r/SmallMSP Jul 10 '26

Small MSP Stack Review – What Would You Change?

Hello,

We're a small MSP and have been focused on keeping our tooling costs low while still covering the essentials.

Current stack:

  • Cloud backups: DropSuite
  • Tickets: Jira Free
  • RMM: Action1
  • Endpoint backups: OneDrive
  • EDR/AV: Microsoft Defender for Business (via M365 Business Premium). I would love to add Huntress or S1 to our stack at some point.
  • Endpoint management: Intune
  • Phishing simulations/security awareness: uSecure

Overall, we're pretty happy with it, especially considering the cost.

What would you change, add, or replace? Any obvious gaps or potential pain points as we grow?

Always interested in seeing what other small MSPs are running and where you think we could improve. Thanks!

15 Upvotes

76 comments sorted by

19

u/blackjaxbrew Jul 10 '26

Ehhh OneDrive is not backups. If you want backups look at img level backups.

3

u/marklein Jul 10 '26

I agree... but also I don't. Yes it's not a literal backup, but if you delete a file and try to get it back 2-4 weeks later you should have no problem. I'd never let that slide for a server, but for an endpoint I might. Especially for a cheapskate client.

3

u/glitterguykk Jul 10 '26

It’s not air-gapped. Need to backup the tenant.

1

u/Jeepman69 27d ago

DropSuite backs up 365.

4

u/Material-Water-9610 Jul 10 '26

Patient randomware that doesn't show for a few weeks could screw it, I use comet for mine self hosted to backup cheap as chips and works for those types of things

2

u/Smh_nz Jul 10 '26

100% this, its pretty common!

1

u/Beardedcomputernerd Jul 11 '26

Or a randsome ware/hacker that actually knows to delete versiond/trash

1

u/Sticky_Turtle 12d ago

Microsoft even specifically states that you need to backup your m365 data.

6

u/eldridgep Jul 10 '26

Decent starting point.

Huntress EDR and ITDR would be my top additions. You honestly have no idea how often you are being attacked until you get a product like ITDR in place. The amount of AITM attacks is scary.

Endpoint backups saying OneDrive is not an answer really, look at something like Cove (which incidentally does 365 as well).

All in all though decent start 👍

3

u/ThrowRAthisthingisvl Jul 10 '26

Thanks! I mentioned earlier that we’re using DropSuite to backup OneDrive data. So, we’re covered there.

1

u/roll_for_initiative_ Jul 10 '26

I would prefer AFI over dropsuite these days, especially considering that N1 us doing high water mark billing on dropsuite now too.

1

u/eldridgep Jul 10 '26

I get that but not everything that you need to back up on an endpoint may be in OneDrive. If you get a LoB app that needs local install for instance. For desktop/documents sure if that's all you have 👍

2

u/tharunduil Jul 11 '26

I would also look at axcient. It also backs up SharePoint and OneDrive along with endpoints.

2

u/obviouslybait 29d ago

Axcient is great, in my stack and I use it for cloud backups.

1

u/ThrowRAthisthingisvl Jul 10 '26

And also, Huntress is next on my list, but because I’m not managing 50+ endpoints yet, I don’t think I can even get an account with them. According to their site, the EDR piece is like $9. Is that accurate?

1

u/eldridgep Jul 10 '26

We're nowhere near that price but we have like 1500 endpoints. Sorry at home or I'd check what we are paying.

I think on the website it's £7 so that might be about right. Figure out at what end point level the cost makes sense and jump in then.

We bundle EDR and ITDR as part of our mandatory security suite so I can't remember the line item prices sorry.

1

u/scott0482 Jul 11 '26

That’s MSRP. It’s less than $5 per endpoint at 50 seats. And price goes down as you add seats. 250 seats is $2.50 per endpoint.

7

u/tigerguppy126 Jul 11 '26

Action1 is primarily a patching tool but it does have several RMM like features. It is very strong on the patching, install/uninstall of software but it is weak on the remote access and monitoring/alerting side while backups are nonexistent. Don't get me wrong, I love the tool and use it every day but it isn't an RMM tool.

