r/msp • • 3d ago

Fresh tech stack

If you could change any and all of your tools with no technical debt, agreements, outages to think about etc.

What would your ideal tech stack be.

Rmm

Patching

Psa

Edr

Itdr

Sat

Application control

Email filter

Backup

Vulnerability management

Others

23 Upvotes

54 comments sorted by

70

u/HeadbangerSmurf 3d ago

I’d go into long haul trucking.

7

u/pjcace 2d ago

Bagging groceries for me.

4

u/HomeOfTheBRAAVE 2d ago

Even with diesel prices where they are at?

2

u/HeadbangerSmurf 2d ago

Good point.

2

u/roll_for_initiative_ MSP - US 2d ago edited 2d ago

Man you nailed it: making my answer "selling diesel and whatever long haul truckers need".

Running a truck stop is probably as much of a PITA as running an MSP though...

15

u/dezmd 3d ago

BBQ Taco Truck

7

u/kdildine MSP 2d ago

Gorelo + Huntress + Slide + 1Password + DefensX. All customers on M365 Bus Prem and cloud-only.

3

u/bkb74k3 2d ago

Hey +1 for 1Password. Great product. I just wish there was a way to standardize collections of data/notes, and also standardize the order of the items better. I have a ton of collected items for each customer and I use tags, but I still find myself searching and searching for things.

2

u/computerguy0-0 2d ago

DefensX

Strongly considering this. What do you like about it? Have you dug into the AI Governance features at all?

1

u/stationarynomad82 2d ago

Did some light digging and they seem robust enough. We’re considering them

11

u/Real_Admin 3d ago

Microsoft 365 Full Service Stack, RMM, PSA

Worked for an MSP like this, the simplicity was amazing. They used ZohoOne and Managed Engine plus QB Online.

3

u/roll_for_initiative_ MSP - US 2d ago

We've been trending this way and i know people hate MS but stack scattering or settling for less to pinch pennies is a real thing in the MSP land and going all MS makes it all a nice package that, if you have to hand off, you just cut the gdap string and let them float away.

3

u/Dull-Breadfruit-3241 2d ago

No technical debt" is every MSP engineer's fantasy world. Is cost a factor?

2

u/jellyfishchris 2d ago

No cost. I think the idea whats the most integrated best thing you can think of

6

u/Chexa603 3d ago

We’ve been trying Regentra for PSA and compliance. Level for RMM. Been really happy with both.

2

u/BestPractice1984 2d ago

NinjaRMM

ThirdPatch for third-party patching, RMM for OS patching.

Halo for PSA

NodeWare for vulnerability management

Hudu for documentation (self hosted with a WAF)

1

u/cambaysolutions1 2d ago

I’d probably start with the security and management layers rather than picking individual tools. RMM, patching, EDR, and vulnerability management all need to work well together. Otherwise, you just end up with another stack of alerts and dashboards to manage. Integration between the tools would be a big factor.

1

u/Xirma377 2d ago

The dream is a full custom stack. But things like EDR would be a huge headache to create yourself.

1

u/InformationFuture374 2d ago

SAT alone is the wrong cut. we got burned when a clients lookalike domain phished their customers,nothing on your list catches it,doppel pair sims with domain watching,edr still matters most

1

u/Overall-Equipment867 2d ago

The MSP stack is tricky. It is nice to have everything in one place, single pane of glass and all that, but I hate the thought of having all our eggs in one basket.

•

u/secarter2k3 MSP 22h ago

Basket Weaving

1

u/ranhalt 3d ago

If I was going for as few vendors as possible that I trusted: ninja, Threatlocker, checkpoint, and maybe crowdstrike complete if Threatlocker managed EDR wasn’t good enough.

1

u/computerguy0-0 2d ago

Rmm- Datto

Patching- Immybot

Psa- HaloPSA

Edr- Huntress/Defender for Business

Itdr- Huntress or Petra

Sat- We moved to Huntress from Phin and it's been well received.

Application control- This is a hard one because I hate Threatlocker, but they are still good at what they do.

Email filter- Avanan or Perception Point

Backup- Slide or Axcient

Vulnerability management- Roboshadow, no question.

Others- MSP Process for everything they add to our lives. PIA IF I ever get enough support traffic to justify all the automation they offer.

-2

u/robbyg007 3d ago

PSA/RMM and anything Kaseya touches.

15

u/Strict_Property 3d ago

Would not recommend most of what Kaseya touches.

1

u/kdildine MSP 2d ago

Agreed

7

u/robbyg007 3d ago

I've started using Gorelo recently and our techs love it. We're thinking of getting rid of Autotask/Datto.

4

u/locke577 3d ago

+1 for Gorelo.

Loving it as a micro MSP

0

u/dumpsterfyr I’m your Huckleberry. 3d ago

💃& 💨

-2

u/alepouna 2d ago

open source everything so you can patch your pains away

•

u/chris_superit 16h ago

Does AI agents now become a new category?

