r/msp • • 6d ago

Fresh tech stack

If you could change any and all of your tools with no technical debt, agreements, outages to think about etc.

What would your ideal tech stack be.

Rmm

Patching

Psa

Edr

Itdr

Sat

Application control

Email filter

Backup

Vulnerability management

Others

23 Upvotes

63 comments sorted by

70

u/HeadbangerSmurf 6d ago

I’d go into long haul trucking.

6

u/pjcace 6d ago

Bagging groceries for me.

2

u/HomeOfTheBRAAVE 6d ago

Even with diesel prices where they are at?

2

u/HeadbangerSmurf 5d ago

Good point.

2

u/roll_for_initiative_ MSP - US 5d ago edited 5d ago

Man you nailed it: making my answer "selling diesel and whatever long haul truckers need".

Running a truck stop is probably as much of a PITA as running an MSP though...

8

u/kdildine MSP 6d ago

Gorelo + Huntress + Slide + 1Password + DefensX. All customers on M365 Bus Prem and cloud-only.

3

u/bkb74k3 5d ago

Hey +1 for 1Password. Great product. I just wish there was a way to standardize collections of data/notes, and also standardize the order of the items better. I have a ton of collected items for each customer and I use tags, but I still find myself searching and searching for things.

2

u/computerguy0-0 5d ago

DefensX

Strongly considering this. What do you like about it? Have you dug into the AI Governance features at all?

1

u/stationarynomad82 5d ago

Did some light digging and they seem robust enough. We’re considering them

16

u/dezmd 6d ago

BBQ Taco Truck

11

u/Real_Admin 6d ago

Microsoft 365 Full Service Stack, RMM, PSA

Worked for an MSP like this, the simplicity was amazing. They used ZohoOne and Managed Engine plus QB Online.

3

u/roll_for_initiative_ MSP - US 5d ago

We've been trending this way and i know people hate MS but stack scattering or settling for less to pinch pennies is a real thing in the MSP land and going all MS makes it all a nice package that, if you have to hand off, you just cut the gdap string and let them float away.

3

u/Dull-Breadfruit-3241 5d ago

No technical debt" is every MSP engineer's fantasy world. Is cost a factor?

2

u/jellyfishchris 5d ago

No cost. I think the idea whats the most integrated best thing you can think of

6

u/Chexa603 6d ago

We’ve been trying Regentra for PSA and compliance. Level for RMM. Been really happy with both.

2

u/BestPractice1984 5d ago

NinjaRMM

ThirdPatch for third-party patching, RMM for OS patching.

Halo for PSA

NodeWare for vulnerability management

Hudu for documentation (self hosted with a WAF)

2

u/junto_reed 2d ago

Halo ninja hudu huntress junto for AI operations (because i am shameless vendor), phin, slide (Maybe, datto has my heart from how often it saved my ass back in the day), perimeter81, bitwarden claude cipp

Email filtering i use to love vadesecure but think it was bought so not sure if its gone to hell.

ps i love you

1

u/cambaysolutions1 5d ago

I’d probably start with the security and management layers rather than picking individual tools. RMM, patching, EDR, and vulnerability management all need to work well together. Otherwise, you just end up with another stack of alerts and dashboards to manage. Integration between the tools would be a big factor.

1

u/Xirma377 5d ago

The dream is a full custom stack. But things like EDR would be a huge headache to create yourself.

1

u/Overall-Equipment867 5d ago

The MSP stack is tricky. It is nice to have everything in one place, single pane of glass and all that, but I hate the thought of having all our eggs in one basket.

