Ten Questions to Ask Before Choosing an MSP

Use these ten questions to evaluate managed services providers, clarify accountability, and choose practical IT support for your business.

  • Get the service scope, exclusions, and billing boundaries in writing.
  • Retain ownership of your cloud tenants, domains, data, and documentation.
  • Ask for specific security, incident response, and backup recovery practices.
  • Evaluate AI guidance as part of security, confidentiality, and governance.
  • Request a clear 90-day onboarding plan before signing an agreement.

Choosing a managed services provider (MSP) is more than outsourcing help desk tickets. The provider you select may have administrative access to your Microsoft 365 tenant, cloud resources, endpoints, backups, business systems, and sensitive information.

For a medical practice, dental office, accounting firm, law office, nonprofit, manufacturer, or growing professional services business, that decision affects daily productivity, risk, and your ability to serve clients or patients. The right provider should explain its approach clearly, document responsibilities, and help you make sound decisions without creating unnecessary complexity.

Before signing an agreement, ask these ten questions.

1. What is included, and what is not included?

Start with the scope of service. Terms such as “fully managed” can mean different things from one provider to another. Ask for a written list of included services, limits, exclusions, and optional work.

Clarify whether the agreement covers:

  • User support, endpoint monitoring, patching, and antivirus or endpoint protection
  • Microsoft 365, Google Workspace, Azure, servers, network equipment, and cloud applications
  • Backup monitoring, backup recovery testing, and disaster recovery planning
  • Vendor coordination for line-of-business applications, internet providers, phone systems, and printers
  • New-user onboarding, employee offboarding, device setup, and after-hours support
  • Strategic planning, compliance support, security reviews, and documentation

A low monthly rate can become expensive if routine work is treated as billable project labor. Ask for examples of common requests and how they would be billed.

2. Who owns the accounts, data, and documentation?

Your organization should retain ownership and administrative control of its business-critical systems. This includes domains, Microsoft 365 or Google Workspace tenants, Azure subscriptions, backups, password vaults, firewall configurations, and vendor accounts.

Ask how ownership will be documented and what happens if you change providers. A responsible MSP should be able to explain its offboarding process without hesitation.

Request confirmation that you will receive current documentation for:

  • Administrative accounts and access procedures
  • Network diagrams, device inventories, and configuration records
  • Licensing details and renewal dates
  • Backup locations, recovery procedures, and test results
  • Key vendor contacts and support agreements

This is particularly important for small firms where a founder, office manager, or one technically capable employee has historically held most of the knowledge.

3. How do you secure Microsoft 365, cloud systems, and user devices?

Most business risk does not come from a dramatic movie-style cyberattack. It often starts with a stolen password, unpatched device, exposed mailbox rule, misconfigured cloud setting, or an employee who clicks a convincing phishing message.

Ask the provider to describe its baseline security approach in plain language. For organizations using Microsoft 365, Azure, Google Workspace, or hybrid environments, discuss identity protection, multi-factor authentication, privileged access, device encryption, software updates, email security, and logging.

Useful follow-up questions include:

  • Is multi-factor authentication required for all users, including administrators?
  • How are local administrator rights controlled?
  • How quickly are critical security updates evaluated and deployed?
  • How are lost laptops and mobile devices handled?
  • What alerts does the provider monitor, and who responds after hours?

Look for a provider that explains tradeoffs honestly. Security controls should be appropriate for your risk, workflow, budget, and regulatory obligations—not copied from a generic checklist.

4. How will you support our compliance and confidentiality obligations?

Healthcare, finance, legal, and nonprofit organizations often handle information that requires careful protection. Even businesses outside regulated sectors may have contractual confidentiality obligations, payment data, employee records, or intellectual property to protect.

An MSP should not promise that a technology package alone makes you compliant. Compliance involves policies, people, process, evidence, and management oversight. However, the provider should understand how technology supports your obligations.

Ask how it can help with access controls, audit logging, encryption, retention settings, vendor risk information, security awareness training, incident documentation, and evidence for assessments. If you use electronic health record, practice management, accounting, legal case management, or payment systems, ask how the provider coordinates with those vendors.

