AI Doesn’t Care About Your MSP Business Model

image

I’ve been thinking about a question that might make some MSPs uncomfortable.

Should the next technology revolution be guided by the same people who have spent the last twenty years building businesses that depend on things staying exactly the way they are?

That sounds harsh, but hear me out.

Every major technology shift creates winners and losers. Cloud changed the value of servers. Microsoft 365 changed the value of maintaining Exchange on-premises. Remote monitoring and management changed the need for technicians driving between customer sites. AI is now doing the same thing to knowledge work.

Yet when I talk to some MSPs about AI, I often hear the same response.

“It’s not ready.”

“Our clients aren’t asking for it.”

“We’ll wait and see.”

“They still need us to do the basics.”

Maybe. But that’s exactly what people said about cloud computing.

The Incentive Problem

The challenge isn’t that MSPs don’t understand technology. Most understand it very well.

The challenge is incentives.

If you’ve built a successful business around selling licences, managing devices, responding to support tickets and charging for technical expertise, then AI creates a problem. The more capable AI becomes, the more it starts consuming activities that have traditionally generated revenue.

If a Microsoft 365 Copilot prompt can analyse a meeting, draft a proposal and create an action plan in minutes, what happens to the hours previously spent doing that work?

If an AI agent can resolve basic support requests, summarise conversations and retrieve information from SharePoint or Teams, what happens to the service model built around handling those requests?

It’s understandable that some MSPs look at this and feel uncomfortable.

But technology has never cared about existing business models.

History Doesn’t Reward Defenders

I’ve seen this pattern before.

Businesses often spend more energy trying to protect the old revenue stream than understanding the new opportunity. They look at disruption as something to resist rather than something to harness.

The problem is that customers rarely share that loyalty to the old model.

Business owners don’t wake up in the morning hoping to buy more support hours. They want outcomes. They want faster decisions. They want less administration. They want their staff spending more time serving customers and less time managing information.

Today, a growing number of those outcomes can be delivered through AI.

Whether MSPs like it or not.

The Risk of Becoming the Blocker

One of the dangers for traditional MSPs is becoming the organisation that says no.

No, you shouldn’t use AI yet.

No, you shouldn’t change your process.

No, your existing approach is good enough.

Meanwhile, another adviser walks in and shows the client how Microsoft 365 Copilot can reduce the time spent preparing for meetings in Teams, drafting emails in Outlook and analysing information in Excel.

Guess which adviser the client sees as helping them move forward?

I’ve always believed that our role as technology professionals is not to preserve the status quo. It’s to help customers navigate change safely and effectively.

That doesn’t mean blindly embracing every new feature that appears. Governance still matters. Security still matters. Data quality still matters. AI without preparation can create as many problems as it solves.

But that’s very different from pretending the change isn’t happening.

The MSP Opportunity

Ironically, AI may create one of the biggest opportunities MSPs have seen in years.

Most businesses have no idea how to prepare their data, secure their environment or establish the governance needed to use AI safely. They need guidance. They need strategy. They need trusted advisers.

That’s where MSPs can create enormous value.

But only if they’re willing to evolve.

The conversation can’t stay focused on devices, licences and tickets. It needs to move towards business processes, information management, knowledge discovery and AI readiness.

That’s where the real opportunity sits.

Final Thoughts

I don’t think AI should be entrusted solely to old-school MSPs who want everything to stay the same. Equally, I don’t think businesses should rush headlong into AI without experienced technology advisers.

The answer lies somewhere in the middle.

The MSPs that thrive over the next decade won’t be the ones defending the past. They’ll be the ones helping clients prepare for the future.

Because AI isn’t interested in protecting anyone’s business model.

It’s simply moving forward.

And the question every MSP needs to answer is whether they’ll be leading that change or explaining to clients why they missed it.

The Hard Part Isn’t Adding Anymore

MAI_d4a9050a50fc1a5a

I caught myself last week with eleven browser tabs open, three half-built automations, a new Planner board nobody asked for, and a Teams channel I’d spun up that morning and already forgotten the purpose of. None of it was hard to create. That was the problem. Every one of those things took me about ninety seconds, and ninety seconds is now the entire cost of bringing something new into existence.

