TL;DR: High-growth MSPs are not avoiding complexity but operationalising it, with 22% growing revenue by more than 20%, 70% supporting devices beyond Windows, and 75% managing more SaaS applications, according to JumpCloud’s webinar-based post. The underlying signal is that scale now depends on policy, automation, and governance across mixed estates, not stack simplification.
At a glance
What this is: This webinar-based post argues that the MSPs growing fastest are not simplifying away complexity, but using policy, automation, and SaaS governance to manage mixed client environments at scale.
Why it matters: It matters because MSP growth increasingly depends on identity governance across devices, applications, and AI-adjacent shadow IT, which directly affects how IAM and lifecycle controls are standardised across client estates.
By the numbers:
- 22% of MSPs surveyed grew their revenue by more than 20% in the past year.
- 70% are supporting devices beyond Windows.
- 27% of devices under management by high-growth MSPs are running macOS.
- 75% are managing more SaaS applications.
Context
Managed service provider growth increasingly tracks with the ability to govern complexity, not remove it. In practical terms, that means identity teams are dealing with mixed device estates, expanding SaaS footprints, and a larger surface area for policy enforcement, access control, and lifecycle management.
JumpCloud’s webinar positions this as a shift in operating model for MSPs: standardisation still matters, but it has to coexist with flexible controls that work across Windows, macOS, mobile, and cloud services. The identity lesson is that scale now depends on repeatable governance across heterogeneous client environments, not a single clean stack.
Key questions
Q: How should MSPs standardise identity controls across multiple client environments?
A: MSPs should define reusable policy baselines, apply them consistently across managed companies, and track any client-specific override as an exception. The goal is to reduce setup drift and keep access decisions reproducible across tenants. That approach gives auditors and operators a common reference point for review.
Q: Why does SaaS sprawl increase non-human identity risk?
A: SaaS sprawl increases NHI risk because every new integration can create tokens, service accounts, OAuth grants, and delegated permissions that persist outside normal review cycles. Those identities often have more reach than human users and fewer lifecycle checks. The result is wider attack surface and harder-to-audit access paths.
Q: What are the best practices for automating MSP security operations?
A: The best practices are to automate repeatable actions that are prone to drift, especially patching, policy enforcement, and compliance checks. Automation should reduce manual variance, not remove human oversight from exceptions. In an MSP environment, the objective is consistent execution at scale so that growth does not increase governance debt.
Q: How should MSPs extend identity governance to AI agents and autonomous bots in client environments?
A: MSPs should treat AI agents as first-class identities, not just workloads or application features. That means assigning unique identity, limiting privileges, enforcing conditional access where possible, and monitoring activity continuously. A single control plane can improve visibility, but governance still depends on policy, lifecycle management, and clear ownership across human users, service accounts, and autonomous systems.
Technical breakdown
Why policy standardisation matters across mixed device estates
Policy standardisation is the practice of applying the same baseline controls across different endpoint types, operating systems, and client environments. In an MSP context, that means security policy, access rules, and compliance requirements cannot depend on a single platform assumption. The operational challenge is not merely managing more devices. It is preserving control consistency while the estate becomes more heterogeneous. That has direct implications for identity governance because device diversity changes how users, admins, and service access are provisioned, monitored, and revoked.
Practical implication: define a common control baseline that can be enforced across all managed platforms, including BYOD where necessary.
How automation changes identity and security operations
Automation in MSP operations is not just about reducing labour. It is about making policy execution repeatable enough that scale does not erode governance quality. The article ties automation to patching, policy enforcement, and compliance tracking, which are all identity-adjacent control points when access and configuration need to stay aligned. Without automation, each additional client environment increases the chance of drift, missed enforcement, and inconsistent response. With it, MSPs can apply the same governance logic at higher volume without relying on manual ticket handling for every decision.
Practical implication: automate repetitive policy and compliance actions where identity, device, and application states must stay aligned.
Why SaaS sprawl creates shadow IT governance pressure
Shadow IT governance becomes harder as SaaS usage expands because the identity perimeter moves outside a centrally managed stack. Unmanaged applications introduce visibility gaps, inconsistent access control, and weaker offboarding discipline, especially when client teams adopt tools without central approval. The article’s point is that governance must extend to discovery, monitoring, and access oversight for sanctioned and unsanctioned SaaS alike. That is where identity control stops being just account administration and becomes application inventory and access governance.
Practical implication: build SaaS discovery and access oversight into your MSP operating model before app sprawl outpaces control.
Breaches seen in the wild
- JumpCloud breach 2023: North Korean hackers breached JumpCloud and abused its device commands framework against a few customers; all admin API keys were reset.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Complexity has become an operating advantage for MSPs that can govern it. The article’s central finding is not that simplification failed, but that modern client estates are too varied for simplification to be a growth strategy on its own. Device diversity, SaaS sprawl, and mixed policy needs now define the market. MSPs that can standardise governance across that variance will outlast those still optimising for a narrow stack.
