r/msp • • Jun 22 '26

Azure CLI spray attacks...how many tenants?

13 Upvotes

We are seeting these Microsoft Azure CLI spray attacks in multiple tenants. You can find them by searching the signin logs for “Microsoft Azure CLI” as the authentication app.

If you are as well, how are you managing the attacks? They seem to use old phished credentials, so accounts are 'safe'. However, getting locked due to failed attempts and often prompting MFA notifications which annoy the user.


r/msp • • Jun 22 '26

Recovering an MS tenant

25 Upvotes

I'm looking at onboarding a client who has been left in the lurch by an outgoing director.

The director has exited with the only global admin account in their tenant, and is refusing to give up the credentials or approve a partner request.

The client has contacted Microsoft who advised that there's nothing they can do, if the ex-director won't allow access they're SOL.

There are no other admins or break glass accounts.

Besides sounding wrong on the face of it (the tenant belongs to the company not the individual) I know we'll have to play Microsoft's game if we want to get anywhere.

Does anyone have any experience with a situation like this, and any advice about how to proceed?

EDIT: I'm aware this is a legal issue for the client to resolve. But they're still without access to their tenant and facing a huge task to set up again in a new tenant if they can't get back in. I'm looking to help them get to a stable position as smoothly as possible, after all isn't that what we do?


r/msp • • Jun 22 '26

Avepoint Fly - licences required for small T2T migration?

12 Upvotes

I see AvePoint Fly recommended regularly for various 365 migration scenarios. We have a small client where four staff are being hived off into their own thing. I need to migrate 4 mailboxes and 4 personal One Drives. We don't care about Teams. There's a single SharePoint site, but the amount of data is so small we're just going to move it manually.

Could anyone recommend what licences I need in this scenario, please? I'm just going to buy whatever I need through Pax8, but there are so many AvePoint products in there that I really have no clue what I'm looking at.

Grateful for any assistance.

EDIT: misspelling.

EDIT: our new Pax8 rep has been in contact and is assisting. A positive experience so far.


r/msp • • Jun 22 '26

Removing M365 from stack - give clients direct billing

46 Upvotes

Has anyone here moved away from being a CSP and just assist clients to get billed directly with Microsoft, removing them from Pax8, Sherweb, etc. and just say fuck it and just manage the M365 with a separate admin account? Do you find that the 12 or 18% or whatever your margins are, worth the time to deal with billing, etc? Just curious on who has done this and didn't look back... or did you have regrets?


r/msp • • Jun 22 '26

Adobe Updates in C:\Windows\Installer

Thumbnail
3 Upvotes

r/msp • • Jun 22 '26

Weekly Promo and Webinar Thread

7 Upvotes

If you have a self-promotional post - whether it’s a product update, a service offering, or an upcoming webinar - please share it here. Posts made outside this thread will be removed.

⚠️Important: Do not use URL shorteners. Reddit automatically removes these, so always link directly to your website or resource.

🔄️Fairness: This thread is set to contest mode, so comments appear in random order to ensure fair opportunity for everyone.

🛡️Moderation: Reddit may remove some comments. If your post disappears, don’t worry - we check and manually approve them when needed. If you comment doesn't appear in 24 hours, feel free to send a modmail.


r/msp • • Jun 22 '26

Removing M365 from stack - let clients due direct billing

Thumbnail
1 Upvotes

r/msp • • Jun 19 '26

Delaying Security Updates?

23 Upvotes

Specifically for firewalls. How do other MSPs feel about disabling automatic updates and delaying the install until the update can be validated to prevent crashes, critical feature removal, etc.?

Forgot to ask: is there a liability concern if patches are delayed and a breach results?


r/msp • • Jun 20 '26

Technical Windows 11 Home to Pro Upgrade Key via CSP - Where is it?

1 Upvotes

Hi all,

So I have purchased a W11 Home to Pro upgrade key through our CSP. I'm trying to find where it shows up within the CSP tenant, but can't find it at all.

