Skip to main content
45 skills in this category.

Alert Reset With Note

Reset a NinjaOne alert only after verifying the condition is genuinely healthy again, with an explanation note posted first. Use for "reset this alert" or "clear the disk alert on <device>", attended or embedded in a Flow.

Backup Failure Triage

Classify a backup-failure alert into its failure mode using alert text plus device state, check recurrence, and decide fix-here vs escalate-to-vendor. Use when a backup job failed, a backup alert lands, or someone asks "did backups run for <client>".

Certificate Inventory

Build the expiry calendar of every certificate a client depends on — public web, RDS/gateway, LOB apps, internal CA, device certs — with ownership and renewal runbook per cert. Use for "what certs does <client> have", "when does anything expire", or after an expired-cert outage.

Circuit Inventory

Build or refresh the inventory of a client's circuits — internet, WAN/MPLS/SD-WAN underlays, POTS-replacement lines — with carrier, circuit ID, account reference, site, bandwidth, and renewal dates. Use for "what circuits does <client> have", renewal planning, or when an outage reveals nobody knows the circuit ID.

Client-Facing Device Report

Produce a sanitized device inventory and health report a client contact can read — counts, health summary, and risks in business language, no internal jargon, no raw tool output. Use for "send <client> a summary of their devices" or QBR fleet slides.

Conference Room AV

Keep meeting rooms working — room-system (Teams Rooms/Zoom Rooms) health, calendar/resource-mailbox integration checks, and a pre-meeting checklist for high-stakes meetings. Use for "the boardroom screen isn't working", recurring room complaints, or "make sure the room works before the board meeting".

Device Approval Review

Work the RMM pending-device approval queue — sort expected devices (onboarding, replacements) from unexpected ones, and approve or reject each with a recorded rationale. Use for "review pending devices" or when new agents show up awaiting approval.

Device Health Check

Diagnose a single device through the RMM — alerts, activities, services, disk, reboot, and patch posture — and propose remediation with a deep-link handoff. Use when a user's workstation or server is misbehaving or someone asks "what's wrong with this machine".

Device Offline Runbook

Work a device-offline alert or "computer won't connect" ticket through a structured diagnostic — site-wide check first, maintenance windows, last activities, power/on-site guidance, and clear escalate criteria. Use when a device shows offline in the RMM or an offline alert fires.

Device-to-User Mapping

Answer "who uses this device" or "what device does this user have" by combining RMM last-logged-on data with contact records, ticket history, and documentation. Use whenever a ticket names a person but not a machine, or a machine but not a person.

Disk Space Remediation

Work a disk-pressure alert or "drive is full" ticket — establish likely consumers from RMM signals, give the tech a safe-cleanup sequence, and hand off via device deep link. Use when a low-disk alert fires or a user reports a full drive.

Endpoint Encryption Audit

Audit disk-encryption coverage across a client's endpoints — BitLocker on Windows, FileVault on Macs — flag unencrypted devices, and verify recovery keys are actually escrowed somewhere retrievable. Use for "are all their laptops encrypted", compliance evidence, or after a lost laptop raises the question.

Firewall Config Backup Audit

Verify that every firewall's current configuration is actually backed up and recent — via Liongard change history or the vendor's own backup state — and flag any device whose config backup is missing or stale. Use for "are our firewall configs backed up", before a firmware change, or a config-backup posture review.

Firewall Rule Change Request

Shepherd a firewall change request from vague ask to change-management-ready spec — business justification, exact source/destination/port/protocol, expiry for temporary rules, and routing to the approver. Use when a ticket asks to "open a port", "allow access to X", or "whitelist this vendor".

Fleet Health Sweep

Sweep an entire client's device fleet through the RMM — offline devices, alert clusters, disk pressure, missing patches — and rank the top issues that need attention. Use for "which devices at <client> need attention" or a proactive per-client health pass.

