{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/close-technician-offboarding-across-msp-access/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/close-technician-offboarding-across-msp-access/",
        "slug": "close-technician-offboarding-across-msp-access",
        "url": "https://update.dsesecurity.com/updates/close-technician-offboarding-across-msp-access/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/close-technician-offboarding-across-msp-access.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/close-technician-offboarding-across-msp-access/"
        },
        "title": "Close technician offboarding across PSA, RMM, vaults, partner portals, and customer access",
        "summary": "Disabling one directory account does not end an MSP technician’s access. Close sessions, groups, RMM and PSA accounts, vault permissions, customer-local identities, API tokens, recovery paths, and shared knowledge.",
        "format": {
            "slug": "checklist",
            "name": "Checklist"
        },
        "priority": {
            "slug": "important",
            "name": "Important"
        },
        "featured": false,
        "image": {
            "theme": "identity-cloud",
            "label": "Identity & cloud",
            "alt": "Governed cloud identity system with connected service and lifecycle nodes.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            },
            {
                "slug": "microsoft-365-identity",
                "name": "Microsoft 365 & Identity",
                "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
            }
        ],
        "author": {
            "name": "Gavin Stewart",
            "url": "https://www.linkedin.com/in/gavin-stewart-0718/",
            "type": "Person"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-08-17T13:23:00+00:00",
        "modified_at": "2026-08-17T19:22:09+00:00",
        "reviewed_on": "2026-08-17",
        "reading_minutes": 3,
        "word_count": 609,
        "potentially_affected": "Technician identities; Microsoft Entra and local directories; PSA and RMM platforms; vaults; backup consoles; partner portals; customer-local accounts; API tokens; remote access; documentation; and recovery mechanisms.",
        "dse_recommendation": "Build a role-based access register, trigger offboarding from an authoritative event, disable and revoke sessions immediately, remove delegated and customer-local access, rotate exposed shared secrets, verify closure, and retain evidence.",
        "primary_source": {
            "name": "CISA: Protecting Against Cyber Threats to Managed Service Providers and their Customers",
            "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-131a",
            "published_on": "2022-05-11",
            "authority": "Cybersecurity and Infrastructure Security Agency"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts: account termination must follow the real access graph</h2>\n<p><a href=\"https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final\" target=\"_blank\" rel=\"noopener noreferrer\">NIST SP 800-53 Rev. 5 Update 1</a> includes controls for managing accounts and for terminating access when employment ends. Its account-management guidance addresses creating, enabling, modifying, disabling, and removing accounts; aligning access with authorized users and roles; monitoring account use; and reviewing accounts. Personnel-termination controls include disabling system access, revoking credentials, retrieving property, and notifying responsible roles.</p>\n<p>Microsoft&#8217;s Cloud Solution Provider guidance likewise emphasizes removing users who no longer require access, reviewing administrative relationships and privileged roles, protecting credentials, and monitoring partner activity. CISA&#8217;s MSP advisory recommends restricting privileged access, tracking provider accounts, logging actions, and coordinating responsibilities between providers and customers.</p>\n<p>Those outcomes cannot be achieved by assuming the primary identity provider is the only control point. MSP access can persist through active browser sessions, local customer accounts, RMM agents, vault exports, API keys, application consents, emergency credentials, shared device codes, documentation copies, SSH keys, vendor portals, and customer-controlled identities. Some paths may not support centralized revocation, and an operator may possess knowledge of a shared credential even after the account that revealed it is disabled.</p>\n\n<h2>DSE recommendation: make offboarding an evidence-backed runbook</h2>\n<p>Build the runbook from the access paths used in daily service delivery. Assign an accountable coordinator, strict target times by risk, and a second person who confirms completion.</p>\n<ol>\n<li><strong>Define the trigger.</strong> Use an authoritative HR or leadership event with effective time, employment status, role change, legal constraints, equipment location, manager, and offboarding risk level. Restrict advance notice when required, but pre-stage the checklist and owners.</li>\n<li><strong>Contain identity first.