NinjaOne
NinjaOne
Magic Library index for the NinjaOne connector — for endpoint management, patching, alerts, and RMM automation inside Super Magic.
Built for NinjaOne. Turn on the NinjaOne connector in Super Magic to run them end to end.
Acronis Cyber Protect
Handle Acronis Cyber Protect alerts: separate a backup failure from an Active Protection anti-ransomware detection and run the matching triage discipline.
Alert Reset With Note
Reset a NinjaOne alert only after the condition is genuinely healthy, posting an explanation note first. Attended or embedded in a recovery Flow.
AV/EDR Agent Offline Alert
Triage an AV/EDR agent-offline alert — decide if the device is off or up with a dead agent, quantify unprotected time, and route on the protection gap.
Axcient Backup Alerts
Triage Axcient x360Recover alerts: distinguish appliance vs Direct-to-Cloud failure families, verify retention, and state the last recoverable point.
Backup Failure Triage
Classify a backup failure by alert text and device state, check for recurrence, and decide whether to fix locally or escalate to the backup vendor.
Backup Missed vs Failed Alert
Distinguish a backup that never ran (missed) from one that ran and errored (failed) — two different routes — and always state exposure via last-known-good.
BSOD Analysis
Triage Windows blue screens by stop code and faulting module, correlating recent patches, drivers, or hardware to split driver, storage, and RAM causes.
Budget Planning Brief
Prep a client's annual IT budget conversation — hardware refresh forecast, license spend, and project pipeline — from tickets, assets, and roadmap items.
Client-Facing Device Report
Produce a sanitized device inventory and health report a client contact can read — counts, health, risks in plain business language, no raw tool output.
Conference Room AV
Keep Teams/Zoom Rooms working — room-system health, calendar and resource-mailbox checks, and a pre-meeting checklist for high-stakes boardroom events.
Cyber Insurance Form Prep
Draft cyber-insurance application answers from ticket, RMM, and posture evidence, cite each source, and mark every unverifiable answer for human review.
Datto BCDR Verification
Work Datto BCDR alerts: screenshot-verification failures, local vs cloud sync lag, virtualization tests. Separate backup-ran from backup-boots and verify.
Device Approval Review
Work the RMM pending-device approval queue — sort expected onboarding or replacement agents from unexpected ones, approving or rejecting with rationale.
Device Health Check
Diagnose one device via the RMM — alerts, activities, services, disk, reboot, and patch posture — then propose remediation with a deep-link handoff.
Device Offline Runbook
Work a device-offline alert or "won't connect" ticket — site-wide check first, maintenance windows, last activities, and clear escalate criteria.
Device-to-User Mapping
Answer "who uses this device" by combining RMM last-logged-on data with contact records, ticket history, and documentation when a ticket names only one.
Disk Space Alert
Triage a low-disk-space alert from any monitor — separate threshold noise from real pressure, read growth rate from history, rank consumer hypotheses.
Disk Space Remediation
Work a disk-pressure alert or full-drive ticket — identify likely consumers from RMM signals and give the tech a safe cleanup sequence with a device link.
EDR Detection Runbook
Work an EDR malware or suspicious-process alert: pull RMM device context, check EDR containment, confirm with the user, then escalate or close.
Endpoint Encryption Audit
Audit disk-encryption coverage on Windows BitLocker and Mac FileVault, flag unencrypted endpoints, and verify recovery keys are escrowed and retrievable.
Fleet Health Sweep
Sweep a client fleet through the RMM — offline devices, alert clusters, disk pressure, and missing patches — ranked into the top issues needing attention.
Hardware Diagnostics
Work desktop and laptop hardware faults — no-boot, random shutdowns, disk noises, battery and thermal — through POST stages, SMART, and warranty routing.
Hardware Refresh Forecast
Build a 4–5 year hardware refresh workbook per client — devices crossing the age threshold each period and the per-client refresh budget for planning.
High CPU/Memory Alert
Triage a CPU or memory threshold alert — separate a transient spike from sustained pressure via history, and route servers versus workstations differently.
