Key Takeaways
- The newly acquired platform brings MSP-focused identity threat detection and access management into BarracudaONE.
- The acquisition could help MSPs manage privileged access, authentication, and identity risks across multiple customer environments.
- Execution will depend on tenant-level visibility, practical integrations, automation, and support for phishing-resistant authentication.
Barracuda has acquired Evo Security to broaden BarracudaONE with identity and access management capabilities designed around managed service provider operations. The move extends Barracuda’s security portfolio beyond email, cloud, and centralized security management, giving MSPs another way to monitor and control identities across customer tenants.
That distinction matters. MSPs do not manage a single workforce inside one security boundary. They may oversee thousands of customer users, privileged administrators, contractors, cloud applications, and service accounts. A compromised MSP administrator account can also create risk across several customers, particularly when technicians rely on shared consoles or hold broad permissions.
Evo Security focuses on identity threat detection and response, commonly shortened to ITDR. In practical terms, ITDR can help identify suspicious authentication, unexpected privilege changes, compromised credentials, and other activity suggesting that an attacker is abusing a legitimate account. Bringing those signals into BarracudaONE could give MSP security teams a broader operational picture alongside email and cloud alerts.
Collecting more alerts is not automatically useful. MSPs will want to see whether Barracuda and the new ITDR capabilities can connect identity events with activity in email, applications, and administrative systems, then make the resulting investigation manageable across many tenants. Clear customer separation, role-based administration, policy templates, and automated remediation could matter as much as detection accuracy.
Demand for outside expertise supports Barracuda’s strategy. According to 2025 Ponemon Institute and GuidePoint Security research, while 83% of organizations have identity policies in place or under development, just 28% have integrated them into IAM platforms. That gap creates an opening for MSPs to offer identity assessments, multifactor authentication deployment, privileged-access reviews, account lifecycle management, and recurring monitoring as packaged services.
Yet MSP readiness is uneven. The CyberSmart MSP Survey 2025 found that only 39% of MSPs globally felt equipped to advise customers on cybersecurity regulations. Just 46% had a formal compliance plan for their own operations. Adding technology can help, but it does not replace documented processes, staff training, or clear responsibility for responding to identity incidents.
The addressable identity problem is growing, too. Everest Group’s 2025 IAM research highlights governance across human, privileged, machine, and emerging AI-agent identities as an important provider capability. That expansion is particularly relevant for MSPs because nonhuman accounts can accumulate quietly across cloud services, automation tools, integrations, and customer environments.
What should MSPs examine first? Tenant architecture is a sensible starting point. BarracudaONE and the acquired technology will need to preserve strict boundaries among customer data while still allowing technicians to work efficiently from centralized views. MSPs should also evaluate integration depth with existing identity directories, cloud applications, ticketing workflows, and security operations processes.
Authentication methods are another consideration. FIDO2 and WebAuthn can support phishing-resistant, passwordless access, particularly for technicians and privileged users. A 2025 MagicAuth review of phishing-resistant MFA requirements outlines the growing policy emphasis on stronger authentication rather than one-time codes that attackers may intercept or socially engineer.
The acquisition also places Barracuda in a competitive field that includes Microsoft, Huntress, and Okta. MSPs are likely to compare licensing, multitenant administration, integrations, policy automation, and the ability to generate customer-facing reports. Price will matter, naturally, but operational labor per customer may prove more consequential.
Barracuda’s broader opportunity is to make identity a native part of managed security rather than a separate project. If BarracudaONE can connect these new identity signals with email, cloud, and security-management data, MSPs could build services around continuous verification and least-privilege access. The practical test will be whether the integrated solution reduces technician workload while improving control across diverse customer environments.
⬇️