When a business hires a managed service provider, the first question is rarely about tools. It is: what happens next? The first 90 days are not a magic transformation. They are the period where a good MSP builds inventory, closes obvious gaps, proves it can restore what it backs up, and earns the right to run your environment day to day.
Here is what that stretch should look like at Marmic Associates — and what you should expect from any MSP worth hiring.
Days 1–30: see everything, stop the bleeding
The first month is discovery and stabilization. If your provider skips this and jumps straight to “we’ll monitor it,” you will both be guessing.
Access and inventory. We get controlled access to Microsoft 365, servers, firewalls, backups, and endpoints — then we document what is actually there. Asset lists from the last vendor are often stale. We verify users, devices, critical apps, and who owns what.
Monitoring and the help desk path. Agents go on the fleet that needs them. You get a clear way to open tickets and reach a senior technician — not a script reader. For managed clients, monitoring should start catching issues before you notice them.
Backups and “are we safe tonight?” We confirm backups exist for the systems that matter, that jobs are succeeding, and that retention matches the business risk. A green checkmark in a backup console is not the same as a restore that works.
Quick wins. Patch holes that are easy and urgent, turn off unused admin accounts, fix DNS or firewall rules that are obviously wrong, and clean up the loudest recurring tickets. The goal is fewer fires in week four than in week one.
By day 30 you should have: a living inventory, monitoring in place, a ticket path you trust, and a short list of risks ranked by urgency — not a binder of vague recommendations.
Days 31–60: harden and prove recovery
Month two is where proactive IT starts to look different from break/fix.
Identity and access. Multifactor authentication where it belongs, least-privilege admin, and cleanup of shared or orphaned accounts. Most modern incidents start with identity, not a fancy exploit.
Patch and baseline. Servers and workstations get on a defined patch cadence. Exceptions are documented on purpose, not because nobody looked.
Security basics that match the business. Endpoint protection, email filtering, DNS filtering, and firewall hygiene — sized for a New Jersey SMB, not a Fortune 50 checklist copied from a slide deck. If AI tools are already in your Microsoft 365 tenant, this is also when we talk about AI Enablement: what Copilot or assistants can already reach, and how to keep that useful without leaking data.
The restore test. We do not only confirm backups ran. We restore something that matters (or a stand-in that proves the path) and write down how long it took and what broke. If your MSP cannot show a restore test, you do not have a recovery plan — you have a hope plan.
Documentation. Network diagrams, admin contacts, vendor logins under a vault, and “how we rebuild X” notes. The point is that support does not depend on one person’s memory.
By day 60 you should see fewer surprises, clearer ownership of risks, and evidence that recovery is more than a checkbox.
Days 61–90: optimize and set the rhythm
Month three turns the onboarding project into an operating rhythm.
Tune the noise. Alert thresholds, ticket categories, and patch windows get adjusted so the team is not drowning in false alarms — and so real ones are not ignored.
Roadmap, not a one-time “project complete.” We prioritize the next 6–12 months: aging servers, Microsoft 365 cleanup, cybersecurity gaps, cloud moves, or backup architecture. You should leave with a short written plan you can say yes or no to — not a 40-page deck.
Business review. What we fixed, what is still open, what it costs to ignore, and how managed IT will run month to month. Marmic has always worked on a no-contract basis: if we are not delivering, you should not be locked in. The 90-day mark is a natural checkpoint for that conversation.
What “done” means. Onboarding ends. Managed IT does not. The first 90 days get you visibility and a stable baseline. After that, the job is keeping that baseline honest as people, software, and threats change.
What you should expect — and red flags
A serious MSP will tell you what it will not finish in 90 days. Full cloud migrations, major app rewrites, or ripping out every legacy system rarely fit cleanly into onboarding. Anyone who promises “fully transformed in 90 days” is selling a timeline, not a plan.
Red flags: no inventory, no restore test, junior-only help desk, endless “phase 2” with no dates, and security tools installed with no one watching the alerts.
Green flags: senior people on the phone, written priorities, monitoring that catches issues early, and a clear path from onboarding into steady managed service.
Ready for a clearer first 90 days?
If you are switching providers — or you never got a real onboarding the first time — we will walk through what the first 90 days would look like in your environment.
Get in touch for a free IT assessment, or call (855) 4-MARMIC.