Maintenance and security / Recurring work
The work between support requests is where managed IT earns its name.
Maintenance is not one universal checklist. It is an agreed rhythm of observation, follow-through, and decisions across the systems your employees actually use.
Lire cette page en françaisProof by process
Ask for a cadence you can inspect.
A provider should be able to describe what happens continuously, what is reviewed on a recurring schedule, what evidence is kept, and which findings need your approval. Exact tools, frequency, coverage, and response commitments depend on the agreed environment and plan; this page does not invent them.
A practical rhythm
| Rhythm | Typical attention | Useful output |
|---|---|---|
| As work arrives | Employee symptoms, access changes, device friction, supported service incidents | Resolution notes, escalation context, or a named decision |
| Recurring operations | Update posture, identity hygiene, operational exceptions, licences, open vendor threads | Exceptions with owners and next actions |
| Periodic review | Patterns, aging items, lifecycle changes, business priorities, upcoming renewals | A short decision agenda rather than a decorative score |
| When conditions change | New locations, applications, roles, risks, or projects | A scope decision and approved path forward |
Security basics
Security work must be named to be owned.
Managed IT can include practical security hygiene around identities, supported endpoints, updates, access changes, and Microsoft 365 settings. It should also distinguish routine stewardship from a specialized assessment, incident response engagement, compliance program, or 24×7 security operation.
- Define which identities and devices are covered
- Name who approves higher-impact access or policy changes
- Record exceptions and the person accepting or resolving them
- Separate urgent incident handling from ordinary support
- Agree when specialist work needs a separate scope
Sample review agenda
Turn maintenance into business-readable decisions.
A useful review can cover recurring employee friction, unresolved exceptions, joiner/leaver quality, device lifecycle decisions, Microsoft 365 changes, vendor dependencies, upcoming renewals, and projects awaiting approval. It should end with owners and next actions—not a collection of unexplained technical counts.
See how decisions move through the serviceNext step
Turn your IT context into a clear scope.
An introduction covers your team, Microsoft 365, devices, vendors, and responsibilities to transfer. You leave with the scope questions that need answers—without sharing secrets.
Prepare an introduction