</strong> Disable privileged and standard accounts at the effective time, revoke active sessions and refresh tokens, remove authentication methods, block remote access, and remove the person from privileged groups, approval workflows, on-call systems, and password-recovery roles.</li>\n<li><strong>Close the MSP stack.</strong> Disable or delete named accounts in PSA, RMM, vault, documentation, backup, security, monitoring, registrar, cloud, telephony, source-control, and vendor systems. Reassign tickets, alerts, automation ownership, secrets, scheduled tasks, and customer communications before removing dependencies.</li>\n<li><strong>Close customer paths.</strong> Query the access register for GDAP groups, customer-local accounts, VPN profiles, firewall accounts, remote-support tools, certificates, SSH keys, API tokens, and customer-managed identities. Coordinate removals with customers where the provider lacks authority and document pending items.</li>\n<li><strong>Rotate exposed shared material.</strong> Change passwords, recovery codes, shared keys, and secrets the technician could retrieve or memorize. Prioritize domain administration, network equipment, backup, hypervisor, vault recovery, and emergency access. Validate dependent services after rotation.</li>\n<li><strong>Recover assets and data.</strong> Collect managed devices, badges, tokens, removable media, paper records, and licensed hardware. Remotely isolate or wipe devices only under approved policy. Preserve required business records and prevent uncontrolled copies of customer data.</li>\n<li><strong>Verify independently.</strong> A second operator should search for the person&#8217;s name, addresses, object IDs, device certificates, tokens, group membership, recent sessions, and customer accounts. Test that old access fails, review post-termination alerts, record exceptions, and obtain owner signoff.</li>\n</ol>\n<p><strong>Factual boundary:</strong> NIST controls describe security outcomes, not product-specific deletion commands or legal procedures. Disabling an identity does not retract information already viewed or copied. Labor, privacy, evidence-preservation, and customer-notification requirements must be determined with the appropriate business and legal owners.</p>\n<p>Track time from effective termination to session revocation, unresolved customer paths, shared-secret rotations, returned assets, orphaned automations, failed verification tests, and post-departure access attempts. A mature process can answer not just when the employee account was disabled, but when every material customer-access path was closed and who verified it.</p>\n\n<h2>Official references</h2>\n<ul>\n<li>NIST, <a href=\"https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Security and Privacy Controls for Information Systems and Organizations</em></a>, SP 800-53 Rev. 5 Update 1.</li>\n<li>Microsoft Learn, <a href=\"https://learn.microsoft.com/en-us/partner-center/security/csp-security-best-practices\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Security best practices for Cloud Solution Provider partners</em></a>.</li>\n<li>CISA, <a href=\"https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-131a\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Protecting Against Cyber Threats to Managed Service Providers and their Customers</em></a>.</li>\n</ul>",
        "content_text": "Source facts: account termination must follow the real access graph\nNIST SP 800-53 Rev. 5 Update 1 includes controls for managing accounts and for terminating access when employment ends. Its account-management guidance addresses creating, enabling, modifying, disabling, and removing accounts; aligning access with authorized users and roles; monitoring account use; and reviewing accounts. Personnel-termination controls include disabling system access, revoking credentials, retrieving property, and notifying responsible roles.\nMicrosoft’s Cloud Solution Provider guidance likewise emphasizes removing users who no longer require access, reviewing administrative relationships and privileged roles, protecting credentials, and monitoring partner activity. CISA’s MSP advisory recommends restricting privileged access, tracking provider accounts, logging actions, and coordinating responsibilities between providers and customers.\nThose outcomes cannot be achieved by assuming the primary identity provider is the only control point. MSP access can persist through active browser sessions, local customer accounts, RMM agents, vault exports, API keys, application consents, emergency credentials, shared device codes, documentation copies, SSH keys, vendor portals, and customer-controlled identities. Some paths may not support centralized revocation, and an operator may possess knowledge of a shared credential even after the account that revealed it is disabled.\n\nDSE recommendation: make offboarding an evidence-backed runbook\nBuild the runbook from the access paths used in daily service delivery. Assign an accountable coordinator, strict target times by risk, and a second person who confirms completion.\n\nDefine the trigger. Use an authoritative HR or leadership event with effective time, employment status, role change, legal constraints, equipment location, manager, and offboarding risk level. Restrict advance notice when required, but pre-stage the checklist and owners.