r/msp • u/jellyfishchris • 12h ago
Cipp
I finally setup CIPP, I know this community loves it. Anyone got any suggestions on best features or things they've setup using it?
r/msp • u/AutoModerator • 2d ago
If you have a self-promotional post - whether it’s a product update, a service offering, or an upcoming webinar - please share it here. Posts made outside this thread will be removed.
⚠️Important: Do not use URL shorteners. Reddit automatically removes these, so always link directly to your website or resource.
🔄️Fairness: This thread is set to contest mode, so comments appear in random order to ensure fair opportunity for everyone.
🛡️Moderation: Reddit may remove some comments. If your post disappears, don’t worry - we check and manually approve them when needed. If you comment doesn't appear in 24 hours, feel free to send a modmail.
r/msp • u/jellyfishchris • 12h ago
I finally setup CIPP, I know this community loves it. Anyone got any suggestions on best features or things they've setup using it?
r/msp • u/ThrowRAthisthingisvl • 5h ago
Hello,
What are you all using to send invoices and collect payments from clients? I've been using Bill[.]com, but I'm interested in looking at other options.
We don't have a PSA yet, so I'm specifically interested in tools that work well on their own. I'd love to hear what's working for you. Thanks!
r/msp • u/ITSpecialist98057 • 1d ago
Does anyone know someone who went out of business mid term with Kaseya? My attorney has no idea what to expect and I'm literally losing sleep over this.
I don't want legal advice, just to know if anyone has/knows someone who has experience with this
r/msp • u/Command007 • 1d ago
Is anyone else using NinjaOne for ticketing with a any reasonable amount of ticket volume (at least several a day) and working with it well?
I find that it's a bit lacking from the standpoint of having eyes on what is there and what is coming in that is new to be acted on.
The dashboards aren't really that helpful and getting notifications of new tickets, aside from Teams integrations, which become noisy, is not very good.
I would just expect a more polished experience and better alerting on tickets.
If you're using NinjaOne for ticketing, how does it work for you?
I think the RMM is great, and managing the tickets inside the ticket itself once you're in there seems fine overall.
r/msp • u/Zealousideal-Ice123 • 1d ago
Hi, we have a nursing home client that has Keri key fobs for their security doors and separately uses Yubikey usb devices for their PCs for M365, etc. They also already all wear ID Badges that we print. I know we can consolidate the Keri fobs into Keri Badge Cards. My question is, is there FIDO2 badge cards we can buy that support both that and the Keri security doors? The doors are just RFID(We do not manage the doors). We want to be able to still print the employees name and image on them still for identification purposes. Wondering what people use in these situations so there’s not 2 and 3 separate things to worry about having on their person. Thanks!
r/msp • u/ITGuyB3n • 1d ago
We're looking to switch away from ITGlue, the searching is awful, this cooper copilot AI is a joke and network glue was terrible too. It doesn't look like Kaseya is trying to improve on this product at all.
I did a demo of Lexful, lexful.ai and it looks promising. I guess the original creator of ITglue made it and it just launched, with an easy migration path from ITGlue.
I've heard good things about Hudu too and they seem to be pretty good as far as cost goes. Lexful is a bit high up there, even more than ITGlue, which seems a little crazy to me to start up like that, but I guess you got to get your startup costs from somewhere.
Has anyone switched to Lexful or other AI documentation platforms? Does Hudu have an AI integration, is it any good? We're currently leaning more towards switching to Hudu, mostly due to cost but don't want that to be the only deciding factor if I can help it.
r/msp • u/SigmaStroud • 2d ago
We're a small MSP with 2 techs in the Western PA area and looking to acquire our first large client. We're confident in our stack and solutions, and confident in what we can provide for them, but I'm not too confident in the pricing as I've not quoted at this scale quite yet. I'd rather not fumble and overshoot as we've been promised that we have their business if our prices can be competitive.
They have a local location and a southern US out-of-state location that will be serviced with about 100 endpoints.
Our current tier has them at $160/device which will include:
Then an extra 225/server/month but includes backup (to a reasonable extent data wise)
I feel like there's a lot included in that $160/device/month. Is this a reasonable ask? Or am I pricing myself out of a deal?
r/msp • u/whitedragon551 • 2d ago
Were making the move everyone has over the last year or 2. We have been on Connectwise since the company was started over 20 years ago. We want to move. We are sick of buying addons to do things the PSA should already do. We have done a lot of demos and evaluations. We have made the decision to move to Halo.
