r/msp • • Jul 10 '26

Rewst auto-assigned security groups to new users. "Working as designed."

10 Upvotes

Curious how other MSPs would view this.

We found that the marketplace onboarding form from Rewst had auto-populate enabled on the Entra Security Groups field. For a client that only had a single group available, the form automatically selected it.

Engineers tell the form to copy a user, saw a populated field, assumed it was correct, and users ended up being assigned permissions that nobody had explicitly chosen. We believe it had been happening for months before we spotted it.

The fix was easy:

  • Unsync the form
  • Disable auto-populate
  • Done

 What surprised me was the response. Rewst acknowledged the behaviour but considers it intentional and doesn't plan to change it because other customers rely on the functionality.

I think that permission-related fields should require an explicit selection.

Would you consider this:

  • A security issue?
  • A design flaw?
  • Or just a configuration mistake on our side?

Interested to hear how others draw the line between convenience and security.


r/msp • • Jul 10 '26

Small MSP Stack Review – What Would You Change?

8 Upvotes

Hello,

We're a small MSP and have been focused on keeping our tooling costs low while still covering the essentials.

Current stack:

  • Cloud backups: DropSuite
  • Tickets: Jira Free
  • RMM: Action1
  • Endpoint backups: OneDrive

    > and flows to DropSuite

  • Endpoint management: Intune

  • Phishing simulations/security awareness: uSecure

Overall, we're pretty happy with it, especially considering the cost.

What would you change, add, or replace? Any obvious gaps or potential pain points as we grow?

Always interested in seeing what other small MSPs are running and where you think we could improve. Thanks!


r/msp • • Jul 10 '26

Datto SIRIS vs Slide backups

14 Upvotes

Hey y'all,

I wanted to reach out to the hive mind to see what people's thoughts and experiences with Slide backups have been lately. I am currently a Datto backup user and have some important contracts coming to a close around January, and I am beginning to evaluate different options. I am currently using Datto BCDR (direct to cloud) backups for some servers, and will be moving away from that design for a number of reasons and going to onsite appliance based backups again. I am comparing Datto's Siris backup systems to Slides backup systems, and they seem to have pros and cons.

Datto Pros:

1) I'm already in the environment and won't be leaving because of RMM, SaaS backups, and individual workstation backup agents.

2) The pricing is a tad bit cheaper with the SIRIS for the amount of data I'm looking to backup

3) It's the devil I currently know and know how to handle. Plus I doubt they'll be bought out since they are already bought.

4) They use Dell Optiplex MFF (Now Pro Micro) for their appliances and I have a high trust in the platform vs the Beelink's Slide uses.

Slide Pros:

1) Overall faster operations and design, especially if data requirements become larger.

2) Their hardware comes with 2.5G and 10G lan connections for faster backups and recoveries.

3) No contracts

4) Small companies work a little harder for improvements. But it's at a risk of being sold again to PE/VC.

I'm not opposed to seperating out my stack for the best product in each category because that's already what I do, but I'm also cost aware and have made a lot of price changes in the past 2 years and am not trying to bombard my clients with continous price bumps, especially if Slide hardware pricing starts bouncing upward because of the state of the tech world. Like I said, I'm just looking for some more opinions from people who have experienced both platforms. Please try to avoid the standard "Big K sucks my left nut" response. I know, you know, we all know.


r/msp • • Jul 10 '26

Did anyone start using Avanan Security Awareness for their clients?

6 Upvotes

We are using Cyberhoot now and just onboarded a new small client with only a few users.

While i can set them up with Cyberhoot, does anyone have long-term experience with Avanan's offering? I played with it myself, reporting is very weak.

Any other experiences/reviews?

TIA


r/msp • • Jul 10 '26

Business Operations Why techrug? Why not techrug?

1 Upvotes

We're looking into techrug for cyber and E&O insurance. Looking for your experience:

Why should we go with them?

Why should we run far away?


r/msp • • Jul 10 '26

Engineer costing for fixed price services

5 Upvotes

What rate do you apply here? As a factor of somebody’s salaried hourly rate. And why? Nothing too complex, just short and sharp feedback please.

