
Tech ConversionInsights28 April 2026Updated 6 October 202610 min
How to choose a managed service provider
How to choose a managed service provider: how the models differ, what an SLA promises, who owns your tenant and licences, and what the exit clause says.
WordsMohammed Imran M
Choosing a managed service provider is one of those purchases where the sales process tells you very little and the contract tells you almost everything. Every provider in the shortlist will say the same words about proactive monitoring and partnership. The differences that matter to you are in the scope schedule, the service levels, the ownership of your accounts and the terms for leaving.
This guide is written from the buyer's side. It assumes you are technically literate, you have been pitched at least twice this month, and you would like to know which questions separate the providers, because that is most of how to choose a managed service provider.
What managed is supposed to mean
The original idea is straightforward. Instead of paying for hours when something breaks, you pay a predictable monthly fee and the provider takes responsibility for keeping things working. The incentive is meant to flip: under break-fix, an outage is revenue for the provider, and under a managed agreement it is cost. That flip only actually happens if the agreement is written so the provider carries the cost of problems, which is exactly the thing to read for.
The shapes on offer
Four models cover nearly everything being sold, and mixing them up is how quotes end up incomparable.
- Break-fix: you call, they bill. Predictable only in the sense that the invoice follows the incident. Sensible for a very small operation with tolerant systems
- Block hours: a bucket of prepaid time, drawn down as used. Cheaper than it looks until the bucket becomes the reason nobody reports small problems
- Fully managed: a monthly fee covering defined services for defined assets. The point of the model is the shifted incentive, and it works when the scope is written honestly
- Co-managed: the provider works alongside your own IT person or team, usually taking the after hours cover, the tooling and the specialisms. Under-considered, and often the right answer for a firm that already has somebody good
When you compare quotes, establish which model each one is before comparing the figures. A fully managed price and a co-managed price are answers to different questions.
Read the service levels as a response promise
Nearly every service level agreement you will be handed commits to a response time, not a resolution time. That is defensible, since a provider cannot promise how long a third party's outage takes to clear. It is also not what most buyers think they are reading.
Work through the definitions in the document rather than the summary table.
- What counts as a response? An automated ticket acknowledgement is not a human looking at your problem, and some agreements are written so that it is
- Who classifies severity? If the provider decides what is critical, the service level is whatever they need it to be
- What are the covered hours, and what happens outside them? Business hours in whose time zone, and on whose public holidays
- Is there a resolution target at all, even a soft one, and what happens when it is missed
- What is the remedy? A service credit against next month's fee is the usual answer, and it tells you what the promise is worth
Our view is that a modest service level written precisely is better than a generous one written vaguely, because you can hold somebody to the first one.
Scope, and the word unlimited
Unlimited support is a pricing strategy, not a scope. It generally means unlimited requests of a defined type, for a defined list of assets, during defined hours, and everything else is a project quoted separately. That can be entirely reasonable. What is not reasonable is discovering the boundary during an incident.
Ask for the scope schedule and read it for the things that will happen to you this year: an office move, a new starter and a leaver, a line of business application nobody wants to own, a failed hard disk, a phishing incident, an auditor asking for evidence, and a migration somebody in the leadership team has already promised.
Ownership of tenants, licences and domains
This is the section that costs the most when it is wrong, and it is nearly invisible during the sale. The question is simple: in whose name is everything held?
- Your cloud tenant should belong to your company, with at least one break-glass administrator account your own staff control
- Licences bought through a provider should be visible to you, with the subscription term and the renewal date in writing, since term commitments are easy to inherit unknowingly
- Administrative access should be delegated and time bound rather than permanent, which is what the modern delegated administration models exist to support
- Your domain names should be registered to your company, with your billing contact, not to the provider as a convenience
- Backups and their storage accounts should be in your name too, because a backup you cannot reach during a dispute is not a backup
One question settles most of this. If we parted company on bad terms tomorrow, which accounts would we be unable to access without your cooperation? A good provider answers it immediately and without discomfort, because they have designed for it.
Security: what is included and what is an upsell
Security is where quotes diverge most, because a thin quote can be made to look competitive by leaving out the expensive parts. Establish which of these are in the monthly fee and which appear later as a proposal.
- Multi-factor authentication enforced across all accounts, including administrative and service accounts
- Endpoint protection, and who reviews the alerts rather than only who installs the agent
- Patching for operating systems and for third party applications, which is the half that gets quietly dropped
- Email security, and what happens when a message is quarantined at an inconvenient time
- Logging and retention, including how long logs are kept and who can read them
- Phishing simulation and staff training, if it matters to you or to your insurer
Ask what happens during an incident, in writing: who leads, who communicates, what is included in the monthly fee and where the hourly work begins. A provider without a written incident process is improvising, and improvising during a ransomware event is expensive.
