<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>MSP Stack on Alfred van Ster</title><link>https://avanster.tech/tags/msp-stack/</link><description>Recent content in MSP Stack on Alfred van Ster</description><generator>Hugo -- 0.161.1</generator><language>en-us</language><lastBuildDate>Sun, 03 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://avanster.tech/tags/msp-stack/index.xml" rel="self" type="application/rss+xml"/><item><title>Architecting Resilient TS Plus Environments for Remote Workforces</title><link>https://avanster.tech/posts/tsplus-high-availability/</link><pubDate>Sun, 03 May 2026 00:00:00 +0000</pubDate><guid>https://avanster.tech/posts/tsplus-high-availability/</guid><description>&lt;h3 id="overview"&gt;Overview&lt;/h3&gt;
&lt;p&gt;Delivering remote applications seamlessly requires more than just opening an RDP port. In a modern Managed Service Provider (MSP) landscape, exposing internal servers directly to the internet is a critical security failure.&lt;/p&gt;
&lt;p&gt;This guide breaks down the architecture required to build a highly available, secure TS Plus environment that guarantees uptime while strictly controlling access via a centralized gateway and external MFA.&lt;/p&gt;
&lt;h3 id="the-architecture"&gt;The Architecture&lt;/h3&gt;
&lt;p&gt;A resilient TS Plus deployment separates the access layer from the execution layer. This ensures that a spike in user traffic or a targeted attack on the gateway does not crash the underlying application servers.&lt;/p&gt;</description></item><item><title>Enforcing Zero-Trust on macOS via Jamf and SentinelOne</title><link>https://avanster.tech/posts/zero-trust-macos-jamf/</link><pubDate>Sun, 03 May 2026 00:00:00 +0000</pubDate><guid>https://avanster.tech/posts/zero-trust-macos-jamf/</guid><description>&lt;h3 id="overview"&gt;Overview&lt;/h3&gt;
&lt;p&gt;Managing Apple devices in a predominantly Windows-centric MSP environment is often treated as an afterthought. However, relying on basic MDM profiles is no longer sufficient. To achieve true Zero-Trust, macOS fleets require the same stringent Endpoint Detection and Response (EDR) and identity controls as their Windows counterparts.&lt;/p&gt;
&lt;p&gt;This guide details the architectural implementation of enforcing Zero-Trust on macOS using Jamf Pro for orchestration, SentinelOne for threat hunting, and Keeper for MFA-backed identity management.&lt;/p&gt;</description></item><item><title>Zero-Touch M365 Offboarding with n8n, Docker, and PowerShell</title><link>https://avanster.tech/posts/zero-touch-m365-offboarding/</link><pubDate>Sun, 03 May 2026 00:00:00 +0000</pubDate><guid>https://avanster.tech/posts/zero-touch-m365-offboarding/</guid><description>&lt;h3 id="overview"&gt;Overview&lt;/h3&gt;
&lt;p&gt;In a Managed Service Provider (MSP) environment, manual offboarding is a massive liability. Missing a step when revoking access can lead to data breaches, compliance violations, and wasted licensing costs.&lt;/p&gt;
&lt;p&gt;This guide outlines an architectural approach to &amp;ldquo;Zero-Touch&amp;rdquo; offboarding, leveraging a self-hosted n8n instance running in Docker to trigger a robust PowerShell workflow that interacts directly with the Microsoft Graph API.&lt;/p&gt;
&lt;h3 id="the-architecture"&gt;The Architecture&lt;/h3&gt;
&lt;p&gt;Relying on technicians to manually run scripts on their local machines creates bottlenecks. By containerizing the automation engine, we achieve predictable, auditable execution.&lt;/p&gt;</description></item></channel></rss>