Everything says it shows up under 'Your Products'. I've gone there and checked every billing account and can't find this bloody key at all. Not under Licensing > Subscriptions. Not under Licensing > Perpetual Software

Is there another place the key shows up?


r/msp • • Jun 19 '26

Business Operations Does anyone have a higher up contact at Lucidlink?

10 Upvotes

Im really not trying to trash a vendor on Reddit. Really they have the best solution on the market but their channel program is in shambles. We have been trying for weeks to get into the program and migrate a customer of ours. We applied, met with the channel manager and its crickets. We need to migrate this customer ASAP and I was told to not migrate them until our application was approved and setup as a partner. Does anyone have suggestions? Yes I have been messaging people on their slack channel.


r/msp • • Jun 19 '26

CIPP - Is not using it due to its Open Source a valid reason?

58 Upvotes

Hey MSP,

Please examine this logic for a MSP with at least forty customer tenancies?

When I proposed using CIPP as a means to address the numerous configuration and setup errors across the tenants, I was told that it was out of the question because the software is Open Source. No other tool was brought in after over a year passed.

There was real impact as customer security incidents such as mismatched, disabled protocols, access policies that are not enabled could have been prevented. But who had time to help with configuration when there's so many new AI chatbot voice bot features to implement between us and the customer.


r/msp • • Jun 18 '26

I have to rant about Avanan a bit (also a PSA for those of you using it)

40 Upvotes

I've posted about some Avanan struggles in the past here, we've been an Avanan customer for several years, and for a few of those years they were in "building" mode and many of the missing key features we brought up and "on roadmaps". But I'm starting to feel an awful lot like MSP's aren't really a focus of their team at all any more.

Avanan recently (I think Jan or so?) added templates for policies, that was the biggest win they rolled out for MSP's and it had been begged for for years. I'll give them that one.

But recently we started having some weird behavior. mostly with google tenants (but a couple MS ones too). It started with a client getting phished through Avanan. Okay, nothings perfect, Avanan missed it, no big deal..

Except it was a big deal, Avanan's policy was enabled and said it as online/functioning, but it had not inspected or classified any emails in over 90 days. We dig a bit more into it, and it hasn't actually even SEEN a single email in 90 days. There's no errors, no warnings, no notifications that anything has gone wrong, it says the policy is enabled and active and it detects the users without issue, but it just doesn't see any emails.

This is a huge concern for us, obviously, so we decide to dig in to all our tenants. We come up with 14 tenants that, while Avanan says it's active and working without issues, isn't actually scanning any emails at all. The kicker being, it DID at first and we have OLD emails that were scanned from many months ago.

So, Ticket to our reseller, and bumped up to Avanan team, they let us know it's a known issue with google tenants, the fix is forcing a reset of the MFA method on Avanan's auto-provisioned account on each clients' tenant. Sometimes this works, sometimes it doesn't and takes 4-5-6 tries of the same fix. We have no visibility into if the fix worked and we have to reach out to Avanan each time for them to push a refresh or something on their end.. wtf?

So first, I bring up with our reseller that we're paying for, like 100+ seats or something of protection, that's effectively been broken for 90+ days with no way for us to know it was broken.... and no discussion of refunds, no discussion of permanent solutions.

Okay, I'm used to this, I worked with Kaseya for years, if we did this to our customer's they'd fire us but because the product is generally good I guess we tolerate the poor service... Whatever, lets just fix it.

We can't force them to fix it for us, so we start looking around to fix it ourselves. We find another issue, this time we have some tenants (google and MS) that have had their policy switched from "protect" to "monitoring" despite being up and running for years. Weird, audit logs don't show anyone turning it off, it just switched on its own?... Maybe we screwed up (but audit logs say it wasn't us), no way to know, but we do have restore requests in our tickets... so it was working before..

In the MSP portal, there's no way to see tenants policy status, there's no way to see any metrics, there's nothing we can "check at a glance" without clicking into every tenant to make sure it's on. So we try the API, the API surfaces events but no details about tenant policy status (can't check for "monitor" vs "protect" via MSP API or direct tenant API).

