CIO Brief: Your MSP Has Admin Rights — Are You Watching?
Retrospective: this article looks back at events from July 2021, written in 2026 with the benefit of hindsight.
The short version: In 2021, ransomware spread through Kaseya — software that IT service providers use to manage their clients' computers — reaching up to about 1,500 businesses at once. If you outsource IT, your provider's tools are a door into your company.
Why MSP access is a board-level risk
Managed service providers often have full administrator access to your devices, servers and Microsoft 365 tenant. That's what lets them help you — and what makes them a high-value target. Attackers compromise one provider to reach many customers.
The business impact
- Simultaneous ransomware across your entire company.
- No warning, because the attack arrives through trusted tools.
- Dependency on the provider's response during the incident.
Questions to ask your MSP
- What level of administrator access do you have in our Microsoft 365 tenant, and is it time-limited?
- Which tools do you use to manage our devices, and how are they protected?
- Do your staff use phishing-resistant MFA?
- How would you notify us of a breach, and how quickly?
Questions to ask your team
- Do we monitor what our MSP does in our environment?
- Could we cut off their access quickly in an emergency?
What good looks like
Least-privilege, time-limited MSP access, contractual security requirements, monitoring of partner activity, and a plan to operate if the MSP is compromised.
The decision
Review your MSP contract and access this quarter. If your provider still has permanent Global Administrator rights, ask them to move to least-privilege access.
- Kaseya VSA (July 2021): Ransomware Delivered Through an MSP Tool Incident Teardowns
- How to Restrict and Monitor MSP Access to Your Microsoft 365 Tenant How-To & Hardening
- Detecting MSP Supply Chain Attack: Sentinel and GuardDuty Detections Detection & Response