← Back to insights

Managed service providers · 19 August 2026 · 4 min

First line can resolve identity tickets itself — if nobody has to grant it rights first

The most expensive flow in an MSP is the ticket waiting for someone with access. Delegation without standing rights lets first line complete identity tickets — safely, traceably and without escalation.

Count the escalations in your own service desk for a week, and a pattern emerges: a large share of identity tickets — group membership, license assignment, new user, changed role — are not resolved where they are received. They are escalated. Not because they are technically difficult, but because first line is not allowed: the rights required to execute the change in the client's tenant are too broad to hand to everyone who answers the phone.

It is a rational restriction in Microsoft's model, where "being able to make the change" and "holding rights in the directory" are the same thing. The consequence, all the same, is that the MSP's most expensive people spend their time on the tickets requiring the least expertise — and that the client waits in second line's queue for something that should have taken four minutes.

Entra Logic separates the two. First line works in the administration portal against a continuously synchronised copy of the client's environment: they find the user, see the groups, licenses and devices, and create an order — structured and correct from the moment it is submitted, because the portal knows what type of change it is and which tenant it concerns. The order follows whatever approval flow the client's per-tenant configuration prescribes. Simple, pre-approved change types can go straight to execution; everything else passes the right approver — on your side or the client's. Execution happens automatically against Microsoft Graph, and the technician who created the order never held rights in the tenant.

Note what did not happen: nobody had to assess whether this particular technician can be trusted with this particular client's directory. The trust question has moved from person to process — anyone in first line can safely propose anything, because nothing happens without approval and everything is logged.

The gains land in three places at once. First-line resolution rate goes up, because the category "can't — no access" disappears. Second line gets back the hours currently spent executing other people's fully diagnosed tickets. And the client experiences shorter response times on exactly the tickets that generate the most day-to-day friction — the new hire waiting for access, the manager waiting for the group change.

The model reaches beyond your own service desk. The same mechanism lets you delegate to the client's own people: HR can submit new hires, a department manager can request group changes — without anyone at the client receiving rights, and without it becoming a support ticket at your end at all. Every delegation is an order flow with approval, not a rights assignment.

Run the numbers: identity tickets per month, times the cost difference between first and second line, plus the waiting time the client is spared. It is rarely a small number.

RELEVANT SOLUTION

See how this is handled in practice:

Norwegian version: Les artikkelen på norsk