What Managed IT Services Should Include for an Architecture Firm
Managed IT services for a 25–50 person architecture firm should include more than a help desk. A complete agreement should cover employee support, Revit workstations, Microsoft 365, Autodesk access, cybersecurity, networks, servers, cloud systems, backup and disaster recovery, vendor coordination, technology budgeting, and strategic planning.
For most architecture firms, comprehensive managed IT pricing may fall between $100 and $275 per user per month. The actual cost depends on support hours, cybersecurity requirements, office locations, infrastructure complexity, cloud services, and which projects are included.
A useful managed IT agreement should provide eight essential outcomes:
- Employees receive timely technical support.
- Revit workstations remain reliable and appropriately specified.
- Microsoft 365, Autodesk, and cloud accounts are secured.
- Servers, networks, and cloud systems are monitored and maintained.
- Project and business data can be restored.
- Cybersecurity controls are implemented and documented.
- Leadership receives a technology roadmap and budget.
- Every major IT responsibility has a clearly identified owner.
The Eight-Part Managed IT Framework for Architecture Firms
1. Responsive Employee Support
The provider should offer a structured help desk for office, remote, and hybrid employees. Support should be available through defined channels such as telephone, email, and a service portal.
Employee support should include:
- Password and account assistance
- Microsoft 365 troubleshooting
- Workstation performance problems
- Software installation
- Printer and plotter connectivity
- Remote-access support
- Conference-room technology
- Autodesk application installation
- Basic Revit troubleshooting
- New employee onboarding
- Employee offboarding
- Mobile-device support when included
The agreement should define response targets by business impact. A firm-wide outage or active cyberattack should receive a faster response than a planned software request.
| Priority | Architecture Firm Example | Illustrative Response Target |
|---|---|---|
| Critical | Ransomware, firm-wide outage, failed server, or complete loss of active project access | 15–30 minutes |
| High | Multiple employees affected or an immediate project deadline at risk | 30–60 minutes |
| Normal | One employee has a workstation, application, or account issue | 1–4 business hours |
| Planned | New equipment, permissions, software, or nonurgent changes | Same or next business day |
2. Revit Workstation and Application Management
Architecture firms require support that understands the relationship between Revit, workstation hardware, graphics drivers, storage, networking, cloud collaboration, add-ins, and project complexity.
The provider should help manage:
- Workstation specifications by employee role
- CPU, memory, GPU, and storage performance
- Revit and Autodesk application deployment
- Approved software versions
- Graphics and peripheral drivers
- Revit add-ins
- Application patching
- Licensing
- Local disk capacity
- Warranty and lifecycle status
- Standardized workstation configurations
A junior designer, project architect, BIM manager, visualization specialist, and administrative employee may require different hardware. The provider should avoid purchasing the same computer for every role without reviewing actual workloads.
Revit support responsibilities should also be divided correctly:
| Issue Type | Primary Owner |
|---|---|
| Workstation crashes or application installation | Managed IT provider |
| Network, storage, or cloud connectivity | Managed IT provider |
| Model standards, templates, and families | BIM manager |
| Model corruption or unusual project behavior | BIM manager and managed IT provider |
| Autodesk account security and licensing | Managed IT provider with Autodesk administrator |
| Revit cloud worksharing permissions | Project administrator with IT support |
The best provider supports the infrastructure around Revit without attempting to replace the firm's BIM leadership.
3. Microsoft 365, Autodesk, and Identity Management
Identity is one of the most important parts of an architecture firm's technology environment. A compromised Microsoft 365 or Autodesk account may expose project files, email, contacts, financial communication, and client information.
Managed identity services should include:
- Employee account creation and removal
- Multi-factor authentication
- Conditional access when appropriate
- Administrator-role management
- License assignment
- Password policies
- Sign-in monitoring
- Guest-user reviews
- Shared mailbox administration
- Distribution group administration
- Autodesk account coordination
- Inactive-account removal
The provider should document who can authorize access changes. Employees should not receive project, financial, administrative, or cloud permissions based only on an informal request.
