HomeMy WebLinkAbout2023-135-E-IT Dept-Catapult Systems, LLC, a Quisitive Company-Fast Track SupportRevised 06/21
1
[Departmental Use Only]
TITLE FastTrack
FY 23
NORTH CAROLINA
SERVICES AGREEMENT NO RFP/RFQ
ORANGE COUNTY
This Services Agreement (hereinafter “Agreement”), made and entered into this 22nd day
of March, 2023, (“Effective Date”) by and between Orange County, North Carolina a political
subdivision of the State of North Carolina (hereinafter, the "County") and Quisitive Company,
(hereinafter, the "Provider").
WITNESSETH:
That the County and Provider, for the consideration herein named, do hereby agree as
follows:
1. Services
a. Scope of Work.
i) This Agreement is for services to be rendered by Provider to County with respect
to (insert type of project): Microsoft M365 Fast Track Services (see Attachment
A)
ii) By executing this Agreement, the Provider represents and agrees that Provider is
qualified to perform and fully capable of performing and providing the services
required or necessary under this Agreement in a fully competent, professional and
timely manner.
iii) Time is of the essence with respect to this Agreement.
iv) The services to be performed under this Agreement consist of Basic Services, as
described and designated in Section 3 hereof. Compensation to the Provider for
Basic Services under this Agreement shall be as set forth herein.
2. Responsibilities of the Provider
a. Services to be provided. The Provider shall provide the County with all services
required in Section 3 to satisfactorily complete the Project within the time limitations set
forth herein and in accordance with the highest professional standards.
b. Standard of Care.
i) The Provider shall exercise reasonable care and diligence in performing services
under this Agreement in accordance with the highest generally accepted standards
of this type of Provider practice throughout the United States and in accordance
with applicable federal, state and local laws and regulations applicable to the
performance of these services. Provider is solely responsible for the professional
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Revised 06/21
2
quality, accuracy and timely completion and submission of all work related to the
Basic Services.
ii) Provider shall be responsible for all errors or omissions of its agents, contractors,
employees, or assigns in the performance of the Agreement. Provider shall
correct any and all errors, omissions, discrepancies, ambiguities, mistakes or
conflicts at no additional cost to the County.
iii) The Provider shall not, except as otherwise provided for in this Agreement,
subcontract the performance of any work under this Agreement without prior
written permission of the County. No permission for subcontracting shall create,
between the County and the subcontractor, any contract or any other relationship.
iv) Provider is an independent contractor of County. Any and all employees of the
Provider engaged by the Provider in the performance of any work or services
required of the Provider under this Agreement, shall be considered employees or
agents of the Provider only and not of the County, and any and all claims that may
or might arise under any workers compensation or other law or contract on behalf
of said employees while so engaged shall be the sole obligation and responsibility
of the Provider.
v) If activities related to the performance of this Agreement require specific licenses,
certifications, or related credentials Provider represents that it or its employees,
agents and subcontractors engaged in such activities possess such licenses,
certifications, or credentials and that such licenses certifications, or credentials are
current, active, and not in a state of suspension or revocation.
vi) In determining the Basic Services to be provided, should any documents be
referenced in this Agreement, the terms of this Agreement shall have priority in
any conflict between the terms of referenced documents and the terms of this
Agreement.
vii) Should this Agreement involve project designs, the construction or creation of
which is to be bid out or fulfilled by other contractors, and bidding or negotiation
with contractors produce prices which, when added to the other elements of the
approved total project cost, produce a cost that is in excess of the approved total
project cost, the Provider shall participate with the County in negotiation and
design adjustments to the extent such are necessary to obtain prices within the
approved total project cost. All activity of the Provider with respect to these
matters shall constitute Basic Services and shall be performed by the Provider
without additional compensation. If negotiation and design adjustments fail to
bring costs within the total project cost the County may reject all bids and
Provider will redesign or reduce portions of the project in an effort to reduce the
bid prices to within the total project cost and rebid the project. One such redesign
is included within Basic Services. If this second letting for bids does not produce
bids that are within the approved total project cost initially or after negotiations
with the contractor the cost is not reduced to an amount within the total project
cost, the Provider is not obligated to engage in further redesign.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Revised 06/21
3
3. Basic Services
a. Basic Services. The Services to be rendered pursuant to this Agreement are as follows
(fully describe services to be provided): Microsoft M365 Consulting
4. Duration of Services
a. Term. The term of this Agreement shall be from March 22, 2023 to March 22, 2024.
b. Scheduling of Services.
i) The Provider shall schedule and perform its activities in a timely manner.
ii) Should the County determine that the Provider is behind schedule, it may require
the Provider to expedite and accelerate its efforts, including providing additional
resources and working overtime, as necessary, to perform its services in
accordance with the approved project schedule at no additional cost to the
County.
iii) The Commencement Date for the Provider's Basic Services shall be March 22,
2023.
