Outsourcing IT: Best Practices for Selecting an MSPhttps://exactitconsulting.com/outsourcing-it-best-practices-msp-benefits/
5%
14 Tips for Choosing and Selecting a Managed Service Provider (MSP) - Entre Technology Serviceshttps://www.entremt.com/14-tips-for-choosing-and-selecting-a-managed-service-provider-msp/
4%
How To Choose a Managed Service Provider (MSP) - Upworkhttps://www.upwork.com/resources/choosing-managed-service-provider
4%
How to Choose a Managed Service Provider: The Ultimate Guidehttps://compassmsp.com/resources/how-to-choose-a-managed-service-provider
3%
13 Tips for Choosing a Managed Service Provider (MSP) for your Businesshttps://lansa.com/blog/managed-services/13-tips-for-choosing-a-msp-for-your-business-needs/
3%
How to choose an MSP Helpdesk Outsourcing Companyhttps://www.supportadventure.com/how-to-choose-an-msp-helpdesk-outsourcing-company/
2%
How To Pick The Right MSP: 8 Criteria To Evaluate Managed IT Providershttps://www.kelsercorp.com/blog/how-to-pick-the-right-msp-8-criteria-to-evaluate-managed-it-providers
2%
15 Tips For Choosing an MSP (Managed Service Provider)https://cmitsolutions.com/blog/choosing-an-msp/
2%
10 Factors to Consider When Choosing An MSP | NinjaOnehttps://www.ninjaone.com/blog/choosing-an-msp/
2%
12 Tips for Choosing a Managed Service Provider | EBShttps://ebs.tech/choosing-a-managed-service-provider/
2%
Question: I'm an IT Director and need to find a managed service provider (MSP) to outsource our help desk. How do I choose a good one?
Evaluating and selecting a managed service provider (MSP) for your help desk is a massive leverage point for your team—done right, it frees up your internal resources for strategic initiatives; done wrong, it becomes a daily exercise in ticket escalation headaches and user frustration.
Here is a structured framework to help you evaluate, vet, and choose the right partner:
Define the Scope and Service Level Agreements (SLAs) First: Map out your current ticket volume, peak hours, and required coverage (24 × 7 vs. business hours). Establish concrete metrics for First Response Time (FRT), Mean Time to Resolution (MTTR), and First Contact Resolution (FCR) rates.
Evaluate Security and Compliance Posture: Since the help desk handles password resets, credential verification, and often frontline triage, ensure the MSP aligns with your regulatory requirements (HIPAA, SOC 2 Type II, ISO 27001, GDPR). Ask about their internal security protocols and multi-factor authentication (MFA) enforcement.
Assess Tech Stack and Integration Capabilities: Determine how they plug into your ecosystem. Check if they integrate smoothly with your existing PSA/RMM tools or ticketing systems (like ServiceNow, Zendesk, or ConnectWise) or if you will be required to use their proprietary platform.
Scrutinize the Cultural Fit and Communication: Your users won't care if the MSP is technically proficient if the agents are rude or struggle with English/local nuances. Request sample call recordings or chat transcripts, and ask about their agent retention rates (high churn at the MSP means constant retraining for your environment).
Understand the Pricing and Contract Structure: Look closely at how they bill—whether it's per-user, per-ticket, or tiered flat-rate pricing. Watch out for hidden fees regarding onboarding, after-hours support, documentation updates, or project-based escalations.
Check References and Peer Validation: Don’t just rely on the case studies they hand you. Ask for references from current clients of a similar size and industry to yours, and check peer communities or review platforms like G2 MSP Reviews or Clutch MSP Directory for unfiltered feedback.
Question: I'm an IT Director and need to find a managed service provider (MSP) to outsource our help desk. How do I choose a good one?
For an IT Director, I’d treat this less like “find a good MSP” and more like . The key is to evaluate the —people, processes, SLAs, escalation, security, reporting, and transition—not the sales presentation.
Question: I'm an IT Director and need to find a managed service provider (MSP) to outsource our help desk. How do I choose a good one?
ChatGPT Search· Sep 22, 2026
Choose the MSP as an extension of your IT organization, not simply the lowest-cost ticket processor.
Define scope: users, hours, channels, endpoints, M365/identity, onboarding/offboarding, escalation to your team, and onsite needs.
Demand measurable SLAs: response/resolution targets by priority, escalation rules, service credits, and reporting.
Evaluate service quality: ask for CSAT, first-contact resolution, backlog, abandonment, reopen rates, and ticket trends—not just SLA compliance.
Check tooling: require visibility into tickets, knowledge base, asset data, automation, reporting, and integrations with your existing stack.
Question: I'm an IT Director and need to find a managed service provider (MSP) to outsource our help desk. How do I choose a good one?
Question: I'm an IT Director and need to find a managed service provider (MSP) to outsource our help desk. How do I choose a good one?
ChatGPT Search· Sep 18, 2026
If you're outsourcing the help desk, I’d treat the MSP selection as a service-design and operating-model decision first, and a vendor-selection exercise second. The cheapest MSP can become expensive quickly if you retain lots of escalations, have poor ticket hygiene, or spend your time managing the provider.
CISA/NIST guidance also recommends establishing a master requirements list, explicit SLAs, clearly defined responsibilities, incident-management terms, logging/monitoring requirements, and vendor-security assurances before signing with an MSP.
1. Define exactly what you're outsourcing
Before talking to vendors, document your current environment and decide what "help desk" means.
For example:
password resets, Microsoft 365, Windows/macOS, mobile devices
Question: I'm an IT Director and need to find a managed service provider (MSP) to outsource our help desk. How do I choose a good one?
ChatGPT Search· Sep 14, 2026
For an IT Director, I’d treat this less like “finding a company that answers tickets” and more like outsourcing a business-critical operating function. The best MSP is the one that can reliably absorb your day-to-day support workload while giving you better service visibility, security, and scalability than you could reasonably build internally.
CISA specifically recommends formalizing MSP requirements in a master requirements list and SLA, and recommends due diligence around security, incident response, employee vetting, logging, subcontractors, and data segregation.
1. Start by defining exactly what you're outsourcing
Before talking to MSPs, establish your baseline:
Number of users and endpoints
Question: I'm an IT Director and need to find a managed service provider (MSP) to outsource our help desk. How do I choose a good one?
Google AI Mode· Sep 14, 2026
Choosing a managed service provider (MSP) for your help desk is a major shift. To protect your team's sanity, your users' productivity, and your budget, you need a structured evaluation process.
Here is a step-by-step framework to evaluate and choose a high-performing help desk MSP:
Define Service Level Agreements (SLAs) and Metrics
First-contact resolution (FCR): Look for providers that track and guarantee a high FCR rate rather than just closing tickets fast.
Speed-to-answer and response times: Demand clear, contractually backed response and resolution times tiered by severity (S₁ through S₄).
Customer satisfaction (CSAT): Ask for their average CSAT scores and how they actively measure and report user feedback.
Evaluate Security and Compliance Standards
Question: I'm an IT Director and need to find a managed service provider (MSP) to outsource our help desk. How do I choose a good one?
