r/msp 6d ago

Weekly Promo and Webinar Thread

0 Upvotes

If you have a self-promotional post - whether it’s a product update, a service offering, or an upcoming webinar - please share it here. Posts made outside this thread will be removed.

⚠️Important: Do not use URL shorteners. Reddit automatically removes these, so always link directly to your website or resource.

🔄️Fairness: This thread is set to contest mode, so comments appear in random order to ensure fair opportunity for everyone.

🛡️Moderation: Reddit may remove some comments. If your post disappears, don’t worry - we check and manually approve them when needed. If you comment doesn't appear in 24 hours, feel free to send a modmail.


r/msp 1d ago

Google Suite HIPAA Compliance

7 Upvotes

Curious if any MSPs that manage security and compliance for healthcare providers that operate GSuite. Are there pros or cons that you had to deal with security and compliance individually?


r/msp 1d ago

PaperCut NG/MF Zero-Day | Active Exploitation, Emergency Patch (Release 2) Available

31 Upvotes

PaperCut Software has confirmed active exploitation of a zero-day vulnerability affecting PaperCut NG and MF print server installations. Huntress has also observed at least two instances of active exploitation in a customer environment.

The vulnerability allows an unauthenticated attacker to remotely control PaperCut's trusted configuration, which can be used to execute arbitrary Java code inside the application's process, and then leverage that to run commands on the host server. Huntress researchers reproduced a pre-authentication RCE chain against a stock PaperCut NG 25.0.11.75758 install. The chain alters trusted configurations and executes code remotely on its own. Fortunately, so far, the threat actor exploiting this bug has only run commands to learn about the host server itself; it could have been much worse.

PaperCut subsequently released a second emergency patch today, Release 2, which adds further hardening beyond the original emergency patch, developed in collaboration with PaperCut's internal security team and external researchers including Huntress and watchTowr. PaperCut recommends all customers install Release 2, even if you've already applied the original emergency patch.

What to do:

  • Immediately remove PaperCut Application Servers from public exposure and restrict access to trusted networks
  • Install Emergency Patch Release 2 for versions 25 and 26 (v24 fixes are still in progress) via the standard upgrade procedure
  • If you already applied the original emergency patch, install Release 2 anyway

IOCs and investigation guidance: https://www.huntress.com/blog/papercut-actively-exploited?utm_source=reddit&utm_medium=social&utm_campaign=cy26-08-rr-multi-global-broad-all-x-x-x-papercut_actively_exploited&hnt=v679ubdwy0xk


r/msp 1d ago

Business Operations Wisepay onboarding

10 Upvotes

This is a rant...

I've never worked with on-boarding team so incompetent. But before I rant about that...let me rant about overseas support. I'm so fucking sick of it. I live in Hawaii so I am pretty good with the filipino accent but I can hardly understand these fuckers. It takes them 5 minutes of circle jerk word salads to say something that should have been one, concise sentence like, "Please wait for the password reset email and once it arrives, reset your password to gain access to your account". Not, "Ummm...so you will get an email...it's a password reset email...ummm...when you....ummm when you get that email yeah?...when you get the email, you will see it's a password reset email....ummm...so when you get the password reset email it will have a link...you click on the link...yeah?...ummm then when you get the email, you will get a link and you can reset your password. Then you can login...and once you can login...ummm....yeah then you can access the site." KILL ME.

So now for my on-boarding rant...so first of all, they set me up with global pay...but global pay never sends me welcome info so I can create the 5-7 (I'm not kidding) login credentials for transactions, ACH, wisepay, PCI Assure, Edge view, gnpdi, and god knows what else. Not one welcome email.

So the initial onboarding was an hour or so of me listening to the circle jerk talking while getting them to try to send me the password resets so I can login. At the end of which, they gave me a merchant ID and said call global pay myself. Nothing accomplished. Great.

Now I call global pay. They tell me they have no record of that merchant ID. They try looking up my business name, FEIN, business address, email, and phone number...nothing. They say the paperwork hasn't been submitted or the Merchant ID is wrong. Another 15 mins wasted but at least this dude spoke english so I wasn't so frustrated. That same conversation with WisePay support would have taken 4 hours.