Hardware Refresh Forecast

Build a 4-5-year refresh-cycle workbook for a client — which devices cross the age threshold in each upcoming period and what the per-client refresh budget looks like. Use for "refresh forecast for <client>", budget planning, or vCIO roadmap prep.

Hypervisor Alert Triage

Triage Hyper-V/VMware host alerts — datastore/volume capacity, snapshot and checkpoint sprawl, host CPU/memory pressure — and decide whether the problem is host-level or VM-level before anyone touches anything. Use when a virtualization host alerts, guests slow together, or a datastore fills.

ImmyBot Environment Review

Review an ImmyBot tenant's computers and maintenance-session history — what ran, what failed, and which machines keep failing — read-only. Use for "did last night's ImmyBot maintenance succeed", "why didn't <software> deploy to <device>", or an ImmyBot coverage check.

Intune vs RMM Reconciliation

Reconcile a client's Intune-enrolled device list against the RMM agent inventory — find machines missing an RMM agent, machines missing Intune enrollment, and double-managed conflicts. Use for "are all Intune devices in the RMM", "why does this machine have no agent", or before an MDM/RMM policy rollout.

ISP Outage Tracking

Manage the lifecycle of a circuit outage in the carrier's hands — capture the carrier ticket reference, run the escalation clock, and keep the client informed on a cadence while waiting on the provider. Use when a site's internet/WAN is down and the ISP owns the fix.

IT Glue Asset & Contact Lookup

On demand, pull a client's IT Glue contacts, credential links, and flex-asset configs and post a plain-text summary with deep links onto the ticket — degrading to the KB or ticket history when IT Glue isn't connected. Use for "get me the IT Glue info for this client"; runs manually on demand.

Liongard Change Review

Answer "what changed in this client's environment recently" from Liongard detections and timelines, and correlate those changes with new tickets. Use when something broke after a change, before/after an incident window, or for a periodic change-awareness pass.

Mac Fleet Management

Review the Macs a client has under RMM management — agent health, macOS version and update posture, disk/encryption basics, and awareness of a separate MDM owning updates. Use when someone asks "how are the Macs looking", a Mac-specific rollout is planned, or a macOS ticket needs fleet context.

Maintenance Mode Workflow

Put a device into (or take it out of) RMM maintenance mode with an explicit duration and reason, plus a follow-up task so monitoring is re-enabled on time. Use for "silence monitoring on <device> during the migration" or "set maintenance for tonight's window".

Mobile Fleet Review

Review a client's phones and tablets under management — enrollment state, OS version spread, compliance flags, and lost-device readiness (can we lock/wipe if one goes missing). Use for "review the mobile devices", "are the phones compliant", or preparing for a lost/stolen-device scenario.

NAS / File Share Provisioning

Plan and document a new network share — folder structure, permission model, quota, and backup inclusion — with an approval gate on the access model before it's created. Use when someone asks to create a new share, set up a department folder, or provision NAS storage.

Network Device Inventory

Build or refresh the living inventory of a client's network devices — switches, access points, firewalls, routers — per site, by combining documentation with what monitoring actually sees. Use for "what network gear does <client> have", site audits, or when docs and reality have drifted.

Network Outage Triage

Triage a suspected site-down — distinguish the all-devices-offline pattern from a single dead device, split ISP from internal causes, identify who to call, and set a comms cadence. Use when multiple offline alerts fire from one client or someone reports "the whole office is down".

New Workstation Imaging Checklist

Run the standard build-and-deploy checklist for a new or re-imaged workstation — naming, OS baseline, enrollment, apps, profile, verification, and handoff. Use when someone asks to image a machine, prep a new laptop, or "get this workstation ready for <user>".

Patch Compliance Review

Report patch status for a device or a client's whole fleet — missing, failed, and pending patches — using ConnectWise RMM patch reads or Liongard metrics when enabled, degrading to NinjaOne alerts and activities otherwise. Use for "are <client>'s machines patched" or a compliance evidence pull.

