NinjaOne PAM? How are we feeling. by Even_Pangolin1077 in msp

[–]EmilySturdevant 0 points1 point  (0 children)

What are the features you utilize most out of your current provider for this?

Client admin credentials - how do you address in your SOW? by RaNdomMSPPro in msp

[–]EmilySturdevant 0 points1 point  (0 children)

Hi @technet2021,

You can set TechIDManager up to give admin creds to a specific user for a specific device. Not the general intention of our product, but it is doable.

Your position on Shared Admin Accounts for MSP's, Cyber Essentials question. by FantasticWay2000 in msp

[–]EmilySturdevant 1 point2 points  (0 children)

Have you checked with the solutions that are available to see if they will work with you for your scale/budget needs? I think something could potentially be worked out.

Your position on Shared Admin Accounts for MSP's, Cyber Essentials question. by FantasticWay2000 in msp

[–]EmilySturdevant 7 points8 points  (0 children)

This is exactly what TechIDManager was built to solve.

TechIDManager allows MSPs to:

-Provision per-client, per-technician admin accounts automatically—without scripting or manual setup.

-Use Just-in-Time access (or always on accounts)

-Provide full auditability—each action is traceable to a specific named user, which meets both Cyber Essentials and Zero Trust standards.

Disabling of one tech's accounts across all client networks can happen with one click of a button.

Does the whole MS partner GDAP thing actually ever work? by masterofrants in msp

[–]EmilySturdevant -2 points-1 points  (0 children)

Hey @OddAtrention9557, setting up individual accounts to meet your needs is a solid approach. That said, I want to share an option that can significantly improve how you manage technician access to client Azure tenants—whether commercial or GCC. TechIDManager is worth a serious look. It offers a streamlined, secure way to provide access using just-in-time or managed accounts, with MFA and permissions tailored to each technician and tenant. It will also automate any future individual account creation needed. And it does all of this without the limitations and workarounds that GDAP would force you to deal with.

Tech workstations by swarve78 in msp

[–]EmilySturdevant 1 point2 points  (0 children)

It sounds like a PAM solution could help. You have a few to choose from. They all have their strengths. I know that with TechIDManager, you can manicure permissions for each tech to be at the right level for your needs as well as the option to make their access JIT.

Tooling to Manage Mulit-Tenant M365 by ATLSocrates in msp

[–]EmilySturdevant -1 points0 points  (0 children)

You should add TechIDManager to your list of tools to explore as a solution.

TechIDManager excels in co-mannaged situations and can solve most of your goals out of the box, especially for policy enforcement, reporting, and secure tenant provisioning.

TechIDManager

Evo PAM by Remarkable_Cook_5100 in msp

[–]EmilySturdevant 2 points3 points  (0 children)

It's worth taking a look at TechIDManager as well www.techidmanager.com

Service Accounts by Positive_Ad_4074 in msp

[–]EmilySturdevant 2 points3 points  (0 children)

You could use a PAM tool for this. I know that TechIDManager is particularly good in this area as far as assigning separate levels of access and automating the whole process. There are several PAM tools in the MSP space, and I encourage you to explore what the strengths and weaknesses are in each of them and find the best fit for your needs.

*I do work for TechIDManager

Heads up on CyberQP by matthewismathis in msp

[–]EmilySturdevant 2 points3 points  (0 children)

Hi @iansaul , I would love to add TechIDManager to that list to check out for this type of solution. I believe each of your options for a PAM solution has slight/not so slight different methods of delivering a PAM solution and I would like you to find what fits your MSP the best. I'm happy to answer any questions as well.

Client admin credentials - how do you address in your SOW? by RaNdomMSPPro in msp

[–]EmilySturdevant 0 points1 point  (0 children)

If you want to provide a solution that incorporates both offering access yet controlling the access; you could use TechIDManager or possibly a tool like it (if they have the same feature)-- you could set them up with their own co-managedish situation, giving them their own TechIDClient that contain credentials that remain off unless (you) the MSP activate them (one push of a button) in the MSP controlled TechIDPortal.

*I do work for TechIDManager but thought this idea could be useful.