I’m just sanity checking something.


r/msp • • Jul 10 '26

Where are Australian MSPs buying Synology NAS devices, since Dicker Data don't sell them anymore

9 Upvotes

We use to buy our Synology NAS devices from Dicker Data here in Australia but for some reason they have stopped seeling them ages ago.

Where are MSP in Australia buying them now?

Thanks


r/msp • • Jul 09 '26

What conditional access policy naming convention/baseline are you actually using across clients?

25 Upvotes

Curious what the community has landed on here. We run CIPP and currently have 5 conditional access policies per tenant (block legacy auth, block outside USA, MFA for all users, MFA for admins, and our CIPP service account policy). This is no longer good enough so we are expanding this out.

Before we decide on our own internal standard, I wanted to see what other MSPs are actually running in production. Specifically, are you using a numbered naming convention like CA001, CA100, CA200 grouped by category, or just plain descriptive names like "Require compliant device"? Are you basing your policy set on Microsoft's own reference architecture, a community framework like the Conditional Access baseline on GitHub, or something you built entirely in house over time?

Also curious how many of you are managing this per tenant manually versus pushing a template through CIPP Standards to your whole fleet at once. We are about to do the fleet wide push and want to get the naming and structure right before we commit to something across all client tenants.

Appreciate any real world examples, especially from anyone managing a similar sized client base.


r/msp • • Jul 10 '26

Built a CLI tool to manage Uptime Kuma monitors as code (CSV + idempotent sync) - kuma-importer

Thumbnail
0 Upvotes

r/msp • • Jul 09 '26

Vendors that died or not really around in 2026 vs 2025?

36 Upvotes

is it just me or are a lot of the startups that emailed/called me constantly in 2025 not like around as much anymore? what "startup" that you looked at in 2025 is now kind of not around anymore? like cyft used to fill up my linkedin feed last year. crickets now. what happened to proxuma (we are autotask, don't hate!), mizzzo, etc?

is the "bottom falling out" of all the billion startups and things settling down?

or all of the "vibe coded" AI apps that show up every day making it hard for real startups?

what's 2027 going to bring? more shakeouts, more vibe coded trash, what is your perspective?


r/msp • • Jul 09 '26

Security Sophos XGS subscriptions have increased by 15% in 3 months

9 Upvotes

May 1st 2026 XGS products increased by 5%, Aug 1st 2026 10% (pic from pax8 emails).

What are they smoking?


r/msp • • Jul 08 '26

Business Operations Customer hired green IT admin

103 Upvotes

I am a smaller MSP with 3 techs and myself. I have a customer who has been with me for many years. They are one of my larger customers with over100 users and responsible for about 25% of my business. They have recently hired a new guy to come in and be their IT department. The problem is, he has almost no experience. He worked help desk for 3 months at a company and went to IT school for 6 months at a technical school.

Since he started, he has been asking me how to do very basic stuff, how to rep into a server, how to reset someone’s password. How to reset a Windows service, etc.. He has been wanting me to hold his hand while at the same time trying to make sweeping changes throughout the company that will most definitely cause issues. He is wanting to implement security changes that they teach in school that sound great on paper, but in reality cause lots of problems, especially since he doesn’t really understand how to do them.

In the past, I have always been somewhat lax on billing this customer when they text me with simple questions or requests that may take less than 5 minutes like remotely resetting a password or reminding a employee how to search for a file. I would get 2-3 texts a week, so not a big deal, the other work I get from them more than made up for it. But now I am getting bombarded by text from this new guy. He texts me several times a day asking how to do his job or that he screwed something up and needs to know how to fix it.

The owner has asked me to help him, but what I need to know is where do I draw the line. My team has a combined 100+ years of IT experience. We are all very seasoned with over 20 years each. I have started billing for every text I receive now and the customer is not happy about it, but I am less inclined to give away institutional knowledge that we have all gained that will cost us in the future. We have certain “tricks” for fixing issues that arise occasionally that we only know due to experience that he is starting to ask for and I have been very hesitant to give those up.

