Defanging the RMM: Zero Trust for MSP Integrations
Stop treating your managed service provider's remote agents like domain admins and start fencing them with strict behavioral controls.

July 2, 2021, felt like a standard Friday afternoon until thousands of servers simultaneously started executing a malicious script dropped by their own management software. The Kaseya VSA supply chain ransomware attack was a masterclass in exploiting implicit trust. The REvil syndicate did not need to phish employees, purchase stolen session tokens, or guess passwords. They just found a zero-day in the central nervous system connecting managed service providers to their downstream clients. By compromising the central server, the attackers instantly gained administrative execution rights across a massive, globally distributed footprint.
When the perimeter is outsourced, the threat model shifts entirely. You are no longer just defending against your own misconfigurations or your users clicking bad links. You are inheriting the operational security failures of a third-party vendor who holds the keys to dozens of other networks. If a threat actor breaches the MSP, they use the legitimate infrastructure to pivot directly into your environment.
Achieving true msp blast radius containment requires treating remote monitoring and management tools not as trusted administrators, but as highly radioactive execution vectors that need constant supervision. You have to assume the remote agent will eventually turn hostile, and you must design your network to survive that exact moment.
The Anatomy of a Trusted Execution Bypass
Exploiting Implicit Trust
Security teams have historically treated RMM tools like untouchable artifacts. The rationale is purely operational. Agents from ConnectWise, Datto, Kaseya, or NinjaOne need deep system access to patch operating systems, install software, execute administrative scripts, and pull system event logs. To prevent endpoint detection and response platforms from isolating these agents during routine maintenance tasks, IT administrators frequently apply blanket folder or hash exclusions. They instruct the EDR to completely ignore whatever the agent executable is doing.
That blanket whitelist is exactly what REvil banked on during the Kaseya incident. By injecting a malicious payload through an authentication bypass and SQL injection vulnerability in the on-premises Kaseya VSA server, the attackers pushed an update down to the client agents. The local EDR agents on the victim networks saw the VSA agent drop an ancient, vulnerable version of Microsoft Defender alongside a malicious DLL file. Because the parent process was the whitelisted RMM agent, the EDR telemetry was effectively muted. The ransomware then used a classic DLL sideloading technique, forcing the legitimate Microsoft executable to load the malicious payload into memory.
The Fallacy of the Vendor Questionnaire
The takeaway from these supply chain attacks is grim but necessary. If your defense strategy relies primarily on a vendor questionnaire asserting that your MSP has a solid security posture and a SOC 2 Type II compliance report, you are operating on borrowed time. Compliance does not equal containment. Trusting the vendor business is fine, but trusting their endpoint agent to act with impunity across your entire fleet is architectural negligence. Defenders must shift from static trust models to continuous verification.
Identity Segregation and Tiering Boundaries
Protecting Tier 0 Assets
Most MSP deployments are fundamentally flawed at the identity layer. An RMM agent typically runs as NT AUTHORITY\SYSTEM on the Windows endpoint. If that endpoint is a Domain Controller, the MSP effectively holds the keys to the kingdom. If the MSP gets breached, the attacker automatically inherits Tier 0 Active Directory privileges within your network, allowing them to dump the NTDS.dit file, forge Golden Tickets, and establish permanent persistence before you even realize an incident is underway.
You must sever this default inheritance. Remote management agents belong on workstations and member servers, but they have absolutely no business running on Tier 0 identity assets, certificate authorities, or critical database clusters. If your service provider insists they need an agent on your Domain Controller to monitor event logs or resource usage, push back hard. Instead, use native Windows Event Forwarding to send those specific logs to a hardened member server where the agent can safely read them without holding SYSTEM rights on the domain.
Service Account Fencing
Furthermore, the dedicated service accounts used by the MSP must be heavily restricted. Using Group Policy Objects, these accounts must be configured to deny interactive logon and deny remote interactive logon. They should only be allowed to authenticate from specific jump boxes or dedicated management VLANs. An MSP service account logging into a database server from a receptionist's workstation is an immediate, glaring anomaly that should trigger an instant account suspension. If you map these logon constraints in your Active Directory architecture, an attacker who compromises the MSP cannot easily pivot laterally using the hijacked credentials because the environment will actively reject the authentication requests.
Writing Behavioral Fences in EDR
Removing blanket exclusions is the critical first step, but you cannot simply flip the switch and let the EDR block your IT provider from doing their job. You have to replace static exclusions with highly tuned behavioral fences. You are no longer asking the system if the file hash is trusted; you are asking if the behavior is contextually appropriate for a management tool.
