139 answers
Microsoft 365 MSP FAQ
Licensing, backup, archiving, Purview, Intune, CSP, Copilot, and operational questions MSPs hit when Microsoft changes the rules.
- Maintained by
- Scopable Team
- Reviewed
- 2026-07-23
- Primary page
- Microsoft 365 integration
Microsoft 365
Is Hornetsecurity or Keepit better for MSPs?
Hornetsecurity is usually better when the MSP already sells Hornetsecurity's Microsoft 365 security and management stack and needs backup for common M365 workloads plus Entra users and groups. Keepit is usually better when Entra ID restore depth is the proof point, including policies, app registrations, selected Intune data, BitLocker keys, and logs.
When does Hornetsecurity 365 Total Backup fit an MSP?
Hornetsecurity 365 Total Backup fits when the MSP wants Microsoft 365 backup tied to a broader Hornetsecurity relationship, with multi-tenant management, automatic backups, unlimited storage messaging, and Entra users and groups in scope.
When does Keepit Entra ID backup fit an MSP?
Keepit Entra ID backup fits when the client needs proof for identity objects beyond users and groups, such as roles, service principals, app registrations, Conditional Access policies, selected Intune policies, BitLocker keys, Windows LAPS, audit logs, and sign-in logs.
What restore proof should an MSP show for Entra ID backup?
MSPs should show the restored object, restore target, test date, technician, outcome, screenshots or job evidence, and relationship details such as group memberships, role assignments, owners, licenses, and policy behavior.
Should Microsoft 365 backup appear in a client QBR?
Yes. A client QBR should show Microsoft 365 backup health, restore-test evidence, covered workloads, excluded identity objects, retention status, and any open decisions. A green backup dashboard is not enough proof by itself.
Should MSPs use Cove or Veeam for Microsoft 365 backup?
Use Cove when Microsoft 365 backup should sit beside server and workstation backup in one backup dashboard with included storage and simple per-user packaging. Use Veeam when Microsoft 365 backup belongs inside a broader Veeam service-provider operation with per-user licensing, restore portal needs, and usage reporting discipline.
Should MSPs use Veeam or Acronis for Microsoft 365 backup?
Use Veeam when Microsoft 365 backup should fit a service-provider backup operation with Exchange, SharePoint, OneDrive, Teams, restore portal, and usage reporting discipline. Use Acronis when Microsoft 365 backup is part of a broader Cyber Protect Cloud service. Either way, define deleted-user handling, restore authorization, retention, and evidence.
Should MSPs use Acronis or Cove for Microsoft 365 backup?
Use Acronis when the client needs Microsoft 365 backup inside a broader Acronis service mix or wants a storage option decision between Acronis Cloud Storage and Microsoft 365 Backup Storage. Use Cove when the MSP wants flat per-user Microsoft 365 backup managed from the same backup dashboard as servers and workstations.
Should MSPs use MSP360 or Acronis for Microsoft 365 backup?
Use MSP360 when Microsoft 365 backup should fit a white-label service with storage control and per-user pricing. Use Acronis when Microsoft 365 backup belongs inside a wider Acronis protection package. Either way, define services covered, retention, restore SLA, authorization, and reporting.
Should MSPs choose Microsoft Defender for Business or Huntress?
MSPs should treat Microsoft Defender for Business as the endpoint security base and Huntress as a managed security layer around monitoring, investigation, and response. The right choice depends less on feature lists and more on who owns alerts, remediation, reporting, and client escalation.
Is Microsoft Defender for Business enough for MSP clients?
Defender for Business can be enough for some MSP clients if it is fully configured, monitored, documented, and tied to a clear response process. If alerts are not owned or after-hours response is vague, the license exists but the managed security service does not.
Does Huntress replace Microsoft Defender for Business?
Usually no. Huntress commonly works with Microsoft Defender signals and adds managed review, threat hunting, and response workflow around covered activity. MSPs should scope which parts are handled by Microsoft, Huntress, the MSP, and the client instead of treating one tool as a total replacement.
Who should own Microsoft Defender alerts in an MSP agreement?
The agreement should name the owner for Defender alert triage, after-hours escalation, remediation approval, client notification, reporting, and exception review. If the owner is not named, the MSP has a service delivery gap even if Defender is correctly licensed.
Should MSPs choose Blumira or Microsoft Sentinel?
MSPs should choose Blumira when they need predictable pricing, faster client onboarding, multi-tenant operations, and SecOps support. Microsoft Sentinel is the better fit when the MSP has Azure security skill and wants custom Microsoft-native SIEM control.
Is Microsoft Sentinel a good SIEM for MSPs?