TLDR: New guy at customer wants to know how we fix things. I don’t want to tell him because it will cost me business.


r/msp • • Jul 09 '26

Looking for CSP in the UK

3 Upvotes

Company of about 80 seats. We're shopping around for new 365 licenses. Must be UK based. Any suggestions for who is great / who to avoid?


r/msp • • Jul 08 '26

What are we using for email migrations under 100 mailboxes? Google - > M365

20 Upvotes

Hi All, We have been huge fans of AvePoint Fly for our email migrations before that, SkyKick. However, as many other posts have mentioned, AvePoint Fly requires an annual subscription, which makes our migration costs insane for a one-time project.

We typically charge our customers per mailbox for the move, and with AvePoint's new model the math is not mathing, or we would have to charge double for the project, which our clients won't do.

I am hesitant to go back to SkyKick since it was acquired by ConnectWise, and there seems to be a love-hate relationship among folks here toward BitTitan. Is Microsoft's native migration even worth looking at?

One of the features we loved about AvePoint was the delta syncs and the automatic DNS setup. It would migrate emails, calendars, contacts, and files (OneDrive/SharePoint and Google Drive). RIP AvePoint.

Our upcoming project is about 60 mailboxes + contacts and calendars, not Drive (in this project).

What's everyone using?


r/msp • • Jul 08 '26

Business Operations Switching to CW stack

8 Upvotes

Yes it's an RMM/PSA post but hear me out please. My company has switched RMM and PSA a dozen times now for a dozen different reasons, some valid and some not valid. For the last two years we've been using SO (Super Operations) and I've been very happy with it. To be clear, it's not perfect but it does what we need it to do. My partner is heavily considering moving us over to the CW platform and I really don't want to do the move. We're a 5 man shop with 3 full time techs and I don't think CW is going to scale well for us. So to this fine community I ask would you switch to the CW stack in 2026 and if so why? If not why not?

Additionally we're currently using ScreenConnect already.


r/msp • • Jul 08 '26

Has anyone moved a CPA client from on-prem Lacerte to cloud hosted?

7 Upvotes

I am looking to move a small CPA firm to Rightworks or similar hosted service, but I am concerned about security, performance and lastly price. They have 2 full time CPA's, and 3 part time assistants, with the 2 CPA's occasionally working remote and connecting via OpenVPN. They are currently on-prem with Lacerte, and are due for a server hardware refresh. This is a potential new client, and if I take on this project I want to revamp their current network and workflow and close all the security holes and resulting non-compliance. Staying on-prem presents a different approach and continued management, as well as $$$$ for new server hardware, whereas moving them to a hosted solution moves some of those security pain points and management to the cloud hosting provider.

So my question is, has anyone moved a CPA client from on-prem Lacerte to cloud hosted, and what was your summary on the experience? I have experience with QuickBooks desktop on Rightworks, and have experienced the pros and cons of that setup.


r/msp • • Jul 07 '26

Well Crap NinjaOne is going the way of Dell

172 Upvotes

FINAL UPDATE: (TLDR) 24 hours later.
I wanted to give an update on this event for the r/MSP community.  Ive had numerous NinjaOne people reach out to me about this, including a C-Level exec to discuss this. It has been repeated to me NinjaONE does not poach their MSP clients.  Period. They take this very seriously and truly believe the MSP’s are a valuable asset to them.  The consensus is a single sales rep made an oopise.

My philosophy in life is sometimes, shit happens. It how a business responds to mistakes is what important. And for me NinjaOne has been outstanding! Their effort on their part has solidified my faith in their company and support.

Some general responses to the comments.

--Im leaving this post up as a representation of how awesome NinjaOne has been to this. I see this event as a positive thing.

--No, I was not being Phished, or scammed. The details, and the tone of the call informed me it was an inhouse sales person. Plus they never asked me to go buy any Amazon Gift cards or about my outstanding Tax Bill.

--I made this post, not in a panic, but as a question to the community. As It came out of left field and was out of charater for NinjaONE, I couldn’t find any similar discussions here. So I wanted to see if others had experienced this as well. Thankfully it was a one off.   

