August 4, 2026 • 6 min read
The MSP Security Stack of 2026 (Part 3)

This is Part 3 of the MSP Security Stack of 2026 series by Joshua Liberman. In Part 1, we mapped the five core areas of the modern MSP security stack, and in Part 2, we went deep on Identity & Access Management. Part 3 covers the second of those core areas: EDR, MDR, XDR, and privileged access management on the endpoint.
EDR/MDR/XDR – Modern Endpoint Protection
The traditional network perimeter may be disappearing, but the endpoint remains one of the most frequently targeted and operationally important parts of the modern security stack. Laptops, desktops, servers, and remote devices continue to handle credentials, applications, and sensitive data - and attackers know it. In this installment, we will examine the layers MSPs should use to protect those endpoints, including EDR, MDR, XDR, privileged access management, DNS filtering, and browser protections.
EDR monitors endpoint activity and provides tools to detect, investigate, isolate, and remediate threats. MDR adds a managed security team that continuously monitors alerts, investigates suspicious activity, and performs or coordinates response. XDR broadens detection and correlation across multiple security domains, including endpoints, identity, and cloud access
Early on, the biggest selling point of EDR was that it addressed the weakness of traditional AV clients – relying upon signature files. With millions of new attacks (or more) annually, pattern file size and AV performance were suffering. And with the (then newfound) polymorphic abilities of attacks (that is, their ability to “appear” as a different attack with a different fingerprint, and therefore avoiding detection by pattern files), the nails were in the coffin of traditional AV clients. For most business environments, EDR has become the practical baseline for modern endpoint protection. These are the sort of attacks that traditional AV clients cannot address, and along with polymorphic attacks, put the final nails in the AV coffin.
Why EDR?
When you get right down to it, attackers are targeting your perimeter (generally protected by your firewalls), your M365 (or Google Workspace) tenants, and your endpoints, as well as other SaaS targets and the pathways you use to gain access to all of these. They focus on different weaknesses endemic to each of them, which we have covered and will cover in more detail in other parts of this series. Though it is not enough to cover just these targets, you also cannot succeed in securing your clients if you fail to protect these. Signature-based detections are still used in modern EDRs, but they are supplemental to behavioral protections. Big name players here include CrowdStrike, SentinelOne, and Deep Instinct, amongst others.
Is EDR Enough?
In my opinion – EDR is just not enough. Without eyes on the endpoint and the ability to respond to activity 24x7, EDR is insufficient. That is why we made the jump to MDR at about the time everyone was suddenly working from anywhere on anything (cue your end user working on an Etch A Sketch by Sat Phone from the restroom at the stadium).
When Covid hit us all here in the States, we very suddenly had hundreds of potential new and poorly identified threats connecting to our (mostly premise-based) sites. The very first remote user we set up on March 13, 2020 (a Friday!) was for the CEO of our largest client, a 15YO desktop that had been upgraded from Windows XP to Windows 7 to Windows 10. Of course.
Just prior to this, I had made the decision to move from EDR to MDR, to silently install DNS filtering (more on this later) on all our managed machines, and to move from SSLVPN to TruGrid proxied RDS for remote access. I cannot say which of these was the most important, but we survived this onslaught of unmanaged (and sometimes, unidentified) remote machines, without issue. I still believe that moving to MDR provided the biggest leap in protection (and peace of mind), while the move from SSL VPN to proxied RDS traffic was also critical.
Comprehensive Protection (XDR)
XDR refers to the correlation of data from multiple security layers. Sophos was a pioneer of XDR in 2018, integrating information from their firewalls, EDR agents, and email security products, to feed their in-house SOC. Today we have a plethora of options here, from firewall and traditional EDR vendors, including SonicWall and Sophos. Then there are SIEMs that work with EDR providers such as Blackpoint Cyber, Huntress, SOC Soter, Solutions Granted (now part of SonicWall), and more. As with so much in our world, this variety is both good news and bad, and the ground is constantly shifting.
Privileged Access Management (PAM)
Since we are focused on the endpoint in this article, I am purposefully going to cover just a slim slice of the larger PAM pie here. For our purposes, we can reduce PAM to privilege elevation and Just in Time (JiT) credentialing. It is well accepted that our end users should always work with standard permission, exercising privilege elevation on the fly, for single actions or brief periods, whenever possible. Modern tools make this once daunting task easier, though not so quick and transparent that users never complain.
From focused offerings such as AutoElevate (now part of CyberFox) and CyberArk, to broader solutions such as the ThreatLocker suite, privilege elevation and JIT capabilities are becoming easier to deploy and support. But they will still irk some users and require a certain degree of focused attention on the part of your staff, not to mention the expectation on the part of end users of far faster responses than most other requests. That said, nothing short of a full-on whitelisting and ringfencing solution does more to protect endpoints than does PAM.
DNS Filtering and More
When Covid hit, we quite suddenly had a remote, work-from-anywhere (and anything) workforce. We scrambled to protect endpoints that had shifted from protected desktops to the accessing of those remotely by means of new, unvetted machines. Moving from EDR to MDR was obvious, but I felt the need for something more.
What could I do that would bring the greatest security benefit at the least cost (in terms of acquisition, installation, and ongoing support)? It only took a few moments to determine that this was going to be DNS filtering. For those unclear on this, DNS filtering works by rejecting requests to known bad sites, including those too new to be trustworthy, typo-squatted names, and more, and it stands apart from content filtering, though there is some overlap. (This is a slight oversimplification for reasons of time and space.)
At the time, we were DNSFilter partners, paying well under $1 per seat, and their silent installation was flawless, so it was an easy choice, at minimal cost (in terms of both time and money). As time passed, I saw this market mature and in 2026, truly welcome changes have come. Today we can reach out to offerings from DefensX and Atakama (amongst others) that bundle traditional DNS filtering with browser protections, content filtering, and even a lightweight degree of governance. DNS filtering has come a long way over six years.
In Summary
Defending the endpoint is a critical aspect (despite the dissolution of the traditional perimeter), the move to Cloud services, and work from anywhere. I believe that, if anything, these trends accentuate the need to improve endpoint protection. But the M365 tenant has appeared as a new class of “endpoint.” M365 protections have already been touched upon earlier in this series, including the reference to it above under XDR. Stay tuned for the next installment in this series, in which we focus on protecting the M365 tenant in depth.
About the author: Joshua Liberman is a longtime MSP and IT security practitioner with an established presence in the MSP community. He has written and spoken extensively about security, managed services, MSP operations, and technology stack design for service providers.

