Why Your MSP Is Losing Money on Expiring SSL Certificates (And How Autotask Asset Tracking Fixes It)

Here's an uncomfortable truth: the most expensive ticket your MSP will ever work is the one generated by a client whose website just went dark because someone forgot to renew an SSL certificate 90 days ago. The chaos is entirely preventable, and the fix is already sitting in your Autotask instance.

Most MSPs know this pain. An expired cert takes down a client site, the client calls screaming, you spend two hours in emergency mode tracking down the certificate vendor, and then you eat the labor cost because there's no graceful way to bill for something that was your responsibility to prevent. Multiply that by even three incidents a year across your client base, and you're looking at a meaningful revenue leak with zero upside.

The good news is Autotask has native domain and SSL certificate tracking. The frustrating news is most MSPs have never turned it on.

The Real Cost of Untracked SSL Certificates

Let's put a number on this. A typical SSL emergency runs two to four hours of technician time once you account for diagnosing the issue, coordinating with the client, tracking down the renewal, deploying it, and verifying everything is back up. At $125/hour fully burdened, that's $250 to $500 per incident in labor alone.

Add the soft costs:

  • Client relationship damage (quantify that however you like, but it's not zero)
  • After-hours premiums if it happens on a weekend
  • Time your senior tech spent on something a process could have handled
  • The contract conversation you now have to have to justify your monitoring fees

Most MSPs do this firefighting for free because there's no pre-existing ticket or contract line capturing it. You're absorbing a cost that your client never sees as billable work, which means it doesn't appear on any report that would prompt a pricing conversation.

The other problem is systemic. If SSL certificates aren't tracked as assets in your PSA, you have no visibility into how many certificates are expiring across your client base at any given time. You're flying blind.

The Feature Most Autotask Users Have Never Activated

Autotask has two system device categories specifically built for this: Domain and SSL Certificate. These aren't just label fields. When you create a device using the Domain category and enter a domain name, Autotask automatically retrieves DNS entries and expiration dates. If an SSL certificate is found, it will prompt you to auto-create a child device for it.

The SSL Certificate category works similarly. Enter the certificate, and Autotask pulls public details automatically. You can also add private key data and intermediate chain information via user-defined fields (UDFs), which Autotask recommends handling through UDFs since they support encryption and view tracking for sensitive data.

The catch: this feature is not activated by default. You have to go to Left Navigation Menu > Admin > Admin Categories > Activations to turn it on. It's also not included in the Essentials contract tier, so if you're on Essentials, the automated retrieval of WHOIS, DNS, and SSL data is disabled.

That activation step is why most Autotask shops have never used this. It's not intuitive, it's not mentioned prominently, and nobody went looking for it because the old way (manual UDFs, spreadsheets, or just hoping someone remembers) technically worked. Until it didn't.

To get started:

  1. Navigate to Admin > Admin Categories > Activations and enable domain and SSL certificate tracking
  2. Go to CRM > Devices and create a new device using the Domain system category
  3. Enter the client's domain; Autotask pulls DNS records and expiration dates automatically
  4. Accept the prompt to create an associated SSL Certificate child device
  5. Repeat for all clients or use the bulk import process if migrating existing records

If you already have devices tracking domains through custom UDFs, you can migrate them by exporting in import template format, updating the category column to Domain or SSL Certificate, and re-importing. Once updated, use the bulk Update Domain Details and Update SSL Certificate Details actions to force-refresh the data.

Building the Renewal Workflow That Actually Prevents Incidents

Tracked assets are only valuable if they trigger action. An SSL certificate record sitting in Autotask with an expiration date is marginally better than a spreadsheet. What you want is a workflow rule that generates a ticket automatically as that date approaches.

Autotask's workflow rules let you fire on configuration item field values, including expiration dates. A reasonable setup:

  • 90 days out: Auto-create an informational ticket tagged to the client, assigned to your account management queue, noting the upcoming renewal
  • 30 days out: Escalate to a technician queue with a task to initiate the renewal process
  • 7 days out: Create a high-priority ticket if the certificate still hasn't been renewed, flagged for immediate action

Each ticket should reference the device record so technicians can see all the certificate details without hunting for them. More importantly, each ticket should be tied to the correct client contract so the labor gets captured and billed.

If you're already doing ticket triage work, the patterns here are the same ones that make AI-driven tools accurate. Clear issue types, consistent queue assignment, and tickets that contain actual context (not just "SSL cert expiring") create a service desk that runs on data instead of institutional memory.

Structuring SSL Management as a Billable Service

Once asset tracking and renewal workflow automation are in place, you have everything you need to package this as a formal service line. Right now, most MSPs absorb SSL and domain management as overhead. The work happens, the time gets lost, and the client has no visibility into the value being delivered.

Packaging it properly means:

  • Creating a recurring service item in Autotask for Domain & SSL Certificate Management
  • Attaching it to client contracts so renewal labor is captured against a billable line
  • Including it in client-facing reports so clients see it as a service, not an assumption
  • Pricing it to cover your technician time and the certificate costs themselves, with a margin

A simple structure: charge a flat monthly fee per domain managed (covering monitoring and renewal coordination) with pass-through on certificate costs plus a handling fee. For a client with five domains and associated certs, that might be $75 to $150 per month. Across 50 clients, that's a service line worth $45,000 to $90,000 annually that previously generated zero revenue.

The Autotask Contracts module supports recurring billing structures that can tie directly to the assets and tickets you're already generating. The workflow you built to create renewal tickets should be configured to associate those tickets with the appropriate contract, so time entries flow into billing automatically rather than requiring manual cleanup at month end.

What to Do With Existing Client Assets

If you've been tracking domains and certs through custom UDFs or spreadsheets, migration is straightforward but requires attention to detail. The key constraint to know upfront: once you assign the Domain or SSL Certificate system category to a device, you cannot change it. Get the category right before you import.

The migration process in brief:

  1. Export existing domain/SSL devices from CRM > Search > Devices using Export > In Import Template Format
  2. Update the category column to Domain or SSL Certificate as appropriate
  3. Map UDF values into the system Domain and SSL Source fields
  4. Re-import via Admin > Features & Settings > Devices > Device Import
  5. Run bulk updates (Update Domain Details / Update SSL Certificate Details) to populate auto-retrieved data

One thing to watch: if hundreds of records are scheduled for update simultaneously, Autotask may not complete all of them in the first pass. Failed updates get rescheduled an hour later automatically, so don't panic if your initial refresh looks incomplete.

The Short Version

SSL and domain management is costing your MSP money in two directions simultaneously: emergency labor you're eating on incidents, and recurring management work you're not billing for. Autotask's native domain and SSL tracking eliminates both problems, but only if you turn it on and build the workflow around it.

The activation is in Admin > Activations. The rest follows logically:

  1. Enable the feature and create device records using the system Domain and SSL Certificate categories
  2. Build workflow rules that generate renewal tickets at 90, 30, and 7 days before expiration
  3. Tie those tickets to client contracts so labor is captured and billed
  4. Package it as a named service on client contracts with a recurring fee

That's the difference between a cost center that occasionally blows up in your face and a managed service line with predictable revenue and zero client surprises.

Tags: