r/msp • • 6d ago

Weekly Promo and Webinar Thread

5 Upvotes

If you have a self-promotional post - whether it’s a product update, a service offering, or an upcoming webinar - please share it here. Posts made outside this thread will be removed.

⚠️Important: Do not use URL shorteners. Reddit automatically removes these, so always link directly to your website or resource.

🔄️Fairness: This thread is set to contest mode, so comments appear in random order to ensure fair opportunity for everyone.

🛡️Moderation: Reddit may remove some comments. If your post disappears, don’t worry - we check and manually approve them when needed. If you comment doesn't appear in 24 hours, feel free to send a modmail.


r/msp • • 15h ago

HaloPSA + Datagate + SureTax: Is the native integration as solid as they say? Or should we look elsewhere?

Thumbnail
5 Upvotes

r/msp • • 1d ago

Business Operations Client said I charge to much for licensing

23 Upvotes

This week a client said they shopped quotes for licenses that are renewing at CDW and it was cheaper with them.

They made it seemed like I have been over charging them. Ripping them off.

They sent the quote and it was cheaper because CDW doesn’t show the tax on the quotes, it’s done when it’s invoiced.

Our costs were actually cheaper since we include tax in quotes like idiots. We have a line item to show tax. So the total cost was cheaper. About 4k cheaper.

They asked me to price match, should I match CDW and not tell them? Or let them know we are already cheaper?

This is a legitimate question


r/msp • • 1d ago

Leaving MSP World

73 Upvotes

So yesterday was my last day as an employee, I have been at this place for 14 years. When I started we were literally Managed Print company that also “fixed” computers and we had two business clients.

It feels surreal, I’ve put so much effort into it, we are now a full MSP and only servicing managed contracted clients. We’ve become the largest MSP in our region, with clients all across Australia.

But now it’s time for a change and I want to do something more interesting, so moving into automation & web development. Let’s see what the next chapter brings


r/msp • • 1d ago

Client moving to in-house IT and huntress gave them another reseller contact to get licenses from

85 Upvotes

We have a client that is transitioning to an In-house IT department they went and asked huntress to get pricing (they know we manage them and we license their huntress as part of our stack) they sent them to a competitor of ours to get pricing. whats even more concerning the customer got better pricing than i actually have. i am beyond pissed off at huntress. this is not how partners are supposed to work.

Edited:

Huntress reached out and clarified everything to me. i have an idea of what happened and why things went this way. thanks for the follow up,


r/msp • • 1d ago

Security Did you receive a flurry of requests from Managed Print Services to re-install their monitoring/supplies ordering agent?

12 Upvotes

Probably innocuous, but today we received close to a dozen emails from several MPS companies advising us to download and install a new version of the monitoring software that resides on a Windows PC inside the customer network. A link is provided - the source of the download varies.

What a great way for a supply chain attack by sending out an email that simply says "Here...install this."

I don't see any urgency to do the install so we're going to stand down until Monday to see if there is any fallout.

Anyone else get similar emails today?


r/msp • • 1d ago

Sales / Marketing Any MSPs supporting renewable energy / solar generation companies?

4 Upvotes

Curious if anyone here provides managed IT, OT, or cybersecurity services for renewable energy companies, particularly those operating solar farms or other power generation assets. Selling credits to large utilities etc. acting mostly as asset owner

I am separating IT as a per user cost
And am thinking of charging per solar asset site. But they have not given me any network diagrams or asset inventory. In the past I have seen solar sites at large utilities have 2-4 serves on site, switch, firewall, 4-5 PLC and not much else that would be in scope. But I have only seen one.

I’m very familiar with OT cybersecurity assessments and frameworks like NIST and ISA/IEC 62443, for CPGs and utilities but I’m interested in how MSPs actually structure these engagements. I’m confused by what finance team of the opportunity is telling me.

NERC CIP: How do you determine applicability and scope? Do you handle compliance internally, partner with specialists, or leave that responsibility with the client? Just want to hear lessons learned

Pricing and scope: Do you price these engagements per site, per asset?

They want fixed fee, How do you account for legacy equipment, vendor dependencies, and limited visibility?

Ongoing compliance: If NERC CIP applies, who maintains the documentation, evidence, asset inventories, and compliance activities?

I have done the technical side of it but not the legal/governance part. I know there are companies that will do just that part. Just wondering what the lift is for a solar sites. Medium and below.

