GDAP and the CallTower Teams Voice Connector
Purpose
Explain what access CallTower requests, why it is needed, how it is used, and how customers retain control. Written for customer administrators, security teams, compliance reviewers, and procurement stakeholders
1. Summary
CallTower may request two complementary forms of access to deliver Microsoft Teams voice provisioning, administration, troubleshooting, and professional services. Each is approved through Microsoft-controlled authorization processes.
Access mechanism | Purpose | Security boundary |
Teams Voice Connector | Application-based automation for Teams Direct Routing and selected Operator Connect or professional-services tasks. | Specific Microsoft Graph application permissions plus assigned Microsoft Entra roles. |
GDAP | Role-based access for authorized CallTower support technicians. | A customer-approved GDAP relationship, selected directory roles, and assignments to CallTower security groups. |
Important distinction
GDAP is delegated technician access. The Voice Connector is application access. Approving one does not automatically grant the other.
What customers are approving
Voice Connector consent for the listed Microsoft Graph application permissions and assignment of required Microsoft Entra roles.
A GDAP relationship containing the role set that matches the selected service, followed by access assignments to CallTower support groups.
Optional or conditional access only when the related service is requested.
2. CallTower Teams Voice Connector
The CallTower Teams Voice Connector is a Microsoft Entra enterprise application used to provision and support aspects of Teams Direct Routing and Operator Connect. It allows approved automation without sharing customer administrator credentials.
Microsoft Graph application permissions
User.ReadWrite.All
What it allows | How CallTower uses it | Security review note |
Create and update users across the tenant. | Build Direct Routing activation users and, during professional services, Teams resource accounts for auto attendants and call queues. | Tenant-wide user write access. The stated use is limited to voice activation users and voice-related resource accounts. |
LicenseAssignment.ReadWrite.All
What it allows | How CallTower uses it | Security review note |
Assign and remove user licenses. | License Direct Routing activation users and assign Phone System licenses when authorized. | Can change license assignments. Licensing administration should only be enabled when CallTower is expected to perform it. |
Domain.ReadWrite.All
What it allows | How CallTower uses it | Security review note |
Create and update verified-domain configuration. | Add and verify Direct Routing domains. | Used for Direct Routing domain onboarding. |
CallRecords.Read.All
What it allows | How CallTower uses it | Security review note |
Read call records for calls and online meetings across the tenant. | Monitor calling services and troubleshoot calling-service issues. | Read-only access to call-record data. CallTower uses it for operational monitoring and troubleshooting, not to modify call records. |
Call-record permission
CallRecords.Read.All was added to this guide because CallTower uses call-record data to monitor service health and investigate calling issues. It does not grant permission to alter call records.
Microsoft Entra roles assigned to the app
Role | Status | Use |
Teams Telephony Administrator | Required | Application-based Teams PowerShell telephony provisioning and administration. |
User Administrator | Optional | Professional services that create Teams resource accounts for auto attendants and call queues. |
License Administrator | Optional | Only when CallTower is expected to assign licenses for the customer. |
3. How the Voice Connector Is Used
A Global Administrator reviews and approves the permissions presented by Microsoft.
The customer assigns the required Microsoft Entra role to the enterprise application.
CallTower automation authenticates as the application rather than using a customer administrator password.
Provisioning and support processes use the approved permissions for domain, user, licensing, telephony, call monitoring, and troubleshooting tasks.
The customer can review or remove consent and role assignments through Microsoft Entra.
Separate controls
Microsoft Graph consent authorizes API operations. Microsoft Entra role assignment authorizes role-governed administration. Both controls apply where required.
4. Granular Delegated Admin Privileges (GDAP)
GDAP is Microsoft’s partner access model for granting selected administrative roles in a customer tenant. CallTower uses GDAP when support technicians need tenant access for authorized support, administration, troubleshooting, or professional services.
Approval and assignment flow
The customer selects the role set matching the service scope.
A customer Global Administrator receives and accepts the invitation.
CallTower assigns approved roles to documented support security groups such as Tier 1, Tier 2, and Tier 3 & Engineering.
The active relationship, selected roles, and access assignments determine effective delegated access.
What GDAP is not
GDAP is not a blanket grant to every CallTower technician. The relationship contains roles, while access assignments connect those roles to specific CallTower support security groups.
5. GDAP Role Assignment Breakdown
Internal CallTower groups and the roles they are eligible for
CallTower access group | Roles included |
Tier 1 | Global Reader; Teams Administrator; User Administrator |
Tier 2 | All Tier 1 roles; Exchange Administrator; SharePoint Administrator; Compliance Administrator; Security Administrator |
Tier 3 & Engineering | All Tier 2 roles; Global Administrator (requires a separate short term GDAP request) |
Project Managers | All Tier 1 roles |
6. Role Purpose Glossary
Role | Business purpose in the request |
Global Reader | Read-only visibility used to investigate configuration and support issues. |
Teams Administrator | Broader Teams service administration. |
Teams Telephony Administrator | Teams calling and telephony administration. |
User Administrator | User and voice resource-account administration. |
Domain Name Administrator | Direct Routing domain onboarding and verification. |
Exchange Administrator | Exchange Online administration for full Microsoft 365 support. |
SharePoint Administrator | SharePoint Online administration for full Microsoft 365 support. |
Compliance Administrator | Compliance administration for full Microsoft 365 support. |
Security Administrator | Security administration for full Microsoft 365 support. |
Global Administrator | Highest-privilege directory role, included only in the Full Microsoft 365 set for Tier 3 & Engineering. |
Least-privilege selection
For voice-only service, customers should use the applicable voice-only set rather than Full Microsoft 365 access unless broader support is specifically required.
7. Security and Governance Considerations
Customer approval: Application consent and GDAP acceptance require customer administrator approval.
No password sharing: The Voice Connector uses application authentication; GDAP uses Microsoft delegated partner access.
Scope matching: Select Direct Routing, Operator Connect, Teams-only, or Full Microsoft 365 according to the service.
Call-record data: CallRecords.Read.All enables reading call records for monitoring and troubleshooting. It does not allow CallTower to modify them.
Conditional permissions: User and license administration should be assigned only for the documented scenarios.
High privilege disclosure: The Full Microsoft 365 set includes Global Administrator for Tier 3 & Engineering.
Frequently Asked Questions
Can CallTower read customer email?
No email-reading permission is listed in this Voice Connector request.
Why is CallRecords.Read.All requested?
CallTower uses this read-only application permission to monitor calling services and troubleshoot calling-service issues.
What call information can the permission reach?
The permission grants tenant-wide read access to call records for calls and online meetings. The approved use described here is monitoring and troubleshooting calling services.
Can CallTower modify call records?
No. CallRecords.Read.All is a read permission and does not grant write access to call records.
Can CallTower create users?
Yes, when User.ReadWrite.All is approved. The stated use is Direct Routing activation users and voice-related resource accounts.
Can CallTower assign licenses?
Yes, when LicenseAssignment.ReadWrite.All and the necessary role are approved.
Why is Domain.ReadWrite.All requested?
To add and verify Direct Routing domains.
Does every GDAP request include Global Administrator?
No. It appears only in the Full Microsoft 365 set for Tier 3 & Engineering.
Are GDAP and the Voice Connector interchangeable?
No. GDAP is delegated technician access; the Voice Connector is application access.