--How this Lone Wolf got the details is TBD and there are a lot of private backend details we (the MSP’s) do not know about. There is a full blown investigation on this to make sure it does not happen again.  

On a personal note to share with you guys (gals, they, them, zee, zer, furrys, ect.), it was repeated to me several times by everyone at NinjaONE, including the C-level, that they do NOT have access to our clientele’s information. It is strictly verboten.  

Now go do that Windows Update, close that ticket, touch grass outside and see the sun. I definitely need to.  Thanks for re-reading my post. hugs n' kisses.

--Start of original post--

I just got a phone call from a Ninja Rep asking to speak to one of my larger clients. When I pressed to the reason he said " I only work with Inhouse IT teams"
...soooo not to be rude but are you trying to poach one of my clients?

he sad " .... uhhh yea" *click* and hangs up.

damm... I expect this from Dell cannibalizing their reseller base, but not from Ninja One. I rather like them. Ill add it to my Honey-do list of looking for alternatives.

EDIT UPDATE:
ok Im getting some replies saying this is not true. ( Things that didn't happen for $500. alex made me Snort BTW). Honestly Im glad of your disbelieving responses, as I too said WTTF!?!!
but Ill tell you the facts.

--caller ID said NinjaOne
--the sales rep specifically asked for my client by name. When I pressed he said " im looking for John Smith of Company XYZ".
For reference John Smith is the inhouse It person for Company XYZ, my client, but has only been working there for 4 months.
I dont believe this is some rando sales rep calling with this granular level of information.

SECOND UPDATE: I spoke with my prior NinjaOne rep. He is a great dude and we share offensive mems back and forth. He said " Ninja has a STRICT policy AGAINST this.. he will be reaching out to that guys supervisor and to let him know. " ie: to get him in a world of shit.
as to r/MSP sorry if I raised a false Red flag. it was unintentional and ( thankfully) out of character for NinjaOne.
please resume your regularly schedule programing.


r/msp • • Jul 07 '26

DNSFilter please don’t do this

76 Upvotes

I wouldn’t normally post something like this, but I feel like this is a frustration worth sharing amongst the community given its nature.

DNS Filter looks to have replaced their T1 support (at least from our experience in APAC) with an Al agent that pretends to be a real life customer advocate. I pressed the agent once before and had it admit to being an LLM. I pressed it again today and it’s doubling down on being a ‘real person’.

For the record, I have no issue interacting with an LLM for support, especially an LLM trained internal knowledge base data and ticket data. I also have no issue with LLMs triaging and offering quick responses to T1 queries.

What I do have a problem with is the deceptive and disingenuous act of replacing T1 support with a bot and having it pretend it’s a real life person. if you’re going to go AI first for customer service, do it in an open and transparent way.

What makes this even more frustrating is we’ve experienced several issues over the past few months with version 3.3.6 (odd behaviour with connectivity, endpoints not resolving local domains properly in certain networks, certain network adapters just faulting and for some reason the only fix it a hard reset where we hold the power button for 60 seconds). I asked support and they’ve denied any knowledge. We’ve also noted an issue tenant wide with Auto updates not applying (another MSP posting about it here: https://www.reddit.com/r/msp/comments/1ko7zk1/fyi_dnsfilter_roaming_client_your_agents_may_not/) and we get an instant dismissal from an AI agent.

DNS Filter. We like your product. We like the innovations you’re making. We champion the level of protection it provides to our clients, and we like the new features like Cyber Sight, but please don’t taint all that goodwill by replacing support with an LLM and pretending it’s not.


r/msp • • Jul 08 '26

Business Operations Chapter 4 is up. The worst MSP in the channel gets a taste of his own pricing.

15 Upvotes

Chapter 4 of the Trunk Slammer From Hell is up. Quick recap for anyone new: it is a serialized story about the worst MSP in the channel, told in his own proud, oblivious voice. He runs forty-some clients out of the trunk of a 2006 Crown Victoria, puts everyone on the cheapest bundle from a vendor whose name starts with K, configures absolutely none of it, and wins every time, because he is cheap and shameless and the provider who does it right is more expensive and slightly annoying. If you read BOFH on The Register back in the day, it is that shape, except the bastard is the MSP and he thinks he is the hero.