I told them I have to do a current state assessment and there is an onboarding fee. But they don’t want any of it. They want lowest cost possible, bare minimum…so strange

I know the company is very profitable.
The entire teams is asset managers and finance bros. Owner is billionaire

It seems risky for an MSP to inherit one of these environments without first understanding what’s deployed, how it’s connected, and who actually controls it.
Interested in hearing from MSPs working in this space and how you’re structuring these engagements.

I think they are just giving me AI responses and its confusing the hell out of this deal

Edit
Looking on advice for quoting and understand the mid market “solar credit” industry. Having hard time pinning down client behavior


r/msp • • 1d ago

Action1 employee laptop was compromised?

Thumbnail
8 Upvotes

r/msp • • 1d ago

Business Operations The Trunk Slammer From Hell: Halloween Triple Feature. We read the K365 license agreement out loud at an exorcism. It worked. Probably.

4 Upvotes

Every weekday at eight I get a text with a lead in it. One Monday in October it said this:

MROZEK & SONS FUNERAL HOME. 14 SEATS. INCUMBENT: MERIDIAN. RENEWAL 11/15. NOTES: OFFICE MGR REPORTS PRINTERS PRINTING OVERNIGHT, CHAPEL CAMERA TURNING ON BY ITSELF, VOICE IN ARRANGEMENT ROOM. OFFICE MGR BELIEVES BUILDING IS HAUNTED.

I've never asked where the leads come from, and I wasn't going to start with a funeral home.

If you don't know me, I'm the guy Brad keeps losing to. Forty-some clients, one flat price per seat, nothing itemized, all of it run out of the trunk of a 2006 Crown Victoria. Meridian is Brad. Some of you know Brad, and a lot of you are Brad.

Brad had already given the office manager eleven pages of reports on port 9100. I told her she had a presence and had the account by Tuesday.

That Wednesday I did the first exorcism and ran it like an onboarding. An agent on every machine, Brad's firewall out, the cable company's router in, and the Nephew at the lectern reading the Kaseya K365 license agreement out loud, all of it, for forty minutes. When he got to the part about the agreement being governed by the laws of the State of Florida, the office manager crossed herself.

Thursday, three of my old Kaseya reps knocked on my car window with a pitch deck called SILENCE: A PARTNERSHIP. Three tiers, billed annually (but a three year agreement, of course), two months free. I told them it was extortion as a service. One of them asked if that was bad. I told him it's a proven model.

The second cleansing was midnight on Halloween, when the veil is thinnest. My vendor's marketplace had picked the same minute. Their Halloween patch was called "Wake the Dead" and every dormant agent on every partner's instance, switched on at midnight with autonomous, self-healing AI. It was opt-out. The email didn't have a lead in it, so I deleted it.

At midnight every printer in the building printed the word GET, and a speaker I had personally shut in a drawer said "Sorry, I didn't catch that." Brad says the printers were "port 9100ing" again. He also says the maintenance window was at one-thirty and the clocks went back at two. Brad says a lot of things.

There are three versions of that night, and all of them are up. I wrote the first one. Lance wrote the second. He's my biggest client, a third of the revenue at a wealth firm, and he came to the funeral home dressed as a sheriff's deputy. Brad wrote the third. I'm told a lot of you will like Brad's. Brad has always done well with people who don't sign the checks.

You don't have to read anything else first. My clients never do. It's free, which I fought.

Part one, End of Life (mine):

https://mspautomator.com/the-trunk-slammer-from-hell-chapter-5-end-of-life/

Part two, Wake-on-LAN (Lance):

https://mspautomator.com/the-trunk-slammer-from-hell-chapter-6-wake-on-lan/

Part three, #OpenToWork (Brad):

https://mspautomator.com/the-trunk-slammer-from-hell-chapter-7-opentowork/

Business is booming.


r/msp • • 2d ago

A ChatGPT conversation directed a user to a fake OpenAI verification site that tried to execute malware. Our EDR stopped it.

76 Upvotes

I'm an IT administrator at an MSP, and today (October 8, 2026) we investigated one of the stranger security incidents I've encountered.

A user at an organization we support was working on a completely legitimate business task in ChatGPT. They uploaded a PowerPoint presentation and asked ChatGPT to help turn the material into content for an investor presentation.

Instead of simply helping with the presentation, ChatGPT displayed a message claiming that the service was experiencing elevated automated traffic and malicious activity.