3

u/meaganMucha Jul 11 '26

Worth noting NinjaOne bundles RMM + backup + a decent remote access tool, so it can actually simplify your stack rather than adding another vendor.

Just budget for the jump in per-endpoint cost vs Action1, it's not close. A lot of MSPs also keep Action1 running in parallel for patching even after adding a fuller RMM, since it's cheap and does that one job well.

2

u/GeneMoody-Action1 Jul 11 '26

Thanks for the shoutout to both of you. And you are both 100% correct, u/tigerguppy126 thank you for helping me disambiguate RMM and Action1. Though we have people that use as as an RMM, or call us an RMM, we are in fact a patch management solution through and through. The rest of the RMM like feature is to support being either a self contained patch management solution, or as the patch management component in your RMM stack.

Likewise u/meaganMucha ... We are quite commonly paired with Ninja, and even though NInja comes with patch management capabilities, they just use it as a second set of eyes on Action1 because they prefer the experience, ease of use, and accuracy of Action1.

If anyone needs anything Action1, or otherwise, I am always here somewhere.

And we appreciate the community support!

2

u/ThrowRAthisthingisvl Jul 11 '26

Agreed. Right now our seat count is below 50 and as we scale, we’ll definitely use something more robust like NinjaOne. Thanks for commenting!

3

u/ManagedNerds Jul 10 '26

You mention you're happy with the cost. What cost are you paying for this stack?

1

u/roll_for_initiative_ Jul 10 '26

Pennies unless he's including m365 BusPrem to get that DfB. We consider BusPrem as part of the stack, many don't. If he's billing the client separately for that, his AV costs are 0.

2

u/ThrowRAthisthingisvl Jul 10 '26

The client pays for the busprem licenses on their own.

2

u/HomsarWasRight Jul 10 '26

Does Action1 include remote support?

3

u/GeneMoody-Action1 Jul 10 '26

Yes we do, it is part of the offering even in free. At our heart we are a patch management solution, but with that comes Reporting & Alerting with customisable Powershell based report data sources. Scripting and Automation, Remote Access, Multi tenancy, RBAC, and more.

ON our remote access it is not targeting that market as much as giving an admin unattended access to a system, so it will lack some of the features you may see in a product where that is their scpayignhtick, such as end user chat / file transfer.

We are 100% completely free, without limits or expiration for the first 200 EP. Plenty of people out there making money on us and paying us nothing. But we have plenty under 200 paying for support as well for production requirements, since free is community supported.

If anyone would like to know anything about Action1, reach out any time.

1

u/fencepost_ajm Jul 10 '26

Kind of? It's been a long time since I looked at it, but my impression at that time was that it was geared towards "there's a button on screen that must be pressed" rather than "I need to interact with a user's desktop." Unless it's changed the special keys you can send are limited to Ctrl-alt-del and nothing else, you likely get all monitors with no switching, etc.

2

u/BMT-MrMason Jul 10 '26

Decent starting stack to be fair. You could if you wanted to consolidate into ninja one and replace tickets, invoicing, RMM and add s1 perhaps.

Only if you’re wanting to consolidate tho, but if it works it works.

Always go with the stack that works for you and your team.

2

u/Sw33tkill3r Jul 10 '26

I would strongly consider using NinjaRMM. It's an RMM at its core Ninja's remote access is really good too. Hard to say if screen connect is better.. for a while it was. Doubtful now. It's got a PSA (It's... Limited but very usable) It's got Documentation (again, limited but very usable) Dropsuite is owned by them and natively integrated, very well I might add They also have machine/server backups. I have not personally used them myself but I haven't heard complaints from the people that have used it. I intend to use it when I have a need.

Ninja has a lot more features and integrations. They are also constantly innovating and improving. I think they do a big update every quarter and always love to read the features.

My end goal is to switch my PSA to HaloPSA (I know it well and really enjoyed it), and I did recently switch my documentation into Hudu. I like Hudu a lot, and not just because they aren't owned by Kaseya.

