Reviewing your MSP relationship
A practical, vendor-neutral guide to operational clarity, continuity and technology governance for Australian businesses.
Not every MSP review begins because something has gone wrong. Many reviews are simply a responsible governance exercise as the business grows. The goal of this page is clarity, not pressure.
Documented environment review
Written, retained by the business
Identity, backup and governance
Mapped against Essential Eight ML1
Useful even if nothing changes
Strengthens any provider relationship
The acknowledgement
Reviewing your MSP does not mean blaming your MSP.
Many reviews are simply a responsible governance exercise.
A review is not a complaint
For many businesses, the hardest part of reviewing a provider is emotional, not technical.
The current provider may have helped the business for years. They may know the staff, understand the history and have supported the organisation through outages, projects, office moves, growth and difficult moments. That matters and deserves acknowledgement.
A provider review does not need to dismiss that history. It does not need to assume poor service. It does not need to become confrontational. Sometimes a review simply means the business has changed and the operating model needs to be checked against where the organisation is now. That is responsible leadership, not criticism.
A measured review separates the things that often get lumped together as "the MSP isn't working":
Service issues
Specific, recent, evidenced
Documentation gaps
Often inherited, often fixable
Contractual obligations
Read the agreement carefully
Inherited technical debt
Decisions made before either party
New compliance expectations
Insurance, OAIC, board reporting
Business growth
The shape of the business has changed
Changing support requirements
Operating model, not provider quality
Genuine provider performance
Sometimes real, often the smallest factor
On transparency
A strong MSP relationship should not depend on mystery. It should depend on clarity, process and mutual accountability. A mature provider is generally comfortable with transparency, because it protects everyone, reduces confusion during incidents and makes renewals easier.
Why businesses actually open a review
None of these signals automatically mean the current provider has done anything wrong. They generally mean the business has reached a point where operational visibility, documentation and governance need to mature alongside it.
Common operational signals
Growth across multiple locations
The service model that worked at 25 staff is rarely the same shape at 80.
Microsoft 365 has become central
Identity, files, Teams and security policies now live in one tenant.
Cyber insurance has tightened
Underwriters now expect evidence, not assurances, at renewal.
Documentation is hard to produce
Asset registers, network diagrams and identity baselines feel incomplete.
Internal teams have changed
New CIO, new operations leader, new finance leader, new expectations.
Incident readiness is unclear
Leadership cannot easily describe what would happen in the first hour.
Board reporting has matured
Quarterly governance now expects risk registers and improvement roadmaps.
Quarterly reviews have stopped
Service is reactive rather than scheduled, even when everyone is working hard.
Contracts are coming up for renewal
A renewal is a natural moment to confirm scope, inclusions and governance rhythm.
A move toward co-managed IT
Internal IT has grown enough that responsibilities need redefining.
A note on tone
A healthy review does not start with blame. Technology environments are living systems built through decisions made over years. Even well-managed environments accumulate documentation gaps as they evolve faster than the governance around them. The best reviews are calm, factual and constructive.
Operating principles
A competent review looks the same, regardless of provider.
Six operating principles for any provider review.
Continuity comes before transformation
The first objective of any transition is that the business continues to operate. Improvement programmes and security uplifts are sequenced after operational stability is established, not bundled into cutover weekend.
Documentation belongs to the business
Asset registers, network diagrams, identity baselines and runbooks are operational artefacts the business should retain in its own systems. A provider holds copies, not originals.
Identity is the centre of gravity
In a Microsoft 365 environment, identity controls who can do what, from where, on which device. Conditional Access, MFA coverage, privileged role assignments and break-glass accounts are reviewed before anything else.
Backups are only real once restored
A backup that has never been restored is a hypothesis. A verified restore inside the first 30 days is part of how recoverability is confirmed, not an optional extra.
Outgoing providers are part of the process
Most providers behave professionally when a client moves on. The handover is treated as a structured operational exercise between two technology teams, not a confrontation.
Governance survives staff turnover
A mature operating model is one a new CIO, finance leader or operations manager can pick up and understand quickly. Documentation, review cadence and ownership clarity exist for the business, not the provider.
