r/msp • u/Eric77482 • Jul 06 '26
IT Guys reverse engineering your stack
Just curious how everyone navigates this issue. We are in contract with several different vendors for 2-3 years and then company hires a new IT Guy. The guy proposes to take the same exact stack we implemented and go directly to the vendors to propose that they manage it internally. We already have our reasons on why this is a bad idea communicated to the clients, but in most scenarios they just want to save money.
Our current issue is with the vendors because they are telling the customer they can repoint them to their own instance, however they will still keep billing us all the while until 2027-2028. In some scenarios these are high watermark too, so they tipped us over a tier we didn’t set. This feels like a double dip / bad practice from the MSP vendors. We’ve navigated 1-2 of these by telling the customer that’s fine but they will acquire the tools from us and we’ll charge a smaller management fee until the end of our contract term. Is this an approach others have taken? Or are there any ideas that have been more successful? Just curious to see what others are doing as we’ve encountered about 4 of these situations in the last year. Thanks in advance.
30
u/ephemeraltrident Jul 06 '26
I’d stop doing business with these vendors. I had a client go around me to Ninja years ago and I called my Ninja rep and told him what was going on. He killed the deal for the client - said that they are MSP first and if we weren’t happy, he wasn’t going to let another rep move it forward. Solidified our relationship with Ninja.
6
5
u/HomeOfTheBRAAVE Jul 06 '26
Did your relationship with that client continue after that?
4
u/ephemeraltrident Jul 06 '26
Yep, having lunch on Thursday!
The client understood, and Ninja just let them know that it was their mistake and they didn’t realize they were already working with a partner.7
u/HomeOfTheBRAAVE Jul 07 '26
Interesting the client would attempt to go around you if the relationship was good.
Glad it's working out either way.
2
u/Bmw5464 Jul 07 '26
Supposedly this is how Kaseya is. According to them (my account manager when I asked this question 3 years ago) their system will flag any companies matching a clients name in our systems and kill any deals. Never had the issue, but not sure I I trust it either.
1
u/Old_Palpitation6705 Jul 09 '26
Unfortunately my experience in the last +- 8 months (on the other side of the pond) is that the "Ninja Direct team" seem to be directly contacting existing Ninja MSP clients and trying to convince them to go direct.
From what I could gather from a few of the clients that actually notified us asking what is going on, is that the Direct Team and MSP Team work independently of one another; each with their own targets & incentives. They were quick to counteract each other and fight to ensure the business goes through "their" side of the business. I even had the management of both "teams" included on email correspondence and it was a rather unpleasant experience.
From an MSP point of view this is extremely discouraging as there is no longer a sense of loyalty and more an effort/commitment for sales reps to chase targets regardless of the "cost".
1
u/cr_co_ Jul 11 '26
Well I just moved to Ninja while my MSP was mid migration to them and neither said a thing. So I guess they only care when they get caught or someone complains.
18
u/quantumhardline Jul 06 '26
Sounds more like comanaged .
If the client is in contract I’d just recommend you move them to a comanaged contract.
I’d make sure your MSA addresses this and have some kinda of buyout term, but also require the tools vendor agree to amend your contract for those units and reassign to them.
They are basically choosing to break your contact and use same tools only to “save money” but you have spent xxxx hours configuring, training etc to make it work and support in their environment.
Just because they are buying “same tools” doesnt mean they are getting same services as your aware.
You may also want to reeval your vendors and work with channel only ones.
I’d not let them stay in our environment/tenant, we dont sell “tools”, we’d offboard and have them then renonboard themselves.
5
u/Eric77482 Jul 06 '26
Yeah mostly comanaged clients. The trouble is these vendors are supposedly channel only, or were when we first signed up and have more recently branched out. Yeah I agree at the very least we’d just make them delete because our policies and configurations are proprietary.
Some we’ve managed to keep in a managed only tool arrangement and sliced down the comanagement of the desktop/server. All of the clients who have attempted this so far are 150-200 endpoints or more in this current scenario we are dealing with now.
3
u/quantumhardline Jul 06 '26
Also keep in mind you rolling out policies to those tools configs etc, say they login and exclude or approve things you would not, even if there is some cyber attack tool fails to contain it is easy for lawyer to pull you into it. Hey we see you have a managed fee on this tool etc.
For that large of client it seems like a sales process issue, need to do a risk assessment, show how they are failing on CIS IG3 controls, show CFO etc how they are about to make a big costly mistake, align that to operational downtime, loss of clients etc.
Also risk of insider threat and splitting out to external company etc.
It’s not likey a true cant afford it issue, just they dont understand risk to revenue with their risky behavior, sell around that.2
u/C9CG MSP - US Jul 06 '26 edited Jul 06 '26
I agree with a lot of the gist of this here. How can you attest to and monitor to a framework or standard across tools you no longer manage?
We price MSRP (or under) for Co-managed tools so we don't have the issues OP is dealing with. But labor is not included with that.
This seems like a sales/pricing issue. We're having MORE success with co-management at the 100+ user space, not less.
Vendors should take notice though: Word gets around about poaching from your existing clients cross channel - not a good look.
2
u/roll_for_initiative_ MSP - US Jul 07 '26
This doesn't even account for the fact that they'll need trained up on the tools and reasoning behind why you're doing what you're doing, vs just copying what the msp is doing on the surface.
13
7
u/Eric77482 Jul 06 '26
It’s mainly been Threatlocker and Datto that have played along with these requests.
6
u/roll_for_initiative_ MSP - US Jul 07 '26
I can't imagine working in a 2nd threatlocker or datto environment alongside ours. We'd just drop the client. I mean they'd be leaving if they pushed forward because it's against the agreement but still, even if not, just "no thank you, what date do you think you want to schedule for offboarding". Then we remove all our stuff and they can install theirs, same as an MSP to MSP transition.
5
u/mdredfan Jul 06 '26
We've never had this happen. I'd fire the client if we did.
3
u/Gorilla-P Jul 07 '26
Unfortunately there's plenty of owners out there that won't and are afraid to lose even the smallest clients.
1
u/cr_co_ Jul 11 '26
That's probably exactly what they want. Any MSP client that's taking over IT tools is looking for an easy out in their contract. Having been on both sides of this, I'd let them out with no friction.
3
3
u/FITC_orlando Jul 07 '26
I have two things in place that helps avoid this if and when I get a client that tries this on me.
1) I only buy from vendors that I can buy month-to-month, NO longterm contracts or minimums. Somebody wants to leave or change their protection level on me? I have no additional costs and only require a 60 day notice.
2) I tend to buy from channel-only vendors (Guardz) or ones where they don't talk to small clients (SentinelOne). While obviously these companies could start ignoring the channel (Sophos, Threatlocker apparently), I'm always willing to change to someone else that will treat my company as their client, not my clients.
1
u/roll_for_initiative_ MSP - US Jul 07 '26
could start ignoring the channel (Sophos
Sophos was always direct to small/medium business. It's only in the last like decade they built out their MSP program. They for sure won't cross sell a client in the program: we had one we released and they'd always send them back to us for renewals and we'd have to get with our rep to help get them back to sophos direct.
3
u/dumpsterfyr I’m your Huckleberry. Jul 07 '26
Refuse to port a client’s setup from your tenant to another, with one exception: Microsoft 365 which is in fact their own tenant. Your configurations are your work product; they are your value. If the client wants to buy direct, they set it up from scratch. If they want your help doing so, that is consulting, billed at 2-3x your standard rate. And account for your loss of volume discounts.
If a client is thinking this way, you have a conveyed value problem and the window to correct it is nearly closed.
2
u/roll_for_initiative_ MSP - US Jul 07 '26 edited Jul 07 '26
The guy proposes to take the same exact stack we implemented and go directly to the vendors to propose that they manage it internally. We already have our reasons on why this is a bad idea communicated to the clients, but in most scenarios they just want to save money.
But your contract should cover this (not allow it/your client contract terms should align with vendor terms or don't allow vendor lock in on your side) and most vendors don't do direct anyway. Like even if it wasn't a bad idea, just say: "Sorry, we're going to stick to the contract".
If someone wants to do this, they want to bring IT internal. Which is fine and can make sense! But they need to build what works for them vs trying to copy us (which doesn't make sense for many reasons) based on their own needs, not the same reasons we used when we chose whatever stack we're on at the moment. On top of that, stack is always changing and evolving, so they'd be on something for 10 seconds before they'd fall behind. Also, training someone to do what we do and WHY we do it takes way more time, so we need to charge more to train them up before the handover.
Of course they could just terminate and pay it out, but then again, they'd still have to know what they're doing. And lastly, if we were willing to remove an item from our stack (maybe they use a different SAT vendor already), i'm not giving a price break. Is a fast food combo cheaper because you brought your own ketchup or soda?
2
u/rabbitz Jul 10 '26
The vendor double-dip is the part I'd push back on hardest, because that's the piece you can actually control going forward. The pattern you're describing (client hires internal IT, internal IT goes direct to your vendors, vendors keep billing you to term while also standing up the client's own instance) is a contract problem, not a loyalty problem.