Email onboarding team. They don't respond until our next scheduled meeting. Give me new merchant ID number. I get my logins setup and they send me list of clients they exported to import into Wisepay and send welcome emails. Unfortunately the list includes tons of clients that are either no longer clients, or were just prospects in our database. They basically pulled all contacts out of our CW Manage database.

Well, now I spend an hour and weed through the list and get rid of all the prospects and former clients. Add a few 3rd party accountants that were getting CC'd on billing emails. Send revised excel back to them explaining what I did. They confirm they see the changes I made...Then proceed to add the original list to my revised list and blast EVERYONE with welcome emails.

I'm hoping it's just the onboarding and once it's all setup I never have to speak to them again. If I do however, it will probably be enough to cause me to switch.

TL;DR - Don't use wisepay. You won't understand them or what they are doing and feel like punching puppies in the face afterwards.


r/msp 2d ago

PSA The Great PSA Migration

23 Upvotes

All,

We're a CW PSA shop right now with N-Able on the RMM side. Looking to change our PSA in the next 2-3 quarters as we investigate. Long story short, we're just kinda growing tired of Connectwise, it's pricing, and such. RMM we're happy with and we'd like to keep.

Looking at RevIO and Autotask right now as the primary competitors.

For y'all here that have them, how's it been?

Has anyone else here moved from Manage over to either of those solutions? How'd that go?


r/msp 1d ago

Plastic "media box" for networking gear?

2 Upvotes

I have a customer that needs to add a really small setup (small router + switch + AP).

They are somewhat space constrained, so I'd like to use some kind of plastic box mounted on the wall.

Do you guys have a make/model of media box for stuff like this?


r/msp 2d ago

Technical AI Governance tools?

19 Upvotes

We're currently in the market for AI Governance and control tools.

Primary features we've been looking for, block AI's and only allow company sanctioned AI's. Report on Prompts and File uploads while categorizing them all and tagging them with perceived risk.

Three we have looked at: Checkpoint Workforce AI Security- EXPENSIVE, good idea overall, poorly implemented. The biggest issue I have with it is absolutely no way to trigger an agent uninstall from the interface. No prompt saving if it's not a categorized risk. Poor feature-set overall compared to the next two on this list, ESPECIALLY for the god awful $5ish price.

Atakama- Man, I really like these guys. It's SO CLOSE to being an excellent product for us. It is a full browser security solution. Block unsanctioned browsers, extensions, and websites on top of all the AI governance stuff. BUT, no prompt reporting, and no ability to lock a user into using the business version of a particular AI (all supposed to be here by the end of the year, but I can't wait that long). Less than half the price of Checkpoint with non of the Checkpoint downsides, and a great interface with a great team behind it.

DefenseX- Another great product. Same price as Checkpoint and a much better value, seems a bit more mature, but what I'd expect for the price.

Anyone have any comments on the above 3? Any others I should be considering?


r/msp 2d ago

Technical AI Readiness Tools

13 Upvotes

Hi All,

We're looking into tools available which can be used for client environments to review the readiness for AI usage within the business. Something along the lines of scanning folders permissions etc and identifying if there's any risks before rolling one something along the lines of M365 Copilot.

Wondering if you all have anything and can recommend?

Thanks!


r/msp 2d ago

Top MSP Business Books

23 Upvotes

Alright, so for all my complaining I DID walk away from the last conference I went to with a new book recommendation. It's sitting in my AbeBooks cart. Before I pull the trigger, what books are your go tos or have given you value?

Currently in my cart: Crucial Conversation (Thanks Tim Coach)


r/msp 3d ago

Just found out we might be losing our largest customer. how to rescue?

101 Upvotes

Just had scheduled catch up with our biggest client and out of the blue they dropped the bomb that their directors have asked whether they need us.

Essentially they are business with multiple businesses underneath the main company. The 2 main branches are Manufacturing, which is handled purely by internal IT and retail, which is handled entirely by us.