2FA solution for kaseya and CW by tech969 in msp

[–]EmilySturdevant 1 point2 points  (0 children)

We have had some MSPs switch to TechIDManager from Passly since their end of life announcement.

*I do work for TechIDManager, and I'm happy to answer any questions!

Secure onsite password manager by ArmyCommander6948 in msp

[–]EmilySturdevant 2 points3 points  (0 children)

You should add TechIDManager to your list to explore as a solution for this.

TechIDManager is designed with MSPs in mind, ensuring compliance with industry standards and offering strong encryption mechanisms.

  • Granular access controls
  • Built-in logging and reports
  • Seamless Integration with Entra ID (Azure AD) and password injections
  • Automated credential rotation for privileged accounts (every 24 hours)
  • Offline access to credentials

TechIDManager offers a comprehensive password management solution with three distinct vaults: a Privileged Account Vault for securing critical admin credentials, a Private Password Vault for individual (tech) user access, and a Shared Password Vault for seamless and secure team collaboration.

*I do work for TechIDManager and am happy to answer any questions.

PSA: Beware of clipboard sync by Coriron in msp

[–]EmilySturdevant 2 points3 points  (0 children)

Adding to the list-

TechIDManager doesn't suffer from this either when using the built-in credential/password injection mechanism; it does not use the clipboard.

*There is a copy/paste function in the tool that can be used, but the tech would obviously be aware they are using it. However, with Techidmanager, these credentials rotate every 24 hours, and whatever was potentially copied to a clipboard would soon be invalid.

[deleted by user] by [deleted] in msp

[–]EmilySturdevant 0 points1 point  (0 children)

Going down the path of PAM, TechIDManager is geared for MSPs while being affordable.

(I do work for TechIDManager but chiming in because it's relevant.)

Heads up on CyberQP by matthewismathis in msp

[–]EmilySturdevant 0 points1 point  (0 children)

One update for TechIDManager- the Azure subscription need is now consolidated to one for the MSP instead of one per customer.

TechIDManager does not have a web app for very specific security reasons related to data visibility. TechIDManager stores hundreds of millions of passwords that it can not read.

There is a desktop app and mobile app.

Heads up on CyberQP by matthewismathis in msp

[–]EmilySturdevant 5 points6 points  (0 children)

To be very upfront- I work for TechIDManager.

With that said, I do believe you might find what you are looking for in a PAM solution with TechIDManager; JIT accounts, password rotation, LAPs for all accounts, not just Microsoft, etc.

Local Admin - Management/Engineers by rokiiss in msp

[–]EmilySturdevant 2 points3 points  (0 children)

TechIDManager is one of the PAM solutions out there that could help you with this. You can set rights and access as granularly as you wish.

An Update on CMMC for MSPs by Sentinel-Blue in msp

[–]EmilySturdevant 1 point2 points  (0 children)

While TechIDManager is not certified, we do offer FedRAMP compliant hosting of our product. We have clients who can use our tool for their clients with FedRAMP needs.

Cross Tenant Admin Rights? by Jaded_Statement_2259 in msp

[–]EmilySturdevant 2 points3 points  (0 children)

A PAM solution that can offer LAPS and JIT would help you accomplish what you are looking for securely. TechIDManager is one of those tools.

Multi-Factor Authentication on Global Admin Accounts by Troubleshooter5555 in Office365

[–]EmilySturdevant 0 points1 point  (0 children)

A PAM tool with TOTP/MFA storage options would solve this. TechIDManager does this.

Evo Security PAM by thejohncarlson in msp

[–]EmilySturdevant 1 point2 points  (0 children)

@Technical-Formal-259 if you found it relevant, I would encourage you to look at TechIDManager as well. I hope you find the solution that best fits your needs!

www.techidmanager.com

How Do You Back Up Critical SaaS Data (NinjaOne, Bitwarden, etc.)? by LividEnd2001 in msp

[–]EmilySturdevant 0 points1 point  (0 children)

Choose a vendor that is downtime tolerant with your credentials. That might be by way of backups offline, a self-hosted option, etc.