Managed IT questions,
answered plainly.
Choose a topic, open a question, and follow the related guide for examples and next steps.
Choosing and verifying a provider
What does an MSP actually do?
An MSP operates the technology responsibilities listed in an ongoing agreement. These may include employee support, device maintenance, cloud administration, networking, security operations, and planning. The service schedule should name covered systems, hours, owners, exclusions, and additional charges.
How many providers should we compare?
A manageable starting point is three qualified finalists, but that is a planning suggestion rather than a rule. First eliminate candidates that cannot meet mandatory requirements. Give the remaining providers the same environment summary and scenarios so you can compare evidence.
How do we verify a provider’s claims?
Ask for dated evidence that matches the exact service: a redacted support report, a recovery-test example, an escalation walkthrough, or a comparable customer reference. Check the entity, scope, and period covered by certifications or assessments. Mark claims without supporting evidence as unverified.
Does a certification guarantee good service?
No. Establish whether it applies to an individual, an organization, a management system, or a specific service. Check current scope and validity with the appropriate issuer or documentation. Then evaluate the team and processes that would actually support your business.
What should we ask a customer reference?
Ask about onboarding, the last difficult support event, unexpected charges, staff changes, and follow-through. A reference with similar size, applications, and coverage needs is more useful than a general endorsement. Avoid asking for confidential incident or customer information.
Should the lowest-priced provider be eliminated?
No. First normalize scope, licenses, coverage, onboarding, and expected extra work. A lower total may reflect efficiency or a different service boundary. Investigate the explanation and compare evidence of delivery before deciding.
Pricing and agreements
How much does managed IT cost in the Bay Area?
This guide does not publish a verified regional price survey. Obtain written quotes against the same quantities and service schedule. Compare recurring services, licenses, onboarding, projects, travel, and exit costs. The pricing guide includes clearly labeled invented figures to demonstrate the calculation.
What is the difference between per-user and per-device pricing?
Per-user pricing ties a fee to each supported person; per-device pricing ties it to defined equipment. Both need clear inclusion rules. Check shared equipment, contractors, servers, mobile devices, seasonal staff, and minimum quantities before comparing the headline rate.
What does “unlimited support” mean?
Only the agreement can define it. Ask which people, systems, applications, hours, channels, and activities are covered. Projects, travel, after-hours work, and remediation may be excluded. Require written examples of included and separately billable work.
How should we compare first-year cost?
Multiply the normalized monthly recurring total by twelve, then add onboarding, agreed remediation, and a consistent project allowance. State assumptions for taxes, hardware, headcount changes, and annual increases. Use the same assumptions for each finalist.
What happens when employee numbers change?
Review minimum commitments, the billing census date, notice requirements, and how reductions differ from additions. Software subscriptions may have separate terms. Ask for a written example of the bill after a headcount change rather than assuming it changes immediately.
Which contract terms deserve attention?
Review scope, exclusions, term, renewal notice, increases, quantity minimums, access ownership, incident responsibilities, and exit assistance together. Check which document controls when schedules conflict. Qualified legal advice may be needed for enforceability and liability questions specific to the agreement.
Who should own our domains and cloud accounts?
The business should retain ownership and authorized access to essential domains, tenants, data, and documentation. The MSP may administer them. Record business ownership, emergency-access arrangements, and handover procedures before onboarding.
Support and Bay Area coverage
Do we need an MSP based near our office?
You need credible service at the places where hands-on work is necessary. A nearby address alone does not establish dispatch capacity. Ask for commitments by location, travel charges, replacement-equipment arrangements, and the role of any subcontractors.
Is on-site support included?
Do not assume so. Distinguish planned visits, emergency dispatch, project work, travel time, mileage, parking, and minimum charges. Put the relevant rules in the service schedule for every office or jobsite.
What is a good response time?
Define impact and urgency first, then negotiate targets suited to the business. Distinguish acknowledgment, meaningful work, restoration, and final resolution. Ask when clocks run or pause and how missed targets and aged tickets appear in reports.
Does 24/7 monitoring mean 24/7 support?
No. Monitoring detects events; intake records requests; a staffed or on-call response service investigates and acts. Ask who responds overnight, what authority they have, which systems are covered, and whether extra charges apply.
How do we compare support for multiple offices?
Create a location schedule with addresses, hours, contacts, access arrangements, and required hands-on work. Walk through two simultaneous incidents. Ask how dispatch is prioritized and whether travel or coverage terms differ between locations.
Can remote employees outside the Bay Area be supported?
