IT Operations

Warning Signs Your IT Provider Isn't Actually Managing Anything

MSP Worx · 4 min read · Updated Oct 10, 2026

There is a version of managed IT that is really just a monthly retainer for reactive support. The monitoring agent is installed. The alerts go somewhere. Nobody reads them. Patches are set to automatic and nobody checks whether they applied. Backups run and nobody has ever restored one.

From the client's side this looks identical to properly managed IT — right up until the day it does not, which is usually the worst possible day.

The good news is that the difference is verifiable. Managed service produces evidence as a byproduct. Here is what to ask for.

Ask for a restore, not a backup report

Backup software reports success when it completes a job. It does not report whether the resulting backup can actually be restored, whether it covers what matters, or whether the retention period matches your obligations.

The only meaningful evidence is a test restore. Ask when the last one was performed, what was restored, and how long it took. A provider doing this properly has a documented answer and probably a schedule.

If the answer is that backups "run nightly and we would be alerted if they failed" — that is a backup job, not a recovery capability. The distinction becomes real only during an incident, when it is too late to discover it.

Ask for last month's patch compliance

A managed environment produces a patch report: which machines are current, which are behind, which failed and why, which need a reboot the user keeps deferring. That last category is where most real exposure lives.

If no such report exists, patching is set to automatic and unsupervised. Automatic patching is better than nothing, but it fails silently and routinely — machines that are off, that fail mid-update, that need a restart nobody performs.

Ask what alerts fired last week and what happened to them

Monitoring generates alerts continuously: disk space, failed services, offline devices, security events. The value is entirely in triage. An alert nobody acts on is worse than no alert, because it creates the appearance of coverage.

A provider managing the environment can tell you what fired, what was actioned, and what was suppressed as noise. A provider who cannot has an agent installed and a dashboard nobody opens.

Ask for the asset inventory and the age profile

Every device, its age, warranty status, operating system version, and whether that version is still receiving security updates. Then ask which machines are due for replacement in the next twelve months, and what that will cost.

This is the difference between a provider planning your environment and one waiting for it to fail. Hardware failure is predictable in aggregate — that is what makes an unmanaged estate expensive rather than merely risky.

Ask which accounts have administrative access

You should get a short, current list, and it should not contain anyone who has left the business. This is the check most likely to produce an uncomfortable silence.

Also ask: do former employees still have active accounts anywhere? Are there shared administrator credentials? Is multi-factor authentication enforced on every administrative account, including the provider's own access into your environment?

That last one matters more than people realise. Your provider's access to your systems is a privileged path into your business, and it should be protected at least as well as your own.

Ask when the last security review happened

Not a sales assessment — an actual review of configuration against a standard. What is exposed to the internet, what MFA coverage looks like, what the email security configuration is, whether legacy authentication is still enabled somewhere.

Most environments accumulate configuration debt continuously. Reviewing it is a scheduled activity or it does not happen.

The pattern underneath all of these

Every question above asks for evidence produced as a byproduct of doing the work. That is deliberate. Claims are easy and evidence is not, and a provider genuinely managing an environment can produce all of it within a day or two because it already exists.

A provider who needs a week, or who answers with reassurance rather than documents, is telling you something specific: the work generating that evidence is not happening.

Ask forEvidence of real managementRed-flag answer
A recent test restoreDate, what was restored, how long it took; a restore schedule"Backups run nightly and we would be alerted"
Last month’s patch complianceReport of current, behind, failed and reboot-pending machinesPatching is "set to automatic"
Last week’s alertsWhat fired, what was actioned, what was suppressed as noiseNo answer; a dashboard nobody opens
Asset inventory and age profileEvery device with age, warranty, OS support status and a 12-month replacement planNo inventory, or an out-of-date one
Administrative access listShort, current, no leavers, MFA on every admin account including the provider’sAn uncomfortable silence
Last security reviewA configuration review against a standard, on a scheduleA sales assessment, or none

If the answers are bad

Raise it directly and in writing before concluding anything. Some of this is scope — a helpdesk-only agreement genuinely does not include patch management or security review, and the provider may be delivering exactly what was sold. That is a contract problem rather than a performance problem, and it is fixable.

If the scope says these things are included and the evidence does not exist, that is different. At that point you are paying for a service that is not being delivered, and the risk sitting in your environment has been accumulating for as long as the arrangement has been running.

Sources

  1. Cybersecurity and Infrastructure Security Agency (CISA) — #StopRansomware Guide
  2. Cybersecurity and Infrastructure Security Agency (CISA) — Known Exploited Vulnerabilities Catalog
  3. Cybersecurity and Infrastructure Security Agency (CISA) — Protecting Against Cyber Threats to Managed Service Providers and their Customers (AA22-131A)
  4. Microsoft Learn — Best practices for Microsoft Entra roles
  5. Microsoft Learn — Block legacy authentication with Conditional Access

Want a straight answer for your business?

Talk to an advisor about your environment. No pitch, no obligation.