
When a business appoints a managed IT provider, the quality of the service should not depend on assumptions, informal promises or what somebody remembers discussing during the sales process.
A good managed IT support agreement should clearly set out what the provider will deliver, what the customer is responsible for, how quickly issues will be handled, how security will be managed and what happens if the relationship eventually comes to an end.
For small and mid-sized businesses, this is particularly important because the managed service provider may be responsible for a significant proportion of the organisation’s technology environment.
So, what should you expect to see in a managed IT support agreement?
What Is a Managed IT Support Agreement?
A managed IT support agreement is the contract between a business and its managed service provider, or MSP.
It normally defines:
- The IT services being provided
- The users, devices and locations covered
- Support hours
- Service response targets
- Cybersecurity responsibilities
- Monitoring and maintenance
- Backup responsibilities
- Microsoft 365 or cloud management
- Customer responsibilities
- Pricing and additional charges
- Contract length and termination arrangements
The exact contents will vary depending on the provider and the services being purchased.
The important point is that the agreement should make the division of responsibility clear.
Businesses should be able to understand exactly what their MSP is responsible for and where the MSP’s responsibility ends.
1. A Clear Description of the Services Included
The agreement should begin by defining exactly what the managed service includes.
“Managed IT support” can mean very different things depending on the provider.
One MSP may include comprehensive monitoring, patching, endpoint management, Microsoft 365 administration and cybersecurity.
Another may provide little more than access to a helpdesk.
The agreement should therefore identify the individual services being delivered.
For example:
- IT helpdesk support
- Remote support
- On-site support
- Device monitoring
- Server monitoring
- Network monitoring
- Microsoft 365 administration
- User account management
- Endpoint management
- Patch management
- Antivirus or endpoint detection and response
- Backup monitoring
- Email security
- DNS and web protection
- Vulnerability management
- Cybersecurity reporting
- IT strategy reviews
The more clearly these services are defined, the less scope there is for disagreement later.
2. Details of What Is Covered
The agreement should also explain which parts of the customer’s IT environment are covered.
For example, this might include:
- Company-owned laptops
- Desktop computers
- Servers
- Network switches
- Firewalls
- Wireless networks
- Microsoft 365
- SharePoint
- Microsoft Teams
- Printers
- Mobile devices
- Business applications
- Remote workers
- Multiple offices or sites
This becomes particularly important for businesses with unusual equipment, multiple locations or specialist software.
A construction company, engineering business or manufacturer, for example, may have devices or applications that fall outside a standard office IT environment.
These should be discussed before the agreement begins.
3. What Is Not Included
Exclusions are just as important as included services.
A good managed IT agreement should clearly explain where additional charges may apply.
Common exclusions might include:
- Major IT projects
- Office relocations
- New site installations
- Large Microsoft 365 migrations
- SharePoint projects
- Cabling
- Specialist application support
- Hardware purchases
- Software licences
- Out-of-hours project work
- Third-party consultancy
- Major cyber incident recovery
There is nothing wrong with an MSP charging separately for work outside the managed service.
The problem occurs when the customer assumes something is included and later discovers that it is chargeable.
Clear exclusions prevent this.
4. Helpdesk Hours
The agreement should state when support is available.
For example:
- Monday to Friday
- 08:00 to 18:00
- Excluding public holidays
Businesses operating outside conventional office hours should pay particular attention to this section.
A hospitality company, care provider, manufacturer or organisation operating shifts may require support during evenings or weekends.
If 24/7 support is required, the agreement should clearly state whether this is included or available as an additional service.
5. Service Levels and Response Times
One of the most important parts of a managed IT agreement is the service level agreement, often referred to as the SLA.
The SLA normally defines how quickly the provider will respond to different types of issue.
For example:
| Priority | Example | Typical Objective |
|---|---|---|
| Critical | Entire business unable to work | Immediate or very rapid response |
| High | Major system unavailable | Rapid response |
| Medium | Individual user significantly affected | Standard priority response |
| Low | Minor issue or general request | Lower priority response |
Businesses should understand the difference between:
Response time
The time before the MSP begins dealing with the issue.
and
Resolution time
The time it takes to completely resolve the issue.
These are not the same thing.
Providers should be careful about guaranteeing resolution times because many IT problems depend on hardware suppliers, software vendors, internet providers or other third parties.
However, response and escalation targets should be clear.
6. How Support Requests Are Prioritised
The agreement should explain how the MSP determines the priority of a ticket.
Priority should normally be based on a combination of:
- Number of users affected
- Business impact
- Urgency
- Security risk
- Availability of alternative systems
For example, one employee being unable to print is very different from an entire company losing access to Microsoft 365.
A structured priority system ensures that the most serious problems receive attention first.
7. Escalation Procedures
The agreement should explain what happens when an issue cannot be resolved by the first-line support team.
A mature MSP should have a defined escalation path.
This might involve:
- First-line support
- Second-line engineers
- Senior technical engineers
- Infrastructure specialists
- Cybersecurity specialists
- Technical management
- Third-party vendors
Customers should also know how they can escalate a problem if they believe an issue is not receiving appropriate attention.
8. Proactive Monitoring
Managed IT should not simply mean waiting for users to report problems.
The agreement should define what systems are actively monitored.
Depending on the service, this may include:
- Servers
- Workstations
- Disk capacity
- Device health
- Backup status
- Security alerts
- Antivirus or EDR alerts
- Network equipment
- Internet connectivity
- Microsoft 365
- Patch compliance
Proactive monitoring can allow an MSP to identify potential problems before they cause significant disruption.
9. Patch Management
Keeping systems updated is an important part of both IT management and cybersecurity.
The agreement should explain the provider’s responsibilities for installing updates.
This might cover:
- Windows updates
- Microsoft applications
- Third-party software
- Servers
- Network infrastructure
- Firewalls
- Endpoint security software
It should also explain how urgent security updates are handled.
Some updates may need to be deployed quickly, while others may require testing before widespread installation.
10. Cybersecurity Responsibilities
Cybersecurity should now be a core part of any modern managed IT agreement.
However, businesses should not assume that every cybersecurity service is included automatically.
The agreement should specify which protections are provided.
These might include:
- Endpoint detection and response
- Antivirus
- Multi-factor authentication
- Microsoft 365 security configuration
- Email security
- DNS filtering
- Web protection
- Vulnerability scanning
- Security awareness training
- Phishing testing
- Security monitoring
- Cybersecurity reporting
- Cyber Essentials support
It should also clarify which cybersecurity responsibilities remain with the customer.
No MSP can completely eliminate cyber risk.
Effective cybersecurity requires cooperation between the provider, management and users.
11. Microsoft 365 Management
For many businesses, Microsoft 365 is now one of their most important technology platforms.
The managed IT agreement should therefore explain what Microsoft 365 administration is included.
For example:
- Creating users
- Removing users
- Licence management
- Password resets
- Multi-factor authentication
- Exchange Online administration
- Microsoft Teams
- SharePoint
- OneDrive
- Security configuration
- Conditional Access
- Intune device management
It should also explain whether major Microsoft 365 configuration projects are included or treated separately.
12. Joiner, Mover and Leaver Management
Adding and removing users is a routine part of managed IT support.
The agreement should explain how these requests are handled.
A structured process might include:
Joiners
- Creating Microsoft 365 accounts
- Assigning licences
- Configuring laptops
- Setting security policies
- Providing access to shared resources
Movers
- Updating permissions
- Changing group membership
- Adjusting application access
Leavers
- Blocking accounts
- Revoking sessions
- Removing access
- Securing company data
- Reassigning email or files
The customer should normally be responsible for notifying the MSP when somebody joins, changes role or leaves.
13. Backup Responsibilities
Backup is an area where misunderstandings can cause significant problems.
The agreement should clearly define:
- Which systems are backed up
- How frequently backups are taken
- How long backups are retained
- Where backups are stored
- Who monitors backup success
- How restoration requests are handled
Businesses should not assume Microsoft 365 automatically provides the same protection as an independent backup service.
If Microsoft 365 backup is required, it should be specifically included in the agreement.
14. Disaster Recovery
Backup and disaster recovery are related, but they are not the same thing.
A backup provides another copy of data.
Disaster recovery deals with how systems will be restored following a major incident.
The agreement should therefore explain whether disaster recovery services are included.
For example:
- Server recovery
- Cloud recovery
- Recovery testing
- Recovery documentation
- Business continuity planning
- Disaster recovery exercises
Where specific Recovery Time Objectives or Recovery Point Objectives have been agreed, these should be documented.
15. On-Site Support
Many MSPs operate primarily through remote support because a large proportion of IT issues can be resolved remotely.
