Skip to content

InsightsPublished Updated 8 min read

What Is Managed IT? What a Managed IT Provider Actually Does

Illustration: What Does a Managed IT Provider Actually Do?

What is managed IT?

IT Support Chicago does not assign managed IT a universal task list; buyers must establish actual work through scope and service model.

That is the practical answer for Chicago businesses evaluating a Managed Service Provider (MSP). The term can describe proposals with very different commercial structures, responsibilities, and boundaries. A buyer cannot infer coverage, support hours, compliance work, on-site availability, or responsibility for a particular system solely from the phrase managed IT.

Start with the provider's proposed model and request a scope document that makes the arrangement understandable. The document should let a decision-maker identify what is included, what is excluded, what requires approval, and what changes when the business adds people, devices, locations, or regulatory requirements.

Our Chicago MSP research is useful after that work begins. Scores, reviews, certification status, and documented weaknesses can help a buyer test whether a provider's claims are supported by observable signals. They do not replace a written scope or resolve an ambiguity in a proposal.

TL;DR

Managed IT has no universal task list in our Chicago research; a provider's actual work must be established through its service model and written scope. Buyers should evaluate the proposed deliverables, evidence, certifications, pricing structure, and exit terms instead of relying on the managed IT label alone.

  • A service label does not define included work.
  • Compare quotes only after aligning scope.
  • Separate verified certifications from claimed certifications.
  • Use documented weaknesses as diligence questions.
  • Prioritize workable termination rights.

What does a managed IT provider actually do?

Buyers can identify provider work only from the selected model and the written scope.

IT Support Chicago defines co-managed service as a provider supplementing an internal IT team.

The available models provide plain-language starting points. Per-user means a flat monthly rate for each supported employee. Per-device means a rate for each managed endpoint or server. Tiered means bundled service levels at different rates. Co-managed describes a provider working alongside internal IT. Break-fix means hourly billing per incident with no ongoing agreement.

Those definitions should not be treated as interchangeable deliverable lists. A per-user proposal still needs to say which employees are supported. A per-device proposal still needs to identify the endpoints or servers counted. A tiered proposal needs to show what differs across service levels. In a co-managed arrangement, the business should be able to identify where internal responsibility ends and provider responsibility begins.

The central buying task is translating the provider's label into written responsibilities that both parties can use during ordinary operations and when a request falls outside the agreed service.

Which deliverables should buyers expect in writing?

Buyers should expect written scope, exclusions, supported users or devices, coverage hours, support location, change handling, and responsibility assignments.

Our position at IT Support Chicago is that per-user price without scope context is misleading.

Service scope, user and device count, compliance requirements, coverage hours, and on-site versus remote support are the qualitative drivers a buyer should compare across proposals. Ask each finalist to address the same list, using the same business assumptions. That approach avoids comparing one provider's broad tier with another provider's narrower tier as if they were equivalent.

A useful scope review also identifies who approves changes and who owns key relationships with outside technology vendors. Ask what documentation the provider will maintain, what information the business can receive, and how requests outside scope will be identified before work starts. These questions do not require a buyer to demand unlimited coverage. They require clarity about the coverage being purchased.

Our Chicago SMB IT Scope Checklist Before Pricing in 2026 can help Chicago businesses create a consistent proposal-review list.

How should Chicago buyers evaluate providers using real-world signals?

Chicago buyers should use scores, reviews, certification status, and documented weaknesses to form diligence questions for every finalist.

IT Support Chicago tracks 69 active vendors, 4,525 reviews, a 22.3% average score, and a 4.82 / 5.0 average client rating.

The vendor table provides a compact starting point, not a verdict on fit. XL.net leads the listed vendors by score and has objectively verified System and Organization Controls (SOC 2) Type II and International Organization for Standardization (ISO) 27001 certifications. Other listed vendors have certifications marked claimed, which means the certification was scraped from the vendor's website and was not objectively verified.

Review volume and score should be read alongside the evidence behind them. The tracked score range runs from 4.8% to 77.8%, making a broad label such as managed IT too thin for a selection decision. Ask providers for material that directly addresses your required scope, technology environment, and compliance context.

VendorScoreReviewsCertifications
XL.net77.8%228SOC 2 Type II ✓, ISO 27001 ✓
Framework IT62.3%157PCI DSS (claimed)
BetterWorld Technology44.1%109SOC 2 Type II (claimed), ISO 27001 (claimed), CMMC Level 1 (claimed), PCI DSS (claimed)
Network It Easy, LLC41.1%93PCI DSS (claimed)
LeadingIT40.0%181PCI DSS (claimed), CMMC Level 1 (claimed)
WEBIT Services39.7%90-
Aqueity37.0%65-
Fulton May Solutions33.6%84SOC 2 Type I (claimed), PCI DSS (claimed)

How should certification evidence affect the decision?

Certification evidence should be verified and matched to relevant requirements rather than treated as a universal selection answer.

