Article managed by Court McMullin
Customer access setup, access review, removal, and administration
Prepared September 2026
Figure 1. CallTower Access Portal landing page
1. Before You Begin
Use this guide when a customer needs to grant CallTower access to a Microsoft 365 tenant, review access that was previously granted, or remove that access. The customer workflow does not require an account to begin.
Have the primary Microsoft 365 domain ready, for example contoso.com.
For new access, have a Microsoft Global Administrator available to complete device-code sign-in and consent.
For Commercial tenants using GDAP, the customer must approve the relationship in the Microsoft 365 admin center.
GCCH tenants use the government Microsoft Graph cloud. GDAP is available only for Commercial tenants.
The portal never asks CallTower to receive or store the customer password. Microsoft handles sign-in and consent directly.
2. Grant New Access
1. Open the portal
Open the CallTower Access Portal. Confirm that the page shows Connect your Microsoft tenant and that the progress indicator is on Tenant.
2. Enter the customer domain
Type the primary domain associated with the Microsoft 365 tenant in Customer domain, then select Continue. The portal detects the tenant cloud and checks whether a previous CallTower setup exists.
Figure 2. Access selection after tenant detection
3. Choose the services CallTower provides
Select one or more services: Direct Routing, Operator Connect, or Microsoft 365 Licensing. If Microsoft 365 Licensing is selected, also select at least one licensing service: Phone System, Email, or File Storage.
4. Choose access packages
Select Voice App Connector to connect calling services to Microsoft Teams. Select GDAP for delegated administration and troubleshooting access. The portal calculates the permissions and roles from these choices.
Figure 3. Service and access-package selection
5. Review the calculated access
Review the application permissions, directory roles, GDAP roles, relationship duration, and auto-renew setting. Use the information buttons beside permissions or roles when you need an explanation. Leave required roles selected.
3. Complete Microsoft Approval
After selecting Next, the portal opens the Enable Access workflow. It shows the requested access on the right and the connection steps on the left.
Figure 4. Enable Access workflow with the access summary
1. Review access: Select Review access and read the access summary. Confirm that the requested permissions and roles match the services being deployed.
2. Copy the device code: Copy the one-time Sign-in code shown in the Voice App Connector step. The code is short-lived and should be treated as temporary authentication information.
3. Sign in at Microsoft: Select Login to Microsoft. In the Microsoft device sign-in page, enter the code and sign in with a Global Administrator account. Complete the Microsoft consent prompt. CallTower does not receive the password.
4. Wait for the portal to detect approval: Return to the portal and leave the page open. It checks Microsoft automatically. The Voice App Connector step changes when approval is complete.
5. Approve GDAP, if shown: After Voice App Connector approval, the portal creates the GDAP relationship and provides an approval link. Open the Microsoft 365 admin center link and approve the relationship as the customer administrator.
6. Confirm completion: Leave the portal open while GDAP status and assignments are checked. The workflow completes when the relationship is approved and the CallTower assignments finish.
Existing Access Detected
When the portal finds a previous CallTower setup for the customer domain, it displays Access may already be connected. The customer must choose whether to inspect the current access or start a separate access request.
Figure 6. Existing access detected for the customer tenant
Choose Review existing access when
You need to confirm which Voice App Connector permissions and directory roles are currently present.
You need to view GDAP relationships, approval status, or assignments.
You need to edit or remove existing Voice App Connector or GDAP access.
Select Review existing access. The portal prepares a fresh, read-only Microsoft device-code sign-in. Complete that sign-in with a verified Global Administrator account, then review the report before making changes.
Choose Grant new access when
The customer needs an additional or new access request.
The existing setup should remain unchanged while a new service request is configured.
Select Grant new access to return to service selection. Choose the services CallTower provides, select Voice App Connector and/or GDAP, review the calculated permissions, and continue through Microsoft approval.
Important distinction
Review existing access is read-only until the customer explicitly selects an edit or removal action. Grant new access starts the setup workflow and may request Microsoft consent for additional access.
Complete Review Existing Access Process
Use this sequence when the portal reports that access may already be connected. The review is read-only until you explicitly choose an edit or removal action.
1. Enter the customer domain: Enter the primary Microsoft 365 domain and select Continue. When existing access is found, the portal displays the Review existing access and Grant new access choices.
2. Start the review: Select Review existing access. The portal opens the Access review page and prepares a fresh, read-only Microsoft sign-in.
Figure 7. Review sign-in with a one-time Microsoft device code
3. Complete Microsoft device sign-in: Copy the Sign-in code, select Login to Microsoft, and enter the code at the Microsoft device sign-in page. Sign in with a verified Global Administrator account. Microsoft handles the password and consent; CallTower does not receive the password.
4. Wait for the report: Leave the portal open after completing Microsoft sign-in. The portal checks approval automatically and then loads the current Voice App Connector and GDAP information.
Figure 8. Existing-access review report
5. Review Voice App Connector access: Confirm whether the Voice App Connector is Present. Review the number and names of application permissions and directory roles. Select Edit access to adjust the access set, or select Remove Voice App Connector only when removal is intended.
6. Review GDAP relationships: Check the GDAP relationships count and each relationship status. Active means CallTower access is active. Approval pending means the customer still needs to approve the relationship in Microsoft 365. Expired or terminating relationships require follow-up before relying on the access.
7. Expand a GDAP relationship: Select a GDAP relationship row or View Details to inspect its auto-extend duration, activation date, end date, assigned roles, and assigned CallTower group. The details are view-only.
Figure 9. Expanded GDAP relationship details and assignments
8. Handle a pending GDAP relationship: For an approval-pending relationship, select Approve to open the Microsoft 365 admin center. Complete the approval there, then keep the portal open while it polls for activation and assignment completion.
9. Remove access when explicitly requested: Use Remove for an active GDAP relationship or Remove Voice App Connector for the Voice App. Confirm the prompt. Voice App removal starts a fresh Global Administrator sign-in; active GDAP termination is asynchronous and may show Termination requested while Microsoft processes it.
10. Grant additional access: Select Grant additional access if the customer needs another service or access package without leaving the review flow. This returns to the new-access setup process and recalculates the requested permissions and roles.
Review results are based on a fresh Microsoft sign-in and live partner-side GDAP data when Partner Graph is configured. The portal records review and removal activity in AccessAudit.
5. Troubleshooting and Security Notes
Continue is disabled: Enter a domain. If Microsoft 365 Licensing is selected, choose Phone System, Email, or File Storage. Select at least one access package.
The tenant is detected as GCCH: Use the supported GCCH Voice App Connector flow. GDAP is not offered for GCCH tenants.
Microsoft approval is still pending: Make sure the code was entered at microsoft.com/device, the correct account was used, and the Microsoft consent page was completed. Keep the portal page open while it polls.
GDAP is waiting for approval: Open the approval link in the Microsoft 365 admin center and approve the relationship. Assignment processing can continue after approval.
Admin console access is denied: Confirm that the signed-in account belongs to the configured CallTower admin tenant and is authorized for the admin application. Contact the CallTower portal owner if authorization is missing.
Security Reminder
do not share device codes, passwords, client secrets, or access tokens. Keep secrets in Azure Function App settings or Key Vault references, never in frontend code or source control.