We are going to use a consultant to do the work, but we havent picked one yet. I want to hear about the consultant you picked, who was it, would you reuse them again? Likes and dislikes about the one you used.
I want a big wall screen showing several important dashboards at once - new tickets, call queues, network/device uptime, backup status etc.
I have dashboards for each of these things, but they are all in different applications and I want to consolidate them.
This is easy enough to do just by snapping the windows to a grid on an external monitor, but i also want to be able to save this configuration so i could pull it up on a laptop, or potentially share it with other staff that need that visibility. A bonus would be able to specify a refresh time on some of the windows as a couple are static.
These are authenticated dashboards, so anything iframe-based tends to break on X-Frame-Options / login sessions.
Does something like this exist? Anything self hosted or open-source? I found OneWebView but its closed source and I won't trust it with this sort of data.
r/msp • u/joe210565 • 2d ago
Hi MSP community,
just wanted to see what you use to manage all your tenants ?
I am looking one pan of glass for M365 and Azure.
Would you suggest lighthouse or something else?
We have a medical client that works in a place where all doctors are part owners, and they all have a shared 365 tenant. There has been a decision made to close that down and everyone has to sort out their own email addresses.
We are migrating 5 addresses out of this tenant for the 5 staff we support (out of the 100ish emails on the tenant). The current IT provider will not provide any access or support.
Most of these email boxes have 60GB+ of email, so using Outlook to create a PST is not an option/not reliable enough.
Anyone have any other ideas ? They're just individual mailboxes with mail/calendar/contacts/small amount of OneDrive and no Teams use.
r/msp • u/mcwiggin • 3d ago
I tend to deal with lots of Windows machines. It's crazy Windows can't even let you put the hostname as part of the login screen. I made a tool modifies your login screen background to show info like Hostname, IP and service status. It's really handy if you are looking at backups or are just connecting remotely.
https://github.com/amcchord/WallpaperIdentity/releases
For clarities sake. I am aware of bgInfo. The challenge is I want to run it at login screen not the desktop (bgInfo just gets cached in a windows 10+ world). Secondly I want the background to refresh before login.
r/msp • u/Sbmizzou • 4d ago
We are a 28 person law firm (50/50 mix of attorneys and staff). We have been the recent victims of various scams. Zero response from our MSP other than "...we have done scan, and don't see anything critical...."
We are in Southern California. We have two offices and use an online case management software, we also outlook, One Drive, etc.
We have had various issues that have gotten to a critical point. I have had the same IT consultants for over 10 years.
The current IT consultants are able to remote onto the various computers and trouble shoot. When we buy new equipment, they typically deliver it and get it up and running. They also have a "help" desk that we can request info to.
I don't necessarily need someone to set up the computers. The focus is on cyber security, recommended clouded services/protections, and troubleshooting.
Thanks.
edit: thanks for everyone's response. we have enough referrals.
I thought this might be an interesting question for the community.
I feel like the ground is shifting from underneath me at an increasingly alarming rate, and the market feels more crowded than ever, so my question is: In an increasingly crowded and volatile space where it’s hard for a two-person MSP to differentiate themselves from a 50 person MSP, what are you doing in your business to stand out?
My personal opinion is the MSP market has always felt a bit crowded and it’s always been hard to stand out. In the past five or so years, it’s felt like there’s also been a huge shift towards commoditisation and I think its evidenced by the amount of MSP gurus popping up, which always makes me think of people selling shovels during the gold rush.
I don’t have an AI generated bridge to sell you, and I promise you that sharing your uniqueness isn’t an instant path to someone copying your services.
We, ourselves, are an MSP in Collingwood, Melbourne (Australia). As an example of uniqueness (kinda) for us is we have very much moved with some of the more mature players in our local market to start promoting alignment with commonly discussed cyber frameworks as a way to show credibility.
This might sound obvious to some people, but the bar is often so low that this is genuinely a unique angle that a lot of prospects I speak with are interested in.
There are a few others doing this, but not the vast majority. Another example is we developed a local HR/IT policy pack for clients (in conjunction with a local HR firm) that aligns with the changes in the frameworks, to help provide a more complete and rounded service to SMEs. Things like a well rounded BYOD, AI and Cybersecurity policy.
I don’t think this is completely unique, but it’s at least something other than “we’re a security first MSP”, “Wait, we’re actually an MSSP (it’s different somehow), or, “We answer the phone in 30 seconds or less”.
