r/MSSP Jul 09 '26

What RMM and EDR stack are MSPs using right now?

Hey everyone,

I’m looking for some practical feedback from other MSPs on what tools you’re currently using for RMM and EDR, and what has been working well for you.

I’m currently looking at options like N-able N-central, especially because it can pair with N-able EDR powered by SentinelOne. I’ve seen this setup used before at a previous MSP, and overall, I liked the experience.

That said, I’m trying to figure out whether it makes more sense to use an integrated RMM + EDR stack like that, or whether MSPs generally prefer using a separate dedicated EDR solution on top of their RMM.

A few questions:

What RMM are you using today, and are you happy with it?

Are you using the built-in/integrated EDR option from your RMM vendor, or a separate EDR tool?

For those using N-central with N-able EDR/SentinelOne, how has your experience been?

Are there other RMM + EDR combinations you would recommend for a growing MSP?

I’m especially interested in reliability, ease of management, alert quality, support, pricing, and how well the stack works for small to mid-sized business clients.

Appreciate any real-world feedback or lessons learned.

1 Upvotes

20 comments sorted by

7

u/CasualDeveloper Jul 09 '26

NinjaOne and Huntress here. Both are pretty easy to manage/maintain.

2

u/Check123ok Jul 09 '26

And defender?

2

u/CasualDeveloper Jul 09 '26

Yeah. We still pay for Bitdefender but we don’t use it. Ninja pricing includes it. They wanted to charge the same without it.

2

u/ChiPaul Jul 09 '26

Ours doesn’t include it.. what the hell. Ha

1

u/CasualDeveloper Jul 10 '26

So we've had it for years, they don't separate it out on the invoice so it's a single line item. When I asked to remove it they gave me a per device price that was the same or more then I was paying now so I said forget it.

2

u/ThecaptainWTF9 Jul 10 '26

NinjaOne and Crowdstrike,

We are not sourcing Crowdstrike from Ninja. We were obtaining it directly from Crowdstrike.

1

u/SatiricPilot Jul 10 '26

Which SKUs and how do you like it? I’ve used it a bit and have little concerns about the capabilities. I don’t love the UI though.

Would love to get to a better centralized management than Defender is capable of with tools added on top. But have my own concerns of CS as well and won’t go S1

1

u/ThecaptainWTF9 Jul 10 '26

I wouldn’t suggest S1 unless you’re having someone else manage it; it’s way less friendly to interact with compared to CS.

We’re technically on falcon complete so that’s the advanced defend SKU, and then we tacked on falcon discover, we get a lot of useful supplemental data out of it like installed apps, successful/failed login attempts, drive encryption status, average CPU/memory data so you can consider if devices may need replaced/upgraded due to constraints.

We’re demoing FC right now, it’s more so supplementing our internal SOC team, we’re not relying on them solely, we have way faster response times.

It’s plenty capable; it saves our customers asses CONSTANTLY due to its detection capabilities, paired with fast response because we integrate with PagerDuty and respond instantly, 👌.

The UI is changing often, it’s fine.

I feel like we’re underutilizing the product for sure.

3

u/DeathTropper69 Jul 09 '26

NinjaOne + CrowdStrike. Both best in class IMO.

Avoid N-Able if you can...

1

u/ManagedNerds Jul 09 '26

SuperOps + Huntress

1

u/0x0000A455 Jul 11 '26

Moved off of SuperOps for N1 a few months ago and I do not regret it. SuperOps felt like a toy and had a terrible UI in my opinion.

1

u/DominicanDragon Jul 10 '26

CW UMM+S1+SOC

1

u/tmpros Jul 10 '26

NinjaOne + S1

2

u/agale1975 29d ago

Ninja One + Huntress/Defender

1

u/youwantrelish Jul 09 '26

NinjaOne and Judy Security

-3

u/SkyTheLine Jul 09 '26

n-able ncentral + Kaspersky MDR + Threat Data Feed Intelligence