\nContain identity first. Disable privileged and standard accounts at the effective time, revoke active sessions and refresh tokens, remove authentication methods, block remote access, and remove the person from privileged groups, approval workflows, on-call systems, and password-recovery roles.\nClose the MSP stack. Disable or delete named accounts in PSA, RMM, vault, documentation, backup, security, monitoring, registrar, cloud, telephony, source-control, and vendor systems. Reassign tickets, alerts, automation ownership, secrets, scheduled tasks, and customer communications before removing dependencies.\nClose customer paths. Query the access register for GDAP groups, customer-local accounts, VPN profiles, firewall accounts, remote-support tools, certificates, SSH keys, API tokens, and customer-managed identities. Coordinate removals with customers where the provider lacks authority and document pending items.\nRotate exposed shared material. Change passwords, recovery codes, shared keys, and secrets the technician could retrieve or memorize. Prioritize domain administration, network equipment, backup, hypervisor, vault recovery, and emergency access. Validate dependent services after rotation.\nRecover assets and data. Collect managed devices, badges, tokens, removable media, paper records, and licensed hardware. Remotely isolate or wipe devices only under approved policy. Preserve required business records and prevent uncontrolled copies of customer data.\nVerify independently. A second operator should search for the person’s name, addresses, object IDs, device certificates, tokens, group membership, recent sessions, and customer accounts. Test that old access fails, review post-termination alerts, record exceptions, and obtain owner signoff.\n\nFactual boundary: NIST controls describe security outcomes, not product-specific deletion commands or legal procedures. Disabling an identity does not retract information already viewed or copied. Labor, privacy, evidence-preservation, and customer-notification requirements must be determined with the appropriate business and legal owners.\nTrack time from effective termination to session revocation, unresolved customer paths, shared-secret rotations, returned assets, orphaned automations, failed verification tests, and post-departure access attempts. A mature process can answer not just when the employee account was disabled, but when every material customer-access path was closed and who verified it.\n\nOfficial references\n\nNIST, Security and Privacy Controls for Information Systems and Organizations, SP 800-53 Rev. 5 Update 1.\nMicrosoft Learn, Security best practices for Cloud Solution Provider partners.\nCISA, Protecting Against Cyber Threats to Managed Service Providers and their Customers.",
        "content_markdown": "## Source facts: account termination must follow the real access graph\n\n[NIST SP 800-53 Rev. 5 Update 1](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final) includes controls for managing accounts and for terminating access when employment ends. Its account-management guidance addresses creating, enabling, modifying, disabling, and removing accounts; aligning access with authorized users and roles; monitoring account use; and reviewing accounts. Personnel-termination controls include disabling system access, revoking credentials, retrieving property, and notifying responsible roles.\n\nMicrosoft’s Cloud Solution Provider guidance likewise emphasizes removing users who no longer require access, reviewing administrative relationships and privileged roles, protecting credentials, and monitoring partner activity. CISA’s MSP advisory recommends restricting privileged access, tracking provider accounts, logging actions, and coordinating responsibilities between providers and customers.\n\nThose outcomes cannot be achieved by assuming the primary identity provider is the only control point. MSP access can persist through active browser sessions, local customer accounts, RMM agents, vault exports, API keys, application consents, emergency credentials, shared device codes, documentation copies, SSH keys, vendor portals, and customer-controlled identities. Some paths may not support centralized revocation, and an operator may possess knowledge of a shared credential even after the account that revealed it is disabled.\n\n## DSE recommendation: make offboarding an evidence-backed runbook\n\nBuild the runbook from the access paths used in daily service delivery. Assign an accountable coordinator, strict target times by risk, and a second person who confirms completion.\n\n- Define the trigger. Use an authoritative HR or leadership event with effective time, employment status, role change, legal constraints, equipment location, manager, and offboarding risk level. Restrict advance notice when required, but pre-stage the checklist and owners.\n\n- Contain identity first. Disable privileged and standard accounts at the effective time, revoke active sessions and refresh tokens, remove authentication methods, block remote access, and remove the person from privileged groups, approval workflows, on-call systems, and password-recovery roles.