Provider Capabilities
This catalog describes the user-facing operations implemented by the current MSPControl provider set. It consolidates duplicate Core and legacy assemblies into one public product entry and omits providers that did not pass the current source and lifecycle review.
Provider availability still depends on the modules, plan limits, provider configuration, credentials, permissions, and third-party licenses in your deployment.
Platform prerequisites
Software required to host the MSPControl platform itself.
Windows ServerHosts the MSPControl Portal, Enterprise Server, Server, and Scheduler components.Prerequisite
Supported scope
Windows Server 2016, 2019, 2022, and 2025; any edition; x64 only.
What MSPControl can do
- Host MSPControl server components on a new or existing Windows Server.
- Use Windows Server roles and services required by the selected MSPControl components.
Requirements and limitations
- Application Initialization must not be installed.
- All MSPControl components in one deployment must use the same build.
Related documentation
Last compatibility review: Review mode: explicit version
Internet Information Services (IIS)Hosts the web-facing MSPControl components and ASP.NET Core Module.Prerequisite
Supported scope
The IIS version included with a supported Windows Server release.
What MSPControl can do
- Host MSPControl web applications.
- Terminate HTTPS by using an IIS certificate and binding.
Requirements and limitations
- Required IIS role services must be enabled.
- Application Initialization must not be installed.
Related documentation
Last compatibility review: Review mode: explicit version
SQL Server (platform database)Stores the shared MSPControl configuration and operational database.Prerequisite
Supported scope
SQL Server 2016 SP2 or later; any edition, including Express. SQL Server 2022 requires CU17 or later.
What MSPControl can do
- Store the single MSPControl platform database.
- Use SQL authentication, the required case-insensitive collation, and TCP connectivity.
Requirements and limitations
- Apply current service packs, cumulative updates, and security updates.
- Database sizing and licensing remain the operator’s responsibility.
Related documentation
Last compatibility review: Review mode: explicit version
Microsoft cloud
Tenant, identity, Azure, device, collaboration, and security administration.
Microsoft 365Centralizes customer-tenant administration, subscriptions, reporting, and service health.Managed service
Supported scope
Current Microsoft 365 cloud services exposed through supported Microsoft APIs.
What MSPControl can do
- Provision and synchronize users and groups.
- Assign and remove licenses and service plans.
- Review subscriptions, service health, reports, and tenant configuration.
Requirements and limitations
- Available actions depend on configured permissions, licensing, and the customer tenant.
- Workloads with their own public entry have additional scope and limitations.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Microsoft Entra IDManages identity, access, roles, applications, risky users, and tenant security data.Managed service
Supported scope
Current Microsoft Entra ID capabilities exposed through Microsoft Graph.
What MSPControl can do
- Provision, update, suspend, and delete users and groups.
- Manage domains, roles, app registrations, consent, and access assignments.
- Review risky users, audit information, and identity-security configuration.
Requirements and limitations
- Administrative actions require the corresponding Microsoft permissions and tenant consent.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Microsoft AzureSurfaces Azure subscriptions, resources, spend, monitoring, recommendations, and backup information.Managed service
Supported scope
Current Azure Resource Manager, Cost Management, Monitor, Advisor, and related service APIs used by MSPControl.
What MSPControl can do
- Discover subscriptions, resource groups, and supported Azure resources.
- Report cost, utilization, margin, and forecast data.
- Review Azure Monitor, Log Analytics, Advisor, Recovery Services, and backup data.
Requirements and limitations
- Resource coverage depends on the Azure APIs and permissions configured for each tenant.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Exchange OnlineManages mailboxes, recipients, permissions, mail flow, retention, and storage settings.Managed service
Supported scope
Current Exchange Online service operations exposed by MSPControl.
What MSPControl can do
- Provision and configure mailboxes and recipients.
- Assign mailbox permissions and configure rules, transport, and journaling.
- Review storage and configure retention and mailbox experience settings.
Requirements and limitations
- Features depend on Microsoft 365 licensing, role assignments, and Exchange Online availability.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Microsoft TeamsSupports selected Teams configuration and reporting within Microsoft 365 administration.Managed service
Supported scope
Teams settings and Microsoft 365 group-backed operations exposed by MSPControl.
What MSPControl can do
- Configure supported Teams-related tenant and policy settings.
- Manage group-backed collaboration objects exposed by MSPControl.
