Skip to main content
Built for Liongard. Turn on the Liongard connector in Super Magic to run them end to end.

Backup Missed vs Failed Alert

Distinguish a backup that never ran (missed) from one that ran and errored (failed) — two different routes — and always state exposure via last-known-good.

Certificate Expiry Alert

Triage a certificate expiry alert — tier urgency by days remaining, identify what the cert secures and who owns renewal, and route into renewal work.

Certificate Inventory

Build an expiry calendar of every certificate a client depends on — public web, RDS, LOB, internal CA, device certs — with owner and renewal steps.

Cyber Insurance Form Prep

Draft cyber-insurance application answers from ticket, RMM, and posture evidence, cite each source, and mark every unverifiable answer for human review.

Cyber Risk Posture Review

Review a client's security posture using the cyber risk dashboard, identity data, open detections, and incident history, ranking the top risks.

DHCP Server Issues

Diagnose DHCP problems — APIPA 169.254 addresses, wrong-subnet leases, scope exhaustion, stuck failover pairs, and rogue DHCP servers on the LAN.

DMARC SPF Failure Triage

Diagnose SPF, DKIM, and DMARC email authentication failures: distinguish real spoofing attempts from sender misconfiguration and explain to the client.

DNS & Domain Issues

Diagnose DNS resolution and domain-expiry problems by laddering client to resolver to authoritative — stale records, intranet failing, whole domain dark.

Domain Expiry Alert Lifecycle

Handle registrar expiry and renewal notices safely: verify the sender is the real registrar, confirm the expiry date, and route to the renewal owner.

Endpoint Encryption Audit

Audit disk-encryption coverage on Windows BitLocker and Mac FileVault, flag unencrypted endpoints, and verify recovery keys are escrowed and retrievable.

Firewall Config Backup Audit

Verify every firewall config backup is current — via Liongard change history or the vendor state — and flag any device whose backup is missing or stale.

Global Admin Audit

Audit a client tenant's global administrator accounts and recent admin-role changes, flagging unexpected admins, missing MFA, and unauthorized grants.

Group Policy Troubleshooting

Diagnose GPO not applying — missing drive mappings, lock screens, software installs — by reading gpresult and walking scope, filtering, and inheritance.

Identity MFA Health Check

Review a client's identity hygiene — MFA coverage, privileged accounts, and stale accounts — and return ranked findings with remediation recommendations.

Inspector Read Discipline

Base skill defining how any Liongard inspector is read — resolve the environment, date the dataprint, verify field angles live, and state data age in every answer.

Internal DNS Server Issues

Fix AD-integrated internal DNS — stale records, external dead while internal works (or reverse), records vanishing — distinct from public DNS/domain.

Intune vs RMM Reconciliation

Reconcile an Intune-enrolled device list against RMM agent inventory — find machines missing an RMM agent, missing Intune, or double-managed conflicts.

IT Roadmap Builder

Draft a client IT roadmap from their ticket history plus asset and posture data — what to fix, upgrade, and invest in, organized into investment tiers.

Liongard Access Pattern

Base pattern for reading any system's config through Liongard: resolve environment, find inspector by systemType, verify run, query dataprint.

Liongard Active Directory Read

Answer on-prem Active Directory questions via Liongard AD inspector: privileged groups, stale accounts, password policy, GPOs, FSMO, and DC health.

Liongard AWS Read

Answer AWS account questions via Liongard AWS inspector: IAM users, access-key age, root/MFA posture, S3 exposure, security groups, resource census.

Liongard Azure Read

Answer Azure subscription questions via Liongard Azure inspector: resource inventory, spend signals, NSG changes, public exposure, unattached resources.

Liongard Bitdefender Read

Interrogate a client's Bitdefender GravityZone tenant via Liongard: protected endpoints, agent/module status, threat detections, policies, admins.

Liongard Change Review

Answer "what changed recently" from Liongard detections and timelines, correlating environment changes with new tickets after breakage or incidents.

Liongard Cisco ASA Read

Interrogate a client's Cisco ASA firewall via Liongard: software version, interfaces, ACLs/NAT, IPsec/AnyConnect VPN config, and admin access review.

Liongard Cisco Network Read

Interrogate Cisco IOS/IOS-XE switches and routers via Liongard: IOS versions, running-config change detection, port/interface inventory, VLAN layout.