Print Server Management

Operate a client's print server layer — spooler known-issue triage, driver deployment discipline (no ad-hoc driver installs), and planning queue migrations to a new server. Use when "everyone can't print", the spooler keeps dying, or print queues need to move.

Printer Fleet Review

Cluster a client's printer-related tickets to find the chronic devices, quantify the time they burn, and recommend replace vs repair per device. Use for "why do we get so many printer tickets from <client>" or a print-environment health pass.

Reboot Request Workflow

Reboot a device through the RMM with user approval — confirm the user is logged off or has saved work, choose normal vs forced deliberately, and verify the device comes back. Use for "reboot <device>", pending-reboot remediation, or "this needs a restart to finish patching".

RMM Cross-Tool Reconciliation

Reconcile a client's device lists across RMM, EDR/security, backup, and documentation — find devices missing agents, orphans in one tool only, and count mismatches that distort billing. Use for "why do NinjaOne and our docs disagree on device count" or an agent-coverage audit.

SD-WAN / Multi-Circuit Monitoring

Review a multi-circuit or SD-WAN site's connectivity — confirm each circuit is up, failover actually works, and open the right ISP escalation when a circuit is down or degraded. Use when a site has multiple WAN links, someone reports one circuit down, or you're verifying failover posture.

Server Decommission Runbook

Safely retire a server — map dependencies, migrate or confirm data, clean up DNS/records/monitoring/backup, wipe, and update documentation — with an approval gate before anything destructive. Use when someone asks to decommission, retire, or "spin down" a server.

Server Diagnostics

Deep single-server review — services, recent activities, alert history, role inference, and change correlation via Liongard detections when enabled. Use when a server is degraded, a server alert fires, or "something changed on <server>".

Server Patch Windows

Plan and verify per-client server patching — map every server to its agreed maintenance window, sequence reboots correctly (dependencies first, domain controllers last and never together), and run the post-patch verification pass. Use for "when do <client>'s servers patch", planning a patch cycle, or verifying last night's window.

Service Restart Runbook

Restart a crashed or stopped Windows service through the RMM — allowlisted safe services only, with state verified before and after and a note posted. Use for "the print spooler died on <device>" or a stopped-service alert, attended or embedded in a Flow.

Storage Capacity Planning

Turn repeated disk-space alerts into a trend-based capacity forecast per server/NAS — growth rate, projected full date, and an expansion-options brief the account team can price. Use when a device alerts on disk for the third time, or someone asks "how long until this fills up" or "what should we buy".

Switch VLAN and Port Change

Prepare a switch port or VLAN change safely — blast-radius check (what else rides that port/VLAN/uplink), agreed change window, and rollback config saved before anything is touched. Use when a ticket asks to move a port to a VLAN, add a VLAN, reconfigure a trunk, or "just change the port for the new printer".

Warranty and EOL Report

Build an aging-fleet report for a client — end-of-life operating systems, old hardware, and warranty status where a source exposes it. Use for "what's running out of support at <client>" or lifecycle-risk reporting.

WiFi Heatmap / Site Survey Request

Decide whether a wireless problem warrants a heatmap/site survey, and capture the complete site information needed to commission one so the surveyor isn't sent back for missing details. Use when someone asks for a WiFi survey, reports chronic coverage/roaming issues, or is planning a new-site wireless deployment.

WiFi Infrastructure Audit

Audit a client's wireless estate — AP inventory per site, coverage-complaint mapping from ticket history, firmware posture, and a guest-network isolation check. Use for "audit the WiFi", recurring "WiFi is slow in <area>" complaints, or pre-refresh assessment of the wireless network.

Windows 11 Readiness Assessment

Assess which of a client's devices can upgrade to Windows 11 — CPU generation, TPM, RAM, and OS edition flags from RMM device details — and produce an upgrade-blocker list. Use for "which machines can't run Win11" or planning an OS migration.