Connect with us

NEWS

ConnectSecure Turns M365 Security Into Scalable MSP Services

ConnectSecure launches multi-tenant M365 auto-remediation, AI assessments and Patch 360 so MSPs can deliver security as a repeatable service instead of tickets.

Published

on

ConnectSecure on August 11 made Microsoft 365 Auto Remediation, AI-powered Training Assessments and Patch 360 available on its platform so managed service providers can approve supported security fixes once and push them across multiple client tenants. The Tampa-based firm says the package turns findings into action, training measurement and staged patching from a single multi-tenant console.

MSPs already scan and report. The new write path and content tools aim to cut the ticket labor that has kept M365 hardening stuck at the scale of individual technicians.

What Landed in the Platform This Week

The M365 Auto Remediation and AI-powered Training Assessments launch sits on top of ConnectSecure’s existing M365 Security Inspection. Auto Remediation covers a defined subset of findings that map to conditional access policy changes or report-only mode. Partners select the finding, choose enable or report-only, and can adjust existing policies before applying the change across tenants that support it.

Supported findings listed in the announcement include administrative users without multifactor authentication enforced, legacy authentication, risky sign-ins, user risk, device registration, security information registration, self-service password reset and Microsoft Secure Defaults. Patch 360, first introduced in June, now sits inside the same platform with pilot-first validation, risk-based prioritization, staged rollouts, approval workflows and integrated rollback.

Training Assessments lets users generate quizzes from a topic, pasted text, uploaded files or templates. The AI drafts questions, choices and explanations; humans review and edit before publish. Settings cover question count, difficulty, time limits, expiration, attempt caps, pass thresholds and question types. Analytics track company pass rates and question-level results. Multi-language support is included for diverse workforces. Use cases named by the company run from compliance and onboarding to third-party due diligence and awareness programs.

Peter Bellini, CEO of ConnectSecure, said in the announcement: “MSPs are under pressure to do more than point out problems. They need to help clients fix gaps, prove progress and build stronger security habits over time.”

Tenant-by-Tenant Work Hits a Hard Wall

Microsoft 365 runs email, files, identity and a growing set of AI features for most organizations. Attackers treat the suite as a single high-value surface. ConnectSecure CTO Shiva Shankar told Channel Dive the biggest risks are weak identity controls, misconfigured settings, risky third-party app permissions and confusion over who owns what.

  • 90 percent of organizations in a study of 1.6 million Microsoft 365 users showed gaps in essential protections such as MFA, email security, password policies and failed-login handling, per ConnectSecure’s own M365 Assessment module features and stats.
  • More than 1,292 vulnerabilities were reported across Microsoft products including Microsoft 365 between 2021 and 2023.
  • A 2023 China-linked breach of Microsoft cloud email systems hit roughly 10,000 organizations.
  • A 2021 Power Apps misconfiguration exposed data of more than 38 million users.

For an MSP the problem multiplies. Each client tenant carries different baselines, risk tolerance and drift. Manual sign-in, policy edit and ticket close does not scale past a handful of accounts without extra headcount or missed findings.

Shankar put the design mismatch plainly: “Microsoft provides strong security tools, but they weren’t designed with MSPs in mind. Most security management happens tenant by tenant, making it difficult to scale across many clients. Ultimately, MSPs need more than visibility. They need a way to deliver security as an efficient, repeatable service.”

Three Capabilities That Finish the Loop

The platform already offered scans, prioritized findings, remediation guidance and scheduled rechecks. Auto Remediation adds the controlled write. Training Assessments adds measurable education. Patch 360 covers the endpoint and application side with the same multi-tenant discipline.

Supported Auto-Remediation Finding Typical Control Lever
Admin users lacking MFA Conditional access / enforcement
Legacy authentication Block or report-only policy
Risky sign-ins / user risk Risk-based CA policies
Device registration gaps Registration and compliance rules
Security info registration / SSPR Self-service and registration policies
Microsoft Secure Defaults Enable or align defaults

Srividya Jagannathan, senior vice president of engineering, said security programs work best when remediation and education run together: partners can address configuration risk more directly and measure whether users understand the practices that keep the posture strong.

  • Approve once, apply across eligible tenants for supported findings instead of per-client tickets.
  • Generate, edit and assign AI-assisted assessments with analytics that prove completion and comprehension.
  • Run Patch 360 pilots, prioritize by risk and CISA signals, stage rollouts and roll back if needed.
  • Keep the full flow inside one multi-tenant console already used for vulnerability and compliance work.

Patch 360 prioritization draws on severity, exploitability and the CISA Known Exploited Vulnerabilities catalog so MSPs can focus scarce change windows on the items most likely to be weaponized.

