Welcome to a new series for a new era of MSPs! I’m Bryan Irwin and in this new blog series, I’ll share practical guidance to help managed service providers grow with Microsoft.
Managed service providers (MSPs) turn software into impact. A product announcement becomes a working configuration. A security recommendation helps protect a customer. A licensing change transforms into a business opportunity. Your actions define how users experience Microsoft products and services and we want your experience, and theirs, to be optimal. We know your needs are genuinely different from those of enterprise IT teams. You manage multiple tenants with varying expectations, needs, and business models. And they all expect you to have a depth and breadth of knowledge that is hard to maintain while busily keeping those tenants secure and productive.
So, what will you find in these blog posts? Practical guidance for MSPs from Microsoft, our ‘For MSPs’ partners, and MVP practitioners. Expect product updates, partner perspectives, and peer lessons learned in real-world customer environments.
Thank you for building your business on our platform. Use the comments to tell us what you want to learn more about, and we will keep showing up with something useful. Now let’s get started with our first edition.
Jump to: Microsoft updates | Roadmap rundown | Resources | Partner solutions | MVP insights | What’s next
Microsoft updates
Introducing Microsoft Meetups for MSPs
First up: How to run a managed service practice in the AI era
September 22, 2026 – 8:00 AM PT | 3:00 PM UTC
Kelvin Tegelaar, CTO @ Lime Networks and Microsoft MVP, will explain how you can build a disciplined AI operating model. Dive into best practices for protecting client data, standardizing tenant configurations, connecting automation to PSA and RMM platforms, and assigning clear human accountability for high-impact decisions.
Have a topic you would like covered in a future meetup? Take the Meetups for MSPs survey.
Roadmap rundown
Microsoft Intune Suite: Unattended Remote Help for Windows
- Why it matters: Remote sign-in could help technicians remediate customer devices when no user is present, especially during after-hours support and automated service operations.
- Suggested action: Evaluate whether unattended support could reduce desk-side work across customer environments. Before enabling it, verify licensing, permissions, auditability, security controls, customer consent, and supported Windows scenarios.
- Current roadmap status: General availability as of August 2026
Microsoft 365 Backup: Configurable recovery window
- Why it matters: Configurable recovery window for Backup is a direct customer conversation. It may affect compliance discussion, backup scope, design, recovery commitments, and storage planning.
- Suggested action: Review how configurable retention fits alongside existing backup services and customer recovery requirements.
- Current roadmap status: Rollout in progress as of August 2026
Microsoft 365 Backup: Full-workload backup
- Why it matters: A full-workload policy model could simplify backup configuration and standardization across customer environments..
- Suggested action: Evaluate whether Full Workload Backup can improve repeatability across customer tenants and simplify ongoing backup management. Compare the capability with the MSP’s current backup operating model before changing service design.
- Current roadmap status: Public Preview
Relevant resources
Microsoft Security
Lior Bela is still advocating for MSPs! Find him on his new series Trust Before Hype Thursday, September 24 (and every 2 weeks). He will also be talking about the Future of the MSP in an AI-First World: Security, Governance & Opportunity on Friday, September 25.
Microsoft Edge for Business
Your customers already spend most of their day in the browser, but few organizations actively manage or secure it. Explore practical guides to address common customer challenges — contractor and bring your own device (BYOD) onboarding, data security, shadow AI protections, branding and extensions — and build new service offerings with Edge for Business.
New to browser management as a service line? The MSP one-pager makes the case for why the browser is a security layer worth managing, and how it fits the Microsoft stack you already run. The license matrix shows which Edge for Business capabilities come with which Microsoft 365 licenses.
Microsoft Purview, Intune, and Entra
AI is creating a new wave of customer conversations around data security, compliance, and information governance. Many customers know they need to better understand and protect their data before fully embracing AI, but they often don’t know where to start. The Security Partner Toolkit is a collection of interactive tools and guidance documents built to eliminate that friction, covering the full partner motion and engagement lifecycle from positioning through deployment. Here’s what you’ll find in the toolkit:
|
Asset |
When to use it |
|
Industry one-pagers |
First customer conversation as an opening to data protection conversation or as leave-behind after customer meetings. |
|
Data security guided assistant |
During discovery/scoping with a new customer or customers with no existing labeling strategy to build a roadmap, co-design labels, and DLP policies. |
|
SOW Generator |
After discovery or during proposal development. Use as a configurable framework, not copy/paste. Currently scoped for Purview engagement only. |
|
Security SMB deployment guides |
Implementation planning and deployment of Business Premium, Purview Suite and Defender Suite |
|
PowerShell deployment scripts |
During implementation — clone, run What-If, review, then apply in a test tenant first. |
Your feedback on these resources will help shape what comes next. Tell us which assets you plan to incorporate into your practice, the customer scenarios or use cases you are addressing, and where additional guidance or automation would create the most value. Share your feedback and planned use cases.
