Kaseya’s 2026 SaaS security report: Closing the unmanaged trust gap, found that trust is the root cause of much of the risk in SMB’s SaaS environments. “We see trust extended to external system users, third-party applications, unapproved tools and machine identities. We also see abuse of already trusted sessions and insufficient validation for legitimate users,” the report states.
This risk represents opportunity—for MSPs to educate their SMB clients, strengthen security and better position themselves as trusted advisors. Here are the key findings contributing to this security gap.
Lingering access capabilities create risk
The report found that guest accounts, created to give quick, temporary access to external users like contractors, now comprise 69% of accounts, significantly outnumbering licensed users.
This finding is significant because of the massive risk it presents. By allowing old guest accounts to linger for months or years, businesses are creating unmonitored entry points to protected company data. The increasing attack surface, combined with many guest accounts mistakenly being given privileged access, means these unmanaged accounts are quickly becoming a security crisis.
In a similar vein, external file sharing is steadily increasing in frequency as SaaS collaboration grows. In 2025, SaaS Alerts monitored more than 277 million shared files across SaaS environments, double the volume observed in 2024. More than 96.6 million of those files were shared externally, the report found.
External file sharing increases risk to sensitive business data, especially when access isn’t revoked after collaboration ends. These files can contain financial records, customer information, internal communications or intellectual property, which means risking leaked data and, in regulated industries, compliance and legal violations.
MSPs can help their clients mitigate these risks by:
- Automating lifecycle management for guest accounts, including expiration, review and removal processes.
- Monitoring guest accounts and external file-sharing activity across SaaS platforms.
- Setting automated alerts for unusual guest account growth, inactive accounts, unusual sharing activity and changes in access permissions to both files and guest accounts.
- Enforcing least-privilege access policies for external users and collaborators.
- Removing unneeded, orphaned sharing links, restricting public link sharing and enforcing expiration policies for external file access.
Internal infrastructure leaves SMBs open to attack
SMBs are also increasingly using OAuth to sign into AI assistants, automation tools and collaboration platforms across Microsoft 365 and Google Workspace, expanding the SaaS attack surface. This means significant risk, since successful attackers can gain persistent access to cloud storage, email conversations, shared documents and internal communications through OAuth-connected applications.
This risk is exacerbated by the alarmingly slow adoption of MFA by SMBs. Though MFA remains one of the most effective defenses against account compromise, the report found that in 2025, 56% of end-user accounts monitored had MFA disabled or inactive. At the organizational level, adoption was even lower. Only 27% of SMBs monitored were actively enforcing MFA policies across their environments, leaving nearly three-quarters of businesses exposed to password-based attacks.
The lack of MFA adoption is the single biggest threat found in the report, says Benjamin Jones, Sr. Manager of Security Analysis at Kaseya. “We still have 73% [of SMBs] not enforcing MFA,” he says. “That’s very disappointing, considering that a lot of the attacks that we see now are brute force attacks or password sprays. They’re very fast and usually effective if you don’t have MFA enabled.”
Without the second layer of protection added by MFA, SMBs are at risk from both OAuth breaches and password-based attacks like phishing, credential theft, and password reuse attacks.
MSPs can help mitigate the risk by:
- Audit OAuth-connected apps, removing unused integrations and limit third-party app permissions using least-privilege access policies.
- Monitoring for suspicious activity such as unusual consent requests or token abuse.
- Automating the detection of risky OAuth activity and unauthorized application access.
- Enforcing MFA across all end-user and administrator accounts and monitoring for accounts with MFA disabled or inactive.
- Requiring MFA during high-risk sign-ins and login attempts.
- Automating alerts for MFA status changes and failed authentication attempts.
Threats hiding amid alerts and trusted infrastructure
Detecting malicious activity is getting more difficult as well. Attackers are getting better at hiding inside of trusted infrastructure, routing attacks through VPNs, proxy networks, cloud hosting providers and compromised systems. This makes traditional security controls that rely on geolocation and IP reputation less effective. Simultaneously, remote work, outsourced operations and global operations are making it more difficult to separate bad actors from legitimate users.
In addition, the overwhelming number of security activity generated by SaaS environments makes it difficult to distinguish genuine threats from normal business activity. Of the 27.6 billion SaaS events monitored by the surveyors in 2025, only 1.1% of them were higher than low-severity, but that is still over 278.9 million medium and critical-level alerts.
The high volume of activity makes it more difficult for security teams to identify and respond to early indicators of compromise. Attacks are hiding inside activity that appears benign on its own, like file access, OAuth usage and automated application logins, but may become a meaningful threat signal when part of a larger behavioral pattern. Low and medium severity events like OAuth access from foreign applications, abnormal file activity and automated logins may initially seem harmless, but they can represent early indicators of account compromise, data exfiltration or persistent unauthorized access.
MSPs can help reduce their clients’ risk and increase visibility by:
- Monitoring for unusual login behavior such as impossible travel, abnormal login times and unfamiliar devices, instead of relying only on IP addresses or geolocation filtering.
- Tracking VPN, proxy and cloud-hosted login activity for suspicious patterns, such as repeated failed logins, password spraying and unusual session activity.
- Using automated alert prioritization to surface high-risk activity faster.
- Correlating low-severity events to identify broader attack patterns.
Defensive moves proactive MSPs can make
MSPs should be approaching security twofold to mitigate these threats, says Jones. “It’s investing more into their security postures, like conditional access policies, to prevent a lot of these attacks from being successful at all — then having a backup to it. I always compare security to Swiss cheese; one piece, you have a bunch of holes. Two pieces, you only have a couple holes here and there.”
Kaseya is making it easy for partners to identify and apply those security controls, says Jones. “Our platform makes it easier to apply those controls in Microsoft and other cloud-based environments with the click of a button. And if you screw up, you’ll be able to roll them back easily. Our platform really specializes helping MSPs apply [these controls] and being that aggregator that pulls in all those logs and identifies the stuff that’s suspicious.”
Related: New developments in MSP security you didn’t know you needed



