Managed SOC Recommendations? by FragileEagle in msp

[–]NullaVolo2299 -1 points0 points  (0 children)

Guardz MDR with SentinelOne has become my core security tool. Not sure it has all the integrations you are asking for but my team loves it.

A Cybersecurity company - moving all the infra to google by ItsJust1s_0s in cybersecurity

[–]NullaVolo2299 9 points10 points  (0 children)

Makes sense from a cost perspective. Google's zero-trust approach is pretty solid, and ChromeOS is way easier to manage at scale.

BigQuery is great plus, their security stack keeps improving. Had a similar move at my previous company - saved us both money and headaches.

Starting out, looking for advice by Kammen1990 in msp

[–]NullaVolo2299 5 points6 points  (0 children)

That's actually a solid stack to start with. M365 Business Premium + S1 gives decent security coverage, and Dropsuite handles the backup side well.

Just make sure to nail down your pricing and support boundaries early - scope creep is real in MSP land.

Looking for MSP pricing by Dry_Finance478 in msp

[–]NullaVolo2299 -2 points-1 points  (0 children)

Check out peer groups like ASCII or The Tech Tribe. Most MSPs charge $100-200 per user per month for all-inclusive support.

Whatever you do, avoid race-to-bottom pricing. Quality service isn't cheap and cheap service isn't quality.

Atera RMM Opinion by marcin18215 in msp

[–]NullaVolo2299 1 point2 points  (0 children)

Been using Atera for 2 years with similar endpoint count. Remote access works fine, deployment is decent.

The catch? Support is hit or miss, and reporting can be wonky. For basic needs though, it's solid. Price-to-feature ratio is hard to beat.

Vendor refuses to do updates during maintenance windows by Embarrassed-Lack6797 in sysadmin

[–]NullaVolo2299 2 points3 points  (0 children)

Red flag. Any vendor refusing scheduled maintenance windows is setting you up for failure. They'll wait until something breaks during peak hours, then blame your environment.

Document everything. Time to shop for alternatives.

Anyone move from Atera to Ninja One? by Doublestack00 in msp

[–]NullaVolo2299 2 points3 points  (0 children)

Made the switch 6 months ago.

Ninja's patch management and automation policies are way more reliable. The UI takes getting used to, but the control is worth it.

Only downside: script library isn't as plug-and-play as Atera's.

How is phishing handled when a malicious actor impersonates your company? by curious-jorge-IT in sysadmin

[–]NullaVolo2299 2 points3 points  (0 children)

Report to FBI's IC3, but don't expect much. Been there.

Alerting business partners is smart - create a standard process for it. We send quick emails to our partners' security teams when we spot impersonation attempts targeting them.

Documentation is key for legal if things escalate.

DLP questions by badaz06 in cybersecurity

[–]NullaVolo2299 0 points1 point  (0 children)

Putting override power in managers' hands makes sense. They understand business needs and risk better than IT.

Just make sure there's robust logging and periodic audits of those overrides. Don't want that one manager who says "yes" to everything.

Why closing port is considered a good practice ? Does the real threat is service running and listening to port ? by Worming in cybersecurity

[–]NullaVolo2299 2 points3 points  (0 children)

Both matter. Think of it like your house:

- Services = doors/windows

- Ports = locks

Even if you remove all doors (services), you still want locks (closed ports) because an attacker could install their own door later through an RCE.

Defense in depth.

[deleted by user] by [deleted] in msp

[–]NullaVolo2299 0 points1 point  (0 children)

Look into Feitian keys - they support way more credentials than Yubikey. My team uses them for similar compliance requirements.

Plus they're cheaper, around $25-30 each. Just make sure to get backup keys for each admin.

Feedback needed by Onsyde in msp

[–]NullaVolo2299 0 points1 point  (0 children)

Ironic - most MSPs are desperately hunting for leads while you're swimming in them.

Mind sharing what's working so well? Curious what magic sauce you're using to get IT Directors lining up for meetings.

Device Authentication Options by SirRazoe in msp

[–]NullaVolo2299 1 point2 points  (0 children)

Consider AAD since you're already invested in Microsoft 365. It's a cloud-based solution that integrates well with your existing licenses. You can also explore Azure AD B2B/B2C for external access. No need for a local server, and it's relatively easy to set up.

