Articles
Security knowledge for MSPs
Guides on Microsoft 365 security, identity, posture management, and the external attack surface for MSPs.
Identity & Access
Reviewing tenant identity, admin roles, and delegated access across customer tenants.
Entra ID & Conditional Access Review for MSPs
A per-tenant checklist for Conditional Access, MFA gaps, legacy authentication, break-glass accounts, and privileged roles.
Read article →GDAP Explained: What MSPs Need to Know About Microsoft's Delegated Admin Model
What changed from DAP to GDAP, why least-privilege and time-bound roles matter across a portfolio, and what to check in your own GDAP relationships.
Read article →Monitoring and Alerts
What to track for security drift across Microsoft 365 and the external attack surface.
External Attack Surface Monitoring
Subdomains, exposed services, open ports, and certificate expiry outside the Microsoft 365 tenant, and what discovery should cover.
Read article →MSP Security Monitoring: What to Track Across Every Customer Tenant
Why asset inventory is not security monitoring, and what to track across Microsoft 365, the external attack surface, certificates, and CVE exposure.
Read article →Subdomain Takeover: How MSPs Detect and Fix Dangling DNS Records
How dangling DNS records turn into takeovers, the checks that catch them across a portfolio, and the order to fix them in.
Read article →Email & Domain Security
Authentication and branding standards for every client domain.
SPF, DKIM, and DMARC Checklist for MSPs Managing Multiple Client Domains
A rollout order for SPF, DKIM, and DMARC across every client domain, the alignment failures that break enforcement, and how to track status across a portfolio.
Read article →BIMI for MSPs: What It Is and Whether It's Worth Setting Up for Clients
What BIMI actually requires, what it does not do, and how to decide which clients are ready to set it up.
Read article →Web & Application Security
Externally checkable gaps on customer-facing websites.
Exposed .git and .env Files: How MSPs Find Them on Customer Websites
Why a misconfigured deploy leaves source history and credentials one HTTP request away, and how to check for it across every customer site.
Read article →Security Headers Checklist: CSP and HSTS for Client Websites
Which HTTP security headers actually matter, the rollout order that avoids breaking a site, and how to track coverage across a portfolio.
Read article →Ready to continuously monitor your customer environments?
Request a demo to see customer workspaces, Microsoft 365 posture, findings, and reports in one platform.
Request a demo