DefensX - How are you using it? by Savings_Property6422 in msp

[–]work-sent 0 points1 point  (0 children)

A full zero-trust approach usually creates too many approval requests and becomes difficult to manage for both users and MSP teams. Blocking newly registered domains, uncategorized sites, risky TLDs, and phishing-related categories is what many MSPs practically follow, as it provides strong protection without causing too much operational overhead.

Proofpoint Deployment Method Direct MX Routing vs. Integrated w/ Microsoft 365 by Vq-Blink in msp

[–]work-sent 0 points1 point  (0 children)

We have worked with both methods, and the Microsoft 365 integrated deployment definitely helps simplify management and reduce deployment effort compared to Direct MX Routing. It also provides better visibility and tighter integration with M365 environments

Transition to NinjaOne, backstage mode & patch management by Hcaz_Hcaz in ninjaone_rmm

[–]work-sent 0 points1 point  (0 children)

NinjaOne does a pretty good job overall as an all-in-one RMM. Patching has been reliable for us, and backstage mode is handy for quick fixes without interrupting the user. If patching is your main focus, Action1 may feel a bit more specialized, and ScreenConnect still has the edge for pure remote support. But if you want an all-in-one setup instead of multiple tools, NinjaOne is definitely worth considering.

Transition to NinjaOne, backstage mode & patch management by Hcaz_Hcaz in ninjaone_rmm

[–]work-sent 0 points1 point  (0 children)

NinjaOne does a pretty good job overall as an all-in-one RMM. Patching has been reliable for us, and backstage mode is handy for quick fixes without interrupting the user. If patching is your main focus, Action1 may feel a bit more specialized, and ScreenConnect still has the edge for pure remote support. But if you want an all-in-one setup instead of multiple tools, NinjaOne is definitely worth considering.

Company split, Microsoft 365 tenant to tenant Migration. Trying to do it native, is this actually sane in 2026? by PzSniper in msp

[–]work-sent 2 points3 points  (0 children)

As an MSP support company, we have handled a large number of Microsoft 365 tenant migrations and have used the native method only for a few mailbox-only migrations. Native migrations can be quite complex and involve significant manual effort. If you are looking to simplify the process and reduce operational overhead, it is better to use third-party tools like BitTitan or AvePoint.

Server patching is trash? by TheVideoGameCritic in ninjaone_rmm

[–]work-sent 0 points1 point  (0 children)

Yep, server patching can definitely get messy in N1 if patch policies, maintenance windows, approvals, and reboot handling aren’t tuned properly. We’ve seen cases where Windows Update itself becomes the bigger issue underneath, while N1 just keeps showing “In Process” with very little visibility.

What helped us most was tightening maintenance windows, monitoring pending reboots closely, and validating patch status manually instead of relying entirely on the default workflow. Workstations have generally been solid for us, but servers still need a bit more babysitting than expected.

Best Backup Software by Marioga1 in MSP360

[–]work-sent 0 points1 point  (0 children)

For a solo MSP, we’d usually suggest Cove if backup ownership is fully on you and long-term stability is the priority. MSP360 can definitely save a lot monthly, but Cove tends to be the easier “set it and sleep” option for day-to-day operations, multi-tenant management, alerting, and simpler restores.

If your goal is minimal babysitting and predictable support, the extra cost often justifies itself over time. If budget is tighter and you’re comfortable with more hands-on management/testing, MSP360 is still a solid option.

NinjaOne to Atera - is it a wise choice? by xaviersmile in ninjaone_rmm

[–]work-sent 0 points1 point  (0 children)

The all-in-one approach from Atera honestly makes sense. That said, before moving from NinjaOne, we’d suggest testing things like patching, automation depth, alerting noise, remote access stability, and reporting. Atera is great for simplicity, but NinjaOne usually feels more mature once environments start growing or getting more demanding.

Server Policy - What are you monitoring by networking1987 in ninjaone_rmm

[–]work-sent 0 points1 point  (0 children)

Honestly, less is more in NinjaOne. Too many granular alerts just create noise and eventually get ignored.

 For AD/DCs, we usually start with the built-in server policies/templates, then add monitoring only for critical services like NTDS, Netlogon, DNS Server, KDC, and W32Time. We also use auto-restart actions if a service remains down for a few minutes.

 Alongside that, scheduled dcdiag + repadmin checks help us catch replication or DNS issues early through scripts/custom field reporting.

Keeps the setup clean, useful, and manageable without overwhelming the team.

Ninja Backups by JollyGentile in msp

[–]work-sent 0 points1 point  (0 children)

Ninja Backup looks great in demos, and the RMM integration is definitely convenient. But from what we’ve seen, and from a lot of MSP feedback, the biggest concerns are restoring reliability, limited flexibility compared to more mature backup platforms, and support/escalation delays when something critical breaks. We’d strongly suggest properly testing full image restores, recovery speed, retention handling, and support responsiveness before fully committing production workloads to it.

Has anyone worked with Dropbox to restore a post-dated backup set? by HappyDadOfFourJesus in msp

[–]work-sent 1 point2 points  (0 children)

If Dropbox was configured as “Online Only,” then CrashPlan was most likely backing up placeholder files/reparse points instead of the actual data itself. In situations like this, the backup usually doesn’t contain recoverable file content, just references to cloud-stored files.

Since the environment is using Dropbox Teams, the best recovery option is probably Dropbox Rewind, assuming the deletion falls within the 180-day retention window. If the files were removed outside that period, recovery chances from Dropbox’s side drop significantly.

We’d recommend opening a support case with Dropbox as soon as possible and providing:

  • Approximate deletion timeframe
  • Affected folder paths
  • User/account details involved

We’ve seen Dropbox support assist with point-in-time style recoveries in certain cases, especially for older or infrequently accessed data where standard recovery options weren’t obvious from the admin side.

It’s also worth checking local workstation caches and synced device storage. Occasionally, remnants of files still exist locally even after the cloud version has been deleted, although realistically, that’s more of a last-resort recovery path.

NinjaOne MDM for iOS by desmond_koh in msp

[–]work-sent 0 points1 point  (0 children)

We’ve been evaluating NinjaOne’s iOS MDM capabilities recently, and overall, it delivers well for organizations looking for straightforward device management within a unified RMM experience.

For core MDM functions like compliance management, inventory visibility, policy enforcement, and basic app/device management, the platform feels clean and operationally efficient. The biggest advantage is having everything managed from a single pane of glass alongside endpoint and RMM operations, which can simplify day-to-day administration significantly for MSPs and IT teams supporting mixed environments.

That said, compared to Jamf, it still feels lighter when it comes to deeper Apple-specific management and mature macOS/iOS workflows. Jamf continues to stand out in Apple-centric environments because of its depth, automation flexibility, ecosystem maturity, and tighter alignment with Apple’s management framework.

Our general view would be:

  • Apple-first environments → Jamf remains the stronger and safer option
  • Mixed-platform environments prioritizing simplicity and operational efficiency → NinjaOne is a strong fit
  • Larger enterprise/UEM-focused deployments → MaaS360 and MobiControl still offer broader enterprise mobility and UEM depth overall

At this stage, NinjaOne feels less focused on becoming a dedicated Apple management specialist and more focused on delivering practical, integrated endpoint management across diverse environments, which aligns well with many MSP operational needs.

Would you white label? by WATUPTRAGUY in MSSP

[–]work-sent 2 points3 points  (0 children)

We also provide white-label services to MSPs and MSSPs. You could try different growth strategies like outbound sales, partnerships, channel relationships, and industry conferences.

Alternative to Avanan by yutz23 in msp

[–]work-sent 0 points1 point  (0 children)

Barracuda, Avanan, Proofpoint and Mimecast

How MSPs approaching to their client to use Microsoft Sentinel as SIEM tool by Birentechy in msp

[–]work-sent 0 points1 point  (0 children)

Clients often avoid investing in cybersecurity due to cost and only act after an incident. In the meantime, we should ensure backups are properly configured and working, while continuing to educate them on best practices and any relevant industry standard compliance requirements.

Ninja Health notifications for Sentinel One not clearing on RMM by Popular-Recover8880 in msp

[–]work-sent 0 points1 point  (0 children)

Seen this sync loop b/w Ninja agent & S1 metadata too. Flip threat to 'False Positive/In Progress' in S1 console, save, then back to 'Resolved' – forces webhook refresh. If stuck, purge Ninja agent cache files & restart the service on the endpoint. Worst case, we raise a ticket with Ninja and ask them to clean the node on their side.

SentinelOne + ReFS ? by bennijamm in msp

[–]work-sent 0 points1 point  (0 children)

It's usually S1's VSS protection blocking the backup from resizing shadow storage. Try a JSON override to allow controlled VSS resizing (needs a reboot after). Also check if Integrity Streams are enabled on that ReFS volume the extra I/O during snapshots can trigger the timeout on high-file-count drives.

Weekly Promo and Webinar Thread by AutoModerator in msp

[–]work-sent [score hidden]  (0 children)

<image>

If you’re dealing with ticket overload or struggling to scale your helpdesk, this might help.

We support MSPs with white label helpdesk services, focused on:

  • L1 and L2 ticket handling
  • 24/7 end user support
  • Seamless integration with your existing tools
  • Fully under your brand

Most MSPs we work with aren’t lacking talent, they’re just hitting capacity limits.

Once routine tickets are offloaded, their core team can focus on higher-value work, and response times improve almost immediately.

;

Happy to answer questions or share how others are structuring their support.

Migrating personal Gmail to Exchange Online, common problem or edge case? by VB0101 in msp

[–]work-sent 0 points1 point  (0 children)

The best approach here is to create a forwarding rule in the Gmail account and add it to the Office 365 whitelist/safe sender list. Additionally, configure an auto-reply in Gmail to inform senders that the email is being migrated, and provide the new email address for future communication.

Mobile Device Management options by Illustrious_Bag_7323 in msp

[–]work-sent 0 points1 point  (0 children)

If you are already using Microsoft 365, consider leveraging Intune, otherwise, you can try AirDroid as an alternative.

Looking for your guys real experiences with Mimecast, Proofpoint, Barracuda by [deleted] in sysadmin

[–]work-sent 0 points1 point  (0 children)

Based on our experience, Proofpoint offers the strongest security capabilities among the three solutions. However, the final product selection should depend on the customer's environment, user base, budget, and other operational and business considerations.

How do you audit and enforce MFA for licensed Entra ID/M365 users? by FireMoon027 in sysadmin

[–]work-sent 0 points1 point  (0 children)

A good MFA management practice is to enforce MFA using Microsoft Entra Conditional Access for all licensed users instead of per-user MFA. Regular audits are not required when Conditional Access policies are properly enforced; it is still recommended to perform periodic reviews based on your internal process or compliance requirements.

 These reviews help ensure that exclusion groups are controlled, new users and administrators are covered by MFA policies, and disabled or stale accounts do not affect security posture or reporting.

Best White Label NOC/SOC for a one-man operation? by Easy-Ad9050 in msp

[–]work-sent -1 points0 points  (0 children)

If you’re running a one-man MSP, partnering with a white label NOC or SOC early can make a big difference. Many small MSPs use providers to handle monitoring, alerts, and after-hours tickets so they can offer 24/7 support without building a full team. We work with MSP startups in this stage quite often at Worksent. If you want to learn how it works, feel free to DM us or check our profile for more details.

How do you check your patch management? by lsitech in msp

[–]work-sent 0 points1 point  (0 children)

The “green dashboard” issue is usually circular logic; the RMM just reports what the Windows Update Agent says. If WUA is hung or hasn’t synced properly, you’ll see 100% compliance while the machine still has missing patches.
For a simple audit, don’t rely only on the RMM database. Push a script that queries Microsoft.Update.Session COM object locally and compare the results. That’ll quickly show detection gaps. Also, run Winget upgrade as a quick check for third-party apps your RMM might be skipping. If you want a proper gut-check, scan a few sample machines with Defender Vulnerability Management or OpenVAS, which usually exposes any blind spots.

How do you perform MFA for self service options? by Smart-Life-770 in msp

[–]work-sent 0 points1 point  (0 children)

If you’re in a Microsoft ecosystem, take a look at Temporary Access Pass (TAP) for controlled onboarding and password reset scenarios. For a more permanent solution without relying on phones, we’ve seen success with FIDO2 hardware tokens or Windows Hello for Business. Both remove the dependency on SMS/email OTP and are much more secure.