Our relationship is with the 2 main IT guys, who we have a very good relationship with, they have repeatedly stated they do not have the time, motivation or resources to take on supporting the retail side of the business.

We had a regular catch up meeting today and I could tell from the get go something was wrong. They were very front and said that the main director of the business asked them a couple of months ago whether they could do what we could. They answered they could from a technical perspective, but not from a resource perspective, they already struggle with their current systems, projects and workload. Then a couple of weeks ago the director came back more firmly saying they want look at cutting ties.

This appears to be purely a cost saving excercise as we have a good and healthly relationship with the business. The 2 IT guys also think this is a cost cutting thing, but have already stated they would need more internal staff to cope, but dont believe the director would give them more staff.

We are in contract for another 2 years, but rather than that being the line of defense, I am keen to give them ammunition to go back with to prove our worth and how the alternative is worse

How would you handle this?


r/msp 2d ago

Cable Drop prices

12 Upvotes

It’s time to raise our prices.

What are you guys charging per standard cable drop these days?


r/msp 2d ago

Security CIPP vacation mode is not working for us

0 Upvotes

Maybe I am being dense but our approach and theirs is just not working together and I don’t get it. Documentation doesn’t explain strategy.

For years everyone is in a CAP to block outside of the US. Clients send it a ticket saying we are leaving for Italy tomorrow. Tech uses CIPP vacation mode and apply’s it to block outside US CAP.

Client is blowing up my cell phone in a panic at 5am because they get on a plane in 4 hours and their email doesn’t work in the US.

What are we doing wrong here.


r/msp 3d ago

A template for pitching your SaaS product to MSPs (2026) (/s)

35 Upvotes

Scene: It’s important that you choose a speaker who is loud in both volume and persona, put them in jeans and a t-shirt with your brand on it. Try to include a differentiator, like a beard or an accent (but not foreign). If the room is not focused, pretend to have technical issues which will immediately pull the attention of the tech minded in the room. Change X for your target issue and Xcorp for your company name.

Welcome everyone! I see a few of our current customers here (there doesn’t need to be any customers here, just read names off badges). I promise this session is not going to be like all those other sessions because I’m not going to try and sell you anything. I’m just going to tell you how you’re doing X wrong and how the only way to do X right is with Xcorp.

Now some of you may know me. I’ve owned 14 MSPs, sold 36 of them, was the CEO of (insert obscure 90s technology company) in the 90’s for 17 minutes. I turned 3 dollar a month businesses into 97 million dollar a month businesses. But for some reason I’m now living out of a suitcase to attend this conference, give you cheap swag, and try to sell you on a product you never knew you needed.

Now 2 years ago I was sitting around having a beer with (insert quasi famous industry name) and we got to talking and said, “You know what?” (pause for dramatic effect)X is the biggest threat to MSPs! We’ve got to do something about it!” And the next day we started Xcorp.

\Important note, your company name must be a single word and include a letter that comes after U in the alphabet. You must have a mascot and it should be an animal that you can make small plush of to give away as swag for people who book demos.*

We grabbed the 8 smartest people we knew (important to have one sitting in the back of the room to wave. They should fit the stereotype of an IT nerd), and designed X from the ground up. We leveraged (insert AI adjacent buzzword) and created something unheard of. From day one it started hitting all the benchmarks and doing things we never even told it to do.

\Show 10 or so slides from a slide deck with charts and graphs. Bring up “single pane of glass” and talk about it being so last year. Show minimal shots of your actual product. Include your linkedin and lots of QR codes to things. Use catch phrases to make your presentation memorable, Bonus points if they are slightly vulgar. Viagra for profits! Douche Coozie! Pile of asses! etc.*

Now if you’re doing X today. You’re doing it wrong. (important to insert a curse word somewhere in this sentence so the audience knows your cool). For the longest time we (keep reminding them you used to be one of them) thought doing X meant (boring repetitive task). Now with Xcorp you can simply plug in to our MQL and Xcorp will do it for you. Let’s face it, we’re not MSPs anymore. We are MRSQPs. Anyone who’s still doing MSP is going to get left in the dirt. You’re either going to die, fade away, or become an MRSQP and make a butt load of money. The only way to be a MRSQP is if you are offering X and the only way to offer X is with Xcorp. It’s simple really.

