Most MSPs can already tell you which of their clients' Microsoft 365 environments are misconfigured. The harder question is why so few get fixed — and what it takes to turn security visibility into security operations at scale. Dave sits down with Nick Ross, CEO of Cloud Capsule and a three-time Microsoft MVP, to talk about the operational gap MSPs can't close with assessment tools alone, and how his team is trying to close the distance between finding problems and remediating them across dozens of client tenants at once.
Nick launched Cloud Capsule's Manage tier in May to move partners beyond assessment into remediation. He argues the biggest challenge in M365 security isn't visibility — it's execution: the knowledge gap around how to architect a policy, plus the manual hours to deploy it one tenant at a time. He walks through how the platform templatizes baselines, enforces desired state configuration so controls can't be quietly tampered with, and gives technicians the context to know whether flipping a control from red to green will flood the help desk with tickets.
The conversation also digs into the harder business questions: whether pushing security work down to junior techs lowers the skill floor and introduces risk, how to prioritize 250+ controls without drowning in red, and the economic reality that many MSPs already know clients are misconfigured but can't get them to pay for the fix. Nick's answer leans on newer levers — the AI-readiness conversation, Copilot data governance, and cyber insurance renewals — to reframe security as table stakes rather than a hard sell.
Supported by:
Guardz
💼 All Our Sponsors
MSP Radio is supported by our partners:
Transit AI · Guardz · Pax8 · ABC Solutions · Rythmz · ScalePad · CometBackup · TimeZest
Supporting the IT services community through insights, analysis, and transparency.
🚀 Join Business of Tech Plus
Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.
👉 https://businessof.tech/plus
🎧 Subscribe to the Business of Tech
Want the show on your favorite podcast app or prefer the written versions of each story?
📲 https://www.businessof.tech/subscribe
📰 Story Links & Sources
Looking for the links from today’s stories?
Every episode script — with full source links — is posted at:
🎙 Want to Be a Guest?
Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:
💬 https://www.podmatch.com/hostdetailpreview/businessoftech
🔗 Follow Business of Tech
LinkedIn: https://www.linkedin.com/company/28908079
YouTube: https://youtube.com/mspradio
Bluesky: https://bsky.app/profile/businessof.tech
Instagram: https://www.instagram.com/mspradio
TikTok: https://www.tiktok.com/@businessoftech
Facebook: https://www.facebook.com/mspradionews
Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.
[00:00:01] Most MSPs can already tell you which of their clients' Microsoft 365 environments are misconfigured. The harder question is why so few have actually fixed them, and what it takes to turn security visibility into security operations at scale. In this conversation with Nick Ross of Cloud Capsule, you'll hear how one company is trying to close the gap between finding problems and remedying them across dozens of client tenants simultaneously.
[00:00:28] And what that shift means for how MSPs price, staff, and prove their security programs. This is the Business of Tech. I'm Dave Sobel. Nick Ross, you are the CEO at Cloud Capsule. Welcome to the Business of Tech. Appreciate it, Dave. Happy to be here. So let's start with, you've launched your managed tier back in May, and the idea was to move beyond assessment into remediation.
[00:00:55] Talk to me a little bit about the operational gap that MSPs were telling you they couldn't close with just the assessment tools alone. Nick Ross, MD Yeah, so I worked at a couple of MSPs myself to understand, you know, kind of the nature of, you know, the operational sense of, hey, we need to do everything from get this reporting to understand where we need standardization. Nick Ross, MD But I also need tooling to understand that we can automate and streamline deployments across our customers when Microsoft's always changing.
[00:01:24] Nick Ross, MD But also because of, you know, the technical knowledge transfer that has to occur with a lot of these different radiations that we're looking to do. Nick Ross, MD Great example. Most MSPs, if you told two technicians to do the same task, you know, go fulfill this one policy in a tenant with documentation. Nick Ross, MD They may or may not have an IT glue or hoodoo as an example. They may do and complete it in two different, highly different ways, right, in that example.
[00:01:49] So really what we're trying to solve for here is consistency, but also streamlining that automation of repetitive work that you have to do managing, you know, 25 to 100 plus clients, right, at one state and time. Nick Ross, MD Especially while the industry as a whole shifts from a security perspective, but also we all have this pain around Microsoft changing all the time, you know, and really being able to scale that out across your MSP as well.
[00:02:14] Nick Ross, MD Gotcha. Now, am I right to think about that as like kind of the first step towards full automation? Because I would think that if you're kind of defining it for people, at some point, you'll be moving toward, well, it'll just do it. Is that the way that I should be thinking about this? Nick Ross, MD Well, I think you have certain constraints.
