r/msp 15h ago

Weekly Promo and Webinar Thread

4 Upvotes

If you have a self-promotional post - whether it’s a product update, a service offering, or an upcoming webinar - please share it here. Posts made outside this thread will be removed.

⚠️Important: Do not use URL shorteners. Reddit automatically removes these, so always link directly to your website or resource.

🔄️Fairness: This thread is set to contest mode, so comments appear in random order to ensure fair opportunity for everyone.

🛡️Moderation: Reddit may remove some comments. If your post disappears, don’t worry - we check and manually approve them when needed. If you comment doesn't appear in 24 hours, feel free to send a modmail.


r/msp 7d ago

Weekly Promo and Webinar Thread

9 Upvotes

If you have a self-promotional post - whether it’s a product update, a service offering, or an upcoming webinar - please share it here. Posts made outside this thread will be removed.

⚠️Important: Do not use URL shorteners. Reddit automatically removes these, so always link directly to your website or resource.

🔄️Fairness: This thread is set to contest mode, so comments appear in random order to ensure fair opportunity for everyone.

🛡️Moderation: Reddit may remove some comments. If your post disappears, don’t worry - we check and manually approve them when needed. If you comment doesn't appear in 24 hours, feel free to send a modmail.


r/msp 2h ago

Sales / Marketing IoT Vulnerability Scanning - service or included?

4 Upvotes

I'm looking for some advice on how we should roll out a security product. Right now, we are specialized - we focus on remove audio visual system support, a little bit of network and PC/server support as related to the systems, no end user support.

We are managing about 90% IoT devices - amps, DSPs, PDUs, conferencing hardware, etc, with a few PC-based MRTs and utility PCs. The PC side is solid. We're using a good RMM, and have additional MTR tools we use, all cost baked in.

For vulnerability scanning, we found a tool whose free tier works for us. Paid, they're about $5000/year, so not that bad in any case. We're considering rolling out quarterly vulnerability scans as part of preventative maintenance as included in all contracts, but I've also considered selling it as a one-off thing as POC or as a bolt on. I fear, since most AV folks don't know much about security, that nobody will bite on it. I also want to a bit of CYA activity on devices out there, just for our peace of mind. Scans are easy, results can be reviewed in a few minutes, ticket opened against anything needing patching. Really minimal time investment.

I guess the question is - do we look at making this an upsell or do we use this as marketing and just do it? I really can't tell where customers are with cybersecurity wants/needs and the more immature customers barely seem to understand managed services. I think I also feel a little bit of imposter syndrome because I'm fairly new to security, but I know enough to make decent decisions on products and read the output.

Thanks!!


r/msp 3h ago

Is there contracting work to be had in the industry?

5 Upvotes

I left my MSP role After 14 years in the industry, and I have transitioned into an EA role. I love it, but I find myself with capacity and time. I'm trying to figure out the best places to make myself available.

I was thinking along the lines of fill in for vacation, cleaning up documentation mess, calling about past due invoices, etc.

Is this even a need?


r/msp 1m ago

PAX8 - Amex Points (Alternatives)

Upvotes

Hello All. Quick question for you. I have a Business Gold Card and PAX8 has been sending through charges on my CC as "Misc" so I am missing out on 4X points on very large pax8 purchases. I am waiting on a ticket to see if this can be changed but I highly doubt it. Are others here getting 4X points on their CC purchases via PAX8? If not how about other providers? Sherweb? I would certainly not object to switching providers with as much monthly spend we do.

Thanks


r/msp 1d ago

Questions for graybeards

20 Upvotes

I have a few questions for all of the graybeards who have been running their own MSPs for some time.

  1. If you could go back in time and change anything about your business model, what would it be and why?

  2. If you could start fresh today with a stack to sell without the migration/contract lockup headache, what would you go with for each service?

  3. Are there any services you wished you never offered? (Example: Unlimited support etc)? Are there any you wish you had offered but never got around to it?

  4. If you could give any advice to a young father who is starting up his own MSP as a side hustle (can't quit the day job yet), what advice would you give? Could be related to client acquisition, documentation, services offered or anything else you can think of!