\n\n- Close the MSP stack. Disable or delete named accounts in PSA, RMM, vault, documentation, backup, security, monitoring, registrar, cloud, telephony, source-control, and vendor systems. Reassign tickets, alerts, automation ownership, secrets, scheduled tasks, and customer communications before removing dependencies.\n\n- Close customer paths. Query the access register for GDAP groups, customer-local accounts, VPN profiles, firewall accounts, remote-support tools, certificates, SSH keys, API tokens, and customer-managed identities. Coordinate removals with customers where the provider lacks authority and document pending items.\n\n- Rotate exposed shared material. Change passwords, recovery codes, shared keys, and secrets the technician could retrieve or memorize. Prioritize domain administration, network equipment, backup, hypervisor, vault recovery, and emergency access. Validate dependent services after rotation.\n\n- Recover assets and data. Collect managed devices, badges, tokens, removable media, paper records, and licensed hardware. Remotely isolate or wipe devices only under approved policy. Preserve required business records and prevent uncontrolled copies of customer data.\n\n- Verify independently. A second operator should search for the person’s name, addresses, object IDs, device certificates, tokens, group membership, recent sessions, and customer accounts. Test that old access fails, review post-termination alerts, record exceptions, and obtain owner signoff.\n\nFactual boundary: NIST controls describe security outcomes, not product-specific deletion commands or legal procedures. Disabling an identity does not retract information already viewed or copied. Labor, privacy, evidence-preservation, and customer-notification requirements must be determined with the appropriate business and legal owners.\n\nTrack time from effective termination to session revocation, unresolved customer paths, shared-secret rotations, returned assets, orphaned automations, failed verification tests, and post-departure access attempts. A mature process can answer not just when the employee account was disabled, but when every material customer-access path was closed and who verified it.\n\n## Official references\n\n- NIST, [Security and Privacy Controls for Information Systems and Organizations](https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final), SP 800-53 Rev. 5 Update 1.\n\n- Microsoft Learn, [Security best practices for Cloud Solution Provider partners](https://learn.microsoft.com/en-us/partner-center/security/csp-security-best-practices).\n\n- CISA, [Protecting Against Cyber Threats to Managed Service Providers and their Customers](https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-131a)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/close-technician-offboarding-across-msp-access/",
                "url": "https://update.dsesecurity.com/updates/close-technician-offboarding-across-msp-access/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-08-17"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/close-technician-offboarding-across-msp-access/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Close technician offboarding across PSA, RMM, vaults, partner portals, and customer access",
                        "item": "https://update.dsesecurity.com/updates/close-technician-offboarding-across-msp-access/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/close-technician-offboarding-across-msp-access/#article",
                "identifier": "https://update.dsesecurity.com/updates/close-technician-offboarding-across-msp-access/",
                "url": "https://update.dsesecurity.com/updates/close-technician-offboarding-across-msp-access/",
                "headline": "Close technician offboarding across PSA, RMM, vaults, partner portals, and customer access",
                "description": "Disabling one directory account does not end an MSP technician’s access. Close sessions, groups, RMM and PSA accounts, vault permissions…",
                "abstract": "Disabling one directory account does not end an MSP technician’s access. Close sessions, groups, RMM and PSA accounts, vault permissions, customer-local identities, API tokens, recovery paths, and shared knowledge.",
                "articleBody": "Source facts: account termination must follow the real access graph\nNIST SP 800-53 Rev. 5 Update 1 includes controls for managing accounts and for terminating access when employment ends. Its account-management guidance addresses creating, enabling, modifying, disabling, and removing accounts; aligning access with authorized users and roles; monitoring account use; and reviewing accounts. Personnel-termination controls include disabling system access, revoking credentials, retrieving property, and notifying responsible roles.\nMicrosoft’s Cloud Solution Provider guidance likewise emphasizes removing users who no longer require access, reviewing administrative relationships and privileged roles, protecting credentials, and monitoring partner activity. CISA’s MSP advisory recommends restricting privileged access, tracking provider accounts, logging actions, and coordinating responsibilities between providers and customers.