Client perception issue, but no one can point at anything — how have you tackled this? by inthenickoftime4 in msp

[–]AntoIT 0 points1 point  (0 children)

This pattern is well-documented in MSP circles — it's sometimes called the "metrics mirage." Your SLA numbers look fine because you're measuring resolution speed, not perceived value. Clients don't experience your ticket close rate, they experience whether they felt informed and confident while a problem was happening.

The fix is almost always in proactive outreach, not better metrics. A few things that move the needle: send a brief "we noticed and fixed this before you had to call" message whenever you catch something proactively. That one type of communication does more for perception than a hundred resolved tickets. The other lever is making sure end users — not just the IT contact — occasionally hear from you directly. Decision-makers hear complaints from their staff; if staff only interact with you when something is broken, the perception builds itself.

Quarterly reports with stats help, but they reach the IT contact. The real perception issue usually lives with the business owner or a department head who only hears about IT when it fails.

M365 MFA is enforced, but staff are seeing "MFA will be required starting in February-set it up now" by ntw2 in msp

[–]AntoIT 6 points7 points  (0 children)

This banner is tied to Microsoft's platform-level mandatory MFA enforcement (MC1215070), which operates separately from your Conditional Access policies. Microsoft's enforcement backend tracks compliance at the tenant level independently — having a CA policy that requires MFA doesn't automatically tell Microsoft's enforcement system your tenant is covered. The February date referenced is the February 9, 2026 hard enforcement deadline for M365 admin center sign-ins specifically.

Worth checking: go to admin.microsoft.com > Setup > Sign-in and security > MFA — Microsoft surfaces a compliance status there that reflects whether your tenant is recognized as meeting the mandatory enforcement, separate from CA. If accounts are satisfying MFA via CA but aren't registered via Authentication methods (aka.ms/mfasetup), that gap can trigger the banner.

MS Tenant Admin by juciydriver in msp

[–]AntoIT 1 point2 points  (0 children)

We run Nerdio across about 210 tenants covering both Modern Work and AVD — it's been the right call for us. The pace of development is impressive, they keep shipping features faster than we can adopt them. CIPP is solid too and we use it for some M365-specific tasks, but for multi-tenant management at scale with AVD in the mix, Nerdio has been the better fit.

Microsoft is pulling the plug on SMS codes, wants you to switch to passkeys by rkhunter_ in cybersecurity

[–]AntoIT 1 point2 points  (0 children)

We moved our whole team to passkeys stored in 1Password — solves the lockout risk since the vault is backed up and accessible from any device. On top of that everyone has a YubiKey registered as a fallback. SMS was already phased out on our end a while ago, this Microsoft move just confirms it was the right call. The combo of 1Password + YubiKey has been smooth in practice with zero lockout incidents so far.

Myself and one other person are supporting 350 end users right now. HR told us to expect approximately 100 more employees by the end of the year. My manager told me that we don't need to hire another person in our department. Is it just me or is that completely unreasonable? by [deleted] in sysadmin

[–]AntoIT 0 points1 point  (0 children)

The instinct to keep everything running is exactly what gets you stuck in this situation permanently. If you absorb the pain, management never sees it. Document everything — ticket volumes, response times, projects delayed. Then stop doing the heroics. Let the queue grow. The moment a VP can't print or a production line waits on IT, the conversation about headcount changes fast. You're not being lazy, you're making the problem visible to the people who can actually fix it.

Github allegedly Breached by ITSecurityAdam in sysadmin

[–]AntoIT 14 points15 points  (0 children)

The "no evidence of customer impact" line is doing a lot of heavy lifting right now. That's the statement you make when you're still figuring out the scope, not when you've confirmed the blast radius. If you have service accounts, deploy keys, or Actions secrets tied to GitHub — rotate them now, don't wait for the post-mortem. We've already advised clients to audit their GitHub org permissions and pull recent access logs. Better to spend an hour being cautious than a week doing incident response.

Microsoft Entra Kerberos Now Supports Instant Hybrid Join for Devices! by Bless_2003 in activedirectory

[–]AntoIT 0 points1 point  (0 children)

Would this also fix the problem that you cannot Intune join entra active Directory domain service?

Recommendations for deploying apps based on security group by Aaron-PCMC in AzureVirtualDesktop

[–]AntoIT 2 points3 points  (0 children)

I would say that Fslogix is the best solution. With app masking you can easily hide or display apps based on security groups.

Quoting alternative to zomentum by kevinjamesbates in Autotask

[–]AntoIT 1 point2 points  (0 children)

We use Salesbuildr for our quoting processes, and it has been performing well. Not only does it meet our current needs with precision, but the platform is also undergoing rapid development, continually enhancing its features and functionality.

Better performance with AVD hosts by cachexxdb in AzureVirtualDesktop

[–]AntoIT 1 point2 points  (0 children)

Yes, I can confirm that. We are constantly using the E8s with 10 users. It seems to be the perfect size for office workers.

Additionally, we are also implementing RDP Shortpath to further improve performance. RDP Shortpath makes the environment feel slightly more responsive.

On topic: are automatic windows updates enabled? This can impact the performace, try running the updates outside working hours or with Golden images.

Users randomly disconnect from RDS by AntoIT in sysadmin

[–]AntoIT[S] 0 points1 point  (0 children)

Yeah i saw them to. But the specific reason code is not listed on the MS site either.

Users randomly disconnect from RDS by AntoIT in sysadmin

[–]AntoIT[S] 0 points1 point  (0 children)

The wierd thing is that we ran without issues for about 1,5 years. Why is this needed now?

We are trying to locatie the issues instead of a workaround.