Google AI Mode· Sep 10, 2026
To choose a good managed service provider (MSP) for outsourcing your help desk, define precise service level agreements (SLAs), evaluate their technical and cultural alignment, and audit their security posture. As an IT Director, your goal is to find a co-managed partner that seamlessly integrates with your existing internal team rather than just a faceless ticket-resolver.
Define Service Level Agreements (SLAs) and Metrics
First-contact resolution rate: Ensure they track and meet targets for fixing issues on the initial interaction.
Question: I'm an IT Director and need to find a managed service provider (MSP) to outsource our help desk. How do I choose a good one?
Your approximate user count and monthly ticket volume?
Whether you need 24 × 7 support or standard business hours?
I can help you draft a tailored RFP or build a scorecard matrix for your vendor evaluations.
buying an outsourced service operation
actual delivery model
A structured RFP is useful because it forces vendors to answer the same questions and makes proposals comparable.
1. Define exactly what you're outsourcing
Before talking to MSPs, document your current environment and decide what stays with you.
For example:
Area
MSP
Internal IT
L1 help desk
✓
Password/MFA issues
✓
PC/Mac troubleshooting
✓
Microsoft 365 support
✓
New-user provisioning
✓
Application-specific support
Maybe
✓
Network administration
Maybe
✓
Infrastructure engineering
Maybe
✓
Security operations
Maybe
✓
Architecture/strategy
✓
Vendor management
✓
Be particularly explicit about what is not included. “Unlimited support” is meaningless unless you know what's considered a support ticket versus a project, engineering work, or billable professional service.
A good RFP should define scope, coverage hours, escalation, SLAs, pricing, and support channels.
2. Evaluate the service desk itself
This is probably your most important category.
I'd ask:
Where are the technicians located?
How many technicians are actually assigned to your account?
What percentage of tickets are handled by L1 vs. L2/L3?
What's their average first-response time?
What's their average resolution time?
What percentage of tickets are resolved at first contact?
How do they handle VIPs?
How do they handle major incidents?
Is there 24×7 support, or merely an answering service after hours?
What happens when your assigned technician is unavailable?
How are tickets escalated?
Can you see the entire ticket history and technician notes?
Can users contact the desk by phone, email, portal, Teams/Slack, etc.?
Don't accept averages alone. Ask for actual SLA performance from the last 6–12 months, ideally from a comparable customer.
One particularly useful question:
“Walk me through what happens when one of our users calls at 9:03 AM with a problem that your L1 technician can't resolve.”
Have them demonstrate the process rather than describe it.
3. Put the SLA in operational terms
Don't let an MSP give you a single vague promise such as “15-minute response.”
Define priorities and consequences.
For example:
Priority
Example
Response
Target
P1
Major business outage
15 min
Continuous escalation
P2
Multiple users affected
30 min
4 business hrs
P3
Individual unable to work
1 hr
1 business day
P4
Routine request
4 hrs
2–3 business days
Those numbers are examples—you should set them from your organization's actual requirements.
Also define:
When does the SLA clock start?
Does an automated acknowledgment count?
What pauses the clock?
What constitutes resolution?
What happens if they miss the SLA?
Are service credits available?
Who can declare a major incident?
What is the escalation procedure?
A useful SLA is measurable enough that you and the MSP can't reasonably disagree about whether it was met.
4. Security should be a separate evaluation
Your MSP will potentially have privileged access to your environment, so you're effectively outsourcing part of your security boundary.
Ask for:
SOC 2 Type II report
Penetration-test summary
Cyber insurance
MFA requirements for MSP technicians
Privileged-access management
Just-in-time/JIT access, if applicable
Technician background checks
Endpoint security on technician workstations
Logging of administrative activity
Separation of customer environments
Incident-response procedures
Breach notification requirements
Data retention/deletion policies
Backup and disaster-recovery procedures
Subcontractor/third-party access
SOC 2 is particularly relevant because it examines controls concerning areas such as security, availability, processing integrity, confidentiality, and privacy.
But don't treat “we have SOC 2” as a security score. Ask to see the report, its scope, the systems covered, the auditor's opinion, and any relevant exceptions.
5. Find out who will actually do the work
This is where MSP sales presentations can be misleading.
Ask:
“Who specifically will be supporting us after the contract is signed?”
Then ask:
How many named technicians?
How many customers does each technician support?
What is the technician-to-user ratio?
What is employee turnover?
How long have the assigned technicians been there?
How much work is outsourced offshore?
Which tiers are offshore?
Where is the after-hours team located?
What happens if the account manager leaves?
Who is your escalation engineer?
Who owns the relationship?
I'd actually request a meet-the-team session with the people who would support you, not just the salesperson and VP.
6. Make them demonstrate your environment
Give each finalist a scenario-based test.
For example:
“It's Monday at 8:15 AM. A new employee starts at 9:00. Their laptop won't authenticate to Microsoft 365, they're missing two applications, and their manager says they need access to three systems.”
Ask the MSP to demonstrate how they would handle it.
Then give them harder scenarios:
A CEO can't access email.
30 users lose access to a critical application.
A user's account is compromised.
A laptop is infected with malware.
A terminated employee still has active credentials.
Microsoft 365 has an outage.
A branch office loses connectivity.
A recurring problem generates 50 tickets.
You're testing judgment and process, not trivia.
7. Demand meaningful reporting
You shouldn't have to ask your MSP what's happening.
At minimum, I'd want monthly reporting covering:
Ticket volume
Tickets by category
Tickets by priority
First-response SLA
Resolution SLA
Reopened tickets
Aging tickets
First-contact resolution
User satisfaction/CSAT
Recurring incidents
Major incidents
Problem-management activity
Security incidents
Patch compliance
Backup status, where applicable
Recommendations
And I would expect an IT service review meeting with someone senior enough to discuss trends and corrective actions.
8. Be extremely careful with pricing
MSP pricing can look inexpensive until you discover what's excluded.
Get vendors to price the same hypothetical environment.
Ask them to separately identify:
Per-user/per-device recurring fee
After-hours support
Onsite support
Projects
Engineering
Migrations
New-user onboarding
Offboarding
Hardware procurement
Licensing
Third-party software
Security services
Backup
vCIO/strategic services
Emergency work
Travel
Then ask:
“If we paid exactly the monthly recurring fee and nothing else, what would you refuse to do?”
That's often more revealing than asking what is included.
9. Check references differently than most companies do
Don't just ask for three references and call them.
Ask for customers similar to you in:
Number of users
Technology stack
Industry
Geographic footprint
Support requirements
And ask the references:
What did the MSP promise during the sales process?
What turned out differently?
How good is the help desk really?
How often do you have to escalate?
Do tickets get bounced around?
How often do you see unfamiliar technicians?
How transparent is billing?
What happens when something goes wrong?
What does the MSP do particularly well?
If you were selecting an MSP again, what would you investigate more carefully?
That last question tends to produce the useful information.
10. Don't overlook the contract and exit
This is one of the most important areas for an IT Director.