Other things I’ve seen in the market are:
r/msp • u/vetian12 • 5d ago
We recently acquired a new client. We're trying to get them set up the same way as all of our other clients and part of that is through PAX8.
We opened a client transfer request and got it kicked back with the following:
"There seems to be an issue on the releasing partner that they haven't settled their bill with us. Unfortunately, we cannot proceed with the migration until the releasing partner is able to settle their balance.
If you have any contact with them, please do let them know to coordinate with our collections team [[email protected]](mailto:[email protected]) for them to settle their balance. Thanks!"
After some back and forth as well as him checking with colleagues and specialists on this he came back with this response:
"Since the client is not bill on behalf on our side, they should be coordinating with their current MSP to settle their bill if there is any. It is an issue with the whole MSP and their clients at this point. We are unaware of the situation and they must settle the situation with their current MSP for us to proceed. Thanks!"
Is this normal for PAX8? What about other companies like Sherweb?
Is it time for us to finally pull the trigger on moving away from PAX8? This is the first time we've had any real issue.
EDIT: Since there seems to be some confusion. The client has paid all bills. The outgoing MSP has already confirmed this. As far as I can tell, this is an issue between the MSP and PAX8. They will not tell us whether the issue is directly related to the client or not.
r/msp • u/terselated • 5d ago
I have a local competitor who offices right down the street from our office. Bigger MSP than us, fairly mature, we've had a few clients off board from them to us. But we have never met up or talked shop or anything like that.
We did a deployment on a client that moved from them to us and the first night our MDR team notified us of a threat on one of the PCs. Confirmed that the previous MSPs tools had been on the machine in question, including their security stack (I won't bad mouth which one), and the issue was not caught prior to changing to our stack.
My question is do I reach out to the competitor and let them know about it? That potentially their MDR/EDR is missing things. Do I keep it to myself in the hopes that it leads to more clients jumping ship? I feel like professional courtesy dictates that I let them know. What would you do and how would you start a conversation like that?
Here is the MDR alert (sanitized).
Hi Team,
Security Incident Report — DESKTOP-*********
Date: July 17, 2026
Severity: Critical
Status: Mitigated — Further action recommended
---
We are reaching out to inform you of a critical security incident detected on one of your endpoints that required manual intervention by our MDR team and may need further action on your side
to fully resolve.
Summary
On July 17, 2026 at 00:28 UTC, our Managed Detection and Response (MDR) team identified a malicious Python-based implant executing on the endpoint DESKTOP-*********. The threat was initially detected by SentinelOne's EDR engine with a "suspicious" confidence level, which means the agent flagged the activity but did not automatically remediate it. Our MDR team reviewed the detection, confirmed it as malicious, and manually initiated full mitigation (kill, quarantine, remediation, and rollback).
What Happened
A malicious file disguised as image.png was executed from a hidden persistence directory (C:\Users\*******\AppData\Roaming\Microsoft\WindowsUpdate\). This directory mimics a legitimate Windows path but is not used by genuine Windows Update processes. Upon execution, the malware:
Masqueraded as a legitimate Windows process (svchost.exe)
Established a command-and-control (C2) connection to an external IP address (176.125.243[.]136) on port 56001
Performed process injection into multiple running applications over a 43-minute window, including browsers (Edge, Chrome), productivity software (Excel, Slack, Acrobat), and the SentinelOne security agent itself
Why Automatic Remediation Did Not Occur
SentinelOne classifies detections with a confidence level — either "malicious" or "suspicious." Only detections classified as "malicious" are automatically mitigated by the agent. In this case, the behavioral detection was classified as "suspicious," so the agent alerted on the activity but waited for analyst review before taking action. Our MDR team confirmed the threat and manually triggered full remediation.
Response Actions Taken
- The threat was detected and flagged by SentinelOne EDR
- Our MDR team confirmed the detection as a true positive
- A full mitigation was manually executed: the malicious process was killed, the file was quarantined, and system changes were rolled back
- The C2 IP address 176.125.243[.]136 has been identified for network-level blocking
Recommended Actions
Network isolation of DESKTOP-********* until a full forensic review is completed, to prevent further C2 communication in the event of re-execution
Full forensic sweep of the endpoint to identify and remove any remaining persistence mechanisms, particularly within the C:\Users\*******\ user profile
Review the "*******" local user account — this account was used to stage the malware and may have been created by the attacker. If it is not a recognized account, it should be disabled and removed
Block C2 IP 176.125.243[.]136 at the firewall/network perimeter level
Review network logs for any other endpoints that may have communicated with 176.125.243[.]136
Please let us know if you would like to proceed with network isolation or if you have any questions.