Huntress EDR Incident
Work Huntress EDR incident reports: foothold, persistence, or active endpoint threats. Read what Huntress isolated, finish remediation, and verify closure.
Hypervisor Alert Triage
Triage Hyper-V and VMware host alerts — datastore capacity, snapshot sprawl, CPU/memory pressure — deciding if the issue is host-level or VM-level first.
Intune vs RMM Reconciliation
Reconcile an Intune-enrolled device list against RMM agent inventory — find machines missing an RMM agent, missing Intune, or double-managed conflicts.
IT Roadmap Builder
Draft a client IT roadmap from their ticket history plus asset and posture data — what to fix, upgrade, and invest in, organized into investment tiers.
License Billing Reconciliation
Reconcile a client's billing against reality — RMM devices, license export, onboarding tickets — to find missed adds, missed removals, and discrepancies.
Mac Fleet Management
Review Macs under RMM — agent health, macOS version and update posture, disk and encryption basics, and awareness of a separate MDM owning updates.
Maintenance Mode Workflow
Put a device into or out of RMM maintenance mode with an explicit duration and reason, plus a follow-up task so monitoring is re-enabled on schedule.
MDR Client Onboarding
Onboard a client to a new MDR or SOC service: scope assets, wire alert routing into the desk, record escalation contacts, and set noise expectations.
Mobile Fleet Review
Review phones and tablets under MDM — enrollment, OS version spread, compliance flags, and readiness to lock or wipe a lost or stolen device.
NAS / File Share Provisioning
Plan and document a new network share — folder structure, permission model, quota, backup inclusion — with an approval gate on the access model first.
Network Device Inventory
Refresh a client network device inventory — switches, APs, firewalls, routers per site — by combining documentation with what monitoring actually sees.
Network Outage Triage
Triage a suspected site-down — all-devices-offline vs single dead device, ISP vs internal, who to call, and set a comms cadence for the client updates.
New Workstation Imaging Checklist
Run the standard build-and-deploy checklist for a new or re-imaged workstation — naming, OS baseline, enrollment, apps, profile, verification, and handoff.
NinjaOne Alert Types
Classify NinjaOne condition and threshold alerts (offline, resource, service, patch, hardware, security) and route each class with a deep-link handoff.
NinjaOne Device Lookup from a Ticket
Figure out which device a ticket is about — from the person, their remembered devices, or a hostname in the thread — find it in NinjaOne, and drop the live device details and a deep link into the ticket so the tech starts with context.
Patch Compliance Review
Report patch status for one device or a whole fleet — missing, failed, and pending patches — via ConnectWise RMM, Liongard, or NinjaOne alerts as fallback.
Patch Failure Alert
Triage a patch-failure alert — separate a one-off from a repeat offender, detect reboot-pending as the usual culprit, correlate against the patch window.
Print Server Management
Operate a print server layer — spooler triage, disciplined driver deployment (no ad-hoc installs), and planning queue migrations to a new print server.
Printer Fleet Review
Cluster a client printer-related tickets to find chronic devices, quantify the time they burn, and recommend replace-vs-repair per problem printer.
QBR & SBR Prep
Prepare an internal brief before a quarterly or strategic business review — trends, recurring issues, sentiment, opportunities, agenda, likely questions.
RAID Degradation Alert
Triage a RAID degraded or failed-member alert with zero-margin urgency — one failure from data loss — and enforce the verify-backups-BEFORE-rebuild rule.
Ransomware Response
Respond to suspected or confirmed ransomware: isolate hosts, verify backups before touching them, engage IR and insurance, and sequence recovery.
Reboot Request Workflow
Reboot a device via the RMM with user approval — confirm logoff or saved work, choose normal vs forced deliberately, and verify the device comes back up.
Recurring Maintenance Tickets
Verify scheduled maintenance tickets (backup checks, patch cycles, monthly server reviews) carry real completion evidence and flag skipped cycles fast.
