Nerdio Manager for MSP (Beta)
Quick DetailsRecommended Agent: On-Demand
Supported Agents: On-Demand and Self-Managed
Is Auto-Discovered By: N/A
Can Auto-Discover: Nerdio Manager for MSP Child Inspectors (one per managed Customer account)
Parent/Child Type Inspector: Yes
Inspected via: API
Default Frequency: Daily. (max every 8 hours)
Data Summary: Nerdio Manager for MSP Inspector Summary
Overview
Nerdio Manager for MSP Inspector (Beta)
Nerdio Manager for MSP (NMM) is a cloud management platform built for MSPs running Azure Virtual Desktop (AVD) and Windows 365 at scale, giving Partners centralized provisioning, autoscaling, image management, and session monitoring across many Customer Azure tenants from a single control plane. The Nerdio Manager for MSP Inspector (Beta) connects to a Partner's NMM installation and surfaces every managed Customer account's AVD workspaces, host pools, session hosts, active sessions, desktop images, autoscale profiles, and backup posture back into Liongard — so configuration drift, stale images, and backup gaps show up without logging into NMM per Customer.
What you can monitor
The Nerdio Manager for MSP Inspector collects AVD configuration, session, and backup data for each managed Customer, including:
- AVD workspaces, host pools, and session host inventory per Customer
- Active user sessions (UPN, application type, session state)
- Desktop image inventory and last-activity change-log enrichment
- Autoscale profile configuration, both MSP-global and Customer-scoped
- Backup-protected items and Azure recovery vaults per Customer
- NMM control-plane platform health (app service, web job, and database status)
How it works
A parent launchpoint authenticates once to the Partner's NMM installation and enumerates every managed Customer account. Liongard creates a child launchpoint for each account, mapped one-to-one to that Customer's Liongard Environment, so AVD configuration and backup posture are tracked independently per Customer.
Benefits
- Catch AVD configuration drift — autoscale settings, load balancer type, session limits — per Customer.
- Surface backup-protected items and recovery vaults for compliance reporting without opening NMM.
- Roll up NMM platform health across the Partner's entire installation.
- Spot host pool or session host count drops from decommissioning or deletion.
- Identify Customers running stale desktop images via the change-log enrichment.
This Inspector ships 16 out-of-the-box metrics (6 Parent / 10 Child) and 9 change-detection rules. All 9 rules ship disabled by default — enable the ones you want per Customer.
Inspector Setup Preparation
Prerequisites & Access RequirementsTo configure the Nerdio Manager for MSP Inspector, ensure you have the following:
- Admin access to the Partner's NMM installation
- Ability to enable the REST API and grant Microsoft Entra ID admin consent in Azure
- Access to the Azure tenant hosting the Partner's NMM Azure app registration
Inspector Setup:
Step 1: Enable the REST API and Create Credentials in NMM
- Sign in to NMM as an admin.
- Navigate to Settings → Integrations → REST API.
- If the API status is Disabled, select Enable. NMM creates an Azure app registration in your tenant.
- Select Grant to grant admin consent in the Azure portal.
- Select Generate to create the client secret, and copy the value immediately — it is shown only once.
- Note the Tenant ID, Client ID, and API Scope, all visible in the Credentials dialog.
Step 2: Configure the Nerdio Manager for MSP Inspector in Liongard
- Log in to the Liongard platform.
- In Liongard, navigate to Admin > Inspectors > Inspector Types > Navigate to the Nerdio Manager for MSP Inspector > Select Add System.
Since NMM is a multi-tenant system where a single installation manages many Customer accounts, you'll set up a single "Parent" Inspector that will then auto-discover a "Child" Inspector for each Customer account.
Fill in the following information:
- Type of Inspector: Parent
- Environment: Select your MSP's Environment
- Friendly Name: Suggested Naming: [MSP Name] Nerdio Manager for MSP Parent
- Agent: Select the On-Demand Agent
- Inspector Version: Latest
- NMM Instance URL: The Partner's NMM portal URL
- Azure Tenant ID: The Entra ID tenant ID, from Step 1
- API Client ID: The Application (Client) ID, from Step 1
- API Client Secret: The client secret generated in Step 1
- API Scope: The API Scope from Step 1 (
api://{application-id}/.default) - Azure Cloud Environment: Leave at the
AzureClouddefault, or selectAzureUSGovernmentonly if NMM runs in Gov / GCC-High - Scheduling: The Inspector will default to run once a day at the time it's set up. Here you can adjust the schedule
- Select Save. The Inspector will now be triggered to run within the minute.
Step 3: Child Inspector Setup
After the first run of the Parent Inspector, each managed Customer account will be auto-discovered and surfaced in the Discovered Systems tab on the Inspectors > Nerdio Manager for MSP Inspector page. Each account is matched to a Liongard Environment by its NMM account name, and appears with the alias Nerdio - [Account Name] — if a Customer lands in the wrong Environment, check for a name mismatch there first. Unlike some other multi-tenant Inspectors, no account is ever skipped: every account NMM returns becomes a child.
- Activate or Archive your Discovered Systems by ensuring they're mapped to the correct Environment > Check the checkbox to the left of Inspector(s) > Select the Actions drop-down menu > Activate Launchpoints (or Archive Launchpoints).
- Click Save.
Troubleshooting
- Parent returns zero accounts: The API client lacks scope on the NMM installation, or the API isn't enabled in NMM. Re-check Settings → Integrations → REST API.
- 401 from Entra ID at parent launch: The client secret is wrong or expired — NMM rotates the secret each time Generate is used. Regenerate it in NMM and re-paste it into Liongard.
- Empty Protected Items or Recovery Vaults tabs on a child: The Customer has no backup resources, or the API role lacks read permission for backup objects. This is tolerated silently — the child run does not fail.
- Child runs slow on Customers with many host pools: Host pool fan-out is the dominant cost. The Inspector caps concurrency at 4 and rate-limits to 5 requests/second — for very large Customers, extend the collection interval.
- Gov Cloud Customers: Set Azure Cloud Environment to
AzureUSGovernmentso the Inspector uses thelogin.microsoftonline.usEntra ID endpoint.
Known V1 LimitationsNo Cloud PCs / Intune-managed devices view — the v1-beta
/devicesendpoint's field schema falls outside the vendor-supplied OpenAPI spec and is planned for v1.1. No user listing — NMM's only paginated endpoint is not needed for v1. No Scripted Actions, Unified App Management, Secure Variables, Schedules, or Reservations — these are operational configuration, not asset state. No Distributor API — that's a separate, billing-focused API with its own key-based auth. No vulnerability or Secure Score enrichment — planned for v2.
Updated about 3 hours ago

