In this joint webinar, Syncro Channel Chief Andy Cormier and IRONSCALES Global Director of MSP Strategy and Enablement Eddie Phillips walk through the full IRONSCALES platform and its integration with Syncro. The session covers why legacy secure email gateways fall short against modern phishing threats, how IRONSCALES’ adaptive AI and crowdsourced threat intelligence work, and three standout features: the 90-day scanback for proving ROI before you commit, three-click API deployment with no DNS changes, and one-click inbox remediation across all customers. Eddie also demos the autonomous SAT campaign builder and DMARC Pro console, and the Q&A covers product tier comparisons, Avanan comparisons, trial setup, and Universal Billing integration.
Key Topics Covered
- Why legacy secure email gateways (SEGs) are no longer sufficient for modern phishing and business email compromise threats
- How IRONSCALES adaptive AI learns communication patterns within each client’s email environment to detect anomalies
- The 90-day scanback: how it works, what it surfaces, and how MSPs use it as a sales and prospecting tool
- Three-click API integration with Microsoft 365 and Google Workspace, no MX record changes required
- One-click threat remediation and auto-clustering across all customer inboxes
- Autonomous SAT campaigns: AI-generated phishing simulations and training on a recurring schedule
- User risk scoring and how it feeds back into IRONSCALES’ AI to weight incident reporting
- DMARC Pro: hosted SPF management, DNS wizard, visual sending source dashboard
- IRONSCALES product tiers: Protect, Email Protect, and Complete Protect, DMARC as an add-on
- Syncro Universal Billing integration: automated daily license counts flowing into recurring invoices
- Comparison to Avanan and legacy SEGs, passive mode co-deployment, and trial mechanics
Product Features Covered in This Webinar
- Existing IRONSCALES account migration to Syncro
- 90-day scanback (automatic on trial install, results in 48-72 hours)
- Three-click API integration with Microsoft 365 (Graph API) and Google Workspace
- Silent mode: passive monitoring alongside existing email security solutions
- Adaptive AI: behavioral email analysis using relationship context and communication patterns
- Crowdsourced real-time threat intelligence feeding the AI across all IRONSCALES partners globally
- Auto-clustering: grouping similar threats for single-action cross-organization remediation
- One-click inbox remediation: remove phishing emails from all affected inboxes simultaneously
- Report phishing button: in-client reporting that feeds directly into the IRONSCALES AI
- Autonomous SAT campaigns: AI-generated phishing simulations and training on recurring schedules
- Custom template creation from real caught threats (de-weaponized)
- New hire simulation automation
- User risk scoring and incident threshold weighting
- Advanced account takeover detection
- Unified quarantine with Microsoft Quarantine
- DMARC Pro: hosted SPF, DMARC policy management, DNS wizard, visual sending source dashboard
- Teams protection (Complete Protect tier)
- Encryption (coming Q2)
- Deepfake protection (coming in future releases)
- Universal Billing integration with Syncro: automated daily license count sync to recurring invoices
Welcome and Syncro Partnership Overview
Andy Cormier: Welcome everybody to our joint webinar with IRONSCALES. My name’s Andy Cormier, and I’m the Channel Chief here at Syncro. Today I’m joined by Eddie Phillips, Global Director of MSP Strategy and Enablement at IRONSCALES. We’re going to go over all things IRONSCALES.
Andy Cormier: We’ve been working with IRONSCALES since early last year trying to bring them into our marketplace, and I’m super excited we’re finally able to get this done. One of the things that attracted us to IRONSCALES in the first place was the simplicity of their approach. Email security in the past has been really cumbersome to deploy, and even more difficult to configure to the point where you’re actually getting value out of what you’re paying for. With IRONSCALES, you can blanket a customer with end-to-end security in minutes.
Andy Cormier: One of my favorite aspects of IRONSCALES is that they’re more than willing to put their money where their mouth is. Because this is exclusively an API-first approach, you can actually sit IRONSCALES right on top of any existing email security solution in a passive mode to see exactly what they’d be catching that your current provider isn’t.
Andy Cormier: Pricing is detailed in the IRONSCALES app card in the App Center of your Syncro instance. We don’t mention pricing publicly on webinars by design, but that’s all available to you there, along with account provisioning. On trials: every time a new customer is added under your IRONSCALES tenant, you can put them into a trial or right into production. That option is always available, even if you’ve been using IRONSCALES successfully for years. No license minimums, no time-based commitments. You pay for exactly what you consume.