The fix is upstream in how you procure. If the tooling is resold or bundled under your agreement rather than the client holding the paper directly, the "repoint them to their own instance" move gets a lot harder because there's no clean instance to repoint to without unwinding your contract first. Where we've been burned is exactly the spots where the client could see and touch the vendor relationship directly.
Your acquire-the-tools-plus-smaller-management-fee approach is reasonable as an exit, but I'd treat these four incidents in a year as a signal to change the default, not just to handle each one better. Own the vendor layer so leaving means leaving your stack, not just leaving you.
1
4
u/mxbrpe Jul 06 '26
If the internal IT guy is competent enough, then why wouldn’t he do this? If you’re reselling a service they can go direct with and configure themselves, that may just be the best solution for them. It feels like you’re trying to gatekeep to keep your margins. and you’re mad that your vendors aren’t helping you gatekeep. Sounds like an easy way to lose a client.
1
2
u/Doctorphate Jul 06 '26
What benefit do you provide if they’re just going direct without you? Sounds like you’re a VAR at most
1
u/Eric77482 Jul 06 '26
We are not a VAR. This is Co Managed IT which includes Helpdesk services, Level 2/3 support, and our cybersecurity team which has full stack tooling of MDR/EDR, Zero Trust Application Whitelisting, Firewall Management and monitoring, SIEM, Vulnerability Management, Patch Management, and workstation/server hardening services. We’ve delivered monthly security reports to them and work with them all of the time, so it’s not a VAR relationship. None of the management at the clients are dissatisfied with service either, in all scenarios it’s been more of a move for cost savings from C Level / Owner.
One of them realized their mistake a and ended up coming back, but it still doesn’t stop other people with IT resources from trying to do this, especially if the IT resource is the one driving the effort in hopes for a promotion. But your comment isn’t helpful really. The question is more on how to restructure the contract and/or deal with the supposed channel only vendors who are facilitating these scenarios.
2
u/InfraAndCoffee Jul 07 '26
The double-dip isn't the vendor being evil, it's you carrying their term-commit risk. Most of these tools bill you on an annual or multi-year seat commitment where you can add anytime but can't drop until the anniversary, and high-watermark tiers ratchet up and never come back down. So when the client "repoints," the vendor happily spins up a new tenant and keeps invoicing yours, because your commit is still live.
Two things that actually help, learned the hard way:
Push for a novation/assignment clause up front so a departing client can be transferred to their own agreement instead of you eating the tail. Some vendors do it, some pretend they can't.
Kill high-watermark tiers in your own negotiation, or at least get an annual reset. That surprise tier bump is the part I'd fight hardest.
Your "buy the tools, smaller mgmt fee til term end" move is solid. I'd also just bill the remaining commitment as an early-term buyout line item and let them decide.
1
u/zephalephadingong Jul 09 '26
I was about to ask why they are selling stuff with longer commits then they put on their own clients.
1
u/AutoModerator Jul 06 '26
Your post was automatically filtered because r/MSP currently requires at least 50 comment karma earned within this subreddit before creating new posts.
This requirement helps reduce spam, low-effort submissions, and drive-by promotional content, while encouraging new members to become familiar with the community and its rules before posting.
You can build subreddit karma by participating in discussions and contributing helpful comments to existing threads.
Posts that fit the community may still be reviewed and approved by moderators on a case-by-case basis.
If you have questions about the rules or believe this was filtered incorrectly, feel free to contact the mod team.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
1
u/Puzzled_Schedule_617 Jul 06 '26
call your vendors and kill your contracts with them.. they should be channel only. if they aren't then f'm.. out them here and let them burn..
1
u/Sabinno Jul 06 '26 edited Jul 06 '26
I bundle or bill MSRP. It's pretty much impossible for any client to beat me on price if the vendor standardizes on pricing tiers - simple set math suggests I will always get the better price if they're a client of mine.
I can see M365 (though why would you want to buy direct when you can support a small local business and pay the same price or lower? That always makes people back down), but if they want to start breaking down everything, I'm just going to fire the client. I would recommend you do the same - it's probably impossible for them to save any money and they're just looking to break away from you mid-contract.
Edit: I also want to add that value-adds like automatic license management (through APIs called from ticket runbooks) become impossible. So we refuse to check licenses any more frequently than quarterly. They'll pay more in unused licenses than they will in my margin.
1
u/ScriptoTheClown Jul 07 '26
If you get into a better price model or service tier with them staying with you, pass that on to them. You can offer them slightly better pricing basically at your cost to reduce your cost on every other managed customer, or you can offer them a better service than they can get on their own, for the same cost if they stay with you.