An RMM agent executing a standard PowerShell script to query WMI is normal behavior. An RMM agent executing a heavily obfuscated, base64-encoded PowerShell script that attempts to disable shadow copies via vssadmin.exe or modify boot configurations is a catastrophic failure. Defenders need to build custom detection rules mapping directly to MITRE ATT&CK techniques, specifically focusing on process lineage, memory allocation patterns, and command-line arguments spawned by management agents. You must write Sigma rules or native EDR queries to catch the exact moment the agent goes rogue.
ParentImage endswith agent.exe AND CommandLine contains any (vssadmin.exe delete shadows, bcdedit.exe /set {default} recoveryenabled no, certutil.exe -urlcache -split -f, powershell.exe -ExecutionPolicy Bypass -EncodedCommand) — Example Sigma rule logic for RMM behavioral fencing
That logic should immediately trigger an automated isolation protocol, severing the host from the network while preserving memory for forensics. Your SOC analysts should also heavily monitor for unexpected child processes. If an RMM tool suddenly spawns cmd.exe to ping external IP addresses, drops unknown binaries into public user directories, or initiates lateral movement via wmiexec, the EDR must suspend the process tree. You are effectively putting the RMM agent in a continuous sandbox. It can do its day job, but it triggers deafening alarms the moment it reaches for standard attacker living-off-the-land binaries.
Enforcing Just-In-Time Access and Network Micro-segmentation
The Death of Persistent Access
The concept of persistent, always-on access for external vendors is a historical relic that has no place in modern security architecture. There is zero operational justification for an MSP to have active administrative sessions into your critical environment at three in the morning unless there is an active, documented incident. Modern access control demands Just-In-Time provisioning tied to an approved ticketing workflow.
When a Tier 2 technician at your provider needs to troubleshoot a server, they should request access through an identity broker. That request temporarily elevates their privileges or enables their network route for a highly specific time window, perhaps two hours. Once the maintenance window closes, the credentials expire, the session forcefully terminates, and the firewall rules revert to a default deny state. If an attacker compromises the MSP outside of that maintenance window, there are no active sessions to hijack and no open network paths to exploit over SMB on Port 445 or WinRM on Port 5985.
Choking the Network Egress
Network micro-segmentation acts as the physical barrier backing up this identity control. RMM agents should only be able to communicate outbound to the specific IP addresses, fully qualified domain names, or API endpoints officially owned and documented by the vendor. They should absolutely not be able to scan your internal subnet, establish peer-to-peer connections with other workstations, or reach out to arbitrary domains. By tightly constricting the egress firewall rules specifically for the agent executable, you cut off the external command and control channels ransomware operators rely on to drop secondary payloads, negotiate encryption keys, and exfiltrate stolen data.
Incident Response and Tabletop Exercises
Preparing for the Call
Even with immaculate controls in place, you must prepare for the operational reality that your MSP will eventually be compromised. Blast radius containment is only effective if your security operations center knows exactly how to respond when the containment systems trigger. When your EDR dashboard lights up with alerts showing the RMM agent attempting to encrypt local disks, the response time is measured in minutes, not hours.
Your incident response plan must include a dedicated playbook for supply chain compromise. You need a pre-authorized kill switch to globally sever all network connections to the MSP's infrastructure, disable their dedicated service accounts in Active Directory, and forcibly isolate any endpoint running the agent. Run tabletop exercises specifically focused on this scenario. Ask your team how long it would take to identify the rogue activity, who has the authority to sever the connection to a critical vendor, and how the business will continue to function while the IT management plane is completely disabled.
The takeaway
You cannot outsource your risk. While a managed service provider provides necessary operational scale and expertise, granting them unfettered, unmonitored access to your infrastructure transforms their massive attack surface into your immediate problem. Containing that blast radius means building a hostile environment for lateral movement, where every action taken by a remote agent is aggressively interrogated by behavioral rules and severely restricted by absolute identity boundaries. Security is not about trusting your partners; it is about cryptographically ensuring that a breach of their systems ends at your front door.
Start by auditing your EDR exceptions today. Rip out the legacy folder exclusions and replace them with precise process behavioral monitoring. If your MSP's own corporate environment goes down, triggering a flood of suspicious communication that spills into your inboxes, tools like MailSleuth.AI can help your SOC rapidly triage the forensic email headers to determine if their Exchange server is sending Business Email Compromise payloads. Trust the service they provide, but verify every single command their software attempts to execute on your metal.
We dissect phishing campaigns and email infrastructure so you don't have to.