Microsoft Sentinel can be a good SIEM for MSPs that already have Azure, KQL, automation, and cost-management discipline. It is risky when the MSP treats Sentinel as a packaged SMB security service without pricing ingestion, retention, connector work, and incident response labor.
How does Blumira MSP pricing compare with Microsoft Sentinel pricing?
Blumira's MSP positioning centers on per-user pricing and no per-GB overage language, which makes quoting simpler. Microsoft Sentinel uses Azure usage-based pricing with pay-as-you-go, commitment tiers, retention, and data lake meters, so the MSP has to manage cost assumptions continuously.
What is the best Microsoft 365 SIEM for MSPs?
The best Microsoft 365 SIEM for an MSP depends on operating model. Blumira fits MSPs that need a repeatable security package around Microsoft 365 and other client sources. Microsoft Sentinel fits MSPs that need custom Microsoft-native analytics and can own the Azure build.
What should MSPs include in a client SIEM scope?
An MSP SIEM scope should name covered data sources, alert triage, after-hours escalation, remediation authority, client approvals, reporting cadence, retention assumptions, and what work is billed separately. Without that scope, the client bought a tool, not a managed security service.
Does Teams record all calls automatically?
No. Teams does not record anything by default. Someone must manually start recording, unless compliance recording is configured with a third-party solution.
Can my employer record Teams calls without telling me?
With compliance recording, yes. Users see a notification that recording is in progress, but they cannot stop it. The policy is set at the admin level.
Where do Teams recordings go?
OneDrive for non-channel meetings (in the organizer's account). SharePoint for channel meetings. Not Microsoft Stream anymore. That changed in 2021.
How long are Teams recordings kept?
120 days by default, then auto-deleted. Admins can change this to any value between 1 and 99,999 days, or disable expiration entirely.
Can I record a Teams call to someone's phone?
Yes, if PSTN call recording is enabled in your calling policy. The other party hears an audio notification when recording starts.
Do guests know when I'm recording a Teams meeting?
Yes. All participants see a banner notification and hear an audio alert when recording starts or stops.
Can I record a Teams meeting without anyone knowing?
No. Not with Teams' built-in recording. All participants are notified. Third-party screen recording software is a different matter, but that creates legal issues in two-party consent states.
Does Microsoft have access to my Teams recordings?
Microsoft stores recordings in your OneDrive/SharePoint. Their standard data processing agreements apply. They don't use customer recordings to train AI models without explicit consent.
What's the difference between convenience and compliance recording in Teams?
Convenience recording is manual, user-initiated, and stored in OneDrive/SharePoint. Compliance recording is automatic, policy-based, requires a third-party solution, and stores recordings in the partner's system.
Can I prevent specific Teams meetings from being recorded?
Meeting organizers can disable recording for their meetings using meeting options. Admins can also restrict recording capabilities through meeting policies assigned to specific users or groups.
What happens to Teams recordings when someone leaves the company?
Recordings in that user's OneDrive follow the OneDrive deletion policy for departed users. Typically deleted 30 days after the account is removed unless IT takes action. Channel meeting recordings in SharePoint are unaffected.
What are the Microsoft 365 price increases for July 2026?
Microsoft 365 commercial pricing changes on July 1, 2026. Microsoft lists Business Basic moving from $6 to $7 per user per month, Business Standard from $12.50 to $14, M365 E3 from $36 to $39, and M365 E5 from $57 to $60. Existing customers move to new pricing at their next renewal after July 1.
How do MSPs re-quote clients after an M365 price increase?
MSPs should export current license counts, verify renewal dates, calculate the monthly and annual delta by client, remove unused licenses, then send revised quotes before the new pricing appears on an invoice. The goal is to make the change feel reviewed, not dumped on the client.
Which M365 plans are affected by the July 2026 price increase?
Microsoft lists price changes for several commercial plans including Business Basic, Business Standard, F1, F3, Office 365 E3/E5, Microsoft 365 E3/E5, and some standalone components. Business Premium shows no commercial list price change in Microsoft's table, though it receives packaging changes.
How much is Microsoft raising M365 Business Basic in 2026?
Microsoft's commercial pricing table shows Microsoft 365 Business Basic increasing from $6 to $7 per user per month on July 1, 2026. That is a $1 per-user monthly increase before any CSP, regional, currency, or distributor-specific adjustments.
How should MSPs communicate M365 price increases to clients?
Tell clients the date, the affected licenses, their estimated monthly and annual impact, and what you reviewed before changing the quote. Keep it short. The strongest message is: Microsoft pricing is changing, we checked your tenant, and here is our recommendation before your bill changes.
What is Microsoft 365 Business with Copilot for MSPs?
Microsoft 365 Business with Copilot combines a Microsoft 365 Business plan with Copilot Business for SMB customers. For MSPs, the useful question is not only which SKU to quote. It is whether the client has clean licensing, data access, security policy, user training, and support ownership before AI seats are added.