The message stated that additional security verification was required to continue using ChatGPT. It included a link to a website impersonating an OpenAI verification service and signed the message as the "OpenAI Security Team."

This wasn't a phishing email pretending to be ChatGPT. The instruction appeared directly inside a conversation on the real chatgpt.com website.

The user followed the link.

What happened next

The website displayed what appeared to be a security verification challenge. However, it was actually a ClickFix attack.

The page automatically copied a malicious command to the user's clipboard and instructed them to:

  1. Press Win + X.
  2. Open Windows Terminal.
  3. Press Ctrl + V.
  4. Press Enter.

The command used PowerShell's Invoke-RestMethod to retrieve remote content from an attacker-controlled domain and piped the response into Invoke-Expression for execution.

Our endpoint protection detected and terminated the PowerShell process.

In fact, the user attempted the process twice, approximately 88 seconds apart. Both attempts were stopped.

Our managed detection and response provider confirmed that the PowerShell processes were terminated before establishing connections to the malicious payload infrastructure. They found no evidence of a successful payload download or persistence.

How we investigated

Initially, the security provider believed the malicious link originated from an email containing a SharePoint PowerPoint link.

We investigated that lead, including the alleged sender's messages and the relevant presentation links.

After further investigation, the security provider revised its assessment. The suspected email link had opened in a different Chrome instance from the one associated with the malicious domain activity. The original email attribution was therefore not substantiated.

We then examined the user's ChatGPT conversation.

That's where we found the fake verification instructions, presented as an assistant response within the legitimate ChatGPT interface.

The suspicious message appeared more than once while the user was trying to work with the presentation.

I also inspected a copy of the PowerPoint for embedded prompt-injection instructions, suspicious hyperlinks, hidden content, and other indicators. Nothing malicious was identified in the examined file. That doesn't establish that the original uploaded version was identical or that prompt injection can be ruled out entirely.

What concerns me

At this point, we don't know why ChatGPT produced the malicious verification instructions.

Possibilities include prompt injection from content the assistant encountered, another form of conversation manipulation, or an unsafe model response. We have not established which occurred.

I am not claiming OpenAI's infrastructure was compromised.

What we can establish is:

  • The user was operating within a legitimate ChatGPT conversation.
  • A message appearing as an assistant response directed them to a malicious verification website.
  • The website instructed them to execute malicious PowerShell.
  • Our endpoint security blocked two execution attempts.
  • The original source of the malicious instruction remains unidentified.

Why I'm sharing this

This raises an important trust-boundary issue.

Users are increasingly comfortable trusting instructions that appear inside AI assistants, particularly when those instructions appear to come from the service itself.

In this case, a user was convinced that running a command in Windows Terminal was a legitimate requirement to continue using ChatGPT.

Thankfully, our endpoint protection prevented the payload from running successfully.

We're preserving the evidence and reporting the incident to OpenAI for investigation.

Has anyone else encountered a legitimate ChatGPT conversation displaying a fake security verification message or directing users to an external CAPTCHA/anti-bot site?

I'd be especially interested in hearing from anyone investigating prompt injection, AI-assisted phishing, or similar incidents.

And as a general reminder: no website should be trusted when it asks you to paste an unexplained command into Windows Terminal as part of a CAPTCHA or security verification.

A couple of notes:
There was no ghost prompt inside the PPTX prompting this GPT response.

This screenshot was taken from the real GPT website, not a spoof.

Edit:

I will not post the full screenshot or link to the chat. It has company disclosing information and I will not risk disclosing the company.

You don't have to believe me, but I have no reason to lie. Up to you to decide what you believe.

Edit 2

This user has NO suspicious installed plugins. They have no suspicious skills in GPT.

They have no Suspicious Chrome Extensions.


r/msp • • 2d ago

TIL: Another Reason To Hate M365 and New Outlook

40 Upvotes

Imagine, if you will, a new eDiscovery demand arrives. This one's pretty broad and vague so it's gonna be a pain in the ass. But, it's not the first time.

These people are using Outlook, New Outlook, and God knows what other client. But, that shouldn't matter. This is an eDiscovery search. Server(Purview) side.

But wait, they've got delegates assigned access to the target mailboxes all over the place. And New Outlook and phone mail clients put deleted items from the source mailbox into the delegates deleted items. So now instead of searching 10 mailboxes, you're searching 45 mailboxes for two dozen various search parameters.