5. Compensation
a. Compensation for Basic Services. Compensation for Basic Services shall include all
compensation due the Provider from the County for all services satisfactorily (as
determined by the County) performed pursuant to this Agreement. The maximum
amount payable for Basic Services shall not exceed Zero Dollars ($0.00). Payment for
satisfactorily performed Basic Services shall become due and payable within thirty (30)
days of Provider properly invoicing County. Payment shall be subject to provisions of
Section 5(b).
b. Disputes. In the event the amount stated on an invoice is disputed by the County, the
County may withhold payment of all or a portion of the amount stated on an invoice
until the parties resolve the dispute. Should Provider fail to perform its duties under the
terms of this Agreement, County may, without fault or penalty, withhold any payment
associated with the work to be performed until such time as said work is completed.
c. Additional Services. County shall not be responsible for costs related to any services in
addition to the Basic Services performed by Provider unless County requests such
additional services in writing and such additional services are evidenced by a written
amendment to this Agreement.
6. Responsibilities of the County
a. Cooperation and Coordination. The County has designated (Jim Northrup) to act as the
County's representative with respect to the Project who shall have the authority to render
decisions within guidelines established by the County Manager or the County Board of
Commissioners and who shall be available during working hours as often as may be
reasonably required to render decisions and to furnish information.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Revised 06/21
4
7. Insurance
a. General Requirements. Provider shall obtain, at its sole expense, Commercial General
Liability Insurance, Automobile Insurance, Workers’ Compensation Insurance, and any
additional insurance as may be required by County’s Risk Manager as such insurance
requirements are described in the Orange County Risk Transfer Policy and Orange
County Minimum Insurance Coverage Requirements (each document is incorporated
herein by reference and may be viewed at
http://www.orangecountync.gov/departments/purchasing_division/contracts.php). If
County’s Risk Manager determines additional insurance coverage is required such
additional insurance shall consist of N/A (if no additional insurance required mark N/A
as being not applicable). Provider shall not commence work until such insurance is in
effect and certification thereof has been received by the County's Risk Manager.
8. Indemnity
a. Indemnity. To the extent authorized by North Carolina law the Provider agrees, without
limitation, to defend, indemnify and hold harmless the County from all loss, liability,
claims or expense, including attorney's fees, arising out of or related to the Project and
arising from property damage or bodily injury including death to any person or persons
caused in whole or in part by the negligence or misconduct of the Provider except to the
extent same are caused by the negligence or willful misconduct of the County. It is the
intent of this provision to require the Provider to indemnify the County to the fullest
extent permitted under North Carolina law.
9. Amendments to the Agreement
a. Changes in Basic Services. Changes in the Basic Services and entitlement to additional
compensation or a change in duration of this Agreement shall be made by a written
Amendment to this Agreement executed by the County and the Provider. The Provider
shall proceed to perform the Services required by the Amendment only after receiving a
fully executed Amendment from the County.
10. Termination
a. Termination for Convenience of the County. This Agreement may be terminated without
cause by the County and for its convenience upon seven (7) days’ prior written notice to
the Provider.
b. Other Termination. The Provider may terminate this Agreement based upon the County's
material breach of this Agreement; provided, the County has not taken all reasonable
actions to remedy the breach. The Provider shall give the County seven (7) days' prior
written notice of its intent to terminate this Agreement for cause. Either party may
terminate this Agreement upon notice to the other party that obligations pursuant to this
Agreement are made impractical due to declarations of emergency by Orange County or
by North Carolina due to events directly impacting Orange County. Both parties shall
remain responsible for all payment and performance due up to the receipt of such notice,
but shall have no further obligation or responsibility beyond that date provided the
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Revised 06/21
5
terminating party has taken all reasonable steps to complete the performance of its
obligations.
c. Compensation After Termination.