[00:02:31] Nick Ross, MD There, but certainly there's a progression path, right, where, you know, you want to have a level of control today because there's a lot of end user impact considerations that you need to be aware of. And I think that's one thing that we do uniquely in the space is we give you all this context to understand what does the existing tenant look like today, but also what's going to happen if you turn this button from red to green, right, in that sense, or you fulfill this control? Are you going to suddenly get a bunch of help desk tickets? Are you going to cut off productivity that you didn't realize that you're going to do within the business?
[00:03:03] Nick Ross, MD Nick Ross, MD
[00:03:14] Nick Ross, MD You would never want them to be turned off or be tampered with. And at a macro sense, like that, that term is called desired state configuration in our, in our space. DSC is an acronym for it. But it's really to say like, hey, I can autonomously push this out. But I can also always monitor it and make sure that's always in a compliant state.
[00:03:34] Nick Ross, MD, PhD through either, you know, accidental tampering or, you know, somebody is co-managed and they have an IT guy go in and turn things off or we did things inadvertently or malicious in nature. You know, we see that with like the MITRE attack surface and conditional access tampering is a great example of that where somebody will compromise user, compromise conditional access policies to then, you know, further their attack in an account. Nick Ross, MD So there's a lot of layers to that in the sense of the security impact as well.
[00:04:02] Nick Ross, MD Gotcha. And the other thing I also thought was interesting is you've said the biggest challenge in Microsoft 365 security is not visibility, but actually execution. And I kind of want to get a little sense of like, what does that gap look like? And what does it cost in like labor hours and breach exposure? Like, and you've been got the experience both being an MSP and working with a customer base. Tell me about that execution gap.
[00:04:24] Nick Ross, MD Yeah, I think it's huge, right? I actually started my own YouTube channel six years ago to try to, you know, basically teach the space about, you know, Microsoft as a whole, you know, just because mostly Microsoft's knowledge and KBs and everything like that truly catered towards enterprise. So I started a channel called T-365. I've got about 34,000 subscribers now, but it's all about Microsoft education for SMB and the MSP space.
[00:04:50] Nick Ross, MD And it was a great example of, hey, there's a big need here, you know, where we're having to constantly keep up with changes. And then first and foremost, but we also need to understand how to modify these policies to work with a small business, not to work with an enterprise. And that gap always continues, right? Microsoft's always come out with something new. My most popular content is a monthly video I do about what's new in Microsoft every month, because they change 10,000 things.
[00:05:15] Nick Ross Powell And I synthesize it down to the top 30. And we talk about what's going to affect you and what might affect your customers. But I think, you know, from the implementation sense on these policies, you first have to overcome that knowledge gap about what it means, how to do it, how to architect it. But then you also have to go through and actually put in the manual hours to go implement that and do it across all of your clients.
[00:05:37] Nick Ross Powell Great example here is Microsoft and as a whole, the industries have a lot of attacks around a concept called token theft, which is really, you know, something where an attacker can actually steal your session token as a user, even if you have MFA in place, right? So it's a way for them to compromise your account. In this situation, Microsoft came out with protections with that for conditional access to say, hey, protect against this type of an event and block that if it happens.
[00:06:05] Nick Ross Powell But as an MSP, you'd have to understand number one, how to go configure that, and then maybe do that across 100 of your tenants, right? One by one. And that could take, right? And if you do it correctly and you surface it all, it may take you 10 to 15 minutes per client. Nick Ross Powell But that's a lot of work, right? To go in and do and then test or pilot it out. In some cases where it does require that end user impact. And so, you know, it's a scalability problem in that sense as well too.
[00:06:31] Nick Ross Powell And being able to template ties, being able to mold, you know, your policies, your baseline templates and deploy them across all of your customers has been a common constraint. And there's been tooling that's come out over the years, but it's often had a lot of gaps, whether that's depth of policies that it could support or, you know, just being friendly to MSPs is a different story as a whole. Nick Ross Powell As you know a lot well too, right? Just in the space of, is it MSP purpose built? Is it multi-tenant capable? There's a lot of big gaps too there.
[00:07:01] Nick Ross Powell Right. Now, the other thing that I want to know a little bit more about is, is I'm going to get your take on the fact that if you start enabling more junior technicians to do this kind of work, right? Because that's always the promise, right, of doing this. It's, hey, we can move this out of your senior work and move it into your junior work. Nick Ross Powell It's a great staffing pitch, right? But what, but doesn't that lowering of the skill floor for security carry additional risk?
