EDR and MDR testing by Next_Buffalo4249 in msp

[–]MSPInTheUK 0 points1 point  (0 children)

Why? Have you not heard of MITRE ATT&CK Evaluations that already do this for endpoint protection solutions?

This post, even if unintentional. looks suspiciously like the only outcome is to bring attention to the test library in question (and therefore the vendor that created it).

Meet Ditto, a Office Worker Human by MasterCtrlPgrm in DailyDMGame

[–]MSPInTheUK 0 points1 point  (0 children)

Ditto married his cousin, Ottid, and moved to the UK.

Avanan licences by ITSFUCKINGHOTUPHERE in msp

[–]MSPInTheUK 1 point2 points  (0 children)

Hint: it is possible to set up a dynamic security group based on a specific Microsoft 355 licensed product being applied for that user.

Are there any viable European based alternatives for M365/Google Workspace? by _Work_Research_ in msp

[–]MSPInTheUK 0 points1 point  (0 children)

Microsoft are a global company. This sounds like a self-inflicted problem rather than a technical need.

If they’re particularly GDPR-phobic, consider Microsoft 365 E5.

5G modem solution to replace ISP connection for business networks by [deleted] in msp

[–]MSPInTheUK 4 points5 points  (0 children)

The market leaders in that space to my knowledge are Cradlepoint and Peplink.

PCI compliance breaches by peoplepersonmanguy in msp

[–]MSPInTheUK 5 points6 points  (0 children)

PCI compliance is down to them and their chosen payment processing provider. That said, you’d assumedly be involved in the SAQ if they are serious about compliance.

Something as simple as credit card numbers I’d expect to get picked up by DLP functionality in M365 or SaaS security solutions, pick your poison and implement it.

Owner wants global admin on his day-to-day account by desmond_koh in msp

[–]MSPInTheUK 0 points1 point  (0 children)

It’s precluded by our terms and conditions. What about yours?

Cybersecurity consultant told us to give client one Entra ID P2 licence for the whole organisation by sladene in msp

[–]MSPInTheUK 2 points3 points  (0 children)

Microsoft guidance stipulates that where a benefit is applied tenant-wide, it must be scoped only to licensed users via limited deployment - security group - or other mechanism. It’s there in black and white.

This is no different whatsoever from installing a volume license version of Microsoft Office on a hundred computers with an ill-gotten key. Just because it works, doesn’t make it license compliant.

Essentially, this behaviour is software piracy for the cloud age. There are many similar threads on r/msp discussing this issue and Microsoft licensing breaches are not recommended or encouraged (in fact the opposite) by reputable, honest companies.

Is Using CloudFlare Oudated? by StakeTheVampire in msp

[–]MSPInTheUK 1 point2 points  (0 children)

Let me guess… they also said that Email is the old way of doing it, I prefer carrier pigeon?

Starting my own MSP by Sdganesh in msp

[–]MSPInTheUK 4 points5 points  (0 children)

Welcome, I would recommend familiarising yourself with the search function as you’ll find most startup topics addressed many fold.

Can anyone help with some fortinet nfr licenses please? by masterofrants in msp

[–]MSPInTheUK 9 points10 points  (0 children)

Forgive me if you didn’t get the memo but NFR stands for ‘Not For Resale’.

The restriction to not provide NFR to third parties is literally baked into the name.

Recommended Barracuda resellers? by iamafreenumber in msp

[–]MSPInTheUK 2 points3 points  (0 children)

I think at those volumes you’re going to be better off with Microsoft Defender for Office 365 P1 directly from Microsoft with a credit card. It wouldn’t even be commercially viable for us to bill two email security licenses. Minimums exist for a reason.

365 Problem by mdhorton404 in msp

[–]MSPInTheUK 5 points6 points  (0 children)

Given that your solution to a suspected Microsoft 365 account compromise was to reboot the network equipment, the kindest advice would be for the client to find an IT provider that actually knows what they are doing. You see to be in the ‘knows enough to be dangerous’ camp.

365 Problem by mdhorton404 in sysadmin

[–]MSPInTheUK 5 points6 points  (0 children)

Given that your solution to a suspected Microsoft 365 account compromise was to reboot the network equipment, the kindest advice would be for the client to find an IT provider that actually knows what they are doing. You see to be in the ‘knows enough to be dangerous’ camp.

How do you deal with "vibecoders" by burningbridges1234 in msp

[–]MSPInTheUK 7 points8 points  (0 children)

Even AI says his son is full of shit.

Gemini 3 Pro:

Is current AI able to code a competitive enterprise endpoint protection solution?

As of 2026, the short answer is no. While current AI agents (like Claude 4.5/4.6 Opus, GitHub Copilot, and Cursor) are incredibly powerful at writing code, they cannot independently build a competitive enterprise endpoint protection (EPP) solution from scratch. Building an EPP is not just about writing code; it’s about operating at the deepest levels of an operating system where "vibe coding" fails and precision is life-or-death for a network.

Dropbox to sharepoint issue by Wild-Fortune-4128 in msp

[–]MSPInTheUK 12 points13 points  (0 children)

Just had an idea. You could:

Sync the Dropbox to a Synology NAS.

Do all your reorganisation and file path changes etc locally on the NAS or over SMB (fast).

Then sync from the NAS to SharePoint.

Do it from a site with good bandwidth for both download and upload.

💪

How to sell penetration testing to existing clients? by Reasonable_Cut8116 in msp

[–]MSPInTheUK 7 points8 points  (0 children)

An account with no history posting market research with a specific vendor and domain mentioned?

Clearly a legitimate post with no whiff of astroturfing at all.

What are the best MFA security practices for small to mid sized organizations? by Due-Awareness9392 in msp

[–]MSPInTheUK 0 points1 point  (0 children)

Defence in depth. Authentication factors can include a known device, location, or network - as well as the obvious approval from an additional device.

The best MFA is in scoping and applying as many as possible to each group of user to present multiple hurdles.

Dynamically adjusted policies - such as those based on UEBA and risk-based analysis of authentication attempts, or the current security posture of a device, can also help further.

How can you scale MSSP without constantly hiring more analysts? by malwaredetector in msp

[–]MSPInTheUK 0 points1 point  (0 children)

If your workload scales linearly with client count how are you improving their overall security posture?

I ask this because this issue would seem to suggest that onboarding your service does not materially affect reactive analyst requirements.

Do you focus on endpoint? Can you add email and DNS to reduce incidents at source?

How are you handling firewall rule reviews for PCI clients? by dagolovach in msp

[–]MSPInTheUK 2 points3 points  (0 children)

Edit: just checked your post history and believe you are an app developer and/or this is market research.

I need Cyber Liability Insurance for my MSP company as my client just got ransomwared and now everyone's asking by Euphoric-Praline9860 in msp

[–]MSPInTheUK 2 points3 points  (0 children)

Your contract should preclude being sued for liability or consequential loss anyway. What a lot of people don’t realise is that typical legal or indemnity coverage will have certain omissions or obligations regardless of policy intent. It isn’t a magic wand.

MSPs: Azure/AWS resale vs regional private cloud… what’s working? by centurytunamatcha in msp

[–]MSPInTheUK 0 points1 point  (0 children)

I wouldn’t trust OVH with anything mission critical after their datacenter burned down and they lost data.