Should MSPs quote Business Basic plus Copilot Business first?
Only when the client is a good fit for a narrow, web-first rollout. Business Basic plus Copilot Business can be a lower-cost entry point, but it does not replace the security, device management, and governance conversation that often points larger or riskier clients toward Business Premium with Copilot.
When should an MSP recommend Business Premium with Copilot instead of Business Standard with Copilot?
What work should MSPs quote around Copilot Business?
Quote the rollout work separately from the license: tenant and license review, permission cleanup, security and governance baseline, pilot users, role-based training, support rules, and a 30, 60, or 90 day adoption review. If that work is missing, the MSP is selling an AI license while absorbing the real implementation cost.
What is Microsoft 365 E7 for MSPs?
Microsoft 365 E7 is Microsoft's Frontier Suite that bundles Microsoft 365 E5, Copilot, Agent 365, and Microsoft Entra Suite. MSPs should treat it as a role-based bundle for users who need all of those pieces, not as a default tenant-wide upgrade.
How should MSPs compare Microsoft 365 E7 vs E5?
Compare E7 vs E5 by user role and add-on overlap. E7 starts to make sense when the same users need E5, Copilot, Agent 365, and Entra Suite. If Copilot adoption is weak or agent governance is theoretical, keep the client on E5 and scope the readiness work first.
What should MSPs verify before quoting Agent 365?
MSPs should verify who inventories agents, approves new agents, reviews data access, responds to agent behavior issues, and owns reporting. Agent 365 licensing should come with a governance and support scope, not only a license line item.
What should MSPs check before quoting Microsoft 365 E7 through CSP?
Before quoting Microsoft 365 E7 through CSP, check seat counts, renewal dates, term duration, billing cadence, Teams variants, promos, distributor pricing, NCE cancellation windows, Extended Service Terms risk, and overlap with Copilot, Entra, Defender, Intune, Purview, backup, email security, and managed support scope.
What is Microsoft 365 Archive file-level archiving?
Microsoft 365 Archive file-level archiving lets organizations move individual SharePoint files or folders into archive storage instead of archiving an entire site. MSPs should treat it as a storage governance decision because archived files may stay visible but cannot be opened until reactivated.
Does SharePoint file-level archiving reduce storage costs?
How long does Microsoft 365 Archive file retrieval take?
Microsoft's Message Center guidance says file reactivation is instant within seven days of archiving. After seven days, reactivation may take up to 24 hours, so MSPs should document retrieval expectations before archiving client files.
Do archived SharePoint files appear in Copilot or normal search?
Microsoft says archived content is not used by Microsoft 365 Copilot. Archived files remain available for compliance and admin discovery paths, but users should not expect normal access, normal Copilot grounding, or ordinary search behavior until files are reactivated.
How should MSPs package Microsoft 365 Archive cleanup work?
Package it as a paid storage assessment and roadmap task. The scope should include archive candidates, retention checks, permission review, owner approval, retrieval rules, and a client-ready decision record instead of free admin cleanup.
What is the difference between Microsoft 365 Archive and backup?
Microsoft 365 Archive moves inactive SharePoint content into colder storage to reduce active storage pressure. Backup creates recovery points so admins can restore from deletion, corruption, ransomware, or other bad changes.
Can Microsoft 365 Archive replace backup for MSP clients?
No. Archive is a storage lifecycle tool, not a point-in-time recovery plan. It can help with inactive SharePoint storage, but clients still need backup scope, restore testing, and recovery ownership.
Are retention policies and legal hold the same as backup?
No. Retention and legal hold preserve content for policy, compliance, or legal discovery. Backup is built around recovery. MSPs should scope these separately so clients do not mistake preserved data for a tested restore path.
When does Microsoft 365 Archive reduce SharePoint storage cost?
Microsoft 365 Archive can reduce cost when archived plus active SharePoint storage exceeds the tenant's included or licensed SharePoint quota. If the tenant is still under quota, archiving content may not create additional archive storage charges.
What should MSPs define before quoting Microsoft 365 Backup?
Define protected sites, OneDrive accounts, and mailboxes; restore point expectations; excluded data; approval rules; recovery labor; and restore test cadence. The backup line item should include the work required to prove recovery, not just storage.
Should MSPs use Microsoft 365 Backup or third-party backup?
Use Microsoft 365 Backup when the client needs native SharePoint, OneDrive, and Exchange recovery, accepts one-year retention, and wants data kept inside Microsoft. Keep third-party backup when the client needs longer retention, broader workload coverage, separate storage control, or stronger MSP reporting.
When is Microsoft 365 Backup good enough for MSP clients?
Microsoft 365 Backup can be enough for clients with straightforward SharePoint, OneDrive, and Exchange recovery needs, one-year retention requirements, and no need for separate non-Microsoft backup storage. MSPs should still test restore behavior and document client approvals before replacing an existing backup service.
What restore tests should MSPs run before changing M365 backup?
Run at least one SharePoint or OneDrive restore and one Exchange restore. Document the restore point, destination choice, approval owner, elapsed time, affected permissions or metadata, and whether the result matched the client-facing RTO and RPO language.
Why would an MSP keep third-party Microsoft 365 backup?
Third-party backup still matters when the MSP needs longer retention, separate administration, non-Microsoft storage control, broader SaaS coverage, partner reporting, or one recovery workflow across many backup services. The tool should match the client promise the MSP is willing to own.
What should be in a client scope for Microsoft 365 Backup?
The scope should name protected workloads, excluded data, retention expectations, restore approval rules, RTO and RPO language, recovery labor, test cadence, storage billing assumptions, and who pays for after-hours restore work. If those details are missing, the backup quote is not finished.
How often do Business Central Dual Use Rights keys need to be replaced?
Microsoft says Business Central online customers running on-premises Business Central through Dual Use Rights must download and replace the DUR license key every six months. MSPs should treat that as recurring license administration with a named owner, reminder, verification step, and documented next due date.
Where do customers download Business Central Dual Use Rights keys?
Microsoft documents the Dual Use Rights key download path in the Microsoft 365 admin center under Billing, Your products, the relevant Dynamics 365 service, and Registration Keys. The MSP still needs to control privileged access, store the key securely, and document who downloaded it.
What should an MSP include in a Business Central DUR key rotation scope?
Include exposed-client discovery, subscription confirmation, admin access review, key download, secure storage, planned import, server instance restart if required, post-change validation, documentation, and the next six-month reminder. If an ERP partner owns the application, include the handoff in the scope.
Who should own Business Central Dual Use Rights key rotation?
Assign one accountable owner for the process and one backup. The client business owner should confirm the subscription and business dependency, while the MSP or ERP partner should own the technical download, import, verification, documentation, and reminder if that work is in scope.
What Intune features are being added to Microsoft 365 E3 and E5 in 2026?
Microsoft says M365 E3 gets Defender for Office Plan 1, Intune Remote Help, Intune Advanced Analytics, Intune Plan 2, Copilot Chat enhancements, and Copilot Chat Analytics. M365 E5 adds those capabilities plus Security Copilot, Intune Endpoint Privilege Management, Microsoft Cloud PKI, and Intune Enterprise Application Management.
When do the Microsoft Intune changes roll out to existing customers?
Microsoft says packaging changes begin rolling out in June 2026, customers get at least 30 days notice in Message Center, and the rollout is complete by August 1, 2026. Pricing changes take effect July 1, 2026, and existing customers stay on current pricing until renewal.
Does Microsoft still sell Intune Suite and add-ons separately?
Yes. Microsoft says the capabilities are also available as add-ons or as part of the Intune Suite. That matters for customers who already buy those tools separately or only need a narrow slice of the stack.
How should MSPs bill for the Intune change?
Audit the tenants that actually use the new capabilities, compare current add-on spend against the bundle, and then decide whether to pass through the suite increase, rebundle the service, or keep the current price and absorb the hit. The only bad move is pretending the change is free.
What is a Microsoft Purview governance review for MSPs?
A Microsoft Purview governance review is an MSP-led review of Microsoft 365 content risk signals: ownerless or single-owner sites, inactive SharePoint and Teams workspaces, oversharing, attestation gaps, and cleanup decisions. The useful deliverable is not the dashboard. It is the client-approved owner, cleanup, archive, or accepted-risk decision.
Why should MSPs care about ownerless SharePoint sites?
What should an MSP include in a Microsoft 365 governance review?
Include site ownership, inactive sites, oversharing, site attestations, retention or legal holds, archive candidates, delete candidates, and a client decision table. Keep remediation separate so cleanup work is approved and priced instead of absorbed as vague admin support.
How often should MSPs run Microsoft 365 governance reviews?
Run a lightweight Microsoft 365 governance review quarterly for active clients and after major changes such as migrations, department restructures, Copilot rollout, retention policy changes, or a large Teams and SharePoint cleanup. High-risk clients may need monthly owner and oversharing checks.
Which is better for MSP reporting, AdminDroid or CoreView?
AdminDroid is usually the better fit when the MSP wants fast reporting, scheduled exports, and audit evidence with minimal setup. CoreView is usually the better fit when the report has to feed delegated remediation, tenant segmentation, and controlled operator access.
Does CoreView replace Microsoft 365 Lighthouse?