However, sometimes an engineer needs to visit the customer’s site.
The agreement should therefore explain:
- Whether on-site support is included
- Whether there is a call-out charge
- Whether travel is chargeable
- Geographic areas covered
- Response expectations
- Whether scheduled site visits are included
For Scottish businesses with multiple or remote locations, this can be particularly important.
16. Hardware and Software Procurement
The agreement should explain how equipment and software are purchased.
This may include:
- Laptops
- PCs
- Servers
- Firewalls
- Switches
- Wireless access points
- Microsoft licences
- Security licences
- Backup licences
Businesses should understand whether the MSP supplies these products directly and whether any procurement or management charges apply.
17. Third-Party Vendor Management
Many IT problems involve suppliers other than the MSP.
For example:
- Internet providers
- Software vendors
- Phone system providers
- Line-of-business applications
- Cloud platforms
- Printer suppliers
A managed IT service may include liaison with these vendors on the customer’s behalf.
If it does, the agreement should explain the extent of this responsibility.
Having an MSP coordinate third-party suppliers can be particularly valuable because it prevents the customer being passed between several companies when something goes wrong.
18. IT Documentation
A professional MSP should maintain documentation about the customer’s IT environment.
This may include:
- Network configuration
- Device inventories
- User information
- Microsoft 365 configuration
- Supplier details
- Licence information
- Backup configuration
- Security controls
- Administrative credentials
- Recovery procedures
The agreement should explain what documentation is maintained and how sensitive information is protected.
19. Asset Management
Businesses should know what IT equipment they own and how old it is.
The managed service may therefore include maintaining an asset register.
This might record:
- Device type
- Manufacturer
- Model
- Serial number
- User
- Location
- Purchase date
- Warranty
- Operating system
- Replacement date
Asset information can then support long-term technology planning.
20. Cybersecurity and IT Reporting
A managed service should provide management with visibility.
The agreement should therefore explain what reporting the customer will receive.
Reports might include:
- Support ticket volumes
- Response performance
- Device health
- Patch compliance
- Backup status
- Cybersecurity alerts
- Vulnerabilities
- Microsoft 365 security
- Equipment lifecycle
- Recommendations
The objective should not simply be to produce technical statistics.
Reports should help directors and managers understand risk, performance and future investment requirements.
21. Strategic IT Reviews
For growing businesses, managed IT should include more than fixing day-to-day problems.
Regular strategic reviews can help the organisation plan ahead.
These might cover:
- Technology roadmap
- IT budget
- Cybersecurity risks
- Hardware replacement
- Microsoft 365
- Cloud strategy
- Business continuity
- New offices
- Business growth
- Mergers or acquisitions
- AI adoption
- Digital transformation
Some MSPs provide this through a vCIO or strategic technology review service.
If strategic reviews are included, the agreement should specify how frequently they take place.
22. Customer Responsibilities
A managed IT agreement should not consist only of provider responsibilities.
The customer will normally have responsibilities too.
These may include:
- Informing the MSP about new employees
- Informing the MSP when staff leave
- Following agreed security policies
- Providing reasonable access to systems
- Keeping contact information updated
- Approving recommended changes
- Maintaining appropriate insurance
- Reporting suspected cybersecurity incidents
- Using supported hardware and software
Clearly defining these responsibilities helps the MSP and customer work effectively together.
23. Supported and Unsupported Technology
MSPs cannot reasonably support every piece of technology indefinitely.
The agreement should therefore explain the provider’s policy for unsupported systems.
Examples might include:
- Out-of-support Windows versions
- Very old servers
- Unsupported applications
- Consumer networking equipment
- Legacy firewalls
- Unlicensed software
A provider may continue supporting these systems on a reasonable-efforts basis while recommending that they are replaced.
24. Data Protection and Confidentiality
An MSP may have significant access to its customers’ systems and information.
The agreement should therefore contain appropriate confidentiality and data protection provisions.
This can include:
- How customer data is handled
- Who can access systems
- How administrative credentials are protected
- Responsibilities where the MSP processes personal information
- Security requirements
- Confidentiality obligations
Where appropriate, businesses should also ensure that suitable data processing arrangements are in place.
25. Pricing
Pricing should be transparent.
The agreement should explain:
- Monthly support charges
- Per-user or per-device pricing
- Licence costs
- Additional services
- Project charges
- On-site charges
- Out-of-hours charges
- Annual price reviews
Customers should also understand what happens when their number of employees or devices increases or decreases.