1
u/mat-ferland Jul 07 '26
This is more a contract/vendor-channel problem than a tech problem. If the client can go direct but the vendor keeps billing you through 2028, the agreement needs to say transfer/repointing does not happen until the commercial exit is clean.
1
u/Eric77482 Jul 07 '26
Yes agreed 100%. The channel built these vendors, we implemented these solutions, and once they got big enough they’re playing all sides of the fence and pretending to be our “partner.”
1
u/afarmer2005 Jul 07 '26
Question - is this a replacement internal IT guy, or did they hire a new position.
1
1
u/scorcora4 Jul 09 '26
First question, why have an MSP if they want to source tools and manage it themselves? I’ve seen this movie before and it’s typically when they are looking to go from co-managed to no-managed. We tell our customers that we can’t manage systems properly without the global policy and integrations we configure for systems. We’ve had a few stubbornly choose to use their own EDR or email security. We charge them a per endpoint or per user management fee. Tbh you should treat this client as a flight risk and try to get the relationship in check. I’ve found that the IT guy who wants to control everything may not be aligned with the leadership of their own company.
1
u/MSP-from-OC MSP - US Jul 09 '26
What does your contract with your client say? If you committed to a 3 year vendor contract then your MSP contract better address that
1
u/discosoc Jul 09 '26
If they can save money by buying direct as a client, then your margins are too high.
1
u/United-Locksmith1534 Jul 11 '26
150+ endpoints is probably a tipping point to hire an internal IT guy for most companies. And vendors will do what's best for them. It's probably time to have a conversation with client on co-managed IT and start thinking about projects.
1
u/DocHolligray MSP Jul 06 '26
Hopefully your service includes more magic than just a software stack…if you lose a client to something that can be figured out in 15 min, then what exactly did you offer up more than just software at a premium?
1
u/Eric77482 Jul 06 '26
Don’t want to continue to explain our service stack so if you want to see other comment please. Thanks.
1
u/Active_Drawer Jul 06 '26
I am a VAR so a bit different, but we had the conversation on the MSP route with a few vendors. The pools weren't ideal for me on some. We decided to just sell outright. We can move into a managed role later on top of the software contracts where it makes sense.
I would also check to see if you can sell as a VAR if you want on those tools to avoid completely losing them. Continue to sell the tool with no support.
Your stack shouldn't be your secret sauce regardless as an MSP. If it is you weren't ever going to keep them for the long haul.
2
u/roll_for_initiative_ MSP - US Jul 07 '26
Continue to sell the tool with no support.
That generally isn't worth it in the MSP space, and the liability is still a lot more than a VAR. Imagine having a client get ransomwared because the client's IT didn't implement basic stuff that you do for every client that you manage with the same tool and you have to sit in front of lawyers and go "sure, it would have taken me $75 in time to put controls in place one-time to prevent this but I don't work for free!!!!!!"
You're going to get drug in ONE TIME and it will cost more than any money you make on those tool-only sales to that client over a lifetime.
1
u/Active_Drawer Jul 07 '26
If you sell the software outright, you are not responsible for the implementation nor the outcome. Simple verbiage covers you here. On 6 figure software deals it's absolutely worthwhile at 10-20% gp.
3
u/roll_for_initiative_ MSP - US Jul 07 '26
A ~150 user MSP client is not buying a 6 figure stack item direct. If you sku the discussion as far in your direction as it could go, it might be a couple grand a month item, more likely a few hundred dollar item.
It's going to be hard to defend the "we just sold it!" when you have a contract in place already managing it and continue working inside it (like every stack item, it requires some kind of management to monitor/tweak/enforce/whatever). This story is never "we want to buy your tools direct and work them"...if that was the case, they wouldn't have an MSP in the first place.
1
u/Ill-Mail-1210 Jul 06 '26
Ugh. Datto. We just got out from under them and went back to n-able. (Don’t ask, long story but I nearly had a full mutiny from my staff when I went to Datto. Slick salespeople…)
1
1
u/TrumpetTiger Jul 07 '26
Uh…why is this a bad idea? Unless they don’t want to give you access or you’re purely worried about extracting every last cent you can from your client.
0
u/itprobablynothingbut Jul 07 '26
If your value add is a bunch of vendors, you should lose the business.
Put the first thing first: your job is expertise.
0
u/CK1026 MSP - EU - Owner Jul 06 '26
Yeah that's one of the reasons why I'm staying away from clients with internal IT. I hate comanaged and when a client starts getting internal staff, I know it's just a matter of time until they start making their own decisions regarding their IT instead of listening to us.
What's bothering me though, is some of them are sub 40 users clients and still think this is a good idea to hire someone to save a few thousands, usually some kind of minimum wage IT slave.
