Skip to main content
Techx4u, Inc

Managed IT

What a Managed IT Contract Should Include

A managed IT contract should define responsibility, response times, security, maintenance and exclusions clearly. Here is what to check before signing an MSP agreement.

· 10 min read

The contract should define who is responsible for what

A managed IT contract is not just a document that says an MSP will provide IT support. It should define what the provider is responsible for, what remains with your business, how problems are handled, and what happens when something falls outside the agreement.

This matters because vague contracts create arguments when something goes wrong. "Unlimited support" sounds useful until you discover that server maintenance is excluded, security incidents are billed separately, or after-hours response only means someone receives an alert. A good contract removes that ambiguity before you need the service.

The starting point should be a clear description of the environment being managed. That might include endpoints, servers, networks, Microsoft 365, cloud services, backups and specific business applications. If a system is important but not listed, do not assume it is covered.

Define the actual services, not just the label

"Managed IT" can mean very different things between providers. One MSP might handle user support and device management. Another might also manage servers, Microsoft 365, backups, patching, network infrastructure and security operations.

Your contract should identify the actual services included. Common areas include:

  • Help desk and user support.
  • Endpoint management and monitoring.
  • Windows and application patching.
  • Server maintenance.
  • Network and firewall management.
  • Microsoft 365 administration.
  • Backup monitoring and recovery assistance.
  • Antivirus, EDR or other endpoint security.
  • Account and access management.
  • Hardware and software coordination.
  • IT documentation and asset management.

You should also understand whether these services are proactive or reactive. If patching is included, for example, does the provider simply report missing updates or actually schedule, deploy and verify them? If backups are included, does the provider monitor successful jobs and test restores, or only configure the backup software?

A useful managed IT services agreement should make these responsibilities explicit rather than relying on assumptions about what the phrase "fully managed" means.

Service levels need more detail than a response-time table

Service level agreements are often reduced to response times, but response is only one part of the service. A provider might promise a response within 30 minutes while making no commitment about when the problem will actually be resolved.

Look for definitions of priority levels and the conditions that trigger them. A complete SLA should explain what qualifies as a critical incident, a high-priority issue, a normal request and a low-priority request.

It should also explain how the clock works. Does the SLA operate 24/7 or only during business hours? Does the timer stop when the provider is waiting for information from you? Are planned maintenance windows excluded?

Resolution targets can be difficult to guarantee because the cause of an incident may be outside the provider's control. That is not necessarily a weakness. An honest contract can distinguish between response commitments and resolution targets instead of promising unrealistic fixes for every situation.

You should also establish the escalation process. If a critical server is unavailable, who gets involved? When does an engineer escalate to a senior engineer, vendor or specialist? A good process matters more than a colourful SLA table.

Security and maintenance should not be vague extras

A common mistake is treating cybersecurity as something separate from managed IT. In reality, everyday IT operations directly affect security. Unpatched endpoints, excessive administrator permissions, stale accounts and unmanaged devices are operational problems with security consequences.

The contract should therefore state which security responsibilities are included. Depending on the service, this could cover endpoint protection, EDR management, patching, account controls, security alert handling and configuration reviews.

It should also be clear what happens during a security incident. Is the MSP expected to investigate suspicious activity? Can it isolate an endpoint? Who has authority to disable an account? Does incident response have a separate fee?

The same principle applies to backup and recovery. "Backups monitored" is not the same as "data recovery included". Define what is monitored, what retention is expected, who performs restores and whether recovery work is included or charged separately. If you are reviewing these areas, a broader data protection service can help separate backup technology from the operational responsibility around it.

What people get wrong when comparing MSP contracts

The biggest mistake is comparing providers mainly on monthly price. A cheaper contract can look attractive because it excludes activities that another provider has included. You then pay separately for projects, after-hours work, security incidents, onboarding, documentation or infrastructure changes.

Another mistake is assuming "unlimited support" means unlimited engineering work. It may cover unlimited tickets for supported users while excluding projects, third-party applications, major migrations or work caused by unsupported equipment.

You should also pay attention to exclusions. Every provider needs them; no MSP can reasonably take responsibility for every technology your business might encounter. The problem is not having exclusions. The problem is discovering them during an outage.

Hardware ownership is another area that causes confusion. Confirm whether hardware purchases are included, whether the provider receives commissions from suppliers, and who owns equipment purchased as part of the agreement.

Finally, check what happens when the contract ends. You should know who owns configurations, documentation, credentials and data, how administrator access is transferred, and whether there are exit or transition charges.

What to do in order

Start by creating a list of the systems and services your business expects the MSP to manage. Include endpoints, servers, networks, Microsoft 365, cloud platforms, backups, security tools and important third-party applications.

Then turn that list into explicit responsibilities. For each item, establish who monitors it, who maintains it, who responds to problems, who performs changes and whether the work is included in the monthly fee.

Next, review the SLA. Check priority definitions, response times, operating hours, escalation procedures, planned maintenance and any resolution commitments. Do not accept a table of response times without understanding how those terms actually work.

After that, read the exclusions and additional charges carefully. Ask what becomes a project, what is billed hourly, what requires approval and what happens during a major incident.

Finally, review the exit terms before signing. You are not planning to leave, but the contract should still explain how access, documentation, configurations and data are handed back. A good managed IT relationship should be easy to operate when things are going well and clear about responsibilities when they are not.

Common questions

What should a managed IT contract include?
A managed IT contract should define the systems covered, included services, support hours, priority levels, response targets, security responsibilities, maintenance, backup responsibilities, exclusions, additional charges and termination terms. It should also identify who owns data, documentation and administrative access. The goal is to remove ambiguity about responsibility before an operational or security problem occurs.
What should I check before signing an MSP contract?
Check exactly what technology is covered, what support is included, how incidents are prioritised, when support is available and which activities cost extra. Pay particular attention to exclusions, project charges, security incident handling, backup recovery, hardware responsibilities and contract exit terms. A low monthly price is meaningless if important operational work sits outside the agreement.
Does an MSP contract include cybersecurity?
It depends on the contract. Some managed IT agreements include endpoint protection, patching, account management and security monitoring, while others treat cybersecurity as a separate service. The contract should state exactly which security tools are managed, who responds to alerts, what incident response includes and whether security assessments or remediation work are charged separately.
What happens when a managed IT contract ends?
The contract should explain how the transition works, including transfer of administrator access, documentation, configurations, credentials and business data. It should also state any notice period, termination fees and transition charges. A sensible agreement makes ownership and handover clear so the business is not dependent on the MSP simply because critical information remains undocumented or inaccessible.
Share

Let's talk about your environment

Tell us what you are running and what worries you. We will come back with a straight assessment and a costed plan — no obligation.