Partner solutions for MSPs
AvePoint: AI Agent Management for Microsoft 365 tenants
What it is: A capability inside AvePoint Elements Workspace Management described as “a single multi-tenant dashboard for discovering, monitoring, and optimizing AI agents across customer environments.”
Covering Microsoft 365 Copilot including personal and chat agents, Copilot Studio, and SharePoint agents, this capability:
- Discovers and inventories AI agents across every customer tenant
- Shows usage, adoption trends, and inactive agents
- Flags inactive agents to inform licensing and cost decisions
- Shows which labeled and sensitive content agents have accessed
Read Introducing AI Agent Management and learn more if you:
- Manage several Microsoft 365 tenants and cannot say how many AI agents are running, who created them, or what data they reach
- Are packaging AI governance as a billable service
- Have customers deploying Copilot Studio or SharePoint agents without an ownership model
Before you quote it: The post is vendor-published and cites AvePoint’s own Road to AI Readiness study. No pricing, licensing tiers, or availability dates are given. Confirm details with AvePoint before using and details with a customer.
CyberDrain: CyberDrain Improved Partner Portal (CIPP) v10.10.0 – “Forget me not”
What it is: A two-week release covering roughly 20 additions plus fixes, including
- Self-hosted migration is open to the latest infrastructure changes
- Message Trace rebuilt on Graph, with historical search and mail-flow statistics
- JIT and PIM role templates that do not require an Entra ID P1 or P2 license
- Certificate-only SAM authentication for secret-less setup
- Quarantine overhaul, GDAP role templates, per-user MFA at user creation, and server-side paging for large tenants
Read the v10.10.0 release notes if you:
- Run CIPP self-hosted. The release notes state there is no support on self-hosted instances, so plan the migration accordingly.
- Spend time in message trace or quarantine across customer tenants.
- Depend on the Best Practice Analyser or classic dashboard. Both are removed in October, which makes this a dated task.
- Manage large tenants where paging performance has been a constraint.
Note: A few hotfixes have shipped since this announcement, so apply the latest available. In addition: the front end moved from MUI v7 to v9, so CyberDrain says “some things might not look exactly the same anymore.” Worth telling your technicians before they open a ticket.
CyberDrain runs its community in the open. You can join the conversation at r/MSP on Reddit, on LinkedIn, and on Discord.
inforcer: Threat Detection & Response for Microsoft 365
What it is: A multi-tenant threat detection and response capability built for MSPs to detect, investigate, contain, and report on threats across Microsoft 365 customer environments from one platform. It expands inforcer from Microsoft 365 configuration management into a broader management and security platform that
- Monitors Entra ID, Exchange, SharePoint, Teams, Defender, and Purview across customer tenants
- Correlates identity, privilege and persistence, data-exfiltration, email and messaging, and app/API signals into incidents using AI-powered detection backed by SOC validation
- Provides a multi-tenant incident view showing what happened, the affected users and services, and how the attack progressed
- Includes response actions such as locking compromised users, revoking active sessions, and retracting malicious email
- Produces forensic and customer-ready reports and identifies Microsoft 365 policies or configurations that could have prevented an incident
Explore Threat detection and response built for MSPs managing Microsoft 365 if you:
- Manage security operations across multiple Microsoft 365 tenants and want incidents correlated in one view
- Need built-in containment actions and customer-ready reporting rather than an alert-only workflow
- Want to connect incident response back to configuration improvements across your customer base
A free trial is available.
Before you quote it: This is vendor-published launch information. Claims about AI-powered detection, SOC validation, supported workloads, response actions, and prevention recommendations are inforcer’s descriptions. Confirm pricing, licensing, tenant prerequisites, data handling, service coverage, and contractual response commitments before positioning it to a customer. inforcer states TDR is generally available to MSPs.
Nerdio: A closer look at the Intune Management Extension
What it is: A practitioner’s guide to the Intune Management Extension (IME), the Windows agent behind Win32 app deployment, PowerShell scripts, remediations, custom compliance discovery, and device query. When an app or script fails, the useful evidence sits on the device rather than in the Intune console, which makes IME troubleshooting a recurring service-desk skill. In the guide, you’ll learn:
- What the Intune Management Extension is and why Intune needs it
- How the agent runs (service, check-in cadence, and execution context)
- The log files that answer common IME tickets
- A troubleshooting playbook for stuck apps and silent scripts
- How the IME behaves on Windows 365 Cloud PCs and Azure Virtual Desktop session hosts
- Where Nerdio Manager extends Intune on both cloud desktop paths, and what this means for your Cloud PC and session host baseline
- Frequently asked questions about Microsoft Intune Management Extension
Read Understanding the Intune Management Extension if you:
- Deploy Win32 apps or PowerShell scripts across customer tenants and want a repeatable diagnostic path for your service desk
- Are training newer technicians who escalate app-install failures without checking device logs first
- Want to turn ad-hoc troubleshooting into a documented runbook
You can also watch an on-demand webinar covering recent Nerdio Manager for MSP updates.