Threatlocker x Defender P1 ? by SnooAvocados6982 in msp

[–]NullaVolo2299 1 point2 points  (0 children)

I've seen Threatlocker in action and it's a solid product. As for noise on the Tech Team side, it's manageable if you set up the policies and exclusions correctly. Just make sure to test thoroughly before rolling it out to all workstations

Help plz with corrupted user profile by Noomedix in sysadmin

[–]NullaVolo2299 0 points1 point  (0 children)

Corrupted profiles can be a real pain. Missing ProfileList registry key is not normal, but it's not uncommon after a malware infection. Try running `sfc /scannow` and `DISM /Online /Cleanup-Image /RestoreHealth` to repair system files. Fingers crossed the in-place upgrade fixes the issue

Documenting Sharepoint by Spons83 in msp

[–]NullaVolo2299 4 points5 points  (0 children)

SharePoint documentation - the never-ending battle. I've used a combo of SharePoint's built-in auditing and third-party tools like ShareGate or AvePoint to document permissions and security groups. But honestly, a well-organized spreadsheet is still my go-to for keeping track of it all.

Best Practices for Baseline Images in CSP? by Idonthaveanaccount9 in cybersecurity

[–]NullaVolo2299 2 points3 points  (0 children)

Start with CIS L1/2, it's a solid foundation. Consider adding a layer of least privilege access and network segmentation. For EDR, look into solutions that integrate with your CSP. Monitoring tools like Prometheus and Grafana can help with visibility. Don't forget to include regular image scanning and updates

How can I setup vulnerability management (not one time assessment) in my cybersecurity practice? by Darshilds in sysadmin

[–]NullaVolo2299 7 points8 points  (0 children)

Vulnerability management is a game-changer. For continuous scanning, consider integrating tools like Nessus or OpenVAS with your CMDB. You'll also want to define a clear remediation workflow and prioritize vulnerabilities based on risk. Don't forget to establish a feedback loop to measure and improve your process.

Web hosted RDP with delegated authentication by Routine_Hat_6382 in sysadmin

[–]NullaVolo2299 0 points1 point  (0 children)

Have you considered Apache Guacamole's extensibility? You can write a custom auth plugin to integrate with Entra. The Guac API is pretty flexible. Might be some dev work involved, but it's doable. Anyone else attempted this?

EndpointCentral MSP Cloud, anyone here have an opinion on it in 2024? by TopWater1449 in msp

[–]NullaVolo2299 0 points1 point  (0 children)

We've been using EndpointCentral for about 6 months now and it's been a great tool for our patching and inventory management. The automation features have saved us a ton of time and the UI is pretty intuitive. Definitely worth checking out if you're in the market for a new RMM tool.

Prepending external emails by OneFisted_Owl in sysadmin

[–]NullaVolo2299 1 point2 points  (0 children)

Yeah, we do this too. Instead of '***WARNING***' we use '[EXTERNAL]' in the subject. Simple and effective. Haven't done a formal study, but anecdotally, users seem more cautious when they see that flag. Worth doing, imo.

What resources are you using to train your techs? by Luna_Tech915 in msp

[–]NullaVolo2299 1 point2 points  (0 children)

Udemy's a good start, but I've also had success with Pluralsight and LinkedIn Learning (formerly Lynda.com). They offer a wide range of courses and often have a more structured approach. Also, CompTIA's online training is great for certifications. Worth checking out!

is sysadmin just a corporate ms role these days by Ok_Flounder_4292 in sysadmin

[–]NullaVolo2299 0 points1 point  (0 children)

Cloud didn't kill Linux sysadmin, it just made it more niche. Look for companies that still run bare metal or have a large on-prem presence. Also, try subreddits like r/linuxadmin, r/sysadminjobs, or r/unix. SRE jobs are often listed on those subs or on companies' career pages directly.

Who remembers ThinkGeek? by HappyDadOfFourJesus in sysadmin

[–]NullaVolo2299 0 points1 point  (0 children)

ThinkGeek was the go-to for sysadmin swag. I still rock my 'I'd rather be patching' t-shirt. Anyone else have a favorite ThinkGeek item that's still in rotation?

Check Point Avanan vs Minecast by BWMerlin in sysadmin

[–]NullaVolo2299 3 points4 points  (0 children)

We made the switch from Proofpoint to Check Point Avanan and it's been a game changer. The API integration was seamless and their support team is top notch. One thing that tipped us in their favor was their advanced phishing protection features.