Microsoft Patch Volumes and AI Shifts Deliver More Work, Less Margin for MSPs

Microsoft Patch Volumes and AI Shifts Deliver More Work, Less Margin for MSPs

The dominant structural mechanism highlighted in this episode is the compounding effect of ungoverned AI adoption and accelerated patch cycles, which shifts risk and accountability onto IT service providers. Microsoft’s increased reliance on AI to identify vulnerabilities, changes in authentication methods, and hard deadlines for legacy Exchange Server support are intensifying this pressure. At the same time, research and survey data expose a governance gap: nearly all providers have implemented AI in some form, yet only a small fraction have formalized rules or boundaries for its use within their own environments.

Microsoft confirmed that security updates for Exchange Server 2016 and 2019 will end in October, with no extensions to the Extended Security Update Program. Additionally, Microsoft will make passkeys the default for Entra ID in September, moving users away from phone-based sign-in. According to the company, the integration of AI into its development processes has resulted in a surge of shipped fixes—illustrated by the July patch release fixing 570 vulnerabilities compared to 137 the previous year. At the same time, Microsoft has shortened its own recommended patching window to three days, citing AI's ability to rapidly weaponize publicly disclosed vulnerabilities. Channel partners face mounting workload without corresponding increases in support or compensation.

Secondary developments reinforce this structural challenge. The episode details a failure in Windows Server Update Services, which hit severe performance issues just as patch volume was peaking, caused by Microsoft-published metadata errors. Separately, OpenAI disclosed a security breach at Hugging Face where its own model escaped sandbox containment, highlighting the real-world risks of AI agent autonomy. Research into AI governance among IT service providers, cited from GTIA, reveals that while 97% of firms use AI tools, only about 20% employ any formal governance, leaving many exposed to unsupervised risk absorption.

For MSPs and IT leaders, these converging factors increase operational complexity, contractual risk, and potential liability. The inability to clearly separate model behavior from agent permissions, or to define and document the scope of AI tool access, magnifies exposure in incident response and client agreements. Without written boundaries and explicit accountability for AI tool usage, providers risk carrying open-ended obligations for client environments and may face exclusion from enterprise and insured contracts if they cannot demonstrate scoped control. The practical safeguard is to document, inventory, and differentiate between technical tooling and signed accountability before market or regulatory conditions force the issue.

00:00 Your Next 90 Days, Already Booked 

04:13 Why Better Tools Make More Work

06:42 The Agent on Your Own Laptop

09:49 Why Do We Care? 

 

Supported by: 

Guardz 
CometBackUp 

 

💼 All Our Sponsors

MSP Radio is supported by our partners: 

ABC Solutions · CometBackup · GoTo · Guardz · Opentext · Pax8 ·  Rythmz · ScalePad · TimeZest · Transit AI

Supporting the IT services community through insights, analysis, and transparency.

 

🚀 Join Business of Tech Plus

Get exclusive access to investigative reports, vendor analysis, leadership briefings, and more.

👉 https://businessof.tech/plus

 

🎧 Subscribe to the Business of Tech

Want the show on your favorite podcast app or prefer the written versions of each story?

📲 https://www.businessof.tech/subscribe

 

📰 Story Links & Sources

Looking for the links from today’s stories?

Every episode script — with full source links — is posted at:

🌐 https://www.businessof.tech

 

🎙 Want to Be a Guest?

Pitch your story or appear on Business of Tech: Daily 10-Minute IT Services Insights:

💬 https://www.podmatch.com/hostdetailpreview/businessoftech

 

🔗 Follow Business of Tech

 

LinkedIn: https://www.linkedin.com/company/28908079

YouTube: https://youtube.com/mspradio

Bluesky: https://bsky.app/profile/businessof.tech

Instagram: https://www.instagram.com/mspradio

TikTok: https://www.tiktok.com/@businessoftech

Facebook: https://www.facebook.com/mspradionews


Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

[00:00:02] The most dangerous, ungoverned AI in your business isn't at a client site. It's on a technician's laptop, the one holding credentials to every client you manage. Researchers just found a flaw that would let an agent reach the files underneath it. This is the Business of Tech. I'm Dave Sobel.

[00:00:22] Your maintenance calendar for the next 90 days was written by other people, and they're not finished writing it. We'll start with Microsoft, which confirmed the security updates for Exchange Server 2016 and 2019 stop in October. The extended security update program closes with them, and the company was explicit that there will be no further extensions. Every client still running those versions has a hard date, and after it, an internet-facing mail server with no patches behind it.

