This article guides you through the process of connecting a customer tenant to PRISM under the Microsoft CSP program. The process has four stages that need to be completed in sequence:
- Create a transitioning tenant
- Associate the customer tenant with the transitioning tenant
- Coordinate with our Operations Team to transfer subscriptions
- Setup tenant access
Create a transitioning tenant
To connect a customer tenant, a transitioning tenant needs to be created in PRISM.
- From the PRISM Portal, select Programs > Microsoft CSP
- Select Connect Tenant
- Enter details for a new customer or select an existing customer, select Next
- Enter details for the tenant, select Next
- Copy the Partner Connect link or see the ‘Confirm Tenant Transition…’ email. These will be required for the next stage
Transitioning tenants appear under the Onboarding category on the Microsoft CSP Tenants screen.
The Partner Connect link is also available from the Manage Tenant screen for transitioning tenants. If a transitioning tenant is no longer needed, it can be cancelled.
Associate the customer tenant with the transitioning tenant
To associate a customer tenant with the transitioning tenant, launch Partner Connect.
- Open Partner Connect using any of the screens or email shown above
Note:
- You can share the link or email with another person for them to complete this process; a PRISM account is not required.
-
From the Connect Tenant screen in Partner Connect, select Next
- From the Sign In screen, select Sign in with Microsoft
-
Sign in to the customer tenant using an administrative account
Important:
- The account requires the ‘Privileged Role Administrator’ role or higher.
- When prompted, accept the requested permissions, these can be revoked later.
- You do not need to consent for the organisation.
-
From the Tenant Details screen, confirm you’ve signed in to the right tenant and the PRISM customer and customer tenant details match. Then, select Next.
- From the Reseller Relationship screen, use the Accept Reseller Relationship link to open Microsoft Admin Center and accept our reseller relationship.
Important:
- Do not bookmark the link, as it’s tailored to the customer tenant.
- Make sure you sign in to the same customer tenant.
- Confirm you’ve accepted our reseller relationship, then select Next
- From the Complete screen, open Microsoft My Apps to revoke the accepted permissions, then sign out. See Revoking Partner Connect Permissions below for guidance.
Once you’ve completed these steps, it may take up to an hour before the tenant appears as active in PRISM.
Transfer Subscriptions
Coordinate with the Operations Team to transfer subscriptions to Crayon. If no subscriptions need to be transferred, skip this step.
Azure subscriptions
If Azure subscriptions need to be transferred, provision an Azure plan subscription via PRISM. This is a pre-requisite step for any Azure subscription transfers.
- From PRISM, navigate to the Manage Tenant screen
- Select Add New Azure Plan (right side of screen)
Setup Tenant Access
When a customer tenant is transferred to Crayon, we have no access by default. Until access is in place, some PRISM functions will not work, and Partner Earned Credit (PEC) will not be attributed to Azure subscriptions (Microsoft CSP Indirect only). Without PEC, discounted pricing won’t be offered for Azure subscription usage.
To set up tenant access:
- From PRISM, navigate to the Manage Tenant screen
- Select Navigate to… > Partner Connect - Setup Access (right side of screen)
- From the Setup Access screen in Partner Connect, select Next
- From the Sign In screen, select Sign in with Microsoft
- Sign in to the customer tenant using an administrative account
Important:
- The account requires the ‘Privileged Role Administrator’ role or higher. If Azure subscriptions require access to be assigned, the ‘User Access Administrator’ role is required on each Azure subscription.
- When prompted, accept the requested permissions, these can be revoked later.
- You do not need to consent for your organisation.
- Accounts with the Global Administrator role do not have the necessary access to Azure subscriptions by default, see Elevating Global Administrator Access to Azure Subscriptions below.
- From the GDAP Relationships screen, review any pending relationships. Open Microsoft Admin Center to accept any pending relationships, then select Refresh to update the status. Select Next.
- From the Azure Subscriptions screen, review any subscriptions with role pending. Select Assign Access to assign the Owner role to our AdminAgents group using your account. Select Next.
- From the Complete screen, open Microsoft My Apps to revoke the accepted permissions, then sign out. See Revoking Partner Connect Permissions below for guidance.
Once you’ve completed these steps, the process of connecting a customer tenant is complete. You can begin transacting with Crayon by managing subscriptions from PRISM.
Elevating Global Administrator Access to Azure Subscriptions
Tenant roles and Azure subscription roles have different scopes and are managed separately. By default, the tenant-level Global Administrator role does provide the required Azure subscription-level access. However, access can be established by enabling ‘Access management for Azure resources’. See Azure RBAC – Understand the different roles for further information.
To elevate access:
- Open the Azure Portal and sign in to the customer tenant
- Open Entra ID
- Select Manage > Properties
- Enable ‘Access management for Azure resources’
- Select Save
You must sign out of the account, then sign in again for the change to apply. Disable the option once Azure subscription access is no longer required.
Revoke Partner Connect Permissions
Permissions granted when signing in to Partner Connect can be revoked using Microsoft My Apps.
- Open Microsoft My Apps
- Sign in with the same account used with Partner Connect
- Locate the Partner Connect app, select … > Manage your application
- Select Revoke consent (right side of screen)
Troubleshooting
Partner Connect shows ‘tenant not found’ or redirects to the homepage
This can occur if the Partner Connect link has expired or is not in the right format. Navigate to the transitioning tenant in PRISM and copy the Partner Connect link again.
Partner Connect shows ‘tenant already connected’
This can occur if the transitioning tenant in PRISM has already been connected to a customer tenant. Navigate to the customer in PRISM then review the Microsoft CSP tenants.
Partner Connect shows ‘tenant already confirmed’ on the Tenant Details screen
This can occur when the ‘Associate the customer tenant with the transitioning tenant’ process has already been completed, but the tenant is not yet active. Please allow for up to an hour for confirmed tenants to become active.
Partner Connect shows ‘tenant still onboarding’
This can occur when the ‘Associate the customer tenant with the transitioning tenant’ process has not been completed. Navigate to the transitioning tenant in PRISM and open Partner Connect again.
Partner Connect shows ‘session expired’
When starting the connect tenant or setup access process in Partner Connect, you have 15 minutes to complete the process. If your session expires, launch the process again using the Partner Connect link.
Comments
0 comments
Article is closed for comments.