[00:07:27] Like how do you prevent the capsules from producing security programs that look great on paper, but might have gaps that a senior practitioner would catch? Nick Ross Powell Yeah, I think that's, that's part of our, our context and validation as well too, that we're doing with our engine internally at Cloud Capsule, Nick Ross Powell Because we're giving you all the enablement in written format, bare minimum, right? Of why this matters. Here's, here's a video go, learned about it more, skill up in that sense as well. Big educational focus in that way.
[00:07:56] But also we're doing our own underlying checks to say like, if you deployed this, even if it's your own template, are you still meeting these control checks that we would look for? Nick Ross Powell And also, are they aligned to best practice when it comes to frameworks like CIS or a NIST as an example? Nick Ross Powell So we map to those and allow you to understand like, are you still failing those checks, you know, that we'd want to do and want to see.
[00:08:18] Nick Ross Powell So it allows you to kind of complement that layer of, you know, more junior person being able to skill up into a senior role, but have confidence in the policies that you're deploying. Nick Ross Powell We maintain over 100 policies internally that you can use to fulfill these controls, already pre-tethered, things like that. Nick Ross Powell So it's a little bit more controlled than I've just got my own template, you know, that I've made as a junior tech and I'm starting to push that out. Am I safe, right? Nick Ross Powell So there's, there's a bit of a wrapper behind it.
[00:08:46] Nick Ross Powell So it's a little bit more of a
[00:09:16] Nick Ross Powell We'll be right back after this message. Nick Ross Powell Here's what I keep hearing from MSPs. The security tools are fine. It's the work underneath them that's breaking people. Nick Ross Powell Too many alerts, nobody on staff to triage them, and client reporting that eats the whole week. That's the part Guards is going after.
[00:09:51] Nick Ross Powell And we're back. Nick Ross Powell Now, Cloud Capsule covers, you talked about 100, but you also cover about more than 250 specific controls. Like, that's a lot of controls.
[00:10:16] And how do you help an MSP who is sort of starting from scratch prioritize which controls matter for risk reduction versus the ones that might be checkbox compliance theater? Nick Ross Powell Yeah, great question. So we spend a lot of time with that as well, too, just given it's overwhelming, right? If you've got 250 controls coming at you, they're all half of them are red. You've got all this noise coming through at you. How do you start to think about eating the elephant in that way?
[00:10:43] And a lot of what we do natively is we prioritize what we call key findings, right, in that sense. And so we'll stack rank those controls based off of criticality. And that might be related to the attack surface. It might be related to that tenant of what we're seeing going on in their environment. But the key thesis between that and the baselines that we populate is there's a natural sense of a progression. And the key piece also with that, too, is that you can communicate that with the client.
[00:11:09] One thing when I started CloudCrafts that I didn't anticipate that is going on rapidly right now is that a lot of MSPs are actually using our tool heavily for their client conversations. So they're able to go showcase to the client, hey, we have all these gaps today. This is the first wave of what we're going to do. This first wave is low to no end user impact. So we're going to get immediate security wins within the first 30 days. We're going to tighten down these controls so that these things can't happen. It's not going to break anything that you guys are doing today.
[00:11:37] And then the next phase of that might be talking about the next business outcome or workload activation. Hey, we're going to enable you for secure remote work. And so we have pre-bundled proposals that relate back to that that also can fill those control checks as well. So we're trying to get them into a continuous improvement plan with their customer as part of their security practice. And that way doesn't seem like super overwhelming or I don't know where to start. I could pick any one of these and start working at it. But then there's never growing list as part of that.
[00:12:05] So we really try hard to make it so that there's a natural progression path that you take with the time that you spend, but also with the communication that inevitably has to go on with the customer as well. Are there particular differences in prioritization based on, say, client size or the verticals of the client? Like, how does that reorganize the way you think about priorities? Yeah, great question.
[00:12:29] So in most cases, like I'd say at an agnostic layer, we often see a huge lack of governance in most tenants, meaning I can, every tenant we onboard, we see a ton of dormant accounts and stale devices. And just like their attack surface is huge because they haven't kept up with change over time. And that is multiplied, you know, by 100x, the bigger that you are, right, obviously, as well, too, just with basic change, but also just the size of the companies that we work with.