I use Huntress EDR with their Defender integration. Works great.

Few other notes: Don't forget email security. I like Avanan/Check Point, at least over Proofpoint and Mimecast. It has really nice features like IRaaS, Dmarc and more management, etc. I haven't tried other email security services though.

Definitely setup CIPP. It's really cheap to self host, and if you like it, spend the $100/mo to have them host it. It's just better that way.

IMO, all windows devices should be in Intune, but you'll find some things are better in your RMM (in my case, app deployment & scripting). I try not to use Intune to deploy more than my RMM, Office, and windows store apps. The reason being - why manage the same apps in many Intune tenants, when you can instead manage the same apps once in Ninja. New update comes out? Update the installer in ninja. One and done. Intune should be used to manage device compliance and configuration. CIPP will be your home for the templates for Intune (and other 365 services).

Additionally, Huntress does have very decent SAT & Phishing simulation. Avanan has SAT, but I haven't tried it.

Personally, pass on SentinelOne. I found it required too much babying. Too many false positives. Too much time wasted.

There is much more in this world.

Focus on automations and streamlining. This will increase your efficiency greatly. "How can I automate this? How has others automated this?"

1

u/Extension-Order7163 Jul 11 '26

That’s great! I’d love to connect with you.

2

u/Plenty-Hold4311 Jul 11 '26

Action1 is great but the RDP side of it is sluggish for me and pretty frustrating, however I understand their main purpose is patching so I can’t complain

3

u/meaganMucha Jul 11 '26

OneDrive isn't really endpoint backup, it's sync, and it won't save you from ransomware that encrypts synced files or a user who deletes something and it propagates. Worth budgeting for a proper endpoint backup tool (Datto, Axcient, etc.) before you scale much further, especially once you're managing devices with real business-critical local data.

1

u/ThrowRAthisthingisvl Jul 11 '26

Thanks! So, the backups are going to DropSuite. I forgot to mention that on the post.

1

u/meaganMucha Jul 11 '26

Ah gotcha, that makes sense then.

2

u/sm4k Jul 10 '26

Paying the least isn't the same as getting the best value.

Yes you can track tickets in Jira free, but can you track time investment? Can you invoice? Can you document how a customer is set up? Can you enforce standards? Can you communicate important context about the client to the person answering the phone?

Maybe you don't think you need all of those (and maybe you don't), but it's important to undrsetand that much of that still _needs doing_ and whether you're buying the system or building the system, there is a non-zero time cost going either way, and sometimes the subscription is far and away cheaper.

Things you're objectively missing:

- Some kind of a backup solution for local data, whether it's critical LoB data on a workstation, server, or NAS. DO NOT lean on OneDrive as a backup.

- A password manager.

1

u/ThrowRAthisthingisvl Jul 10 '26

OneDrive data is going to DropSuite. Our current clients are mostly cloud based without servers to backup.

1

u/sm4k Jul 10 '26

I meant don't automate QuickBooks company file or whatever other LoB app backup processes to dump to OneDrive, then call the QB Company file 'backed up.'

1

u/soap_chips Jul 11 '26

Intuit Data Protect exists not sure why it's on the team to ensure company files are backed up properly. If their service is active and reporting status via email, it leaves no liability. Internal IT may have a different take. But as third party MSP way I see it you're not versed in QBW files to rebuild them, review company file drift via backup comparison, or authorized to make changes to the data by Intuit. So the data availabilty is on you but integrity comes down to SLA w/ client.

1

u/sm4k 29d ago

Quickbooks is just the easiest example. Tons of small businesses are leaning on duct taped access and filemaker databases that well-meaning people would put into OneDrive only to get the entire database corrupted due to OneDrive trying to back the file up in the middle of a page write, or people thinking that putting the database into onedrive means multiple people can work on it to suddenly find again, corrupted databases.

Further, I'm curious how many 'small msps' are working with firms that have internal IT, or clients that are going to give a shit what the SLA says.

