Microsoft keeps changing — and MSPs need to understand not only what is changing, but what those changes mean across the customer environments they manage.
On September 24, 2026, Microsoft MVP and Windows & Security Expert Sami Laiho joined us for a special MSP edition of Saminarium: an in-depth session covering security, Windows, identity, Microsoft Intune, AI and the broader Microsoft ecosystem.
If you missed the live session — or simply want the most important points again — you can find the recap, full recording and key takeaways below.
Saminarium for MSPs in 5 Minutes
Five hours of Saminarium, distilled into five practical takeaways for MSPs heading into 2027.
Five things MSPs should take into 2027
1. Patch speed is a security control
Vulnerability management is not only about identifying issues. The time between a fix becoming available and actually deploying it matters.
The direction is clear: organizations need to reduce the time attackers have to exploit known weaknesses while maintaining the level of operational control their environments require.
2. Protect how administration happens
For MSPs, protecting customer environments also means protecting the way those environments are administered.
Privileged access deserves stronger controls than ordinary user access. Where administrators connect from, which devices they use and how privileged access is granted all affect the potential blast radius of a compromised identity.
3. MFA is the baseline — not the finish line
Multi-factor authentication remains essential, but attackers increasingly target sessions, authentication flows and other weaknesses around MFA itself.
Phishing-resistant authentication, stronger access controls and continuous evaluation of access are becoming increasingly important parts of the security model.
4. Find legacy dependencies before they become urgent
Changes around technologies such as RC4 and NTLM show why legacy dependencies need to be understood before Microsoft changes defaults or removes support.
For MSPs managing many customer environments, visibility matters: knowing where older protocols and dependencies still exist makes it possible to address them before they become urgent operational problems.
5. Security is becoming continuous
The Microsoft security model continues to move away from static trust.
Passwords, permanent administrative rights, broad VPN access and network-location-based trust are increasingly being replaced by approaches such as:
- passkeys
- ephemeral privilege elevation
- per-application network access
- continuous authorization
- federated workload identities
- continuous device health and risk evaluation
At the same time, Microsoft Intune continues to expand beyond traditional endpoint management, with capabilities such as Intune Suite and Cloud PKI becoming part of a broader security and management platform.
Watch the full Saminarium for MSPs
Want the full context behind the five takeaways?
Watch the edited recording of the complete Saminarium for MSPs session below.
Topics covered during the session
The session explored a wide range of changes affecting MSP-managed customer environments, including:
- the current cybersecurity threat landscape
- ransomware groups and modern attack models
- privileged identity and administrative security
- Privileged Access Workstations
- identity attacks and rogue device registration
- vulnerabilities and patching
- AI opportunities, risks and cybercrime
- Windows 10 end of support
- Secure Boot changes
- RC4 deprecation
- NTLM and legacy authentication
- the future of Active Directory and Windows Server
- MFA, passkeys and phishing-resistant authentication
- Azure, Microsoft Intune and cloud developments
- the future of Windows
- continuous Windows servicing and hotpatching
- security development areas heading into 2027 and beyond
MSP Pulse: what the Saminarium audience told us
During the live session, we asked attendees three anonymous questions about the challenges and priorities they see in their own work.
The results point to three themes: capacity, visibility and AI.
49%: keeping up comes down to time and capacity
We asked:
What do you think is the hardest part for MSPs when Microsoft keeps changing?
49% of respondents selected:
Finding enough time and capacity to keep up
n=136
The challenge is not necessarily a lack of information. MSP teams need enough operational capacity to understand what has changed, determine which customers are affected and turn that information into action.
47%: configuration and policy changes are hardest to see clearly
We asked:
Which area do you think is hardest for MSPs to maintain clear visibility across customer environments?
47% of respondents selected:
Configuration and policy changes
n=107
As the number of customer environments grows, maintaining a consistent picture of configurations and policy changes becomes increasingly difficult.
That makes visibility across tenants an operational issue as much as a technical one.
57%: AI-related risks and opportunities lead the 2027 agenda
We asked:
Looking toward 2027, which area do you think deserves the most attention from MSPs?
57% of respondents selected:
AI-related risks and opportunities
n=140
AI was the clearest priority among the Saminarium audience.
But the security question is broader than whether AI itself is good or bad. MSPs increasingly need to consider how AI is accessed, what data it can reach, which identities are involved and how its use is governed across customer environments.
Responses from attendees of Saminarium for MSPs, September 24, 2026. These results reflect the participating audience and are not intended as a representative market survey.
What does this mean for MSP operations?
One theme ran through many parts of the session: Microsoft environments are becoming more dynamic, while MSPs are expected to manage them consistently across multiple customers.
That creates a practical challenge.
It is one thing to understand that Microsoft has changed a security recommendation, authentication method or endpoint capability.
It is another to know:
- which customer environments are affected
- whether configurations differ between tenants
- where legacy dependencies still exist
- whether required changes have actually been implemented
- whether environments remain aligned over time
The more customer environments an MSP manages, the harder this becomes to solve through manual processes alone.
Standardize security operations across customer environments
Plentics helps MSPs standardize and scale security and management operations across their customers’ Microsoft Intune and Microsoft 365 environments.
Bring consistency, visibility and automation to multi-customer operations — without managing each environment as a separate island.