i) In the event of termination, the Provider shall be paid that portion of the fees and
expenses that it has earned to the date of termination, less any costs or expenses
incurred or anticipated to be incurred by the County due to errors or omissions of
the Provider. Upon request of the County, the Provider shall submit to County all
relevant documentation, including but not limited to, job cost records, to support
its claims for final compensation.
ii) Should this Agreement be terminated, the Provider shall deliver to the County
within seven (7) days, at no additional cost, all deliverables including any
electronic data or files relating to the Project.
d. Waiver. The payment of any sums by the County under this Agreement or the failure of
the County to require compliance by the Provider with any provisions of this Agreement
or the waiver by the County of any breach of this Agreement shall not constitute a
waiver of any claim for damages by the County for any breach of this Agreement or a
waiver of any other required compliance with this Agreement.
e. Suspension. County may suspend the Basic Services and this Agreement at any time for
County’s convenience and without penalty to County upon three (3) days’ notice to
Provider. Upon any suspension by County, Provider shall discontinue work on the Basic
Services and shall not resume the Basic Services until notified to proceed by County.
11. Additional Provisions
a. Limitation and Assignment. The County and the Provider each bind themselves, their
successors, assigns and legal representatives to the terms of this Agreement. Neither the
County nor the Provider shall assign or transfer its interest in this Agreement without the
written consent of the other.
b. Governing Law. This Agreement and the duties, responsibilities, obligations and rights
of respective parties hereunder shall be governed by the laws of the State of North
Carolina. By executing this Agreement Provider affirms that Provider and any
subcontractors of Provider are and shall remain in compliance with Article 2 of Chapter
64 of the North Carolina General Statutes. By executing this Agreement Provider
certifies that Provider has not been identified, and has not utilized the services of any
agent or subcontractor identified, on the list created by the State Treasurer pursuant to
G.S. 147-86.58. By executing this Agreement Provider certifies that Provider has not
been identified, and has not utilized the services of any agent or subcontractor identified,
on the list created by the State Treasurer pursuant to G.S. 147-86.81.
c. Non-Discrimination. Provider shall at all times remain in compliance with all applicable
local, state, and federal laws, rules, and regulations including but not limited to all state
and federal non-discrimination laws, policies, rules, and regulations and the Orange
County Non-Discrimination Policy and Orange County Living Wage Policy (each policy
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Revised 06/21
6
is incorporated herein by reference and may be viewed at
http://www.orangecountync.gov/departments/purchasing_division/contracts.php.) Any
violation of the Orange County Non-Discrimination Policy is a breach of this Agreement
and County may immediately terminate this Agreement without further obligation on the
part of the County. This paragraph is not intended to limit and does not limit the
definition of breach to discrimination.
d. Dispute Resolution. Any and all suits or actions to enforce, interpret or seek damages
with respect to any provision of, or the performance or non-performance of, this
Agreement shall be brought in the General Court of Justice of North Carolina sitting in
Orange County, North Carolina. It is agreed by the parties that no other court shall have
jurisdiction or venue with respect to such suits or actions. Binding arbitration may not
be initiated by either Party, however, the Parties may agree to nonbinding mediation of
any dispute prior to the bringing of such suit or action.
e. Entire Agreement. This Agreement represents the entire and integrated agreement
between the County and the Provider and supersedes all prior negotiations,
representations or agreements, either written or oral. This Agreement may be amended
only by written instrument signed by both parties. Modifications may be evidenced by
facsimile signatures.
f. Severability. If any provision of this Agreement is held as a matter of law to be
unenforceable, the remainder of this Agreement shall be valid and binding upon the
Parties.
g. Ownership of Work Product. Should Provider’s performance of this Agreement generate
documents, items or things that are specific to this Project such documents, items or
things shall become the property of the County and may be used on any other project
without additional compensation to the Provider. The use of the documents, items or
things by the County or by any person or entity for any purpose other than the Project as
set forth in this Agreement shall be at the full risk of the County.
h. Non-Appropriation. Provider acknowledges that County is a governmental entity, and
the validity of this Agreement is based upon the availability of public funding under the
authority of its statutory mandate.
In the event that public funds are unavailable or not appropriated for the performance of
County’s obligations under this Agreement, then this Agreement shall automatically
expire without penalty to County immediately upon written noti ce to Provider of the
unavailability or non-appropriation of public funds. It is expressly agreed that County
shall not activate this non-appropriation provision for its convenience or to circumvent
the requirements of this Agreement.