Guardz MDR Team
r/msp • u/jackmusick • 5d ago
Hi everyone,
We’re a small-ish MSP, around 17 staff and 4MM in yearly revenue. I’m overdue for a peer group. Anything people like outside of the Pax8 ones (I think previously this was SeaLevel?)
Truthfully I was hoping for an active channel on MSPGeek, but I don’t think there is one. I’ve also tried TechTribe but feel we grew out of it unfortunately.
Really just looking for occasional gut checks from people in a similar place. I’ve posted her occasionally, but I’m not always looking for mixed feedback from techs and others if that makes sense.
r/msp • u/statitica • 5d ago
As the title might suggest to the observant reader, we have recently applied to become a Cloudflare partner. According to their forms, it takes around 3 weeks to hear anything back. So we waited 3 weeks. And then gave them another 2 weeks just in case.
And... crickets.
No rejection email. No approval email. Not even a "we received your application" email.
Is this par for the course with Cloudflare, or am I holding it wrong?
r/msp • u/nostradx • 6d ago
I'm curious whether anyone has come across a vendor working on this. I'm looking for an AI-driven solution that can ingest and correlate data from multiple systems and communication channels in near real time, including:
PSA/ticketing
RMM
VoIP calls
Cell calls
SMS/text messages
E-mail
Microsoft Teams
Internal documentation
For example, if a technician discusses an issue via phone, follows up in Teams, exchanges emails with the client, works a ticket in the PSA, and makes configuration changes through the RMM, the platform would correlate all of those interactions into a single documented record.
I'm aware of AI note-taking tools, conversation intelligence platforms, and documentation products, but I'm specifically interested in a solution that acts as a cross-platform knowledge aggregation and documentation engine.
Edit with additional thoughts:
Taking it a step further, I'd love to see a solution that can observe and summarize actual technician work. For example, during a ScreenConnect session the AI could capture actions performed, identify troubleshooting steps attempted, and document the eventual resolution.
Example:
User reports Outlook crashing
Tech reviews event viewer and Office logs
Runs Office repair
Tests a new Outlook profile
Ultimately resolves the issue by modifying a specific registry key
The AI would automatically document:
Steps attempted
Commands executed
Configuration changes made
Registry keys modified
Root cause identified
Final resolution
Ideally it would then update internal documentation and create a reusable knowledge base article without requiring the technician to write it manually.
So I guess my updated question would be: Is anyone trying to build the "digital memory" for an MSP, where every conversation, ticket update, remote session, script execution, and configuration change becomes searchable organizational knowledge automatically?
r/msp • u/toplessflamingo • 6d ago
Need a pax8 escalation contact. Account rep is MIA. If anyone has one Please DM me
r/msp • u/ThrowRAthisthingisvl • 6d ago
Hello,
I came across this "MXDR" solution from SonicWall a few weeks ago and I wanted to ask this group for feedback. I haven't seen a demo or anything yet, but I'm curious. Yay or Nay?
r/msp • u/gumbo1999 • 6d ago
Has anyone managed to get this working and do anything useful with it?
I've managed to get an Copilot Agent connected to CIPP, but it's incredibly slow and frequently fails to answer questions because Copilot hits the 70 tool limit - this is despite me creating a separate/scoped connection for each CIPP tool set.
Beyond setting the API in Azure, there's not much info or direction coming from CIPP themselves.
I've spent a fair bit of time fumbling around trying the get it working and I'm getting to the point where I'm questioning if it's worth the toil.
r/msp • u/cokebottle22 • 6d ago
I was logging in to CW Home this am and noticed that the version of CW that I use is now called "classic". The version under it is called the "Platform". Now, I admit to not paying too much attention to this - I just click on the top one.
Has anyone used the "Platform"? Is this Asio? I've got so much crap integrated with "Classic" I really don't want to migrate....If there is a deadline for classic, I'd have to evaluate all the other platforms.....
Hey everyone
Like many of you, we’re using tools like Augmentt and LCI to manage our M365 clients’ security.
A few of our clients are in GWS, but they’re around five users each so we’re not doing formal security benchmarking for them anyway.
However, we have one GWS client that’s large and growing, so we need to formalize our security benchmarking and reporting but it seems that no vendor cares to build out their platform to include GWS.
What are you all using?
Thanks!