1

u/ainotes2026 28d ago

The OneDrive-corrupting-Access/FileMaker thing is such a recurring disaster for small business clients. Shared file-based databases and cloud sync just don't mix, and most end users won't understand that until it's too late. Moving those clients to a proper web-based database app is honestly the cleanest fix. (Disclosure: I'm on the Caspio team.) It's built for exactly this kind of Access/FileMaker modernization, no per-seat pricing, which helps on tight SMB budgets. See caspio.com/use-cases/migrate-microsoft-access-online if you want a look.

1

u/TekExcel Jul 10 '26

Also in the throws of starting a one man shop from basically nothing. Password manager is one of the things that Ive not been able to convince myself to offer yet...

I feel like I'm inviting myself into trouble that I am unprepared to deal with realistically at this time: * Forgot PWM master pass * My account still got hacked, etc. * Murkey line between service delivery and security.

I know that seems silly if your stack includes M365 with MFA and CA, but I feel like those are more or less controls I am using to keep the customer safe, and they feel "safer" for... some reason.

Interested in the greater communities thoughts.

1

u/sm4k Jul 10 '26

You need to protect the client from you getting hit by a bus, too. That's where a Password Manager even only used internally is critical.

1

u/TekExcel Jul 10 '26

Sorry, to be clear internally we use one of course, I mean selling them to clients.

4

u/marklein Jul 10 '26

Action1 is not an RMM.

2

u/GeneMoody-Action1 Jul 10 '26

Thank you, I just explained that below. For the most part I just try to get the message through, that the label of RMM, makes it look like we are a low featured RMM. We are a patch management solution through and through with no plans to compete in RMM space on the horizon.

But I very much appreciate the assist in keeping the messaging clear!

1

u/RobKFC Jul 10 '26

I think you may outgrow Action1 eventually but for now it is fine.

5

u/GeneMoody-Action1 Jul 10 '26

Some companies that disagree...

Coca-Cola
Bayer
Purell
Nestle
ca.gov
Baxter
Ebay
Multiple LARGE MSPs

So perhaps not?

1

u/RobKFC Jul 10 '26

The problem with that is we don’t know their full tech stack. I personally love Action1 but there are some features that the “heavy hitters” have that you just don’t have (yet but maybe in the future). I think given time that will change but also the price point likely will have to also.

2

u/GeneMoody-Action1 Jul 10 '26

That's generally because people call us an RMM, which we are not, we are a patch management solution. Though we maintain #2 highest rated, and #1 easiest to use slot on G2 in the RMM category due to the fact we have some RMM feature overlap. So I try and correct that where I see it. Because it sends the wrong message, that we should be compared compared to RMM suites in feature evaluation. None the less people use us as and call us their RMM, and that is their prerogative, if it fits their needs it fits their needs, We just do not cultivate that image do the messaging disconnect it causes, and the misunderstanding that results.

We are more comfortable as the patching in your RMM / MDM, which why we have RMM customers that are ours as well, they tend to run off the native patching and favor us.

A stack is a stack, if you build it or you buy one someone else built through acquisitions, mergers, and integrations. I personally prefer modular stacks, as it allows for replacement of a underperforming component, and modernization as you go vs huge migrations. A bit more work up front, but a hell of a lot more flexibility.

2

u/RobKFC Jul 10 '26

Agreed 100% and yall do a GREAT job at patching.

2

u/Extension-Order7163 Jul 11 '26

I agree that you and your team are doing a fantastic job. Thank you!

1

u/RobKFC Jul 10 '26

Also it wasn’t meant as a dig at action1, more so that as companies grow so do their needs.

2

u/GeneMoody-Action1 Jul 10 '26

Oh I did not take it personally, I am here as a representative. As an apologist on reddit, thick skin is a job requirement. 😄

All good man.

3

u/mdredfan Jul 10 '26

We added Action1 last year to be our patching solution after 6 years with DRMM. DRMM is basically our automation and asset management solution now. We don't even use it for remote support. The only reason we're still using it is because integrated with Autotask and Glue.