Ask explicitly about time zones, device management, shipping, returns, and local hands-on assistance. Remote troubleshooting can cover many issues, but hardware replacement and specialist applications may need separate arrangements.
Security, cloud, and recovery
Is cybersecurity automatically included in managed IT?
Coverage varies by agreement. Ask who monitors, investigates, contains, communicates, and supports recovery. A security tool list does not establish an operated response service. Define hours, authority, reporting, and exclusions.
How should we assess the MSP’s own access to our systems?
Ask how privileged access is granted, reviewed, recorded, and removed, including access by subcontractors. Establish customer visibility and emergency access. CISA’s guidance for MSP customers provides a useful starting point for discussing outsourcing risk.
Is an MSP responsible for all compliance obligations?
No. An MSP can operate agreed controls and supply evidence, but its service does not automatically satisfy an organization’s obligations. Determine the applicable requirements with responsible business and qualified specialist owners, then document the provider’s exact tasks.
Does Microsoft 365 need a separate recovery plan?
Yes: define which workloads, deletion scenarios, retention needs, and recovery objectives must be covered. Microsoft offers backup capabilities, and providers may propose other products. Check current documentation and test the chosen approach; do not assume a productivity license covers every recovery requirement.
What is the difference between RTO and RPO?
Recovery time objective is the target time to resume a system or process. Recovery point objective describes acceptable data loss measured in time. Both are business requirements to validate against the recovery design, rather than guarantees that follow from having backups.
How do we know backups actually work?
Ask for a representative restoration result showing the data or system restored, validation by the appropriate owner, elapsed time, and remaining issues. A successful backup job is useful evidence of collection, but it does not by itself demonstrate usable recovery.
What should we do if we suspect an active incident?
Use your organization’s approved incident-response and escalation process immediately. Contact the designated IT/security responder through a trusted channel. This site and its matching form are not monitored incident-response services; do not submit credentials, sensitive logs, or incident evidence here.
Onboarding, offboarding, and switching
How long does MSP onboarding take?
The plan depends on access, inventory, applications, locations, tooling, and remediation. Ask for phases with deliverables and acceptance criteria rather than relying on a generic duration. Our 90-day guide is a planning sequence, not a universal completion promise.
What should happen before support goes live?
Confirm support channels, authorized contacts, access, critical-system ownership, escalation, monitoring, and recovery responsibilities. Test a representative request and document exceptions. Employees should know how to obtain help on launch day.
Can we change providers without replacing everything?
Often the work can be scoped around existing systems, but licensing, management tools, backup products, and contract restrictions may affect the transition. Request a dependency inventory and identify what transfers, what must change, and what requires separate approval.
When should we remove the outgoing provider’s access?
Use an agreed handover plan. Validate incoming access, support, monitoring, and recovery before revoking permissions that still support continuity. Then remove former access, rotate appropriate secrets, reconcile integrations, and document completion. Security incidents may require a different authorized response.
Who approves employee onboarding and offboarding?
An authorized business role should confirm identity, permissions, and timing; IT performs the technical work. Include application owners where necessary. Role changes should remove obsolete permissions as well as add new ones.
What should we check in a monthly service review?
Review previous actions, aged and reopened tickets, recurring problems, security exceptions, recovery evidence, billed quantities, and upcoming decisions. Finish with a short record of owners, dates, and evidence needed to close each action.
Using this guide and requesting a match
Are the examples real provider quotes or case studies?
No. Examples are labeled as illustrative. We do not present the sample budgets, scenarios, or scoring weights as verified market data, provider performance, or customer results. Use them to structure questions and replace the assumptions with your own evidence.
Does this site rank or certify MSPs?
The current site publishes buyer education and accepts matching requests. Its guides are not an audited provider ranking or certification scheme. Evaluate actual provider evidence and contract terms before selecting a service.
Does submitting a request create a contract?
The request form is free and does not obligate you to hire a provider. Availability and suitability are not guaranteed. Agree any eventual scope, charges, and terms directly through the appropriate provider contracting process.
Can providers compensate the guide?
The site discloses that some participating providers may compensate it. Treat a commercial introduction as one input to your own evaluation. The editorial policy explains the current limits of the guide; it does not claim exhaustive market coverage or audited provider rankings.
What information should we put in the request?
Share only basic business contact information, location, team size, needs, and timing. Keep the description high level. Do not include passwords, authentication codes, patient or client records, confidential system exports, or incident evidence. Read the data-use notice before submitting.