2Labs Tech

What Should Managed IT Services Include?

Managed IT services should give a small business clear, written responsibility for support, security, backups, updates, and technology planning. “Managed IT” can describe anything from basic device monitoring to a complete outsourced IT department. The label alone does not tell you what the provider will do, which tools are included or who is responsible when something goes wrong.

Before comparing plans, ask for a written service scope. A useful plan should clearly identify the people, devices, locations and systems covered, along with its exclusions.

If managed IT is still a new term, begin with what an MSP is and how managed support differs from calling for repairs, then use this guide to evaluate the actual scope.

The core services most small businesses should expect

Helpdesk support

Employees need a clear way to request help by phone, email or a support portal. The agreement should state the support hours, what counts as an emergency and whether there are limits on routine requests.

Common helpdesk work includes password and sign-in problems, software errors, printer issues, device setup and basic Microsoft 365 or Google Workspace support.

2Labs describes its local and remote approach on the managed helpdesk and support page.

Device monitoring and management

A provider should know which supported computers and servers are online, whether they are reporting problems and which devices are missing required tools.

Monitoring is useful only when someone responds to the alerts. Ask what the provider watches, which alerts create action and how you will be told about recurring or serious problems.

System updates and patching

Operating systems, common business applications and network equipment need security and reliability updates. The provider should explain:

  • Which systems it patches
  • How quickly critical updates are evaluated and installed
  • Whether updates are tested or staged
  • When restarts occur
  • How failed updates are handled
  • Which applications remain the customer’s or another vendor’s responsibility

There is no responsible universal answer to “How often should systems be updated?” Routine patching commonly follows a regular maintenance schedule, while actively exploited or high-risk vulnerabilities may require faster action. Unsupported software should be upgraded or replaced because it may no longer receive security fixes at all.

Endpoint and account security

A managed plan should identify the security controls included for laptops, desktops and user accounts. Depending on the business, that may include endpoint detection and response, email filtering, multi-factor authentication, password policies, disk encryption and security awareness training.

Do not assume “antivirus included” means the provider is managing a complete security program. The 2Labs cybersecurity services page describes the broader layers rural businesses should consider.

Backup monitoring and recovery support

A provider may manage backups directly or coordinate with another backup vendor. Either way, the scope should say what data is protected, how often backups run, how long versions are retained and who tests restores.

A backup alert that nobody reads is not protection. Ask how failed jobs are handled and what recovery assistance is included after an incident.

User onboarding and offboarding

New employees need the right accounts, licenses, devices and permissions. Departing employees need access removed promptly while the business preserves necessary files and email.

A repeatable checklist prevents old accounts from remaining active and reduces the chance of hurried setup mistakes.

Network and Wi-Fi support

The provider should document supported firewalls, switches, wireless access points and internet connections. Confirm whether monitoring, configuration changes, guest network separation and vendor calls are included.

Physical cabling, new access points and major network redesigns are often treated as projects rather than routine support. For rural and multi-building environments, review 2Labs networking and connectivity services.

Documentation

The business should not depend on one technician’s memory. Useful documentation includes equipment, warranties, network layouts, internet providers, software vendors, administrative ownership and recovery procedures.

The business should retain control of its accounts and data even when the provider manages daily access.

Planning and reporting

Managed IT should help the owner see what is coming next. That can include equipment replacement plans, security recommendations, recurring issue reviews, license cleanup and an annual technology budget.

Some providers include regular planning meetings in every plan. Others offer strategic work through a separate virtual CIO service.

Remote support versus on-site support

Most software, account and configuration problems can be handled remotely. Remote work is usually faster because a technician does not need to travel before beginning.

On-site service remains important when the work involves failed hardware, network cabling, wireless coverage, physical security equipment or a problem that prevents remote access.

A rural Kansas business should ask:

  • What areas receive on-site service?
  • Is travel included or billed separately?
  • How are urgent physical failures prioritized?
  • Does the provider use local technicians or dispatch an unknown third party?
  • Which problems are remote-only under the plan?

The best model is usually not remote or on-site. It is remote when that solves the problem efficiently and local field service when physical work is necessary.

What are MSP tiers and service levels?

Providers package services in different ways. A common structure may look like this:

  • Monitoring plan: device visibility, alerts and patching, with support billed separately
  • Support plan: monitoring plus employee helpdesk and routine administration
  • Comprehensive plan: support, security, backup oversight, planning and broader coverage

Those names are not standardized. A “premium” plan from one company may cover less than a “standard” plan from another. Compare the actual responsibilities, not the package labels.

A service level can also describe response commitments. For example, a business-stopping incident should receive a faster initial response than a request to install a nonurgent application. The agreement should define priority levels and response targets in language an owner can understand.

Are cloud services included?

An MSP may administer Microsoft 365, Google Workspace, cloud backups and business applications, but the cloud licenses themselves may be included, resold or billed directly to the customer.

Confirm who owns the primary account, who can create administrators, how access is removed, whether cloud data is backed up separately and what happens to licenses if the relationship ends.

Cloud software reduces the amount of equipment in the office, but it does not eliminate IT management. Someone still needs to secure accounts, manage permissions, review billing and help employees use the system correctly.

What employee training should be provided?

The provider should teach employees the procedures that affect daily work. That may include:

  • How to request support
  • How to use multi-factor authentication
  • How to identify and report suspicious email
  • How files should be stored and shared
  • What to do with a lost or stolen device
  • Which software and accounts are approved
  • What to expect during planned maintenance

Training does not need to be a long seminar. Short, repeated lessons tied to real situations are often more useful.

Also ask how the provider trains its own employees, checks their access and handles departures. A company with broad administrative access to client systems should have internal security and accountability practices it can explain.

Services that are often separate projects

Even a broad managed plan may not include:

  • New office buildouts or major moves
  • Cabling and construction work
  • Large server or cloud migrations
  • Website development
  • New camera or access-control installations
  • Specialized application consulting
  • Equipment purchases
  • Recovery from problems that existed before onboarding
  • Work outside the stated service hours

Exclusions are not automatically red flags. Hidden exclusions are.

A simple way to compare managed IT plans

Create one list of responsibilities and place each item in one of three columns:

  1. Included in the monthly plan
  2. Available for an additional fee
  3. Not provided

Do that for helpdesk, monitoring, updates, security, backups, accounts, network support, on-site work, cloud administration, projects and planning. You will quickly see whether two proposals are actually comparable.

Related MSP guides

If you are not sure what should be managed first, the 2Labs IT Health Checklist covers network, cybersecurity, backups, access and physical security in plain language. A Practical Tech Checkup can then turn the results into a prioritized scope instead of a pile of product names.