Operations

ITSM

IT Service Management

IT Service Management is the operating discipline for delivering, supporting, measuring, and continuously improving IT services through structured, repeatable processes rather than ad hoc firefighting.

Why ITSM matters in a Microsoft estate

ITSM matters when teams need repeatable day-two work rather than one-off fixes. Definitions in this area should help readers connect reporting, review, remediation, backup, drift, and evidence capture to a controlled operating model.

How ITSM shows up in practice

It is typically organised around a small set of core process areas: incident management for restoring a disrupted service quickly, problem management for finding and removing the underlying cause behind recurring incidents, change management for controlling how modifications reach production systems safely, and request management for handling routine, predictable asks like access or provisioning through a standard, low-friction path. Frameworks such as ITIL describe how these processes should fit together. Most organisations implement some or all of them through a service desk platform that tracks tickets, enforces SLAs, and produces the reporting that shows whether the service is actually being delivered at the standard promised.

For teams running Microsoft 365 and Azure estates specifically, ITSM discipline is what determines whether cost optimisation, security remediation, and licence management findings turn into completed work or sit unresolved in a report nobody actioned. A rightsizing recommendation or a licence reclaim opportunity is only valuable once it is logged as a change or a request, assigned an owner, tracked to completion, and closed with evidence. Tooling that surfaces findings without a path into that operational workflow tends to produce reports that get read once and then ignored. Change management is where ITSM discipline intersects most directly with tenant configuration drift and configuration baselines, since a properly governed change process is exactly what should prevent an ungoverned, undocumented tenant change in the first place.

A tenant with a mature change management practice should, in principle, see less unexplained drift than one where admins make direct changes outside any tracked process. In practice, most tenants sit somewhere between those extremes, which is why drift detection remains a useful independent check even in organisations with a formal ITSM process, since it catches what got past the process rather than assuming the process caught everything. Problem management is similarly relevant to remediation work.

A security or Intune finding that keeps recurring across a fleet of devices, or repeatedly needs the same fix applied, is a signal of an underlying root cause, whether a misconfigured baseline, a group policy conflict, or an image build issue, that a one-off remediation will not resolve. Treating it as a problem rather than a string of unrelated incidents is what actually stops the pattern. For MSPs, ITSM maturity is also a commercial differentiator and a Quarterly Business Review talking point. Being able to show a customer consistent SLA performance, a declining incident trend for a given root cause, and a clean audit trail of changes made to their tenant is evidence of a well-run service relationship, not just a technical process running quietly in the background.

Glossary