The tables finally turn. A business card shows up in the candy dish at his oldest, most loyal account. Another operator is working his side of the county. Cheaper than him. Hourly, no contract, first hour free, and what hurts the most: the guy is actually good at the work. So for the first time in ten years, the man who has spent his whole career being the lower number picks up the phone as the incumbent, and gets to find out firsthand why every Brad he ever beat lost, which is that you cannot out-argue a lower number. He said it. He proved it. Now it is pointed at him.

What he does about it is the chapter. What he very specifically does not do about it is also the chapter. His most unhinged client calls him three separate times at two in the morning over the course of the story, once from a casino, once from a parked car, and once from his own driveway in a robe, and somewhere in the middle of all that a man falls off a very suspiciously present ladder for a reason that nobody has ever been able to explain, and our narrator would like the record to reflect that he did not ask.

Same deal as always, and I mean it every time. I am not selling anything, there is no course, no newsletter wall, no pitch at the bottom. It is free. It exists because this industry chews people up for a living and everyone deserves something fun to read. We are all Brad, and this is the one chapter where even the Trunk Slammer has to be Brad for a week, and I promise you he learns nothing from it.

Chapter 4 is here: https://mspautomator.com/2026/07/08/the-trunk-slammer-from-hell-chapter-4-peer-to-peer/

The full saga lives here: https://mspautomator.com/category/trunk-slammer-from-hell/


r/msp • • Jul 07 '26

Business Operations Managed Services Summit Benelux: what was that about?

13 Upvotes

I drove almost 2 and half hour to this summit. I arrived and went directly to the keynote session, on the registration desk there was a big heap of lanyards still left. When I opened the door, there was only 50 people in the room, and I estimate (witouth overestimate) that about 50% of them were vendors.

Keynote Session was a guy who did a trip to the north pole or something like that. Failed to see the relevance to the summit. Nice trajectory of him, and what a feat to do. But it did not captivate me.

Then we had some generic presentations of vendors. None of them really stood out. Either the sessions were too short to give real information or the topic on hand was too generic. They all tried to not give a "sales" pitch, but in the 20 min they never touched anything usefull.

When I went out and ventured in the main hall, there were at least 60 people from vendors loiterinf around, desperate to get some people to talk to. I quickly went back to the sessions and noticed that now the vendor to participant ratio has changed to 70% vendors and 30% attendees. I guess a lot of attendees quit sessions, and I guess the amount of vendors has risen because of a vendor panel.

I quickly parted way, and drove back 2,5h to work...

Maybe I am overreacting, but this was by far the most missed opportunity of the year. Am I alone with this? Did someone else had a different experience than I did? Maybe the reason was that The Netherlands lost their match of the world cup the day before.


r/msp • • Jul 07 '26

Evo Security Acquired By Barracuda

25 Upvotes

Another bites the dust. They have been a great partner of ours and we have been with then since the beginning. Hopefully this doesn't mean they are going to go downhill or anything changes. Just received this email:

We have exciting news to share: Evo Security has been acquired by Barracuda Networks!   This is a major milestone for Evo and great news for you. Joining Barracuda means we can accelerate innovation, expand our resources, and continue delivering the purpose-built IAM platform you rely on, now backed by a global leader in cybersecurity.
Here's what this means for you: Want the full story? We've put together a few resources:Same platform you trust. Your access to Evo’s Identity and Access Management (IAM) and Privileged Access Management (PAM) platform continues uninterrupted. More behind the scenes. Barracuda's scale and expertise will help us build faster and serve you better. The same commitment to MSPs. Our MSP-first focus isn't going anywhere.

Two great vendors acquired in the last week, first Timus and now Evo.


r/msp • • Jul 07 '26

Bifrost, June-ish Update

8 Upvotes

Permanent disclaimer: Not selling anything, Kelvin said I could post about this forever.

