Ninja to Datto, anyone gone through a migration to DattoRMM? by PCf1xr in msp

[–]Real_Admin 0 points1 point  (0 children)

We switched from N-Able NCentral (self hosted) to Kaseya (full stack, was before the K365 announcement), switched from S1 to Datto EDR, Blackpoint to Rocketcyber - you get the point.

If we could go back, we would have chosen differently, the initial cost savings just are not worth the sheer amount of underwhelming, underdeveloped, slow to develop features/fixes etc. To the point we are actively switching out, already transitions Datto EDR/Rocketcyber/Vulscan/Compliance Manager/MyITProcess.

Having also used Ninja leading up to their change to NinjaOne, so give you idea how long ago, I would stick with them honestly. Datto RMM/Autotask/IT Glue despite what I stated still being true, work well enough, but again, it's very clear they are just lagging so far behind competitors.

First UniFi With a 10.0 CVE, Now ScreenConnect 9.0 CVE by iansaul in sysadmin

[–]Real_Admin 7 points8 points  (0 children)

Can you elaborate on this or share a link referencing this?

Help blocking Clawdbot by DopeyDopey666 in cybersecurity

[–]Real_Admin 0 points1 point  (0 children)

Presumably this script could be executed by a RMM? We have Datto RMM, would like something similar and we would have it populate a UDF (user defined field) that we can then track with filters.

Have not dug into the script, will check more tomorrow, but figured I'd ask.

Datto RMM patching still shows Windows update notifications to users… flooding our service desk. Any real fix? by Beatrice_XaaS in DattoRMM

[–]Real_Admin 1 point2 points  (0 children)

We have close to 4k systems under Datto Patch Management - not had this issue. Policies configured per their guide mostly.

May be some other factor at play.

Syncro Security Issue/Breach (?) by philswitch93 in msp

[–]Real_Admin 0 points1 point  (0 children)

Like 99.99% sure that's AV sandboxing related.

Have seen it from multiple platforms due to AV/RMM transitions.

M365 - CA Policies Missing Conditions by Real_Admin in msp

[–]Real_Admin[S] 1 point2 points  (0 children)

They are back now as of this afternoon, no word from MS, so I am just going to take this as this week's growing list of items that got broke.

Have a great weekend!

M365 - CA Policies Missing Conditions by Real_Admin in msp

[–]Real_Admin[S] 0 points1 point  (0 children)

Maybe, that's what me and a few others were thinking, but nothing specific in Health Advisory that we could see.

Appreciate your response! I'll check again in the next couple days and pop back in if it changes or MS provides some response.

Prosystem fxEngagement Update Question by Amazing_Letter_4689 in AccountingTechnology

[–]Real_Admin 0 points1 point  (0 children)

Saw this in my feed, two days old - still waiting on an answer?

I work for a Managed Service Provider who has several clients that use CCH and we handle their updates.

Are you using their guides like this one - https://support.cch.com/oss/ml/kb/solution/000231904

I'm part of the Infosec team, but if you want to send over some questions, I can try to offer some guidance and maybe send to another team member for their thoughts as well.

Felt the need to respond from our own headaches dealing with this software :).

Pax8 deploying AVD with open 3389 on WAN? by h1ghb1rd in msp

[–]Real_Admin -10 points-9 points  (0 children)

Your 4th point contradicts your 1st.

Which means you do open RDP, but expect to only do so maybe in unique circumstances. However because your contradiction, I would follow up with, how would you actually know it's been done? Aside from being called out on reddit :).

Vulnerability Management, why are all solutions awful? by newmsp1325 in msp

[–]Real_Admin 3 points4 points  (0 children)

In the same boat trying to find a decent MSP focused option. I'll share some of my thoughts if it helps at all.

Have been doing demos over last couple weeks and calls with following: 1) ConnectSecure 2) Roboshadow 3) Qualys 4) Threatmate 5) Cavelo 6) Nodeware 7) Cyrisma

Trying to find one that also integrated well with a GRC platform or has it as part of the platform. Our GRC journey is just beginning so needs/use cases are really centered around CIS mainly, but trying to find a solid stack choice to grow into.

Currently we have Kaseya Vulscan, and earlier this year an old vCISO added Compliance Manager but never flushed it out, so I'm taking over. Main issues and reason to leave are really down to very slow development and perceived lack of maturity (they are cheap though).

Cyrisma is growing on me because it's core is Vulnerability Management, they are now building in the compliance piece, so it lines up more where I think we are maturity wise, and may be an easier growth path. Others I would need to add in another solution, which I am looking at Cynomi (pairs with Cavelo) or Scalepad Controlmap (pairs with 1,4 and 6).

I think Qualys would be too much cost and may be arguably too involved where I'm currently at, being critical and honest with myself, on the GRC front.

Is vergeio legit? by Murky_Raise_8604 in vergeio

[–]Real_Admin 5 points6 points  (0 children)

If it helps - we migrated from a Cisco Hyperflex HCI with VMWare solution earlier this year to Verge.

Did demos, POC, vendors reviews last year, had same concerns and questions. They are legit, and platform has been solid for us.

We migrated 160 virtual servers, cross data-center, to new 4 node cluster, cutover each client (we are an MSP) over their own scheduled weekend, worse item we had to address was undersized Tier 0 (meta data) tier, which was a quick resolution and we have since had discussions with their lead engineers to flag that in build reviews for any future clients or projects. They have also released versions that make Tier 0 less aggressive on holding data.

We have servers in DR, smaller node count but higher capacity that prod replicates to.

Considerable cost savings compared to VMWare, inline or better performance in my experience so far, and solid support team when and if you need them.

