MSPs aren’t just tweaking around the edges; our business model is flipping upside down. The work that filled 60–80% of MSP revenue—password resets, patching, basic troubleshooting, simple reporting—is exactly what AI agents are being built to eliminate, not merely reduce. The future MSP is a strategic partner for security, AI governance, data, and business outcomes, and over the past couple of years I’ve been writing the roadmap for that shift.
In this article I want to pull those threads together. I’ll reference each of the key posts so you can go deeper where it matters for your business. Think of this as the table of contents for building your next‑generation MSP.
Flipping The MSP Business Model
In Deep thoughts on MSPs in the AI age, I make a simple claim: MSPs are going to flip upside down. Infrastructure and endpoint care remain essential, but they’re increasingly delivered through AI‑driven stacks (M365 + Defender + Intune + Copilots, etc.) and become the platform fee, not your main offering.
That post lays out three big consequences for your business model:
- Helpdesk as profit center fades as AI and automation handle Tier 1/2 basics.
- Security engineers, data/automation specialists, and client‑facing advisors become your most important roles.
- You must stop investing in the “old” and begin deliberately pivoting into new services, tools, and talent—starting now, not five years from now.
If you want the high‑level forecast this sits on top of, go back to Predicting the future of MSPs, where I summarize the trends: security and compliance as table stakes, AI‑enabled IT and governance, business‑outcome engagement, and elevated advisory roles for MSPs. Read that one as the macro view, then let Deep thoughts be your operational blueprint.
Building The Modern MSP Stack
The future MSP isn’t just a different marketing pitch; it runs on a different stack. In Deep thoughts on MSPs in the AI age, I outline the backbone:
- Identity‑first: Entra, conditional access, Zero Trust principles.
- Security: all the Defenders, MDO, MDR/XDR, security baselines, compliance, and shadow IT controls.
- Training: Microsoft 365, Copilot and other AIs, security, data management, and privacy as ongoing education.
- Data management: DLP, Purview, awareness of where data lives, and aggressive archiving and retention.
- AI: your clients’ industry tools and Copilots brought under governance, not left as shadow IT.
You see this stack show up again in Smarter MSP Strategies for Enhanced Security, where I dive into how AI is already embedded in threat detection, email security, incident triage, and user awareness. That article gives technicians and owners a practical vocabulary for AI, ML, NLP, and GenAI, and shows how today’s platforms use these techniques to cluster emails, analyze URLs, sandbox attachments, and drive adaptive training.
If you need a structured way to upskill the team on this stack, the Courses for MSPs page is where I codified it into training: M365 security, Defender XDR, Intune, Zero Trust, and AI governance. I explicitly note there that technical skills don’t exist in a vacuum—the MSP model is shifting from infrastructure‑heavy to advisory‑heavy, and that’s exactly what the stack above supports.
We offer most of our courses on a descrete schedule, offering it once or twice to MSPs that are really interesting in going deep on a topic. But we also offer a continuing education program in Microsoft 365 and Security. Every MSP should be heavily investing in training today.
New Service Lines: Managed AI, Managed Security, Fractional Leadership
Once you accept that AI will handle much of the reactive busywork, you have room to build new profit centers. In Deep thoughts on MSPs in the AI age, I highlight three service lines you can start or mature today:
- Managed AI services
- Managed security and compliance with AI in the loop
- Fractional CIO/CISO with an AI focus
Managed AI services are the low‑hanging fruit. In that post I suggest starting with AI readiness assessments, acceptable use and ethics policies, shadow AI control, Copilot deployment and training, and ongoing “AI optimization” retainers where you continuously improve prompts, automations, and integrations. All of that turns AI governance into a first‑class service: defining acceptable use, data boundaries, and app approvals, then monitoring them over time.
Managed security and compliance with AI in the loop is the logical evolution of what many MSPs already do. In Smarter MSP Strategies for Enhanced Security, I walk through how AI is already sifting events for anomalies, analyzing email campaigns, summarizing alerts, and guiding investigations. That article bridges the gap between vendor features and service design, showing how you can re‑frame your security offering around faster, smarter decisions, not just “more tools.”