[00:12:56] In some cases, like we had 150,000 user tenant connect, you know, the other month and their amount of sprawl in their tenant was massive, right, in that sense. And so it's a good place to start from that layer to get into some of that. And often cases we find that people just haven't even done the basics yet, right? Not all users are enrolled for MFA. It's something that you would have thought would be done, but actually isn't.
[00:13:21] And so there's a lot of progression that comes in that sense as well, too. But then with the larger organizations, mid-market to enterprise customers, especially as well, they're looking to align to a framework like a CIS or a NIST because they're operationally able to support that in a lot of ways. Because it's not just the technical control checks. There's obviously governance aspects that they want to incorporate.
[00:13:45] And we have a little bit of a GRC element in that way where you can markup controls with your own commentary. You can link outside evidence for those checks. And so those organizations kind of move into that track because they're able to support it. Whereas the SMB customers might fall into a generic Microsoft best practice baseline or these quick fixes that we allow you to do.
[00:14:07] And so it's something that they can digest, get immediate security benefit, and then maybe over time work their way up into more of the framework driven approach when they get to that maturity level. But there's often a ton of work that they could do in the forefront that would immediately or greatly improve their security posture, especially as we see this whole, obviously, expansion into AI workflows and data governance.
[00:14:31] Like there's a licensing problem in the sense that even now business premium has gaps with data compliance that you would want to have if you really are implementing a holistic layer of AI security and governance. Right. Where users can't walk out the door, you know, with data because they can now chat with co-pilot and ask for sensitive documents that maybe they shouldn't have access to, that they never knew they had access to before.
[00:14:57] As an example. And so we try to, you know, emphasize like the control checks that would go into that. As part of that, I think that's kind of some of the biggest arbitrage we're seeing lately, just given, you know, a lot of people are trying to put focus into that and make sure that they're AI ready, quote unquote, before they start lighting up these tools, whether it's co-pilot or it's a different frontier model like GPT or CLOP.
[00:15:17] So they still want to have some level sense that their data is not just going to go inadvertently into the wrong hands, whether that's an insider or obviously external threat is still there as well, too.
[00:15:30] So that's a big piece. And then I think, you know, a big focus for a lot of people lately, you know, in the sense of the holistic is also just understanding most people that we walk or have walked through the door haven't activated a ton of workloads that they have access to that they're paying for in Microsoft.
[00:15:50] And a lot of those relate back to, you know, major security benefits for them. Defender is a great example where even if you're using a third party EDR tool like a CrowdStriker sent on one, you can still get massive benefits from Defender being enabled and passive mode. So there's a big knowledge gap there, too, and just kind of what you have at your disposal. And we're showing how you can use that to find shadow AI, right, in your organization and, you know, use it to do it without an agent, right? You're reducing supply chain risk.
[00:16:19] So there's a lot of ripple effects with that as well, too. That's just kind of a knowledge gap as well. We'll be right back after this message. OpenTex 2026 threat report found business PC infection rates rose nearly 12% last year and 42% of infected devices got hit more than once. The problem isn't just detection, it's response.
[00:16:44] OpenTex EDR is built to stop lateral movement before attackers get deeper into your clients' networks. Learn more at cybersecurity.opentext.com. And we're back. Now you brought up those other tools. I wanted to ask that. Cloud Capsule is really focused exclusively on Microsoft 365 today.
[00:17:06] But we know MSPs run heterogeneous environments, things like Sentinel-1 for EDR or third-party email security or mixed identity providers. Like, isn't focusing just on M365 leaving a growing blind spot? Like, how are you thinking about yourself as part of the holistic security space? Yeah, great question. I think there's kind of a now and in the future conversation with where we're at. So, I want to start with Microsoft. Obviously, we have a lot of competency there.
[00:17:35] And, you know, a lot of our partners that are coming to us have also started to standardize on the Microsoft stack because there's TCO conversations that make it, you know, much more cost-effective. There's also conversations around operational savings, right, that you get by not having to pit it into all these different tools in that sense. Because traditionally, they haven't been the most multi-tenant friendly when it comes to things like EDR, right, as an example. Or often not best in breed when it comes to necessarily email security, right, as another example, too.
[00:18:04] So, we still allow you today to complement that with these overrides and markup within the app. That's, again, GRC in nature to say, hey, we're using Avanon instead of 365, right, for this email security. We're using Sentinel-1 for EDR. So, it gives them a complement of kind of understanding where they potentially still have holes because there's kind of this manual recording layer there. But in the future, the intention for us, we did build the platform with multi-tenancy in mind. My co-founder and I both come from Pax8.