No. Microsoft 365 Lighthouse gives MSPs deployment insights across managed tenants, while CoreView focuses more on delegated administration, segmentation, and policy control. CoreView can go deeper on operator access, but the MSP still needs a cleanup owner and a client decision record.
Can AdminDroid handle multi-tenant cleanup workflows?
AdminDroid can surface the evidence, export it, and automate parts of the review, but it is still strongest as a reporting and audit layer. The cleanup workflow still needs owner assignment, approval, and a place to track the follow-up work.
What should an MSP do when a report has no cleanup owner?
Assign one before you do anything else. Turn the report into a client-approved cleanup item, roadmap task, or accepted-risk decision, then track the work in your QBR or project system. A report without an owner is just another screenshot.
Should an MSP buy both AdminDroid and CoreView?
Only if the team can clearly separate the jobs. Use one as the evidence layer and the other as the control layer, or you will pay twice for overlapping admin visibility. Most MSPs should start with the one that matches the bigger problem and fix the workflow first.
Is Pax8 or Sherweb better for MSPs?
Pax8 is usually a better fit when an MSP wants a broad cloud marketplace and already has a clean billing process. Sherweb is usually a better fit when an MSP is Microsoft-heavy and wants more direct CSP guidance. The right choice depends on billing accuracy, support path, renewal help, catalog fit, and migration risk.
What should MSPs audit before choosing a CSP distributor?
Audit client license counts, SKU mix, renewal dates, distributor cost, client-billed amount, margin, agreement language, support escalation path, reporting exports, and migration timing. Do not pick a distributor from vendor claims alone. Compare the invoice and the client workflow you will actually run.
Why does the July 2026 Microsoft 365 pricing change affect distributor choice?
The July 2026 Microsoft 365 pricing change makes renewal accuracy more visible. MSPs need clean distributor reports, clear renewal dates, and client-ready quote math before invoices change. A weak distributor workflow can turn a small license increase into a client trust problem.
How should MSPs compare CSP billing between distributors?
Compare how each distributor shows prorations, renewal dates, SKU changes, client-level cost, discounts, promotions, and historical changes. Then test whether that data can be reconciled to your PSA and client invoices without manual cleanup every month.
When should an MSP switch CSP distributors?
Switch when billing, support, renewal guidance, or Microsoft program help creates repeatable client risk that cannot be fixed through escalation or internal process cleanup. Do not switch during a renewal crunch unless the current setup is already hurting clients.
Is Pax8 or Ingram Micro better for MSPs?
Pax8 is usually better when cloud subscriptions, PSA sync, and recurring marketplace workflows are the center of the MSP business. Ingram Micro is usually better when Microsoft CSP, hardware, Azure, and broader procurement need to sit inside one distributor relationship.
Which has better PSA sync, Pax8 or Ingram Micro?
Pax8 publishes PSA integrations for tools such as Autotask, ConnectWise, Kaseya, RepairShopr, Syncro, and SuperOps. Ingram Micro has also added PSA-connected marketplace workflows. The better choice is the one that maps subscriptions to the correct company, agreement, invoice line, and renewal date with less manual finance cleanup.
When does Ingram Micro make sense for Microsoft CSP?
Ingram Micro makes sense when an MSP wants Microsoft CSP support inside a broader distributor relationship that can also cover hardware, Azure, cloud services, incentives, and enablement. It is a stronger fit when the client deal is bigger than a subscription cart.
What should MSPs check before moving CSP billing from Pax8 to Ingram Micro?
Audit renewal dates, term lengths, seat counts, distributor costs, client-billed amounts, PSA agreement mappings, invoice lines, delegated admin access, and cancellation windows. Do not move tenants until finance can prove how every charge will reconcile after the switch.
What is the biggest risk when switching between Pax8 and Ingram Micro?
The biggest risk is not the portal change. It is losing control of renewal timing, seat cleanup, client approvals, support ownership, and PSA billing mappings during the move. Run one pilot client before moving a wider Microsoft CSP book.
What is Microsoft Extended Service Term for CSP subscriptions?
Microsoft Extended Service Term is a paid monthly continuation state for eligible CSP subscriptions that reach the end of term without a normal renewal or explicit cancellation. Microsoft says EST keeps service active and bills at the current monthly term rate plus a 3% uplift, or 23% if no monthly plan exists.
How can MSPs avoid unwanted EST billing?
MSPs avoid unwanted EST billing by auditing upcoming CSP renewals, identifying subscriptions set to EST, getting client approval in writing, and setting explicit end-of-term instructions in Partner Center. Auto-renew false alone is not enough for eligible subscriptions because Microsoft can convert that state to EST unless cancellation is explicit.
How long do MSPs have to reduce NCE seats at renewal?
