What Should an IT AMC in Dubai Actually Cover? A Contract Scope Checklist for Business Owners

April 26, 2026

What Should an IT AMC in Dubai Actually Cover? A Contract Scope Checklist for Business Owners

An IT annual maintenance contract can look reassuring until the first serious problem occurs. The proposal may promise unlimited support, preventive maintenance and fast response, yet the agreement does not explain which users, systems or locations are covered. A server issue appears and turns out to be “project work.” A backup failure is discovered, but restore testing was never included. An engineer visits the office, but the internet provider, firewall vendor and application company each say the problem belongs to someone else.

A useful IT AMC should remove these grey areas before support begins. It should define the environment, responsibilities, service hours, escalation process, security expectations and evidence the business will receive. Price matters, but an inexpensive contract with unclear ownership can become costly through downtime, emergency work and repeated disputes.

Start with a complete service baseline

The provider cannot support an environment it has not documented. Before the contract starts, both parties should agree the assets, users, locations and services that fall within scope.

The baseline should include:

  • number of employees and support users;
  • laptops, desktops, mobile devices and shared workstations;
  • printers, scanners and meeting-room equipment;
  • Microsoft 365 or other cloud subscriptions;
  • servers, storage, virtualization and business applications;
  • firewalls, switches, wireless access points and internet links;
  • backup systems and protected workloads;
  • offices, branches, warehouses, retail sites and remote users;
  • existing technology vendors and support contracts;
  • known risks, recurring incidents and ageing equipment.

This information should become an environment register rather than remaining in the salesperson’s notes. The register needs an owner and a process for updating it when people, devices or systems change.

Define user support in practical terms

“Helpdesk included” is not enough. The contract should explain which requests users may raise and how support will be delivered.

Typical user-support scope may include:

  • operating-system and standard software issues;
  • Microsoft 365, email, Teams, OneDrive and SharePoint assistance;
  • password, access and account problems;
  • printer, scanner and office connectivity troubleshooting;
  • approved application coordination;
  • new-user setup and employee offboarding;
  • remote support and scheduled onsite assistance;
  • basic user guidance and recurring-issue documentation.

It should also state what is not covered. Personal devices, unlicensed software, unsupported applications or home networks may require separate treatment. Users should know where to raise requests and should not depend on informal messages to individual engineers.

Separate incident support from service requests and projects

Different types of work need different expectations.

Work typeMeaningExample
IncidentAn existing service is unavailable or degraded.Email outage, failed internet connection or application error.
Service requestA standard user or administrative request.New mailbox, access change, software installation or device setup.
Problem managementWork to identify and remove the cause of repeated incidents.Recurring Wi-Fi drops or repeated profile corruption.
ChangeA controlled modification to the environment.Firewall rule, network change or major Microsoft 365 policy update.
ProjectPlanned work with separate scope, effort and acceptance.Office relocation, server migration or new branch deployment.

An AMC can include selected standard changes, but larger projects should have separate estimates and approvals. The agreement should define the boundary so normal support is not repeatedly delayed by unplanned project work.

Specify remote and onsite coverage

Many issues can be resolved remotely, while some require physical access. A clear Dubai AMC should state:

  • service hours and working days;
  • remote-support coverage;
  • number or frequency of scheduled visits;
  • conditions for emergency onsite attendance;
  • areas or locations covered;
  • travel, parking or access requirements;
  • after-hours and public-holiday treatment;
  • charges that apply outside the agreed allowance.

A contract should not promise immediate onsite response for every ticket. It should explain how business impact determines priority and when remote diagnosis occurs first.

Include Microsoft 365 and identity responsibilities

For many Dubai businesses, Microsoft 365 is the centre of email, collaboration, files and user identity. The AMC should clarify whether it includes:

  • user and license administration;
  • mailboxes, groups and shared mailboxes;
  • Teams, OneDrive and SharePoint support;
  • multifactor authentication setup;
  • administrator-role review;
  • joiner, mover and leaver activities;
  • mail-flow and delivery troubleshooting;
  • external sharing and guest-user support;
  • security alerts and risky exceptions;
  • vendor escalation to Microsoft where applicable.

Microsoft describes identity lifecycle management through joiner, mover and leaver processes, with tasks such as enabling or disabling accounts, assigning licenses and changing group membership. Its identity lifecycle guidance is a useful reference when defining these operational responsibilities.

The provider should not use shared administrator credentials. Administrative access, emergency accounts and approvals should be documented.

Clarify infrastructure monitoring and maintenance

“Proactive support” should translate into named activities. Depending on the environment, the AMC may cover:

  • server availability, disk, memory and critical-service monitoring;
  • firewall, switch and access-point health checks;
  • internet-link and VPN issue coordination;
  • patching oversight for supported systems;
  • configuration backup for selected infrastructure;
  • capacity and lifecycle observations;
  • alert review and escalation;
  • preventive maintenance windows.

The contract should identify which tools are included, who owns their licenses and what happens when an alert is generated. Monitoring without an agreed response process provides limited value.

Make cybersecurity responsibilities explicit

An IT AMC is not automatically a full cybersecurity service. The agreement should distinguish routine security hygiene from specialist security work.