\nThose outcomes cannot be achieved by assuming the primary identity provider is the only control point. MSP access can persist through active browser sessions, local customer accounts, RMM agents, vault exports, API keys, application consents, emergency credentials, shared device codes, documentation copies, SSH keys, vendor portals, and customer-controlled identities. Some paths may not support centralized revocation, and an operator may possess knowledge of a shared credential even after the account that revealed it is disabled.\n\nDSE recommendation: make offboarding an evidence-backed runbook\nBuild the runbook from the access paths used in daily service delivery. Assign an accountable coordinator, strict target times by risk, and a second person who confirms completion.\n\nDefine the trigger. Use an authoritative HR or leadership event with effective time, employment status, role change, legal constraints, equipment location, manager, and offboarding risk level. Restrict advance notice when required, but pre-stage the checklist and owners.\nContain identity first. Disable privileged and standard accounts at the effective time, revoke active sessions and refresh tokens, remove authentication methods, block remote access, and remove the person from privileged groups, approval workflows, on-call systems, and password-recovery roles.\nClose the MSP stack. Disable or delete named accounts in PSA, RMM, vault, documentation, backup, security, monitoring, registrar, cloud, telephony, source-control, and vendor systems. Reassign tickets, alerts, automation ownership, secrets, scheduled tasks, and customer communications before removing dependencies.\nClose customer paths. Query the access register for GDAP groups, customer-local accounts, VPN profiles, firewall accounts, remote-support tools, certificates, SSH keys, API tokens, and customer-managed identities. Coordinate removals with customers where the provider lacks authority and document pending items.\nRotate exposed shared material. Change passwords, recovery codes, shared keys, and secrets the technician could retrieve or memorize. Prioritize domain administration, network equipment, backup, hypervisor, vault recovery, and emergency access. Validate dependent services after rotation.\nRecover assets and data. Collect managed devices, badges, tokens, removable media, paper records, and licensed hardware. Remotely isolate or wipe devices only under approved policy. Preserve required business records and prevent uncontrolled copies of customer data.\nVerify independently. A second operator should search for the person’s name, addresses, object IDs, device certificates, tokens, group membership, recent sessions, and customer accounts. Test that old access fails, review post-termination alerts, record exceptions, and obtain owner signoff.\n\nFactual boundary: NIST controls describe security outcomes, not product-specific deletion commands or legal procedures. Disabling an identity does not retract information already viewed or copied. Labor, privacy, evidence-preservation, and customer-notification requirements must be determined with the appropriate business and legal owners.\nTrack time from effective termination to session revocation, unresolved customer paths, shared-secret rotations, returned assets, orphaned automations, failed verification tests, and post-departure access attempts. A mature process can answer not just when the employee account was disabled, but when every material customer-access path was closed and who verified it.\n\nOfficial references\n\nNIST, Security and Privacy Controls for Information Systems and Organizations, SP 800-53 Rev. 5 Update 1.\nMicrosoft Learn, Security best practices for Cloud Solution Provider partners.\nCISA, Protecting Against Cyber Threats to Managed Service Providers and their Customers.",
                "datePublished": "2026-08-17T13:23:00+00:00",
                "dateModified": "2026-08-17T19:22:09+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/close-technician-offboarding-across-msp-access/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Person",
                    "name": "Gavin Stewart",
                    "url": "https://www.linkedin.com/in/gavin-stewart-0718/"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/close-technician-offboarding-across-msp-access/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/identity-cloud-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Close technician offboarding across PSA, RMM, vaults, partner portals, and customer access"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Microsoft 365 & Identity",
                    "Checklist",
                    "Important priority"
                ],
                "genre": "Checklist",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Microsoft 365 & Identity",
                        "url": "https://update.dsesecurity.com/topic/microsoft-365-identity/"
                    }
                ],
                "wordCount": 609,
                "timeRequired": "PT3M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "CISA: Protecting Against Cyber Threats to Managed Service Providers and their Customers",
                    "url": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-131a",
                    "datePublished": "2022-05-11"
                }
            }
        ]
    }
}