All Resources
Managed IT Services

What Belongs in a Managed IT Services Agreement

A managed IT services agreement is the document that defines what you're actually buying from an MSP, and two contracts that look similar on the surface can be very different underneath. This guide breaks down what belongs in a modern managed services contract so you can read any proposal and immediately spot what's missing.

Published July 22, 2026 11 min read Greater Sudbury & Ontario

How to read a managed IT services agreement

Before comparing line items, know what you're looking at. A proper MSP agreement has three parts: a scope of service that lists what's covered, a service-level agreement (SLA) that defines response times, and a pricing schedule that shows per-user or per-device rates plus any excluded work. If a proposal is missing any of those three, ask for them in writing before signing.

Monitoring

Continuous monitoring on every managed device — workstations, servers, firewalls, and switches — with automated alerts for issues that need attention. Monitoring by itself is not enough; the agreement should specify who reviews alerts and how they're actioned.

Patch management

  • Windows and macOS operating system patching
  • Third-party application patching (browsers, PDF readers, Zoom, Teams, VPN clients, etc.)
  • Firmware updates for managed servers and network gear
  • Maintenance windows agreed with the customer
  • Rollback plan if a patch causes issues

Help desk

Unlimited remote help desk during business hours is standard in most Sudbury MSP agreements. Confirm the specific hours of coverage, how after-hours issues are handled, and how tickets are opened (phone, email, portal, chat).

Endpoint security

Modern endpoint detection and response should be deployed and actively managed by the MSP on every managed device. Consumer antivirus is not enough. The agreement should name the specific product and confirm the MSP is monitoring alerts, not just installing the agent.

Backup monitoring

Backup jobs should be monitored daily, with alerts on failures and a documented restore test schedule. If backup is listed as "customer responsibility," price out the true cost of adding it before signing.

Microsoft 365 administration

  • Tenant configuration and hygiene
  • Licence management and true-ups
  • Identity administration and MFA enforcement
  • Conditional Access and sign-in policies
  • Mailbox, SharePoint, and Teams management
  • Backup of Microsoft 365 data through a third-party tool

Reporting

Monthly or quarterly reporting on tickets, patching, backup, security events, and hardware age. Reports without a review conversation are just PDFs — the agreement should specify how often you'll actually sit down with your account lead.

Vendor management

The MSP should coordinate with your ISP, phone provider, printer vendor, and line-of-business software providers so you're not stuck in the middle of vendor arguments. Confirm this is included and not billed hourly.

Onboarding

Every real MSP agreement starts with a one-time onboarding: inventory, documentation, monitoring deployment, security stack rollout, credential vaulting, and backup verification. Be wary of any provider whose onboarding fee is suspiciously low.

What's commonly excluded

  • Major project work (server migrations, office moves, Microsoft 365 migrations)
  • Third-party software licences (usually pass-through)
  • Hardware and hardware procurement
  • After-hours or weekend work outside of documented coverage
  • Cabling and physical infrastructure projects
  • Custom development or line-of-business application customization

Service-level expectations

The agreement should include an SLA with defined priority levels (critical / high / normal / low), response targets for each, and an escalation path. Look for concrete numbers, not vague "best effort" language.

Frequently asked questions

Is Microsoft 365 licensing included in a managed IT agreement?

The administration of your Microsoft 365 tenant should be included. The actual licensing fee is usually passed through at Microsoft's list price or slightly above.

What's usually excluded from managed IT agreements?

Major projects, hardware, software licences, cabling, and after-hours work outside of the documented coverage window are the most common exclusions. Every reputable MSP puts these in writing.

How do agreements handle special requests?

Requests within the documented scope are usually included. Anything outside scope — a new server, an office move, a new site build — is quoted as a project.

Should the SLA guarantee uptime?

Uptime guarantees are common for hosted services the MSP directly controls (like their own cloud offerings). For your on-premise environment, the SLA should cover response and resolution targets rather than uptime, because uptime depends on hardware, ISP, and other factors outside the MSP's control.

Can we ask for changes to a proposed agreement?

Yes. Any MSP that refuses to adjust a proposed scope of service to fit your business is a warning sign. Reasonable changes are normal.

Book a free 30-minute IT assessment

See exactly where your business technology stands and get a clear, no-pressure plan for what to fix first — no obligation and no sales pressure.

Keep exploring

Related services, locations, and resources

Related services

Related resources