An MSP Admin can access a customer's archives in order to perform eDiscovery and compliance actions on the customer's behalf. The MSP can access the admin UI to configure the customer's tenant, but by default they will not have access to search customer archives.
MSP access to customer tenants is visible to the customer in the following places:
- The MSP’s login will be shown at the customer’s login URL.
- The MSP’s IDP connection will be displayed under Settings > Authentication.
- MSP Administrator accounts will be shown under Staff Members.
To access a customer’s archive, an MSP user must be able to authenticate to the customer’s archive tenant directly. This means they must either:
(1) have an account on the customer’s IDP; or
(2) have the MSP's IDP connected to the customer’s archive tenant.
Where option 1 is the case, the MSP can simply configure authentication between the archive tenant and the customer’s IDP as they normally would, and log in using the user account they have access to on their IDP.
To achieve option 2, the MSP admin can create a new connection in the customer archive tenant under Settings > Authentication. For most IDPs, this connection can be to an existing registration. For instance, if using Microsoft Entra, the MSP only needs to generate a new client secret in their existing Entra app registration. They can use the same app registration for any number of customer archive tenants.
In order to search as a Privileged User or act as a Data Guardian, an MSP user must also have permissions as a Staff Member in the customer’s archive tenant.
.png)
 1.png)