Robopack introduces Intune Academy
What it is: An education-based program designed to work around you with on-demand modules that let you start with the basics, build confidence, and work toward a more advanced setup without anyone setting the pace for you. Focus on what matters most and move as fast or as slowly as you need to utilizing:
- Free video courses – Short, focused demos and video lessons will be released weekly, covering Intune fundamentals through to advanced topics
- Track your progress – Mark lessons as complete and pick up where you left off. Visual progress tracking keeps you motivated throughout each course.
- 1:1 clinics – Book a one-on-one session with an Intune expert. Get personalized help with your specific deployment challenges.
- Completion badge – Complete the Academy and earn a digital badge that recognizes your progress and commitment to growing your Intune skills.
- Regular office hours – Live, community-led sessions to talk through real-life scenarios and get guidance from peers and industry experts alike.
- Community support – Stay connected between sessions with a dedicated space to ask questions, share what’s working in your environment, and tap into other Intune admins’ experiences.
Join the waitlist at https://intune.academy if you:
- Look after Intune across multiple tenants and want a consistent baseline rather than a different approach per customer
- Are onboarding technicians who need structured Intune training without a budget line
- Own Intune alongside other responsibilities and want a repeatable way to run it
Worth noting: The program is vendor-run and new, so course content and cadence may change as the first cohort works through it.
MVP insights
MVP-authored materials are provided for informational purposes and reflect the authors’ views, not necessarily Microsoft’s. Microsoft has not independently validated or endorsed the content. Verify technical, security, compliance, licensing, and business guidance against current official Microsoft documentation and your requirements before acting.
IntuneFans: A community hub for Intune news
What it is: An aggregation of Intune content into a single timeline, described as “real-time updates from Microsoft Intune blogs, community authors, and official docs, no algorithms, just fresh Intune news delivered daily.” Here are a few highlights for popular feeds and features:
- Radar collects community blog posts, YouTube channels, and short-form updates from seeded sources, with tagging by topic.
- Sonar and Docs Radar track Microsoft 365 Message center items and official documentation changes separately from community content.
- A conference calendar lists Intune community events and open calls for papers, with Sessionize and Meetup integration.
- Authors can add their own blog by RSS feed, submit a YouTube channel, register an event, or exclude individual posts from Radar.
Read the IntuneFans FAQ and visit IntuneFans if you:
- Track Intune changes across a dozen blogs and want one timeline instead of a dozen tabs
- Need to watch Microsoft 365 Message center and documentation changes that affect customer tenants
- Publish your own Intune content and want it reaching the community, or speak at events and want your sessions listed
- Are planning conference travel and want Intune community events and CFP deadlines in one calendar
Source: Simon Skotheimsvik
Before you quote it: IntuneFans site aggregates community-authored content alongside Microsoft sources. Aggregation is not validation, so verify any technical claim against the original post and Microsoft documentation.
Making application control maintainable
What it is: An article with tips on avoiding the “exception factory” that develops when application-control policies arrive without an operating model behind them. It offers five techniques for keeping an enforced policy maintainable: Managed Installer, supplemental policies, documented exceptions, deployment rings, and rollback planning. It also emphasizes key points, such as:
- Managed Installer tagging is not retroactive so applications installed before the configuration reached the device do not become trusted.
- Delivery can take up to 30 minutes after the policy becomes active, and the Managed Installer overview can take up to 24 hours to update device status.
Read App Control for Business Part 2: How to Avoid the Exception Factory if you:
- Are planning to enforce application control for a customer and have not yet defined the exception process
- Already run App Control and find exception requests consuming more time each month
- Want application control to work as a repeatable managed service rather than a one-time deployment
Source: Dustin Gullett
Before you quote it: This article is practitioner interpretation. Verify claims about supported behavior, join requirements, and limitations with the Microsoft documentation linked to in the article.
Detecting and managing shadow AI
What it is: A walkthrough of how Intune inventory and investigation capabilities support conversations about unmanaged local AI agents, using OpenClaw as the example. The sequence is discover, investigate, then control, and the order matters, because blocking first can disrupt legitimate Node.js or Windows Subsystem for Linux workloads. Other insights from the article:
- The control step uses the Local AI Agent Baseline – OpenClaw (Preview), which ships two firewall rules, both blocking outbound TCP from Node.js executables.
