MS365 Access and Permissions

Prev Next

GDAP and the CallTower Teams Voice Connector

Purpose

Explain what access CallTower requests, why it is needed, how it is used, and how customers retain control. Written for customer administrators, security teams, compliance reviewers, and procurement stakeholders

1. Summary

CallTower may request two complementary forms of access to deliver Microsoft Teams voice provisioning, administration, troubleshooting, and professional services. Each is approved through Microsoft-controlled authorization processes.

Access mechanism

Purpose

Security boundary

Teams Voice Connector

Application-based automation for Teams Direct Routing and selected Operator Connect or professional-services tasks.

Specific Microsoft Graph application permissions plus assigned Microsoft Entra roles.

GDAP

Role-based access for authorized CallTower support technicians.

A customer-approved GDAP relationship, selected directory roles, and assignments to CallTower security groups.

Important distinction

GDAP is delegated technician access. The Voice Connector is application access. Approving one does not automatically grant the other.

What customers are approving

  • Voice Connector consent for the listed Microsoft Graph application permissions and assignment of required Microsoft Entra roles.

  • A GDAP relationship containing the role set that matches the selected service, followed by access assignments to CallTower support groups.

  • Optional or conditional access only when the related service is requested.

2. CallTower Teams Voice Connector

The CallTower Teams Voice Connector is a Microsoft Entra enterprise application used to provision and support aspects of Teams Direct Routing and Operator Connect. It allows approved automation without sharing customer administrator credentials.

Microsoft Graph application permissions

User.ReadWrite.All

What it allows

How CallTower uses it

Security review note

Create and update users across the tenant.

Build Direct Routing activation users and, during professional services, Teams resource accounts for auto attendants and call queues.

Tenant-wide user write access. The stated use is limited to voice activation users and voice-related resource accounts.

LicenseAssignment.ReadWrite.All

What it allows

How CallTower uses it

Security review note

Assign and remove user licenses.

License Direct Routing activation users and assign Phone System licenses when authorized.

Can change license assignments. Licensing administration should only be enabled when CallTower is expected to perform it.

Domain.ReadWrite.All

What it allows

How CallTower uses it

Security review note

Create and update verified-domain configuration.

Add and verify Direct Routing domains.

Used for Direct Routing domain onboarding.

CallRecords.Read.All

What it allows

How CallTower uses it

Security review note

Read call records for calls and online meetings across the tenant.

Monitor calling services and troubleshoot calling-service issues.

Read-only access to call-record data. CallTower uses it for operational monitoring and troubleshooting, not to modify call records.

Call-record permission

CallRecords.Read.All was added to this guide because CallTower uses call-record data to monitor service health and investigate calling issues. It does not grant permission to alter call records.

Microsoft Entra roles assigned to the app

Role

Status

Use

Teams Telephony Administrator

Required

Application-based Teams PowerShell telephony provisioning and administration.

User Administrator

Optional

Professional services that create Teams resource accounts for auto attendants and call queues.

License Administrator

Optional

Only when CallTower is expected to assign licenses for the customer.


3. How the Voice Connector Is Used

  • A Global Administrator reviews and approves the permissions presented by Microsoft.

  • The customer assigns the required Microsoft Entra role to the enterprise application.

  • CallTower automation authenticates as the application rather than using a customer administrator password.

  • Provisioning and support processes use the approved permissions for domain, user, licensing, telephony, call monitoring, and troubleshooting tasks.

  • The customer can review or remove consent and role assignments through Microsoft Entra.

Separate controls

Microsoft Graph consent authorizes API operations. Microsoft Entra role assignment authorizes role-governed administration. Both controls apply where required.

4. Granular Delegated Admin Privileges (GDAP)

GDAP is Microsoft’s partner access model for granting selected administrative roles in a customer tenant. CallTower uses GDAP when support technicians need tenant access for authorized support, administration, troubleshooting, or professional services.

Approval and assignment flow

  • The customer selects the role set matching the service scope.

  • A customer Global Administrator receives and accepts the invitation.

  • CallTower assigns approved roles to documented support security groups such as Tier 1, Tier 2, and Tier 3 & Engineering.

  • The active relationship, selected roles, and access assignments determine effective delegated access.

What GDAP is not

GDAP is not a blanket grant to every CallTower technician. The relationship contains roles, while access assignments connect those roles to specific CallTower support security groups.

5. GDAP Role Assignment Breakdown

Internal CallTower groups and the roles they are eligible for

CallTower access group

Roles included

Tier 1

Global Reader; Teams Administrator; User Administrator

Tier 2

All Tier 1 roles; Exchange Administrator; SharePoint Administrator; Compliance Administrator; Security Administrator

Tier 3 & Engineering

All Tier 2 roles; Global Administrator (requires a separate short term GDAP request)

Project Managers

All Tier 1 roles

6. Role Purpose Glossary

Role

Business purpose in the request

Global Reader

Read-only visibility used to investigate configuration and support issues.

Teams Administrator

Broader Teams service administration.

Teams Telephony Administrator

Teams calling and telephony administration.

User Administrator

User and voice resource-account administration.

Domain Name Administrator

Direct Routing domain onboarding and verification.

Exchange Administrator

Exchange Online administration for full Microsoft 365 support.

SharePoint Administrator

SharePoint Online administration for full Microsoft 365 support.

Compliance Administrator

Compliance administration for full Microsoft 365 support.

Security Administrator

Security administration for full Microsoft 365 support.

Global Administrator

Highest-privilege directory role, included only in the Full Microsoft 365 set for Tier 3 & Engineering.

Least-privilege selection

For voice-only service, customers should use the applicable voice-only set rather than Full Microsoft 365 access unless broader support is specifically required.

7. Security and Governance Considerations

  • Customer approval: Application consent and GDAP acceptance require customer administrator approval.

  • No password sharing: The Voice Connector uses application authentication; GDAP uses Microsoft delegated partner access.

  • Scope matching: Select Direct Routing, Operator Connect, Teams-only, or Full Microsoft 365 according to the service.

  • Call-record data: CallRecords.Read.All enables reading call records for monitoring and troubleshooting. It does not allow CallTower to modify them.

  • Conditional permissions: User and license administration should be assigned only for the documented scenarios.

  • High privilege disclosure: The Full Microsoft 365 set includes Global Administrator for Tier 3 & Engineering.

Frequently Asked Questions

Can CallTower read customer email?

No email-reading permission is listed in this Voice Connector request.

Why is CallRecords.Read.All requested?

CallTower uses this read-only application permission to monitor calling services and troubleshoot calling-service issues.

What call information can the permission reach?

The permission grants tenant-wide read access to call records for calls and online meetings. The approved use described here is monitoring and troubleshooting calling services.

Can CallTower modify call records?

No. CallRecords.Read.All is a read permission and does not grant write access to call records.

Can CallTower create users?

Yes, when User.ReadWrite.All is approved. The stated use is Direct Routing activation users and voice-related resource accounts.

Can CallTower assign licenses?

Yes, when LicenseAssignment.ReadWrite.All and the necessary role are approved.

Why is Domain.ReadWrite.All requested?

To add and verify Direct Routing domains.

Does every GDAP request include Global Administrator?

No. It appears only in the Full Microsoft 365 set for Tier 3 & Engineering.

Are GDAP and the Voice Connector interchangeable?

No. GDAP is delegated technician access; the Voice Connector is application access.