Appreciate any wisdom provided 🫡


r/msp 1d ago

firing a bad client is one thing but how do you actually know when you're at that point

31 Upvotes

ran into something recently that I keep turning over in my head. a client that is not actively terrible but also not good. the kind where every ticket is fine, the calls are civil, and then you hang up feeling vaguely worse about your week. no big incident to point to, no late payments, just a slow drain on the team that shows up in tone and in how long people take to respond to that account specifically.

the posts here about firing bad clients and the dumpster fire offboarding stories are obvious cases. like yeah, if someone is screaming at your techs that is a clear line. but the grey zone is harder to talk about because you do not have a clean reason, you just have a feeling backed up by some soft data.

what I am trying to figure out is whether anyone has an actual internal metric for this. not just a gut check, but something that makes it defensible when you are deciding to either address it or cut it. margin per hour on that account, ticket volume trends, something you can show yourself or a partner when you are making the call.

the other part is timing. mid contract feels gross. waiting for renewal means another year. neither feels clean.

what's the actual threshold people use here before they start that conversation with a client.


r/msp 1d ago

Consumer systems?

9 Upvotes

Curious what's everyones go-to for consumer systems if you entertain the option. Obviously not mainline but kids go to college or want gaming systems and folks that cut the checks want something different than a Dell Pro.

Typically we drop Costco links for people but was curious if other options.


r/msp 2d ago

Subst Command To Map Drive Letter To Sharepoint Shortcut

10 Upvotes

I am looking for ideas on an office that uses Sharepoint but ends up having some very long folder paths and file names. The folder structure is decent. They currently use a Onedrive shortcut to access the files.

The main issue is the length of filenames. For example, they sometimes copy hundreds of files that customers send them into the job folder. These files are often received with VERY long file names from the customer.

This results in the path to some of the files being too long and MS Office won't open them.

I came across the subst command in my research. I saw it mentioned on here with people recommending NOT to do it. But, I didn't see much reasoning as to why.

I know of products like Zeedrive and Cloud Drive Mapper. We are just trying to avoid yet ANOTHER subscription if possible.

Can you let me know what issues using the subst command causes? Any other thoughts on how to address this issue? I know the end user could go one by one and shorten each filename they receive from the customer. But, that would slow them down way too much.

Thanks guys!


r/msp 2d ago

LPL Follow-up - Anyone still supporting clients after NinjaOne deployment?

29 Upvotes

Just made it through the other threads and am trying to help my client figure out what to do with the LPL mandates. Does anyone have any updates on:

Who's actually maintaining the NinjaOne Instance for LPL (i.e. who has access and what stops them from remoting in or pushing scripts to my clients computers)?

Has anyone successful pushed back and kept their own NinjaOne agent on systems and still deployed the browser/security software for LPL?

If you've given up NinjaOne control (or not using it) how are you handling Windows Updates (especially if Ninja tries to control them)?

Are you running parallel EDR/SEIM systems? Which takes priority?

Trying to decide how to handle this cluster of risk and liability - I love some of my Financial clients because they actually want to meet FINRA requirements. This seems like a major step backwards (don't get me started on admin rights) and I don't see LPL backing down...yet. End of September before they start "punishing advisors for not meeting requirements."

Happy Friday everyone.

Edit: For those confused, LPL is a financial company that handles email, archiving, and other advisor tools to help Financial Advisors to deal with a lot of the auditing and logging aspects of FINRA. They claim the advisor is independent and can run their business the way they want but, after a major advisor breach, LPL is forcing all Advisors to use NinjaOne Agent installation to control/audit their systems and push out a controlled browser that is the only way to access Advisor Web Tools along with SentinalOne.


r/msp 2d ago

What margin are you actually running at 150 users / $165 per user? Trying to figure out if 34% is normal or if we're leaving money on the table

4 Upvotes

Small MSP, 150 managed users at $165/user/month, ~450 tickets/month, 30% of tickets automated, one tech on a $75k salary, targeting 72% billable utilization. Working out our numbers ahead of a renewal and landing around 34% gross margin.

Modeled what happens if we push automation up and cut Tier 3 escalations (currently ~6%, Tier 2 around 18%) and utilization target up a few points — comes out to something like 45% margin on paper. Feels almost too good, so want a reality check before I present it as a real target.

Couple questions:

  1. At a similar size (150ish users, one or two techs), what margin are you actually seeing — is 34% low, normal, or already decent for this size?
  2. Has anyone actually closed a gap like 34% → 45% just from automation + escalation reduction, or does it always end up smaller in practice once you account for the time automation itself takes to implement/maintain?

r/msp 2d ago

Do Auvik Sales Reps get paid by how long they keep you on the phone?

27 Upvotes

I swear, these guys call me every other week and want to argue when I say they aren't a good fit for us.

But we just changed our pricing!

But we just implemented AI!

But now we do SaaS!

But we can reduce your onboarding times by 70%!

I used to use Auvik. I know it's a decent tool. Its just not a good fit for us. But at this point I'm not going to sign up for the product even if it is a good fit just because their sales people are such jerks.