26. Contract Length
The agreement should clearly specify the minimum contract period.
Common arrangements may include:
- Monthly rolling agreements
- 12-month agreements
- 24-month agreements
- 36-month agreements
Longer agreements are not necessarily a problem.
However, customers should understand the commitment they are making and any notice period required.
27. Termination and Exit Arrangements
One of the most overlooked parts of an IT support agreement is what happens when the relationship ends.
The agreement should explain how either party can terminate the contract.
It should also cover the MSP’s responsibilities during transition.
For example:
- Supplying IT documentation
- Transferring administrative access
- Providing passwords securely
- Assisting the incoming provider
- Exporting relevant information
- Removing management software
- Transferring licences where possible
A professional MSP should make it possible for a customer to move provider without deliberately making the process difficult.
28. Ownership of Accounts, Domains and Data
Businesses should retain appropriate control over their technology.
The agreement should make clear who owns:
- Domain names
- Microsoft 365 tenants
- Customer data
- Cloud services
- Software licences
- Documentation
- Backup data
Wherever practical, important business services should be registered in the customer’s name rather than being owned solely by the MSP.
This can make changing provider significantly easier.
What Questions Should You Ask Before Signing a Managed IT Agreement?
Before signing, consider asking:
- What exactly is included in the monthly fee?
- What services cost extra?
- What are your helpdesk hours?
- What are your response targets?
- Is on-site support included?
- What cybersecurity services are included?
- Do you manage Microsoft 365?
- Are backups included?
- Who monitors backups?
- Do you provide cybersecurity reporting?
- Do you carry out strategic IT reviews?
- What happens when we add employees?
- How are major projects charged?
- What happens if we want to change provider?
- Who owns our Microsoft 365 tenant and domain?
- What documentation will you provide when the agreement ends?
If the answers are unclear before signing the agreement, they are unlikely to become clearer afterwards.
What Are the Warning Signs of a Poor IT Support Agreement?
Businesses should be cautious where an agreement:
- Uses vague descriptions of the service
- Contains no meaningful service levels
- Does not define exclusions
- Provides little information about cybersecurity
- Does not specify backup responsibilities
- Contains unclear additional charges
- Gives the MSP ownership of important customer accounts
- Makes leaving excessively difficult
- Includes no transition arrangements
- Provides no strategic review process
The agreement should create clarity for both sides rather than simply protect the provider.
Should a Small Business Have a Formal Managed IT Agreement?
Yes.
Even relatively small businesses may depend heavily on:
- Microsoft 365
- Internet connectivity
- Business applications
- Cloud systems
- Cybersecurity
- Remote working
- Company data
If these systems are essential to the operation of the business, the responsibilities for managing them should be formally documented.
A written managed IT agreement gives both the customer and the provider a common understanding of how the service should operate.
A Managed IT Agreement Should Provide Clarity, Not Complexity
The best managed IT agreements are not necessarily the longest.
They are the ones that clearly answer the important questions:
What are you responsible for?
What is the MSP responsible for?
How quickly will problems be handled?
What security protections are included?
What costs extra?
How will our technology be reviewed?
What happens if we decide to leave?
If those points are clear, both the business and the IT provider have a much stronger foundation for a successful long-term relationship.
Looking for Managed IT Support in Scotland?
Stratiis provides managed IT support, cybersecurity, Microsoft 365, cloud, connectivity and strategic technology services to small and mid-sized organisations across Scotland.
Our approach goes beyond simply responding to IT problems.
We help organisations understand their technology risks, improve cybersecurity, plan future investment and build a technology environment that supports the wider goals of the business.
If you are reviewing your current managed IT agreement, considering changing provider or want to understand what should be included in a modern managed IT service, speak to Stratiis about a Managed IT & Cybersecurity Review.
Reviewing your current IT support agreement?
Book a Managed IT and Cybersecurity Review
Related Articles
How Much Should Managed IT Support Cost for a 10–100 Employee Business in Scotland?
The 7 Warning Signs Your Business Has Outgrown Its Current IT Provider
How to Switch IT Providers Without Disrupting Your Business
What Should Business Leaders Ask During an MSP Review Meeting?
What Cybersecurity Protections Does a 50-Person Business Actually Need?
What Does a Strategic vCIO Do for a Growing Business and Is It Worth It?