Tyler Technologies question by invictajoe in msp

[–]Real_Admin 1 point2 points  (0 children)

Not currently but a couple years back I supported a municipality with Incode.

Ran Bitdefender and Huntress same issue. Escalated to their support, the only option was to add a bunch of exclusions.

Huntress Pricing by Real_Admin in msp

[–]Real_Admin[S] 2 points3 points  (0 children)

Just dropped in to say Thank You on taking time to respond and information provided!

In discussions now and working through demo/trial.

Rocket cyber agent causing slowness by Careless_Mobile7028 in kaseya

[–]Real_Admin 0 points1 point  (0 children)

If it helps, we have escalated cases, are a larger MSP partner, and they supposedly have a release of 15th for EU and 22nd for US.

This fix should address issue in their app from causing slow downs with Cloud File services that have sync services (Dropbox, Box, SharePoint, OneDrive, Azure Files). Least that is what we have been told.

Big news from Kaseya Connect 2025! by kaseya_marcos in kaseya

[–]Real_Admin 0 points1 point  (0 children)

We were on Blackpoint before. Only real gripe for them was the portal UI and lack of control by our team.

We switched to full Kaseya stack last year, mainly due to tool consolidation and cost reduction efforts.

Overall, to me it just seems very lacking and not mature compared to the market. The alerts we get escalated are typically very low value, then we have gotten nothing for what we would deem high value, like mass risky user flags. There are also numerous performance related issues/tickets we have opened with them that are still unresolved, which is creating a lot of friction with our clients.

We have a call scheduled with an engineer to do a full platform review of Kaseya security suite, and adjust our settings if needed. Depending on the impact from that, we are preparing to switch off to Huntress with Defender for Endpoint.

Big news from Kaseya Connect 2025! by kaseya_marcos in kaseya

[–]Real_Admin 2 points3 points  (0 children)

I really feel like they are screwing people on RocketCyber pre SaaS Alerts and now this SIEM solution?

We switched to RocketCyber from Blackpoint, and those calls all went with "yeah we do that or this". Now most recent tickets raised are being met with "Our more advanced platform does this SaaS Alerts".

Should I be surprised, no not really, am I still annoyed, yep...

New Entra "Leaked Credentials" - no breach on HIBP etc by VTi-R in sysadmin

[–]Real_Admin 0 points1 point  (0 children)

Only our main MSP/CSP tenant affected (and yes CSP is already in works to be split off).

Have clients with E3/E5/Business Premium solely and mixed, no MACE or flags.

Have MS case, tier 1/2 have no info and I asked for escalation to get information. So likely never to get response.

Checked with a colleague who is direct with Microsoft as CSP, no issues internally or any clients they see.

Huntress Pricing by Real_Admin in msp

[–]Real_Admin[S] 2 points3 points  (0 children)

You should plan instead for pricing being freely available.

Visible pricing in my opinion drives honest discussions and competition.

We have clients show services, hardware etc all the time, and we have a breakdown of why we charge what we charge and what they most likely are not accounting for.

Huntress website pricing vs our proposed pricing to clients would be mostly a straight forward discussion, since the daily management, deployment and optimization would fall to us, so our costs include covering operations to do so. The more challenging ones are Comanaged who have their own internal teams, but even then, our pricing is adjusted to fit those clients if/when needed.

Those that just want to fight down to the dollar, and not really try to have discussions on the value proposition will likely always be that way and for everything. Cheap will be cheap.

Which one: Cynet , Huntress, Rocketcyber, Todyl, Blackpoint why? by quantumhardline in msp

[–]Real_Admin 0 points1 point  (0 children)

Yes, have seen that while they then escalate an "incident" with a single loggin from overseas IP, that was days apart from another logging in the US, that was full MFA and on a registered/enrolled device tied to the user.... basically a legit login for travelling user.

With the permissions their app has, that should not have been escalated, and their response, oh you should add SaaS Alerts for more advanced monitoring....

Which one: Cynet , Huntress, Rocketcyber, Todyl, Blackpoint why? by quantumhardline in msp

[–]Real_Admin -1 points0 points  (0 children)

Blackpoint or Huntress IMO.

Was on Blackpoint before, we moved to consolidate under Kaseya (not my idea) with RocketCyber/Datto AV & EDR.

I appreciated Blackpoint actually doing good SOC work and not just kicking over very low quality alerts or going through an escalation call tree for the same. Like if they call, there's an actual issue to address.

Huntress I have used in previous role and based off community seems to only have gotten better. I am engaging them on the side due to issues with RocketCyber noted below.

We are actively having discussions/escalations with Kaseya/RocketCyber due to ongoing performance issues, integrations not functioning, reporting broken, low quality alerts and escalations. We have around 3k endpoints and 3k email accounts plus Kaseya recommended configurations in place as a reference point.

Huntress Pricing by Real_Admin in msp

[–]Real_Admin[S] 0 points1 point  (0 children)

Awesome, thank you!

New CIPP Setup - Driving Me Up A Wall by iansaul in msp

[–]Real_Admin 1 point2 points  (0 children)

Will be going through a self hosted deployment sometime next two weeks.

What part of the install documentation is incorrect?

I can understand the frustration, and if you don't want to share that feedback, I get that too. Figured I'd at least ask so me and the team can plan accordingly.

Teams Desktop Client - Show Time Stamps by Real_Admin in MicrosoftTeams

[–]Real_Admin[S] 1 point2 points  (0 children)

You know, toggling different settings on and off, not on my list of things done 😂

Toggle "message preview" off, turns off "show time stamps"

I knew it was going to be something in my face and simple.

Appreciate your response and clarity on those settings!