Andy Cormier: IRONSCALES is fully compatible with our Universal Billing Framework. Map your Syncro customers to your IRONSCALES customers and we pull all your usage data automatically into Syncro every day. Those counts flow into your recurring invoices and adjust automatically as license counts change, so you never have to manually enter that data again. If you’re an existing IRONSCALES customer and want to migrate to Syncro to get access to Universal Billing, email ironscales@synchromsp.com and we can get that process started.
Eddie Phillips Introduction: Former MSP CEO Background
Eddie Phillips: Thanks for joining, I love the turnout. I want to frame this webinar from the perspective of a former MSP CEO. Before I joined the vendor side, I owned an MSP for 14 years and sold it in 2022. In 2014, something significant happened to me. One of our biggest clients, the world’s largest winter clothing manufacturer, got hit by ransomware while preparing their online and print catalog. 14 terabytes of data. A staff member had fallen for a phishing email, a fake invoice attack.
Eddie Phillips: As an MSP, you have one job: keep your client’s data available to the people who are supposed to have access. That’s it. Everything we do as MSPs circles around that one deliverable. Since 2014, it’s only gotten more complex. More phishing campaigns, more account takeovers, more credential theft, faster lateral movement. And it’s going to get even more complex as deepfakes and social engineering evolve.
Eddie Phillips: When I decided to join IRONSCALES, I had to do a serious evaluation. Would my MSP use this product? Can I confidently recommend it? IRONSCALES delivers protection from these threats in two main ways: adaptive AI email security, and security awareness training with phishing simulation.
Why Legacy Email Gateways Are No Longer Enough
Eddie Phillips: Legacy email gateways leaned on static policies, rules, whitelists, and blocklists. Today you can’t get away with that, because attacks are so dynamic. Business email compromise, vendor impersonation attacks, these legacy items just aren’t cutting it. My MSP was a Mimecast partner, and in its day it was cutting edge, but as things evolved, we needed a better, easier way to do email security.
Eddie Phillips: When legacy gateways changed your MX records and required you to stage email on their servers, you opened up the risk of breaking email flow. Then we got API plugins, and some started using AI, although most of it is still static, looking at malicious links or attachments but not the contextual, adaptive AI that IRONSCALES has developed. IRONSCALES has been using AI and machine learning since 2015. Before AI was cool, we were the hipsters of AI.
Eddie Phillips: IRONSCALES has three layers of defense. The first is adaptive AI: the platform learns the type of relationship between any two people in your email ecosystem. What’s a normal conversation between Andy and me? If Andy suddenly starts asking me for gift cards, IRONSCALES flags it. The second layer is the world’s largest crowdsourced threat intelligence, where real-time feedback from all IRONSCALES partners feeds the AI continuously, which is what makes it outstanding at stopping zero-day phishing attacks. The third layer integrates security awareness training, with user risk scores feeding back into the AI.
Feature 1: The 90-Day Scanback
Eddie Phillips: My top favorite feature: the ROI writes itself. When you install IRONSCALES, even on a trial, the 90-day scanback runs automatically. Within about 48 to 72 hours, we look back three months and show you what would have happened if IRONSCALES had been installed. A lot of vendors use what I call the Trust Me Bro framework: kick their software around for 14 days and trust it’ll work. We show you three months of actual evidence based on email that already exists in your client’s environment.
Eddie Phillips: Here’s how MSPs are using it as a sales tool. Install the trial, run the 90-day scanback, present the results to a prospect within 72 hours. Some partners are offering a free or paid email security assessment: they reach out, offer to run an email security assessment showing where the customer currently stands, install IRONSCALES in silent mode, and present that report. It’s compelling because every threat in that report is an active, live email currently sitting in the user’s inbox. It’s not theoretical. These emails made it through Microsoft, through Google, through whatever gateway they already have in place.
Andy Cormier: To double down on that: MSPs often struggle to differentiate when going after a new bid. Being able to show a prospect not just ‘we’ll protect all your stuff’ but ‘here is everything that would have been caught, from email that already got through, in your actual environment,’ is a huge win. It doesn’t cost anything. This is the best tool I know of when it comes to landing a new customer or expanding into an existing customer that doesn’t have email security.
