Ask a restoration owner who handles their technology and the answer comes fast. The MSP.
Follow up by asking who removed last month's departing estimator from Xactimate, the job management platform, the phone system and the TPA portals, and the answer slows down.
Plenty of MSPs do excellent work. A restoration company also runs on Microsoft or Google, a phone provider, estimating and documentation platforms, an accounting system and a pile of carrier and vendor portals. Each provider handles its own piece. The gaps between them cost real money: accounts left open, seats nobody uses, after-hours calls that ring to nowhere and job files that vanish when someone leaves.
I spent 35 years in IT and cybersecurity before I started building systems for restoration contractors. The first document I ask an owner for is the MSP agreement, and my first question is when anyone last read the scope section.
What the MSP agreement usually covers
An MSP typically handles the infrastructure it's contracted for. Help desk, laptops and workstations, patching, network equipment and endpoint security are common. Microsoft 365 administration and backup are sometimes included and sometimes sold as add-ons.
Two providers can quote a similar per-user price and cover different things. Neither one is doing anything wrong. The risk is your team assuming the bigger scope when the contract says the smaller one.
The systems sitting around the MSP
Depending on the company, the list can include Microsoft 365 or Google Workspace, a VoIP phone system, Xactimate and XactAnalysis, a field documentation app like Encircle, a job management platform like DASH or PSA, QuickBooks or another accounting system, a CRM, cloud storage, field phones and tablets, and carrier and TPA portals. Few companies run all of them. Most run several.
Microsoft's shared responsibility model is explicit about where its job ends. For every type of cloud deployment, the customer owns its data and identities. Microsoft keeps the platform running. Accounts, permissions and data protection are yours to manage, directly or through whoever you hire, and the agreement decides which parts the MSP took on.
Microsoft 365, Google Workspace and MFA
Somebody configured your tenant. It might have been the MSP or a former office manager. Mail forwarding rules and admin accounts tend to stay exactly the way that person left them.
MFA gets set up product by product. CISA recommends requiring it wherever possible and starting with privileged, administrative and remote access users. Email may be covered while the accounting system and the field documentation app are still running on passwords alone.
Admin accounts and privileged access
Admin accounts can change almost anything, which is why Microsoft recommends giving the Global Administrator role to fewer than five people. Ask for the current list and check every name on it. If a departed employee or a vendor's old login still holds that role, fix that before anything else on this page.
Your job management and accounting platforms have their own admin roles too, set in their own portals. The MSP may never see them.
Phones and after-hours routing
Phones usually come from a separate provider with a separate admin portal. That portal controls branch ring groups and after-hours emergency routing.
For a restoration company, the overnight call is often the job. If routing at one branch breaks at 1 a.m., somebody has to know whether that's an MSP ticket or a phone-provider ticket before the homeowner dials the next company on the list.
Backups nobody has tested
A backup that's never been restored is an assumption. CISA's Cyber Essentials puts backup on its short list of first steps for small organizations. Ask your MSP for the date of the last test restore and what was restored.
Then check coverage. Email and OneDrive or SharePoint are the usual starting point. The accounting file comes next. Job photos and signed work authorizations saved to someone's desktop are easy to miss. Your restoration software vendors hold their own data, and export and retention terms are a separate conversation with each of them.
Software you may be paying for twice
Unused seats bill every month. So do two branches paying for two platforms that do the same job. Your MSP manages laptops and usually isn't asked to compare software usage, and the vendor's account rep has no reason to raise it at renewal. The controller is usually the first to notice, one line at a time on the card statement. If that sounds familiar, take a full count of what the company is paying for.
Run the offboarding test on your last departure
Take a project manager at your second location whose last day was the 14th. HR processes the paperwork and opens a ticket. The MSP disables the Microsoft 365 account and closes the ticket.
Now list what that PM could log into. An Xactimate license. The job management platform. The documentation app on a company iPhone, and maybe on a personal one. QuickBooks, if they approved vendor bills. A phone extension forwarding to their cell. Shared job folders. TPA portals where they're still the named contact. An account at the equipment rental house.
The MSP handled one line of that list.
Deleting too fast creates a different problem. A deleted Microsoft 365 user stays recoverable for 30 days, and after that Microsoft says neither you nor its support team can restore the account. The user's OneDrive is kept for 30 days by default unless an admin changes the setting. If that PM saved photos or supplement notes to OneDrive, a supplement still in dispute may have lost its support. That's a decision about job files as much as accounts, and it needs someone who understands both.
When an outage crosses vendor lines
Calls at your second branch start dropping on a Monday morning during a storm week. The MSP checks the network, says it's healthy and points to the phone provider. The phone provider says its service is up and points to the internet circuit. The job management vendor confirms its platform is running, which is true and doesn't help. Each answer is correct about one piece.
And the calls are still dropping. During a storm week, a missed call is often a job that goes to whoever answered.
Restoration work moves through a long chain of first call, field documentation, estimate, submission, invoice and collections. Every handoff between systems is a handoff between vendors too, and somebody has to represent ownership when the vendors disagree about whose problem it is.
Independent oversight and who should own it
Managing each system and governing the whole environment are two separate jobs.
NIST's Cybersecurity Framework 2.0, published in February 2024, added a Govern function. One of its outcomes, GV.SC-02, calls for security roles and responsibilities with suppliers and partners to be spelled out and coordinated with each of them. NIST's own implementation examples suggest documenting those roles in a responsibility matrix.
That's governance work, and it sits with ownership. Someone has to read every contract against what the business assumes and put a name next to each gap. In some companies that's a strong controller or an internal IT lead. Others use an outside advisor who doesn't sell the services being reviewed, so the reviewer and the provider are different people. When that becomes a standing need, it's a technology leadership question.
A responsibility matrix for restoration owners
Write a person's name in the last column. Any row you can't fill is a gap.
| Responsibility | Often assumed | Question to answer | Named owner |
|---|---|---|---|
| Microsoft 365 or Google Workspace setup and MFA | The MSP | Which systems outside email have MFA enforced today? | |
| Admin and privileged accounts | The MSP | Who holds admin rights in each system, and does each one still need it? | |
| Offboarding across every system | HR or the MSP | Who holds the full checklist, including vendor and carrier portals? | |
| Phones and after-hours routing | The phone provider | Who changes routing, and who gets the call when it fails? | |
| Backups and test restores | The MSP | What was last restored on purpose, and when? | |
| Software seats and overlap | Each software vendor | Who compares seats and usage across branches before renewal? | |
| Outages that cross vendors | Whoever picks up the phone | Who represents ownership until it's fixed? |
Four things to do before your next renewal
- List every system, app and portal the company pays for or logs into, by branch.
- Read the scope section of your MSP agreement and mark what's excluded.
- Run the offboarding test against the last person who left.
- Ask your MSP for the current admin list and the date of the last test restore.
Questions owners ask about MSP scope
Does our MSP manage Xactimate, Encircle or DASH?
Usually the MSP supports the devices and network those platforms run on. User setup and permissions inside them tend to sit with your team and the software vendor unless your agreement says otherwise.
Is Microsoft backing up our Microsoft 365 data?
Microsoft runs the platform and offers retention and recovery features with time limits. Its shared responsibility model puts data and identities with the customer, so decide with your IT provider whether those features are enough or a separate backup makes sense.
Who should own offboarding at a restoration company?
One named person holding a system-by-system checklist. HR starts the process and the MSP handles its systems. The checklist owner closes everything else, including phones, devices, software platforms and vendor portals.
Should we replace our MSP?
Fix scope and ownership first. If the review shows the MSP isn't delivering what the contract covers, that's a separate conversation to have with them.
Sources (accessed October 5, 2026)
- Microsoft Learn: Shared responsibility in the cloud
- Microsoft Learn: Best practices for Microsoft Entra roles
- Microsoft Learn: Restore or remove a recently deleted user (Microsoft Entra)
- Microsoft Learn: Restore a deleted OneDrive
- CISA: Require Multifactor Authentication
- CISA: Cyber Essentials
- NIST: CSF 2.0 Implementation Examples (February 2024)
