What to Expect From a Managed IT Provider Now

March 19, 2024 Updated August 15, 2026 By Vulcan365 Team

The job changed. Managed IT used to mean someone who arrived when the server broke. Now the servers are mostly gone, the security stakes are considerably higher, and the value of a provider is measured in problems that never reached you. Here's what that means when you're choosing one.

What the job actually is today

Three shifts explain most of the difference.

The infrastructure moved. With email, files, and increasingly applications in Microsoft 365 and Azure, there's less hardware to maintain and far more configuration to get right. Provider skill moved from racking servers to designing identity, access, and data governance — less visible work, and considerably more consequential when it's done badly.

Security became the main event. It used to be a line item. Now the same controls a provider manages — identity, device management, backup, monitoring — are what stand between a small business and an incident it might not survive. Any provider treating security as an optional add-on is describing a 2015 service.

The office boundary dissolved. Staff work from anywhere on devices that never touch the office network. Support and security both have to work without assuming physical proximity — see securing remote workers.

What a good provider should be doing

  • Patching on a schedule, with reporting that shows what actually applied — not just "automatic updates are on"
  • Monitoring that produces action, not just dashboards nobody reads
  • Backups tested by restoring, with the recovery time documented
  • Identity and access managed deliberately — MFA everywhere, conditional access, least privilege, prompt offboarding
  • Documentation you own and could hand to a successor
  • Regular strategic review — what's coming up for renewal or replacement, what the budget should be next year
  • An incident response process you've seen in writing before you need it

Notice how much of that is preventive. A provider whose value shows up only when things break has an incentive problem — and the good ones look, from the outside, like not much is happening.

Pricing models and what they do to behavior

Break-fix — you pay per incident. Cheap when nothing goes wrong, and it aligns the provider's revenue with your problems. Reasonable only for very small businesses with minimal dependency on technology.

Per-user or per-device monthly — the standard model, typically $100–200 per user per month depending on what's included. The incentive here is right: the provider profits from your systems being stable, because every ticket costs them margin.

Co-managed — you have internal IT and the provider supplements them with specialist skills, after-hours coverage, or tooling. Increasingly common, and sensible once you're large enough to have someone internal but not large enough to have a full team.

Whatever the model, read what's excluded. Projects, hardware, third-party licensing, and after-hours work are often billed separately, and that's fine — as long as you knew before signing.

Questions worth asking before you sign

  1. What's your guaranteed response time, and what happens if you miss it? A commitment with no consequence is a marketing claim.
  2. Who actually answers when we call? A named team who learns your environment, or whoever's free?
  3. What's included in security, specifically? Ask for the list. Vague answers here are a genuine warning sign.
  4. How do you protect your own access to our systems? They'll hold administrative rights across your network, which makes their security part of yours — see supply chain attacks.
  5. What happens if we leave? Who owns the documentation, the licenses, the tenant? Get this answered before you're unhappy.
  6. Can we talk to a client of similar size in our industry?
  7. Do you have people who can build things? Increasingly the difference between a provider who resolves your tickets and one who removes the cause of them.

Signs you've outgrown your current provider

  • The same problems recur and nobody addresses the underlying cause
  • You hear from them only when something breaks or a renewal is due
  • You can't get a straight answer about your own backups or security configuration
  • They still talk in terms of servers when your business runs on cloud services
  • Nobody has proposed an improvement in a year
  • You'd struggle to describe what you're paying for each month

Where this is heading

The interesting shift is that the routine work — patching, monitoring, standard troubleshooting — keeps getting more automated. What that frees up, at providers that use it well, is time to fix things properly: to automate a manual process, to integrate two systems that don't talk to each other, to remove a recurring source of friction rather than servicing it forever.

That's the direction we've taken deliberately — we've written about why we keep software engineers on staff and what it lets us do that a pure support desk can't. It's also why we think the useful question to ask a provider isn't "how fast do you close tickets" but "what have you made unnecessary?"

Evaluating providers?

Vulcan365 provides managed IT, Microsoft 365, Azure, and custom software for businesses across Birmingham and Central Alabama. We're happy to answer every question on that list about ourselves — and to tell you if what you have is already working.

Our managed services Start a conversation

The Digital Frustration You Can't See

Small daily technology delays add up to real payroll cost.

The Hidden BYOD Risk

Staff expose company data on personal phones without realizing it.

The Domain Controller Backup Challenge

Why bare metal recovery often isn't an option, and what to do instead.

Browse all articles · See our managed IT services