For new commerce license-based subscriptions, Microsoft says cancellation is generally available within seven calendar days of purchase or renewal, except where law requires otherwise. MSPs should treat that as an execution window, not a planning window. Seat cleanup and client approval should happen before renewal.
Should an MSP choose renew, cancel, or EST?
Choose renew when the client wants another standard term, cancel when the client wants service to stop at expiration, and EST when the client needs short-term continuity while deciding next steps. EST is useful when it is intentional. It is a margin problem when it happens because nobody collected a decision.
What should MSPs audit before Microsoft 365 renewal?
Before Microsoft 365 renewal, MSPs should audit term end dates, auto-renew state, EST settings, seat counts, disabled users, duplicate SKUs, add-ons, monthly versus annual term mix, client approval status, and agreement language. The output should be a renewal quote with clear assumptions and deadlines.
How should MSPs charge for Microsoft Intune management?
MSPs should charge for Intune in three parts: paid discovery, a fixed-fee deployment project, then monthly management. The license may already exist in Microsoft 365, but policy design, enrollment cleanup, app packaging, reporting, and support ownership still need a priced scope.
Is Intune included in Microsoft 365 Business Premium?
What should an MSP include in an Intune deployment project?
An Intune deployment scope should include license review, device inventory, identity model, enrollment method, compliance and configuration policies, app packaging, pilot groups, user communication, support ownership, reporting, and exclusions for remediation or onsite work.
Can Intune replace SCCM for SMB clients?
For many SMB clients, Intune is the cleaner default path for endpoint management. SCCM, now Microsoft Configuration Manager, still matters in larger legacy environments, co-management scenarios, and phased workload moves. Do not quote that migration as a weekend cleanup.
Does Intune replace an RMM for MSPs?
No. Intune handles Microsoft endpoint and app management, compliance policy, and enrollment workflows. An RMM still covers monitoring, scripting, remote access, patch operations, automation, and technician workflows that Intune does not replace.
What is included in monthly Intune management?
Monthly Intune management usually includes compliance review, policy monitoring, minor policy changes, stale device review, reporting, and exception handling. App repackaging, major migrations, onsite remediation, procurement, and user training should be separate line items unless the agreement says otherwise.
When should MSPs use Windows 10 ESU?
Use ESU only as a temporary bridge when a device cannot move right away. If the PC qualifies for Windows 11, upgrade it. If it does not, replace it or document the exception.
What should an MSP check before moving a client to Windows 11?
Check CPU, TPM 2.0, Secure Boot, RAM, storage, app compatibility, peripheral dependencies, and device role. A machine can pass a quick glance and still fail in production.
How long do Microsoft 365 Apps stay supported on Windows 10?
Microsoft says Windows 10 support ended on October 14, 2025, but Microsoft 365 Apps on Windows 10 will keep receiving security updates for three years after that date, through October 10, 2028. That is app support, not OS support.
What should MSPs do about Secure Boot certificates expiring in 2026?
MSPs should audit client devices for old Secure Boot certificate state, update OEM firmware first, pilot the 2023 certificate update, verify BitLocker recovery keys, and quote remediation or replacement work before broad rollout.
Will devices stop booting when Secure Boot certificates expire in June 2026?
Microsoft says devices that have not received the newer 2023 Secure Boot certificates can continue to start and install standard Windows updates. The risk is that they may stop receiving future protections for early boot components, Boot Manager updates, Secure Boot databases, and revocation lists.
Why should MSPs check BitLocker keys before Secure Boot certificate updates?
Secure Boot certificate and firmware changes can trigger BitLocker recovery prompts on some devices. MSPs should verify recovery-key escrow, test representative BitLocker-enabled devices, and brief helpdesk before broad deployment.
How should an MSP scope a Secure Boot certificate audit?
Scope the audit as client-approved work: device inventory, Secure Boot state, certificate update status, event and registry signals, firmware version, BitLocker readiness, boot order, recommended remediation path, and exception list.
What is the YellowKey BitLocker risk for MSPs?
YellowKey, tracked as CVE-2026-45585, is a Windows BitLocker security feature bypass that matters most when an attacker has physical access to a device. MSPs should patch affected systems, identify TPM-only BitLocker laptops, verify recovery-key escrow, and document where stronger startup protection is needed.
Should MSPs turn on TPM+PIN for every BitLocker device after YellowKey?
No. Microsoft says TPM+PIN is not exploitable for CVE-2026-45585, but TPM+PIN adds user friction and support process. MSPs should use it first for higher-risk laptops such as executives, travelers, field staff, finance, legal, healthcare, and regulated users, then document where TPM-only remains accepted after patching.
What should a YellowKey mitigation plan include?