4. Cybersecurity Management
Cybersecurity should be included as an operational service rather than sold as an optional collection of disconnected tools.
A complete baseline should address:
- Multi-factor authentication
- Endpoint detection and response
- Email security
- Disk encryption
- Operating-system patching
- Application patching
- Firewall management
- Secure remote access
- Administrator privilege restrictions
- Security awareness training
- Phishing simulations
- Vulnerability remediation
- Security alert monitoring
- Incident response
- Cyber insurance documentation
911 IT provides cybersecurity services designed to protect identities, endpoints, email, networks, cloud systems, and business operations.
The agreement should state who monitors alerts, when alerts are reviewed, what happens after hours, and which incident-response activities are included.
5. Network, Server, and Cloud Infrastructure Management
The provider should monitor and maintain the systems that employees depend on to reach project files, cloud applications, consultants, and clients.
Infrastructure management may include:
- Firewalls
- Network switches
- Wireless access points
- Internet connections
- Servers
- Virtual machines
- Local storage
- Cloud infrastructure
- Azure services
- Remote-access systems
- Domain and DNS services
- Phone systems when included
- Network configuration backups
The provider should maintain current diagrams, configurations, warranties, administrative access, and vendor information.
Monitoring should identify issues such as:
- Failed hardware
- Low disk space
- High server utilization
- Internet instability
- Firewall failures
- Backup failures
- Unsupported operating systems
- Expiring certificates
- Unusual network activity
6. Backup, Disaster Recovery, and Business Continuity
Managed IT should protect both local and cloud information. A provider should not assume that Microsoft 365, Autodesk, or another cloud platform eliminates the need for recovery planning.
The backup scope should identify whether it includes:
- Active Revit and project files
- Local file servers
- Microsoft 365 mailboxes
- OneDrive
- SharePoint
- Teams-related files
- Cloud servers
- Accounting systems
- Project-management platforms
- Network configurations
- Archived projects
For every protected system, the agreement should document:
- Backup frequency
- Retention period
- Encryption
- Storage location
- Monitoring responsibilities
- Restoration procedures
- Recovery time expectations
- Recovery point expectations
- Testing frequency
Backup alerts are not enough. The provider should regularly restore representative files, Microsoft 365 data, servers, and project information to verify that recovery works.
911 IT helps firms prepare for outages, ransomware, hardware failure, and cloud disruption through business continuity services.
7. Vendor and Technology Coordination
Architecture firms commonly work with several technology vendors, including:
- Autodesk
- Microsoft
- Internet providers
- Phone providers
- Plotter and printer vendors
- Accounting software companies
- Project-management platforms
- Cloud providers
- Security vendors
- Building management
The managed IT provider should act as a technical coordinator when issues involve multiple vendors. Employees should not be required to determine whether a problem belongs to Autodesk, Microsoft, the internet carrier, the workstation manufacturer, or the network.
The provider should:
- Open and manage vendor support cases
- Maintain account and contract information
- Track renewals
- Review technical proposals
- Coordinate installations
- Escalate unresolved problems
- Document outcomes
Vendor management does not mean the provider makes every business decision. Leadership should retain approval authority for contracts, costs, and major changes.
8. vCIO Strategy, Budgeting, and Roadmaps
A managed IT provider should help leadership plan rather than wait for systems to fail.
Strategic services should include:
- Quarterly technology reviews
- Annual IT budgeting
- Hardware lifecycle planning
- Cybersecurity roadmaps
- Cloud strategy
- Office expansion planning
- Business continuity planning
- Vendor reviews
- Cyber insurance readiness
- Policy development
- Three-year technology roadmaps
A useful roadmap should identify:
- The business reason for each recommendation
- The systems or employees affected
- Estimated cost
- Target quarter
- Business risk of delaying the project
- Responsible owner
- Expected outcome
The roadmap should not be a generic list of products. It should connect technology decisions to employee productivity, project delivery, cybersecurity, growth, and financial planning.
What Should Be Included in the Monthly Managed IT Fee?
Every provider packages services differently. Architecture firms should compare proposals line by line.
| Service | Commonly Included | Questions to Ask |
|---|---|---|
| Remote help desk | Often | Are support hours, users, and issue types limited? |
| Onsite support | Sometimes | Are visits included, limited, or billed separately? |
| After-hours support | Sometimes | Which incidents qualify and are additional fees charged? |
| Endpoint monitoring | Often | Which devices are covered? |
| Patch management | Often | Does it include third-party applications? |
| Endpoint security | Often | Is it basic antivirus or monitored endpoint detection and response? |
| Email security | Sometimes | Does it include phishing, impersonation, and malicious-link protection? |
| Microsoft 365 management | Often | Are security policies, licensing, and projects included? |
| Backup monitoring | Often | Are licenses, storage, and restoration labor included? |
| Recovery testing | Sometimes | How frequently are actual restorations performed? |
| Network management | Often | Which firewalls, switches, wireless systems, and locations are covered? |
| Strategic planning | Sometimes | How often will leadership meet with a vCIO? |
| Projects | Varies | Which upgrades and migrations cost extra? |
Services That May Be Priced Separately
Some projects and expenses may reasonably fall outside the recurring monthly fee. The important requirement is transparency.
Separately priced items may include:
- New office installations
- Office moves
- Major cloud migrations
- Azure Virtual Desktop deployments
- Server replacements
- Large Microsoft 365 migrations
- Major cybersecurity remediation
- Structured cabling
- Hardware purchases
- Software licensing
- Compliance assessments
- Penetration testing
- After-hours project work
- Large acquisition integrations
The provider should identify likely project costs during annual budgeting rather than surprising leadership after equipment fails.
How Much Should Managed IT Cost for an Architecture Firm?
For a 25–50 person architecture firm, a comprehensive managed IT agreement may cost approximately $100–$275 per user per month.
| Service Level | Illustrative Range | Potential Scope |
|---|---|---|
| Basic managed support | $100–$150 per user per month | Help desk, monitoring, patching, and basic administration |
| Managed IT with cybersecurity | $150–$225 per user per month | Support, security tools, Microsoft 365, infrastructure, and backup monitoring |
| Comprehensive managed IT | $200–$275 per user per month | Broad support, advanced security, strategic planning, recovery, and architecture-specific expertise |
These figures are planning ranges rather than fixed market prices. Actual proposals vary according to:
- Number of employees
- Number of devices
- Office locations
- Support hours
- Onsite requirements
- Server and network complexity
- Cloud services
- Cybersecurity requirements
- Compliance obligations
- Included software and licensing
- Project scope
Example Budget for a 40-Person Architecture Firm
Consider a 40-person architecture firm paying $185 per user per month for comprehensive managed IT.
40 users × $185 × 12 months = $88,800 per year.
The annual fee might include:
- Remote employee support
- Scheduled onsite support
- Workstation monitoring
- Patch management
- Endpoint detection and response
- Email security
- Microsoft 365 administration
- Network and server management
- Backup monitoring
- Quarterly technology reviews
- Hardware lifecycle planning
- Vendor coordination
The firm may still budget separately for:
- Microsoft 365 licenses
- Autodesk licenses
- Workstation purchases
- Server or firewall replacements
- Cloud consumption
- Major migrations
- New office projects
A clear proposal should distinguish recurring service fees from software, hardware, cloud usage, and project expenses.
How to Compare Managed IT Proposals
Do not compare only the per-user price. Two providers may use the same pricing model while including very different services.