Feature 2: Three-Click API Deployment
Eddie Phillips: My number two favorite feature: it’s so easy to implement. We’re not changing MX records. There are no complex, risky DNS changes. We’re not breaking email flow. It is a three-click API change integration with Microsoft or Google Workspace. That’s it.
Eddie Phillips: The last thing you want to do is break a new potential customer’s environment during deployment. Legacy gateways required you to route all email through external servers, and anything that goes wrong there creates real downtime risk. We just make it easy.
Andy Cormier: The first time I tried to deploy a legacy SEG, I was testing it on our own email tenant, and I accidentally routed the MX records wrong and took our email down for three hours. With IRONSCALES it’s: put in your credentials, you’re done. That legacy model is just that at this point.
Feature 3: One-Click Threat Remediation
Eddie Phillips: My number three: fast remediation. The old way: a user forwards a suspicious email to your help desk, it creates a ticket, you do a thread analysis, figure out if it’s phishing, then you have to do a message trace to find out who else in the organization got it. By the time you communicate to end users not to open it, you’re racing the clock. That whole process takes about 30 minutes and increases risk throughout.
Eddie Phillips: With IRONSCALES: auto-clustering groups emails that share around 80% in common, so one incident covers all similar emails. Users report via the in-client report phishing button. The AI re-evaluates. If confirmed phishing, you can reach out and remove the email from every affected inbox across the entire organization in one click, without a message trace, without manually tracking down all recipients, without worrying about whether the attacker changed the domain or wording slightly. Static rules fall apart on that, we learn it on the fly and apply it across all your customers.
Additional Features Overview
Eddie Phillips: Beyond those three core differentiators, IRONSCALES also includes advanced account takeover detection; unified quarantine with Microsoft Quarantine; autonomous SAT campaigns where the AI generates and sends security awareness training on a recurring schedule; new hire simulation automation that triggers automatically when a new hire is added without manual configuration; DMARC Management; and DMARC Pro launched this month. Coming in Q2: encryption and deepfake protection.
SAT Campaigns Demo
Andy Cormier: Can you drill into the SAT campaigns specifically? We get a lot of questions about how easy they are to set up, especially around current-event-based phishing like Super Bowl season campaigns.
Eddie Phillips: In the simulation and training console, you come in and schedule training. The autonomous campaigns are the best feature: set them up once to run every month, and the AI generates new content each time so you’re not spending cycles every month or year creating something new.
Eddie Phillips: You can also build your own simulations. Choose your tenant, name the campaign, choose participants, set your schedule and start and end dates, configure reporting to managers for incomplete training. Then you get to select and modify templates. One standout feature: if IRONSCALES catches a really clever phishing email in the wild, you can go into the incident, click Create Template, and it dumps that email into your templates library, de-weaponized with links and attachments removed. You can then use that actual threat as a phishing simulation template for your users. That’s how you keep training relevant.
Eddie Phillips: Training materials range from short snippet training to longer security awareness courses. You can also upload your own. The platform tracks risk levels per mailbox so you can identify high-risk users who need extra attention. And those same risk scores feed back into the AI: users who are very good at spotting and reporting phishing get weighted more heavily in the AI’s incident evaluation, so their reports carry more weight when determining whether something gets flagged as a real threat.
Andy Cormier: So if Bob clicks every phishing simulation we ever send him, and then Bob starts reporting things, the AI is going to treat Bob’s reports with a bit of skepticism. That’s very cool.
Eddie Phillips: Exactly. If they keep falling for phishing, they stay at beginner risk level, and incident thresholds for their reports reflect that accordingly.
DMARC Pro Demo
Eddie Phillips: DMARC Pro launched this month. The console is available from a button at the top of the IRONSCALES console. There’s no charge for the console itself, which includes a free domain analyzer tool and a power toolbox similar to MX Toolbox.
Eddie Phillips: Where it gets powerful: instead of managing DMARC through cryptic XML files, IRONSCALES provides a visual interface for everything. You go through a wizard to set up a domain, which does require one DNS record change. But once that’s done, IRONSCALES hosts your SPF records, meaning you can flatten all your SPF records and manage them directly in the platform without ever logging into your DNS host again.