Shared Responsibility Still Sits With the Customer

Microsoft’s documentation is unambiguous. Under the shared responsibility model for SaaS workloads, the customer owns data, identities, configurations, settings, access management and multifactor authentication decisions. Microsoft owns the underlying infrastructure, physical hosts, network fabric inside its datacenters and large parts of the platform itself.

Many SMB buyers still assume the vendor “secures everything.” That assumption leaves MFA gaps, open legacy protocols and over-permissioned apps untouched until an incident or an insurance questionnaire forces the issue. Shankar noted that for many small and mid-sized businesses the MSP is the security team. Those firms face the same threats as larger enterprises without dedicated staff. The new tools target exactly that gap: give the partner a way to close configurations, train users and patch at the speed of a productized service rather than a project.

The same identity and productivity surface is also absorbing more AI features. Tools such as the Microsoft Copilot super app consolidation raise the value of a clean tenant and the cost of a misconfigured one.

From CyberCNS Roots to Millions of Assets

  1. 2021, CyberCNS founded by Cisco and Microsoft veterans; focused on MSP multi-tenant vulnerability management.
  2. 2022, Peter Bellini (ConnectWise family) invests; rebrand to ConnectSecure begins; early MSP count already above 1,200.
  3. October 2024, M365 Assessment module enters beta with CIS-aligned scans, reports and guided remediation.
  4. June 2026, Patch 360 launches; TD SYNNEX distribution partnership expands global reach with flexible month-to-month terms.
  5. August 11, 2026, Auto Remediation and AI Training Assessments go live; Patch 360 integrated into the same console.

Bellini has said the company now protects more than 2.2 million assets and wants that number higher. The stated mission is affordable, solid cybersecurity delivered through the MSP channel because that is how most SMBs actually buy protection. The platform sits in the vulnerability and compliance management platform category, scanning endpoints, networks, cloud and identity while mapping to CIS, NIST, SOC 2 and similar frameworks.

Partners Will Test Controls Before They Promise SLAs

Early independent commentary flagged the need for a fully public control catalog, exact GDAP and Graph permission scopes, rollback behavior and commercial packaging details. The announcement does list the initial supported findings and ties changes to conditional access or report-only mode, yet production MSPs still treat any write path into a customer tenant as high-risk until they have run it on a pilot.

Automating remediation is great; automating mystery settings is how MSPs earn gray hairs.

That line from a Windows Forum summary captures the practical stance many operators are taking. The responsible first move is a non-production or low-risk tenant, comparison against the MSP’s own documented baseline, least-privilege GDAP roles, and an audit trail that records who approved what and when. Exception handling for clients that intentionally diverge from the standard also matters for long-term trust.

AI-generated assessments carry a parallel discipline requirement. Generic questions about controls the client does not use, or obsolete procedures, teach the wrong response. The review-and-edit step before publish is therefore non-negotiable if the assessments are to support real incident behavior rather than checkbox training.

The broader category is already moving. Other multi-tenant M365 remediation and detection tools have appeared in the same window, confirming that scaling configuration hygiene across dozens of tenants is a live operational pain point rather than a niche feature request.

How the Economics Shift for the Partner

Visibility alone creates tickets. A standardized, approved remediation that can run across many tenants turns the same finding into a billable, repeatable service line. Training analytics give the partner proof of progress to show the client and the insurer. Staged patching with rollback reduces the weekend fire drills that erode margin.

Bellini has framed the larger channel move as a second shift after the original jump from break-fix to managed services: many MSPs are now pivoting from reactive cybersecurity to managed security. Tools that close the loop from find to fix to educate make that pivot concrete. The MSP can price a baseline M365 hardening and awareness package, deliver it consistently, and still leave room for higher-tier consulting on the exceptions.

For the SMB client the outcome is simpler. The organization that never hired a security engineer still gets MFA enforced for admins, legacy protocols retired, risky apps reviewed and users tested on the practices that matter. The shared-responsibility gap shrinks because the partner finally has software that matches the multi-tenant reality of the business model.

ConnectSecure’s August package does not invent new Microsoft controls. It packages the ones MSPs already know they must enforce and gives them a way to enforce them at the speed of a product. That is the second-order change: security stops being a collection of one-off tasks and starts looking like a scalable service.

Logan Pierce is a writer and web publisher with over seven years of experience covering consumer technology. He has published work on independent tech blogs and freelance bylines covering Android devices, privacy focused software, and budget gadgets. Logan founded Oton Technology to publish clear, no nonsense tech news and reviews based on real hands on testing. He has personally tested and reviewed dozens of mid range and budget Android phones, written extensively about app privacy, and built and managed multiple WordPress publications over the past decade. Logan holds a bachelor's degree in English and studied digital marketing at a certificate level.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending