Compliance

Rogue IT Provider in Your Systems: Detection Guide

Rogue IT Provider in Your Systems: Detection Guide

Know what attackers see before they do. See a sample Radar scan report →

An engineer logs into a client's environment during a routine check and finds something that shouldn't be there: a competitor's RMM agent quietly running on every server, a domain admin account nobody created, and Global Admin access already established in the cloud tenant. The previous IT provider hadn't fully left — they'd left a door open.

This isn't a hypothetical. It's a real scenario that surfaced in an IT community forum, and it's more common than most small business owners realize. What makes it especially dangerous isn't the boldness of the move — it's how long it goes undetected.

Silent Access Is the Real Threat

Most small businesses have no systematic way to answer a simple question: What software is actually running on my servers right now, and who put it there?

That gap is exactly what attackers — and unethical IT providers — exploit. According to The Hacker News, a newly discovered backdoor called SLEEPWALKER is engineered to stay completely inert until it receives a single crafted network packet — at which point it executes its own bytecode payload. It generates no alerts, no unusual traffic, and no visible process activity until the moment it's triggered. A competing MSP's unauthorized RMM agent operates on the same principle: it sits quietly, does nothing suspicious, and waits.

Meanwhile, as Security News reported on August 25, 2026, small businesses are facing a cybersecurity affordability crisis — breach costs are hitting record highs while the tools to prevent them remain priced for enterprise budgets. That combination — high exposure, limited tooling, and no detection plan — is exactly why unauthorized access goes unnoticed for months.

And when a foothold does get activated, the escalation can be rapid. Security News also covered SynkLoader, a multistage malware tool with screen-hijacking and credential-theft capabilities that researchers believe may be a precursor to ransomware deployment. Whether the initial access came from a threat actor or a rogue IT provider, the downstream risk is the same.

What Unauthorized Access Actually Looks Like

Before you can detect it, you need to know what you're looking for. Here are the four most common artifacts left behind by unauthorized remote access:

1. Unknown RMM agents running as services Tools like Action1, ConnectWise Control, AnyDesk, and NinjaRMM install as Windows services or scheduled tasks. If your current IT provider didn't install it, it shouldn't be there. Check services.msc, Task Scheduler, and your installed programs list — and compare against what you've authorized.

2. Ghost admin accounts Look in Active Directory for accounts created outside your normal provisioning process, especially those with Domain Admin or Enterprise Admin privileges. In Microsoft 365, check the Admin Center under Users > Active Users, filtering by admin roles. Any account you don't recognize is a red flag.

3. Global Admin access in cloud tenants Microsoft 365 Global Admin is the highest privilege level available. Pull the list of Global Admins from the M365 Admin Center and verify each one. A former provider or unauthorized party with Global Admin can reset passwords, access email, disable MFA, and exfiltrate data — silently.

4. Persistent remote access via scheduled tasks or startup entries RMM agents and backdoors often survive reboots by registering as startup items or scheduled tasks. Run schtasks /query /fo LIST /v on Windows servers and review anything with an unfamiliar binary path or publisher.

Your Detection Checklist

Run through this checklist any time you transition IT providers, suspect unauthorized access, or simply haven't audited your environment recently:

  • [ ] Inventory all running services on every server — compare against your approved software list
  • [ ] Audit installed programs on servers and workstations for RMM tools you didn't authorize
  • [ ] Pull all admin accounts from Active Directory and M365 — verify each one by name and creation date
  • [ ] Review Global Admin and privileged role assignments in your cloud tenant
  • [ ] Check scheduled tasks and startup entries for unknown binaries
  • [ ] Review firewall logs for outbound connections to unfamiliar RMM cloud infrastructure (e.g., action1.com, connectwise.com domains you don't use)
  • [ ] Audit your DNS and MX records for unauthorized changes that could redirect email or traffic
  • [ ] Check VPN and remote access logs for logins from unknown IP ranges or off-hours activity

This is also directly relevant if you're managing an MSP transition — we've written about MSP transition security risks and what old IT providers leave behind, including how to systematically revoke access during a handoff.

Why Passive Monitoring Isn't Enough

The SLEEPWALKER backdoor example is instructive here. A tool that generates zero network activity and no process anomalies until it's triggered will not be caught by standard alerting. The same is true for an RMM agent that's legitimately signed, communicates over HTTPS to a known cloud platform, and runs as a normal Windows service. Your antivirus won't flag it. Your SIEM won't alert on it. It looks exactly like authorized software — because the software itself is legitimate. Only the authorization is missing.

This is why endpoint visibility needs to be proactive, not reactive. You need a periodic, systematic inventory of what's running — not just alerts when something bad happens. We covered a similar gap in our post on IT provider offboarding and data hostage risk, where the problem isn't malware — it's authorized-looking access that was never properly revoked.

