Adding a Client to Lighthouse / GDAP (Indirect via Ingram Micro)
Overview
This process outlines how Nordic IT:
- Establishes the Indirect Reseller relationship via Ingram Micro
- Deploys GDAP access using Microsoft 365 Lighthouse
- Configures auto-renewal in Partner Center
This ensures:
- Secure, role-based access
- No onboarding delays
- No unexpected loss of access
๐ Standard Access Model (READ FIRST)
Nordic IT performs all actions on behalf of the client using a dedicated Global Admin account stored in Bitwarden.
Global Admin Naming Standard:
- nordicits@<client>.onmicrosoft.com
Core Rule:
All approvals are completed internally using Bitwarden-stored Global Admin credentials.
Do not send approval links to the client unless explicitly instructed.
What This Means for Techs:
- โ Log in as the client to approve relationships
- โ Do NOT wait on the client
- โ Complete the entire process yourself
Prerequisites
- Client has Microsoft 365 subscription
- Global Admin exists in Bitwarden
- Access to Lighthouse and Partner Center
Step 1 โ Establish Indirect Reseller Relationship
Accept Indirect Reseller Relationship
Approval Process:
- Open InPrivate browser
- Retrieve Global Admin from Bitwarden
- Sign in as nordicits@<client>.onmicrosoft.com
- Accept relationship
Result: Nordic IT becomes the Indirect Reseller
Step 2 โ Assign GDAP via Lighthouse
Navigate
- Open Microsoft 365 Lighthouse
- Go to Home โ Delegated access
- Select GDAP templates
Assign Template
- Select Helpdesk Admins
- Click the three dots (โฎ)
- Click Assign template
What Happens:
- Select tenant
- Relationship is created
- Status = Pending
Step 3 โ Approve GDAP Relationship (Bitwarden Process)
Get Link
- Go to Delegated access โ Relationships
- Locate tenant (Pending)
- Copy approval link
Approve Internally
- Open InPrivate browser
- Retrieve Global Admin from Bitwarden
- Paste approval link
- Sign in as client Global Admin
- Click Approve
Result:
- Relationship = Active
- Access is live
Important:
Always use an InPrivate browser. Failure to do so may approve under the wrong tenant.
Step 4 โ Enable Auto-Extend (REQUIRED)
Why This Matters:
- GDAP relationships expire
- Lighthouse does NOT auto-renew
- Without Auto Extend:
- Access will be lost
- Tenant disappears from Lighthouse
- Relationship must be rebuilt
Steps (Partner Center)
- Open Microsoft Partner Center
- Go to Customers โ Client โ Admin relationships
- Open the GDAP relationship (LHSetup: <GUID>)
Enable Auto Extend
- Locate: Auto Extend = Disabled
- Toggle to: Enabled
Result:
- Relationship auto-renews
- No future access interruption
Important:
Auto Extend must be enabled on every GDAP relationship. Lighthouse does not manage renewal.
Step 5 โ Verify
- Relationship = Active
- Auto Extend = Enabled
- Tenant visible in Lighthouse
- Access functioning
Fix: Legacy / Broken Scenarios
Scenario A โ Advisor Only (No GDAP)
Common with older clients onboarded before Indirect Reseller existed
Cause:
- Tenant only has Advisor relationship
- No Indirect Reseller + no GDAP
Fix (Full Rebuild Required):
- Start with Step 1 (Indirect Reseller link)
- Complete Step 2 (Assign template)
- Complete Step 3 (Approve GDAP)
- Complete Step 4 (Enable Auto Extend)
Result:
- Upgraded to Indirect Reseller
- Fully managed via GDAP + Lighthouse
Scenario B โ GDAP Exists but No Access
Fix: Reassign template and reapprove if needed
Scenario C โ Access Lost
Cause: Auto Extend not enabled
Fix: Recreate GDAP and enable Auto Extend
Scenario D โ Still Using DAP
Fix: Replace with GDAP and remove DAP
Common Gotchas
| Issue | Cause | Fix |
|---|---|---|
| GDAP stuck Pending | Not approved | Approve via Bitwarden |
| Wrong tenant approved | Cached login | Use InPrivate |
| Access lost later | Auto Extend off | Enable in Partner Center |
| Tenant missing | Relationship expired | Recreate GDAP |
| Advisor only | No Indirect Reseller | Start at Step 1 |
Quick Checklist
- Accept Ingram relationship (Bitwarden GA)
- Assign Lighthouse template
- Copy approval link
- Open InPrivate browser
- Log in with Global Admin
- Approve relationship
- Enable Auto Extend
- Verify access
Internal Best Practices
- โ Always use Bitwarden Global Admin
- โ Never rely on client for approvals
- โ Always enable Auto Extend
- โ Always use InPrivate browser
- โ Standardize Lighthouse templates
- โ No DAP โ GDAP only
