If Microsoft 365, Teams, Windows devices, and cloud applications run your business, managed IT needs to connect user support with the administration behind it. Closing tickets is useful, but it does not establish who removes old access, maintains device policies, verifies recovery, or coordinates an application outage.
Use this checklist to define an agreement. These are responsibilities to evaluate, not a claim that every provider or Monster MSP engagement includes every item.
The service-scope checklist
For each row, record included, separately scoped, or retained internally, then name an owner. Ask for the evidence in the last column instead of accepting a feature list alone.
Scroll horizontally to compare all columns.
| Area | What the scope should answer | Evidence to request |
|---|---|---|
| User support | Which users, devices, applications, channels, locations, and hours are covered? | Intake instructions, escalation map, exclusions |
| Identity lifecycle | Who creates, changes, and removes access after authorized requests? | Joiner/mover/leaver checklist and completion record |
| Microsoft administration | Who owns licenses, service health, tenant changes, and vendor escalation? | Administrator-role inventory and change process |
| Device operations | Who handles inventory, enrollment, updates, configuration, and retirement? | Device coverage report, exceptions, lifecycle record |
| Collaboration governance | Who reviews site ownership, sharing, guests, and inactive workspaces? | Owner register and periodic review record |
| Security operations | Which signals are reviewed, by whom, and during which hours? | Alert route, triage responsibility, action authority |
| Recovery | Which data and systems are protected, and who tests restoration? | Workload inventory and dated restore-test evidence |
| Network and site systems | Who supports connectivity, Wi-Fi, firewalls, and physical dependencies? | Network diagram, vendor contacts, on-site boundaries |
| Application vendors | Who opens cases, follows up, and keeps the business informed? | Vendor register and escalation ownership |
| Planning and reporting | Who identifies recurring problems, risks, renewals, and investment needs? | Sample operational review and prioritized backlog |
A dashboard screenshot is not sufficient proof of coverage. Compare the assets in your inventory with the assets reporting into the relevant tools, and ask who investigates the difference.
Separate recurring operations from project work
Routine administration maintains an agreed environment and performs agreed repeatable changes. Projects introduce a separately scoped change, migration, or new capability. The boundary should be explicit enough that a new employee does not trigger an argument over scope.
Scroll horizontally to compare all columns.
| Request | Possible recurring scope | Work often scoped separately |
|---|---|---|
| New employee | Approved account, standard license, and existing device setup process | Designing a new onboarding workflow or application integration |
| Microsoft 365 access | Approved membership or permission change | Restructuring SharePoint information architecture |
| Device policy | Maintain and troubleshoot approved settings | Initial Intune migration or broad policy redesign |
| Office connectivity | Diagnose supported network equipment | New-site design, cabling, equipment installation |
| Business reporting | Report on agreed operational measures | Build a custom application, integration, or AI workflow |
These boundaries vary by agreement. Ask how projects are estimated, approved, documented, and handed back to support. “One partner” should make that handoff clearer; it does not mean every change is included in a recurring fee.
Keep approvals with the right people
An operating provider needs authority to do its assigned work, but should not decide business access or financial priorities alone.
- HR or an authorized manager approves employment-related access changes.
- The application or data owner approves access to sensitive business information.
- The service operator executes and records the approved change.
- Leadership accepts significant residual risk and approves spending.
- The incident lead follows agreed authority for urgent containment and escalation.
For example, an employee moving into payroll may need new access and removal of their previous access. Treat this as a business-owner approval followed by an operational checklist, not a helpdesk guess based on job title.
Questions that expose exclusions
- Are subscriptions, cloud consumption, backup capacity, and security licenses included or itemized separately?
- Are servers, personal devices, contractors, shared devices, and unsupported systems covered?
- What happens outside staffed hours, and what triggers additional charges?
- Who owns tenant administration, domains, documentation, and tooling data when the agreement ends?
- Which changes require a project, and who supports the result after launch?
- Is recovery testing included, or only backup-job monitoring?
- Are on-site visits, travel, specialist response, and application-vendor fees separate?
For Microsoft controls, verify entitlements against the exact feature and affected users; purchasing a subscription is not the same as configuring and operating it. For example, Microsoft distinguishes ordinary Conditional Access licensing from risk-based policies in its Conditional Access requirements.
Common questions
Is Microsoft 365 governance the same as user support?
No. Support resolves individual issues. Governance assigns ongoing responsibility for access, workspace ownership, lifecycle rules, and recurring reviews. They should connect, but an agreement should name both. See Microsoft 365 governance.
Does managed IT include AI and development?
Not automatically. Those may be separately scoped capabilities with their own discovery, acceptance, ownership, and maintenance requirements. A useful agreement explains how the support team receives documentation and escalation instructions for a new system.
Turn the checklist into a scope conversation
Mark the rows your team owns today and the rows nobody consistently handles. That is a more useful starting point than asking for “everything included.”
Request a Free Initial Assessment to discuss those gaps, or explore SMB IT services for the operating approach.