Requirements and limitations
- MSPControl does not expose every Teams administration surface.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Microsoft OneDriveReports OneDrive ownership, allocation, usage, and recent activity.Managed service
Supported scope
OneDrive for Business storage data exposed by Microsoft 365 APIs.
What MSPControl can do
- Report OneDrive storage allocation and consumption.
- Identify owners, site links, and recently modified content indicators.
Requirements and limitations
- The current surface is focused on visibility and reporting rather than file-content management.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Microsoft IntuneManages enrolled devices, configuration, compliance, applications, updates, and enrollment profiles.Managed service
Supported scope
Current Microsoft Graph device-management APIs used by MSPControl.
What MSPControl can do
- Synchronize and report managed devices.
- Create and assign configuration and compliance profiles.
- Manage applications, update rings, Enrollment Status Page settings, and Autopilot profiles.
Requirements and limitations
- Supported settings vary by platform and by the Microsoft Graph device-management API.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Microsoft Defender for EndpointSurfaces device security health, incidents, recommendations, vulnerabilities, and onboarding state.Managed service
Supported scope
Current Microsoft Defender for Endpoint APIs used by MSPControl.
What MSPControl can do
- Monitor device health and security incidents.
- Review security recommendations and vulnerabilities.
- Generate and apply supported onboarding or offboarding packages.
Requirements and limitations
- Requires Defender for Endpoint licensing and permissions.
- Remediation remains limited to operations explicitly exposed by MSPControl.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Microsoft Defender for CloudReports Azure security posture and configures selected Defender for Cloud settings.Managed service
Supported scope
Azure security plans, secure-score data, and security contacts exposed by MSPControl.
What MSPControl can do
- Review secure-score and security-plan data.
- Configure supported security contacts and plan settings.
Requirements and limitations
- This is separate from Defender for Endpoint device protection.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Windows provisioning packagesBuilds Windows provisioning artifacts used by supported device enrollment and migration workflows.Managed service
Supported scope
Windows provisioning-package workflows exposed by the current Core provider.
What MSPControl can do
- Generate provisioning packages for supported Windows device workflows.
- Use package output with supported enrollment or tenant-migration processes.
Requirements and limitations
- Package behavior depends on Windows edition, policy, and the selected workflow.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
MSPControl native platform
Capabilities delivered directly by MSPControl and its Windows endpoint agent.
Hosted OrganizationsProvides the customer, organization, user, domain, plan, and resource hierarchy used by MSPControl.Native capability
Supported scope
Current MSPControl organization and hosting-space model.
What MSPControl can do
- Provision customer organizations and hosting spaces.
- Assign users, domains, plans, quotas, and service resources.
- Suspend, restore, move, and report supported organization services.
Requirements and limitations
- Available service items depend on installed providers and plan quotas.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
MSPControl Autopilot (Windows Agent)Connects Windows endpoints for inventory, monitoring, policy, automation, patching, and remote operations.Native capability
Supported scope
Current MSPControl Autopilot package on supported Windows 10 and Windows 11 releases.
What MSPControl can do
- Register devices and report hardware, software, network, health, security, and user inventory.
- Apply device settings, firewall and update policies, software actions, and local-user commands.
- Run supported reboot, rename, update, cleanup, reporting, and remote-access workflows.
Requirements and limitations
- Use a current agent build to receive compatibility and security fixes.
- Some operations require Intune, Defender, ScreenConnect, Veeam, or other separately configured services.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Web, database, and storage
Services MSPControl can provision and administer for customers.
IIS Web HostingProvisions websites, application pools, bindings, virtual directories, security, and certificates.Managed service
Supported scope
IIS sites managed by the current MSPControl Core web provider.
What MSPControl can do
- Create, update, start, stop, and delete websites and application pools.
- Manage bindings, virtual directories, permissions, secured folders, users, and groups.
- Configure certificates, Let’s Encrypt, HSTS, URL Rewrite, PHP, WordPress, and IP restrictions.
Requirements and limitations
- This managed-service provider is separate from IIS as an MSPControl runtime prerequisite.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
SQL Server databasesProvisions customer databases, users, access assignments, backups, and restores.Managed service
Supported scope
SQL Server instances configured as customer database providers.
What MSPControl can do
- Create, update, delete, and report databases.
- Create users, reset passwords, configure hosts, and assign database access.
- Run supported backup, restore, truncate, connectivity, and query operations.
Requirements and limitations
- This managed-service provider is separate from the SQL Server instance that stores MSPControl itself.