For most of my working life, the brake on doing more was effort. You wanted a new report, a new process, a new client deliverable — and the friction of actually building it slowed you down enough to ask whether it was worth it. That friction is mostly gone. Copilot drafts the document, the deck, the email sequence. Power Automate wires the workflow. The wall that used to stop me from acting on every passing idea has quietly come down.

Speed without judgement is just mess

I’ll be honest about the wiring in my own head. I’m wired to react. A thought lands, I want to act on it immediately, and for years that instinct ran straight into the resistance of having to do the work by hand. The work was the filter. It forced a pause.

Now there’s no pause. The reaction and the execution have collapsed into the same moment. I think “we should have a dashboard for that” and Copilot in Excel has one in front of me before the idea’s even finished forming. Multiply that across a week and you don’t get a sharper business. You get a cluttered one. More dashboards nobody reads. More channels nobody checks. More automations quietly firing into inboxes that have stopped paying attention.

The skill that used to matter was production — the ability to make the thing. That’s not scarce anymore. Anyone with a Copilot licence can produce. What’s scarce now is the judgement to know which of the ten things you could build is the one that actually matters, and the discipline to let the other nine die.

Taste is the work now

I keep coming back to the word taste, because I can’t find a better one. It’s the ability to look at everything you’re capable of generating and recognise what’s worth keeping. It’s hearing the difference between a real signal and noise dressed up to look like progress. And it’s having the spine to cut — to delete the document, kill the channel, switch off the automation — even though it cost you almost nothing to make and feels wasteful to throw away.

This is uncomfortable, especially for those of us who measure ourselves by output. Cutting feels like the opposite of productivity. But a business that adds endlessly and never subtracts doesn’t get faster. It gets heavier. Every new thing you create has a maintenance cost, an attention cost, a “what was this for again?” cost that lands months later. The Loop pages multiply. The SharePoint sites pile up. The thing you built in ninety seconds takes a year to quietly rot in front of everyone.

So I’ve started running my week the other way around. Instead of asking Copilot what else I could build, I ask it what I should stop. I’ll point it at a Teams channel and ask for a summary of the last month — and if the honest answer is “three automated posts and no human replies,” that’s my cue to shut it down. I use Copilot to find the dead weight, not just to make more.

The momentum problem

Here’s the part I want to be straight about, because it’s where I think a lot of us are stuck. You can feel that your best work is still in front of you. The ambition is real. But the momentum you’re chasing won’t arrive while the business is carrying this much weight. Every unfinished idea, every half-used tool, every process you bolted on and never removed is drag. You can’t accelerate something this loaded, no matter how fast you’re able to add to it.

The temptation, when you feel slow, is to add more — a new tool, a new system, a new initiative to fix the sluggishness. That instinct is exactly backwards. The way through isn’t more production. It’s subtraction. The lightness comes from what you’re willing to remove.

It’s never been easier to make something. Which means the rare, valuable, genuinely hard skill is no longer making — it’s choosing. Less, but the right less. That’s the whole game now.

The Report You Should Be Checking Every Month

image

I’ve lost count of how many times I’ve seen organisations proudly tell me they’ve automated patch management, only to discover they have no idea whether the updates actually made it to the devices.

Getting updates deployed is only half the job. Knowing what happened afterwards is where the real value lies.

That’s why I think one of the most overlooked additions to Windows Autopatch is its reporting capability. Microsoft has invested heavily in giving administrators visibility into both quality updates and feature updates, yet many people still seem to view Autopatch as a simple “set and forget” service. It isn’t. It’s a managed update service that still needs oversight. [learn.microsoft.com]

In my experience, the organisations that get the most value from Windows Autopatch are the ones that spend a few minutes each month reviewing the reports rather than assuming everything worked perfectly.

Compliance Is Not the Same as Configuration

When I speak with MSPs and SMBs, I often hear a variation of the same story.

“We’ve got update policies configured in Intune.”

That’s great, but having a policy isn’t proof that devices are patched.

A device can be powered off, have a failed update, miss a reboot, or simply stop checking in. The policy might be configured perfectly, yet the endpoint remains vulnerable. That distinction matters. In fact, it came up recently in a discussion about the importance of validating that updates have actually reached devices rather than relying on configuration alone.