Make sure the contract addresses:
Initial term
Renewal
Termination for convenience
Termination for cause
SLA failures
Price increases
Minimum commitments
Data ownership
Documentation ownership
Password/credential ownership
Configuration ownership
Ticket-history export
Asset/inventory data
Transition assistance
Knowledge-transfer obligations
Assistance to your next MSP
Data deletion after termination
Notice period
Your MSP should make it easy to leave.
That sounds counterintuitive, but it's an excellent indicator of whether you're buying a service relationship rather than becoming dependent on a vendor.
A practical scorecard
I'd use something like this for the final 3–5 vendors:
Category
Weight
Help desk & SLA performance
25%
Technical depth & escalation
15%
Security & access controls
15%
Staffing & service-delivery model
15%
Reporting & ITSM processes
10%
Transition/onboarding plan
10%
Pricing & contract
10%
Total
100%
Have each evaluator score vendors before the finalist presentations, then compare scores and discuss the large discrepancies. A published 2026 MSP scorecard similarly emphasizes defining scope and P1 criteria rather than relying on generic “unlimited IT” claims.
I would also impose some non-negotiable gates rather than letting a cheap price compensate for a serious weakness:
No acceptable security controls → eliminate
Cannot provide meaningful SLA reporting → eliminate
And I'd make the MSP prove its operational model before signing, rather than selecting based on a polished sales presentation.
The most important mental model is: you're not buying “IT expertise.” You're buying a repeatable service-delivery machine. Evaluate the machine.
If you tell me your approximate user count, locations, hours of support needed, Microsoft 365/Azure vs. other stack, and what you want to retain internally, I can turn this into a vendor-ready MSP RFP and a weighted 100-point scorecard you can actually send to bidders.
That last question tends to produce the useful information.
10. Don't overlook the contract and exit
This is one of the most important areas for an IT Director.
Make sure the contract addresses:
Initial term
Renewal
Termination for convenience
Termination for cause
SLA failures
Price increases
Minimum commitments
Data ownership
Documentation ownership
Password/credential ownership
Configuration ownership
Ticket-history export
Asset/inventory data
Transition assistance
Knowledge-transfer obligations
Assistance to your next MSP
Data deletion after termination
Notice period
Your MSP should make it easy to leave.
That sounds counterintuitive, but it's an excellent indicator of whether you're buying a service relationship rather than becoming dependent on a vendor.
A practical scorecard
I'd use something like this for the final 3–5 vendors:
Category
Weight
Help desk & SLA performance
25%
Technical depth & escalation
15%
Security & access controls
15%
Staffing & service-delivery model
15%
Reporting & ITSM processes
10%
Transition/onboarding plan
10%
Pricing & contract
10%
Total
100%
Have each evaluator score vendors before the finalist presentations, then compare scores and discuss the large discrepancies. A published 2026 MSP scorecard similarly emphasizes defining scope and P1 criteria rather than relying on generic “unlimited IT” claims.
Probe security: SOC 2/ISO 27001 where appropriate, privileged-access controls, MFA, logging, background checks, incident response, and data handling.
Test escalation: give finalists 3–5 realistic incidents and have their actual support team demonstrate how they would handle them.
Reference-check similar customers: same employee count, geography, technology stack, and support complexity.
Scrutinize the contract: minimums, after-hours charges, project fees, annual increases, termination assistance, ticket ownership/data export, and what is explicitly out of scope.
Start with a transition plan: documentation, knowledge transfer, shadowing, baseline metrics, and a 30/60/90-day service review.
A useful RFP scorecard should emphasize support quality, SLA/metrics, security, technical capability, transition approach, cultural fit, and total cost rather than headline price. ITIL-oriented practices and continual improvement are useful evaluation signals.
To choose a good managed service provider (MSP) for your help desk, define your exact service level agreements (SLAs), evaluate their technical depth and ticketing tools, and verify their security compliance standards before signing any contract . As an IT Director, you want to treat this search like an enterprise vendor evaluation rather than a simple contractor hire.
1. Define Scope and Service Level Agreements (SLAs)
Support Hours: Decide if you need 8x5, 24/7/365 coverage , or follow-the-sun support.
Response vs. Resolution: Do not just look at response times; tie contract penalties to mean time to resolution (MTTR) and first-contact resolution rates.
Tiered Support Model: Clarify how escalation paths work between Tier 1 (password resets, basic triage) and Tier 2/3 (network issues, advanced software troubleshooting) engineers.
2. Evaluate Technical Stack and Integration
Ticketing & PSA Tools: Ensure their Professional Services Automation (PSA) and Remote Monitoring and Management (RMM) tools can integrate or cleanly sync with your internal ITSM (like Jira, ServiceNow, or Zendesk).
Self-Service Capabilities: Check if they provide a modern, AI-assisted knowledge base or chat portal that deflects trivial tickets and reduces end-user friction.
Certifications: Request third-party audits such as SOC 2 Type II compliance or ISO 27001 certifications.
Data Access & Privacy: Review what level of network and credential access their help desk agents will possess, and enforce strict Least Privilege access rules.
Compliance Alignment: If your organization operates in healthcare, finance, or defense, confirm their staff is trained on relevant frameworks like HIPAA, PCI-DSS, or CMMC.
4. Cultural Fit and References
Communication Styles: Listen closely to how their tier-1 staff speaks during mock calls or reference checks; user satisfaction (CSAT) hinges entirely on user empathy and clear communication.
Reference Checks: Speak directly with peer IT Directors who have outsourced to this specific provider for at least 12 months, asking specifically about staff turnover and onboarding pain.
If you want to narrow this down further, tell me:
What is your company size and ticket volume per month?
Are you looking for a co-managed model or a fully outsourced help desk?
I can help you build an evaluation scorecard or an RFP template.
Onboarding/offboarding: who owns the workflow and approvals
After-hours: genuine 24×7 support versus emergency-only coverage
Escalation: exactly what comes back to your internal IT team
I'd create a simple RACI matrix for these before issuing an RFP.
A particularly important question is:
"What percentage of our tickets will you actually resolve without involving my team?"
Ask them to provide historical numbers from comparable customers rather than simply promising "high first-call resolution."
2. Establish the metrics you will hold them to
Don't accept an SLA that merely says "99.9% availability."
For a help desk, I'd want metrics such as:
Metric
Example requirement
Phone answer time
≥90% answered within 30–60 sec
First response
P1: 15 min; P2: 30 min; P3: 4 business hrs
First-contact resolution
Target established from baseline
Resolution time
By priority/severity
Ticket backlog
Defined maximum
Reopen rate
<X%
Customer satisfaction
≥X%
Abandonment rate
<X%
Escalation rate
Tracked by category
SLA compliance
≥X% monthly
After-hours response
Explicitly defined
Major incident communications
Defined cadence
The exact numbers should come from your business requirements rather than blindly adopting these examples.
Also distinguish response time from resolution time. Vendors sometimes advertise excellent response SLAs while taking considerably longer to actually resolve incidents.
3. Look very closely at the staffing model
This is one of the biggest differences between MSPs that look similar on paper.
Ask:
Where are the service desk technicians located?
Are they employees or subcontractors?
How many technicians support customers of our size?
What is the technician-to-user ratio?
What happens during peak periods?
What's the average technician tenure?
What's annual service-desk turnover?
Is there a dedicated team or a shared queue?
Can we interview the people who would actually support us?
How are escalations handled?
Is there an L2/L3 engineering team?
Do technicians have security training and background checks?
I'd be particularly interested in who will actually answer the phone at 2:00 PM on a Tuesday, rather than the account executive's description of the company.
4. Demand a real demonstration
Don't sit through a generic PowerPoint.
Give each finalist 5–10 realistic tickets from your environment and have them demonstrate how they would handle them.
For example:
User can't authenticate to Microsoft 365 after changing phones.
Executive's laptop has intermittent Wi-Fi.
Employee reports a suspicious MFA prompt.
New employee starts Monday and needs laptop/apps/access.
Printer works for everyone except one department.
User accidentally deleted an important OneDrive file.
VPN stops working while traveling.
Employee leaves the company unexpectedly.
Watch for whether they:
ask good diagnostic questions;
distinguish incidents from requests;
verify identity before making account changes;
recognize security incidents;
document tickets properly;
escalate appropriately;
communicate clearly to the end user;
know when not to make a change.
That exercise can tell you more than a 50-slide sales presentation.
5. Evaluate their technology stack—but don't let the tools fool you
Ask what they use for:
ITSM/ticketing
Remote monitoring and management (RMM)
Endpoint management
Microsoft 365 administration
Identity management
Documentation/knowledge base
Asset management
Endpoint detection/response
Backup
Network monitoring
Reporting/analytics
Then ask the more important question:
"Show me what my team will actually see."
You should have appropriate visibility into tickets, SLA performance, escalations, assets, changes, incidents and relevant security activity.
CISA specifically recommends contractual provisions around monitoring/logging, provider access to customer systems, incident notification, and appropriate security controls.
6. Treat security as part of the MSP evaluation
You're giving another organization privileged access to your environment. That's a substantially different risk from hiring an ordinary business-services vendor.
At minimum, investigate:
SOC 2 Type II report, if applicable
ISO 27001 certification, if applicable
MFA for MSP administrative access
Privileged-access management
Least-privilege architecture
Separate customer environments/data
Logging and audit trails
Background screening
Security awareness training
Vulnerability management
Incident-response process
Breach notification obligations
Business continuity/disaster recovery
Backup architecture
Subcontractors
Cyber insurance
Penetration testing
Offboarding procedures
Don't just ask "Are you SOC 2 compliant?"
Ask for the report, identify exceptions, and determine whether the controls actually cover the services you're buying.
CISA recommends, among other things, MFA, least-privilege access, monitoring/logging, incident notification, and contractual security requirements when working with MSPs.
7. Reference checks are incredibly valuable
Ask for three customers similar to you, preferably:
similar employee count;
similar technology stack;
similar regulatory/security requirements;
customers who have been with them for several years.
Don't let the MSP select only their happiest reference if you can avoid it.
I'd ask those references:
"What did the MSP promise during the sales process that turned out not to be true?"
"What happens when they screw something up?"
"How often do you have to escalate things internally?"
"How good is the service desk after the honeymoon period?"
"What costs surprised you?"
"How difficult would it be to leave them?"
That last question is particularly revealing.
8. Pay close attention to the contract
This is where seemingly inexpensive MSPs can become expensive.
Look for:
Per-user vs. per-device pricing
Minimum user/device commitments
After-hours charges
Project fees
Onboarding fees
Hardware/software markups
Microsoft licensing markups
On-site support charges
Travel expenses
Out-of-scope definitions
Security incident responsibilities
SLA credits
Price increases
Contract renewal
Termination rights
Data ownership
Data export
Documentation ownership
Administrative-account ownership
Transition assistance when you leave
The exit clause matters almost as much as the SLA.
You want the ability to leave without discovering that the MSP owns your documentation, has all the admin credentials, and will charge you a six-figure "transition project" to hand your environment back.
CISA's current MSP guidance similarly emphasizes defining responsibilities, incident response, outage compensation, records/logging, and other requirements contractually before award.
9. Don't automatically outsource everything
As IT Director, I'd seriously consider a hybrid model.
For example:
MSP
L1 help desk
Password/account requests
Endpoint support
Standard software
Device provisioning
Basic M365 support
Routine onboarding/offboarding
Internal IT
Architecture
Security governance
Vendor management
Business applications
IT strategy
Complex escalations
Major incidents
High-impact changes
Relationship with business leadership
That can give you the scale of an MSP without surrendering the knowledge and control you need internally.
10. Build a weighted scorecard
I'd use something like this:
Category
Weight
Service desk quality & staffing
25%
SLA/operational performance
15%
Security
15%
Technical capabilities
10%
Integration with internal IT
10%
Customer references
10%
Reporting/transparency
5%
Commercial terms
10%
Then have each finalist respond to the same requirements and scenarios.
Importantly, don't let price dominate the scoring. If Vendor A costs $70/user and Vendor B costs $85/user, the $15 difference may be insignificant if B resolves substantially more issues without your intervention.
A good RFP structure
If you're at the point of actually going to market, I'd structure the process like this:
Phase 1 — Internal discovery
Current ticket volumes
Users/devices
Hours of support
Ticket categories
Resolution times
Escalation rates
Current staffing costs
Technology environment
Phase 2 — Requirements
Scope
SLAs
Security requirements
Reporting
Staffing
Transition requirements
Commercial model
Phase 3 — RFP
Send identical requirements to 5–8 MSPs.
Phase 4 — Shortlist
Select 3 finalists based on written responses.
Phase 5 — Technical/operational validation
Ticket simulations
Tool demonstrations
Security review
Reference calls
Phase 6 — Commercial negotiation
Compare total cost over 3 years, not just monthly per-user price.
Phase 7 — Transition
Knowledge transfer
Documentation
Tool deployment
Pilot group
Parallel operation
Full cutover
One thing I'd do differently from many IT departments
Don't start by asking "Which MSP should we hire?"
Start with:
"What service do we want our employees to experience, what work do we want our internal IT team to stop doing, and what measurable outcomes will prove the MSP is delivering it?"
Once you have those answers, selecting the MSP becomes considerably easier.
If you tell me roughly your number of users, locations, hours of desired support, Microsoft/Google environment, current help-desk staffing, and whether you want L1 only or L1–L2, I can turn this into a practical MSP RFP + weighted evaluation scorecard you could send to vendors.
One thing I'd do differently from many IT departments
Don't start by asking "Which MSP should we hire?"
Start with:
"What service do we want our employees to experience, what work do we want our internal IT team to stop doing, and what measurable outcomes will prove the MSP is delivering it?"
Once you have those answers, selecting the MSP becomes considerably easier.
If you tell me roughly your number of users, locations, hours of desired support, Microsoft/Google environment, current help-desk staffing, and whether you want L1 only or L1–L2, I can turn this into a practical MSP RFP + weighted evaluation scorecard you could send to vendors.