Related documentation
Last compatibility review: Review mode: explicit version
MySQL databasesProvisions MySQL databases, users, access assignments, backups, and restores.Managed service
Supported scope
MySQL instances compatible with the current MSPControl Core database provider.
What MSPControl can do
- Create, update, delete, and report databases.
- Create users, reset passwords, configure hosts, and assign database access.
- Run supported backup, restore, connectivity, and query operations.
Requirements and limitations
- Validate the intended MySQL release and authentication mode before production deployment.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
MSPControl Cloud FoldersProvisions customer file areas, WebDAV access, drive maps, permissions, and usage reporting.Native capability
Supported scope
Current MSPControl Cloud Folders provider on Windows file services and WebDAV.
What MSPControl can do
- Create and move supported cloud-folder service items.
- Configure WebDAV folder rules and virtual directories.
- Report folder usage and manage personal and shared folder workflows.
Requirements and limitations
- Requires the corresponding Windows file-service and WebDAV configuration.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Windows Storage SpacesManages supported storage pools, tiers, virtual disks, volumes, and related capacity data.Managed service
Supported scope
Windows Server Storage Spaces providers included with the current Core solution.
What MSPControl can do
- Discover and report storage pools, tiers, disks, volumes, and capacity.
- Create and manage supported virtual disks and volumes.
- Expose performance and cluster-resource information used by MSPControl.
Requirements and limitations
- Supported operations depend on Windows Server storage topology and provider version.
Related documentation
Last compatibility review: Review mode: explicit version
DNS
Authoritative DNS zones and record-management providers.
Azure DNSManages azure DNS zones and record sets.Managed service
Supported scope
Azure DNS zones and record sets.
What MSPControl can do
- Create, update, list, and delete supported DNS zones.
- Create, export, update, and delete supported DNS records.
- Manage SOA data and supported primary or secondary zone settings.
Requirements and limitations
- Available record types and secondary-zone behavior depend on the selected DNS provider.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Cloudflare DNSManages cloudflare zones and DNS records through the Cloudflare API.Managed service
Supported scope
Cloudflare zones and DNS records through the Cloudflare API.
What MSPControl can do
- Create, update, list, and delete supported DNS zones.
- Create, export, update, and delete supported DNS records.
- Manage SOA data and supported primary or secondary zone settings.
Requirements and limitations
- Available record types and secondary-zone behavior depend on the selected DNS provider.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Microsoft DNS ServerManages windows DNS zones and records.Managed service
Supported scope
Windows DNS zones and records.
What MSPControl can do
- Create, update, list, and delete supported DNS zones.
- Create, export, update, and delete supported DNS records.
- Manage SOA data and supported primary or secondary zone settings.
Requirements and limitations
- Available record types and secondary-zone behavior depend on the selected DNS provider.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
PowerDNS Authoritative ServerManages authoritative zones and records through the PowerDNS API.Managed service
Supported scope
Authoritative zones and records through the PowerDNS API.
What MSPControl can do
- Create, update, list, and delete supported DNS zones.
- Create, export, update, and delete supported DNS records.
- Manage SOA data and supported primary or secondary zone settings.
Requirements and limitations
- Available record types and secondary-zone behavior depend on the selected DNS provider.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Simple DNS PlusManages dNS zones and records through the Simple DNS Plus HTTP API.Managed service
Supported scope
DNS zones and records through the Simple DNS Plus HTTP API.
What MSPControl can do
- Create, update, list, and delete supported DNS zones.
- Create, export, update, and delete supported DNS records.
- Manage SOA data and supported primary or secondary zone settings.
Requirements and limitations
- Available record types and secondary-zone behavior depend on the selected DNS provider.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Hosted mail platforms and on-premises Exchange administration.
MailEnableProvisions hosted mail domains, mailboxes, aliases, groups, and distribution lists.Managed service
Supported scope
Current vendor-supported MailEnable releases compatible with the MSPControl Core provider.
What MSPControl can do
- Create and manage post offices, domains, and mailboxes.
- Manage aliases, groups, lists, address maps, quotas, passwords, and mailbox options.
- Report mailbox and domain configuration exposed by MSPControl.
Requirements and limitations
- Validate the selected MailEnable edition and release in a non-production environment.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
SmarterMailProvisions SmarterMail domains, users, aliases, groups, lists, policies, and DKIM settings.Managed service
Supported scope
Current vendor-supported SmarterMail releases supported by the current Core provider.
What MSPControl can do
- Create and manage domains, mailboxes, aliases, groups, and mailing lists.