Windows Autopatch reports help bridge that gap by showing what has actually happened on the endpoint rather than what should have happened.

Visibility at Multiple Levels

The quality update reporting in Windows Autopatch provides several different perspectives. There is a summary view that gives an organisational snapshot, a device-level status report that drills into individual machines, and a trending report that shows update progress over time. Microsoft states that these reports are designed to provide insight into readiness, update health, alerts, compliance, and update status trends over the previous 90 days. [learn.microsoft.com]

That combination is important.

A dashboard might tell you that 95% of devices are compliant. Useful information, certainly. But the remaining 5% are often where the interesting conversations happen.

Which devices failed?

Why are they behind?

Have they stopped checking in?

Do they belong to a key executive, a remote worker, or a critical system?

Those are the questions that reduce risk.

Better Conversations with Copilot

One area I think many organisations overlook is how these reports can work alongside Microsoft 365 Copilot.

Imagine exporting your Windows Autopatch status data into Excel and then asking Copilot questions such as:

  • Which devices have failed their latest quality update?

  • Summarise update issues by department.

  • Identify devices that haven’t checked in recently.

  • Explain the trend in update compliance over the last quarter.

Rather than manually analysing thousands of rows, Copilot can help surface patterns and priorities much faster. The update data becomes more than just a compliance report. It becomes a decision-making tool.

That’s where I see real value emerging. The reporting tells you what happened. Copilot helps you understand what you should do next.

Reports Help During Audits Too

Anyone who’s been through a security assessment, cyber insurance review, or customer audit knows that “we patch our systems” isn’t usually enough.

You’ll often be asked to demonstrate patch status, prove compliance, explain exceptions, and show evidence of remediation efforts.

The Windows Autopatch reporting framework provides exactly the sort of information auditors tend to request, including device status, readiness information, alerts, compliance data, and historical trends. The data can also be exported for further analysis and reporting. [learn.microsoft.com]

That means you’re not scrambling to produce evidence when someone asks the question.

The evidence is already there.

My Recommendation

If you’re already using Windows Autopatch, add a recurring monthly task to your calendar.

Open the reports.

Review the summary dashboard.

Look for failed devices.

Investigate alerts.

Check the trend lines.

Even better, use Copilot in Excel to help analyse the exported data and identify patterns you might otherwise miss.

Patching isn’t finished when Microsoft releases the update. Patching is finished when you can prove the update successfully reached the devices you’re responsible for.

Windows Autopatch helps automate deployment.

The reports tell you whether that automation is actually working.

CIA Brief 20260711

image

Security

Microsoft 365 & Windows

Cloud & AI

As always, the challenge isn’t finding information — it’s focusing on what actually matters.

After hours

Half Life web port – https://hl2.slqnt.dev/

Editorial

If you found this valuable, the I’d appreciate a ‘like’ or perhaps a donation at https://ko-fi.com/ciaops. This helps me know that people enjoy what I have created and provides resources to allow me to create more content. If you have any feedback or suggestions around this, I’m all ears. You can also find me via email director@ciaops.com and on X (Twitter) at https://www.twitter.com/directorcia.

If you want to be part of a dedicated Microsoft Cloud community with information and interactions daily, then consider becoming a CIAOPS Patron – www.ciaopspatron.com.

Watch out for the next CIA Brief next week

Need to Know podcast–Episode 368

Latest news and updates from the Microsoft cloud from security, to copilot and beyond. I also  share my thoughts on recent changes at Microsoft, Cowork costs, security challenges with agents and my experiences configuring local AI. Always keen to hear your thoughts and feedback on the content in this episode.