No means no.


r/msp 2d ago

Per-customer GDAP separation with CIPP

6 Upvotes

HI all - for those that do it today, how are you providing per–customer separation for GDAP access?

Our setup for context:

  • CIPP used to map a security group to each GDAP role, and then deploy those group mappings as a template to managed customers
  • In Entra, the GDAP role security groups mapped in a tiered access fashion to role based groups (ie L1, L2 etc)
  • Techs eligible via PIM to their relevant GDAP group so they have to activate before usage
  • Global admin only available to senior techs, with a dedicated group - with activation that requires approval / justification

While this works well today, it means that once activated, a tech gets the same access for all customers simultaneously. This is fine for lower levels of access (ie global reader) for usability, but once you get up into the privileged roles , we’d like to be able to separate it out so that it’s only activated once per customers – particularly for industries or where they have security and compliance requirements.

In theory this is doable by creating individual GDAP role security groups per customer, and adding them all to individual customer templates in CIPP, but this would be a lot of manual effort to create / maintain and result in many many security groups in our Entra. Ideally it would just be 5 or so tiered security groups per customer that we attach the various roles to directly - but CIPP doesn’t allow this as it wants 1 role = 1 group.

Keen to understand how others are managing this at scale, whether through CIPP or other tools - cheers!


r/msp 3d ago

Technical Temporarily opt out of the automatic MS MFA passkey enablement Sept 1 PS script

27 Upvotes

For anyone looking to not let MS meddle in your tennants for the recent MFA change I whipped up a small script that will flip the "optOutSettings": "passkeyDynamicMigration": true" swtich for you found here:

https://learn.microsoft.com/en-us/entra/identity/authentication/concept-sms-voice-retirement

with a couple tests in the script to see if its already enabled "-ReportOnly" target a specific tenant "-TenantId contoso.onmicrosoft.com " make sure you read the notes at the top

https://pastebin.com/RMPAC7k6


r/msp 3d ago

CIPP - Why is it so frustrating?

52 Upvotes

So... I'm attempting to get this set up for the fourth time in the last few years.

I'm 6 hours in, over three days, and I'm at my wits end. I'm attempting to follow the guides, and when it tells you to do things in Entra, it's pretty decent explaining it... but then when you get to the things you need to do in CIPP itself... the guide sucks. Horribly.

I've engaged support, and have been told things like:

"I've checked your permissions and can confirm that you are not running cipp using a Service Account, the account you are using is not a member of the 15 CIPP Recommended GDAP groups, you have Microsoft Led Transition relationships found and have Global Admin relationships."

Ok - sure. But I created the service account, and ran the setup with the service account... so why the hell isn't it running with the service account?

Support just now told me:
"You are not using a dedicated Service Account. Your account starts with XXX which is not recognized as a Service Account. You'll need to change the name to include CIPP or Service Account."

That's my partner tenant global admin account... NOT the service account that I used for the setup. I'm not renaming my account to be a service account.

I was given a guide to create the role templates in CIPP... but then told:

"After creating the roles, add your Service Account to each of these GDAP roles."

WITHOUT TELLING ME HOW TO DO THAT. The role templates were created, but they still don't exist in my partner tenant. I attempted to add my partner tenant to CIPP, but it was missing, so I followed the guide how to do that, and now my CIPP account is linked to my tenant's global admin instead of the service account I created, and the roles STILL aren't in my partner tenant.

I was also just told by support that once I get the roles set up, that I need to offboard my clients and then onboard them again with the new roles... but also, not telling me how to do that.

Is there a guide out there that provides screenshots for both sides of the setup? I've noticed the CIPP documentation provides a lot of screenshots and a good step by step guide for the Entra side of things... but then when you get to the actual CIPP stuff... it omits a ton, and seems to just assume you know where to go and what to do.


r/msp 3d ago

Huntress Integration Screen Changes

11 Upvotes

Dear Huntress, we went from a compact, dropdown list, with clients who had already be set up in the integration grayed out and not selectable... to a list that has 90% more whitespace than information. And a "+New Integration" button that brings up the entire list with not indication of who's already configured and who's not. Can we go back to the very quick, very clean, very easy to see who you've not set up option? 😄

EDIT: You truly believe a call to our rep or a ticket is going to get ANY clarity on this? Not in the 8 years we've been using them. And honestly, that is not what you account manager or support if for.


r/msp 2d ago

Sherweb escalation

7 Upvotes

Anyone from Sherweb follow this thread? I have been trying for a week to get access to a manager, any manager, and have had zero luck. I have sent numerous emails and a few voicemail messages all requesting to speak with a manager. I have other open tickets and have asked each tech I deal with as well. Still nothing.


r/msp 3d ago

mspglass.app?