Finally, Fractional CIO/CISO with AI focus raises the bar on your client conversations. If you’re still doing quarterly business reviews, you’re already behind. In Deep thoughts I call out the need for true strategy sessions focused on automation roadmaps, AI use cases, vendor consolidation, budget, process modernization, and tying AI outcomes to business metrics like time saved and error reduction. This is where your best MSPs are already playing.
Customer Outcome As The North Star
If AI is doing more of the work, and clients can buy tools directly, why do they still need you? The answer, in my view, is customer outcome.
In Why Customer Outcome is the New North Star for MSPs, I argue that we have to move beyond “customer service” and even beyond “customer success” into a more demanding metric: whether the customer actually achieves their intended business outcomes with our help. Closed tickets and uptime don’t tell that story; morale, productivity, error reduction, and new capabilities do.
That post is deliberately practical. I recommend that you:
- Lead with business conversations, not technical ones—especially around security.
- Let the customer do most of the talking and ask for a tour of how the business operates, not just a tour of the server room.
- Frame projects, roadmaps, and AI deployments in terms of outcomes like “do more with less,” “reduce specific errors,” or “free up key staff,” then align KPIs accordingly.
This ties directly into Most MSPs are using AI wrong, where I point out that many MSPs are using AI to slightly optimize the last ten years of their business rather than to build the next ten. When AI is just shaving minutes off tickets, it’s a cost‑saver; when it’s redesigning workflows around outcomes, it becomes a growth lever.
Rethinking Tools, Bundles, And Messaging
None of this change lands if your tools, bundles, and marketing all scream “we’re a traditional MSP.”
It’s a moldy oldie by Internet standards but still relevant for an AI forward MSP. In Why some firms don’t choose RMM, I explore why some MSPs avoid traditional RMM not because they dislike management and monitoring, but because they don’t want tool‑driven processes that lock them into old models. As cloud‑first and AI‑assisted approaches mature, you have more options for how you build your platform layer.
In What should your MSP drop or adopt?, I build on industry research and my own experience to list areas you may need to sunset or reinvent and areas you should aggressively build into. That post anticipates small businesses expecting comprehensive cybersecurity, expanded cloud and collaboration, AI and automation as normal, better customer experience, and virtual CISO‑style expertise. It’s a practical checklist for rationalizing services.
On the messaging side, Deep thoughts on MSPs in the AI age is blunt: you must change your messaging everywhere. I specifically call out updating proposals and decks, rewriting your elevator pitch, revising your website, and updating your MRR bundles to visibly include AI readiness, governance policies, deployment, training, optimization, and reporting.
If you want a curated path through the broader business topics this touches—things like leadership, empowering staff, and “The answer is always Yes”—the Business Strategies for Success hub pulls those posts together. That page is where I gather the content that supports owners as they make the tough decisions this transformation demands. You can also check out the full business content in the blog.
Training The Team For The Future MSP
Last, but maybe most important: none of this can be implemented without changing what your team does all day.
On the Courses for MSPs page, I say explicitly that technical skills are only one piece of the puzzle; the bigger change is that MSPs are becoming more advisory and outcome‑driven. The courses—M365 security, Defender XDR, Intune, Zero Trust, AI governance, and more—are designed to give your technicians and consultants the skills to operate the modern stack we’ve been discussing.
Paired with workshops like the Zero Trust Workshop and ongoing content like Speak To Your Clients About Email Threats and Speak to your clients about AI Agents, and you have a training path that covers both technology and communication. The future MSP doesn’t just deploy tools; it explains risk, opportunity, AI, and automation clearly to non‑technical business owners and staff.
Put together, these posts and courses form a coherent narrative:
- Predict where the MSP market is going.
- Redesign your stack and services for identity, security, data, and AI.
- Move your value into governance and business outcomes.
- Retrain your team to deliver and communicate that value.
That’s the future MSP I’ve been writing about—and the one I believe will thrive in the AI age
If you’d like some help transiting your MSP into the future world, consider joining our Mastermind Group. You’ll be with like minded business owners and managers working their way through question after question.