PAL Partner Admin Link - Partner Facing
PAL Partner Admin Link - Partner Facing
Customer
Customer and Partner links Customer and
provides
1 partner enter 2 partner with 3 MPN ID to the 4 partner receive
an agreement user account reporting
admin access
Customer determines access to their Customers grant partners access to their • All attributes of the user • Customer and partner facing reporting
Azure environment based on the environment via 3 mechanisms today: credentials are now associated based on the link
engagement with the partner 1. External user (guest access) with the partner (MPN ID)
2. Service principal • The link is per user credential
3. An account within the customers per customer tenant
directory
Scope Of Tracking
• Management access for Azure
• Spans all licensing programs (i.e. EA, web direct, CSP)
• All partners can link including when work overlaps
Information linked:
• User credentials
• Scope of access
• Admin role granted
• Resources under management
• Consumption of resources
Creating A Link
Linking can be done through three mechanisms
1. PowerShell
2. Command Line Interface (CLI)
3. Azure Management Portal UI – coming soon
*Partner Admin Link is not a replacement for existing partner incentives programs. Partners should
continue participation in programs like DPOR in addition to participation in this preview.
Timeline: Partner Admin Link
Post GA improvements
• Customer reporting
• Internal Microsoft reporting
• Improvements to partner reporting
Maintaining Customer Privacy
Partner Admin Link respects customer’s management controls:
• MPN ID is added as an attribute to the user profile
• The MPN ID is stored separately from the customer’s data
• Linking is transparent to customers via the management portal,
documentation, and customer facing reporting
• Linking an ID does not change, add or amend the partners access to customer
resources or data
• Partners will not see any customer identifiable data that has not been granted by
the customer through granting administrative credentials
• The link abides by any change to the admin credential scope (increase, decrease or
removal of access)
• When a customer revokes admin rights the link is removed and reporting ceases
Questions & Assistance
[email protected]
Link to documentation:
aka.ms/partneradminlink
Q: If a consultant is using their work credentials as a “guest” in multiple customer accounts will they need to associate the MPN ID
once or multiple times?
A: If a consultant from the partner is using the same credentials in multiple customer’s environments they will need to associat e an
MPN ID in each customer environment. The association happens on a per customer environment basis and is not inherited in all
customer environments.
Q: Will another partner be able to write over my MPN ID if I link it within a customer account
A: No, the link is established as an attribute for a set of user credentials. Only the individual who is using the credentials can set or
change the MPN ID