Skip to content

What Managed IT Services Actually Include in a Typical Agreement

Two proposals sit on the desk, both say “managed IT services”, and the monthly figures are nowhere near each other. That is usually because the phrase covers a wide range of scopes, and the only way to compare them fairly is to know what normally sits inside an agreement, what normally sits outside it, and where the grey areas are.

The core of a managed IT agreement

Almost every genuine managed agreement rests on the same idea: the provider takes ongoing responsibility for keeping a defined set of systems healthy, rather than waiting for something to break and billing to fix it. That responsibility shows up as a handful of recurring services.

Monitoring and alerting

A small agent runs on each server and workstation, watching disk space, failed services, backup jobs, security tool status and hardware warnings. The value is not the dashboard; it is that somebody acts on a full disk or a failing drive before it becomes an outage. Ask how alerts are triaged and by whom, because a tool that emails an unattended mailbox is not monitoring.

Patching and updates

Operating system updates, browser and productivity application updates, and firmware where it can be automated. A good scope states the cadence, the maintenance window, whether patches are tested before broad release, and how laptops that rarely touch the office network get covered.

Help desk

The scope should say the hours, the channels available (phone, portal, email), what counts as an incident versus a request, and the targets for first response and for resolution. “Unlimited” help desk is common, but it is usually bounded by fair use and by what is in scope, so read the definitions rather than the headline.

Backup management

Most agreements include managing the backup platform: configuring jobs, confirming they succeed, and performing restores when asked. What varies is whether the storage is included, whether the provider performs scheduled test restores, and how long data is retained. If your business has a legal or contractual retention need, that has to be written in rather than assumed.

Security tooling

At minimum, managed endpoint protection and email filtering. Increasingly, endpoint detection and response, multi-factor authentication administration and security awareness training are bundled or offered as a higher tier. The scope should list the tools by function, and say plainly who responds when one of them raises an alert at two in the morning.

Vendor management and reporting

Vendor management means the provider deals with your internet carrier, phone system supplier and line-of-business software support on your behalf. Reporting is a periodic summary of tickets, patch status, backup results and open risks, and the useful ones lead to a conversation about what to fix next.

What usually sits outside

The recurring fee buys operations, not everything with a plug. The items below are normally quoted separately, and a provider who says so up front is being fair rather than evasive.

Projects are the biggest one. Migrating email to the cloud, replacing a server, moving offices or rolling out a new phone system are defined pieces of work with a start and an end, and they are scoped as projects. Our IT project management work is handled this way precisely so the recurring service stays predictable.

Hardware and software licences are almost always purchased by you or passed through at cost. The provider recommends, sources and installs; you own the asset and the licence. Third-party support contracts, such as the maintenance agreement on your accounting software or your multifunction printer, remain with that vendor.

Anything not on the asset list is out of scope by definition. If the warehouse has a workstation nobody told the provider about, it is not being patched or backed up. Keeping that list current is a shared duty, so ask how the provider discovers new devices.

The grey areas worth settling in writing

Three areas cause most disputes, and all of them can be settled in the scope. The first is after-hours work: is it included, on call with a response target, or billed separately? The second is on-site attendance: some agreements include it, some cap it, and some treat every visit as billable. The third is user changes: onboarding one new starter is routine, onboarding forty in a month is reasonably a project.

Ask too about ownership. Documentation, administrative passwords, licences and domain registrations should be in your name, held where you can reach them, and handed over cleanly if the relationship ends.

How to read a scope document

Start with the asset list, because everything else hangs off it. Then find the service level definitions and check that response and resolution are treated separately. Look for the words “excluded” and “additional” and read every sentence around them. Check the term and the exit clause. Finally, look for what the provider commits to doing proactively: test restores, quarterly reviews, a security roadmap. An agreement that is entirely reactive is a help desk contract with a nicer name.

Common questions

Is cybersecurity included in managed IT services?

Basic protection such as endpoint security and email filtering is usually part of the standard scope. Deeper layers, including endpoint detection and response, security monitoring and awareness training, are often a separate tier. Read the scope for the tools by function and for who responds to alerts, because a tool nobody watches is not protection.

Are hardware and software purchases included?

Almost never as part of the recurring fee. The provider will recommend, source and install equipment and licences, but you normally buy and own them. This keeps the monthly service predictable and means the assets remain yours if you ever change provider. Ask for quotes that show the service and the products separately.

What counts as a project rather than support?

A reasonable test is whether the work has a defined start, a defined end and a change to how the business operates once it is finished. Replacing a server, migrating email or moving offices are projects. Fixing a printer, resetting a password or setting up one new laptop are support. Most agreements state the boundary; if yours does not, ask for it in writing.

Can we keep some IT tasks in house?

Yes. Many organizations keep an internal person or team and bring in a provider for after-hours coverage, specialist security work, or the routine patching and monitoring that consumes internal time. This is usually called co-managed IT, and the division of responsibilities is written into the scope in the same way as a fully outsourced agreement.

If you have a proposal in hand and want a second pair of eyes on what it does and does not cover, our managed IT services and IT support desk pages describe how we scope the same work, and you can contact us to talk through the specifics of your environment.

← All articles

Ready to Get Started?

Talk to our experts about your needs by calling +1 (647) 725-9693 or book a free 30-minute consultation.

Book a Meeting

Our Partners

Microsoft
Azure
Aws
Google cloud
Cisco
Dell
Lenovo
Hp aruba
Fortinet
Crowdstrike
Checkpoint
Veeam
Microsoft
Azure
Aws
Google cloud
Cisco
Dell
Lenovo
Hp aruba
Fortinet
Crowdstrike
Checkpoint
Veeam