I'd build a simple RACI matrix for every major IT function. For example:
Function
Internal IT
MSP
Password resets
A
R
Endpoint troubleshooting
C
R
New-user provisioning
A
R
Microsoft 365 admin
A
R
Security incidents
A
C/R
Infrastructure architecture
R
C
Vendor management
R
C
Executive support
A/R
C
Major incidents
A
R
You don't want the contract to say "managed help desk" while you and your team are still doing half the work.
2. Don't select primarily on price
I'd weight the evaluation roughly like this:
Category
Weight
Help-desk capability & staffing
25%
Service quality / SLA / metrics
20%
Security & access controls
15%
Technical capability
15%
Transition/onboarding approach
10%
Cultural/organizational fit
10%
Price
5%
The reason I'd make price only 5% is that a cheap help desk that frustrates your employees can cost considerably more than an expensive one that resolves issues quickly.
Also beware of MSPs that give you an extremely low per-user price and then monetize everything outside the basic package.
Ask explicitly:
"What isn't included in your standard monthly fee?"
Then ask for the complete rate card.
3. Dig deeply into their help desk operation
This is where I'd separate the serious MSPs from the sales organizations.
Ask to see their actual operation—not just a PowerPoint.
You want to know:
Where are Tier 1/2/3 technicians located?
Are they employees or subcontractors?
What percentage of tickets are resolved at Tier 1?
What are their current first-response and resolution times?
What are their abandonment rates?
What is their technician-to-user ratio?
How do they handle ticket spikes?
How do they handle VIPs?
How do they handle major incidents?
What happens when a technician doesn't know the answer?
Is there 24×7 support, and is it actually staffed 24×7?
Can you speak directly to Tier 2/3?
How much technician turnover do they have?
What is their average technician tenure?
The single best question:
"Show me the last 90 days of anonymized help-desk metrics for a customer roughly our size."
A provider that can't—or won't—show meaningful operational metrics deserves scrutiny.
4. Make them demonstrate the service
Don't just run an RFP.
Give your finalists 5–10 realistic tickets and ask them to demonstrate how they'd handle them.
For example:
"User can't connect to VPN."
"Executive's laptop won't connect to Teams five minutes before a board meeting."
"New employee starts Monday; laptop hasn't been provisioned."
"User reports a suspicious MFA prompt."
"Printer isn't working for the accounting department."
"Employee needs access to three applications."
"CEO calls after hours because email isn't working."
rather than simply telling you that they have "great customer service."
5. Be extremely specific about SLAs
Don't accept:
"We provide industry-leading SLAs."
Put measurable commitments into the contract.
For example:
Priority
Example
Response
Target resolution
P1
Major outage
15 min
4 hrs / workaround
P2
Department outage
30 min
8 hrs
P3
Individual unable to work
1 hr
1 business day
P4
Routine request
4 hrs
2–3 business days
Those numbers are examples, not universal benchmarks—you should establish targets from your current ticket data and business requirements.
More importantly, define what "response" and "resolution" actually mean. Otherwise the MSP can technically meet the SLA by sending:
"We're looking into it."
Gartner similarly emphasizes clear service levels and SOW language because vague scope and deliverables make providers difficult to hold accountable.
I'd also negotiate:
SLA measurement methodology
Exclusions
Service credits
Chronic SLA failure remedies
Escalation procedures
Reporting requirements
Customer satisfaction targets
Ticket reopen rates
First-contact resolution
Backlog limits
6. Security deserves almost as much scrutiny as support
You're giving an outside company privileged access to your environment.
That makes the MSP a security dependency, not merely a vendor.
CISA warns that compromising an MSP can provide attackers with a pathway into multiple customer environments.
I'd require evidence around:
SOC 2 Type II and/or ISO 27001
MFA everywhere
Privileged access management
Least privilege
Separate admin accounts
Conditional access
Endpoint security
Logging and monitoring
Background checks
Employee security training
Security incident notification
Breach response
Backup/recovery
Business continuity
Disaster recovery
Subcontractor management
Data segregation
Access reviews
Offboarding procedures
CISA's current MSP guidance specifically recommends obtaining evidence around certifications/attestations, security practices, employee vetting, logging, data segregation, incident management, and the MSP's ability to provide relevant security telemetry.
I'd also ask:
"Show me exactly how an MSP technician gets privileged access to one of our systems."
You want to see a controlled process—not a shared Domain Admin account sitting in a password vault.
7. Investigate their actual customers
References are incredibly valuable, but don't just ask for "three references."
Ask for:
One customer approximately your size
One customer that has been with them >3 years
One customer who migrated from another MSP
One customer with a similar technology stack
Then ask those customers:
"What do you wish you knew before signing?"
"What does the MSP still not do well?"
"How much management attention does the MSP require from your IT leadership?"
"When something goes wrong, what happens?"
"Would you hire them again?"
That last question is often more informative than a dozen vendor presentations.
8. Pay close attention to the transition plan
A great MSP can still fail spectacularly during onboarding.
Require a written 30/60/90-day transition plan.
It should cover:
Asset discovery
Documentation transfer
Network discovery
Account/access setup
Monitoring deployment
Endpoint tooling
Ticket migration
Knowledge transfer
Application documentation
Vendor contacts
Escalation paths
Runbooks
User communications
Baseline metrics
Service commencement criteria
I'd actually make successful transition a contractual milestone, rather than simply accepting "go-live" as success.
9. Ask how they make money
This is an underrated part of MSP selection.
Understand whether the MSP makes money from:
Per-user fees
Per-device fees
Minimum monthly charges
Projects
Hardware
Licensing
Security services
Cloud services
After-hours support
Onsite visits
Change requests
Then ask:
"What incentives does your pricing model create for you?"
For example, if they charge separately for every onsite visit, they may have an incentive to avoid solving certain issues remotely. If they're paid a fixed fee, they may have an incentive to automate aggressively.
Neither model is automatically good or bad—you just want to understand it.
10. Watch for these red flags
I'd be cautious if an MSP:
Talks more about products than outcomes
Can't produce real operational metrics
Won't let you meet actual technicians
Uses subcontractors without transparency
Has vague SLAs
Has huge numbers of certifications but little operational evidence
Promises "unlimited" everything
Can't explain escalation
Has no meaningful transition methodology
Wants broad administrative access immediately
Can't explain its own security architecture
Has unusually high technician turnover
Gives you a very low initial price but a huge add-on rate card
Doesn't ask many questions about your environment
Has a sales team that seems substantially more sophisticated than the service organization
That last one is a big one.
You are buying the service organization, not the sales presentation.
11. I'd run the selection as a 3-stage process
Stage 1 — RFI
Send 8–12 MSPs a short questionnaire.
Eliminate companies that don't meet your non-negotiables.
Stage 2 — RFP
Take perhaps 4–5 finalists and give them the same requirements, ticket volumes, environment information and SLA expectations.
Require standardized pricing.
This prevents vendors from interpreting the requirements differently. Gartner's recent sourcing guidance similarly emphasizes clear requirements, SOWs and measurable service expectations.