Compare each proposal across these categories:
- Support hours and response targets
- Remote and onsite coverage
- Revit and Autodesk experience
- Cybersecurity tools and monitoring
- Microsoft 365 administration
- Server, network, and cloud management
- Backup and recovery
- Strategic planning
- Project pricing
- Documentation and transition terms
| Comparison Area | Provider A | Provider B | Provider C |
|---|---|---|---|
| Monthly fee | Record total | Record total | Record total |
| Included users and devices | Document scope | Document scope | Document scope |
| Critical response target | Record commitment | Record commitment | Record commitment |
| Onsite support | Included or extra | Included or extra | Included or extra |
| Endpoint security | Document platform | Document platform | Document platform |
| Email security | Included or extra | Included or extra | Included or extra |
| Backup and recovery | Document systems | Document systems | Document systems |
| vCIO planning | Frequency and scope | Frequency and scope | Frequency and scope |
| Projects | Included or extra | Included or extra | Included or extra |
| Architecture experience | Verify examples | Verify examples | Verify examples |
Architecture-Specific Questions to Ask
- How do you troubleshoot slow Revit performance?
- How do you specify workstations for different architecture roles?
- Do you support Autodesk Construction Cloud?
- How do you manage Revit versions and add-ins?
- How do you separate BIM workflow support from IT support?
- Can you troubleshoot model access across offices?
- How do you support large files, point clouds, and rendering workloads?
- How do you prepare for major permit and submission deadlines?
- Can you support Azure Virtual Desktop for Revit?
- How do you protect consultant and guest access?
- How do you back up project and Microsoft 365 data?
- Can you provide references from architecture or engineering firms?
A provider does not need to serve architecture firms exclusively, but it should understand the technical and operational demands of design work.
911 IT offers specialized engineering IT support for firms that depend on high-performance workstations, BIM collaboration, cloud platforms, security, and reliable project delivery.
What Should Employee Onboarding Include?
A documented onboarding process should begin before the employee's first day.
Managed onboarding should include:
- Employee name, title, and start date
- Manager approval
- Microsoft 365 account
- Multi-factor authentication
- Autodesk licensing
- Project access
- Security groups
- Shared mailboxes
- Workstation preparation
- Revit and application installation
- Printer and plotter access
- Remote-work configuration
- Security training
- Equipment documentation
For reliable onboarding, the provider should receive the request at least 5–10 business days before the start date when new equipment must be purchased.
What Should Employee Offboarding Include?
Offboarding should protect client information, project access, email, equipment, and firm accounts.
The process should include:
- Confirming the final work time
- Disabling Microsoft 365 access
- Revoking active sessions
- Removing Autodesk access
- Removing remote access
- Changing shared credentials when necessary
- Transferring email and files
- Recovering company equipment
- Removing mobile-device access
- Reviewing administrator privileges
- Documenting completion
Urgent terminations should have a coordinated timeline involving leadership, human resources, the employee's manager, and IT.
What Reports Should Leadership Receive?
Leadership should receive concise reports that connect technology performance to business risk and priorities.
A quarterly report may include:
- Support volume
- Response and resolution performance
- Recurring problems
- Workstation lifecycle status
- Server and network health
- Patch compliance
- Endpoint security coverage
- Backup performance
- Recovery test results
- Microsoft 365 security findings
- Open risks
- Completed projects
- Upcoming projects
- Budget status
The report should clearly identify decisions leadership must make. A long technical report without priorities, costs, and recommended actions has limited value.
What Should a Quarterly Technology Review Cover?
A quarterly review should take approximately 60–90 minutes and focus on business decisions.
A useful agenda includes:
- Business changes and upcoming projects
- Support performance
- Cybersecurity status
- Backup and recovery status
- Hardware lifecycle
- Cloud and licensing costs
- Open technical risks
- Roadmap progress
- Next-quarter projects
- Budget approvals
Participants may include firm leadership, operations, finance, internal IT, the BIM manager, and the provider's strategic advisor.
How Managed IT Should Handle Cyber Insurance
The provider should help the firm verify and document technical controls requested by its insurer.
This may include evidence for:
- Multi-factor authentication
- Endpoint detection and response
- Encryption
- Patch management
- Email security
- Administrator access
- Backups
- Recovery testing
- Security awareness training
- Incident response
The provider should not complete the entire insurance application without leadership review. Firm leadership remains responsible for the accuracy of business representations.
