Onboard a first tenant
- Establish the GDAP relationship in Partner Center first. PatchPilot can’t create this relationship — the MSP requests it and the customer approves it in Microsoft Partner Center, outside PatchPilot entirely. See Known Issues.
- Once the relationship is active, open Settings > Tenants and click Discover (or the page-level re-probe action) to have PatchPilot pick up the new tenant.
- Confirm its Consent column reads Active and its Reachability column reads Reachable. If Reachability shows Needs consent, the customer’s admin consent for PatchPilot’s app registration is still outstanding — see App Registration.
- The tenant starts read-only. Leave it that way until you’ve reviewed its data; opt in write access explicitly on the same Tenants row when you’re ready to dispatch remediations against it.
- Switch the tenant selector to the new tenant and check Setup > Setup Health > Readiness — this confirms the tenant is actually synced (Defender onboarding present, latest sync succeeded), not just reachable.
- From here, the Dashboard for that tenant should populate on the next scheduled sync. Continue to Remediate a vulnerability.