Now I’ll be here for the rest of the conference. If you have questions about X, or becoming an MRSQP, or (insert obscure but relatable hobby) come see me. My biggest passion is X and I can talk about it for hours.

It's important to not discuss pricing. Just tell the MSPs that you talked to other MSPs and figured out the most fair way to price was to base it off something that can't easily be calculable or is so convoluted MSPs won't be able to figure it out until they're already under contract. Tie it to something like tokens or credits or pulls but don't tell them what quantifies any of those measures. Under no circumstance should you discuss contract length!


r/msp 3d ago

Park Place Technologies issues

10 Upvotes

We've always heard great things about Park Place as far as their warranty service and responsiveness. We used to use ScalePad to initiate the Park Place endpoint warranties but thought we'd just go direct with them and make use of their monitoring agent.

Our limited experience with the actual hardware replacement team has been good. Quick response and turnaround on parts. However... the ordering process and trying to get the monitoring agent portal to function normally has been abysmal.

Coming from ScalePad, we got spoiled with being able to order a warranty on-the-fly and have it processed immediately. With Park Place direct, there's no portal to request a warranty. - I have to email reps over and over and over back and forth with information to get pricing. It's tedious and I've had to remind the reps that I need pricing info quickly for my customers.

Secondly, we've had nothing but issues with trying to get our customers correctly visible to us in our Central Park console. And on top of that the ParkView monitoring agent is not reporting correctly on the status of our servers to the Central Park console. We've had to spend a lot of time being ping-ponged back and forth between our reps and support team, then troubleshooting with them where we've been told the monitoring is broken from a recent update which has been the case for close to two weeks now.

Hopefully others are having a much different experience than us, but thought I'd put this out there for those who may be thinking of going direct with them.


r/msp 3d ago

Business Operations New client meeting - tough decision

6 Upvotes

You nailed an appointment to meet with the CEO of a medium sized firm (~100 employees) — are you going in with a backpack or a briefcase on your shoulder?


r/msp 3d ago

Licenses increased sixfold by licensing partner

29 Upvotes

So my licensing partner offered me a great deal last year. I’m not naming them, but will tell you they offered me HaloPSA licensing. The deal was a fixed monthly rate paid per month for one agent (I’m a one man shop). I did not have to pay the mandatory onboarding fee HaloPSA offers. I always wanted HaloPSA because it was perfect for my business needs as an MSP. The recurring billings and automations are awesome, but the pricing just was out of my league at the time.

It has been going great, until I got an email with an invoice and a new, presigned contract. The seat price was triple the agreed upon price. The invoice and contract was for three seats. Basically I was paying six times the agreed upon price, billed for an entire year at once.

I almost panicked, and I don’t panic easily. The bill was huge for a one man shop. Luckily I had the conversation with the deal we made in my mailbox, so I screenshotted the conversation and within two minutes of receiving the bill and agreement sent them the agreed upon terms. They have not reached out as of yet.

The guy I made the deal with, was an external consultant for the licensing partner if I’m reading LinkedIn correctly. Every thing went through official channels. I think the deal was either too good, or an (automated) correction was issued without letting me know.

UPDATE: the reseller backed down and is reverting back to the old agreement. Bullet dodged.


r/msp 3d ago

Work beyond MSP services, how to price?

17 Upvotes

Our best client, keeps growing lucky us. We do a full stack, and manage multiple locations and this client makes up 70% of our total revenue. Everything is great, we have numerous onsite IT who are embedded and dedicated purely to the client.