Routine scope may include:

  • endpoint-protection status checks;
  • patch and update coordination;
  • multifactor authentication administration;
  • administrator and remote-access control;
  • basic email-security configuration;
  • security-alert escalation;
  • user offboarding and access removal;
  • firewall-rule governance.

Specialist work such as penetration testing, digital forensics, incident containment, compliance audits or twenty-four-hour security monitoring may require separate services. CISA’s guidance for managed service providers and customers recommends transparent discussion of security responsibilities and stronger controls around remote access, including multifactor authentication. The joint MSP security guidance can help management frame those questions.

Do not accept “backup included” without detail

The provider must state whether it supplies the backup platform, monitors an existing platform or only helps when a restore is requested.

The scope should identify:

  • systems and data being protected;
  • backup frequency and retention;
  • onsite, cloud and offline copies where applicable;
  • who receives failed-job alerts;
  • how quickly failures are investigated;
  • how restore tests are scheduled;
  • recovery priorities and dependencies;
  • license and storage ownership;
  • limitations and excluded workloads.

A successful backup job is not proof that recovery will work. Restore testing and recovery documentation should be included or separately scheduled.

Define third-party vendor coordination

Businesses often depend on internet providers, software vendors, hardware warranties, cloud platforms and application partners. The IT provider may coordinate these parties, but cannot control their resolution times.

The AMC should explain:

  • which vendors the provider will contact;
  • who must maintain active warranties and subscriptions;
  • which customer approvals are required;
  • how vendor cases are recorded and followed up;
  • how dependency delays affect the SLA;
  • whether application-level troubleshooting is included.

Coordination should have an owner even when the final fix depends on another company.

Agree a support priority model

Priority should reflect business impact and urgency, not the job title of the person raising the ticket.

PriorityTypical business impact
CriticalMajor operation unavailable, many users affected or serious security/recovery event.
HighImportant function unavailable with no practical workaround.
NormalLimited user or process impact with a workaround available.
LowRoutine request, information request or planned change.

Response targets, update frequency and escalation should be stated for each level. Resolution targets should recognise vendor, hardware, approval and procurement dependencies.

Require reporting that management can use

A monthly report should not be a list of closed tickets. It should help leadership understand the environment.

Useful reporting includes:

  • ticket volume and response performance;
  • major incidents and business impact;
  • repeated issues and root-cause actions;
  • open risks and overdue decisions;
  • backup and restore status;
  • security and patch exceptions;
  • asset, license and access changes;
  • vendor dependencies;
  • recommended improvements and budget items.

The contract should include a service-review meeting at an agreed frequency, with actions and owners recorded.

List exclusions in plain language

Common exclusions can include:

  • new office or branch projects;
  • major migrations and upgrades;
  • structured cabling and civil work;
  • replacement hardware and spare parts;
  • third-party license charges;
  • custom application development;
  • forensic investigations;
  • support for unsupported or unlicensed systems;
  • work outside agreed hours or locations.

Exclusions are not a weakness when they are clear. They allow the business to plan and avoid conflict.

Use an onboarding and exit clause

The beginning and end of the contract deserve as much attention as the monthly service.

Onboarding should cover:

  • environment discovery;
  • credential handover and secure storage;
  • asset and vendor records;
  • open issues and risks;
  • monitoring deployment;
  • user communication;
  • initial security and backup review.

The exit clause should require return of documentation, credentials, configuration backups, asset records, current tickets and vendor information. The customer should retain ownership of its accounts and data.

The final IT AMC contract checklist

  1. Is every supported user, location and asset category listed?
  2. Are helpdesk, onsite and after-hours arrangements clear?
  3. Are incidents, requests, changes and projects separated?
  4. Are Microsoft 365 and identity duties defined?
  5. Are monitoring and preventive tasks named?
  6. Are cybersecurity responsibilities and limitations explicit?
  7. Are protected backups and restore tests identified?
  8. Is third-party vendor coordination included?
  9. Are priorities, response targets and update rules documented?
  10. Will management receive useful monthly reporting?
  11. Are exclusions and additional charges understandable?
  12. Are onboarding, documentation ownership and exit handover covered?

Frequently asked questions

Does an IT AMC include unlimited support?

It may include unlimited eligible tickets within a defined environment and service window, but projects, unsupported systems, after-hours work or additional locations can still fall outside scope.

Should onsite visits be fixed or incident-based?

The best model depends on the environment. Scheduled preventive visits can be combined with incident-based attendance when remote support cannot resolve a high-impact issue.

Is cybersecurity automatically included?

Basic security hygiene may be included, but specialist monitoring, incident response, compliance and penetration testing should be explicitly stated.

Who should own Microsoft 365 administrator accounts?

The customer should retain ownership. Provider access should use named, controlled accounts with appropriate permissions and a documented exit process.

What is the best way to compare AMC proposals?

Compare the actual service baseline, responsibilities, exclusions, reporting, security controls and recovery duties—not only the monthly price or number of visits.

A strong AMC gives a Dubai business a dependable operating model rather than a vague promise of support. Businesses that need broader service desk, Microsoft 365, infrastructure, security, backup and governance coverage can review the full scope of managed IT services in Dubai.