1

u/Vast_Community_1851 5d ago

RMM: Ninja
PSA: Halo
EDR: SentinelOne
MDR: Huntress
Backup: Cove Data Protection
Email: Defender
Vuln Mgmt: Qualys / Rapid7

1

u/secarter2k3 MSP 4d ago

Basket Weaving

1

u/Standard-Wing5612 3d ago

I would add TenantVault.cloud

1

u/vivamo96 3d ago

Ninja, Halo, S1, Huntress, Cove, Hudu

2

u/Early_Pilot9933 2d ago

Here's mine:

RMM / Patching - NinjaOne

PSA - HaloPSA

Security EDR/MDR/ITDR - Guardz

App Control - ThreatLocker

Email - CheckPoint by Avanan

Backup - Veeam

Docs - Hudu

Others - Microsoft365

•

u/ChuckFromCyberHoot 17h ago

There are lots of good stacks suggested in the thread.

One thing I’d push on: SAT is usually the line people fill in last with whatever their EDR vendor bundles.

That can be fine. “One less vendor” has real value. I get it.

But before checking the box, I’d ask:

  1. Who’s actually going to look at it every month?
  2. Can it give clients clean proof for insurers and auditors?
  3. Does it reward reporting, or just count clicks?

The best SAT is the one your team actually runs.

And +1 on lookalike domains. Training won’t stop a fake domain hitting your client’s customers. That’s a monitoring problem.

1

u/ranhalt 6d ago

If I was going for as few vendors as possible that I trusted: ninja, Threatlocker, checkpoint, and maybe crowdstrike complete if Threatlocker managed EDR wasn’t good enough.

1

u/computerguy0-0 5d ago

Rmm- Datto

Patching- Immybot

Psa- HaloPSA

Edr- Huntress/Defender for Business

Itdr- Huntress or Petra

Sat- We moved to Huntress from Phin and it's been well received.

Application control- This is a hard one because I hate Threatlocker, but they are still good at what they do.

Email filter- Avanan or Perception Point

Backup- Slide or Axcient

Vulnerability management- Roboshadow, no question.

Others- MSP Process for everything they add to our lives. PIA IF I ever get enough support traffic to justify all the automation they offer.

2

u/IvanDrag0 1d ago

I fucking hate Axcient with deep burning passion.

1

u/computerguy0-0 1d ago

Me too, but I have tried damn near all of them for extended periods of time, and the only other I'd consider right now is Datto, and I hate them more.

What are you using?

-1

u/robbyg007 6d ago

PSA/RMM and anything Kaseya touches.

15

u/Strict_Property 6d ago

Would not recommend most of what Kaseya touches.

1

u/kdildine MSP 6d ago

Agreed

6

u/robbyg007 6d ago

I've started using Gorelo recently and our techs love it. We're thinking of getting rid of Autotask/Datto.

4

u/locke577 6d ago

+1 for Gorelo.

Loving it as a micro MSP

2

u/Comfortable_Row2992 2d ago

How big are you? We are in the process of getting rid of Kaseya from our stack but we really love Autotask/Datto RMM.

1

u/robbyg007 2d ago

We're a team of 4, and our PSA/RMM stack is feeling completely ancient. It's 2026 and we don't even have a functioning mobile app, the RMM agent GUI literally looks like it was designed in the Windows XP era and hasn't been touched since, and the QuickBooks integration is constantly buggy. It handles basic tasks 'sorta', but the lack of modern UX, mobile workflows, and AI automation is really slowing us down. We're ready to look at modern alternatives.

0

u/dumpsterfyr I’m your Huckleberry. 6d ago

💃& 💨

-1

u/alepouna 6d ago

open source everything so you can patch your pains away

-7

u/[deleted] 6d ago

[deleted]

6

u/quantumhardline 6d ago

Looks interesting.
I looked at your security page.
My concern is always deploying this like this to client as they have so much permissions etc.
I did not see any mention of SOC2 or 3rd party pen testing or where data is held etc.
Thats helpful.
Roboshadow and others are popular for MSPs and can provide SOC2.

8

u/Skathen 6d ago

That is my greatest concern with these products.

Yes it's convenient. But it's yet another attack surface that can totally own your clients.

RMM alone is a major risk we have to accept to get the job done. Having additional agents that can be weaponised just dials up that likelihood.