A practical YellowKey plan should include June 2026 Windows security updates, TPM-only BitLocker inventory, recovery-key escrow checks, a risk-based TPM+PIN decision, WinRE mitigation documentation where needed, pilot testing, client approval, and an exception list.
Can Kali365 bypass Microsoft 365 MFA?
The FBI says Kali365 can capture Microsoft 365 OAuth access and refresh tokens, which can let attackers keep access without needing the user's password or another MFA prompt. MSPs should treat ordinary MFA as one layer, not the whole access-control plan.
What should MSPs check after the Kali365 warning?
MSPs should check admin MFA strength, Conditional Access coverage, device-code flow exposure, risky sign-ins, token and session revocation procedures, device compliance requirements, user reporting, and client responsibility boundaries.
Does revoking Microsoft 365 sessions immediately remove all access?
Not always. Microsoft says administrators can revoke refresh tokens and block new token issuance, but existing access tokens and application session tokens can remain valid until they expire or the application revokes them. That is why MSPs need a tested runbook, not just a portal button.
Should token-theft cleanup be included in monthly MSP support?
Basic account help may fit normal support, but tenant-wide sign-in review, Conditional Access redesign, executive reporting, and incident response should be separately scoped. If the client wants the MSP to own token-theft response, put the work and limits in the agreement.
Which data sources are best for an MSP SaaS audit?
The best sources are Microsoft 365 usage reports, Microsoft Entra enterprise apps and permissions, SSO logs, browser or extension inventory, finance exports, endpoint inventory, SaaS management tools, and client interviews. Each source catches a different part of the sprawl.
What is the difference between prepaid Copilot Credits and pay-as-you-go?
Prepaid Copilot Credits give the client committed capacity that is consumed first. Pay-as-you-go covers usage after prepaid capacity is exhausted or when no prepaid plan is attached. MSPs should document which billing method applies to each spending policy before approving agent access.
How should Copilot Credits appear in an MSP client invoice?
Copilot Credit usage should be explained as metered Microsoft AI usage and kept distinct from MSP labor. The client invoice should show whether credits are pass-through, included up to a cap, or billed as part of a managed AI service with defined limits.
Should MSPs choose Universal Print or PrinterLogic?
Choose Universal Print when the client already has eligible Microsoft 365 licenses, newer printers, manageable print volume, and a Microsoft-native admin model. Choose PrinterLogic when print server removal, direct IP printing, driver deployment, self-service installs, location rules, and ticket reduction matter more than using what Microsoft already includes.
How many Universal Print jobs does Microsoft 365 Business Premium include?
Why do MSPs look at PrinterLogic for direct IP printing?
MSPs look at PrinterLogic when they want to reduce print server dependence while still centrally managing printers, drivers, default settings, location rules, and self-service installs. Direct IP printing can remove one old failure point, but the MSP still needs discovery, pilot testing, rollback, and support handoff.
Which has better reporting, Universal Print or PrinterLogic?
Universal Print gives Microsoft-native usage reporting in Azure Portal, including current-month capacity, remaining jobs, and CSV downloads for recent user and printer usage. PrinterLogic markets real-time activity, reporting, quotas, and cost management, so MSPs should validate export fields, retention, tenant separation, and whether page counts are actual or estimated.
How should MSPs quote a Universal Print or PrinterLogic cutover?
Quote the cutover as project work: discovery, printer inventory, licensing review, pilot users, driver testing, app workflow validation, user comms, rollback, and first-month support review. Do not bury a print migration inside normal helpdesk time unless the client has accepted a very narrow scope.
Should MSPs choose Universal Print or Printix?
Choose Universal Print when the client already has eligible Microsoft 365 licensing, Intune-managed Windows devices, newer printers, and manageable print volume. Choose Printix when the MSP wants a dedicated cloud print management service with partner operations, secure print, active-user billing, and broader print-specific control.
How does Printix pricing work for MSP clients?
Printix describes business pricing around active users, with monthly postpaid billing based on active users in the preceding month and annual prepaid billing for nominated users. Small tenants with fewer than 15 users have a minimum monthly service fee, so MSPs should check active-user cleanup and minimums before quoting.
Does Intune make Universal Print the obvious MSP choice?
Intune makes Universal Print easier to deploy for Microsoft-standard Windows environments, but it does not settle every print project. Printix still deserves a look when secure print, mixed endpoints, partner operations, hybrid cloud printing, or print-specific service packaging matter more than staying inside Microsoft admin tools.
How should MSPs quote a Universal Print or Printix cutover?
Quote the cutover as project work: printer inventory, Microsoft license and job-pool review, Printix active-user review, pilot users, driver testing, secure print validation, business-app printing, user comms, rollback, and first-month support review. Do not bury print migration work inside normal helpdesk time.
What does Windows Ready Print mean for MSPs in July 2026?