Liongard ConnectWise Automate Read

Interrogate ConnectWise Automate (LabTech) via Liongard: managed computer inventory, agent check-in status, patch state, monitors, and locations.

Liongard Cross-Client Census

Answer "which clients run <system>?" across the book via Liongard launchpoint inventory: install-base census for zero-days, EOL waves, vendor risk.

Liongard Datto RMM Read

Interrogate a client's Datto RMM footprint via Liongard: managed device inventory, agent online status, patch state, monitored alerts, and sites.

Liongard Duo Read

Answer Duo MFA posture questions via the Liongard Duo inspector: enrollment coverage, bypass users, admin list, and protected-integration inventory.

Liongard Email Security Config Read

Read a client's Mimecast/Proofpoint-class email security config via Liongard: policy posture, connector state, and config drift without admin console.

Liongard Exchange On-Prem Read

Interrogate on-premises Microsoft Exchange via Liongard: server version/CU/build, databases, mailbox inventory, connectors, and admin access review.

Liongard FortiGate Read

Interrogate a client's FortiGate via the Liongard Fortinet inspector: FortiOS firmware, policy changes, VPN tunnels, admin accounts, license state.

Liongard Google Workspace Read

Answer Google Workspace tenant questions via Liongard: super admin roles, 2SV coverage, license usage, and Drive-sharing posture for Google clients.

Liongard Hyper-V Read

Interrogate a client's Hyper-V hosts via Liongard: host and VM inventory, checkpoint sprawl, replica health, and VM placement and power state.

Liongard Internet Domain & TLS Read

Answer domain, DNS, and TLS questions via Liongard Internet Domain and TLS inspectors: registrar, expiry, DNS changes, mail-auth records, cert sweeps.

Liongard JumpCloud Read

Interrogate a client's JumpCloud directory via Liongard: users, MFA enrollment, admins, groups, bound systems, and SSO app assignments for reviews.

Liongard Kaseya VSA Read

Interrogate a client's Kaseya VSA footprint via Liongard: managed agent inventory, online status, patch state, monitor sets, and machine groups.

Liongard M365 Tenant Read

Answer tenant-level Microsoft 365 questions via the Liongard M365 inspector: license assignment, mailbox stats, admin roles, secure score, sharing.

Liongard Meraki Read

Interrogate a client's Cisco Meraki org via the Liongard Meraki inspector: SSIDs, VLANs, firmware, admin list, device inventory, and license state.

Liongard Mimecast Read

Interrogate a client's Mimecast tenant via Liongard: managed domains, users and licenses, policies, connectors and routing, and admin accounts.

Liongard N-central Read

Interrogate a client's N-able N-central footprint via Liongard: managed device inventory, agent/probe status, patch state, monitored services, sites.

Liongard Network Documentation Sync

Diff what Liongard inspectors see (firewalls, switches, wireless, hypervisors, servers) against the doc platform and draft network-doc corrections.

Liongard Okta Read

Answer Okta tenant questions via the Liongard Okta inspector: app assignments, admin roles, MFA policies, and deactivated-user hygiene reviews.

Liongard Palo Alto Read

Interrogate a client's Palo Alto firewall via Liongard: PAN-OS version, config changes and commit history, admin activity, HA state, policy posture.

Liongard pfSense Read

Interrogate a client's pfSense firewall via the Liongard pfSense inspector: version, interfaces, firewall/NAT rules, VPN config, packages, admins.

Liongard Proofpoint Read

Interrogate a client's Proofpoint Essentials tenant via Liongard: protected domains, users and licenses, filtering policy, spooling, and admins.

Liongard QBR Evidence Pack

Assemble QBR-grade posture evidence for one client from Liongard inspectors: identity risk, EOL exposure, cert/domain hygiene, and config drift.

Liongard SentinelOne Read

Interrogate a client's SentinelOne tenant via Liongard: protected agents, agent/version health, threat detections, policy/site assignment, admins.

Liongard SonicWall Read

Interrogate a client's SonicWall via Liongard: SonicOS firmware, security-services licensing and expiry, access rules, VPN policies, admin accounts.

Liongard Sophos Central Read

Interrogate a client's Sophos Central tenant via Liongard: protected endpoints, threat/health status, tamper protection, policy, and admin list.

