
If your CPA firm runs Practice Protect and the renewal is coming up, this is the guide we wish someone had handed us before the first one. Practice Protect is a well-known product. It sells single sign-on, password control, geo-locking and offboarding to accounting firms, and it reports serving more than 25,000 accounting professionals. It was acquired by Rightworks in June 2024, and Rightworks is owned by BV Investment Partners, a Boston private-equity firm. None of that makes it a bad product. It does mean the company you signed with is not the company you renew with, and that is the right moment to ask what you are actually paying for.
What Practice Protect is, and what it is not
Practice Protect is an identity and access layer. It sits between your staff and the cloud applications they use, so logins run through one gateway with multi-factor authentication, location rules, an audit trail, and a fast way to cut off a departing employee. Those are real controls and every CPA firm needs them. The FTC Safeguards Rule requires MFA for anyone who touches client information, and a written information security plan that documents how access is controlled.
What it is not is a complete security program. It does not patch your computers, watch your network at 3 a.m., back up your data, run your incident response, or sit with your Qualified Individual to produce the annual report. A firm that buys Practice Protect and nothing else has covered one line of the Safeguards Rule and left the other eight open.
What users say when it goes wrong
Ratings on the review sites are high, and most reviewers praise the support team. The lower-rated reviews on G2 and GetApp describe the same handful of problems, and they are worth reading because they are structural, not one-offs:
- Onboarding is complicated. Routing every application through a gateway means every application has to be set up, and re-set when a vendor changes its login procedure.
- When the gateway has a problem, nobody can get into anything. That is the trade-off of a single front door. In tax season it is the trade-off that matters.
- Support hours do not always match the firm’s hours. The company is Australian in origin, and reviewers in other time zones reported waiting.
- Getting out is harder than getting in. One reviewer described a cancellation request that went unanswered. Exit terms belong in your renewal questions.
We are quoting public reviews, not our own experience with the product, and we are not naming the reviewers. Read them yourself before you decide anything.
The alternative most Charlotte CPA firms already own
The controls Practice Protect sells are, for most firms, already sitting inside a Microsoft 365 Business Premium licence: Microsoft Entra ID for single sign-on and conditional access, phishing-resistant MFA, location and device rules, Intune for device compliance, and Defender for the endpoints. Network Essentials is a Microsoft shop, and Entra ID is our standard for every client; we support Okta for the few firms that already run it. What the licence does not include is someone to configure it correctly, keep it that way, watch it, and document it for your WISP. That is the job of a managed IT provider, and it is the difference between a subscription and a security program.
Done that way, identity and access stop being a separate vendor with its own renewal and become one part of a program that also covers the other eight Safeguards elements: risk assessment, monitoring, training, backup, incident response, vendor oversight, the annual report and keeping it all current. We map every CPA client’s program to the NIST Cybersecurity Framework 2.0 so the firm can show an auditor, an insurer or a client exactly what is covered and by whom.
Seven questions to ask before you renew
- Who owns you now, and who owns them? The answer is public. Ask anyway, and ask what has changed in support and roadmap since the sale.
- What happens to my staff’s access if your service is down during filing season? Ask for the outage history and the fallback.
- Which of my applications are actually protected today, and which are bypassed? Get the list. Gateways only protect what has been onboarded.
- What is the support commitment in Eastern time? A response target, in writing, for a locked-out partner at 7 a.m. in April.
- How do I export my password vault and cancel? Ask for the procedure and the notice period before you need them.
- Which Safeguards Rule elements does this cover, in your words? A vendor that says “all of them” has not read the rule.
- What is the renewal price, in writing, before the renewal date? Not on it.
Clear answers mean stay, at least for this term. Vague answers on questions 2, 5 and 7 are the signal to start a comparison 90 days before the date.
How the switch works without locking anyone out
This is how Network Essentials onboards a firm that is leaving a provider or a product, and it does not start with a month of discovery.
- Day one: we take the keys. We collect every credential that gives us the access needed to support you, change the passwords that lock out the old provider, and start taking support requests the same day. Your staff have someone to call from the first morning.
- Weeks one to four: we document everything. Every application, every user, every shared credential, and which of them currently route through the Practice Protect gateway. Full documentation takes two to four weeks, and it is what makes support fast afterward.
- Build the new front door beside the old one. Entra ID single sign-on, conditional access and phishing-resistant MFA are configured and tested on a pilot group while Practice Protect keeps running.
- Move the password vault. Export, import into a managed password manager, and verify the shared credentials for applications that do not support single sign-on.
- Cut over outside of filing season, then cancel in writing. Staff sign in once with the new MFA. The old gateway is disabled, not cancelled, for two weeks, then cancelled with the confirmation kept on file. The WISP’s access-control section and vendor list are updated the same week.
Nothing about it should cause a day of downtime. Support starts on day one, and the old system stays live until the new one is proven.
Where Network Essentials stands
Network Essentials has been independently owned in Charlotte since 2002, with no private-equity parent, and is CISSP-led. For CPA and tax firms we run identity and access as part of a full Safeguards Rule program: 24/7 monitoring, help desk staffed Monday to Friday 6am to 6pm, after-hours emergency support for clients, quarterly security reviews, and the documentation your Qualified Individual needs. Engagements are a flat monthly fee with a minimum of $2,000 per month and no long-term lock-in. If you want a second opinion on a Practice Protect renewal, we will read it with you and tell you honestly whether staying is the right call. Call (704) 206-8900 or request a free IT audit, and see our IT services for financial and accounting firms.
Frequently asked questions
Is Practice Protect required for CPA firms?
No. The FTC Safeguards Rule requires multi-factor authentication, access controls and a written information security plan. It does not require any particular product. Practice Protect is one way to meet the access-control parts of the rule; Microsoft Entra ID configured by a managed IT provider is another.
Can we keep Practice Protect and still use a managed IT provider?
Yes. Many firms do. The question is whether you are paying twice for identity controls, and whether the two vendors agree on who is responsible when a login fails.
Does switching mean new passwords for everyone?
Staff sign in once with a new multi-factor method. Application passwords move with the vault. A well-run switch is one sign-in event per person, not a reset of every credential.
Who owns Practice Protect now?
Rightworks acquired Practice Protect in June 2024. Rightworks is owned by BV Investment Partners, a Boston private-equity firm.