Eddie Phillips: IRONSCALES includes a DNS wizard that detects your DNS hosting provider, prompts for credentials, and makes that initial DNS change on your behalf. After that, adding a new email-sending service like MailChimp is just: find MailChimp in the list, click it, modify, save. No DNS login required. Hosted DMARC lets you set policy to do nothing, quarantine, or reject, all in one click. The Sending Sources view color-codes all sources sending from your domain so you can immediately see approved senders in green and anything suspicious or unauthorized in red or orange, without digging through XML. DMARC is priced per domain.
Q&A
Andy Cormier: Do you suggest running IRONSCALES alongside Barracuda or similar, or is it enough to run alone?
Eddie Phillips: Run us alone. Save your money, save the configuration complexity. If you’re going to embrace AI, there’s a paradigm shift: leave the legacy SEGs in the past. The longer IRONSCALES is in place, the more it learns, and the less you have to do. This is where AI is going to take real cycles off MSPs: you can stop going into your console to release emails and create policies.
Andy Cormier: How does IRONSCALES compare to Avanan, specifically on false positives?
Eddie Phillips: Avanan has pivoted to API-level integration and added some AI, but where a lot of competitors fall short is real-time, zero-day email threat context and feeding the AI based on what’s happening right now. For example, if a partner in Australia reports a phishing email at the start of their morning, the AI processes it, and it rips that threat out of your users’ inboxes before they even wake up in the US. That ability to feed the machine in real time using crowdsourced intelligence is where IRONSCALES is outstanding.
Andy Cormier: Can IRONSCALES stop a bad email before it hits the mailbox, or is it delivered and then removed?
Eddie Phillips: Scanning is on delivery and post-delivery. Because we’ve got the algorithms dialed in and we’re looking strictly at the algorithmic output of emails, we identify threats extremely fast. It is not purely pre-delivery blocking, but the speed of detection and the auto-remediation make the distinction largely irrelevant in practice.
Andy Cormier: How does IRONSCALES see mail without changing MX records?
Eddie Phillips: It plugs in at the mailbox level inside the Microsoft or Google Workspace ecosystem using the Graph API. That’s why there are no MX record changes and no email routing risks.
Andy Cormier: Is the DMARC add-on priced for the whole tenant or per domain?
Eddie Phillips: Per domain.
Andy Cormier: Is IRONSCALES pricing month-to-month?
Andy Cormier: Yes, 100% month-to-month. No minimums. If you need to increment up or down because you added or lost a customer, you pay exactly what you use in any given month.
Andy Cormier: Does IRONSCALES protect all of M365, like Teams, OneDrive, SharePoint?
Andy Cormier: IRONSCALES covers email specifically. Teams protection is included in the Complete Protect tier. OneDrive and SharePoint coverage are not part of the IRONSCALES scope. For M365 Cloud Backup covering OneDrive, SharePoint, and Teams data, Syncro has its own native backup solution available in the App Center.
Andy Cormier: Final notes: Existing Syncro customers, provision your IRONSCALES account directly in the App Center. Non-Syncro customers, links for a demo or free trial were shared in the chat. Any follow-up questions, email andy@syncrosecure.com. The webinar will be recorded and shared with all attendees.

See How Syncro Powers Your Business
Schedule a one-on-one walkthrough with a product expert to see the Syncro platform in action. No fluff — just a personalized look at how to unify endpoint management, service operations, and M365 workflows.
Frequently Asked Questions
When you install IRONSCALES, even on a free trial, it automatically runs a 90-day scanback that looks back three months at your client’s email environment and shows you what IRONSCALES would have caught. Results are typically available within 48 to 72 hours. Because IRONSCALES integrates at the API level and sits after all other filters, every threat surfaced in the report represents real emails currently sitting in your client’s inbox, not theoretical catches. MSPs are using this as a paid or free email security assessment offer: install IRONSCALES in silent mode, run the scanback, and present the report to prospects to demonstrate exactly what their current solution is missing.
IRONSCALES connects to Microsoft 365 and Google Workspace via a three-click API integration using Microsoft Graph API or the Google Workspace equivalent. There are no MX record changes, no email flow rerouting, and no DNS configuration required beyond DMARC management if you choose to add it. This eliminates the risk of breaking email flow during deployment, a common problem with legacy secure email gateways that route mail through external servers. The entire setup can be completed without involving DNS administrators or risking downtime.