Stage 3 — Proof of capability
Take the top 2–3 and have them:
Demo their help desk
Walk through real tickets
Show reporting
Show their escalation process
Explain a security incident
Walk through onboarding
Meet the actual service-management team
Provide references
Review the draft SLA/SOW with you
Don't choose the winner until after Stage 3.
12. The contract matters enormously
Make sure the final agreement covers:
Exact service scope
SLA/SLO definitions
Pricing
Rate card
Annual increases
Minimum commitments
Service credits
Security requirements
Data ownership
Data return
Confidentiality
Breach notification
Subcontractors
Insurance
Business continuity
Disaster recovery
Audit rights
Access controls
Documentation ownership
IP ownership
Termination rights
Transition assistance
Exit costs
Knowledge transfer
The exit clause is particularly important.
Before signing, ask:
"If we terminate this contract three years from now, exactly what will you give us and how much will the transition cost?"
You want a very boring answer.
My recommended scorecard
If I were in your position, I'd build a spreadsheet with roughly 50–70 scored questions, grouped into:
Service desk operations — 25%
Security — 15%
Technical capability — 15%
SLA/performance — 15%
Transition — 10%
References/culture — 10%
Commercials — 10%
Score each finalist 1–5, require written evidence for scores of 4 or 5, and have your IT/security/procurement stakeholders score independently before discussing the results.
That reduces the chance that the most polished salesperson wins.
One final recommendation
I'd avoid starting with "Which MSPs are the best?"
Start with:
"What does excellent outsourced IT support look like for our organization, and what evidence would prove that an MSP can deliver it?"
Then make vendors compete against that definition.
If you tell me roughly how many employees/endpoints you have, whether you're Microsoft 365/Entra, your industry, locations, current ticket volume, and whether you want only help desk or also infrastructure/security, I can turn this into a ready-to-send MSP RFP with requirements, 50–70 evaluation questions, SLA requirements, scoring matrix, and a vendor comparison spreadsheet structure.
One final recommendation
I'd avoid starting with "Which MSPs are the best?"
Start with:
"What does excellent outsourced IT support look like for our organization, and what evidence would prove that an MSP can deliver it?"
Then make vendors compete against that definition.
If you tell me roughly how many employees/endpoints you have, whether you're Microsoft 365/Entra, your industry, locations, current ticket volume, and whether you want only help desk or also infrastructure/security, I can turn this into a ready-to-send MSP RFP with requirements, 50–70 evaluation questions, SLA requirements, scoring matrix, and a vendor comparison spreadsheet structure.
Stage 1 — RFI
Send 8–12 MSPs a short questionnaire.
Eliminate companies that don't meet your non-negotiables.
Stage 2 — RFP
Take perhaps 4–5 finalists and give them the same requirements, ticket volumes, environment information and SLA expectations.
Require standardized pricing.
This prevents vendors from interpreting the requirements differently. Gartner's recent sourcing guidance similarly emphasizes clear requirements, SOWs and measurable service expectations.
Certifications: Verify compliance standards relevant to your industry, such as SOC 2 Type II, HIPAA, or ISO 27001.
Access management: Understand how they handle credentials, privileged access management (PAM), and multi-factor authentication (MFA) within your environment.
Data residency: Confirm where your user data and ticket logs are stored, processed, and backed up.
Assess Technical Alignment and Integration
Toolchain compatibility: Check if they integrate smoothly with your existing stack (e.g., ServiceNow, Jira, Zendesk, or Microsoft 365).
Tiered support structure: Clarify where Tier 1 ends and Tier 2/3 begins, and how seamless the escalation path is to your internal team or third-party vendors.
Documentation ownership: Ensure the contract explicitly states that your organization owns all documentation, runbooks, and configurations they build or update.
Scrutinize Staffing and Operational Model
Follow-the-sun vs. shift coverage: Determine if they offer true 24/7/365 coverage or just after-hours paging services.
Agent training and retention: Ask about their turnover rates and how they train agents on your specific company culture, vertical, and software stack.
Communication channels: Check if they support the channels your users actually use (phone, email, chat, Microsoft Teams, or Slack integration).
Review Financial and Contractual Transparency
Pricing structure: Analyze whether they charge per-user, per-device, or per-ticket, and look out for hidden fees for onboarding, after-hours support, or project work.
Exit strategy: Review the offboarding clause carefully to ensure a clean transition of knowledge, data, and access if you ever decide to change providers.
References and case studies: Request references from clients of a similar size and complexity to your organization.
If you'd like, tell me:
What is your company size and user count?
Are you looking for 24/7 support or business hours only?
I can help you build a specific RFP (Request for Proposal) questionnaire or weigh per-user vs. per-ticket pricing models.
Response and resolution times: Set tiered metrics based on severity levels (e.g., critical business stoppage vs. a password reset).
Penalty clauses: Look for contracts that offer service credits if they consistently miss agreed-upon SLA benchmarks.
Evaluate Technical Stack and Integration
Ticketing system integration: Check if their platform can sync or integrate smoothly with your internal tools (like Jira, ServiceNow, or ConnectWise).
Tiered support structure: Verify how they handle escalation from Tier 1 (basic troubleshooting) to Tier 2 and Tier 3 (network or system administration).
Toolset transparency: Ensure they provide real-time dashboards and granular reporting so you retain full visibility over user friction points.
Audit Security and Compliance Standards
Certifications: Request proof of independent audits, such as SOC 2 Type II compliance or ISO 27001 certification.
Data privacy handling: Verify how their remote support staff handles credential access, endpoint management, and customer data privacy.
Security tool compatibility: Confirm their agents do not conflict with your existing endpoint detection and response (EDR) or identity provider (IdP) tools.
Assess Cultural Fit and Communication
Communication style: Test their agent soft skills during the sales and vetting process; they represent your department to the rest of the company.
Dedicated management: Ask if you will have a designated account manager or fractional service delivery manager for regular reviews.
References and track record: Speak with current clients of a similar size and industry vertical to evaluate their actual performance under pressure.
If you'd like to narrow this down, tell me:
What is your company size and user count?
Are you looking for 24/7 coverage or standard business hours?
I can help you build a tailored RFP template or scorecard for your vendor evaluations.
Choosing an MSP for help desk outsourcing is less about finding the vendor with the most impressive technology stack and more about finding a partner that can reliably operate as an extension of your IT team. A good selection process evaluates service quality, operational maturity, security, and business fit—not just price.
Here is a practical framework I would use as an IT Director.
1. Define what success looks like before talking to MSPs
Document your current state and desired outcomes:
Number of users, endpoints, locations, and applications supported
A provider cannot be evaluated fairly if you do not define what you are buying.
2. Evaluate the help desk operating model
The biggest mistake companies make is buying "hours of support" instead of a support outcome.
Ask:
Who answers the phone/chat/tickets?
Are agents employees of the MSP or subcontractors?
What percentage of tickets are resolved at first contact?
What is the escalation path?
Do they have dedicated resources for your account?
What is the average technician tenure?
How many clients does each technician support?