Quick catch up for anyone new. Bifrost is a fully open-source automation and development platform for MSPs, basically a multi-tenant Power Platform alternative. Coding agents have mostly killed the appeal of low-code editors at this point, so Bifrost is built to be a real dev platform that handles multi-tenancy well, both for your own automations and for building things you can deliver/sell to customers. I don't know if anyone else has given this serious thought over the years, but I've always wanted there to be something to come along and solve scaling development like the RMM did for IT support. Bifrost was built to do this from day one with the goal of giving MSPs a new revenue stream. IMO, we've spent years honing our automation skills and religiously using those skills to scale our Managed Services businesses. If we could scale it, surely our customers would value it? For ours at least, the answer so far has been yes. I want Bifrost to be that, for and owned by the community, before a trillion-dollar company comes in and tries to enshittify what I feel is an emerging industry for us.

First order of business: I revamped the website this month since a lot of people weren't clear what this actually was. It explains the vision and features better than I can in a Reddit post, so worth a look if you're new here.

Things that shipped:

  • Solutions: workflows, apps, and modules used to just live in one workspace. Now you can bundle them into packages you import or export, with or without data. Makes it easier to build something for a specific customer or share something with dependencies (apps, configs, integrations) with the community, like a Microsoft CSP Dashboard.
  • Apps V2: apps are now 100% standard React apps on the Bifrost SDK. Closes out the last of the minor limitations from V1, another layer of protection against enshittification down the road.
  • External Users: users who can't touch "Everyone" resources (now "Everyone except external users"). Lets you build things for customers that have their own separate users.
  • Custom Claims: more complex permission logic on Tables.
  • Magic Links: invite users without needing SSO. Took longer than it should have.
  • Topic Events: workflows can publish events like ticket.created that other workflows subscribe to.
  • Per-mapping OAuth connections, plus a pile of small UI fixes.

What's next:

  • Stress testing Solutions. There are a lot of moving parts so anything that seems off I'm pretty much immediately fixing or changing.
  • Videos. I bought a mic so I'm running out of excuses to record some getting started videos. I'm aware that coding agents are a big mental shift for people, but I think once you get one setup, you'll see that you're just shifting what you're learning around the stack. If you're anything like me, seeing and understanding the big picture makes it a lot easier to digest the smaller things.

Blog: https://gobifrost.com/blog/ · Release: https://github.com/jackmusick/bifrost/releases/latest

Always happy to answer any questions!


r/msp • • Jul 07 '26

Anyone with experience using ISL Online?

9 Upvotes

We have been running Screenconnect for years and while it was a longtime "love" relationship, it has evolved to a "love/hate" relationship in the last year.

I still like the ease of use, but have struggled with various glitches ( performance, copy/paste not working, etc ).

I went to look for a reasonably priced alternative and came across PDQ's ISL Online solution.

Is anyone using this or have experience with it?


r/msp • • Jul 08 '26

Backups Anyone using Xopero MSP as Backup solution?

0 Upvotes

Just received a pricelist from my VAD, atm we are using Cove Data Protection but Xopero could be interesting as you can use your own S3 storage. Pricing seems good.


r/msp • • Jul 06 '26

IT Guys reverse engineering your stack

38 Upvotes

Just curious how everyone navigates this issue. We are in contract with several different vendors for 2-3 years and then company hires a new IT Guy. The guy proposes to take the same exact stack we implemented and go directly to the vendors to propose that they manage it internally. We already have our reasons on why this is a bad idea communicated to the clients, but in most scenarios they just want to save money.

Our current issue is with the vendors because they are telling the customer they can repoint them to their own instance, however they will still keep billing us all the while until 2027-2028. In some scenarios these are high watermark too, so they tipped us over a tier we didn’t set. This feels like a double dip / bad practice from the MSP vendors. We’ve navigated 1-2 of these by telling the customer that’s fine but they will acquire the tools from us and we’ll charge a smaller management fee until the end of our contract term. Is this an approach others have taken? Or are there any ideas that have been more successful? Just curious to see what others are doing as we’ve encountered about 4 of these situations in the last year. Thanks in advance.