Skip to main content
Right of Boom

Our Speakers

An Uncompromising Roster of Experts.
Our speakers bring unfiltered, tactical insights forged in the crucible of real-world incident response.

Back to all speakers
Chris Plouffe

Chris Plouffe

Senior Technical Trainer

NERDIO

Sessions

Every MSP with a client on Microsoft 365 is about to have the same conversation: “Can we turn on Copilot?” The honest answer, for most tenants, is not yet — because Copilot doesn't create new exposure, it finds it. It reads everything a user can already reach, and says it out loud. This session is about the governance work that has to happen before that conversation, and the governance job MSPs are about to inherit as their clients' AI use moves from assistants that answer questions to agents that take action on their own.

Part one is the foundation: what Microsoft Purview actually controls (audit logging, data loss prevention, sensitivity labels, and retention), what's already included starting at Business Premium versus what requires E5 or the Purview Suite, and where a management platform's automation stops and an MSP's own policy judgment has to start. Attendees leave with a concrete baseline checklist (not a vendor pitch) they can run against any client tenant this week.

Part two makes the case that AI/agent governance is becoming a durable MSP service line, not just a compliance checkbox. Client tenants are already using AI tooling in some form, sanctioned or not, and someone has to own six jobs that come with it: blocking or allow-listing AI tools, tracking usage across the client base, managing the cost of that usage, enforcing security policy around it, assessing tenant AI/Copilot readiness - and as agents move from pilot to production - developing, selling, and managing agents themselves. Nerdio's own product leadership expects a meaningful share of MSP time by 2028 to be spent in exactly this: agent management, helping clients get real work done through agents acting on their behalf.

Completion earns attendees a scored AI Governance Readiness assessment of their own environment, plus a working framework for standing up AI/agent governance as a new client-facing service, positioning them ahead of a shift Nerdio's own product team expects to reshape how MSPs spend their time within the next two years.

Key Takeaways

  • A working Purview baseline checklist — audit, endpoint DLP, sensitivity labels, retention - mapped to real Microsoft licensing tiers, that attendees can run against a client tenant immediately.
  • Where automated policy enforcement ends and MSP judgment has to begin: writing DLP policies, designing a label taxonomy, and authoring retention schedules are not things a platform can do for you — and knowing that line matters for both security and liability.
  • The six jobs that make up AI/agent governance as an MSP service line: blocking or allow-listing AI tools, usage tracking, cost management, security policy enforcement, tenant AI/Copilot readiness assessment, and agent lifecycle management.
  • A practical risk model for agentic AI: permission scope, blast radius, and auditability for autonomous agents, not just human users, and why each of those problems gets 2–4x harder the moment you add tenant boundaries.

Why This Session, Why Now

  • Copilot and AI adoption is accelerating across MSP client bases heading into 2027, and most tenants carry oversharing and DLP gaps that predate AI — gaps that become active liabilities the moment AI is turned on.
  • Client tenants are already using AI tooling in some form, whether or not their MSP is the one governing it. Blocking, tracking, cost management, and policy enforcement around that usage is a gap most MSPs haven't formalized yet, and it's a sellable service the moment it is.
  • Nerdio's own product leadership expects a meaningful share of MSP time by 2028 to be spent in agent management — helping clients extract real value from agents doing work on their behalf. MSPs who build the governance muscle now will be positioned to sell it as a service later, rather than reacting to it after a client asks.