RMM Cross-Tool Reconciliation
Reconcile device lists across RMM, EDR, backup, and documentation — find missing agents, single-tool orphans, and count mismatches that distort billing.
SD-WAN / Multi-Circuit Monitoring
Review a multi-circuit or SD-WAN site — confirm each circuit is up, failover works, and open the right ISP escalation when a link is down or degraded.
Seat Count True-Up
Monthly true-up for per-seat and per-device agreements — compare actual counts from RMM and onboarding tickets against billing, and produce evidence.
Security Onboarding New Client
Run a new-client security intake: MFA coverage, admin inventory, backup posture, EDR presence, and produce the day-one risk list before an incident.
SentinelOne Ranger
Work SentinelOne Ranger network-discovery findings: read the rogue or unmanaged-device signal and drive to identify-then-manage without blind action.
SentinelOne Threat Verdict
Triage SentinelOne threat detections: read static vs behavioral engine verdicts, direct kill, quarantine, rollback, and hold on exclusion requests.
Server Decommission Runbook
Safely retire a server — map dependencies, migrate data, clean up DNS, monitoring, backup, wipe, and update docs, with an approval gate before destruction.
Server Diagnostics
Deep single-server review — services, activities, alert history, role inference, and change correlation via Liongard detections when the tenant is on.
Server Patch Windows
Plan and verify per-client server patching — map each server to its maintenance window, sequence reboots correctly, and run post-patch verification passes.
Service Restart Runbook
Restart a crashed Windows service via the RMM — allowlisted safe services only, state verified before and after, with a ticket note posted on completion.
Slow Computer
Triage a slow-computer ticket via resource hogs, disk health, startup load, and profile weight, ending with reimage or replace decision criteria.
Sophos Endpoint Alerts
Triage Sophos Central endpoint alerts: read health status and cleanup result, handle tamper protection correctly, and verify cleanup before closing.
Storage Capacity Planning
Turn repeated disk-space alerts into a trend-based capacity forecast per server or NAS — growth rate, projected full date, and expansion options to price.
Ticket Research Copilot
Read-only research sweep for an in-progress ticket: similar resolved tickets, KB, IT Glue and Hudu docs, and live RMM device state as a cited brief.
Veeam Job Failures
Diagnose Veeam backup job failures: classify by taxonomy (VSS, credentials, repository, network), apply retry discipline, and state the last restore point.
Vulnerability Report Triage
Triage a CVE, vendor advisory, or researcher disclosure: assess severity vs exploitability, check affected assets, and plan patch or mitigation steps.
Warranty and EOL Report
Build an aging-fleet report for a client — end-of-life operating systems, old hardware, and warranty status where a source exposes it, for lifecycle risk.
Warranty Claim Handling
When a device fails and you need to know whether it's under warranty, how to file the claim, and how to arrange a loaner while it's away.
WatchGuard Firewall Alerts
Triage WatchGuard events: Firebox offline in WatchGuard Cloud, AuthPoint MFA push and token trouble, and mobile VPN authentication failures on the desk.
Webroot Legacy AV
Work Webroot or other legacy signature-AV detections with thin telemetry, and frame the modern-EDR migration conversation on facts, not fear.
WiFi Heatmap / Site Survey Request
Decide when a wireless problem warrants a heatmap or site survey, and capture the site information needed to commission one without a return visit.
WiFi Infrastructure Audit
Audit a wireless estate — AP inventory per site, coverage complaints from ticket history, firmware posture, and a guest-network isolation check per client.
Windows 11 Readiness Assessment
Assess which client devices can upgrade to Windows 11 — CPU generation, TPM, RAM, and edition flags from RMM device details — with an upgrade-blocker list.
Windows Profile Corruption
Fix Windows profile corruption and temporary-profile logons: confirm via profile-service event IDs, choose repair vs rebuild, and preserve user data first.
Zero-Day Emergency Response
Coordinate an emergency response to an actively exploited zero-day: count each client's exposure, apply mitigations, and communicate the same night.
Was this page helpful?
⌘I