In the event of a change in the County’s statutory authority, mandate or mandated
functions, by state or federal legislative or regulatory action, which adversely affects
County’s authority to continue its obligations under this Agreement, then this Agreement
shall automatically terminate without penalty to County upon written notice to Provider
of such limitation or change in County’s legal authority.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Revised 06/21
7
i. Signatures. This Agreement together with any amendments or modifications may be
executed electronically. All electronic signatures affixed hereto evidence the consent of
the Parties to utilize electronic signatures and the intent of the Parties to comply with
Article 11A and Article 40 of North Carolina General Statute Chapter 66.
j. Notices. Any notice required by this Agreement shall be in writing and delivered by
certified or registered mail, return receipt requested to the following:
Orange County Provider’s Name
Attention:Jim Northrup Quisitive, LLC
P.O. Box 8181 1431 Greenway Drive, #1000
Hillsborough, NC 27278 Irving, Texas 75038
[SIGNATURE PAGE TO FOLLOW]
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Revised 06/21
8
IN WITNESS WHEREOF, the Parties, by and through their authorized agents, have
hereunder set their hands and seal, all as of the day and year first above written.
ORANGE COUNTY: PROVIDER:
By: _________________________________
Jim Northrup, Chief Information Officer
By: __________________________________
Syed Hasan, VP of Management Services
& Operations
Printed Name and Title
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
3/23/20233/28/2023
Revised 06/21
9
ORANGE COUNTY—DEPARTMENT USE ONLY
______________________________________________________________________________
Party/Vendor Name: Catapult Systems, LLC, a Quisitive Company Party/Vendor Contact Person: Syed Hasan
Contact Phone: Party/Vendor Address: 5301 Southwest Parkway, Bldg 1, Suite 425 City Austin State: TX
Zip: 78735 Department: Information Technologies Amount: $0.00 Purpose: Fast Track Support Budget Code(s):
N/A Vendor # N/A (N/A if new vendor) Vendor is a BOCC consultant? Yes No Contract Type: (Check
one) New Renewal Amendment Effective Date 3/22/2023 Approved by Board Yes No Agenda
Date: --- For Section XIV. c. contracts only, Approved by Board in Current FY Budget Yes No
This agreement is approved as to technical form and content and I as Department Director affirmatively state work
on this project has not been initiated prior to execution of the agreement:
Department Director’s Signature ________________________________________ Date: ________
Agreements for emergency services or repair are not subject to the above affirmation. If services related to this
agreement have already begun or been completed please briefly describe the nature of the emergency condition that
was addressed: N/A
Information Technologies
(Applicable only to hardware/software purchases or related services) This agreement has been reviewed and is
approved as to information technology content and specifications:
Office of the Chief Information Officer___________________________________ Date: ________
Risk Management
This agreement is approved for sufficiency of insurance standards, specifications, and requirements:
Office of the Risk Management Officer___________________________________ Date: _________
Financial Services
This instrument has been pre-audited in the manner required by the Local Government Budget and Fiscal Control
Act:
Office of the Chief Financial Officer ____________________________________ Date: _________
Legal Services
This agreement is approved as to legal form and sufficiency:
Office of the County Attorney __________________________________________Date: ________
Clerk to the Board
Received for record retention:
All Docusign contracts must be copied to the Clerk upon completion: occlerkdocs@orangecountync.gov
The following signature block is for hard copies only and is not required for Docusign contracts:
Office of the Clerk to the Board __________________________________________Date:_________
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
3/23/2023
3/23/2023
3/24/2023
3/24/2023
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 1 of 26
FastTrack Benefit Services
1. Objective
This statement of work (hereinafter “SOW”) represents an agreement between Quisitive
(hereinafter “Quisitive”) and Orange County NC (hereinafter “Client”). The purpose of this
engagement is to deliver the Microsoft FastTrack Benefit for eligible products and plans as defined
by the Microsoft FastTrack benefit guidance by workload.
2.Scope of Services
FastTrack services provide a recommended approach, guidance, and best practices for technical
onboarding (core onboarding, service onboarding, and data migration) and user adoption. User
adoption services provide guidance and templates to ensure your users are aware of the eligible
services and can use them to drive business value. All in scope FastTrack services are delivered
remotely via scheduled online meetings between the Client and Quisitive FastTrack Specialists.