5. What happens during a security incident or outage?

A good answer includes more than “we monitor your systems.” Ask for the provider’s incident response and escalation process. You should know who contacts you, how quickly, what information you will receive, and who has authority to make urgent decisions.

Discuss realistic scenarios:

  • A staff member’s Microsoft 365 account appears compromised
  • Ransomware is detected on a workstation or server
  • Your internet connection fails during patient appointments or month-end accounting
  • A line-of-business application is unavailable
  • A cloud backup needs to be restored

Ask whether the MSP performs recovery testing and how it measures whether backups can actually be restored. A backup that has never been tested is not the same as a recovery plan.

6. What service levels and communication should we expect?

For a two-person office, a delayed response can stop operations. For a 100-user organization, inconsistent communication can create frustration across departments. Ask how requests are prioritized, what response targets apply, and how critical issues are handled.

Also ask who will communicate with your team. Will you have a named service contact, a technical account manager, or only a ticket portal? Can your office manager or operations leader get clear updates without translating technical jargon?

Request examples of the provider’s status updates, ticket reports, and review meetings. Good communication is concrete: what happened, what is being done, what your team needs to decide, and when the next update will arrive.

7. How do you handle legacy and mixed environments?

Many small and mid-sized organizations operate in transition. You may have on-premises servers alongside Microsoft 365, a legacy accounting application, a specialized dental or medical system, older network equipment, or a mix of Windows and Apple devices.

Avoid providers that dismiss your current environment without first understanding it. At the same time, be cautious of those who simply maintain every outdated system indefinitely.

Ask for a practical modernization approach. The provider should identify immediate risks, document dependencies, prioritize improvements, and build a realistic roadmap. A manufacturer may need reliable shop-floor connectivity; a legal office may depend on document-management workflows; a practice may need to protect appointment and clinical systems. Context matters.

8. How will you advise us on AI tools and data use?

Employees may already be using Microsoft Copilot, ChatGPT, Claude, Google AI tools, or other AI services to draft messages, summarize documents, analyze data, or support research. The question is not only whether AI is useful. It is whether the intended use is appropriate for your data and business responsibilities.

Ask the MSP how it helps clients evaluate AI tools, configure identity and data controls, establish acceptable-use guidance, and distinguish approved business tools from personal accounts. If you are considering Copilot Studio, Azure-based AI, or on-premises AI infrastructure, ask about access controls, data sources, logging, cost management, and governance.

A sound provider will not treat AI as a shortcut around security, confidentiality, or human review.

9. What is the pricing model, and what could change the cost?

Ask for transparent pricing in writing. Understand the per-user, per-device, per-server, project, licensing, and after-hours components. Confirm whether onboarding, remediation, major upgrades, compliance work, and emergency response are included or separate.

It is reasonable for a provider to charge separately for significant projects. What matters is that the boundaries are clear before work begins. Ask how price changes are communicated, how often rates are reviewed, and whether you can see the licenses being billed.

Compare proposals based on scope and accountability, not only the monthly total.

10. What will the first 90 days look like?

The transition plan often reveals how organized a provider really is. Ask for a phased onboarding outline that covers discovery, documentation, access changes, security priorities, communication with staff, and initial recommendations.

The first 90 days should not be a surprise to your team. You should know what the MSP needs from you, which changes may affect users, and which risks will be addressed first. For a busy practice or small business, minimizing disruption is as important as completing technical tasks.

Make the decision with evidence

Before you sign, ask for references from organizations similar in size or complexity to yours. Review the agreement, service scope, security responsibilities, and exit terms carefully. Include your business owner, operations lead, office manager, compliance contact, or internal IT resource in the discussion.

The best MSP relationship is a working partnership. Your provider should make your environment easier to understand, improve your ability to make decisions, and help your business operate with fewer avoidable interruptions. If answers are vague, overly technical, or difficult to document before the contract begins, that is useful information to have before you commit.