[00:18:34] And my co-founder is actually the CTO and COO there for a long time, Michael Denlow. And, you know, his background was developing the Pax8 ecosystem, right, and the marketplace there. So, we've got a lot of familiarity with being able to do that and, you know, continue wanting to press into other vendors as we continue our journey and growth as well. Gotcha. Well, I want to give some actionable advice.
[00:18:58] For MSPs, there's really a strong argument that the real security problem around M365 isn't tooling. It's that MSPs can't sell the security services because their clients won't pay for them. And no assessment or remediation changes the economic reality for them. What do you tell an MSP who says, I already know my clients are misconfigured. I just can't get them to pay me to fix it. What do you say to them? Yeah, we hear this a lot, right? Or my clients don't care about security.
[00:19:27] This is another item, you know, that we hear a decent amount, you know, with some of the constraints that they deal with. And so, that's where we try to bake in a lot of enablement behind our product. Like, most of our team has been in the MSP space for quite some time. Our channel chief, as an example, ran an MSP for 25 years and exited afterwards as well. So, there's a lot of knowledge that we can bring down, you know, to talk about these constraints. And in a lot of cases, you know, we're able to use different levers.
[00:19:56] And mostly today, we're also able to use levers like the AI hype conversation, right? To drive the security conversation back up in that sense. A lot of our partners are using that as well too to say, hey, we can go implement these AI workloads and we can enable you to do this. But no, we have to do these other security pieces, you know, to get you enabled to do that.
[00:20:16] So, in a lot of cases, that's working really well to overcome the pricing conversation because they're so infatuated with getting this productivity benefit around the AI that they're able to kind of overcome and say, yeah, it's just table stakes, right? To get this licensing now to start to protect, you know, what we want to get done. And it's lesser of like pulling teeth like MFA, right? We've had to pull teeth on that for years. And this is kind of a different conversation behind that.
[00:20:43] I think also measuring it against, you know, these achievable goals, depending on their standards. We use multiple levers in Cloud Capsule, like cyber insurance as an example. We use obviously the frameworks like CIS and NIST to really showcase to the client, hey, you can't even meet these controls because you don't have the licensing yet to go do it. And so it's incentive for them versus just we need to do this to make you secure. Well, that's like you want to get this goal of getting your cyber insurance renewal and potentially lowering the premium.
[00:21:12] So these are the things that we want to get done to get that accomplished. It's not a positioning equation in a lot of senses. And then, you know, from there, it's really showcasing a better ROI motion on, hey, we unlock this workload for you by doing this security. So there's a positive reinforcement loop. It takes some time and you really have to bake into your operations. But with the reporting layer being so quick, that's one thing that we solve for like our average tenant scans in about 60 seconds to gather all this data.
[00:21:42] And so time to value is really a big equation there. We don't have to spend all that time doing that. It can focus more of your time back on the client conversation and overcoming objections like the, you know, the security risk or the security concerns or paying more for that as well, too. Well, there's the execution nugget right there. Nick Ross is CEO of Cloud Capsule and a three-time Microsoft MVP.
[00:22:03] He built Cloud Capsule into an MSP-focused Microsoft 365 security platform, automating assessments, remediation, and continuous proof of security outcomes across multiple client tenants. He also runs T-365, a YouTube channel with 32,000 subscribers and 2.9 million lifetime views, one of the most prominent practitioner education voices in the M365 and MSP space. Nick, where can people reach out to have a conversation and continue the dialogue?
[00:22:33] T-365.com is my blog. So I put all my content and then I'll link out to my YouTube channel as well, too, just to see more of that. So I put out a piece of content every week and try to always provide value in that way and give a lot of enablement out of there as well, too. So those are great places to connect. Same thing on LinkedIn. Found me, Nick Ross, on LinkedIn as well. Nick, this has been great. Thanks for joining me today. Awesome. Yeah, appreciate you having me today. This was fun. Want to go deeper than the news?
[00:23:01] The Small Biz Thoughts community is where MSP owners and operators work on the business, not just in it. Member meetings, a deep resource library, and courses through IT Service Provider University. Everything you need to run the practice you actually want. Join us at smallbizthoughts.org. Interested in advertising? Head to mspradio.com slash engage.
[00:23:25] The Business of Tech is written and produced by me, Dave Sobel, under ethics guidelines posted at businessof.tech. Thanks for listening. I'll see you on the next episode. Part of the MSP Radio Network.