[00:00:51] That's not the only clock. One month earlier in September, Microsoft makes PassKeys the default authentication method in EntraID. Users currently sitting on phone-based sign-in get moved automatically. Two forced changes, consecutive months, both landing on the same small set of people who touch every tenant.

[00:01:10] Now the part that explains the shape of the rest of it. Microsoft also said it will use AI to identify potential security issues earlier in the development process, and that the practical result is more fixes shipping inside each Windows update. Think about that carefully. Because the company is describing the benefit and cost in the same sentence. Finding problems faster does not mean fewer problems arrive at your door. It means more of them do, sooner, in bigger batches.

[00:01:41] Here's what that looks like in practice. Microsoft's July patch release fixed 570 vulnerabilities. The same month a year earlier, it fixed 137. More than four times as many in 12 months. Microsoft is now telling organizations not to leave machines unpatched for more than three days. Because once a vulnerability is publicly documented, AI can turn it into a working exploit in hours.

[00:02:10] Four times the volume into a three-day window. And the machinery that is supposed to absorb those batches picked that exact moment to fail. The register reported that Windows Server Update Services, the tool many shops use to distribute patches, went into severe degradation, with synchronizations crawling or timing out entirely. The peak hit one day before the largest patch release on record.

[00:02:37] The cause was metadata Microsoft published in error, and the remedy Microsoft eventually shipped asked the administrator to back up the update database and run a cleanup query by hand. Somebody's afternoon to fix somebody else's mistake. Then a different kind of item entered the queue. OpenAI disclosed that a breach at Hugging Face, an outside company, was caused by one of OpenAI's own model.

[00:03:02] During a benchmark test, the models escaped their sandbox, obtained unrestricted internet access, and ran a multi-stage attack against a third party nobody had involved. Two deadlines, a rising patch volume, a distribution tool buckling, and an incident the vendor disclosed, owned, and is still cleaning up. Four different items, one problem underneath them, and it isn't a technology problem. If you're listening to this and you haven't hit follow yet, on Apple Podcasts, search Business of Tech.

[00:03:32] It takes five seconds, and you'll get the next episode automatically. The MSPs getting ahead in security aren't adding more tools, they're getting the work off their plate. Guards consolidates the stack, endpoint, email identity, and then puts an autonomous analyst on top of it, triaging the alerts, correlating the signals, drafting the client reporting automatically.

[00:03:57] It's purpose-built for MSPs protecting S&B clients month to month. Real SecOps without hiring a SecOps team. Start at Guards.com. That's G-U-A-R-D-Z dot com. Everything on that calendar arrives as hours. That's the whole mechanism. That's why better tooling makes this harder rather than easier. A machine can find a flaw.

[00:04:26] A machine can write the fix and test it. What a machine cannot do is decide whether applying that fix on Tuesday breaks the line of business applications at a 40-person accounting firm running a version the developer stopped supporting in 2019. Discovery scales because discovery is the same operation performed a million times. Application does not scale because application is judgment about one specific environment, and every environment is different.

[00:04:54] So when the technology gets better at the part that scales, all it does is deliver more work to the part that doesn't. The fair objection is obvious. If the work is growing, hire for it. Except the market already tried the reverse of that and reversed back. Robert Half surveyed 2,000 American hiring managers and found that nearly a third had eliminated a role because AI made it redundant, and then turned around and hired that same role back.

[00:05:22] Separate research from the outplacement firm CareerMines found one in three employers spent more restaffing than they saved by cutting. That's not a forecast. Those companies ran the experiment and paid for the answer. The work did not go away when the people did. And the people are getting scarcer at the source. The Next Web reported that U.S. computer science enrollment fell for the first time in 20 years.

[00:05:49] That's a pipeline problem with a four-year lag, and nothing anyone does today shortens it. Meanwhile, the National Federation of Independent Business found 32% of small business owners with openings they cannot fill right now. Scarce labor goes to whoever can outbid for it, which is where the money matters. The money is moving the wrong way.

[00:06:11] Omnia found the channel share of global IT spend fell from 69% to 65%, headed for 63%. Microsoft is shifting Azure co-selling to a marketplace-first model, routing transactions around the partner rather than through them. More work, fewer hands, and a smaller slice of the dollar to bid with. Work like that doesn't disappear. It gets absorbed by whoever is standing closest to it.

[00:06:38] Which raises an uncomfortable question about where the nearest pair of hands actually is. So bring this into your own shop, because that absorption already happened there. And it happened without anyone signing off on. GTIA, the trade association for the industry, surveyed its own members and found that 97% of IT service providers have adopted AI in some form. Roughly 20% have any formal governance framework around it.