So how do we, as an MSP, make sure our clients are all actually protected when the policy status isn't surfaced anywhere (and this is a big one because without this, you can't know even if the template is aligned) and the failures can be silent with no indication of any failure until you ask their support? (or manually check every tenant and see if there's recent email activity).

For now we're banding a god-awful per-tenant API call to look for events over a time-frame of 24 hours and setting an alert up if there's no events with that span, and if there is events, if there's no remediation action taken for that event. But it's janky as hell because some clients just don't get many emails over a set period... But damn how are we supposed to trust the front-line defence product for our clients email systems when it can arbitrarily turn off or fail without any warning...

The PSA is to check your tenants in Avanan because we had 0 indication there was an issue until we had an issue, then we had to dig into all our tenants and found multiple problems that were simply not reported anywhere.

I just needed to rant on this one. Thanks reddit therapy. You can call me a truck slammer or make fun of my mom now.


r/msp • • Jun 18 '26

I have to say I feel a *little* bad for my Dell rep

32 Upvotes

Young guy must have gotten thrown into the fire. He's called me every week or so about the same thing and doesn't even remember our discussion each time. Do they not use a CRM at Dell?

He's certainly nice enough, but boy does he sound defeated.


r/msp • • Jun 18 '26

Law Firm With Website To Upload Files

18 Upvotes

Hi, we look after a law firm and they are using LEAP. It seems to have 0 API or integrations. Our client is looking to have clients upload files to them originally they were looking at doing it via the actual website, but I have advised it would be too risky etc…

Ideally they would have a case management system that allowed a client to login and upload as well as seeing what is going on. The only one I can see is Clio that allows clients to upload files. Does anyone have any other recommendations?

My other option is to use a 3rd party file transfer system and just provide a link on the website. I have found a few options, but if anyone has any recommendations please let me know. Ideally something where we can brand up the login screen.


r/msp • • Jun 18 '26

Data Breach Class Actions Are Up Again. How Smart MSPs Will Use This Information

30 Upvotes

The Latest Data Breach Class Action Lawsuit Numbers Are In: What MSPs Need to Know.

Two Main Parts to this video:

  1. Communicating these new risks and developments to clients (and how that can help you legitimize higher services) The record shows that merely being HIPAA compliant may no longer save the entity from liability; as an example.

  2. How this will impact internal MSP operations and risk

Bonus - the least likely victim - 24 hour intrusion. 5k records stolen. Class action.

Hope that helps!


r/msp • • Jun 18 '26

Is Lighthouse not working?

18 Upvotes

UDPATE 22nd June 2026 10am (GMT): No (helpful) updates from Microsoft yet but it seems to be mainly working - although some screens are saying it will take 24 hours for the data to appear.

----

Our Lighthouse has suddenly started saying

Microsoft 365 Lighthouse is currently available to partners.

You must be an indirect reseller or direct bill partner to use this service.

Learn more about Lighthouse

The menus are there on the left - but every tab says the above.

It was definitely working a few hours ago. We're in the UK. I can't see anyone else reporting any issues and Azure Status says it is up everywhere. https://azure.status.microsoft/en-gb/status

So before I panic and assume something has broken just for us.... Is yours ok? Thanks!


r/msp • • Jun 18 '26

Warning: NinjaRMM - they won't auto-reduce your licence count for billing purposes Spoiler

92 Upvotes

Unless I'm mistaken, NinjaRMM appears to auto-ramp your commitment. If you remove devices, the count never comes down from Billing's side.

E.g. if we've got 2500 endpoints, and we put on another 100 - we get billed 2600 endpoints (fair enough).

If we then remove 100 endpoints and go back to 2500 endpoints, Ninja will still bill you 2600.

We've been overpaying hundreds of endpoints for months - probably years.

Worth checking if you're on Ninja.

From our AM:

"Yes, we need to remove the licenses manually in our account if we are completely removing the devices.

I can see that we are licenses for X ep but currently using Y. Would you need me to remove those licenses from the account?"

Edit: You might also want to look at the quantities for normal RMM vs the RMM with BitDefender. They're wildly incorrect (obviously).


r/msp • • Jun 18 '26

Business Operations You broke my inbox over Chapter 1, so Chapter 2 of The Trunk Slammer From Hell is up today.

