RMM fundamentals: safe automation, remote access and securing the RMM
Running scripts and automation without causing outages, using remote access with consent and an audit trail, and protecting the RMM itself, which attackers target because it can reach every customer: MFA, least privilege, logging and the public guidance from CISA and partners.
- Level
- Intermediate
- Length
- About 55 minutes
- Contents
- 3 lessons · final exam
- Status
- Published · updated 1 Oct 2026
Skills you'll practise
- Choose the right run-as context and scope for a script, and test it before running it widely
- Keep secrets out of scripts and use the product's credential store or the customer's vault instead
- Start remote sessions with the right consent and leave an auditable record
- Explain why attackers target RMM tools and name the controls that protect them (MFA, least privilege, logging, allowlisting)
- Recognize signs of RMM misuse and escalate them quickly
Course outline
- 1.Scripts and automation without surprisesLesson · 18 min
- 2.Remote access with consent and a recordLesson · 15 min
- 3.The RMM as an attack targetLesson · 20 min
- 4.RMM fundamentals: safe automation, remote access and securing the RMM: knowledge checkKnowledge check · 15 questions
- 5.An unknown remote tool on a customer's PCsScenario
- 6.Final exam8 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- CISA, NSA and MS-ISAC: Protecting Against Malicious Use of Remote Monitoring and Management Software (AA23-025A, 2023)
- CISA and partners: Protecting Against Cyber Threats to Managed Service Providers and their Customers (AA22-131A, 2022)
- CISA-FBI guidance for MSPs and their customers affected by the Kaseya VSA supply-chain ransomware attack (2021)
- CISA JCDC: Remote Monitoring and Management (RMM) Cyber Defense Plan (2023)
- NIST SP 800-53 Rev. 5: Security and Privacy Controls (AC-6 Least Privilege, IA-2 Identification and Authentication incl. IA-2(1) MFA to privileged accounts, AU-2 Event Logging, AU-6 Audit Record Review)
- CIS Critical Security Controls v8.1 (Control 5 Account Management, Control 6 Access Control Management incl. 6.5 Require MFA for Administrative Access, Control 7 Continuous Vulnerability Management)
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.