What's Included in Managed IT Services? Complete Checklist

"Managed IT services" can mean a full outsourced IT department or a monitoring agent and a phone number — and both get sold under the same name at very different prices. This checklist defines what a real agreement includes in 2026, what's legitimately extra, and how to expose the difference before you sign.

The short answer: complete managed IT includes unlimited helpdesk, 24/7 monitoring, patching, endpoint and email security, managed and tested backups, network management, vendor management, documentation, and strategic reviews — bundled into one per-user fee, which at 2026 market rates runs $100–$250 per user per month. Everything below is the line-item version.

What Should Be in the Core Agreement?

Ten categories make up a complete managed service. Use this as a literal checklist — send it to providers and have them mark each line.

# Category What "included" should mean
1 Helpdesk Unlimited remote support for covered users; phone + email + portal; defined hours
2 Monitoring (RMM) 24/7 agents on every device and server; alerting with human response
3 Patch management Scheduled OS and third-party app updates, with compliance reporting
4 Endpoint security Managed EDR on every machine — watched, not just installed
5 Email security Phishing/malware filtering, spoofing protection (SPF/DKIM/DMARC)
6 Identity & MFA MFA enforced everywhere; joiner/leaver account lifecycle handled
7 Backup & DR Managed backups for servers and cloud data, with scheduled restore tests
8 Network management Firewall, switches, Wi-Fi managed; firmware current; configs documented
9 Vendor management MSP owns tickets with your ISP, phone, and software vendors
10 Documentation & reviews Environment documented (and owned by you); QBRs and annual budget/roadmap

Rows 4–7 are where thin offerings quietly economize, and they're exactly the rows your cyber-insurance application asks about. Our managed IT services page shows how we structure the full stack, and the security rows are expanded on our cybersecurity services page.

What's Legitimately Not Included?

Every honest agreement has exclusions — the goal is knowing them up front, not eliminating them. Standard exclusions across the industry:

  • Projects — migrations, office moves, server replacements, major rollouts; quoted separately as project work
  • Hardware and software purchases — the MSP procures and recommends, you pay for the goods
  • Custom development — MSPs run systems; they don't build software
  • Out-of-scope devices — personal machines, home equipment, anything not enrolled
  • After-hours or on-site quotas — some plans cap on-site visits or bill after-hours work at a multiplier; fine if disclosed

The trap isn't the exclusion list — it's an agreement where the exclusions are discovered invoice by invoice. Ask for the boundary in writing, and pair this checklist with our 15 questions to ask before hiring a provider.

Which Add-Ons Are Worth Paying For?

Some extras are upsell padding; several are genuinely worth it depending on your risk profile. The ones we consider legitimate value in 2026:

  • MDR / 24/7 SOC monitoring — human analysts watching your EDR overnight; increasingly demanded by insurers
  • Security awareness training + phishing simulation — cheap, measurable, and targets the #1 breach vector
  • Microsoft 365 / Google Workspace backup — the platforms' native retention is not backup; third-party protection typically runs a few dollars per user
  • Compliance packages — HIPAA, FTC Safeguards, or CMMC documentation and evidence support (see IT compliance)
  • Co-managed tooling tiers — if you have internal IT, plans that share the MSP's platform with your staff (co-managed IT)

Add-ons that deserve skepticism: per-ticket fees on an "unlimited" plan, charges for the provider's own documentation, and "security reviews" that are just a PDF export from a scanner.

How Do You Compare Two Quotes That Look Nothing Alike?

Normalize scope before comparing dollars — that's the entire method. Take the ten-row table above plus the add-on list, have each provider mark included / add-on / not offered, then divide each total monthly cost by user count. Providers that looked far apart usually converge; when one stays dramatically cheaper, you've found missing rows, not efficiency.

Two more normalization questions that change the math: Who owns the security and backup licenses if you leave? And is onboarding (typically free to one month's value at market rates) a fee or bundled? Exit terms and onboarding quality are part of the price even though they're not on the monthly invoice.

Want a pre-filled version of this checklist for your environment? Request a free IT assessment — we'll inventory what you currently have against all ten rows and hand you the gap list, no strings attached.

The Bottom Line

If a "managed IT" quote doesn't clearly include monitored EDR, enforced MFA, tested backups, and unlimited helpdesk in the base fee, it isn't complete managed IT — it's a partial plan that will finish pricing itself after you sign. Use the checklist, get every row in writing, and compare total scope rather than sticker price. That one habit prevents most bad MSP relationships before they start.

We work through this exact checklist with businesses across the Sacramento region — from Sacramento to Folsom and El Dorado Hills — and the gap analysis is often the most valuable page a prospective client takes away, whoever they end up hiring.

Frequently asked questions

What's included in a standard managed IT agreement?
A legitimate all-inclusive agreement covers unlimited remote helpdesk, 24/7 monitoring, patch management, endpoint security (EDR), email security, backup management with restore testing, network management, vendor management, documentation, and periodic strategy reviews. If several of those are missing or billed separately, you're looking at a partial plan priced like a full one.
What's usually NOT included in managed IT?
Large one-time projects (migrations, office moves), hardware and software purchases, custom development, and sometimes after-hours support or on-site visits beyond a quota. None of these exclusions are unreasonable — the problem is only when they're discovered after signing. Get the boundary list in writing.
What is RMM and why does it matter?
RMM (remote monitoring and management) is the agent software an MSP installs on every computer and server — it reports health, deploys patches, and enables remote support. It's the difference between IT that watches your environment and IT that waits for your call. If a provider has no RMM story, they're break-fix wearing a subscription.
Are security tools like EDR extra, or included?
In credible 2026 offerings, EDR, email filtering, and MFA management are included in the core per-user fee — market rates of $100–$250 per user per month reflect that bundling. Advanced layers like 24/7 SOC monitoring (MDR), security awareness platforms, or compliance tooling are legitimately add-ons at some providers. Ask for the security bill of materials.
Is backup storage really unlimited?
Rarely — most agreements include a storage pool or per-device quota with overage fees, which is fine as long as it's disclosed. The question that matters more is whether restore testing is included and scheduled. Backup that's never test-restored is a hope, not a service.
How should I use this checklist when comparing providers?
Send it to each provider and ask them to mark every line included, add-on, or not offered — in writing. Quotes that looked $50 apart per user often turn out identical once scope is normalized, and the cheapest quote usually gets expensive right around row ten. Comparing scope first turns pricing from a guess into arithmetic.

Find out what your IT should be doing for you

Get a free, no-obligation IT assessment — a plain-English report on your security, backups, and support gaps.

Get Your Free IT Assessment