A strong MSP should be able to explain its staffing model clearly and show how it prevents your users from becoming anonymous tickets in a queue.
3. Demand measurable SLAs and reporting
Avoid vague promises like "fast response" or "excellent customer service."
Your agreement should define:
Metric
Example requirement
Initial response
15–60 minutes for critical issues
Resolution targets
Defined by priority level
Escalation
Named process and timelines
Ticket ownership
Clear accountability
Reporting
Monthly service reviews
Ask to see sample reports:
Ticket volume trends
SLA attainment
First-contact resolution
Aging tickets
User satisfaction scores
Root cause analysis
A provider should measure the same things you care about.
4. Test their technical depth
Your help desk will touch your environment daily. Verify they understand your stack.
Ask about experience with:
Microsoft 365 / Entra ID
Intune or endpoint management
Windows/macOS support
Networking
VPN and remote access
SaaS applications
Identity management
Device lifecycle management
Your industry-specific applications
Do not be overly impressed by a long list of vendor badges. Ask them to explain how they have solved problems similar to yours.
5. Treat security as a primary selection criterion
An MSP will likely have privileged access to your systems. Evaluate them like a third-party risk partner.
Ask:
Do they enforce MFA internally?
How do they manage privileged accounts?
Do technicians use named accounts?
How are administrative credentials stored?
What endpoint security tools do they use?
Do they conduct security awareness training?
Do they have incident response procedures?
Can they provide security audit documentation?
Their security practices become part of your risk profile.
6. Review onboarding carefully
The transition period often determines whether the relationship succeeds.
A good MSP should have a structured onboarding plan covering:
Environment discovery
Documentation review
Knowledge transfer
Tool deployment
User communication
Support process changes
Escalation procedures
First 30/60/90-day milestones
Ask:
"Walk me through exactly what happens from contract signing to the first day your team supports our users."
If the answer is vague, expect problems later.
7. Check references — but ask the right questions
Do not just ask, "Are you happy with them?"
Ask references:
How long have you used them?
What was the transition like?
How often do SLAs get missed?
How do they handle major outages?
Do they proactively identify problems?
What surprised you after signing?
What would you change about the relationship?
Request references from organizations similar to yours in size and complexity.
8. Understand the pricing model
Compare total cost, not monthly price.
Look for:
Per-user vs. per-device pricing
Included hours
After-hours charges
Project rates
Onboarding fees
Tool licensing
Hardware/software markups
Contract escalation clauses
Minimum commitments
A cheaper MSP can become expensive if everything outside basic tickets becomes an additional charge.
9. Watch for red flags
Be cautious if an MSP:
Cannot provide references
Won't share SLA metrics
Has unclear escalation procedures
Pushes long contracts before proving value
Treats security as an optional add-on
Cannot explain who will actually support you
Has poor documentation practices
Focuses more on tools than outcomes
10. Use a weighted scorecard
I would typically score finalists like this:
Category
Weight
Help desk quality and staffing model
25%
Security maturity
20%
SLA performance and reporting
15%
Technical capability
15%
Cultural fit and communication
10%
Transition/onboarding plan
10%
Price matters, but the cheapest MSP often becomes expensive when internal staff must manage escalations, complaints, and missed expectations.
Suggested RFP questions
A good shortlist process might ask each MSP:
Describe your help desk staffing model.
What was your SLA performance last quarter?
What percentage of tickets are resolved without escalation?
Who supports our account after hours?
What security controls protect your technicians and tools?
Provide three similar customer references.
Describe your onboarding process.
What is included in the monthly fee?
What services trigger additional charges?
How do we exit the agreement and retrieve our documentation?
For an IT Director, the best MSP is usually the one that makes your environment more predictable, measurable, and secure—not necessarily the one that promises the fastest ticket closure.
If you’re outsourcing the help desk, I’d evaluate an MSP less like a technology vendor and more like an extension of your IT department. The biggest mistake is choosing based on price, tool stack, or a polished sales presentation rather than the provider’s ability to consistently deliver good support.
CISA specifically recommends defining requirements, SLAs, incident responsibilities, access controls, and security responsibilities before selecting an MSP.
1. Define exactly what you want outsourced
Before talking to vendors, document your current environment and decide what the MSP actually owns.
For a help-desk engagement, I'd define:
Coverage: 8×5, extended hours, 24×7, holidays
Users: total employees, locations, VIPs/executives
Endpoints: Windows/Mac, mobile, thin clients, etc.
Escalation: what comes back to your internal IT team
This prevents the classic MSP problem of discovering six months later that "that's outside our managed services scope."
2. Put the SLA at the center of the evaluation
Don't accept vague promises such as "fast response" or "world-class support."
Require measurable commitments.
For example:
Metric
Example requirement
P1 response
≤ 15 minutes
P2 response
≤ 30 minutes
P3 response
≤ 4 business hours
P4 response
≤ 1 business day
P1 escalation
Immediate
P1 update frequency
Every 30–60 minutes
Ticket acknowledgement
I'd also distinguish response time, restore time, and resolution time. Vendors sometimes advertise excellent response SLAs while making no meaningful commitment about actually fixing the problem.
CISA recommends specific performance SLAs with clear delineation between operational IT and security services.
3. Ask how they actually staff the desk
This is one of the most important areas to investigate.
Ask:
"Walk me through what happens when one of our users calls at 10:17 AM on a Tuesday."
Then dig into:
How many agents are actually on the desk during your coverage hours?
Where are they located?
Are they employees or contractors?
What's the agent-to-user ratio?
What is their annual turnover?
What's average agent tenure?
How do they handle lunch/shift changes?
How do they handle spikes?
What happens when an agent doesn't know the answer?
How quickly does a ticket reach Tier 2?
Do you get a dedicated team or a pooled queue?
Can you interview the people who will actually support you?
Huge red flag: the salesperson describes a dedicated team, but the contract actually provides access to a generic pooled help desk.
4. Test their troubleshooting ability
Don't just ask for references. Give finalists a few realistic scenarios.
For example:
"Our CFO can't access Outlook, Teams, or several SaaS applications. Other users are fine. Walk us through your troubleshooting process."
Or:
"At 8:05 AM, 30 users report that they're unable to authenticate. What happens?"
You're looking for evidence that they:
Establish impact and scope.
Check for known incidents.
Troubleshoot systematically.
Communicate with the user.
Escalate appropriately.
Document the resolution.
Identify recurring/root causes.
A good MSP should demonstrate operational maturity, not merely familiarity with Microsoft products.
5. Evaluate their security as seriously as their support
An MSP will potentially have privileged access to your environment, so you're effectively adding another attack surface.
CISA warns that MSPs can be an infection vector for ransomware and recommends least privilege, separation of duties, MFA, logging, and contractual security requirements.
I'd ask for:
SOC 2 Type II report
ISO 27001 certification, if applicable
Recent penetration-test summary
Cyber liability insurance
Security policies
Employee background-check policy
MFA requirements
Privileged-access management
Just-in-time/JIT access, if available
Dedicated admin accounts
Logging and monitoring of technician activity
Customer data segregation
Incident-response plan
Breach-notification commitments
Backup/recovery responsibilities
Business continuity/disaster recovery testing
Don't simply ask "Are you SOC 2 compliant?" Ask for the report and understand the scope and exceptions.