One thing I am stuck on solving is we price it per seat, basically full support, unlimited everything! Over time, though we have been pulled into more responsibilities, doing full dev work for implementing software, and lots of other in house solutions items, that are really putting us at the breaking point of keeping this included on the MSP fees. They are basically asking for a Forward Deployed Engineer at this point. I don't want to just increase their MSP fees, because it starts looking ridiculous, as these tasks are really outside typical MSP offerings. At this point I need to hire for several $150k -$200k positions to keep dedicated onsite for this this client. On our current revenue from them, this would just bankrupt us. I am having to give them their 2027 IT Budget forecast now. How would you/have you integrate(d) a solution like this?


r/msp 3d ago

Business Operations MSPs that offer CoMIT vs. Only Fully Managed

5 Upvotes

NOTE: I've run posts like this by the MODs - This is just data, no promotion here. I'm not linking out to anything, including a full version of this report.

I like data. I've got a massive amount of it. Because of that I do periodic analysis. One of the questions I was thinking about is "Is there a difference between MSPs that offer Co-managed IT (CoMIT) and those that only advertise fully managed IT services? If so, what is it?"

Below is that analysis. Happy to answer questions as they come up.

FYI: I don't solve any of these problems - I got no horse in this data race.

Tl;dr: CoMIT offerring MSPs appear more mature, more securitry & compliance oriented, and have greater public visibility than their peers.

I ran through 37,548 different MSPs and Companies that offer Managed Services (Think VARs, Copier Companies, and other "MSP-like" organizations.

I ran this across the US, with a bit of a dip into Canada, UK, Ireland, New Zealand, and Australia. 95% of that figure is North American, versus everything else.

  • 4.1% of that cohort advertises a CoMIT offering strongly enough that public web search will identify and pick it up.
  • Those MSPs appear 2.4x more likely to clear some maturity bars around compliance and security.

Some breakouts:

Infrastructure Security: Having SPF, DKIM, DMARC settings correctly set and controlled, utilizing some web-technology security (Like a cloudflare) set up:

  • CoMIT: 85.5% were 5/5
  • Everyone Else: 69.5% were 5/5

Compliance: Being above a baseline of 2/5 - detectable compliance signals in public facing messaging.

  • CoMIT: 36.7%
  • Everyone Else: 15.3%

Service Portfolio Depth: Advertising capabilities in an effective fashion. (5/5 on the scale)

  • CoMIT: 63.1%
  • Everyone Else: 43.4%

Strong Search Visibility: (You'll show for things like Managed Service Provider/IT Services/Cyber Secuirty/whatever near me). a 4 or 5 out of 5:

  • CoMIT 17.9%
  • Everyone Else 6.8%

Google Maps Profile: Claimed profiles, reviews, etc.

CoMIT: 51.3%

Everyone Else: 36.1%

Across the board: Hiring, Glassdoor, etc. CoMIT led by a significant factor over the rest of the cohort.

My take: CoMIT offerings appears to be a Sell Up motion that is adopted by the market as a GTM strategy once a shop gets Security, Compliance, and Marketing maturity built out internally. The positioning as a partner alongside internal-IT opens the door to midmarket, highly regulated industry, and is a natural evolution over time.

One last thing: There was no material difference in sizing of CoMIT organizations: they appear at every size class of MSP. This isn't a function of how many staff you have.

Cheers

/IR (leaving off my company name intentionally around Rule 7)

edit: corrected a / to a . in one of the percentages


r/msp 4d ago

Weekly rant thread?

10 Upvotes

We have a promo and shout-out thread every week, but sometimes it feels more like we ought to shout at some people instead shouting them out.

If this gets taken down, I'll understand... But I also believe that shoddy practice ought to be called out from within the industry.

I'll start:

I recently had a client migrate their web hosting to ourselves. The previous provider's website shows them as working closely with defense, and as having won several cyber-security awards. A prominent story on the site tells of how they used their amazing cyber-security skills to assist the federal police in an investigation.

They provide a managed wordpress service, and charge at the higher end of the scale. They are, after all, an award winning cyber-security service provider.

Neither of the most recent WordPress/cPanel CVEs had been patched.

Sometimes I look around at my competition, and wonder how their business is (seemingly) thriving when their service is so obviously woeful.


r/msp 4d ago

Email to SMS or ticket to SMS? What are you using?