For CMMC Level 1 contractors, this isn't optional. Access control and system inventory are foundational requirements, and an unauthorized admin account or undisclosed remote access tool is a direct compliance failure.

If You Find Something You Didn't Authorize

Don't just delete it. The steps matter:

  1. Document everything first — screenshot the service, account, or task before removing it. You may need this for legal or insurance purposes.
  2. Isolate the affected system if you believe active access is occurring.
  3. Disable, don't delete, the account — deletion can destroy audit trail evidence.
  4. Change all credentials on systems the unauthorized party could have accessed, including service accounts.
  5. Notify your cyber insurance carrier — unauthorized access is a covered event under most policies, but late reporting can void the claim.
  6. Review your RMM security posture — our RMM tool emergency playbook walks through the response steps in detail.

Take Action

The uncomfortable truth is that most small businesses couldn't answer the question "What software is running on my servers right now?" in under five minutes. That's the gap a rogue IT provider — or a sophisticated threat actor — will walk right through.

Proactive scanning catches unauthorized agents, ghost admin accounts, and rogue remote access tools before someone else is quietly running your environment. Oscar Six Security's Radar does exactly that — an affordable, no-fluff vulnerability and exposure scan at $99/scan built specifically for small businesses and in-house IT teams who need answers without an enterprise budget.

Focus Forward. We've Got Your Six.

See what Radar scans for →

Frequently Asked Questions

How do I check if an unauthorized RMM agent is installed on my server?

Open Services (services.msc) and review all running services, paying attention to any with names or binary paths associated with RMM tools like Action1, AnyDesk, ConnectWise, or NinjaRMM that you didn't authorize. Also check Task Scheduler and your installed programs list for tools your current IT provider didn't deploy. A proactive scan with a tool like Oscar Six Radar can surface these automatically.

Can a former IT provider still access my systems after I fire them?

Yes — if their RMM agent was never uninstalled, their admin accounts were never disabled, or their cloud tenant access was never revoked, a former provider may retain full access to your environment indefinitely. This is why a systematic offboarding audit — covering Active Directory, Microsoft 365 admin roles, and installed software — is critical whenever you change IT providers.

What is an unauthorized RMM agent and why is it dangerous?

An unauthorized RMM (Remote Monitoring and Management) agent is remote access software installed on your systems without your knowledge or consent. It gives whoever controls it the ability to execute commands, transfer files, and access data on your servers — silently, and often indistinguishable from legitimate software. Discovery is difficult without proactive endpoint inventory.

How much does it cost to scan for unauthorized software on my network?

Enterprise vulnerability management platforms can cost thousands per year, but Oscar Six Security's Radar offers a full exposure scan for $99 per scan — designed specifically for small businesses and in-house IT teams who need actionable answers without the enterprise price tag. You can learn more at oscarsixsecurityllc.com/#solutions.

Does finding an unauthorized admin account mean I've been breached?

Not necessarily, but it must be treated as a potential breach until proven otherwise. An unauthorized admin account means someone had — or still has — elevated access to your environment, and you should assume they may have accessed, copied, or modified data. Document the account, disable it without deleting it, rotate all credentials on affected systems, and notify your cyber insurance carrier.

Step-by-Step Guide

  1. Inventory Running Services

    On each server, open services.msc and review all running services. Flag any with names or binary paths associated with RMM tools or remote access software you did not authorize your current IT provider to install.

  2. Audit Installed Programs

    Check Add/Remove Programs (or Apps & Features) on servers and key workstations. Compare the list against your approved software inventory and flag anything unrecognized, especially remote access or monitoring tools.

  3. Pull All Admin Accounts

    In Active Directory, pull all accounts with Domain Admin or Enterprise Admin privileges. In Microsoft 365, review the Global Admin and privileged role lists under Users. Verify every account by name, creation date, and business justification.

  4. Review Scheduled Tasks and Startup Entries

    Run 'schtasks /query /fo LIST /v' on Windows servers and review all scheduled tasks for unfamiliar binary paths or publishers. Also check startup entries in the registry and startup folders for persistent access mechanisms.

  5. Check Firewall Logs for Outbound RMM Traffic

    Review outbound firewall logs for connections to RMM cloud infrastructure domains you don't recognize or don't use. Unauthorized agents typically beacon home on a regular schedule, which will appear as periodic HTTPS connections to vendor-specific cloud endpoints.

  6. Document and Respond to Findings

    If you find unauthorized software or accounts, screenshot and document everything before making changes. Disable accounts rather than deleting them, isolate affected systems if active access is suspected, rotate all credentials, and notify your cyber insurance carrier.

Find out what's exposed. Radar scans your external attack surface and shows you exactly what needs fixing. See a sample report →