IRONSCALES uses auto-clustering to group emails that share approximately 80% or more in common, so one reported incident can trigger a response across all similar emails in your environment. When a user reports a suspicious email via the built-in report phishing button, the AI re-evaluates it. If confirmed as phishing, IRONSCALES can reach into every affected inbox across your entire customer base and remove the email in one click, without requiring a manual message trace or end-user communications. This reduces what was historically a 30-minute incident response process to a single action.
Legacy secure email gateways rely on static rules, blocklists, and signature-based detection, and they sit outside your email ecosystem, so they cannot see internal emails, direct-send traffic from devices like printers, or lateral movement inside your environment. IRONSCALES uses adaptive AI that learns the normal communication patterns within each client’s email environment and flags deviations, such as a known contact suddenly requesting gift cards. It also pulls from a real-time crowdsourced threat feed: when a partner anywhere in the world reports a phishing email, that signal is fed into the AI immediately, which can proactively remove the same threat from other users’ inboxes before they even see it.
IRONSCALES’ security awareness training module includes an autonomous campaign feature that uses AI to automatically generate and send phishing simulations and training content on a recurring schedule, without requiring manual campaign creation each month. MSPs can configure the schedule, target audience, and templates once, and the AI handles the rest. A standout feature is the ability to convert a real phishing email caught by IRONSCALES into a de-weaponized simulation template, allowing MSPs to train users on the exact types of attacks currently targeting their clients. The platform also tracks user risk scores based on simulation results and weights those scores in the AI, so repeat phishing victims have less influence on incident thresholds than users who consistently identify threats correctly.
Yes. IRONSCALES can run in silent mode alongside any existing email security tool, including secure email gateways like Barracuda, Avanan, or Mimecast, without blocking any emails or making any changes to the environment. In silent mode, the 90-day scanback still runs and IRONSCALES still surfaces threats it identifies, allowing you to compare its coverage against your current solution. The recommended approach from IRONSCALES, however, is to run it as a standalone solution rather than layering it on top of a gateway. The longer IRONSCALES is the primary tool in place, the more its AI learns the environment and the more effective it becomes.
IRONSCALES offers three core email security tiers. Protect provides basic email scanning on links and attachments but does not include continuous scanning, third-party scanner integration, or advanced features. Email Protect adds stronger email protection but does not include Microsoft Teams protection, account takeover detection, or security awareness training. Complete Protect includes all of the above: full adaptive AI email security, Teams protection, account takeover detection, and the autonomous SAT and phishing simulation platform. DMARC management is available as an add-on across all tiers and is priced per domain. The most commonly sold tier for MSPs looking for comprehensive coverage is Complete Protect.
IRONSCALES is fully compatible with Syncro’s Universal Billing framework. MSPs map their Syncro customers to their IRONSCALES customers, and Syncro automatically pulls daily license usage counts from IRONSCALES and flows them into recurring invoices. As license counts change, recurring invoice quantities update automatically, eliminating manual data entry. This integration is available for both new IRONSCALES accounts provisioned through Syncro’s App Center and for existing IRONSCALES customers who want to migrate their account to Syncro. Pricing details and account provisioning are available in the IRONSCALES app card in the Syncro App Center. All plans are month-to-month with no minimums or time-based commitments.
Webinar Hosts

Andy Cormier
Channel Chief, Syncro
Andy Cormier is Channel Chief at Syncro, where he leads partner and channel strategy. In this joint webinar with IRONSCALES, Andy outlined Syncro’s partnership with IRONSCALES, covering the Universal Billing integration, marketplace provisioning, trial structure, and the value of an API-first email security approach for MSPs looking to modernize their security stack.

Eddie Phillips
Global Director of MSP Strategy and Enablement, IRONSCALES
Eddie Phillips is Global Director of MSP Strategy and Enablement at IRONSCALES, and a former MSP CEO with 14 years of experience running his own managed services business before selling in 2022. In this webinar, Eddie drew on his MSP background to walk through IRONSCALES’ three core differentiators: the 90-day scanback for proving email security ROI, a three-click API-based deployment with no MX record changes, and one-click threat remediation across all customer inboxes. He also demonstrated the autonomous SAT campaign builder, DMARC Pro management, and the IRONSCALES product tier structure.
Share