Brought to you by www.ciaopspatron.com

you can listen directly to this episode at:

https://ciaops.podbean.com/e/episode-367-goldilocks-gone/

Subscribe via iTunes at:

https://itunes.apple.com/au/podcast/ciaops-need-to-know-podcasts/id406891445?mt=2

or Spotify:

https://open.spotify.com/show/7ejj00cOuw8977GnnE2lPb

Don’t forget to give the show a rating as well as send me any feedback or suggestions you may have for the show

Resources

CIAOPS Need to Know podcast – CIAOPS – Need to Know podcasts | CIAOPS

X – https://www.twitter.com/directorcia

director@ciaops.com

CIAOPS Blog

Join my Teams Shared Channel – CIAOPS

CIAOPS Merch store – CIAOPS

Become a CIAOPS Patron

CIAOPS AI Dojo

CIAOPS weekly news update – CIA Brief – CIAOPS

CIAOPS Labs – The Special Activities Division of the CIAOPS

Support CIAOPS

Get your M365 questions answered via email

Join my email list

A special thanks to the CIAOPS Patron community for making this podcast possible. You can find the benefits of a subscription to the community and become a member at https://www.ciaopspatron.com

Security & Threat Intelligence
Microsoft 365 Copilot & AI
SharePoint & Content Management
Microsoft Corporate News

The Real Power of Copilot in Excel Isn’t Formulas. It’s Repeatability.

image

The first thing most people do when they open Copilot in Excel is ask it for a formula.

That’s understandable. For decades, Excel expertise has often been measured by how quickly someone can build complex formulas, create PivotTables, or untangle messy spreadsheets. Copilot changes that. You can now describe what you want in plain English and let the AI do much of the heavy lifting.

But after looking at the latest capabilities around Copilot Skills in Excel, I think many people are missing the bigger opportunity.

The real value isn’t that Copilot can generate a formula.

It’s that it can help you repeat a proven process over and over again.

In most organisations, especially SMBs and MSPs, there are a handful of people who know how to make Excel sing. They’re the people who understand financial models, reporting structures, forecasting tools, and data analysis techniques. Everyone else tends to rely on them whenever something complicated appears in a workbook.

That creates a bottleneck.

I’ve seen it countless times. Month-end reporting arrives and everyone waits for the same person. Quarterly forecasting needs updating and the same expert gets involved again. A new staff member arrives and spends weeks learning spreadsheet processes that only exist in somebody’s head.

That’s not really an Excel problem.

It’s a knowledge-sharing problem.

Copilot Skills in Excel feel like Microsoft’s attempt to address exactly that issue. Rather than repeatedly explaining the same process, you can package those instructions into a reusable skill that Copilot can invoke when required. According to Microsoft’s documentation, skills allow Copilot in Excel to perform repeatable tasks using predefined instructions, and organisations can create custom skills stored in OneDrive for reuse. [support.mi…rosoft.com], [support.mi…rosoft.com]

That might sound like a small change, but I think it’s significant.

From Spreadsheet Expert to Process Expert

Imagine you’ve spent years refining a monthly reporting workbook.

You know exactly how the raw data is imported. You know which columns need cleaning. You know which calculations matter and which charts management expects to see.

Traditionally, every new employee needed training. Documentation had to be updated. Mistakes inevitably crept in.

Now imagine creating a skill that guides Copilot through that process.

Instead of asking a colleague to remember twenty separate steps, they simply invoke the skill and allow Copilot to perform the work in a consistent manner.

The expertise becomes transferable.

That’s a very different proposition from merely generating formulas.

Excel Is Becoming More Conversational

Something else strikes me here.

For years, becoming good at Excel meant learning Excel’s language. You memorised formulas, syntax, functions, and workarounds.

Copilot flips that model.

Now Excel is increasingly learning your language.

You can ask questions about data. Request analysis. Generate charts. Create reports. Import information. Explain formulas. Build dashboards. And increasingly, define repeatable business processes using natural language instructions. [support.mi…rosoft.com], [support.mi…rosoft.com]

That’s a major shift.

The barrier to entry drops dramatically.

People who previously avoided advanced spreadsheet work now have a capable assistant sitting beside them.

The Opportunity for MSPs

From an MSP perspective, I think this capability will become particularly interesting.

Most advice around AI focuses on content generation, meeting summaries, or email drafting. Those are valuable, but they’re often incremental productivity gains.

Skills have the potential to standardise operations.