The governance view
Microsoft 365 has quietly changed what an MSP is for.
Two lenses every leadership team should use.
Part one · Microsoft 365 governance
Microsoft 365 has quietly changed what an MSP is for
For most Australian businesses, Microsoft 365 now holds email, files, identity, Teams content, device policies and a meaningful slice of compliance evidence. It is the centre of operations rather than one application among many.
That shift has changed the modern MSP role. Helpdesk and infrastructure still matter, but identity governance, Conditional Access, privileged role management and tenant backup are now where operational risk concentrates. A provider that was a strong fit for break-fix support five years ago may simply need a broader operating model today.
The questions on the right are the ones we ask first in any environment review. None are designed to catch a provider out. They are designed to help the business understand its own posture.
Who holds Global Administrator access today?
Including any third-party vendors with persistent admin rights.
Is MFA enforced across every active user?
With Conditional Access policies documented and reviewed.
Are privileged role assignments reviewed quarterly?
Privileged Identity Management or equivalent governance in place.
Are break-glass accounts configured and tested?
Documented, monitored, with credentials stored independently.
Is legacy authentication still permitted?
Basic auth, IMAP and POP turned off unless explicitly required.
Is Microsoft 365 data backed up independently?
Mailboxes, OneDrive, SharePoint and Teams content recoverable outside the tenant.
A business that can answer each of the six questions in writing within an hour is generally well governed. A business that cannot is not failing. It simply has documentation work to do.
Part two · The executive view
Executives do not need every technical detail. They do need confidence the right questions have been answered.
Business owners, directors and executives do not need to understand firewall rules, Conditional Access policies or backup retention schedules. That is engineering work.
What leadership does need is a clear, written answer to a small set of plain-English questions. If those answers exist, the business is in operational governance. If they do not, the business is in hope.
None of these are technical micromanagement. They are operational governance, expressed in the language a board can read.
Operational governance · executive view
Who owns the key systems and who has administrative access today
Whether multi-factor authentication is enforced across every user
Whether backups can actually be restored and when that was last tested
Whether users are removed properly from systems when they leave
Whether the documentation needed during an incident actually exists
Whether cyber insurance questions can be answered accurately and quickly
Whether there is a plan, in writing, if something significant goes wrong
Whether the current provider relationship still matches what the business needs
A leadership team that can answer this list in writing within an afternoon is well governed, regardless of provider.
Concerns & impact
Most leaders are not afraid of change. They are concerned about disruption.
A well-considered approach has a minimal effect on risk and cost.
Part one · The practical concerns
Most leaders are not afraid of change. They are concerned about disruption.
These are the practical questions that come up in the first conversation, in roughly the order they arrive. Naming them in advance is part of how anxiety is reduced. Planning replaces uncertainty with process.
Will staff lose access to email?
Mailboxes, calendars and Teams data remain inside the same Microsoft 365 tenant throughout. No mailbox is moved or recreated.
Will files disappear?
SharePoint, OneDrive and Teams files are not touched at cutover. A verified, independent backup is taken before any administrative change is executed.
Will support tickets get missed?
Open tickets are reviewed individually with both providers, formally transferred, and tracked through to closure during the hypercare window.
Will the outgoing provider become difficult?
Most providers behave professionally when expectations are written and respectful. Where cooperation is poor, contractual and regulatory paths exist.
Will this take more time than we have?
Leadership is typically needed for four to six short conversations. The technical work happens in the background.
Will something break on Monday morning?
Cutover is scheduled outside business hours, runbooks include rollback triggers, and engineers are available through the first business day.
Will there be double billing?
Notice periods are read carefully against the existing agreement before transition is scheduled. Overlap windows are agreed in writing.
Will historical knowledge be lost?
Asset registers, runbooks and contextual notes are exported, structured and retained by the business before handover begins.
On planning
The purpose of planning is not to make a transition sound easy. The purpose is to make the risks visible, owned and controlled in advance, so leadership can sign off on a process they understand rather than approve a black box.
Part two · Internal load
A well-run review should reduce internal effort, not add to it
The people involved are usually already running operations, finance, HR, compliance and service delivery. The process should carry the technical work, not push it back onto the business. Leadership stays informed and in control. Staff barely notice.