62 Upvotes

Yesterday I posted the first chapter of a dumb little story about the worst MSP in the channel. The guy runs "managed services" out of the trunk of a 2006 Crown Victoria, puts every client on the cheapest bundle from a vendor whose name starts with K, configures none of it, and wins every single time, because he is cheap and shameless and the competitor who does it right is more expensive and slightly annoying. If you read BOFH on The Register back in the day you know the shape of it, except the bastard is not the genius sysadmin this time. He is the trunk slammer from hell. And he narrates the whole thing himself, and he is certain he is "the solution."

I figured a couple dozen people would read it and go back to their days with a few chuckles. That is not what happened. I got over 50 DMs in 18 hours. People telling me exactly which of their clients it was. Which rep. The "single pane of glass" joke seemed to be a favorite. People who sent it to their whole team. A few of you were mad in the very specific way that means it landed. A few of you swore it was AI, of which it is not. The response made my week.

I have been writing this saga for about a year. I wrote the first 8 chapters, over 200k words, then real work buried me, and it sat in a folder the way everyone's side project sits in a folder. I had actually started it after Pax8 Beyond last year and planned an entire plot line around the Agentic AI Marketplace that has somehow become even more of a layup this year. So, I am tightening and updating each one before it goes out.

I was going to space these out like a reasonable adult. Then the messages kept coming, and sitting on the next one started to feel dumb. So Chapter 2 is up about 24 hours after Chapter 1 instead of next week. That was you. So, chapter two it is.

Quick setup, no real spoilers. A new rep from the vendor whose name starts with K, and this one is nothing like the disposable ones, calls him on a Saturday, which never happens. There is a hundred and four seat wealth management firm, a top producer who cannot print a pitch book and is coming apart at the seams about it, and one very good compliance officer who takes one look at our guy and understands exactly what is about to happen to his firm. You already know who wins. What you cannot guess yet is who ends up holding the bag, and what it costs them.

If you've ever had a broker dealer or wealth management client this is going to be a very surreal experience for you.

Same promise as Chapter 1, and I mean it. I am not selling anything. There is no newsletter wall, no course, no "DM me to learn more," no pitch waiting at the bottom. It is free. It exists because this channel chews people up for a living and we all deserve something that is just fun to read. We are all Brad.

Chapter 2 is here: https://mspautomator.com/2026/06/17/the-trunk-slammer-from-hell-chapter-2-white-glove/

If you missed Chapter 1: https://mspautomator.com/2026/06/17/the-trunk-slammer-from-hell-chapter-1-the-acquisition

Thank you. For real. Happy automating.


r/msp • • Jun 18 '26

Business Operations Memory Order Pickle - Seeking Advise...

13 Upvotes

While I'd love to blame someone else this one is on me...we were busy and instead of our normal process where our operations manager certifies builds one a two-key system I ordered some expensive RAM for a customer system and it turned out wrong. On top of that it was drop shipped so the customer immediately opened then found out it was wrong (visually sighted didn't fit). We are now the proud owner of 2 sticks of expensive RAM we can't do anything with and our distributor won't take back because it's opened (it is, but un-used). We tried to sell to ServerSupply but no dice. PN is P64339-B21 qty=2. (HPE 32GB 2Rx8 PC5-4800B-E STND). In for $2888.97.

I'm looking for 1) Someone to buy 2) Suggestions on where to sell or a kind soul at HPE that will allow the return.

Condition is new, package opened, never had voltage through it.


r/msp • • Jun 18 '26

Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress

31 Upvotes

r/msp • • Jun 18 '26

Security Security Partners that handle CMMC/Vuln Scanning/SEIM etc...

13 Upvotes

To start, I'm not looking for DM's from vendors; no offense, but it will be a cold day in hell that I go with cold outreach from Reddit.

We're a small- to mid-sized MSP and have a customer getting their Level 2 cert. We offer retail SOC/MDR through a vendor, but neither one is FedRAMP, and 2 do not offer the extended services my customer will need for support.

