Let's have an uncomfortable but necessary conversation. As an MSP, you've spent years thinking of yourself as the people who protect customers from attackers. That's still true. But there's a second truth that's harder to sit with: to an attacker, you are the most efficient way in. Why pick the locks on a hundred separate front doors when you can compromise the one company that holds a key to all of them?
This isn't fearmongering. It's where the threat landscape has actually moved, and the data is stark. So let's look at it honestly — and then talk about what genuinely reduces your risk, rather than what just feels reassuring.
Attackers stopped breaking in and started logging in — through their providers
The headline shift is this: third parties are now central to how breaches happen. According to the Verizon 2025 Data Breach Investigations Report, summarised in supply chain attack analysis, third-party involvement in breaches doubled from 15% to 30% in a single year — the largest single-year jump the DBIR has ever recorded.
Drill into who those third parties are and it gets personal. Microsoft's own threat reporting, summarised for MSPs by Syncro, identifies compromises of software vendors, cloud integrators, and MSP and MSSP partners among the fastest-growing attack patterns. You are not collateral damage in someone else's breach. Increasingly, you're the target, because you're the multiplier.
And when these attacks land, they're the hardest to clean up. A supply-chain compromise now costs around $4.91 million on average and takes roughly 267 days to identify and contain — the longest lifecycle of any breach vector. That's not a bad week. That's most of a year living inside the wreckage.
Why the MSP model is so attractive to attackers
It helps to see your business the way an attacker does. You have privileged access into dozens or hundreds of customer tenants. You authenticate into all of them, often from the same set of admin identities and the same tooling. If those identities or that tooling get compromised, the attacker doesn't get one tenant — they get your whole book.
That's the brutal arithmetic of "100 tenants, 100 front doors." Every tenant you manage is a door, and historically the MSP toolchain has handed attackers a master key: standing admin access, shared credentials, broad delegated privileges, and tools that authenticate broadly across customers. The efficiency that makes you valuable to customers is the same efficiency that makes you valuable to attackers.
This is precisely why Microsoft moved so aggressively to kill standing Global Admin across the channel and push everyone toward least-privilege, time-bound access. The old model wasn't just untidy — it was a supply-chain attack waiting to happen.
The goal isn't "don't get targeted." It's "shrink the blast radius."
Here's the mindset shift that matters. You cannot make yourself an uninteresting target — your business model makes you interesting by definition. What you can control is what an attacker gets when something does go wrong. The entire game is blast radius.
Think about the difference between two MSPs who both suffer a compromised admin account:
- MSP A uses shared admin identities with broad standing access and tooling that authenticates across all tenants with one set of credentials. One compromise, and the attacker can move laterally into every customer. The breach lifecycle starts ticking toward that 267-day average.
- MSP B uses granular, time-bound access, with isolation enforced at the architecture level so credentials for one tenant can't reach another. The same compromise is contained to a far smaller footprint, detected faster, and far cheaper to remediate.
Same incident. Wildly different outcome. The difference is architecture, decided long before the incident.
How DendronAI shrinks the blast radius
This is exactly the threat model DendronAI is designed around. The relevant protections aren't security features bolted on after the fact — they're built into how the platform works, because for a tool that touches every tenant you manage, isolation is the product.
Per-tenant scoped tokens. Every Microsoft Graph call carries a tenant-scoped token, so customers stay isolated and no cross-tenant leaks are possible. This is the single most important property for blast-radius control: even in a bad scenario, access to one tenant cannot become access to the next. The master key simply doesn't exist.
GDAP-only, time-bound, fully audited. The platform never uses delegated admin. Roles are granular and time-bound, and every action is audited against the role used. Time-bound access means there's no permanent standing door for an attacker to find; granular roles mean a compromised role grants far less than "everything."
Partner Center as source of truth. Because your tenant list syncs from Partner Center rather than a CSV, your access map reflects reality. You're not carrying forgotten standing access into tenants you off-boarded months ago — the kind of orphaned access that supply-chain attackers love.
Visibility to detect fast. The longest, most expensive part of a supply-chain breach is the time spent undetected. DendronAI's cross-tenant ITDR surfaces identity threats — privilege escalation, impossible travel, risky sign-ins — across every tenant in one console, so an anomaly in one customer doesn't sit unnoticed for months. We report a 14-minute median MTTR; the goal is to find and contain trouble in minutes, not the better part of a year.
The honest caveats
Let's be fair and clear-eyed. No architecture makes you breach-proof. Per-tenant tokens and GDAP dramatically reduce lateral movement, but they don't eliminate every risk — phishing your staff, a compromised endpoint, or a vulnerability in any vendor in your chain (including platform vendors) are all still live concerns. Concentrating operations on any single platform also means that platform's own security posture matters enormously, which is exactly why you should scrutinise it: ask about isolation, audits and certifications. Northern Tech Hub publishes its approach on its security and trust page, and you should hold every vendor — us included — to that standard.
The point isn't that the right tooling makes you invulnerable. It's that the right architecture changes a catastrophe into a contained incident. When the average supply-chain breach runs to nearly $5 million and the better part of a year, turning "every tenant" into "one small footprint" is the most valuable security decision you can make.
The takeaway
The threat landscape has decided what MSPs are: a high-value path into many organisations at once. You can't opt out of being interesting. What you can do is make sure that when something goes wrong, an attacker finds isolated tenants and time-bound, granular access instead of a master key.
If you'd like to see how DendronAI keeps your tenants isolated and your blast radius small, take a look. We'll walk through your tenant shape and where your real exposure sits today.
You manage a hundred front doors. Let's make sure they don't all share one lock.