How Managed IT Should Support Business Growth
A provider should help the architecture firm prepare for:
- Hiring
- New offices
- Remote employees
- Acquisitions
- Higher project volume
- Larger Revit models
- New visualization workloads
- Government or regulated projects
- Cloud migrations
- Additional security requirements
Growth planning should estimate:
- Workstation requirements
- Licensing
- Internet capacity
- Network capacity
- Cloud costs
- Support workload
- Security requirements
- Backup capacity
- Project timelines
Technology should be planned before a new office opens or a large group of employees begins work.
Common Managed IT Contract Red Flags
Cybersecurity Is Mostly Optional
Basic antivirus without monitored endpoint protection, email security, multi-factor authentication, and incident response may leave serious gaps.
Backup Responsibilities Are Vague
The agreement should identify every protected system, retention period, monitoring process, and restoration responsibility.
No Architecture or Revit Experience
The provider may understand general office technology but lack experience with high-performance workstations, large files, cloud worksharing, and BIM workflows.
Every Project Costs Extra
Some projects should be separate, but a managed agreement that excludes all upgrades, planning, and improvement work may become unpredictable and expensive.
Onsite Support Is Undefined
The firm should know when onsite service is available, how quickly someone can arrive, and what it costs.
No After-Hours Escalation
Architecture firms need a clear method for reporting ransomware, major outages, and deadline-threatening problems outside normal hours.
Leadership Receives No Roadmap
Without budgeting and lifecycle planning, the relationship may remain reactive.
The Provider Owns the Firm's Accounts
The architecture firm should retain ownership and administrative visibility for domains, Microsoft 365, Autodesk, cloud systems, licenses, and business data.
Documentation Is Not Available
The firm should have appropriate access to system, vendor, account, configuration, and recovery documentation.
Offboarding Terms Are Missing
The agreement should explain how accounts, documentation, credentials, licenses, and data are transferred if the relationship ends.
Example: Managed IT Scope for a 35-Person Architecture Firm
Consider a 35-person Salt Lake City architecture firm with 24 Revit users, Microsoft 365, Autodesk Construction Cloud, one local server, hybrid employees, and outside engineering consultants.
A comprehensive managed IT agreement could include:
| Category | Included Services |
|---|---|
| Employee support | Remote help desk, scheduled onsite support, onboarding, offboarding, and application troubleshooting |
| Workstations | Monitoring, patching, security, standardized deployment, warranty tracking, and replacement planning |
| Microsoft 365 | Account administration, multi-factor authentication, licensing, email security, and guest-access reviews |
| Autodesk | Account coordination, software deployment, licensing assistance, and infrastructure troubleshooting |
| Cybersecurity | Endpoint detection and response, email protection, encryption, training, and incident response |
| Infrastructure | Firewall, wireless, switch, server, remote-access, and internet monitoring |
| Backup | Server and Microsoft 365 backup monitoring with quarterly restoration tests |
| Strategy | Quarterly reviews, annual budgeting, hardware lifecycle planning, and a three-year roadmap |
The first 90 days might focus on:
- Documenting all systems and vendors
- Standardizing endpoint security
- Enforcing multi-factor authentication
- Reviewing backup coverage
- Identifying aging Revit workstations
- Testing project-file recovery
- Creating a prioritized technology roadmap
A 30-Day Managed IT Provider Evaluation
Week 1: Document Current Needs
- List employees, devices, offices, servers, and cloud systems.
- Document Revit, Autodesk, Microsoft 365, and project workflows.
- Identify current support and security problems.
- Define required support hours.
Week 2: Establish Required Services
- Set response-time expectations.
- Define cybersecurity controls.
- Identify backup and recovery requirements.
- Determine onsite and after-hours needs.
- List strategic planning expectations.
Week 3: Compare Providers
- Request proposals using the same requirements.
- Compare included tools and services.
- Review architecture and Revit experience.
- Contact client references.
- Review contract and offboarding terms.
Week 4: Select and Plan
- Score providers by coverage, expertise, service, security, and cost.
- Clarify all exclusions.
- Approve the selected agreement.
- Create a 30-, 60-, and 90-day transition plan.