Liongard Sophos Firewall Read

Interrogate a client's Sophos Firewall (XG/SFOS) via Liongard: firmware, firewall rules, port-forwards/NAT, VPN config, interfaces, admin access.

Liongard UniFi Read

Interrogate a client's Ubiquiti UniFi controller via the Liongard inspector: device inventory, adoption state, firmware drift, and WLAN/network config.

Liongard Veeam Posture Read

Interrogate a client's Veeam deployment via Liongard: job inventory and schedules, repository capacity, protected-VM census, and license state.

Liongard VMware Read

Interrogate a client's vCenter/ESXi estate via Liongard: host versions and build levels, datastore capacity, snapshot sprawl, VM inventory/placement.

Liongard WatchGuard Config Read

Interrogate a client's WatchGuard Firebox posture via Liongard: Fireware version, subscription/licensing, policy inventory, VPN config, admin accounts.

Liongard Webroot Read

Interrogate a client's Webroot GSM console via the Liongard Webroot inspector: protected endpoints, agent status, threat state, policy, and sites.

Liongard Windows Server Read

Interrogate a client's Windows Servers via Liongard: installed roles, local admin members, services, patch level, OS version and end-of-life flags.

Mobile Fleet Review

Review phones and tablets under MDM — enrollment, OS version spread, compliance flags, and readiness to lock or wipe a lost or stolen device.

Monthly Security Report

Produce a client's monthly security digest: incident and alert counts, notable events, posture trend, and recommendations for client or internal review.

Network Device Inventory

Refresh a client network device inventory — switches, APs, firewalls, routers per site — by combining documentation with what monitoring actually sees.

NIST CSF Gap Brief

Map a client's security posture to the NIST Cybersecurity Framework functions and return a plain-language gap brief — no certification or compliance claim.

Patch Compliance Review

Report patch status for one device or a whole fleet — missing, failed, and pending patches — via ConnectWise RMM, Liongard, or NinjaOne alerts as fallback.

QBR & SBR Prep

Prepare an internal brief before a quarterly or strategic business review — trends, recurring issues, sentiment, opportunities, agenda, likely questions.

RAID Degradation Alert

Triage a RAID degraded or failed-member alert with zero-margin urgency — one failure from data loss — and enforce the verify-backups-BEFORE-rebuild rule.

RDS / AVD Troubleshooting

Diagnose Remote Desktop Services and Azure Virtual Desktop session issues: connect failures, profile hangs, licensing, black screens, missing printers.

RMM Cross-Tool Reconciliation

Reconcile device lists across RMM, EDR, backup, and documentation — find missing agents, single-tool orphans, and count mismatches that distort billing.

Sage 50 / Sage 100

Diagnose Sage 50 and Sage 100 problems: data-path faults, share permissions, Pervasive/Actian PSQL engine service, and multi-user access errors at close.

SD-WAN / Multi-Circuit Monitoring

Review a multi-circuit or SD-WAN site — confirm each circuit is up, failover works, and open the right ISP escalation when a link is down or degraded.

Security Onboarding New Client

Run a new-client security intake: MFA coverage, admin inventory, backup posture, EDR presence, and produce the day-one risk list before an incident.

Server Decommission Runbook

Safely retire a server — map dependencies, migrate data, clean up DNS, monitoring, backup, wipe, and update docs, with an approval gate before destruction.

Server Diagnostics

Deep single-server review — services, activities, alert history, role inference, and change correlation via Liongard detections when the tenant is on.

Switch VLAN and Port Change

Prepare a switch port or VLAN change safely — blast-radius check, agreed change window, and a rollback config saved before anything on the switch changes.

Tenant Onboarding Checklist

Onboard a new Microsoft 365 tenant: GDAP scoping, break-glass accounts, security-defaults-vs-CA decision, admin and licensing inventory.

Typosquat Domain Alert

Work a typosquat or lookalike domain alert impersonating a client: gather registrar and DNS facts without visiting, gauge capability, draft a warning.

Warranty and EOL Report

Build an aging-fleet report for a client — end-of-life operating systems, old hardware, and warranty status where a source exposes it, for lifecycle risk.

WiFi Infrastructure Audit

Audit a wireless estate — AP inventory per site, coverage complaints from ticket history, firmware posture, and a guest-network isolation check per client.