Backups, and the only proof that counts
Every provider backs up. Far fewer restore, and the distinction is the whole of the subject. A backup that has never been restored is a belief.
Ask when they last performed a test restore for a client of your size, what was restored, how long it took, and whether you can see the report. Then ask about immutability, since backups that an administrator can delete are the first target in a serious intrusion, and about where copies physically sit. Recovery point and recovery time objectives are worth agreeing in the contract, as a stated target rather than an aspiration, because they are what determines how much work your business would repeat after a bad day.
Compliance, for a business operating in India
If your provider handles your data, their practices become part of your compliance position. Three things are worth naming in the conversation.
- The Digital Personal Data Protection Act, 2023, at meity.gov.in/data-protection-framework, which governs personal data you hold and makes your provider a processor acting on your instructions. Those instructions should exist in the contract rather than by assumption
- The CERT-In directions on incident reporting and log retention, which place obligations on service providers and intermediaries operating in India, and which shape how quickly an incident must be reported and how long logs are kept
- Certifications, where ISO 27001 and SOC 2 are the ones asked for in enterprise procurement. A provider is certified, is working towards certification, or is aligned to the standard, and these are three different statements. Ask which one applies and ask to see the certificate or the report
A logo on a website is not evidence. In our experience a provider with a genuine certificate produces it within the hour, and one without begins explaining the difference between alignment and certification.
Onboarding is where you find out
The first sixty days tell you more than any reference call. A serious provider produces documentation you can read: an asset register, a network diagram, a list of administrative accounts and who holds them, the licence position, and a written list of risks found with a proposed order for fixing them.
If onboarding produces nothing you can keep, the provider has not documented your environment, which means the knowledge lives in the head of whichever engineer answered the phone. That is a dependency you are paying to create.
The exit clause, read before you sign
Nobody wants to negotiate the ending during the beginning, which is why this clause is so often accepted as drafted. It determines how much a poor relationship can cost you.
- Notice period, and whether the contract renews automatically if you miss the window
- What offboarding includes, whether it is chargeable, and at what rate
- How your data is returned: in what format, over what period, and who verifies it is complete
- Transfer of domains, tenants, licences and administrative credentials, with a stated timeframe
- Documentation handover, since the asset register and the diagrams are yours if the contract says they are and frequently not if it does not
- What happens to your backups after termination, and how long they are retained before deletion
How the price is built
Per user, per device, tiered, or a flat fee with a scope schedule. All of them are defensible, and what matters is that you can predict next year's invoice. Ask what makes the figure move: headcount changes, new sites, servers, out of hours work, projects, licence uplifts at renewal, and the annual increase, which should be in the contract as a mechanism rather than an intention.
The cheapest quote in a shortlist is usually cheapest because something in this article is missing from it. That is worth finding out during the comparison rather than during the first incident, and the way to find out is to put the same scope schedule in front of every provider and make them price the identical list.
The questions we would ask on the call
- Which model is this, and what would the co-managed version cost instead?
- Show me the scope schedule, and tell me three things that are outside it
- Who classifies severity, and what is the remedy when a service level is missed?
- If we left tomorrow, what could we not access without you?
- When did you last do a test restore for a client our size, and may I see the report?
- What does onboarding hand over as documents I keep?
- Which of ISO 27001 or SOC 2 applies to you, and is that certified, in progress or aligned?
The providers worth shortlisting answer the leaving question first and without hesitation. It is the cheapest piece of due diligence available to a buyer. Tech Conversion
Questions people ask about this
What does a managed service provider actually do?
A managed service provider takes ongoing responsibility for defined parts of your IT for a recurring fee, typically monitoring, patching, endpoint security, backup, user support and vendor management for a named list of assets. The purpose of the model is to shift the cost of problems onto the provider, which only happens if the scope and service levels are written to do so. If you are hiring an MSP for the first time, ask for both in writing before you compare prices.
What should an SLA actually promise?
Most service level agreements promise a response time rather than a resolution time, which is defensible but often misread. Check what counts as a response, who classifies severity, which hours and holidays are covered, whether any resolution target exists, and what the remedy is when a level is missed. A precise modest commitment beats a vague generous one.
Who should own our Microsoft licences and tenant?
Your company, in every case. The tenant should be in your name with a break-glass administrator account your own staff control, licences should be visible to you with terms and renewal dates in writing, administrative access should be delegated and time bound, and domains should be registered to your company. Ask what you could not access if you parted company tomorrow.
How do I compare quotes from different providers?
Put the same scope schedule in front of each of them and make them price an identical list, otherwise you are comparing answers to different questions. Establish the model first, then check what is excluded, what security is included rather than sold later, what onboarding hands over, and what leaving costs. The cheapest quote is usually missing something specific.

Mohammed Imran M
Founder & Director · LinkedIn
Started the firm on one rule: understand the business before recommending what it should buy.
Start a conversation