What leadership is needed for
A few short conversations
- Explaining business priorities and known constraints
- Confirming the critical systems the business cannot operate without
- Identifying key staff, sites and operational rhythms
- Approving access requests against the existing agreement
- Reviewing findings and signing off on commercial decisions
- Agreeing the timing and tone of staff communications
- Confirming what level of operational risk is acceptable
Leadership should be informed and involved, not buried in technical coordination.
What staff actually notice
Usually very little
- A new support contact and updated helpdesk instructions
- Possibly a re-authentication prompt during cutover weekend
- A new monitoring or endpoint protection agent appearing on devices
- Clearer escalation paths if a ticket is taking too long
- Improved communication on open tickets through the changeover
- A short, plain-English explanation of what is changing and why
- Generally, very little visible disruption to day-to-day work
The objective is not to make IT change visible for its own sake. It is to make support clearer while keeping normal business activity stable.
Part three · Standing still is also a decision
Doing nothing carries its own operational risk
Changing providers carries risk. So does standing still. If documentation is incomplete, backups are untested, privileged access is informal or incident procedures live in someone's head, the business is already carrying operational risk. That risk rarely appears during normal weeks.
It usually appears under pressure, on the worst possible day. A review does not create those risks. It surfaces them early enough that they can be managed calmly, in writing, before they become incidents.
Where unmanaged risk tends to surface
A key staff member leaves and admin credentials become unclear
A cyber insurance renewal arrives and questions cannot be answered
A director asks for a written risk report on short notice
A backup needs to be restored for the first time in years
An administrator account is locked out at 5pm on a Friday
A domain renewal is missed and a public-facing service goes down
A breach or suspected breach occurs and the first hour is unclear
A provider relationship changes unexpectedly through merger or sale
None of these scenarios are unusual. They are the moments when the absence of documentation, backup verification or governance becomes expensive. A structured review brings them forward into a calm conversation rather than an incident response.
Transition methodology
Maturity is built incrementally, contextually and intentionally.
Five stages. A written deliverable at every stage.
Five stages · written deliverable at every stage
What happens in this stage
Scoped operational conversation with leadership to confirm priorities, obligations and known constraints
Read-only review of Microsoft 365, Entra ID, backup platform and network where access is available
Inventory of users, devices, licences, domains, certificates and key SaaS dependencies
Identity posture review: Global Administrator accounts, Conditional Access, MFA coverage, break-glass account status
Mapping against ASD Essential Eight Maturity Level 1 and SMB1001 baseline expectations
Written summary of operational risks, dependencies and documentation gaps
Environment review document. Retained by the business.
Note
A business can stop here. The review is useful regardless of what comes next.
Operational maturity
Maturity is built incrementally, not transformationally
Many businesses assume mature IT means large transformation projects. In practice, operational maturity is the result of small, consistent improvements over time. None of the rungs below are dramatic individually. Collectively, they significantly improve resilience and reduce operational friction.
Documentation written down
Asset register, network diagram and identity baseline exist on paper, even if imperfect.
MFA enforced and monitored
Multi-factor authentication is on for every user, with reporting in place. Exclusions are documented and reviewed.
Verified backup with restore tested
Critical systems are backed up to an independent location and a restore has actually been performed inside the last 90 days.
Endpoint detection and response
EDR is deployed on every endpoint and server, alerting goes somewhere a human reads, and incident process is documented.
Documented incident response plan
Plain-English playbook with named owners, communication tree and OAIC notification path. Tested at least annually.
Quarterly governance cadence
Scheduled reviews of risk, posture, licensing and roadmap with attendees, inputs and outputs all documented.
The rungs broadly align with ASD Essential Eight Maturity Level 1 baseline controls and the SMB1001 starter tier. A business at rung 03 or above is generally well placed for cyber insurance renewal in 2026.
Documentation the business retains
Seven operational artefacts. Held by the business.
A common operational risk in long-running provider relationships is that documentation accrues only on the provider's side. If the business ever needs to change provider, recover from an incident, or onboard new leadership, it effectively starts from zero.