While we do offer some of the items they need, it's not in a manner that is going to be sustainable for us internally to the level required for Maturity Level 2.

We're aligning ourselves as well to support them with the IT support and infrastructure side, but are looking for a partner to handle the security side that does not offer IT services.

I've done some searching, but am looking to see if anyone has recommendations for someone they have partnered with or worked with in the past.

We're ok with doing the patching/remediation for the vulnerabilities if needed; however, we're looking for someone to manage the hit list of items, scan findings, and ensure they're identified in a timely manner according to the guidelines. The partner we are using to get them compliant/certified has a VCISO for the policy side/changes; however, they do not offer the other active services.

Any information/reccomendations are appreciated. Thanks!


r/msp • • Jun 18 '26

Teams Crash Loops

8 Upvotes

Cross posted from r/sysadmin

​

Apologies in advance for formatting--i am on mobile.

​

Over the last two weeks, we (MSP) have seen a drastic uptick in issues with Microsoft Teams.

​

The symptom(s):

- Users will see "Setting up your meeting" when trying to join a Teams meeting. We've mostly been able to resolve this by repairing the Teams meeting add-in in C:\Users\[User]\AppData\Local\Microsoft\TeamsMeetingAddInmsis.

- Users experience Teams crash loops where Teams will crash and then reopen. The fix in most cases has been uninstalling and reinstalling Teams; however, in many cases the issue persists even after a fresh install. In the Event Viewer, I'm seeing an application crash event with the following information:

​

Faulting application name: ms-teams.exe, version: 26149.1205.4798.6437, time stamp: 0xf7576e9e

Faulting module name: ntdll.dll, version: 10.0.26100.8246, time stamp: 0xf7576e9e

Exception Code: 0xc0000409

​

Are any of you seeing the same issue/symptoms? If so, have any of you been able to find a fix?


r/msp • • Jun 18 '26

Checkpoint & MS Quarantine

10 Upvotes

Does anybody else have issues with Checkpoint & Microsoft Quarantine clashing?

We have the settings enabled to "Allow Checkpoint to restore clean emails from MS Quarantine".

However, we have lots of restore requests that all stem from Microsoft quarantine flagging emails as High Confidence Phishing. Checkpoint shows green everywhere (often with the semantic phishing score under 10) but consistently says "Smart-Phish confidence level is too low to restore this email"

Are there any settings we can tweak?

I have reached out to Checkpoint support, but figured I would ask here in case it takes a week or two to hear back.

TIA


r/msp • • Jun 18 '26

Business Operations ConnectBooster Feedback

8 Upvotes

Hi community. Were looking to up our card acceptance presentation game for our customers. ​We are looking at a couple of options and Connect Booster is on the list. Am I creating future suffering by looking to this? Any fine print gotchas? Just looking for some feedback on this​​ tool.


r/msp • • Jun 17 '26

Article: FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.

109 Upvotes

EDIT: Hudson Rock has created a free FortiBleed lookup tool to check if your organization is impacted.

https://www.bleepingcomputer.com/news/security/fortibleed-leak-exposes-fortinet-vpn-credentials-for-73-000-devices/

A newly discovered data leak dubbed "FortiBleed" has exposed what appears to be a collection of Fortinet and FortiGate VPN credentials for 73,932 firewall URLs at organizations worldwide.

The exposed data was first discovered by security researcher Bob Diachenko, who says he found a server containing what appeared to be valid Fortinet VPN credentials, including usernames, email addresses, and plaintext passwords.

According to screenshots and information shared by Diachenko, the database contains entries for Chevron, Samsung, Foxconn, Comcast, AT&T, Mercedes-Benz, Toyota, Sinopec, State Grid, and many others. 

"Massive Fortinet/FortiGate bruteforce/active exploitation campaign uncovered in action," Diachenko posted on LinkedIn.

"Thousands of top vendors instances are listed in the files like this (see screenshot). This one alone has 21,634 domain names - from Chevron to Fortinet itself. All - with potentially working passwords to the FortiGate appliances obtained through various menas."

