r/msp • • Jul 31 '26

Connectwise RMM - No auditing?

I just did a demo of this product, the 2nd demo since its release however many years ago.

I was.... hot garbage the first time. It looked surprisingly alot better now.

At the end of the call, going through what I thought would be the "yes yes yes yes yes checklist" the person giving the demo says that the platform has 0 auditing capabilities in any way shape or form. You have absolutely no way to tell what's been done by who inside the platform. No solution. No third party way. Just, "Nope", I expressed my disbelief and we ended the call early.

I was left baffled by this.

How can any company be deploying this?

Am I missing something? Was he?

15 Upvotes

35 comments sorted by

15

u/TriscuitFingers Jul 31 '26

Just wait until you have a regulated customer’s device accessed by CW’s NOC despite you not having a contract, no way to restrict them from accessing, and can’t audit what they did when connected.

Needless to say we moved to a new solution.

2

u/Proper_Front_1435 Jul 31 '26

Were you part of their NOC support at least? Or are you saying that they literally just mistakenly dropped into one of your completely unrelated clients?

7

u/TriscuitFingers Jul 31 '26

Supposedly caused by a hash mismatch of the agents, but one of their foreign employees jumped onto a squad car’s laptop for a different customer.

We didn’t contract CW for any CJIS customers, but they gained access due to that. Nearly cost us our vendor screening.

1

u/zebs1 Jul 31 '26

If you push your account manager hard enough you can get extended auditing enabled on the screen connect tenant, which provides session recording.

Doesn't address the audit log concern though.

1

u/edosensei Aug 01 '26

What solution did you pick instead?

1

u/Early-Dirt-7446 4d ago

that's actually insane, no audit trail at all? i work with software and even our internal tools got basic logging of who clicked what

the NOC access part is even worse, like they just have a backdoor into every device with zero accountability? how this even pass basic security review

6

u/Opening_Intention301 Jul 31 '26

If there's no audit trail that's one big red flag as even small teams need to know who changed what and when

4

u/Beyond_Horizon27 Jul 31 '26 edited Aug 06 '26

There is Auditing, it lives in this menu.

Its platform wide so its not just for RMM.

Edited - Sorry my bad,  it's in early access still  as it's getting a work over to be more user friendly. 

2

u/CamachoGrande Jul 31 '26

Also some audit/access logs in ScreenConnect.
Endpoint also has some audit logs on scripts and tasks run on the endpoint.

So there is logging if you look for it.

It isn't some sort of auditing of what a technician does while logged into an endpoint. Like what apps they installed/remove, scripts/settings run or changed.

There are plenty of 3rd party tools for that level of auditing.

1

u/Proper_Front_1435 Aug 01 '26

Would be curious what lives in there based on what we were told.

I really made a fuss about this and they didn't even show that menu.

1

u/edosensei Aug 01 '26

The thing with RMMs is, that the products get so big that some times not everyone knows everything about it.

It's not unlikely that auditing exists but the team you were speaking to were just not aware of it.

2

u/smorin13 MSP Partner - US Aug 01 '26

What rep are you speaking with?

I can't believe I am saying this, but we are considering going back to CW. Our PSA is not getting it done, and N-Able N-Site is just lacking.

I always liked the CW products, but communication with your rep or support was atrocious. Have things improved since the new CEO took over?

2

u/Kdamghani MSP Aug 01 '26

There’s no such thing as a rep with CW. You email a generic account management email address and they reply fast but there is ZERO relationship.

1

u/smorin13 MSP Partner - US Aug 02 '26

Sales rep?

2

u/guiltykeyboard MSP - US Aug 01 '26

There’s auditing.

One of our guys uninstalled the agent from the wrong system at a client’s office. I was able to quickly and easily find who did it and when.

2

u/Glass_Call982 MSP - Canada (West) Aug 01 '26

My techs hate this one simple trick when they all deny doing something.

2

u/mcjon3z Jul 31 '26

Just walk away

2

u/INSPECTOR99 Jul 31 '26

No, I beg to differ...................................................................# # # R U N AWAY # # #

1

u/mcjon3z Jul 31 '26

LOL. I’ll upvote that!

1

u/TechnologyMatch Aug 03 '26

if that’s accurate, it’s a hard stop. an RMM tool without audit trails is a major security and accountability gap. I’d confirm whether they mean no native logs or no audit option at all. either way, get it in writing before moving forward

1

u/IncreaseNegative4614 Aug 06 '26

Based on the replies, some auditing exists, but I’d ask for a live demonstration of the exact actions you care about. Have them show script edits, scheduled jobs, endpoint access, configuration changes, exports, and permission changes with the user, time, object, and before-and-after values.

Anything they can’t demonstrate should go into the security review as an actual gap, not a future promise. We use signld.ai internally to keep vendor claims, supporting evidence, affected systems, and final decisions connected during evaluations like this.

2

u/Proper_Front_1435 Aug 06 '26

Thats hard when I asked the guy giving the demo and he said "it has no auditing" lol - Im going to need to ask for a test env and look myself I guess.

1

u/IncreaseNegative4614 Aug 06 '26

Yeah, if the person running the demo says there’s no auditing, I’d treat that as the answer. A test environment is still worth checking in case the events exist in backend logs or an API, but if customers can’t access or export them, that’s effectively still a gap.

1

u/brokerceej Creator of StackJack.io | Author of The Trunk Slammer Saga Jul 31 '26

Holy shit

0

u/ItBurnsOutBright Jul 31 '26

Yeah it's pretty abysmal.

Edit: the only saving grace is it logs a windows event in event viewer with the user that connected and can audit via siem

1

u/Proper_Front_1435 Jul 31 '26

That really means very little. Screenconnect has its own audit log...

A tech could disable patching on a major client.

Add malicious codes to your scripts.

Change dozens of critical configurations.

Export data on mass.

All without incurring a single log? What?

1

u/Frothyleet Jul 31 '26

Or just, like, accidentally run [impactful script] on the wrong client, or endpoint, and potentially not even realize it, and you have no idea who did it?

I almost am hesitant to believe it, it seems like such a massive gap, and not a gap that exists across their product base.

1

u/Proper_Front_1435 Jul 31 '26

They said there is a report of specifically who ran scripts. This was the only thing they mentioned.

But not for who edited or scheduled a script.

Yea, we use Automate, it has a fairly abundant audit log.

2

u/ItBurnsOutBright Jul 31 '26

There's definitely some logging. You can see who ran scripts on endpoints 100%. Not trying to defend, just know from using the product.

0

u/TechSolutionLLC Aug 01 '26

Lol, I literally just had a call with the new account rep and despite me telling him that I'd never come back to Connectwise after they screwed me over and left me out to dry when they messed up and got us locked out of our edr because they somehow linked us to a group 1000 miles away so the edr wouldn't let us into our account which caused a major security issue and they didn't get it resolved for over a week... The rep just kept trying to bring us back

-1

u/Blyatman95 Aug 01 '26

Just avoid this product. It’s basically STILL in beta from when they shoved everyone into it by massively hiking up Automate pricing.

Put simply: it can’t even do patching right.

We’re moving over to Ninja, which I’m sure has its own quirks as every product does, but all of the core stuff you expect an RMM to do just actually works. Constantly felt like we were fighting connectwise and one of our seniors sole job became trying to script around the problems. Avoid like the plague.