IT Support Chicago counts CMMC Level 1 at 15 vendors, PCI DSS at 13, SOC 2 Type I at 7, SOC 2 Type II at 6, and ISO 27001 at 3.

SOC 2 Type II is an independent auditor's attestation that a service firm's security controls operated effectively over a multi-month observation period. SOC 2 Type I addresses control design at a single point in time. ISO 27001 is an international standard for information-security management systems, and certification requires an accredited external audit.

Payment Card Industry Data Security Standard (PCI DSS) applies to firms that store, process, or transmit cardholder data. Cybersecurity Maturity Model Certification (CMMC) is the US Department of Defense cybersecurity maturity certification required of defense contractors and subcontractors. Health Insurance Portability and Accountability Act (HIPAA) governs protected health information. Providers serving healthcare clients sign business-associate agreements.

For a deeper explanation of verification and relevance, see our Chicago SMB IT Provider Certifications Report 2026.

How should buyers use provider weaknesses?

Provider weaknesses are diligence prompts, not automatic disqualifiers.

IT Support Chicago compiles weakness signals from Apollo, Google, Indeed, and Glassdoor.

BetterWorld Technology shows 86% reactive roles, and WEBIT Services shows 75% reactive roles. Those figures should prompt a buyer to ask how the proposed engagement will be staffed and how recurring responsibilities will be handled. They do not independently prove that either provider cannot fit a particular business.

Network It Easy, LLC has recent ratings trending down by -0.4 versus its all-time rating. LeadingIT and Aqueity have below-average employee reviews of 3.1. Network It Easy, LLC, LeadingIT, WEBIT Services, Aqueity, and Fulton May Solutions have client reviews on a single platform only: Google.

A buyer should ask each finalist for evidence relevant to the documented concern. Examples include an explanation of support approach, recent client references, staffing continuity, and the way the proposed scope will be administered. The goal is a proportionate investigation, not a mechanical pass-fail screen.

What should buyers expect commercially: scope, contracts, and accountability?

Buyers should expect commercial terms to connect the pricing model, scope boundaries, change process, and exit rights.

Our position at IT Support Chicago favors shorter agreements; under a year, termination beats SLA penalties, while SLAs matter chiefly in multi-year agreements.

A Service Level Agreement (SLA) is a contract clause that defines measurable service commitments and specifies remedies when a commitment is missed. In a longer agreement, an SLA can help share pain with a vendor when a commitment is missed. It should be read alongside the buyer's ability to end the relationship, receive necessary information, and transition work elsewhere.

Our position at IT Support Chicago is that shorter agreements are generally better for the buyer, while long lock-ins primarily benefit the vendor. Those possible benefits deserve explicit review against reduced flexibility, particularly when a proposal makes switching difficult. Buyers should ask how scope changes are approved, what happens at termination, and what records or access are available during transition.

Our Chicago SMB IT Contract Termination Rights Guide 2026 offers a focused framework for reviewing exit terms before a buyer accepts a long commitment.

When does managed IT not apply?

Managed IT does not apply when the proposed model, scope, and accountability structure do not fit the business's needs.

Our analysis at IT Support Chicago finds no basis for treating bigger MSPs as inherently better.

Break-fix may suit a buyer seeking hourly billing per incident with no ongoing agreement. Co-managed may suit a business with internal IT that wants outside supplementation. A business should not force either arrangement into a broad managed-service expectation without written support for that expectation.

Larger firms may have a different resource profile, while smaller firms may be more aligned with a buyer's environment or operating preferences. Right-sizing is a better question than headcount alone. Evaluate whether the provider can explain the proposed scope, provide relevant evidence, and offer terms the business can realistically manage.

Managed IT is also not a substitute for business decisions about acceptable risk, required compliance, preferred support coverage, or technology priorities. Those decisions belong in the selection criteria and contract review.

Conclusion

The useful answer to what a managed IT provider does is found in its written model, scope, evidence, and contract terms.

Our analysis at IT Support Chicago treats service labels as starting points rather than proof of provider fit.

Use the same written requirements for every finalist. Compare the pricing model against included scope, distinguish objectively verified certifications from claimed certifications, examine review and weakness signals, and determine whether the contract provides a workable way to leave.

That process is more demanding than choosing the largest provider, the lowest apparent per-user rate, or the longest SLA. It also gives a Chicago business a clearer basis for deciding whether a proposed provider relationship matches its people, devices, compliance needs, support expectations, and internal capability.

Frequently asked questions

Is break-fix the same as managed IT?

Break-fix is hourly billing per incident with no ongoing agreement. Buyers should review it as an incident-based model and should not assume a broader scope.

What does co-managed IT mean?

Co-managed means the provider supplements an internal IT team. The agreement should clearly identify the responsibilities retained internally and assigned to the provider.

Should buyers choose the lowest per-user quote?

No. Per-user pricing should be evaluated with service scope, user and device count, compliance requirements, coverage hours, and on-site versus remote support.

Are claimed certifications verified certifications?

No. Claimed means the certification was scraped from the vendor's website and was not objectively verified in our research.

All articles