- Configure quotas, throttling, sharing, feature permissions, and domain options.
- Configure DKIM and report supported domain or account statistics.
Requirements and limitations
- Provider behavior varies across SmarterMail API generations; validate the intended release before production use.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Hosted Exchange ServerProvisions on-premises Exchange organizations, mailboxes, recipients, policies, permissions, and mail flow.Managed service
Supported scope
Exchange Server 2013, 2016, 2019, and Subscription Edition, retained as an explicit product-owner compatibility exception.
What MSPControl can do
- Provision organizations, accepted domains, mailboxes, contacts, distribution lists, and public folders.
- Manage permissions, mailbox plans, ActiveSync, retention, storage, archiving, and recipient settings.
- Configure supported transport, journaling, disclaimer, signature, and mail-flow rules.
Requirements and limitations
- Exchange Server 2013, 2016, and 2019 are outside Microsoft support; use is an MSPControl owner exception, not a Microsoft lifecycle extension.
- Keep the underlying Exchange environment patched and validate any legacy deployment before changes.
Related documentation
Last compatibility review: Review mode: owner exception
FTP
FTP sites and account-management providers.
IIS FTPProvisions IIS FTP FTP sites and user accounts.Managed service
Supported scope
IIS FTP sites and accounts supported by the current Core FTP provider.
What MSPControl can do
- Create, update, start, stop, list, and delete FTP sites.
- Create, update, disable, list, and delete FTP accounts.
Requirements and limitations
- Authentication, encryption, and filesystem behavior depend on the selected FTP server and its local configuration.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
FileZilla ServerProvisions FileZilla Server FTP sites and user accounts.Managed service
Supported scope
FileZilla Server sites and accounts supported by the current Core FTP provider.
What MSPControl can do
- Create, update, start, stop, list, and delete FTP sites.
- Create, update, disable, list, and delete FTP accounts.
Requirements and limitations
- Authentication, encryption, and filesystem behavior depend on the selected FTP server and its local configuration.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Serv-UProvisions Serv-U FTP sites and user accounts.Managed service
Supported scope
Serv-U sites and accounts supported by the current Core FTP provider.
What MSPControl can do
- Create, update, start, stop, list, and delete FTP sites.
- Create, update, disable, list, and delete FTP accounts.
Requirements and limitations
- Authentication, encryption, and filesystem behavior depend on the selected FTP server and its local configuration.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Infrastructure
Virtualization, Remote Desktop Services, and update infrastructure.
Microsoft Hyper-VProvisions and operates virtual machines, storage, networking, checkpoints, and replication.Managed service
Supported scope
Hyper-V on Windows Server 2016, 2019, 2022, and 2025.
What MSPControl can do
- Create, update, rename, export, start, stop, pause, resume, and delete virtual machines.
- Manage CPU, memory, disks, virtual switches, network adapters, DVD media, and VHD files.
- Create and manage checkpoints, replication, metrics, and supported SCVMM operations.
Requirements and limitations
- Available operations depend on host version, cluster topology, and configured virtualization provider.
Related documentation
Last compatibility review: Review mode: explicit version
Remote Desktop ServicesManages RDS collections, session hosts, users, applications, sessions, profiles, and certificates.Managed service
Supported scope
Remote Desktop Services on supported Windows Server releases.
What MSPControl can do
- Create and configure collections, session hosts, users, and RemoteApp applications.
- Monitor sessions and run supported logoff, restart, or shutdown operations.
- Manage profiles, certificates, Group Policy settings, and application deployment through Chocolatey.
Requirements and limitations
- Requires a correctly licensed and configured RDS environment.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Windows Server Update Services (WSUS)Synchronizes device groups and supports Windows update administration and reporting.Managed service
Supported scope
WSUS integration delivered by the current Core provider and Windows Agent workflows.
What MSPControl can do
- Synchronize MSPControl Autopilot organizations and computer groups with WSUS.
- Expose supported update, group, and device information to MSPControl workflows.
Requirements and limitations
- Microsoft has deprecated WSUS features but continues to support the existing role; plan future update-management strategy accordingly.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
Security, statistics, and voice
Email protection, web analytics, statistics, and PBX administration.
SpamExperts / N-able Mail AssureProvisions protected domains, users, destinations, aliases, contacts, reports, and access tickets.Managed service
Supported scope
SpamExperts-compatible API used by the current Core email-security provider.
What MSPControl can do
- Add and remove protected domains and recipients.
- Configure delivery destinations, aliases, passwords, and domain contacts.
