June 12, 2026 • 5 min read
The MSP Security Stack of 2026 (Part 1)

This is the first in a multi-part series covering what I consider to be today’s ideal security stack for MSPs. Over the past 15 years, I have written this series three times, for ChannelPro, Business Solutions, and others. Of course, there have been significant changes over this time, and the pace of those changes has done nothing but accelerate.
Way back in the old days (15 to 20 years ago), many MSPs relied on just three things: patching, antivirus, and a perimeter firewall. We also generally assumed we were defending an office perimeter. None of these ring true today. But even the complexity of doing that well is vastly greater than it was in 2010. We also have more and better tools, but we face far more numerous and capable adversaries, not to mention AI-driven attacks. The net result is greater complexity and more distributed risk, so it is through that lens that we will focus going forward.
First, Some Assumptions About the Modern MSP Security Stack
I assume you have an effective patch management process in place, as well as internal vulnerability management (they are not the same thing). Further, I assume that you have a modern, managed firewall in place (or ZTNA services that obviate that need). Lastly, I want to stress that we are not talking about compliance issues here, just security.
Five Core Areas of the 2026 MSP Security Stack
I will focus here on IAM, EDR/MDR & PAM, M365 protection, and protecting connection pathways by means of proxied RDS and ZTNA technologies. If the timing works out right, there might even be a bonus round specifically focused on defense against AI-driven attacks, if we are not yet all enslaved by our robot masters. Just kidding here.
In this first article of the series, I will briefly touch on each of those challenges, to “sell” you on why they are each so critical. The rest of the series will drill down on each specific aspect of your security stack, going into greater detail and helping to thread it all together. Here is a quick overview of what we will be covering going forward, as of today.
Identity and Access Management (IAM)
The way I see this, modern IT security begins with identifying and managing identity. As simple as that may sound, the MSP industry was slow to key into this, for years dancing around this requirement. Then suddenly, the space exploded, with tools popping up faster than an IT analyst can plot them on a graph or spin up acronyms.
As with so much else in IT, there is overlap between IAM and other technologies, such as MFA (multi-factor authentication) and SSO (single sign on), not to mention PAM (privileged access management). In this series, we will focus first on these technologies and how they verify identity, provide privilege elevation on demand (when justified), and manage the user experience.
I want to digress and point out that ID Verification is an oft-overlooked aspect of IAM. Ideally, this both verifies the identity of end users requesting support and enables your staff to verify those end users as who they purport to be. Nothing puts a screen door on a submarine faster than allowing “Microsoft support” into your sites, making ID Verification crucial.
Endpoint Detection & Response (EDR) and Privileged Access Management (PAM)
EDR was new to many of us just a few years ago but is nearly ubiquitous now. EDR is a newer solution, notable for using behavioral (or heuristic) analysis of activity rather than simply using pattern files to match attack fingerprints.
MDR builds upon that adding log analysis and response (usually delivered by a 24×7 SOC), working in the background behind your EDR agents. Between the endless new attacks and their ability to change to avoid pattern file recognition (polymorphism), EDR grew from the necessity to update and replace traditional AV technology.
Privileged Access Management is part of this same conversation because endpoint protection alone does not control when, why, and how elevated privileges are used. For MSPs, reducing standing admin access and managing privilege elevation on demand can limit the damage caused by compromised credentials or misused administrative accounts.
Protecting Microsoft 365 Tenants
Not long ago, the only thing most MSPs did around protecting their client (or their own) M365 tenants was spam filtering and phishing detection. But today the focus has shifted to more secure tenant configuration emphasizing such things as tenant hardening, anomaly detection/alerting, identity management, and backup/recovery services.
There are dozens of offerings for configuration and hardening. Anomalous behavior detection is also rapidly advancing, with standalone M365 tools and capabilities integrated into larger suites of products. Identity Management tools, as well as backup and recovery tools are also widely available and improving fast (again, M365 focused or part of larger suites).
Zero Trust Network Access (ZTNA)
This brings together aspects of remote access and identity management. ZTNA is the next step as you migrate from traditional remote access methods such as IPSEC and SSLVPN to modern technologies including proxied RDP/RDS and Secure Access Service Edge (SASE). This also encompasses securing access to cloud resources with the same tools you use to secure access to on-premises equipment, potentially incorporating all of this into one solution. There are already many offerings out there from vendors as diverse as firewall vendors and providers of “pure” ZTNA solutions. This is a rapidly growing field but should not be confused with “traditional” Zero Trust solutions.
What Comes Next in the Series
This will be an ambitious set of articles, covering what may be the fastest moving target in our industry. My goal is not to preach but to take you through the process I have used to design this stack. I hope to both lead you down your own road, and to improve it as we do so together. If you stick around for the entire series, we will work together to build your own perfect stack.
About the author: Joshua Liberman is a longtime MSP and IT security practitioner with an established presence in the MSP community. He has written and spoken extensively about security, managed services, MSP operations, and technology stack design for service providers.