Imagine creating repeatable Excel processes for:

  • Monthly financial reporting

  • Customer profitability analysis

  • Service desk trend reporting

  • Project forecasting

  • Licence consumption tracking

  • Security compliance reporting

Rather than documenting procedures in lengthy manuals, organisations can embed that knowledge directly into skills that guide Copilot.

That’s a much more scalable approach.

And importantly, it helps preserve organisational knowledge when staff move on.

The Human Still Matters

Of course, none of this removes the need for human oversight.

One lesson I’ve repeated many times with Microsoft 365 Copilot is that AI works best when it’s treated as a capable assistant, not an autonomous decision maker.

If Copilot analyses data, review the results.

If it creates a forecast, validate the assumptions.

If it generates a report, make sure the conclusions make sense.

The person remains accountable. Copilot simply removes much of the repetitive effort.

Final Thoughts

When people think about AI in Excel, they often focus on saving a few minutes creating formulas or formatting data.

That’s useful.

But I think the more interesting story is the ability to capture expertise and make it reusable.

The organisations that benefit most from AI won’t necessarily be those with the smartest prompts. They’ll be the ones that systematically turn repeatable knowledge into repeatable processes.

Excel Skills look like another step in that direction.

And for many businesses, that could end up being far more valuable than any individual formula.

You Didn’t Build a Business. You Built a To-Do List That Breathes.

MAI_dd7b3dc5448fe805

I had coffee with an MSP owner a few weeks back who couldn’t tell me what his business actually did anymore. Not because he didn’t know — but because there was too much to say. Three service lines. A new marketing funnel. A second office. A partner program he’d signed up for and half-forgotten. A stack of AI tools nobody had time to learn. He listed it all, then went quiet, and said the thing I keep hearing: “I’m busier than I’ve ever been and I can’t feel any of it.”

That’s the trap nobody warns you about. We’re told growth is addition. More clients, more staff, more channels, more tools. So we add. And every addition feels like progress on the day you make it. The problem is what addition does over time. It buries the thing that made the business worth building in the first place.

More Doesn’t Sound Like More

When you started, people could hear you. A client rang and got you. An email went out and it sounded like a person. The whole thing had a voice because there was one person behind it, and that person was unmistakable.

Then you scaled. You hired. You layered in process and policy and a second tier of support. All sensible. All necessary. But somewhere in there your voice got distributed across fifteen people and four systems, and the signal faded. The business got louder and you got quieter. That’s not a failure of growth — it’s the natural physics of it. The bigger the thing, the harder it is to hear the person who started it.

The Calendar Owns You Now

Here’s the part that stings. You built this to get freedom, and now it runs your week. Your inbox sets your priorities. Your calendar tells you where to be. Saturday morning you’re at the desk again, not because anyone made you, but because the machine you built only runs if you keep feeding it. You didn’t escape the job. You promoted yourself into a bigger one.

I don’t think the answer is to add a productivity app to manage the other productivity apps. That’s just one more thing on the pile. The answer is subtraction — and the uncomfortable truth is that subtraction takes more discipline than addition ever did. Anyone can say yes to a new channel. Saying no, or worse, dismantling something you already built, feels like going backwards.

Where Copilot Actually Earns Its Keep

This is the one place I’ll defend the AI tools, because most of them genuinely are just more noise. The useful ones give you back the thing you lost: your attention.

I use Copilot in Outlook to clear the overnight pile in minutes instead of an hour — not to write clever emails, but to tell me which three actually need me and draft the rest so I can move on. I’ll open a week’s worth of Teams meetings I half-listened to and ask Copilot to pull out what was decided and what’s mine to do, so I’m not carrying it all in my head. When a client account feels foggy, I ask Copilot to summarise everything across the emails, the files in SharePoint, and the chat history into one page. That’s not adding a tool. That’s using a tool to remove the overhead the other tools created.

The test is simple. Does it give you back time, or does it ask for more? If a new system needs three people and a fortnightly meeting to maintain, it isn’t growth. It’s weight. I’ve quietly killed more standing meetings and subscriptions this year than I started, and the business got clearer for it.

Audit What You’ve Added

Try this. Open your calendar in Outlook and look at last month honestly. Every recurring meeting, every program, every channel — ask what it actually returns. Not what it promised when you started it. What it returns now. Most owners I know find a third of it could go tomorrow and nobody would notice, except them, who’d suddenly have their head back.