- Microsoft is direct about the limits: “These settings might not fully block all agent execution paths,” and the baseline “might also block other processes in addition to OpenClaw.”
- Intune inventory applies to corporate-owned, Intune-managed Windows devices that are Microsoft Entra joined or hybrid joined, and initial data can take up to 24 hours
- The Shadow AI view in the Microsoft 365 admin center requires Frontier preview opt-in, Microsoft Defender for Endpoint, Intune enrollment, and Microsoft 365 E5.
Read Detect and Block Shadow AI with Intune: OpenClaw in Practice if you:
- Have customers asking what AI tools are running on their endpoints and cannot answer yet
- Support developer or engineering customers where Node.js and WSL are part of daily work
- Are building endpoint AI governance into a security service and want a starting sequence
Source: Jannik Reinhard
Before you quote it: The baseline is in preview. Confirm device support, prerequisites, and licensing, and test against legitimate developer workloads and Microsoft documentation before deploying broadly.
Managing multiple accounts with app protection policies
What it is: A walkthrough of Multiple Managed Accounts, the Intune mobile application management capability that lets a user hold more than one MAM-enabled account inside a single app, each governed by its own app protection policy. This is the consultant scenario: an engineer with a managed account at their employer and a second at a customer. This is what you’ll see in action:
- Supported today on Teams for iOS and iPadOS at v8.10.0 or later, and Outlook for iOS and iPadOS at v5.2626.0 or later
- Microsoft notes the feature “is rolling out gradually and may not yet be available in your tenant”
- One account can be MDM and MAM managed with additional accounts MAM-only. Multiple MDM is not supported, and wrapped apps are out of scope
- Teams shows one account at a time. Outlook shows several, and Microsoft states that “Mixed views always enforce a full lockdown (most restrictive behavior)”, blocking cut, copy, paste, and screen capture
- The IntuneMAMAllowedAccountsOnly key restricts an app to a single managed account on managed devices
Read Using multiple managed accounts with app protection policies if you
- Have technicians who work across their own tenant and customer tenants from mobile devices
- Are supporting engineers through a merger or acquisition with accounts in two tenants
- Plan to build a workflow that depends on copy and paste between accounts, which mixed-view lockdown will block
Source: Peter van der Woude
Before you quote it: Confirm app versions, platform scope, and rollout status in each tenant involved before designing around this.
Windows Autopilot device association series
What it is: A three-part series that moves from mechanism to automation to architecture. Start with terminology, because the models are not peers. Microsoft defines device association as “a feature of Windows Autopilot device preparation that binds a Windows device to your organization before the device enrolls with a mobile device management (MDM) provider.” Windows Autopilot and Windows Autopilot device preparation are the deployment solutions. Device association is an optional feature that gives device preparation early knowledge of the organization. In order, the series offers:
- Technical deep dive. Windows Autopilot Device Association follows the complete flow: exporting the DeviceLink identity, discovery, TPM-backed attestation, the signed association stored in UEFI, and Windows retrieving the device preparation OOBE settings.
- Practical automation. Windows Autopilot Device Association: somebody has to be the OEM: OEM and partner pre-association is not available, so somebody still has to do that work. This article introduces Get-AutopilotDeviceAssociation, a script that automates association, validation, and removal in place of the manual USB and Intune portal workflow.
- Architecture and comparison. Windows Autopilot Device Preparation vs Device Association vs Classic Autopilot: What Is the Difference? compares classic Autopilot, base device preparation, and device preparation with device association, covering what changed, what each model can do before sign-in, and where the support boundaries sit.
Key takeaways:
- Device association writes a tenant affinity marker into the device’s UEFI firmware, verified through hardware-based attestation and TPM-backed validation.
- That unlocks device-targeted policy assignment, device naming before enrollment, automatic corporate marking, and OOBE customizations base device preparation cannot apply.
- Precedence is documented: if the device is not associated, the Windows Autopilot profile wins; if it is associated, device association wins and the device preparation deployment runs.
- Both solutions can run side by side in one organization, but any single device runs only one.
Check out the full series if you:
- Are choosing a provisioning model for a new customer and need the support boundaries side by side
- Support customers on hybrid join, Windows 10, or pre-provisioned scenarios, which remain Windows Autopilot territory
- Work with GCC High or DoD customers, where device preparation is supported and Windows Autopilot is not
Source: Rudy Ooms
Before you quote it: OEM and partner pre-association is not available today, which is why the association step still needs someone to perform it. Confirm current support boundaries in Microsoft Learn before building a provisioning design around them.
What’s next
We want to build a useful blog and meetup series so I hope you join the next meetup, subscribe to this blog, and leave your comments, questions, and suggestions for future topics below. Help us bring you the experts, topics, and insights that will help you grow your business.