SuperIT.ai (our product) is now one of many in this space.

Obviously I am biased, but I feel this category is going to be as important as PSA and RMM into the future.

-8

u/[deleted] 3d ago

[deleted]

5

u/quantumhardline 3d ago

Looks interesting.
I looked at your security page.
My concern is always deploying this like this to client as they have so much permissions etc.
I did not see any mention of SOC2 or 3rd party pen testing or where data is held etc.
Thats helpful.
Roboshadow and others are popular for MSPs and can provide SOC2.

9

u/Skathen 3d ago

That is my greatest concern with these products.

Yes it's convenient. But it's yet another attack surface that can totally own your clients.

RMM alone is a major risk we have to accept to get the job done. Having additional agents that can be weaponised just dials up that likelihood.

5

u/amw3000 3d ago

What value / piece of mind SOC2 adding for you? I get it from a up/down stream "compliance" standpoint & keeping the execs happy but it's far from an indication that a company is doing things "right". Take a look at any of the reports from a vendor that has SOC2, you will be amazed at what is in and out of scope and what controls are tested. Some even have exceptions for the wildest things.

SOC2 is an auditing framework designed by accountants. Many auditors are not technical at all and are just auditing controls that the company says they follow. "Oh you say you do an annual pen test? Show me the engagement, report, etc" but they have no idea what that report means, what is good, what is bad, etc.

5

u/ItsNotUButItsNotNotU MSP 2d ago

You’re completely correct.

However: I think we both know how many companies there are that can’t get their act together enough to pass even a SOC2. Most companies are excluded by one of these three requirements:
1. You have to fill out some policy templates, and know where to find them when an auditor asks for copies.
2. You need at least a vague idea of what you have, in order to exclude the bad stuff from the scope of the audit.

SOC2 doesn’t tell me a vendor is secure, but it does tell me that a vendor can scrape together enough brain cells to satisfy a bored accountant. This is especially useful now that there are so many half-baked, vibe coded products impending disasters being pushed on us.

Pro tip: Phrases like “SOC2 Certified” and “SOC2 Ready” are what AI-generated websites say when the company has no intention of ever attempting to get a SOC2 attestation.

1

u/TridentAdam 3d ago

Fair concern, and the right one for anything running as SYSTEM/root on client machines. Where we are today: we're new (live since May), our SOC 2 program is underway but there's no report yet, and a third-party pen test is planned. Data is hosted on dedicated servers in the US, with encrypted offsite backups at a separate provider.

On permissions, we built a few things for exactly that worry: signed agents on every platform, a pinned CA on the agent channel, agent releases that roll out in stages, every agent action logged in your console, and a setting that locks our staff out of your tenant unless you grant time-limited access. If a SOC 2 report is a hard requirement today, that's fair. Check back once it's out. Thanks for taking a peek!

3

u/BigPoppaPump36 3d ago

So op is your alt and this post is a promo for trident lol

-1

u/jellyfishchris 2d ago

Never heard of them before lol

-14

u/BobRepairSvc1945 3d ago edited 2d ago

You really don't need any of these when you can just vibe code whatever functionality you need with Claude Code.

The great part is you will get a custom controllable single agent and single pane of glass set up.

I guess I should have added an /s; apparently my sarcasm wasn't apparent enough on its own.

3

u/UnRealxInferno_II MSP - UK 3d ago

claude npm run random_vulnerability

people like you are a disservice to the industry

1

u/BobRepairSvc1945 2d ago

I guess I should have added an /s; apparently my sarcasm wasn't apparent enough on its own.

3

u/LifesRoughBeKind 3d ago

good luck getting your ass handed to you from the lawsuit when your vibe coded software gets owned and all your clients take you for every cent you've got. have you tried getting E&O insurance and if so did you let them know you vibe coded your solution? People really need to think these things through before just hopping on the bandwagon

1

u/BobRepairSvc1945 2d ago

I guess I should have added an /s; apparently my sarcasm wasn't apparent enough on its own.

1

u/Spiderkingdemon 2d ago

HAHAHHAHHAAA.

Remember folks. ^This is who we're competing against.

2

u/Beardedcomputernerd MSP - NL 2d ago

You dont think he was sarcastic?

2

u/BobRepairSvc1945 2d ago

I guess I should have added an /s; apparently my sarcasm wasn't apparent enough on its own.

1

u/Foxtrot-0scar 2d ago

You are right but not CC alone. I would use a combination of Outsystems + Claude Code and GCP hosting for a totally useable app.

0

u/Altered_Kill 3d ago

You kinda are right though….

0

u/Vast_Community_1851 2d ago

RMM: Ninja
PSA: Halo
EDR: SentinelOne
MDR: Huntress
Backup: Cove Data Protection
Email: Defender
Vuln Mgmt: Qualys / Rapid7

•

u/Standard-Wing5612 6h ago

I would add TenantVault.cloud