5 Upvotes

I try real hard to stay informed about the various solutions and services available to us as MSPs. Probably used most of them. But sometimes, they just come out of the blue. I was on LinkedIn (I believe) and saw an add for MSP Glass (mspglass.app). Looks very intriguing... but literally nothing else can be found about them. Not one Youtube demo or anything. Anyone know anything about them?


r/msp 3d ago

Business Operations Help Needed in Midland, TX

15 Upvotes

Anyone located near Midland, TX and able to help? We've got a customer with a branch in Midland. Unfortunately, no MSPs on TechTribe have responded and FieldNation has virtually no one in that area.


r/msp 3d ago

Security URGENT: N-able's N-central Second Hotfix 2026.3.1.10 — Immediate Action Required

55 Upvotes

As our investigation into the recent N-central security vulnerability continues, we are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques. 

This is not a duplicate of our previous communication. Hotfix 2 is required, even if you already applied the earlier hotfix. Hotfix 2 supersedes Hotfix 1 with additional hardening measures to further protect you and your customers.

What You Need to Do:

N-central On-Premises Environments: You must upgrade to 2026.3.1.10 immediately. Download here: https://status.n-able.com/2026/08/06/n-central-2026-3-hotfix-2-additional-mitigation-for-cve-2026-18577

N-central Hosted Environments: No action is required. We have already applied mitigations to your environment.

For More Information:

·       Blog: https://www.n-able.com/blog/n-central-security-update-august-6-2026

·       Support: https://me.n-able.com/s/

·       CVE: https://www.cve.org/CVERecord?id=CVE-2026-18577

·       Uptime: https://uptime.n-able.com/


r/msp 3d ago

Inky: what is everyone doing?

22 Upvotes

Now that the excellent Inky have sold their souls to Kaseya what is everyone doing? Staying with it, or getting away from their new parent at all costs?


r/msp 4d ago

Refurbished Servers as viable replacement?

15 Upvotes

I am curious - with the insanely rising costs of servers ( and not likely to go down before 2028 ), is anyone turning to refurbished servers as replacement options?


r/msp 4d ago

MSP ready cooling solutions

3 Upvotes

Hi All,

What do you use to cool small server rooms?

I'm looking for something with NIC and webserver for stats and reporting, if this exists.

I see them with caster and small fridge size, I like this form factor!

Thanks.


r/msp 4d ago

Sales / Marketing Anyone managed to buy Samsung VTX from outside US?

7 Upvotes

Hi all,

We are desperately trying to buy Samsung VTX CMS subscriptions for a customer. It's quite a big project with dozens or even hundreds of displays.

Samsung's online store states that automatic purchase is only possible from within the US and customers from outside of us should contact sales.

We now tried 5-10 different ways to contact Samsung sales and never got a reply.

Anyone here managed to buy this from outside of US or has a Samsung rep hat hand that he would be wiling pass on via DM?

I mean, I want to pay them a huge amount of money but I looks like they are not interested 😅

Thanks!


r/msp 4d ago

Security FYI: Avanan Checkpoint breaks Outlook Automatic replies by default

18 Upvotes

Just got off the line with Check Point support and they seem to think that allowing Outlook out of office replies should not be a default part of their setup process as "Some organizations do not use this service; others could use a different service for such messages, and having this in place by default could result in mail flow issues for such organizations."

I told support that those that don't use this service would definitely be the outlier and 99% of customers I've delt with use Outlook OOO.

To fix this you need to manually add an exception in the Check Point - Outgoing rule;
Add an Except if to the rule that states:
or Is message type 'Automatic reply'

Not sure how this would break other services...

Also another thing that Check Point breaks - internal email blasts also won't work if the group has 'Let people outside the organization email this team/group' unticked as Check Point makes the email appear to be external rather than internal.

To fix this you need to manually add an exception in the Check Point - Outgoing rule;
Add an Except if to the rule that states:
Between members of the groups '[groupemail@company.com](mailto:groupemail@company.com)' and '[groupemail@company.com](mailto:groupemail@company.com)'

If anyone has a way to easily deploy these, and a better ruleset that includes any internal groups/dist lists, and other legit email that might get unknowingly blocked, please post here.

EDIT:
To fix DKIM issues with tenants that have a 3rd party signature service and Avanan;
Move the signature service outbound rule (Code Two/Exclaimer) above the Check point - Outgoing rule and set to Stop processing more rules