The strongest businesses I work with aren’t the ones that added the most. They’re the ones that stayed recognisable — where you can still hear the person who built it, because they were ruthless about what they let in.

You can add forever. There’s always another channel, another tool, another hire. But at some point the thing you built starts to own you instead of the other way around. The way out isn’t more. It’s less, chosen on purpose.

One macOS login that finally uses Entra

image

Most MSPs treat the Macs in a client tenant like orphans. Enrol them in Intune, push a couple of profiles, tick the box, move on.

But the user still signs into that Mac with a local password. One nobody rotates, nobody recovers, and nobody can tie back to a real person. The Entra identity you spent all that effort hardening — MFA, Conditional Access, the lot — stops dead at the macOS login window.

That’s not managed. That’s two identities wearing the same hoodie.

Platform SSO closes the gap. And here’s the part that annoys me: it’s been sitting in your Intune licence the entire time.

What is Platform SSO, really?

It’s the thing that finally makes a Mac sign in with Entra ID the same way a Windows device does with Windows Hello for Business.

When you turn it on, the Mac gets joined to your Entra tenant and a hardware-bound certificate is locked to the device. From then on, the user’s Entra account is their login. Touch ID unlocks the machine. Apps and browsers get single sign-on off the back of it. No more re-typing the work password into every prompt.

You pick one of three flavours — Secure Enclave, smart card, or password. Microsoft recommends Secure Enclave, and so do I. It’s passwordless, phishing-resistant, and conceptually identical to Windows Hello for Business. The other two exist for edge cases.

Here’s the real win: it’s included with every Intune licensing plan. No add-on, no separate SKU. If you’ve got Business Premium, you already own this.

Step-by-Step: turning it on

Portal only. No scripts.

Check the prereqs first

Devices need macOS 13 or newer — push for macOS 14 Sonoma(opens in new window) for the cleanest experience. The Company Portal app must be version 5.2404.0 or later, because that’s what carries the SSO plug-in. And the user has to be allowed to join devices to Entra. Miss any of these and registration silently never happens.

Build the profile

In the Intune admin center, go to Devices > Manage devices > Configuration > Create > New policy. Platform: macOS. Profile type: Settings catalog.

Drop in the values

In the settings picker, expand Platform SSO and add the core settings:

Authentication Method   UserSecureEnclaveKey
Extension Identifier     com.microsoft.CompanyPortalMac.ssoextension
Team Identifier          UBF8T346G9
Registration token       {{DEVICEREGISTRATION}}

Notice what’s missing? No password field. No certificate to mint. No on-prem ADFS box wheezing in a cupboard. The Mac proves who it is with a key baked into its own silicon.

Deploy Company Portal, then assign

Push the latest Company Portal as a required app — that’s what installs the plug-in. Then assign the policy. One catch that bites people: for devices with user affinity, assign to users, not device groups or filters. Get that wrong and Conditional Access can lock the user out of the very resources you were protecting.

Why this actually changes behaviour

The first time the policy lands, the user sees a “Registration required” notification. They click it, sign in with their Entra account, do MFA once, and it’s done.

That prompt trips up every first-timer. It looks like something broke. It didn’t. That’s the moment the device gets Entra-joined and the certificate binds. Tell your clients it’s coming and the support ticket never gets raised.

“Why does it still ask for my old Mac password after a reboot?”

Because FileVault uses the local password as the disk unlock key. So after a cold boot you enter it once — then Touch ID takes over for the rest of the session. That’s by design, not a half-finished feature. Worth saying out loud before a client assumes it’s flaky.

And if there’s still an on-prem domain in the picture, you can layer Kerberos SSO to on-premises Active Directory onto the same policy. The Mac quietly handles both worlds.

Get this in place and a client’s Mac stops being the weak identity in the room. Same MFA. Same Conditional Access. Same audit trail as every Windows device. One login, one identity, one set of rules.

If you’re rolling out Macs and not showing clients this, you’re handing them a managed device with an unmanaged front door.

Platform SSO isn’t there to make Mac logins prettier. It’s there to make the local password irrelevant.