NIST's 2026 supply-chain guidance also emphasizes due diligence around supplier resilience, foundational cyber practices, provenance, and supply-chain tiers.
6. Make the MSP prove its reporting capabilities
As IT Director, you shouldn't have to call the MSP to find out whether they're doing a good job.
Your monthly service review should show things like:
Ticket volume
Tickets by category
Tickets by priority
First-contact resolution
Mean time to respond
Mean time to resolve
SLA compliance
Reopened tickets
Aging tickets
Escalations
Backlog
User satisfaction
Repeat incidents
Major incidents
Problem-management trends
Endpoint/patching status, if included
More importantly, ask:
"Show me an anonymized report from one of your existing customers."
A mature MSP should be able to demonstrate exactly how it manages service quality.
7. Investigate the economics carefully
Get pricing normalized so you can compare apples to apples.
Ask whether pricing is based on:
Per user
Per device
Per endpoint
Per ticket
Per technician
Fixed monthly fee
Minimum monthly commitment
Hybrid model
Then identify every excluded charge.
Particularly watch for:
After-hours support
VIP support
On-site visits
Projects
New-user onboarding
Offboarding
Network changes
Server work
Microsoft licensing
Security products
Vendor coordination
Major incident response
Travel
Hardware procurement
Documentation
Backup/recovery
"Out of scope" troubleshooting
A $30/user/month proposal can become much more expensive than a $45/user/month proposal once all the exclusions are accounted for.
8. Talk to references—but interview them properly
Don't ask:
"Are you happy with them?"
You'll get a useless answer.
Ask:
How long have you used them?
What was the biggest problem during implementation?
How long did it take to stabilize?
How often do you have to escalate to management?
Do they actually meet their SLAs?
How good are they during major incidents?
How good are they with executives?
What do they routinely not do well?
What unexpected charges have you encountered?
How difficult is it to get something out of scope?
What happens when you disagree with them?
Would you select them again?
If you were starting over, what would you negotiate differently?
That last question is particularly valuable.
9. Don't let the MSP dictate your technology strategy
Be cautious if the vendor's answer to every problem is:
"Buy our stack."
A good MSP should be able to explain why a particular tool is appropriate and work within your existing architecture when reasonable.
Ask:
"Which components of your recommended stack are mandatory, and which are optional?"
And:
"What happens if we decide to replace your RMM/PSA/EDR/M365 tooling?"
This also protects you from vendor lock-in.
10. Make implementation part of the evaluation
The transition is often harder than the steady-state service.
Require an implementation plan covering:
Discovery → documentation → tooling deployment → knowledge transfer → pilot → parallel support → cutover → stabilization → BAU
Ask specifically how they'll acquire knowledge about:
Your applications
Network
Business processes
VIPs
Known recurring issues
Vendors
Security procedures
Existing documentation
Exceptions and workarounds
I'd strongly prefer an MSP that proposes a 30–90 day transition/stabilization period with measurable milestones rather than one that says, "We'll get started Monday."
11. Put exit requirements in the contract
This is frequently overlooked.
Your contract should specify what happens when the relationship ends.
Require:
Complete return of your documentation
Configuration information
Credentials/accounts under your ownership
Ticket history
Knowledge-base articles
Asset information
Monitoring configuration
Data export
Assistance transitioning to your next provider
Defined transition period
No unreasonable termination fees
Clear ownership of scripts/automation created for you
CISA recommends formalizing responsibilities and requirements in the agreement, including incident management, outage compensation, data separation, and records/logging.
A practical scoring model
I'd use a weighted scorecard rather than letting the lowest bid win:
Category
Weight
Help-desk operational capability
25%
SLA/service quality
20%
Security & risk management
15%
Staffing & escalation model
10%
Technology/ITSM integration
10%
Reporting & governance
Then have 5–7 vendors complete the same RFP, narrow to three, and put the finalists through the same technical/service scenarios.
I'd also have the actual service-delivery manager participate in the finalist presentations—not just the salesperson and account executive.
My "green flags" vs. "red flags"
Green flags
They ask lots of questions about your environment before proposing anything.
They clearly separate Tier 1/2/3 responsibilities.
Their SLA metrics are measurable.
They readily provide references.
They can show real anonymized service reports.
Their technicians demonstrate structured troubleshooting.
They have strong internal security controls.
They proactively discuss transition and exit.
Pricing is transparent.
They acknowledge what they don't do well.
Red flags
Everything is "AI-powered" but nobody can explain the operating model.
The salesperson can't explain staffing.
"24/7 support" actually means an on-call technician.
They won't let you speak with current customers.
They won't provide meaningful security documentation.
Their SLA only measures response time.
Most services are "out of scope."
They insist on replacing your entire technology stack.
The contract makes termination painful.
They promise a spectacularly low price without explaining how they're staffing it.
If I were running your selection
I'd make the process:
Week 1: Define requirements, ticket volumes, coverage and SLAs
Week 2: Issue RFP to 5–7 MSPs
Week 3: Evaluate written responses
Week 4: Shortlist 3
Week 5: Technical/service scenario + finalist presentations
Week 6: Reference checks + security due diligence
Week 7: Negotiate MSA/SLA/pricing
Week 8: Select vendor and begin transition
The key principle is: buy the service, not the sales pitch. Your best MSP is the one that can repeatedly deliver measurable user support while giving you visibility, security, and an uncomplicated way out if they don't perform.
If you'd like, I can also build you a complete MSP help-desk RFP and 100-point vendor scorecard you can send to vendors, including the exact questions I'd ask about SLAs, staffing, security, pricing, references, and transition.
I'd make the process:
Week 1: Define requirements, ticket volumes, coverage and SLAs
Week 2: Issue RFP to 5–7 MSPs
Week 3: Evaluate written responses
Week 4: Shortlist 3
Week 5: Technical/service scenario + finalist presentations
Week 6: Reference checks + security due diligence
Week 7: Negotiate MSA/SLA/pricing
Week 8: Select vendor and begin transition
The key principle is: buy the service, not the sales pitch. Your best MSP is the one that can repeatedly deliver measurable user support while giving you visibility, security, and an uncomplicated way out if they don't perform.
If you'd like, I can also build you a complete MSP help-desk RFP and 100-point vendor scorecard you can send to vendors, including the exact questions I'd ask about SLAs, staffing, security, pricing, references, and transition.
Your contract should specify what happens when the relationship ends.
Require:
Complete return of your documentation
Configuration information
Credentials/accounts under your ownership
Ticket history
Knowledge-base articles
Asset information
Monitoring configuration
Data export
Assistance transitioning to your next provider
Defined transition period
No unreasonable termination fees
Clear ownership of scripts/automation created for you
CISA recommends formalizing responsibilities and requirements in the agreement, including incident management, outage compensation, data separation, and records/logging.
A practical scoring model
I'd use a weighted scorecard rather than letting the lowest bid win: