Skip to main content
You can use Partner Center for most clients and Direct access for an exception in the same workspace. A client does not have to be in your partner customer list to use a direct connection: an administrator of that client’s Microsoft tenant authorises access instead. For example, your MSP uses Partner Center for Acme, but a newly onboarded client has no GDAP relationship with you. Keep the workspace default and select Direct for that client.

Before you begin

  • Create or identify the correct Alignr client.
  • Have the Microsoft tenant ID belonging to that client, rather than your MSP’s tenant ID or its Alignr Organization ID.
  • Use a role with integration.read to view connection settings and integration.manage to change them. You also need access to the client.
  • For Direct, arrange for a client administrator who can approve the requested Microsoft application permissions. For Partner Center, your partner authorisation, customer consent and GDAP access must be in place.
GDAP is Microsoft’s granular delegated admin privileges relationship between a partner and a customer. Selecting Partner Center in Alignr does not create that relationship or give your partner user additional roles. See Microsoft’s GDAP introduction for the underlying access model.

Understand the default and the client choice

The default chooses a method; it does not authorise every client. The partner account itself is selected at workspace level. There is no separate partner-account picker in the client form. Alignr uses the selected route for Microsoft evidence. If it is incomplete, the client has a visible setup gap; Alignr does not silently switch to the other route to fill it.

Set your usual workspace connection

Open Settings → Microsoft. Under How your clients connect, choose Default connection method:
  1. Choose Partner Center · use your partner account.
  2. Choose an enabled live Partner account, or select Add partner connection.
  3. Select Save Microsoft defaults.
  4. Select Authorise partner account and complete Microsoft’s authorisation.
  5. Return to each client’s Connections tab to confirm its customer assignment and access.
Use the Microsoft 365 partner-access connection for these identity checks. The separate Partner Center connection that supplies customer lists and purchased subscriptions does not itself grant this Graph access.
Checkpoint: the workspace default is saved. Client setup remains a separate task.

Connect a client outside your partner relationship

Use this path when the client is not in Partner Center, has no suitable GDAP relationship, or needs the supported Direct route for Intune device checks.
1

Open the client's Microsoft settings

Open Clients, select the client, then Connections. Find How this client connects in the Microsoft section.Check the client name before making changes. This is a client preference, so you do not need to change the workspace default for your other clients.
2

Save a Direct preference

Set Connection method to Direct. Enter the client’s Microsoft tenant ID and select Save preference.Checkpoint: the saved summary says Currently using Direct. Choosing an option without saving has not changed the active route.
3

Prepare the direct connection

Under Authorise this client directly, leave Use my own Microsoft application unticked to use the Alignr application. Select Set up direct connection.Alignr prepares the client’s Entra ID and Intune connections and their client mappings. Preparing those records is not Microsoft consent.If this client already has a direct connection, review the existing connection panel instead of creating another. For a different application or tenant, see Replace an existing connection.
4

Authorise the client tenant

Select Authorise Microsoft in the direct-access panel. Complete the Microsoft authorisation with an administrator of the intended client tenant. Review the requested access on Microsoft’s screen.Alignr uses the client’s direct consent for this route; a partner GDAP relationship is not its prerequisite. Do not authorise your MSP tenant in place of the client’s tenant.
5

Check access, then collect

Return to the client’s connection and select Check access. Review the available and unavailable capabilities. For device evidence, also follow Check Microsoft Intune access and review that connection.Once the required access is available, open the relevant integration, use Sync now when available and inspect Sync history. Confirm fresh evidence belongs to the intended client before running checks.Checkpoint: the client uses Direct, its tenant is correct, and current observations come from its selected connection.
Setting up a direct connection saves an explicit Direct client preference. If you want the client to follow later workspace default changes, select Use workspace default and Save preference after reviewing what that default currently means.

Connect a client through your partner account

In Clients → select client → Connections, choose Use workspace default when that default is Partner Center, or explicitly choose Partner Center. Confirm Microsoft tenant ID and select Save preference. Under Connect this Microsoft customer:
  1. Confirm that the displayed customer name and tenant ID belong to this client.
  2. If an assignment is missing, use Assign Microsoft customer to review and link the correct customer record.
  3. Select Connect client. This checks access and, where authorised, requests missing customer read consent. Your existing GDAP roles must allow it.
  4. Review any unavailable capabilities. The access check does not create a GDAP relationship, collect evidence or run the client’s controls.
  5. Sync the selected connection, inspect collected observations and then run the assessment.
Managed-device checks are currently available through Direct. If you need that route for the client, use the direct walkthrough above rather than assuming partner access supplies Intune evidence.

Change a preference deliberately

Changing the workspace default affects clients that inherit it. Clients explicitly set to Direct or Partner Center keep their chosen method. A client explicitly using Partner Center still depends on the partner account selected in workspace settings. To restore inheritance, open the client’s Connections, choose Use workspace default and select Save preference. Read the Currently using… summary to confirm the resolved method. If workspace setup is incomplete, the form asks you to finish it or choose a client-specific method. After a route change, review access, collect current evidence and evaluate again. A previous result does not prove the new connection is working.

Replace an existing connection

For an existing Direct connection, expand Use a different Microsoft application or tenant and select Set up a different connection. Then prepare and authorise the intended new connection. Current Microsoft evidence stops contributing until the replacement is authorised and synced. Previous connections and history remain in Integrations. Review the tenant ID before proceeding; changing the client setting is not permission to use evidence from a different business. If your organisation needs its own application registration, select Use my own Microsoft application during direct setup and provide Application client ID and Application secret. That application still needs the required Microsoft permissions and consent. Keep the secret in the connection form, never in assessment notes or support screenshots.

If setup needs attention

You are ready to continue when you can name the client’s selected method, its Microsoft tenant, the connection supplying its evidence and any capabilities still unavailable.

Next: check collection and coverage

Confirm that authorised access produces the observations your controls need.