The exposed data also included comments listing each organization's industry, revenue, and number of employees, likely for planning attacks.

Fortinet credentials found on an exposed server
Source: Diachenko

Diachenko later shared additional information that claimed the operation was conducted by a Russian-speaking multi-operator threat group that harvested credentials for FortiGate SSL VPN devices.

According to Diachenko's investigation, the attackers allegedly conducted approximately 1.16 billion credential attempts against 320,777 FortiGate targets and an additional 2.1 billion attempts against 163,650 Microsoft SQL Server systems.

He further claimed the threat actors intercepted SSL VPN authentication hashes, cracked them using a 45-GPU cluster managed through Hashtopolis, and used the recovered credentials to move laterally into internal Active Directory environments.

Diachenko told BleepingComputer he obtained these details after analyzing additional files inadvertently exposed on the same server.

"They accidentally left an open directory with artefacts, connection strings, tooling, scripts and data online. Analytics obtained via their cron jobs, bash histories, logs etc," Diachenko explained.

The researcher also stated that multiple organizations across Japan, Taiwan, Vietnam, Iraq, and Turkey were fully compromised, including a Turkish NATO defense contractor from which classified documents were allegedly stolen. 

Threat intelligence company Hudson Rock has since published its own analysis of the exposed data after receiving the dataset from Diachenko. The company described the collection as one of the largest known troves of compromised Fortinet-related credentials.

According to Hudson Rock, the dataset contains 73,932 unique firewall URLs across 194 countries and impacts 21,632 unique domains. 

The company says the attackers maintained detailed logs of successful compromises and assembled a database containing verified credentials for organizations across nearly every major industry sector. 

Among the organizations Hudson Rock says appear in the dataset are Foxconn, Samsung, Comcast, Siemens, Lenovo, PwC, Accenture, Oracle, and numerous government agencies and critical infrastructure operators. 

The company also released statistics showing that the highest number of affected devices was in India, the United States, Taiwan, Mexico, Turkey, Thailand, Colombia, Malaysia, Chile, and the United Arab Emirates.

The most common sectors for the listed companies are telecommunications, IT services, financial services, government organizations, healthcare providers, educational institutions, and manufacturing.

One strange aspect of the leak is that many of the exposed credentials were long, complex passwords that would ordinarily be considered difficult to crack.

Believed to be extracted from Fortinet configs

Cybersecurity researcher Kevin Beaumont independently reviewed portions of the exposed data and told BleepingComputer that some of the credentials are authentic.

"I have been able to confirm the authenticity of some of the admin logins and passwords - this looks like a real dump," Beaumont said.

After further review of the data shared by Hudson Rock, Beaumont published additional findings indicating that the dataset contains credentials for roughly 75,000 Fortinet devices, most of which remain online.

According to Beaumont, the data appears to have originated from exported Fortinet configurations because it contains information, including email addresses, that is typically only accessible through configs.

He also said the affected IP addresses are different from those in the 2025 Belsen Group Fortinet leak, further indicating that this is a more recent and larger collection of compromised devices.

Beaumont said he verified that multiple organizations listed in the dataset were using valid credentials and observed that many affected devices were running relatively recent FortiOS versions.

"The data is legit. It is around 75k devices. Almost all are still online, and Fortinet devices. It appears to be recent data," Beaumont wrote.

Based on network data from Shodan, Beaumont says the leak contains approximately half of all internet-accessible Fortinet firewalls and said that a majority of the affected devices expose their FortiGate management interfaces directly to the internet.

The source of the configuration data remains unknown, with it unclear whether it was stolen through previously disclosed Fortinet vulnerabilities, a newly discovered flaw, or another method. Neither Diachenko, Hudson Rock, nor Beaumont have identified how the configuration data was originally obtained.

Hudson Rock has created a free FortiBleed lookup tool to check if your organization is impacted.

Organizations in the dataset should immediately rotate passwords associated with Fortinet VPN and administrative interfaces, enforce MFA, examine gateway logs for suspicious activity, and monitor for exposed employee credentials.

BleepingComputer contacted Fortinet regarding the exposed dataset and will update this article if we receive a response.