Start Free Trial

Free Trial is currently available for our Business Plans.
Please choose an option that meets your trial needs below

SecureRDP Icon

SecureRDP Business

$15 per user per month

Starts at 20 Users / unlimited computers

No credit card required

SecureRDP Icon

BitLocker Business

$2.22
per computer per month

Minimum 20 Computers

No credit card required

Compare all plans & features on the Pricing page

Blog

The MSP Security Stack of 2026 (Part 2)

The MSP Security Stack of 2026 (Part 2) - Identity & Access Management (IAM)

Identity & Access Management (IAM)

This is Part 2 of the MSP Security Stack of 2026 series by Joshua Liberman. In Part 1, we mapped the five core areas of the modern MSP security stack. Here, we go deeper on the first of them: Identity & Access Management.

Why Identity Is the New Perimeter for MSPs

SonicWall recently wrote that “identity has become the new perimeter” in the sense that most attacks begin by compromising identity. And that is why we are starting here with what I believe should be the primary focus of modern IT security, Identity & Access Management, or IAM. (I miss the days when a firewall and antivirus client constituted a full security stack.)

Although there is no universal definition of IAM, for the purposes of this article, I will consider IAM to consist of multi-factor authentication (MFA), single sign-on (SSO), and password management. (We will also touch upon Secure Configuration Management, or SCM, of the M365 tenant briefly, though that will be covered in more depth in a later article.)

Multi-Factor Authentication (MFA): Beyond SMS

The days of relying upon traditional credential sets (username/password) are long gone. Just a few years ago, delivering a second factor by SMS (texting) was common. In fact, NIST now classifies SMS and voice delivery as “RESTRICTED” due to risks such as SIM swapping and number porting, and CISA considers it the weakest form of MFA, to be used only as a last resort. Today, for many organizations, authenticator-app-based MFA (especially TOTP) is the most common approach.

Recently, we have seen the proliferation of MFA across devices and services. More security-mature organizations are also beginning to move beyond traditional password-plus-MFA workflows toward passwordless and more phishing-resistant approaches, including FIDO2 keys, passkeys, and device-bound authentication. While not yet universal, they are the future.

MFA and Cyber Liability Insurance

Cyber Liability coverage is increasingly requiring demonstrable MFA implementations for access to all devices, local and remote, and many highly security-conscious entities have done this for years. Some address this entirely within the Microsoft ecosystem, and others have adopted third-party Privileged Access Management providers such as CyberArk and BeyondTrust.

There has also been a broad abandonment of “front end” logins to devices (switches, APs, firewalls), replaced by proxied, web-based access that can be more easily secured by MFA (without direct Internet exposure). Vendors such as Datto (owned by Kaseya now), Ubiquiti, and others have led this charge for years.

Single Sign-On (SSO): Solving the Convenience Problem

Ten years ago, the primary resistance many MSPs encountered to the deployment of sophisticated security stacks was the cost. About that time, I authored an article about just this entitled “Stop Selling Security” that advised MSPs to simply bundle their entire security stack into every plan they offered, and to never sell security separately. With that hurdle cleared, we found the new primary complaint was one of inconvenience; a solid complaint once you adopt universal MFA. SSO simplifies the user experience with MFA, by greatly reducing the frequency of requests to provide your credential set and MFA codes, thus greatly reducing the friction of MFA from the user perspective.

SSO is not a panacea, but it does significantly improve the user experience. SSO requires a designated Identity Provider (IdP) to serve as the ultimate arbiter of identity. This is where you must decide between sticking with a native Microsoft solution (assuming that can be bent to your needs), or going with a third-party offering such as Duo, Evo Security, or others such as Okta. Before adopting SSO (and IdP), you must verify that your clients’ applications and services will respect that identity authority, and work with it.

Password Management: Still Essential in the AI Era

Another challenge for MSPs is password management, which can greatly improve the security posture of their clientele. Despite the near ubiquity of MFA, and because of the increasing spread of SSO, password hygiene is more important now than ever. This includes password design (complexity and length) and management.

For many years there has been an ongoing discussion (argument, perhaps) over what constitutes secure password design. The oldest advice was to create passwords of at least fourteen characters and to use a mix of letters, numbers, and punctuation. Passphrases were all the rage just five years back, as was the creation of acronyms based upon these phrases. We also harp upon not creating predictable passwords based upon readily accessible data (birthdates, spousal or pet names, and the like), and the need for unique passwords across all sites.

But with the advent of AI-driven password cracking (and the tendency of users to ignore some or all of the above), only truly complex, lengthy, and unique passwords are considered safe. How do your end users feel? Doing this right without causing the spontaneous cerebral combustion of your end users is why we all need password management. Choosing a solid password management solution addresses these issues and even better, provides integrated enforcement and documentation that you have done so.

Secure Configuration Management (SCM) for M365

I am using this general term here to refer to properly designing your M365 tenants to resist typical attempts to compromise identity. For the purposes of this article, I will focus on protections that reduce the likelihood of MFA bypass, along with alerting mechanisms that help detect these events should they occur anyway. I hope that most of us have prevailed upon our clients to enforce MFA on all accounts and enable Conditional Access (CA), assuming you have Entra ID P1 or Business Premium. The next step is to strike a good balance between highly secure CA rules and end user acceptance; another greasy tightrope for us all to walk. But failure here is just not an option.

SCM requires not only proper configuration, which can be quite daunting itself, but also alerting of changes that might be indicative of attacks or other anomalous activities. When it comes to proper initial setup, tools like CyberDrain CIPP, Inforcer, and Optimize365 all come to mind. For alerting you to changes in your tenant, native Microsoft tools, ManageEngine, SaaS Alerts (Kaseya), and others come first to mind. In the end though, having a SOC or SIEM behind these tenants is no longer optional and should always be in place, as your final line of defense.

Tying It All Together

Between MFA, SSO, password management, and SCM, we have a good start on IAM (and fine acronym soup). But as usual, tomorrow will bring new challenges, as will the next day. Our job is to remain diligent, keeping one eye on the threat landscape, the other on improving our skills and toolsets, while keeping both of those hands on the wheel.

About the author: Joshua Liberman is a longtime MSP and IT security practitioner with an established presence in the MSP community. He has written and spoken extensively about security, managed services, MSP operations, and technology stack design for service providers.

TruGrid
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.