Create a specific customer service account (customer consent)

You can still use Cloud User Hub to manage your customer even where they have denied you access to their tenant through your partner service account. For example, they have removed the admin relationship, introduced additional security settings, or you already have GDAP permissions.

In this scenario, you would require customer consent to manage the customer through Cloud User Hub.

To achieve this, ask the customer to log into their tenants and create a dedicated service account to use in Cloud User Hub for configuring their services. This provides the least privileged access to the specific customer tenant. After creating the service account, work with the customer to verify the account settings.

  1. The customer signs into the Azure Active Directory Admin Center

  2. Choose Users

  3. Click New user > Create new user

  4. Populate the required User name and Name fields.

    We recommend using a username that easily identifies this user as the Cloud User Hub service account

  5. Click on the User link beside "Roles"

  6. Select any of the roles that you would like to manage in Cloud User Hub

    For example, to manage "Teams" in Cloud User Hub, find and assign the "Teams" roles

  7. Set a Usage location

  8. Click Create to add the service account

Verify the Cloud User Hub service account settings

  1. Sign into the Azure Active Directory Admin Center with the newly created Cloud User Hub service account

  2. Update your password when prompted

  3. Ensure MFA is configured

  4. Once MFA is configured, you are directed to the Microsoft Partner Center portal

  5. Select Users

  6. Choose your Cloud User Hub service account

  7. Click Assigned roles

  8. Ensure the user is assigned the relevant roles. From the above example, these would be the roles related to "Teams"

Now that you have configured the customer-specific service account, you can work with the customer to add their tenant in Cloud User Hub. Once onboard, you can manage the customer in exactly the same way as you would in a partner-managed scenario.