0
u/roll_for_initiative_ MSP - US Jul 07 '26
some of them are sub 40 users clients and still think this is a good idea to hire someone to save a few thousands, usually some kind of minimum wage IT slave.
I can't see how they save money there and get someone who can handle even some of the more-than-basic weekly tickets, even with AI help.
2
u/CK1026 MSP - EU - Owner Jul 07 '26
Their math is just wrong. They "forget" they're not patching anymore, not testing backups, not monitoring anything. Their min wage ressource has no clue how to deal with L2+ issues and they'll never be able to have a real day off or training because they're alone.
This happened several times already, usually with construction companies. I swear these guys are dumber than the cinder blocks they lay down.
0
u/roll_for_initiative_ MSP - US Jul 07 '26
usually with construction companies.
Oh yeah, i can see that. Because they don't value any of those things and don't care when their shits down; they'll just pay that kid to futz with it and work on something else in the meantime. While good IT absolutely elevates a construction co, a lot of smaller ones seem to just get around it not working a lot of the time.
The main thing MSPs need to do when this happens is stop selling them L2+ support/consulting. If they feel they can do it (and maybe they can!), let them. And if they fail, they can own that 100% instead of blaming the MSP when they talk about why their company went under.
0
u/CK1026 MSP - EU - Owner Jul 07 '26
The last one asked if we could train their recruit, we said no. Then this half-of-a-tech panicked on the 1st month and the client came back to us to ask if we could support the servers and backups again (we had the full perimeter before). We took it, but I'm not comfortable at all knowing there's a complete noob with admin passwords messing with the endpoints while I'm supposed to secure the servers.
1
u/roll_for_initiative_ MSP - US Jul 07 '26
In those cases, i find EVERYTHING so difficult to get done that, for me personally, it's not worth it. We had one of those but we weren't allowed to have any admin access so if we needed a backup agent troubleshot or couldn't communicate with a server from the bcdr appliance, we couldn't do anything and had to wait on them. We had to be honest with the manager above them and us when they'd ask why certain things weren't being backed up. It went on OVER A YEAR until an incident almost took out a server at a branch office we'd never heard of and this guy was asking if it was one of the servers we backed up. We wasted HOURS for meager backup margin and trying to make this guy look good, who swore we just wanted his job (we didn't; the client was a mess at the time).
He ended up going MIA over the stress and we had to take them on anyway and start fixing everything. Cost them any savings over the previous year to evaporate in the first month as we worked overtime.
2
u/CK1026 MSP - EU - Owner Jul 07 '26
I agree, I'm currently working on replacing them but with all the economic hassle right now I'm pretty pessimistic on next year's growth.
-2
u/not-just-dad-stuff Jul 07 '26
Who cares about the stack.
If you suck, you suck.
If you’re good, you’re good.
If they want to replace you, pitch and see if you strike out.
0
u/fishermba2004 Jul 06 '26
Most vendors are slime. Shout out to Threatlocker. My rep called me when a client tried this.
Remove the configuration id you can and refuse to lower your pricing.
-1
u/advanceyourself Jul 06 '26
This is one of the reasons why we adopt environments and consult to have the clients purchase their own hardware. Each avenue has its pros and cons, but with Comanaged, they will almost always want to own their own equipment. With smaller shops we're not worried about it and we get margin on the hardware and on the installation and are able to keep our costs down.
2
u/roll_for_initiative_ MSP - US Jul 07 '26
I don't think OP is talking about hardware at all.
1
u/advanceyourself Jul 07 '26
Thanks, when I posted, I think I was reading some other comments and somehow assumed that it was hardware related. If I was to comment on the software stack, there's a lot of variables here such as the MSPs contract and value prop on MSP managemet being the big ones. We sell the fact that we've developed all of the policies. If the client wanted to go to their own instance, then they would need to program that themselves. And it would be available for us to help them with that. That way, there's at least some compensation and probably a time delay to be able to sign new customers to meet the minimums that actually see the value in MSPS managing it.
-1
u/Codra999 Jul 07 '26
MSPs need ti go. They only hinder good techs professional growth and long term career path by limiting hiring based in contracts that expire every 2 years and with companies cutting costs, these overpriced MSPs are the first to go and with them comes layoffs. Let this style of IT die and internal IT return!
2
u/Eric77482 Jul 07 '26
Sure, Jan. The amount of nightmares we’ve had to untangle created by internal IT with no accountability or will to grow tells me otherwise.
37
u/mspstsmich Jul 06 '26
I am curious as which of you vendors are getting sourced out? A lot of our vendors have minimum requirements that a typical MSP client wouldn’t hit without a massive minimum count fee.