Starting in July 2026, new eligible printer installations on Windows will prefer Windows Ready Print where supported. MSPs should inventory printer queues, test business workflows, set policy intentionally, document OEM driver exceptions, and get client signoff before broad rollout.
Is Windows Ready Print the same as Windows Protected Print Mode?
No. Windows Ready Print is the standards-based print path that uses IPP and the Windows inbox driver where supported. Windows Protected Print Mode is a stricter security mode that exclusively uses Windows Ready Print and can remove printers that depend on third-party drivers.
Should MSPs disable Windows Ready Print by default?
Not automatically. MSPs should prefer Windows Ready Print for simple, compatible printer fleets after pilot testing, but keep documented OEM driver exceptions for copiers, label printers, accounting codes, finishing options, old print servers, and fragile business apps.
How should MSPs quote Windows Ready Print readiness work?
Quote it as project work: assessment, pilot, cutover, after-hours validation, and support handoff. Do not bury printer inventory, policy changes, business-app testing, rollback planning, and vendor-driver exceptions inside normal helpdesk time.
Is Barracuda Email Protection or Defender for Office 365 better for MSPs?
Defender for Office 365 is usually better when the client is Microsoft-standardized and the MSP can operate policy tuning, quarantine, alert review, response, and reporting. Barracuda Email Protection is usually better when the client needs flexible deployment, post-delivery remediation, archiving, DMARC reporting, training, or a clearer MSP-packaged email security line item.
Is Microsoft Defender for Office 365 enough for MSP clients?
Microsoft Defender for Office 365 can be enough for MSP clients when the license matches the client's risk and the MSP owns setup, tuning, monitoring, quarantine handling, and response. It is not enough when the MSP treats an included license as an included managed service without defining who watches and cleans up the work.
When is Barracuda Email Protection worth it for an MSP client?
Barracuda Email Protection is easier to justify when the client needs deployment options outside a pure Microsoft model, faster post-delivery cleanup, account takeover help, DMARC reporting, cloud archiving, security awareness training, or attack simulation. The MSP still needs to document which modules are included and which work remains MSP-owned.
Does Business Premium include enough email security for MSPs?
What should MSPs include in managed email security scope?
Managed email security scope should name license coverage, policy baseline, SPF, DKIM, and DMARC ownership, quarantine review, user reporting, false-positive handling, post-delivery response, training, archiving, reporting, and escalation authority. If those items are not named, the client will assume the MSP owns more than the quote priced.
Should MSPs choose ShareGate or AvePoint Fly?
When is ShareGate a better fit for MSP migrations?
When is AvePoint Fly a better fit for MSP migrations?
AvePoint Fly is often a better fit when the project includes mailboxes, OneDrive, SharePoint, Teams, Teams chat, Google Workspace, Slack, Box, Dropbox, identity, or managed migration support. The broader fit does not remove the need for a detailed SOW and cutover plan.
Should MSPs choose Windows 365 or Azure Virtual Desktop?
MSPs should start with Windows 365 when a client needs predictable dedicated Cloud PCs per named user. Start with Azure Virtual Desktop when the client needs pooled sessions, RemoteApp, custom Azure networking, or cost control through autoscale and consumption management.
Is Nerdio worth it for MSPs managing AVD and Windows 365?
Nerdio is worth evaluating when an MSP manages AVD or Windows 365 across multiple tenants and needs repeatable provisioning, image, autoscale, and cost workflows. It is less urgent for a tiny Windows 365 Business deployment with little ongoing Azure work.
What is Entra hard matching for MSPs?
Entra hard matching is when Entra Connect Sync or Cloud Sync matches a new Active Directory user to an existing cloud-managed Entra user using sourceAnchor and onPremisesImmutableId, then changes the target's source of authority. MSPs should review privileged and break-glass accounts before allowing that match.
Who is affected by Microsoft's Entra hard-match block?
Beginning June 1, 2026, Microsoft Entra ID blocks a new Active Directory user from hard-matching to an existing cloud-managed Entra user that holds a Microsoft Entra role. Cloud users without Entra roles are not affected by this specific block.
Are existing hard-matched Entra users affected?
No. Microsoft says ongoing Active Directory to Entra ID sync for previously hard-matched objects is not affected. The change applies to new hard-match attempts involving privileged cloud-managed users.
What should an MSP check before Entra Connect or Cloud Sync cleanup?
Review cloud-only admins, break-glass accounts, Entra role assignments, onPremisesImmutableId and sourceAnchor history, sync filters, delegated access, the approval owner, rollback steps, and post-sync validation before changing identity source of authority.
Browse another FAQ cluster
Want the system behind the answers?
Scopable turns client context into roadmaps, scopes, and quotes your team can defend.