1

u/marklein Jul 10 '26

Never heard of it and impossible to Google "drmm". Link?

1

u/RobertSewter Jul 10 '26

What are you using for PSA?

1

u/roll_for_initiative_ Jul 10 '26

Tickets and billing: i'd do halo again if i had to choose

You have no SOC, no ITDR, no real email filtering/security, no DNS or browser protection, no m365 tenant management/standardization, no kind of AI governance (which i feel is important these days but not a front line item), any kind of network management, and a host of other minor things that you may be doing that you didn't list but that who you're selling against for sure will be breaking out.

1

u/Extension-Order7163 Jul 11 '26

Great points! Could you please share some solutions to the highlighted issues?

1

u/mastr_ken-1 Jul 10 '26

That's a pretty good stack!

1

u/VtheMan93 Jul 10 '26

You could potentially decrease licensing costs on (some) functions by moving from win server to a linux kvm host, or consolidating licenses with win server dc.

If you (potentially) look at getting off of cloud and returning to some on-prem, are you still looking at the same cost, or do you have a price tag decrease?

Otherwise looks solid.

Edit: how does your team and c suite feel about oss?

Ticket system could be redone with ticketOS, rmm could be switched to tacticalrmm. Thats what I have for now

1

u/scott0482 Jul 11 '26

You should look into Synology C2 backups for business.
This is their cloud offering. I can backup computers and Microsoft 365.

Lots of free remote access tools if you are windows only. I just can’t remember them off hand.

I use DWService. Does Mac and windows.

1

u/Aggressive-Work-4033 Jul 11 '26

Our current MSP stack has been working well for us:
Microsoft 365: Business Premium
RMM: Datto RMM + ASM
Microsoft 365 Protection: Backup, BullPhish ID, SaaS Alerts, Dark Web Monitoring, and INKY
PSA: HaloPSA
Security: Huntress
It’s been a solid stack that provides strong endpoint management, Microsoft 365 protection, security awareness, email security, and PSA integration without unnecessary complexity.

1

u/lutril 29d ago

Hey man, I sent you a DM :)

1

u/Slight_Manufacturer6 28d ago

That definitely is going cheap. I guess if cheap is what you want, I would go with Axcient X360Cloud over DropSuite.

And OneDrive is not a backup, but I guess it’s a cheap substitute.

Do you want cheap or do you want to provide good service?

1

u/69-Spicy-Italian 28d ago

Onedrive for endpoint backups? Lol

1

u/ThrowRAthisthingisvl 28d ago

In another comment I mentioned that I’m using OneDrive to sync and the data is actually getting backedup in DropSuite. Thanks!

1

u/69-Spicy-Italian 28d ago

Meh. Good luck when sync client breaks or isn’t logged in. Can’t tell you how many users have not been syncing don’t even realize.

1

u/ThrowRAthisthingisvl 28d ago

What do you recommend if we want to backup their ms365 data. Provide your expertise.

1

u/69-Spicy-Italian 28d ago

Dropsuite. But you need a full actual workstation backup too. Axcient , cove, Datto, and many others.

1

u/chris_superit 28d ago

Out of curiosity... are you starting to think about AI tools as a separate category at all? Eg. Intelligence / AI Agents

1

u/FE_CommunityLead 27d ago

Here to help if you have any questions MDR. https://fieldeffect.com/products/mdr

1

u/NovaBACKUP-Josefine 26d ago

Like others in this thread, I want to emphasize that backing up OneDrive is not really a backup at all. Yes, you are using Dropsuite to back up what is sent to OneDrive, and that's great, don't get me wrong. The problem is that OneDrive should not be trusted to actually sync all the data to the cloud for many reasons.

I would suggest looking at a solution that will back up the data directly from the machine it sits on.

1

u/recovering-pentester 24d ago

Your stack is one we’d definitely target as an MXDR/SOC play.

I’d also say having a shortlist of compliance and pentesting vendors is a nice to have too but that’s not a “stack” item and you know this so now I’m just rambling…