Endpoint Security for MSPs: Choose the Platform by Who Runs the SOC
Contents
Executive summary
An MSP should choose its endpoint platform by first deciding who answers the 2am alert, because that decision sets your staffing cost, your client contracts and your liability before any feature or price does. There are three models: run your own SOC on a vendor's EDR, resell a platform whose 24/7 SOC is included in the seat price, or buy the vendor's SOC as an add-on for the clients who need it. Only once that is settled do RMM and PSA integrations and per-seat margin decide between the remaining options.
Multi-tenant management is available in 16 of 17 tracked products (vendor data 2026-10-02); 8 of those include EDR, and 3 include a 24/7 SOC in the price. Regulated clients narrow the list further: two platforms built around the MSP channel, Huntress and ThreatDown, do not sign HIPAA Business Associate Agreements.
Three SOC models
| Model | Who answers the alert | Fits an MSP that | Example platforms |
|---|---|---|---|
| Your own SOC on vendor EDR | Your technicians, around the clock | Already runs a 24/7 NOC with security skills | Microsoft Defender for Business, ThreatDown Advanced, SentinelOne Singularity Complete |
| SOC included in the seat | The vendor's analysts, under your service name | Has no security staff and wants one price per seat | Huntress Managed EDR, ThreatDown Elite, Cynet |
| SOC as an add-on | The vendor, for clients who pay for it | Sells tiered packages to clients with different needs | WatchGuard Endpoint Security 360, Webroot Business Endpoint Protection |
The included-SOC model is the simplest to sell and the hardest to differentiate. The own-SOC model has the best margin on paper and the highest payroll in practice. The add-on model lets you tier clients but gives you two contracts to manage.
Managed response and EDR by platform
Limited to multi-tenant products that include EDR, since a security service built on antivirus alone gives your SOC nothing to investigate:
| Product | 24/7 managed response | Ransomware rollback | SIEM integration |
|---|---|---|---|
| Not offered | Not offered | Included | |
| Included | Included | Included | |
| Not offered | Included | Included | |
| Not offered | Included | Included | |
| Included | Not offered | Included | |
| Included | Included | Included | |
| Not offered | Included | Included | |
| Add-on | Included | Included |
RMM and PSA fit
Integrations are where a platform saves or costs technician hours every day. This table covers every multi-tenant product, including those without EDR, because many MSPs still run a cheaper antivirus tier for low-risk clients:
| Product | RMM/PSA integration | Named integrations |
|---|---|---|
| Included | ConnectWise Automate, ConnectWise RMM, ConnectWise PSA, Datto RMM, Kaseya VSA, HaloPSA | |
| Included | ConnectWise Asio, ConnectWise Automate, ConnectWise Manage, Kaseya VSA, Kaseya VSA X, Datto RMM, Datto Autotask, N-able, NinjaOne, Atera, SuperOps | |
| Included | None named | |
| Included | ConnectWise Automate, ConnectWise RMM, ConnectWise PSA, Datto RMM, Kaseya VSA, HaloPSA | |
| Included | ConnectWise Automate | |
| Included | ConnectWise, Datto RMM, Datto Autotask PSA, NinjaOne, Kaseya VSA, HaloPSA | |
| Included | ConnectWise Automate, ConnectWise Manage, Kaseya VSA, N-able | |
| Included | Syncro, SuperOps, ConnectWise Asio, ConnectWise Automate, ConnectWise Manage, Kaseya VSA, Kaseya BMS, Datto RMM, Datto Autotask, Atera RMM, Octoja RMM | |
| Included | Syncro, SuperOps, ConnectWise Asio, ConnectWise Automate, ConnectWise Manage, Kaseya VSA, Kaseya BMS, Datto RMM, Datto Autotask, Atera RMM, Octoja RMM | |
| Included | ConnectWise PSA, ConnectWise Automate, Autotask (Datto) PSA, Kaseya VSA | |
| Included | ConnectWise, NinjaOne | |
| Included | ConnectWise Manage, ConnectWise Automate, Autotask, HaloPSA, Kaseya BMS, Syncro, SyncroMSP, NinjaOne, N-Able, Kaseya VSA, Datto RMM | |
| Included | ConnectWise, Kaseya Datto, Atera, NinjaOne, N-able, HaloPSA, Datto RMM, Datto Autotask, ConnectWise RMM | |
| Included | ConnectWise, NinjaOne | |
| Included | Kaseya VSA, N-able N-central, N-able N-sight, NinjaOne, ConnectWise Manage, Autotask, HaloPSA | |
| Included | ConnectWise Automate, ConnectWise Manage, Kaseya VSA, Autotask PSA |
"None named" does not mean impossible. Microsoft Defender for Business, for instance, integrates through Microsoft 365 Lighthouse and its APIs rather than naming RMM partners.
Regulated clients change the shortlist
Healthcare clients. Huntress states that it does not provide BAAs, and ThreatDown says the same of its products. If a clinic's risk analysis says the endpoint vendor needs a BAA, your default stack cannot go on that client. Keep a BAA-capable platform in reserve; the medical and dental guide lists them.
