What Managed Service Provider (MSP) means in practice
The managed model exists because internal IT teams below a certain size cannot cover the breadth modern environments require. A single systems administrator cannot simultaneously be current on identity, endpoint management, cloud infrastructure, networking, security operations and licensing, and cannot provide continuous coverage while taking leave.
Scope varies more than the label suggests, and the differences are where disputes come from. Fully managed means the provider owns outcomes for everything in scope. Co-managed means the provider works alongside an internal team, typically taking the after-hours load, specialist platforms and escalation while internal staff keep business relationships and application ownership. Project work is often separate from the recurring agreement, which is reasonable as long as the boundary is written down.
Pricing is usually per user or per device. Per user is simpler when people have multiple devices and it maps cleanly to licensing. Per device suits environments with shared terminals or heavy server estates. Either way, the number that matters is the total including licences, security tooling, backup and after-hours coverage, because these are frequently quoted separately.
The questions that reveal quality are operational. What are the contracted response and resolution targets by severity, and are they reported against monthly? Who is the named engineer that knows the environment, and what happens when they leave? Is documentation maintained and handed over, or held hostage? Is security monitoring included or an upsell? What is the exit process — how quickly are administrative credentials, documentation and tenant ownership transferred?
The commercial risk to watch is misalignment: an agreement priced on ticket volume rewards a provider for an environment that generates tickets. Agreements built around reducing recurring incidents, with reporting to prove it, align the two sides better.
How we help with this
Related terms
- APRA CPS 230CPS 230 is the APRA prudential standard on operational risk management.
- APRA CPS 234CPS 234 is the APRA prudential standard on information security.
- Azure Virtual Desktop (AVD)Azure Virtual Desktop is Microsoft's cloud virtual desktop infrastructure service.
- Conditional AccessConditional Access is the policy engine in Microsoft Entra ID that decides what happens after a sign-in is authenticated.