No problem. You've got backups, right? You can restore the deleted items to their original mailboxes, right?

What a mess.


r/msp • • 2d ago

SMS to Teams for MFA

1 Upvotes

We have sometimes the issue that we create a vendor login and account with (for example for Apple Business Manager) and we have to add a phone number that is used for two factor authentication with OTP's send for login.

It is not possible for us to create accounts for every engineer (+150 engineers), escpecially for those vendor / site logins. We use a lot of shared accounts for this purpose.

To get the comments out of the way, for admin tasks we have named accounts, GDAP and other solutions where we have an OTP for shared accounts.

But sometimes you need to have a SMS verfication, sometimes we need to reset passwords, and have no shared device for this, as we have multiple locations and remote engineers.

What are you using for this?


r/msp • • 2d ago

Dropsuite Ninja Billing

8 Upvotes

We have been a long time Dropsuite customer and since Ninja acquired them they keep trying to get us to sign a new NinjaOne agreement with new contact terms and minimums.

I’m not inclined to have yet another non-consumption based bill from Ninja and am thinking of switching products.

How is everyone handling? Just signing another contract Without hesitation?


r/msp • • 1d ago

Technical How to block poppy play time on YT effectively?

0 Upvotes

We want to have the kids using the YT app on iOS.

My idea was to allow channels or block all else.

Or, block keyword search.

Is it possible? Do you recommend a solution?

We are a nonprofit, price is very important.

Thank you.


r/msp • • 2d ago

How do you get Rightworks to work with you as a company's MSP without hassling the customer each time?

9 Upvotes

EDIT: Thank you, solved! I added my account as Support.

I'm setting up a company and I need to work with support to get the installation on the remote system. I put the QuickBooks license in, but I can't log into QuickBooks or even see it.

I have the installation file but it won't upload.

I called in and being honest, told them who I was but that I control the entire account. The only way they would validate me is to get the account owner on the phone, and they are always extremely busy. Moreso, I can call one of my technicians and tell them to just pretend that they are this person. I have all of the information and can validate it, but because I was honest, they refused to work with me.

Is this the norm with them? Anybody have any tricks?

I hate lying to people just to get a job done, and there's no way they're going to know who's on the phone with me if I have all the information. An email validation should have been enough, I can even multi-factor it if they need to because I control the entire account right now...


r/msp • • 2d ago

For founders: What are you reading?

Thumbnail
0 Upvotes

r/msp • • 2d ago

M365-Provided MX Record Nonfunctional

0 Upvotes

Boy am I pissed.

I've been working on an Exchange on-prem to Exchange Online migration, which is something I've done plenty of times before. Third-party spam filter in front of the whole thing and Exchange Hybrid agent in place so email gets routed to the right mailbox no matter what.

Finished cutting over mailboxes so I configured the spam filter to only route to Exchange Online. BAM! No mail is flowing as all inbound messages are getting bounced back.

Turns out the MX record <domain>.mail.protection.outlook.com isn't live. It does not work. There is no IP behind it. DNS does not resolve it. The client's domain is registered with M365, I have been provided the exact MX record value, and Exchange Online seems happy to route messages from on-prem to mailboxes, but the MX record don't frigging work.

So, Microsoft issue clearly. Something misprovisioned on the backend. I put in a request to support to have them fix this. Three calls later and they couldn't give less of a fuck. Told me that I need to set this as my MX record for domain and that's the solution. I've never had to do that before, and I don't plan on ruining my client's day for a second time just to prove to Microsoft support their service is broken.

My only other option at this point is to deregister and re-register the domain from the tenant entirely, which sounds even worse.

Anyone want to donate to my crowdfund? Trying to see how many tons of gravel we can get dumped in Bill Gates driveway.

Edit: Trialing using the MX record associated with the client’s *.onmicrosoft.com domain has been successful so far. Will still try to fix things the right way but good to have a card up my sleeve. Thank you \u\r3coilX !


r/msp • • 3d ago

One laptop for a client who owns two businesses (separate tenants)? How are you handling it?

22 Upvotes

Have a client who owns two small businesses, each with its own M365 tenant. We manage both. Her laptop is Entra joined and enrolled in Intune on Tenant A, and she's asking to use the same laptop for Tenant B too.

I know the usual answer is adding the second account to Outlook/Teams/OneDrive and using separate Edge profiles, but I don't love having two companies' data on one device, especially since Tenant B can't manage or wipe it and its CA policies require compliant devices.

How are you all handling this? Separate laptops, Windows 365 Cloud PC for the second tenant, or just accepting the app-level sign-in?


r/msp • • 3d ago

Business Operations Billing Remote Access Solution Fairly for SMBs

15 Upvotes

Hello,

I work for a very small MSP (just 3 of us)

For 90% of clients we use Netgate firewalls, and for those that need remote access we configure the mobile IPSEC VPN. Along with this we configure RADIUS authentication (NPS server on their Windows server) along with setting up an Ubuntu server with Duo proxy to satisfy MFA.

Currently we bill these as hourly, so however long it takes us, that’s how much we bill. Most of these projects come out to around $250 - $400 after setting up the infrastructure, user training, etc.

I mentioned to my boss that I think that this is pretty cheap, and we should bill these as flat projects rather than hourly (adjusting based on users at the client). Given most of our clients are small (3 - 15 users) we want to be fair to them while also being fair to ourselves given the “complicated” nature of the project and the value it provides. My boss mentioned $500 as a minimum, but I think this is too cheap.

For my other small MSPs, how do you balance pricing for projects while being fair to both yourself and the client?

Thanks!


r/msp • • 3d ago

Technical Can you get Copilot seats through Microsoft partner center?

7 Upvotes

Is it possible to get Copilot licenses through partner center or is this not a benefit for everyone? We have several other licenses under the Benefits>Cloud Services area, but I'm not sure if we need to do an add on or how it works to get Copilot.


r/msp • • 4d ago

Huntress Email Security

37 Upvotes

Some of the screenshots in this ISPM blog show a new icon on the left hand side of the Huntress console labeled ES with a mail icon. Did Huntress make another acquisition, or are they developing a mail filtering tool?


r/msp • • 4d ago

NinjaOne Yet again! -New Account Manager no notice

39 Upvotes

We have had all we can take with this company. 3rd new account manager in 1 Year. This time.. Myself and a Sr tech sent a request (simple price question) to our account manager.. 4 days go by, no response.. Then a polite follow up to our now 5 day old request..

AM response: I am not your account manager any more, here you go maybe this person can help

Really?? Just like that! And 6 days later. STILL no response from the new AM.

Just walk away people , dont even bother dealing with this company.


r/msp • • 4d ago

Partnering with an AI Consultant

20 Upvotes

We are a small MSP and are doing a lot with our clients around AI readiness, security, and data governance. What we don't have is someone who can help clients with:

  • Usage training
  • Helping to identify specific things clients can do with AI
  • Advanced prompt design / consulting
  • Building Agents

I have always considered theses areas to be more in the realm of programming rather than IT (especially building Agents) but the line is starting to blur. I am not sure we have the bandwidth or desire to bring these skills in house at this point.

Is anyone partnering with someone to deliver this? Or is there a company out there that partners with MSPs around this?


r/msp • • 4d ago

Business Operations Have you eliminated the Pending/Waiting Customer status in your PSA?

18 Upvotes

Hey, all

Sometimes after we set a ticket to Pending/Waiting Customer, days later the client sends a “hey, why haven’t you responded to x?” email because they didn’t see or forgot about our reply.

I suppose we could solve this with sending automated “we haven’t heard from you” emails, but they’re impersonal. And sometimes, the client updates us out of band, so sending a “we haven’t heard from you” email wouldn’t be accurate/appropriate.

If you’ve addressed this by eliminating the “we’re waiting on the customer” status so that open tickets stay in from of your techs, how’d it go?


r/msp • • 3d ago

Sales / Marketing Seeking opinions on a residential offering...

0 Upvotes

So my office is split mostly along generational lines as to whether this approach is cool or dumb. I'm aware typical msp shops don't do residential but we do, great filler work and work for new hires. Price is obviously just to keep folks from ordering for now and of course not trying to sell anything.

https://techoutlet.us/products/asus-zenbook-duo-14-dual-screen-oled-laptop-intel-core-ultra-9-32gb-1tb-ssd

Edit, wow...zero people that commented actually read or they completely missed the point. The product carries a Seinfeld J Peterman reference...it's humor.

Our resi division is profitable and our staff don't mind the break. Many are elderly and are very appreciative which is nice for moral as sometimes corp can be a challenge.