Required for the site to work (login, preferences, security). Always on.
MSP FAQ: remote-access governance after a Priority-1 client CVE
Governance sequel to ScreenConnect CVE pack: roles, MFA, audit, tenant boundaries. Does not restamp GDAP or login≠isolation.
MSP FAQ: remote-access governance checklist after a Priority-1 client CVE
Hook: After a Priority-1 remote-access / RMM client CVE (see sibling draft screenconnect-cve-2026-84869-msp-advisory), what governance checklist should an MSP run across technician roles, MFA, audit logs, and customer-tenant boundaries?
This FAQ is a governance sequel — it does not restamp already-staged GDAP governance or login≠isolation packs. Focus: remote-access tool roles, session hygiene, and per-customer blast-radius after patch urgency.
# MSP remote-access governance after P1 client CVE (defensive; NO PoC)
1. Patch/reinstall clients to vendor min build; verify fleet strings
2. Role audit: who has TransferFiles / shell / admin on which customers
3. Enforce MFA or SSO on all technician consoles; kill stale sessions
4. Per-customer tenant boundaries: no shared break-glass across estates
5. Audit log retention + alert on anomalous file-transfer / elevation
6. Change window docs + customer notice template ready before next P1
# Distinct from GDAP and login≠isolation FAQs already staged
Link the ScreenConnect advisory for patch facts; keep this pack for process. Soft Lodestar skipped (403). Soft Auris not forced here (see NHI FAQ / Muse consent packs for identity posture).
Draft only — do not publish without editorial review.