Shadow IT is no longer a side issue in MSP delivery models. Once SaaS adoption becomes the norm, unmanaged applications turn into an access governance problem as much as an inventory problem. The control gap is visibility into what is being used and who can access it. That makes application discovery, entitlement oversight, and offboarding discipline part of the core MSP identity service, not an add-on.
Identity governance for MSPs now has to span endpoints, applications, and digital workers. The article’s closing guidance on AI agents is important because it shows how quickly identity scope expands once a provider manages not just users and devices but autonomous or semi-autonomous actors. The practitioner takeaway is that MSP governance models must evolve from account management toward a broader identity lifecycle view that covers every access-bearing subject, including machine and agent identities.
Repeatable controls matter more than platform uniformity. The strongest MSPs in this analysis are not winning by reducing complexity to one environment. They are winning by making policy, automation, and oversight repeatable across many environments. That is the governance pattern identity teams should copy: build controls that survive variation, because variation is now the default condition of managed services.
Identity blast radius: The real growth constraint is not client diversity itself, but the size of the governance gap created when access, device policy, and SaaS oversight are treated as separate operating problems. The implication is that MSP programmes need one operating model for all access-bearing identities, not separate workflows for endpoints, applications, and emerging AI workers.
What this signals
Managed service provider governance is shifting from stack reduction to control repeatability. The practical challenge is no longer whether a client environment is complex, but whether the provider can apply the same access and policy logic consistently across every estate it manages. That is where identity governance becomes a delivery model, not just an administrative function.
Shadow IT discovery should now sit inside MSP operating models. SaaS sprawl creates hidden access paths that can outgrow manual review very quickly, especially when clients adopt tools outside central approval. MSPs that can map sanctioned and unsanctioned applications early will have a clearer view of entitlement risk and offboarding exposure.
AI agents extend the identity perimeter into new forms of governance debt. If an MSP already struggles to track devices and applications consistently, unmanaged digital workers will compound the same problem. The control question is not whether the tool is automated, but whether its access is scoped, monitored, and removed with the same discipline applied to other access-bearing identities.
For practitioners
- Audit policy drift across client estates Compare security baselines, access rules, and compliance exceptions across managed environments so that Windows, macOS, mobile, and SaaS controls are not governed by separate assumptions.
- Automate repetitive governance tasks Move patching, policy enforcement, and compliance checks into repeatable workflows so that service delivery does not depend on manual ticket handling for every client change.
- Build SaaS discovery into operations Track sanctioned and unsanctioned applications as part of the MSP control model, with regular review of who can access each tool and how offboarding is handled.
- Treat AI agents as governed identities Assign access only when a digital worker has a defined task, monitor its activity like any other identity, and remove privileges when the task ends.
Key takeaways
- High-growth MSPs are succeeding by governing complexity, not by pretending modern client estates can be standardised into one narrow stack.
- The strongest operational levers in the article are policy consistency, automation, and SaaS visibility across mixed environments.
- Identity teams supporting MSPs should treat devices, applications, and AI agents as one governance surface when designing lifecycle and access controls.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-10 — Human Use of NHI | The article ends by treating AI agents as identities that need governed access and revocation. |
| NHI-01 — Improper Offboarding | The MSP governance model depends on removing access cleanly across SaaS and digital workers. | |
| Recommendation — Treat AI agents as governed identities and revoke their access when tasks end. Build offboarding steps that remove access from SaaS accounts and other access-bearing identities promptly. | ||
| NIST CSF 2.0 | PR.AA-05 — Access Permissions, Entitlements and Authorizations | The article centers on policy enforcement and entitlement control across mixed estates. |
| Recommendation — Apply consistent entitlement governance across endpoints, SaaS, and managed identities. | ||
| CIS Controls v8 | CIS-5 — Account Management | MSP growth depends on repeatable account and access management across client environments. |
| Recommendation — Standardise account lifecycle processes so access stays aligned across every managed client. | ||
Key terms
- Managed Service Provider Identity Governance: Managed Service Provider Identity Governance is the set of policies, controls, and oversight practices used to manage identities operated by a service provider on behalf of clients. It covers account lifecycle, access approvals, segregation of duties, logging, and periodic review so outsourced administration does not create hidden privilege or compliance gaps.
- Shadow IT Policy: A Shadow IT Policy is the governance document that defines how unapproved tools are discovered, approved, logged, and monitored. It creates the rules for registration, ownership, procurement, data handling, and exception management so that hidden services do not become unmanaged security and compliance risks.
- Policy Standardisation: The practice of applying a consistent control baseline across multiple environments. For MSPs, it reduces variance in device posture, application access, and enforcement logic so technicians can govern mixed estates without rebuilding the policy model for every client.
- Digital Worker Identity: A non-human identity used by an automated system, AI agent, or other software-driven worker that can access tools or data. For MSPs, the key issue is that it must be governed like any other identity, with scoped access, monitoring, and revocation.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 11, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org