Multi-CloudCIO BriefingsRetrospectives

CIO Brief: Your MSP Has Admin Rights — Are You Watching?

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from July 2021, written in 2026 with the benefit of hindsight.

The short version: In 2021, ransomware spread through Kaseya — software that IT service providers use to manage their clients' computers — reaching up to about 1,500 businesses at once. If you outsource IT, your provider's tools are a door into your company.

Why MSP access is a board-level risk

Managed service providers often have full administrator access to your devices, servers and Microsoft 365 tenant. That's what lets them help you — and what makes them a high-value target. Attackers compromise one provider to reach many customers.

The business impact

  • Simultaneous ransomware across your entire company.
  • No warning, because the attack arrives through trusted tools.
  • Dependency on the provider's response during the incident.

Questions to ask your MSP

  • What level of administrator access do you have in our Microsoft 365 tenant, and is it time-limited?
  • Which tools do you use to manage our devices, and how are they protected?
  • Do your staff use phishing-resistant MFA?
  • How would you notify us of a breach, and how quickly?

Questions to ask your team

  • Do we monitor what our MSP does in our environment?
  • Could we cut off their access quickly in an emergency?

What good looks like

Least-privilege, time-limited MSP access, contractual security requirements, monitoring of partner activity, and a plan to operate if the MSP is compromised.

The decision

Review your MSP contract and access this quarter. If your provider still has permanent Global Administrator rights, ask them to move to least-privilege access.

kaseya ransomware attack impactKaseya2021

More on this story