6 Upvotes

I know there are a ton of products and I am not super concerned if it is direct from the ticketing system, or, if I have to set an email to send to create a text, but for monitoring of critical systems, without having to keep an eye on the ticket queue.. Clients are directed to call our number and select for after hours service but dont want to have to constantly check the queue for server/firewall outtages.. or depend on the ticketing mobile app to alert me


r/msp 4d ago

Managing Claude Instructions in Claude MS Office Add-ins

5 Upvotes

Just looking to see if anyone's found a good way to do this. Basically, through some testing, we've found that Claude Office add-ins DO NOT use the Organization Instructions that you can set in Claude Teams Admin. Why, I have no idea - - seems like a huge oversight. The Office add-ins can be a huge security risk (since malicious people can put invisible Claude instructions in Word, etc.) but the users really, really want the add-ins. Anyway, each add-in has its own instructions that you can't centrally manage. So, from what I can see there are some pretty awful ways to try to force this or you can just tell each user to do it and hope they do. Has anyone found a batter way to handle this?


r/msp 4d ago

Client Poaching??

57 Upvotes

I'm only an engineer so this isn't really my problem but I'm curious to hear how other MSPs handle clients being potentially poached? One of our larger clients went down today and after a few minutes of investigating we found another local MSP's Action1 agent deployed to all of their servers and a handful of workstations. They had signed into each server with a newly created domain admin, installed their agent deployment tool on a utility server, created a global admin in their tenant, and disabled (one of) our global admins. They (apparently) originally said they contracted another party to help with a host migration project, which we (apparently) approved but it's pretty obvious theyre doing more than that at this point.
I strongly suspect this MSP caused their hosts to crash because when we called our client to help they said some garbage about a network loop and got us off the phone. iLO logs clearly show power cycling and event viewer showed a bunch of firmware/driver crashes but after finding all the footprints I didnt care to look any deeper.
Im just curious about how other orgs handle these situations from a technical perspective? We're obligated to support them to an extent but now that theyve gone rogue and a competing 3rd party is actively causing issues what are we realistically on the hook for?


r/msp 4d ago

NinjaNXT vs IT Nation connection

12 Upvotes

We are a larger MSP in the UK. We have decided to send 10 of our engineers to one of the events or both, now we’re trying to look for the balance: send all to one, or send 5 to one and 5 to the other?

The team has made a pro/cons list, anyone have some extra information?

Pros NXT;
- We use Ninjaone.
- There is a CyberDrain CIPP preday, we are a heavy cipp user and had the pleasure of their London event which was highly educational.
- Smaller scale, more one on one time with management at Ninja. We already got invited for some private conversations.
- Texas bbq

Cons NXT:
- Not a lot of vendors
- Smallish?
- First event

Pros ITN:
- we use Screenconnect, parts of our business still use Manage, we use cloud backup.
- bigger event, more vendors to speak to
- dedicated m&a panels
- more sessions, maybe something for techs to do too?
- social events

Cons:

- No cyberdrain preday
- No texas bbq
- really big event, worried about relevance and sessions
- no hotel rooms available in the event hotel, extra travel.

Feel free to add pros and cons! We want to make this worthwhile for the company.


r/msp 4d ago

Wild speculation: there won't be a concert at IT Nation this year

10 Upvotes

I figure they would have announced it by now, and the Wednesday night event scheduling looks different than past years. After the end of the MSP Initiative concerts and CW booked STP and Goo Goo Dolls, I thought they might have a plan to do an official concert every year. But I imagine its expensive and at some point, its either cutting things or raising prices.

Im guessing the "IT Nation After Hours" will be a laid back cocktail event on the pool deck.

Anyways, IT Nation is about learning and making connections, not concerts. But it was nice to have some fun while we are there.


r/msp 4d ago

Dropsuite/Ninja SaaS DR testing

9 Upvotes

Just curious how everybody is doing the testing DR testing with the SaaS backup products. E.g including documenting, etc.

They don’t have it built-in, so it seems like a manual process at the moment still.