Most contract problems with an IT provider start before anyone signs. The proposal says “full support,” the business hears “everything is covered,” and nobody checks what that means until a server fails or a laptop gets compromised. Knowing what to ask before hiring a managed service provider is the best way to close that gap. It lets you compare providers on how they work, not just on price and promises.
This list is built around the problems that cause real disruption: unclear scope, backups nobody has tested, slow help desk response, and vendors with more access than anyone remembers granting.
What to Ask Before Hiring a Managed Service Provider: Scope and Ownership
Start with the plainest question: what exactly is covered, and what isn’t?
A business with 40 employees might assume the provider handles the office internet, the phones, Microsoft 365, the line-of-business software, and the printers. The contract may cover only workstations and the help desk. When the internet drops at one location, the provider says it’s the carrier’s issue, the carrier says it’s the firewall, and your staff sit idle while two vendors point at each other.
Ask these before you go further:
- Which systems, locations, and devices are included, and which are excluded?
- Who talks to our internet carrier, software vendors, and phone provider when something breaks?
- If we already have an internal IT person, who owns what? Some arrangements work well as co-managed support, but only when the split is written down.
- Who is our named contact, and what happens when that person is out?
- What does onboarding involve, and how long before you have a complete inventory of our systems?
The last question matters more than it looks. A provider that can’t tell you how it will document your environment in the first 30 to 60 days will probably struggle to support it later.
Questions About Security and Recovery
Security is where vague answers cost the most. Current guidance for smaller organizations treats multi-factor authentication, endpoint protection, email security, access controls, patching, backups, employee awareness, and incident response as connected pieces. A provider that talks only about antivirus or only about MFA is giving you part of the picture.
Useful questions:
- Which of those pieces are included in the price, and which cost extra?
- Who reviews Microsoft 365 settings such as administrator accounts, conditional access, sharing controls, and suspicious sign-ins? And how often?
- What happens in the first 24 hours of a suspected security incident? Who calls whom?
- What is your process when an employee leaves, for both accounts and devices?
Ask about backups in a specific way
“Do you do backups?” will always get a yes. Ask better questions instead:
- What is being backed up, and what isn’t? Microsoft 365 features shouldn’t automatically be treated as a full backup and recovery plan, so ask how email, files, and SharePoint data are protected.
- Are backup copies protected from tampering, and is access separated from everyday admin accounts?
- When was the last full restore test, and can you show me the result?
- What are the recovery time and recovery point targets? In plain terms: how long could we be down, and how much recent work could we lose?
Picture a firm that learns its nightly backup has been failing for three weeks only when a file server dies. The backup “existed.” Recovery didn’t. A provider who tests restores on a schedule and shares the results has already thought about that day.
Questions About Support, Reporting, and Accountability
Help desk speed shapes how your staff feel about IT every day. A slow response to a locked account or a broken Outlook profile costs you an hour or two of someone’s workday, repeated across the office.
Get specifics:
- How do employees request help: phone, email, portal, or all three?
- What are your response times, and how do you define response versus resolution?
- Is after-hours support included, and what counts as an emergency?
- What reports will we get, and who walks us through them?
That last one is a good test of the relationship. Ticket volume, repeat issues, and time-to-resolve data can reveal hidden problems. If the same printer, VPN, or Wi-Fi complaint keeps coming back, a good provider should flag the pattern and propose a fix, not close the ticket for the fifth time. Ask for an example of how they’ve handled a recurring problem, with client details removed.
Also ask how they handle planning. Hardware ages, licenses renew, and offices move. A provider who offers a periodic review of your technology roadmap and budget makes cost easier to predict. One who only reacts will leave you with surprise invoices.
A Common Blind Spot: Skipping the Exit and Access Questions
Most buyers focus on what happens when things go well. Few ask what happens if the relationship ends.
Before signing, find out:
- Who owns the documentation, passwords, and admin accounts? You should hold the keys to your own systems.
- What is the contract term, and what does it take to leave?
- How will the provider’s own access to your systems be controlled, logged, and removed afterward?
Vendor access is a real risk. If a former IT company still has admin rights to your Microsoft 365 tenant or firewall months after leaving, you have an unmanaged door into your business. The same applies to your current vendors, so ask the provider how it reviews and cleans up third-party access, including when it takes over from someone else.
The consequence of skipping these questions is rarely dramatic on day one. It shows up later: a delayed recovery because no one knows where the credentials are, a compliance review that turns up accounts nobody can explain, or a painful transition because the old provider holds the documentation.
What This Means for Your Business
The goal isn’t to quiz a provider until they give up. It’s to see whether they answer clearly, put things in writing, and show evidence such as restore test results, sample reports, and a defined onboarding process. Vague answers now usually mean vague service later.
Write down your own priorities first, such as downtime tolerance, security obligations, and which systems your staff can’t work without. Then compare providers against those, not against a generic feature list. If you’re also weighing outside help against your current setup, our guidance on managed IT support for growing businesses explains how these arrangements typically work.
If you’d like a second opinion on a proposal or a list of questions tailored to your setup, the TECHZN team is happy to talk it through, with no pressure to switch.