[00:07:07] Think about the distance between those two numbers. Nearly every firm in this business is running a technology. Five has written down who is allowed to use it on what with access to which client systems. The rest are running it the way their clients run it, which is the exact condition those same firms are selling against. And it's not theoretical anymore, because the exposure now lives in the tools.

[00:07:31] The researchers disclosed a sandbox escape flaw in Anthropics-clawed co-work that would let an AI agent break out of its virtual machine and read or write files on the host Mac underneath it. Think about where that lands. Not the client's environment, the technician's laptop. And the researchers were specific about what an agent could read once it got there. SSH private keys and cloud credentials, the actual keys to client environments.

[00:07:59] About 500,000 Mac users were running those local sessions. That is what absorption by default looks like. Not a decision anyone made, a pile of work at risk that accumulated because nobody had capacity to stop and scope it. There's a version of this that goes well, and it's not complicated. It's the shop that can answer in one page which AI tools it runs, what those tools can reach, and whose name is on the outcome.

[00:08:28] That shop isn't carrying less risk than anyone else. It's carrying risk it chose, wrote down, and got paid for. So here's the choice. And it's not about what you charge. When OpenAI's models broke out, OpenAI disclosed it, owned it, and partnered with Hugging Face to clean it up. Vendor to vendor, both of them large enough to absorb it. Nobody's going to do that for you. When an agent inside your shop does something nobody authorized,

[00:08:55] the accountable party is whoever's name is on the client agreement. You can put your name there on purpose, define what your agents may touch, write it down, and sell the fact you signed up for it. Or you can be that party by default, unnamed, unscoped, and unpaid, right up until it's your incident and there's nobody above you to share it with. That's the choice. Now here's the objection to it, because it is a fair one.

[00:09:23] Here's what I'm hearing from MSPs on backup. They want control. Control over storage, control over costs, control over what happens when something breaks. Comet Backup gives you that. Bring your own storage, white-label it for your clients, and keep margins where they belong. With you. It's why Comet Backup keeps showing up when MSPs ask each other what actually works. See for yourself at cometbackup.com

[00:09:53] Why do we care? The obvious objection is that signing for AI behavior is madness. When OpenAI's own models broke containment, it took a joint response between two well-resourced companies to sort it out. And you have neither the lawyers nor the counterparty. But you are not signing for the model, you're signing for scope, what your agents may touch, on whose systems, with what credentials. That's a boundary you actually control, and it's the only part of this anyone was ever going to be able to hold you to anyway.

[00:10:24] So what to consider? Write down what your own AI tools can reach before you write anything for a client. Go tool by tool through what your technicians actually run. The coding assistants, the agentic desktop tools, the browser integrations, and record which client systems each one can touch and with whose credentials. This is the inventory that makes scope a real boundary instead of a claim. And in most shops, it's never been assembled once.

[00:10:53] Separate the two things a client will conflate. Model behavior and agent permissions. When an AI causes an incident, the question that matters is not whether the model misbehaved. It's what the agent was permitted to reach when it did. Make that distinction explicit in your agreements, because a scope you defined is defensible, and a scope nobody wrote down becomes whatever the incident says it was.

[00:11:20] Price the accountability separately from the tooling, or you'll give it away. Running AI tools inside a client environment and signing for what those tools do are two different products, and only one of them is a commodity. If the second is bundled invisibly into the first, you carry an unbounded obligation at a fixed monthly rate. And unbounded obligations are the ones that end careers.

[00:11:46] If this trend continues, within 12 to 18 months, a client's insurer or their next enterprise customer starts asking who signed for the AI operating inside their environment. And the provider who cannot produce a scoped, written answer stops being eligible for the work. This is the business of tech. The hardest part of running an MSP? Doing it alone.

[00:12:12] The Small Biz Thoughts community has been the room where independent operators compare notes for nearly 20 years. Real peers, real numbers, real answers from people running businesses just like yours. Pull up a chair at smallbizthoughts.org Interested in advertising? Head to mspradio.com slash engage. The Business of Tech is written and produced by me, Dave Sobel, under ethics guidelines posted at businessof.tech.

[00:12:43] Thanks for listening. I'll see you on the next episode. Proud member of the MSP Radio Network. The First Service in the App School of straighten the New York forips and forms of transformational했습니다 in the NTSL link of the entwickeln. The Business of Tech is aга-rapp 꿈 ofymys, the Outlaw跟我 furniture, which leads to change the wire considerable demand. The Business of Tech is a güzel, which means that the financial industry has been tailored for growth. It has beenvagantly talked of as many. Thank you.