- Schedule the first quarterly technology review.
Managed IT Provider Scorecard
| Category | Evaluation Question |
|---|---|
| Support | Are response targets appropriate for project deadlines and business impact? |
| Architecture expertise | Does the provider understand Revit, Autodesk, BIM, large files, and high-performance workstations? |
| Cybersecurity | Are identity, endpoints, email, networks, training, and incident response included? |
| Infrastructure | Can the provider manage local, cloud, network, and remote-work systems? |
| Backup | Are local and cloud systems protected, monitored, and tested? |
| Strategic planning | Will leadership receive a roadmap, budget, and lifecycle plan? |
| Onsite support | Is onsite coverage clearly defined? |
| After-hours support | Can the firm reach qualified support during emergencies? |
| Transparency | Are included services, exclusions, projects, licenses, and fees clearly documented? |
| Ownership | Does the firm retain control of its accounts, data, licenses, and documentation? |
Questions to Ask Before Signing a Managed IT Agreement
- Which services are included in the monthly fee?
- Which services cost extra?
- What are your response targets?
- Do automated replies count as responses?
- What onsite support is included?
- How does after-hours support work?
- Which cybersecurity tools are included?
- Who monitors security alerts?
- How do you support Revit and Autodesk?
- How do you specify architecture workstations?
- Which Microsoft 365 services do you manage?
- Which systems are backed up?
- How often do you test restoration?
- What vCIO services are included?
- Will you prepare an annual technology budget?
- How are major projects priced?
- How will you document our environment?
- Who owns our accounts and licenses?
- How will you transition us from our current provider?
- What happens when the agreement ends?
Frequently Asked Questions
What does a managed IT provider do?
A managed IT provider supports employees, maintains devices and infrastructure, administers cloud services, implements cybersecurity, manages backups, coordinates vendors, and helps leadership plan technology investments.
Should managed IT include cybersecurity?
Yes. At minimum, the agreement should address multi-factor authentication, endpoint protection, email security, patching, encryption, administrator access, monitoring, training, and incident response.
Does managed IT include Revit support?
It should include workstation, installation, licensing, network, storage, cloud-access, and performance support. BIM standards, families, templates, and model-management questions may remain with the BIM team.
Does managed IT include Microsoft 365 licenses?
Some providers bundle licensing, while others bill it separately. The proposal should clearly separate service fees from software licenses.
Should backup be included?
Backup monitoring and recovery planning should be included in a complete managed service. Confirm which systems, licenses, storage, restoration labor, and tests are covered.
How much does managed IT cost for an architecture firm?
A planning range for a 25–50 person architecture firm is approximately $100–$275 per user per month. Actual pricing depends on scope, security, infrastructure, support hours, and included tools.
Are major projects included in managed IT?
Some providers include limited project work, while others price major migrations, office moves, and infrastructure replacements separately. The contract should define both categories.
How often should leadership meet with the provider?
Quarterly technology reviews are appropriate for many firms. High-growth or high-risk organizations may need more frequent strategic meetings.
Who should own Microsoft 365 and Autodesk accounts?
The architecture firm should retain ownership and appropriate administrative visibility. The managed provider may administer the systems on the firm's behalf.
How long should a managed IT transition take?
A structured transition may take 30–90 days depending on documentation quality, device count, security changes, infrastructure complexity, and cooperation from the previous provider.
Choose Managed IT That Supports Project Delivery
A strong managed IT agreement should give an architecture firm reliable support, secure systems, recoverable project information, predictable planning, and clear accountability. It should also recognize that architecture firms depend on Revit, BIM collaboration, powerful workstations, cloud platforms, consultants, and deadline-driven project work.
911 IT helps architecture and engineering firms manage employees, workstations, Microsoft 365, Autodesk environments, cybersecurity, infrastructure, backup, recovery, and strategic planning through managed IT services, cybersecurity services, and specialized engineering IT support.
Schedule a discovery call to review your current IT coverage and build a managed service plan around your firm's employees, projects, security requirements, and growth goals.