- Manage recipient protection reports and generate supported authentication tickets.
Requirements and limitations
- Product naming and subscription availability depend on the N-able service in use.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
AWStatsCreates and maintains web-log statistics sites for hosted websites.Managed service
Supported scope
AWStats 8.0 with the current Core provider.
What MSPControl can do
- Provision and remove AWStats service items.
- Generate and expose supported website log statistics.
Requirements and limitations
- The AWStats project announced a maintenance transition; prefer Matomo for new analytics deployments where appropriate.
Related documentation
Last compatibility review: Review mode: explicit version
MatomoProvisions analytics sites, users, access assignments, and authentication tokens.Managed service
Supported scope
Current Matomo releases compatible with the Matomo HTTP API used by MSPControl.
What MSPControl can do
- Create, update, list, and delete analytics sites.
- Create and delete users and assign or revoke site access.
- Generate supported authentication tokens.
Requirements and limitations
- Requires a reachable Matomo instance and API credentials with suitable permissions.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
SmarterStatsProvisions statistics servers, sites, users, log locations, and access settings.Managed service
Supported scope
Current vendor-supported SmarterStats releases compatible with the Core provider.
What MSPControl can do
- Create, update, move, list, and delete statistics sites.
- Create and manage users, site ownership, log locations, and requested settings.
- Validate logins and expose supported statistics-site information.
Requirements and limitations
- API behavior differs by SmarterStats generation; validate the intended release.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
MiRTA PBXProvisions tenants and manages selected extensions, DIDs, destinations, comments, and Teams credentials.Managed service
Supported scope
MiRTA PBX APIs used by the current Core PBX provider.
What MSPControl can do
- Create, update, list, and delete PBX tenants.
- List, rename, and delete supported extensions.
- Inspect DIDs and destinations, update DID comments, and synchronize supported Teams credentials.
Requirements and limitations
- The current MSPControl provider exposes a subset of the full MiRTA PBX API.
Last compatibility review: Review mode: evergreen API/protocol
Integrations and deployment tools
External systems connected to MSPControl workflows and reporting.
Veeam backup reportingSynchronizes backup jobs, sessions, object results, storage, restore-point, and reporting data.Integration
Supported scope
Veeam and Veeam Backup for Microsoft 365 reporting surfaces implemented by MSPControl.
What MSPControl can do
- Monitor backup jobs, sessions, states, storage, and copy history.
- Inspect backup objects and restore-point data exposed by MSPControl.
- Generate reports and notifications, including Microsoft 365 backup reporting.
Requirements and limitations
- The documented integration is monitoring and reporting; it does not claim that MSPControl performs a Veeam restore.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
ConnectWise PSAConnects service tickets, companies, members, boards, scheduling, SLA analytics, sentiment, and Service Watch.Integration
Supported scope
ConnectWise PSA service-management data and API workflows implemented by MSPControl.
What MSPControl can do
- Synchronize supported tickets, comments, status, schedule, escalation, attachments, companies, members, and boards.
- Report SLA, ticket-volume, member, and client metrics and export supported detail.
- Surface SmileBack, sentiment, and Service Watch follow-up analytics when configured.
Requirements and limitations
- Feature availability depends on ConnectWise PSA permissions, configured boards, mappings, and optional integrations.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol
WHMCSAutomates MSPControl account lifecycle and exposes supported client-area and sign-on workflows.Integration
Supported scope
MSPControl WHMCS Module 3.0.7. No official WHMCS/PHP version matrix has been published.
What MSPControl can do
- Create, terminate, suspend, and unsuspend MSPControl services.
- Change passwords, change packages, and report supported usage.
- Expose supported single sign-on and client-area functions.
Requirements and limitations
- Test the module with your WHMCS version in a non-production environment before deployment.
Related documentation
Last compatibility review: Review mode: explicit version
ChocolateyInstalls, updates, and removes packages in supported Windows Agent and RDS workflows.Integration
Supported scope
Chocolatey CLI workflows used by MSPControl for supported application deployment.
What MSPControl can do
- Install, update, and uninstall supported Chocolatey packages.
- Synchronize feeds and use package metadata in supported RDS and endpoint application workflows.
Requirements and limitations
- Chocolatey is a deployment tool used by MSPControl, not a hosted service managed as a customer resource.
- Package licensing, repository trust, and package behavior remain the operator’s responsibility.
Related documentation
Last compatibility review: Review mode: evergreen API/protocol