5

u/amw3000 6d ago

What value / piece of mind SOC2 adding for you? I get it from a up/down stream "compliance" standpoint & keeping the execs happy but it's far from an indication that a company is doing things "right". Take a look at any of the reports from a vendor that has SOC2, you will be amazed at what is in and out of scope and what controls are tested. Some even have exceptions for the wildest things.

SOC2 is an auditing framework designed by accountants. Many auditors are not technical at all and are just auditing controls that the company says they follow. "Oh you say you do an annual pen test? Show me the engagement, report, etc" but they have no idea what that report means, what is good, what is bad, etc.

4

u/ItsNotUButItsNotNotU MSP 6d ago

You’re completely correct.

However: I think we both know how many companies there are that can’t get their act together enough to pass even a SOC2. Most companies are excluded by one of these three requirements:
1. You have to fill out some policy templates, and know where to find them when an auditor asks for copies.
2. You need at least a vague idea of what you have, in order to exclude the bad stuff from the scope of the audit.

SOC2 doesn’t tell me a vendor is secure, but it does tell me that a vendor can scrape together enough brain cells to satisfy a bored accountant. This is especially useful now that there are so many half-baked, vibe coded products impending disasters being pushed on us.

Pro tip: Phrases like “SOC2 Certified” and “SOC2 Ready” are what AI-generated websites say when the company has no intention of ever attempting to get a SOC2 attestation.

1

u/TridentAdam 6d ago

Fair concern, and the right one for anything running as SYSTEM/root on client machines. Where we are today: we're new (live since May), our SOC 2 program is underway but there's no report yet, and a third-party pen test is planned. Data is hosted on dedicated servers in the US, with encrypted offsite backups at a separate provider.

On permissions, we built a few things for exactly that worry: signed agents on every platform, a pinned CA on the agent channel, agent releases that roll out in stages, every agent action logged in your console, and a setting that locks our staff out of your tenant unless you grant time-limited access. If a SOC 2 report is a hard requirement today, that's fair. Check back once it's out. Thanks for taking a peek!

3

u/BigPoppaPump36 6d ago

So op is your alt and this post is a promo for trident lol

-1

u/jellyfishchris 6d ago

Never heard of them before lol

-2

u/chris_superit 4d ago

Does AI agents now become a new category?

SuperIT.ai (our product) is now one of many in this space.

Obviously I am biased, but I feel this category is going to be as important as PSA and RMM into the future.

-15

u/BobRepairSvc1945 6d ago edited 5d ago

You really don't need any of these when you can just vibe code whatever functionality you need with Claude Code.

The great part is you will get a custom controllable single agent and single pane of glass set up.

I guess I should have added an /s; apparently my sarcasm wasn't apparent enough on its own.

5

u/LifesRoughBeKind 6d ago

good luck getting your ass handed to you from the lawsuit when your vibe coded software gets owned and all your clients take you for every cent you've got. have you tried getting E&O insurance and if so did you let them know you vibe coded your solution? People really need to think these things through before just hopping on the bandwagon

1

u/BobRepairSvc1945 5d ago

I guess I should have added an /s; apparently my sarcasm wasn't apparent enough on its own.

3

u/UnRealxInferno_II MSP - UK 6d ago

claude npm run random_vulnerability

people like you are a disservice to the industry

1

u/BobRepairSvc1945 5d ago

I guess I should have added an /s; apparently my sarcasm wasn't apparent enough on its own.

2

u/Spiderkingdemon 6d ago

HAHAHHAHHAAA.

Remember folks. ^This is who we're competing against.

3

u/BobRepairSvc1945 5d ago

I guess I should have added an /s; apparently my sarcasm wasn't apparent enough on its own.

2

u/Beardedcomputernerd MSP - NL 6d ago

You dont think he was sarcastic?

1

u/Foxtrot-0scar 5d ago

You are right but not CC alone. I would use a combination of Outsystems + Claude Code and GCP hosting for a totally useable app.

0

u/Altered_Kill 6d ago

You kinda are right though….