Support expectations
Which users, devices and locations are covered? What is the support intake and escalation path? Which requests or projects are outside recurring scope?
Managed IT Buying Guide
A useful provider conversation should make responsibility visible. Ask what is included, what is excluded, who owns Microsoft 365, security, backups, escalation and documentation, and how the provider will help leadership understand unresolved risk and priorities.
What should you ask an IT support company? Start with scope, exclusions and ownership. A strong answer explains who handles day-to-day support, Microsoft 365 and identity, endpoints, cybersecurity escalation, backup and recovery, vendors, documentation, onboarding and offboarding, reporting and strategic planning — including what the provider does not own.
Before the sales call
Provider comparisons are easier when you know which users, systems, vendors and recovery expectations matter to the business. Use the questions below to compare operating responsibility rather than marketing labels.
Which users, devices and locations are covered? What is the support intake and escalation path? Which requests or projects are outside recurring scope?
Who administers users, privileged roles, onboarding, offboarding, licensing and access changes? How are responsibilities shared if internal IT remains involved?
Which endpoint, identity, email or incident-response responsibilities belong to the provider, which belong to other vendors, and what requires a separate scope?
What is actually backed up, what is excluded, who monitors failures, how restores are requested and what evidence is available from testing?
Who maintains administrative ownership, asset and vendor information, diagrams or dependency notes, and how can authorized leadership obtain it when needed?
How will the provider communicate unresolved risks, lifecycle needs, project priorities and decisions instead of only closing support tickets?
Ask for a plain-language description of the recurring service. The important question is not whether the package has a familiar label such as “managed IT”; it is whether the business can tell what the provider owns.
Security is rarely one product or one provider responsibility. Ask the provider to identify the controls and escalation activities it will own, what is shared, and what remains outside scope.
A provider should be able to explain both how it will enter the environment and how control can later be transferred. That reduces dependence on undocumented credentials or one person’s memory.
| Area | Ask the provider to make explicit |
|---|---|
| Support | Users/devices covered, intake, escalation, exclusions and project boundaries. |
| Microsoft 365 | User lifecycle, administrator roles, identity ownership and collaboration responsibilities. |
| Cybersecurity | Controls managed, escalation ownership, other-vendor dependencies and evidence/reporting. |
| Backup & recovery | Protected scope, exclusions, monitoring, restore process and testing evidence. |
| Infrastructure & vendors | Network/server responsibilities, vendor coordination and escalation paths. |
| Documentation | What is maintained, where it is stored and how authorized leadership can obtain it. |
| Planning | How risks, lifecycle needs and projects are prioritized and communicated. |
| Transition | Onboarding steps, access transfer and the eventual offboarding/handover process. |
Scallex perspective
Scallex uses the same questions when discussing managed or co-managed IT: what has to work, who owns each responsibility, what evidence exists and what the next priority is. A provider should be able to describe boundaries without relying on invented guarantees or vague “everything is covered” language.
Next step
If the questions above reveal unclear ownership across support, security, Microsoft 365, recovery or vendors, use the Free IT Assessment for a broader review.