An engineer logs into a client's environment during a routine check and finds something that shouldn't be there: a competitor's RMM agent quietly running on every server, a domain admin account nobody created, and Global Admin access already established in the cloud tenant. The previous IT provider hadn't fully left — they'd left a door open.
This isn't a hypothetical. It's a real scenario that surfaced in an IT community forum, and it's more common than most small business owners realize. What makes it especially dangerous isn't the boldness of the move — it's how long it goes undetected.
Silent Access Is the Real Threat
Most small businesses have no systematic way to answer a simple question: What software is actually running on my servers right now, and who put it there?
That gap is exactly what attackers — and unethical IT providers — exploit. According to The Hacker News, a newly discovered backdoor called SLEEPWALKER is engineered to stay completely inert until it receives a single crafted network packet — at which point it executes its own bytecode payload. It generates no alerts, no unusual traffic, and no visible process activity until the moment it's triggered. A competing MSP's unauthorized RMM agent operates on the same principle: it sits quietly, does nothing suspicious, and waits.
Meanwhile, as Security News reported on August 25, 2026, small businesses are facing a cybersecurity affordability crisis — breach costs are hitting record highs while the tools to prevent them remain priced for enterprise budgets. That combination — high exposure, limited tooling, and no detection plan — is exactly why unauthorized access goes unnoticed for months.
And when a foothold does get activated, the escalation can be rapid. Security News also covered SynkLoader, a multistage malware tool with screen-hijacking and credential-theft capabilities that researchers believe may be a precursor to ransomware deployment. Whether the initial access came from a threat actor or a rogue IT provider, the downstream risk is the same.
What Unauthorized Access Actually Looks Like
Before you can detect it, you need to know what you're looking for. Here are the four most common artifacts left behind by unauthorized remote access:
1. Unknown RMM agents running as services
Tools like Action1, ConnectWise Control, AnyDesk, and NinjaRMM install as Windows services or scheduled tasks. If your current IT provider didn't install it, it shouldn't be there. Check services.msc, Task Scheduler, and your installed programs list — and compare against what you've authorized.
2. Ghost admin accounts Look in Active Directory for accounts created outside your normal provisioning process, especially those with Domain Admin or Enterprise Admin privileges. In Microsoft 365, check the Admin Center under Users > Active Users, filtering by admin roles. Any account you don't recognize is a red flag.
3. Global Admin access in cloud tenants Microsoft 365 Global Admin is the highest privilege level available. Pull the list of Global Admins from the M365 Admin Center and verify each one. A former provider or unauthorized party with Global Admin can reset passwords, access email, disable MFA, and exfiltrate data — silently.
4. Persistent remote access via scheduled tasks or startup entries
RMM agents and backdoors often survive reboots by registering as startup items or scheduled tasks. Run schtasks /query /fo LIST /v on Windows servers and review anything with an unfamiliar binary path or publisher.
Your Detection Checklist
Run through this checklist any time you transition IT providers, suspect unauthorized access, or simply haven't audited your environment recently:
- [ ] Inventory all running services on every server — compare against your approved software list
- [ ] Audit installed programs on servers and workstations for RMM tools you didn't authorize
- [ ] Pull all admin accounts from Active Directory and M365 — verify each one by name and creation date
- [ ] Review Global Admin and privileged role assignments in your cloud tenant
- [ ] Check scheduled tasks and startup entries for unknown binaries
- [ ] Review firewall logs for outbound connections to unfamiliar RMM cloud infrastructure (e.g., action1.com, connectwise.com domains you don't use)
- [ ] Audit your DNS and MX records for unauthorized changes that could redirect email or traffic
- [ ] Check VPN and remote access logs for logins from unknown IP ranges or off-hours activity
This is also directly relevant if you're managing an MSP transition — we've written about MSP transition security risks and what old IT providers leave behind, including how to systematically revoke access during a handoff.
Why Passive Monitoring Isn't Enough
The SLEEPWALKER backdoor example is instructive here. A tool that generates zero network activity and no process anomalies until it's triggered will not be caught by standard alerting. The same is true for an RMM agent that's legitimately signed, communicates over HTTPS to a known cloud platform, and runs as a normal Windows service. Your antivirus won't flag it. Your SIEM won't alert on it. It looks exactly like authorized software — because the software itself is legitimate. Only the authorization is missing.
This is why endpoint visibility needs to be proactive, not reactive. You need a periodic, systematic inventory of what's running — not just alerts when something bad happens. We covered a similar gap in our post on IT provider offboarding and data hostage risk, where the problem isn't malware — it's authorized-looking access that was never properly revoked.
For CMMC Level 1 contractors, this isn't optional. Access control and system inventory are foundational requirements, and an unauthorized admin account or undisclosed remote access tool is a direct compliance failure.
If You Find Something You Didn't Authorize
Don't just delete it. The steps matter:
- Document everything first — screenshot the service, account, or task before removing it. You may need this for legal or insurance purposes.
- Isolate the affected system if you believe active access is occurring.
- Disable, don't delete, the account — deletion can destroy audit trail evidence.
- Change all credentials on systems the unauthorized party could have accessed, including service accounts.
- Notify your cyber insurance carrier — unauthorized access is a covered event under most policies, but late reporting can void the claim.
- Review your RMM security posture — our RMM tool emergency playbook walks through the response steps in detail.
Take Action
The uncomfortable truth is that most small businesses couldn't answer the question "What software is running on my servers right now?" in under five minutes. That's the gap a rogue IT provider — or a sophisticated threat actor — will walk right through.
Proactive scanning catches unauthorized agents, ghost admin accounts, and rogue remote access tools before someone else is quietly running your environment. Oscar Six Security's Radar does exactly that — an affordable, no-fluff vulnerability and exposure scan at $99/scan built specifically for small businesses and in-house IT teams who need answers without an enterprise budget.
Focus Forward. We've Got Your Six.