partner Center. • Map each tenant to an existing Hudu customer (manual or rule-based matching), with override options. • Show GDAP status/scope per customer (active, pending, missing permissions). 3. Scoped cross-tenant access • Reuse the single partner connection to pull Microsoft 365 / Intune data from each customer tenant, strictly within GDAP scopes. • Support least-privilege permission sets; provide a permissions checklist and health/status view per tenant. 4. Operational controls • Per-customer enable/disable toggles for data sync (M365, Intune, Defender, etc.). • Clear audit logs of sync actions and authorization events. • Optional fall-back: allow per-tenant App Registration for customers outside GDAP or with special requirements. 5. Security & lifecycle • Secrets/certificates stored encrypted; rotation workflows and expiration alerts in Hudu. • Visibility into failures (e.g., GDAP expired/insufficient) with actionable error messages. Benefits • One connection, many customers: massively simpler setup and maintenance. • Fewer auth failures: no scattered app secrets per tenant; centralized token lifecycle with alerts. • Faster onboarding: link the customer in Hudu and start syncing immediately when GDAP is in place. • Least privilege by design: access constrained by GDAP scopes, improving security posture. In short, we’re requesting a Partner-Center (GDAP) authorization mode that lets Hudu authenticate once at the partner level and securely access customer tenants via GDAP—reducing complexity, avoiding per-tenant app registration overhead, and improving reliability for Microsoft 365/Intune integrations.
0
Load More