Defense clients. Under CMMC, an MSP whose services process a client's CUI is an External Service Provider inside that client's assessment scope. Your tooling becomes their evidence. The defense contractor guide covers the 90-day preservation duty your platform must support.
Financial clients. Amended Regulation S-P requires advisers to make their service providers report a breach within 72 hours, and the FTC Safeguards Rule requires tax preparers to log user activity. Expect those duties to arrive in your contracts. See the financial adviser guide.
Huntress, SentinelOne or ThreatDown?
These three put the SOC models side by side. Huntress Managed EDR ($107.88 per endpoint per year) includes its SOC, has no minimum through the MSP channel, and has no public lab results. ThreatDown Elite ($99.00 per endpoint per year) includes managed detection and response and publishes a long list of named RMM/PSA integrations. SentinelOne Singularity Complete ($179.99 per endpoint per year) shares a FedRAMP authorisation with Singularity Control, the only other EDR product here that has one, and its package table lists managed detection and response as not included, so the MSP running it supplies the overnight cover itself. Field-by-field: Huntress vs SentinelOne, Huntress vs ThreatDown Elite, Huntress vs Microsoft Defender for Business.
What the list prices say
| Product | Per unit per month | 10 seats / yr | 25 seats / yr | 100 seats / yr |
|---|---|---|---|---|
| $3.00 /user/mo | $360.00 | $900.00 | $3,600.00 | |
| $6.58 /endpoint/mo | $790.00 | Via sales (online up to 20) | Via sales (online up to 20) | |
| $6.67 /endpoint/mo | $799.90 | $1,999.75 | $7,999.00 | |
| $8.25 /endpoint/mo | $990.00 | Via sales (online up to 20) | Via sales (online up to 20) | |
| $15.00 /endpoint/mo | $1,799.90 | $4,499.75 | $17,999.00 | |
| Min 50 seats | Min 50 seats | Min 50 seats | $9,588.00 |
These are end-customer list prices, the same ones the endpoint security price index tracks. Partner and distributor pricing is lower and usually published only after you sign up, so use this table for the relative cost of platforms and model your own margin with each partner programme. Huntress's direct purchase minimum of 50 endpoints does not apply through the MSP channel, and Huntress does not publish what it charges partners.
What should each MSP choose?
MSP of 2 to 5 technicians with no security staff. Included SOC. Pick between Huntress and ThreatDown Elite on your RMM, and keep a BAA-capable option for any healthcare client.
MSP with a staffed 24/7 NOC. You can run the SOC yourself on Microsoft Defender for Business or ThreatDown Advanced, or buy add-on SOC for overflow. Price the analysts honestly before choosing this model.
MSP with a healthcare-heavy book. Standardise on a platform whose vendor will sign a business associate agreement, so one stack covers every client. Among the multi-tenant products here, 4 come from a vendor that publishes a BAA offer: both SentinelOne Singularity tiers, Trend Micro Worry-Free, and Acronis Cyber Protect, where Acronis signs only for Advanced or Cyber Protect Cloud with Acronis Cloud Storage in a US data centre. Only the two SentinelOne tiers include EDR. For Cynet, Microsoft and the rest, get the vendor's answer in writing before you standardise.
MSP serving defense suppliers. Expect to hand over your own evidence to clients' assessors. Choose tooling whose telemetry you can export and retain for at least 90 days after an incident report.
Mistakes MSPs make
- One stack for every client, including a clinic that needs a BAA the vendor will not sign.
- Selling "24/7 monitoring" on an add-on SOC the client has not paid for. Your service description and the vendor contract must match.
- Choosing on list price. RMM fit and SOC quality cost or save more technician hours than a dollar per seat.
- Migrating the whole base without a pilot. Run it on your own devices, then one friendly client.
Frequently asked questions
Which endpoint platforms include a SOC an MSP can resell?
3 multi-tenant platforms fold the SOC into the seat price; others charge for it on top. The capability table marks each.
Which platforms integrate with ConnectWise, Datto, Kaseya or NinjaOne?
The RMM/PSA table lists the named integrations each vendor publishes. Unlisted integrations may exist through marketplaces or APIs.
Can an MSP use Huntress for healthcare clients?
Huntress does not sign BAAs. It can be used only where the client's own risk analysis concludes the service handles no ePHI and documents that; otherwise use a BAA-capable platform.
Does Huntress have a minimum purchase for MSPs?
Huntress sets no minimum for endpoints sold through an MSP; direct and reseller purchases carry a 50-endpoint minimum.
Methodology and caveats
Multi-tenant support, integrations, SOC inclusion and prices come from the Endpoint Index database, each with a vendor source and verification date. The capability and cost tables are filtered to multi-tenant products that include EDR; the RMM/PSA table includes every multi-tenant product. The SOC model table and the example platforms in it are editorial groupings based on those recorded capabilities. Prices are list, not partner, pricing.
Sources
- Huntress. Huntress and HIPAA Compliance.
- Huntress. Pricing.
- Endpoint Index comparison pages linked above and product pages for each product named. Dataset last verified 2026-10-02.
Related research
All research ›Methodology · Report an error · Vendor not listed? Get listed