CIO Support › Managed IT

🛠️ Managed IT

Running IT well: outsourced IT departments, Microsoft 365 security, and choosing a provider.

What is an outsourced IT help desk and how does it work?

An outsourced IT help desk is a contracted provider that handles your employees' IT requests, such as login problems, device issues, software access and outages, by phone, email, chat or portal. It works best as part of a provider that also manages your devices, accounts and systems, so the people answering tickets can actually fix the underlying problem rather than log and forward it.

What should I look for in a managed service provider contract?

A good managed service provider contract clearly defines scope and exclusions, service levels by priority, security responsibilities on both sides, incident notification and handling, who holds administrator access, your ownership of data and documentation, pricing and change rules, and exit terms including handover. If any of these are vague, clarify them in writing before you sign.

Does Microsoft back up my Microsoft 365 data?

Not in the way most companies assume. Microsoft keeps its service resilient and retains deleted items for limited periods, but under the shared responsibility model your data remains your responsibility, and Microsoft's Services Agreement recommends you regularly back up your content. For protection against ransomware, mass deletion or long-delayed discovery, you need a backup: Microsoft 365 Backup or a third-party product.

How do I know if we should replace our IT provider?

You should consider replacing your IT provider when the same problems keep recurring after you have raised them clearly: missed service levels, repeat outages, weak security practices, untested backups, no documentation, or no help with the decisions your business faces. Before switching, secure your admin credentials, domains, licenses and documentation, and plan an overlap so monitoring and backups never lapse.

What should an IT onboarding and offboarding checklist include?

An IT onboarding checklist should cover account creation, multifactor authentication, role-based access, a configured and managed device, and security training. An offboarding checklist should block sign-in and revoke sessions promptly, recover or wipe devices, preserve and hand over email and files, remove licenses and third-party access, and document each step. Both should be triggered by HR, not by memory.

How do you migrate from one Microsoft 365 tenant to another?

A Microsoft 365 tenant-to-tenant migration moves users, mailboxes, OneDrive and SharePoint content, Teams and domains from one tenant to another, typically after an acquisition, divestiture or rebrand. It is done with Microsoft's cross-tenant migration features or third-party tools, and succeeds or fails on planning: identity mapping, licensing, domain cutover, permissions and user communication.

What is co-managed IT and when does it make sense?

Co-managed IT is an arrangement where a managed IT provider works alongside your internal IT person or team instead of replacing them. Your staff usually keep business applications and user relationships, while the provider adds monitoring, security tooling, patching, after-hours coverage and project capacity. It makes sense when you value your internal staff but lack depth or coverage, and only works with a written split of responsibilities.

What is an outsourced IT department and is it right for my company?

An outsourced IT department is an arrangement where a managed IT provider runs most or all of your IT function under contract: help desk, devices, networks, cloud services, security operations and projects. It suits small and mid-size companies that cannot staff every IT skill internally. Your company still owns risk decisions, so the contract, oversight and data access need to be clearly defined.

What should a Microsoft 365 security baseline include?

A Microsoft 365 security baseline is the documented minimum set of security settings every tenant should meet. At its core: multifactor authentication for all users, stronger protection for administrators, legacy authentication blocked, and email, sharing and device settings hardened. Use Microsoft security defaults or Conditional Access to enforce it, Microsoft Secure Score to track it, and CISA's SCuBA baselines as a detailed reference.

How do I choose a managed IT provider in the San Francisco Bay Area?

Choose a Bay Area managed IT provider by testing five things: its own security practices, on-site coverage for your locations, experience in your industry and compliance requirements, a contract with clear scope and service levels, and how it controls administrative access to your systems. Ask for references from similar-sized companies and confirm who will actually support you day to day.

LAN Service Group provides managed IT services, fully outsourced or co-managed.

CIO Support is an executive technology library published by LAN Service Group, Inc. — an IT management, cybersecurity, compliance and AI services firm in San Ramon, California, serving businesses since 1992.

Talk to LAN Service Group