The set below is the minimum documentation footprint any business of meaningful size should hold in its own systems, refreshed at least annually. Strong operational transparency generally creates stronger long-term partnerships, not weaker ones.
Broadly the documentation set the OAIC and most Australian cyber insurers expect a business to be able to produce within 48 hours of a notifiable event.
Operational artefact
Asset register
Users, devices, licences, domains and certificates with documented owners and renewal dates.
Finance · operations · audit
Network diagram
Sites, links, firewalls, switches, access points and core services. PDF with editable source files retained.
IT · auditors · incoming engineers
Identity baseline
Entra ID groups, Conditional Access policies, MFA coverage, privileged role assignments and break-glass account documentation.
Security · cyber insurance · auditors
Backup runbook
What is protected, where it is stored, how long it is retained, and the date of the most recent verified restore.
Operations · cyber insurance · IT
Vendor matrix
Third-party SaaS platforms, hardware vendors and telecommunications carriers with contract dates and administrative contacts.
Finance · procurement · IT
Incident response plan
Plain-English procedure covering who to contact, what is communicated, and the steps an engineer takes in the first hour.
Leadership · security · OAIC readiness
Governance schedule
Cadence of operational reviews, security reviews and licensing reviews, with documented attendees and inputs.
Leadership · IT · finance
Outcomes & next step
Staying, sharing, or moving. All three are legitimate.
The purpose of a structured review is clarity, not provider change.
Three valid outcomes
Stay with the current provider
Sometimes the existing relationship just needs structure
- Updated documentation requested from the provider
- Quarterly review cadence formalised
- Service expectations clarified in writing
- Backup and identity reporting improved
- Microsoft 365 governance uplifted alongside the existing provider
Often the best result is giving a capable provider the structure, authority and expectations they need to support the business properly.
Move to a co-managed model
Internal IT and an external partner sharing accountability
- Internal IT focuses on strategy, proximity and project work
- External partner delivers helpdesk, after-hours and security operations
- Roles, escalation paths and ownership documented end to end
- Often the right model between roughly 80 and 200 staff
- Reduces single-person dependency without losing institutional knowledge
The maths usually flips in this band: a single senior IT hire cannot deliver helpdesk, security operations and strategy simultaneously.
Transition to a new provider
Where the operating model genuinely no longer fits
- Reporting and governance expectations have outgrown the relationship
- Documentation is not available and cannot be produced
- Security expectations have moved beyond the current service model
- Multi-site or compliance obligations require broader coverage
- There is a persistent gap between expectations and delivery
A provider can be capable and still not be the right fit for the next stage of the business. Fit matters.
A note on contracts
The starting point is usually reading the existing agreement carefully
Most contractual concerns dissolve once the document itself has been read end-to-end. The patterns below appear in the majority of Australian managed services agreements we see.
Notice and handover clauses
Most Australian managed services agreements contain a defined notice period and a documented handover process. The first practical step in any review is reading the existing agreement to understand notice obligations, handover clauses and any remaining payment terms.
Where multi-year obligations sit
Where genuine multi-year obligations exist, they are typically tied to hardware finance, licensing commitments or telecommunications contracts rather than the managed services agreement itself. Those obligations generally remain with the business regardless of who manages them, and can usually be transitioned smoothly.
When to take legal advice
Where any aspect of the agreement is unclear, a short review with a commercial lawyer before formal notice is given is a sensible step. This page is operational guidance based on patterns seen across the Australian MSP market and is not legal advice.
Practical questions from leadership teams considering a review
Answers reflect patterns from environment reviews completed across Queensland, NSW and Victoria. Click any question to expand.
Start with understanding
A documented environment review is a low-risk first step
Before discussing platforms, projects or provider changes, most businesses benefit from understanding how their environment is structured today, where operational dependencies sit, how identity is governed, and how recoverability is validated.
That understanding alone usually improves operational decision-making, regardless of which provider holds the relationship at the end of it. The review is documented, retained by the business, and useful even if nothing else changes.
Calls and reviews are advisory. There is no obligation to proceed, no high-pressure follow-up, and the documentation is yours to keep regardless of the outcome.

Remote Support