Workload Designation
Utilizing their FastTrack benefits, Orange County NC will be provided guidance as outlined by
workload per the FastTrack process and expectations. Orange County NC selects Quisitive as
their FastTrack partner for the following workloads designated by a ☒:
Office 365
☒Exchange Online ☒Microsoft Teams – Platform/Core
enablement☒SharePoint Online & OneDrive ☒Microsoft Teams – Phone Systems☒Microsoft 365 Apps ☒Microsoft Teams – Meetings☒Yammer ☒PowerBI☒Project Online ☒Project Online Pro and Premium
Discover and Respond ☒Purview eDiscovery ☒Purview Audit☒Compliance Manager ☒Purview Insider Risk Management
Security and Compliance
☒Azure Active Directory Premium ☒Microsoft Purview Information
Protection☒Microsoft Information Governance ☒Microsoft Intune☒Microsoft Defender for Identity (MDI)☒Microsoft Defender for Cloud Apps☒Microsoft Defender for Office 365 ☒Microsoft Defender for EndPoint☒Microsoft 365 Defender ☒Azure Information Protection☒Microsoft Purview Data Lifecycle
Management
Employee Experience ☒Employee Experience using Microsoft Viva ☒Microsoft Viva Connections☒Microsoft Viva Insights ☒Microsoft Viva Topics
Attachment ADocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 2 of 26
☒ Microsoft Viva Learning
Windows ☒ Windows 10 ☒ Windows 365 Enterprise ☒ Windows 11 ☒ App Assure ☒ Universal Print ☒ Microsoft Edge
Tenant’s sub-domain name, e.g. yourcompany.onmicrosoft.com
Required: orangecountync.onmicrosoft.com
Directory ID/Tenant ID (Found in Azure Active Directory under "Manage", "Properties")
Required: b507459c-743d-4f3f-ae6e-d1526b7a62ad
FastTrack benefits guidance (this APS updated 1/23/2023)
Updated Monthly Online (https://docs.microsoft.com/en-us/fasttrack/products-and-capabilities)
Migration
FastTrack Migration Services, as described in the Data Migration section of the FastTrack Center
Benefit for Microsoft 365 are provided directly by Microsoft for this Program and are not part of
FastTrack Benefit Services to be provided by Program Partners.
FastTrack Core Onboarding
We provide remote guidance on core onboarding, which involves service provisioning, tenant, and
identity integration. It also includes steps for providing a foundation for onboarding services like
Exchange Online, SharePoint Online, and Microsoft Teams, including a discussion on security,
network connectivity, and compliance.
Onboarding for one or more eligible services can begin once core onboarding is finished.
Identity Integration
Provide remote guidance for:
• Preparing on-premises Active Directory Identities for synchronization to Azure Active
Directory (Azure AD) including installing and configuring Azure AD Connect (single- or
multi-forest) and licensing (including group-based licensing).
• Creating cloud identities including bulk import and licensing including using group-based
licensing.
• Choosing and enabling the correct authentication method for your cloud journey, Password
Hash Sync, Pass-through Authentication, or Active Directory Federation Services (AD
FS).
• Choosing and enabling a more convenient authentication experience for your users with
passwordless authentication using Fast Identity Online (FIDO)2, Microsoft Authenticator
App, or Windows Hello for Business cloud trust.
• Providing planning guidance for Windows Hello for Business hybrid key or certificate
trust.
• Enabling AD FS for customers with a single Active Directory forest and identities
synchronized with the Azure AD Connect tool. This requires Windows Server 2012 R2
Active Directory Federation Services 2.0 or greater.
• Migrating authentication from AD FS to Azure AD using Password Hash Sync or Pass-
through Authentication.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 3 of 26
• Migrating pre-integrated apps (like Azure AD gallery software-as-a-service (SaaS) apps)
from AD FS to Azure AD for single sign-on (SSO).
• Enabling SaaS app integrations with SSO from the Azure AD gallery.
• Enabling automatic user provisioning for pre-integrated SaaS apps as listed in the App
integration tutorial list (limited to Azure AD gallery SaaS apps and outbound provisioning
only).
Microsoft 365 Apps
Provide remote deployment guidance for:
• Addressing deployment issues.
• Assigning end-user and device-based licenses using the Microsoft 365 admin center and
Windows PowerShell.
• Installing Microsoft 365 Apps from the Office 365 portal using Click-to-Run.
• Installing Office Mobile apps (like Outlook Mobile, Word Mobile, Excel Mobile, and
PowerPoint Mobile) on your iOS or Android devices.
• Configuring update settings using the Office 365 Deployment Tool.
• Selection and setup of a local or cloud installation.
• Creation of the Office Deployment Tool configuration XML with the Office
Customization Tool or native XML to configure the deployment package.
• Deployment using Microsoft Endpoint Configuration Manager, including assistance with
the creation of Microsoft Endpoint Configuration Manager packaging. Additionally, if you
have a macro or add-in that worked with prior versions of Office and you experience
compatibility issues, we provide guidance to remediate the compatibility issue at no
additional cost through the App Assure program.
Network Health
• We provide remote guidance with obtaining and interpreting key network connectivity
data from your environment showing how aligned your organization’s sites are to
Microsoft’s principles of network connectivity. This highlights your network score which
directly impacts migration velocity, user experience, service performance, and reliability.
We also guide you through any remediation steps highlighted by this data to help you
improve your network score.
FASTTRACK BENEFIT FOR SECURITY AND COMPLIANCE:
Microsoft Azure Active Directory and Azure AD Premium
Provide remote guidance on:
• Configuring and enabling strong authentication for your identities, including protecting
with Azure Multi-Factor Authentication (MFA) (cloud only), the Microsoft Authenticator
app, and combined registration for Azure MFA and self-service password reset (SSPR).
• For non-Azure AD Premium customers, guidance is provided to secure your identities
using security defaults.
• For Azure AD premium customers, guidance is provided to secure your identities with
Conditional Access.
• Detecting and blocking the use of weak passwords with Azure AD Password Protection.
• Securing remote access to on-premises web apps with Azure AD Application Proxy.
• Enabling risk-based detection and remediation with Azure Identity Protection.
• Enabling a customized sign-in screen, including logo, text, and images with custom
branding.
• Securely sharing apps and services with guest users using Azure AD B2B.
• Managing access for your Office 365 admins using role-based access control (RBAC)
built-in administrative roles and to reduce the number of privileged admin accounts.
• Configuring hybrid Azure AD join.
• Configuring Azure AD join.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 4 of 26
• Enabling remote monitoring for AD FS, Azure AD Connect, and domain controllers with
Azure AD Connect Health.
• Managing your Azure AD identity and access lifecycle at scale with Azure AD entitlement
management.
• Managing Azure AD group memberships, enterprise app access, and role assignments with
Azure AD access reviews.
• Reviewing Azure AD Terms of Use.
• Managing and controlling access to privileged admin accounts with Azure AD Privileged
Identity Management.
• Enabling Azure AD SSPR.
• Allowing users to create and manage their own cloud security or Office 365 groups with
Azure AD self-service group management.
• Managing delegated access to enterprise apps with Azure AD delegated group
management.
• Enabling Azure AD dynamic groups.
• Organizing apps in the My Apps portal using collections.
Purview eDiscovery (Premium)
We provide remote guidance for:
• Creating a new case.
• Putting custodians on hold.
• Performing searches.
• Adding search results to a review set.
• Running analytics on a review set.
• Reviewing and tagging documents.
• Exporting data from the review set.
• Importing non-Office 365 data.
Purview Audit (only supported in E5)
We provide remote guidance for:
• Enabling advanced auditing.
• Performing a search audit log UI and basic audit PowerShell commands.
Purview Compliance Manager
We provide remote guidance for:
• Reviewing role types.
• Adding and configuring assessments.
• Assessing compliance by implementing improvement actions and determining how this
impacts your compliance score.
• Reviewing built-in control mapping and assessing controls.
• Generating a report within an assessment.
The following is out of scope:
• Custom scripting or coding.
• Purview eDiscovery API.
• Data connectors.
• Compliance boundaries and security filters.
• Data investigations.
• Data subject requests.
• Design, architect, and third-party document review.
• Compliance with industry and regional regulations and requirements.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 5 of 26
Hands-on implementation of recommended improvement actions for assessments in Purview
Compliance Manager.
Purview Insider Risk Management
We provide remote guidance for:
• Creating policies and reviewing settings.
• Accessing reports and alerts.
• Creating cases.
• Creating notice templates.
• Guidance on creating the human resources (HR) connector.
Purview Communication Compliance
We provide remote guidance for:
• Creating policies and reviewing settings.
• Accessing reports and alerts.
• Creating notice templates.
Purview Compliance Manager
We provide remote guidance for:
• Reviewing role types.
• Adding and configuring assessments.
• Assessing compliance by implementing improvement actions and determining how this
impacts your compliance score.
• Reviewing built-in control mapping and assessing controls.
• Generating a report within an assessment.
The following is out of scope:
• Creating and managing Power Automate flows.
• Data connectors (beyond the HR connector).
• Custom regular expression (RegEx) configurations.
• Design, architect, and third-party document review.
• Information barriers.
• Privileged access management.
• Compliance with industry and regional regulations and requirements.
• Hands-on implementation of recommended improvement actions for assessments in
Purview Compliance Manager.
Microsoft Purview Data Lifecycle
We provide remote guidance for:
• Creating and applying retention policies (supported in E3 and E5).
• Creating and publishing retention labels (supported in E3 and E5).
• Creating and applying event-based retention labels (supported in E5).
• Creating and applying adaptive policy scopes (supported in E5).
• Reviewing file plan creation (supported in E5).
• Reviewing dispositions (supported in E5).
• Policy lookups (supported in E5).
Purview Compliance Manager
Provide remote guidance on:
• Reviewing role types.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 6 of 26
• Adding and configuring assessments.
• Assessing compliance by implementing improvement actions and determining how
this impacts your compliance score.
• Reviewing built-in control mapping and assessing controls.
• Generating a report within an assessment.
The following is out of scope:
• Development of a records management file plan.
• Data connectors.
• Development of information architecture in SharePoint.
• Custom scripting and coding.
• Design, architect, and third-party document review.
• Compliance with industry and regional regulations and requirements.
• Hands-on implementation of recommended improvement actions for assessments in
Purview Compliance Manager.
• Importing PST files to Office 365.
Microsoft Purview Information Protection
We provide remote guidance for:
• Data classification (supported in E3 and E5).
• Sensitive information types (supported in E3 and E5).
• Creating sensitivity labels (supported in E3 and E5).
• Applying sensitivity labels (supported in E3 and E5).
• Trainable classifiers (supported in E5).
• Exact Data Match (EDM) custom sensitive information types (supported in E5).
• Knowing your data with content explorer and activity explorer (supported in E5).
• Publishing labels using policies (manual and automatic) (supported in E5).
• Creating Endpoint data loss prevention (DLP) policies for Windows 10 devices (supported
in E5).
• Creating DLP policies for Microsoft Teams chats and channels.
Purview Compliance Manager
We provide remote guidance for:
• Reviewing role types.
• Adding and configuring assessments.
• Assessing compliance by implementing improvement actions and determining how
this impacts your compliance score.
• Reviewing built-in control mapping and assessing controls.
• Generating a report within an assessment.
Microsoft Purview Information Protection
We provide remote guidance for:
• Activating and configuring your tenant.
• Creating and setting up labels and policies (supported in P1 and P2).
• Applying information protection to documents (supported in P1 and P2).
• Automatically classifying and labeling information in Office apps (like Word,
PowerPoint, Excel, and Outlook) running on Windows and using the Microsoft
Purview Information Protection client (supported in P2).
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 7 of 26
• Discovering and labeling files at rest using the Microsoft Purview Information
Protection scanner (supported in P1 and P2).
• Monitoring emails in transit using Exchange Online mail flow rules.
• Migration guidance from Azure Information Protection add-in to built-in labeling for
Office apps.
• We also provide guidance if you want to apply protection using Microsoft Azure
Rights Management Services (Azure RMS), Office 365 Message Encryption (OME),
and data loss prevention (DLP).
The following is out of scope:
• Customer key.
• Custom regular expressions (RegEx) development for sensitive information types.
• Creation or modification of keyword dictionaries.
• Interacting with customer data or specific guidelines for configuration of EDM-
sensitive information types.
• Custom scripting and coding.
• Azure Purview.
• Design, architect, and third-party document review.
• Compliance with industry and regional regulations and requirements.
• Hands-on implementation of recommended improvement actions for assessments in
Purview Compliance Manager.
Microsoft Defender for Identity
Microsoft Defender for Identity is a cloud-based security solution that leverages your on-premises
Active Directory signals to identify, detect, and investigate advanced threats, compromised
identities, and malicious insider actions directed at your organization. We provide remote guidance
for:
• Running the sizing tool for resource capacity planning.
• Creating your instance of Defender for Identity.
• Connecting Defender for Identity to Active Directory.
• Deploying the sensor to capture and parse network traffic and Windows events directly
from your domain controllers, including:
o Downloading the sensor package.
o Configuring the sensor.
o Installing the sensor on your domain controller silently.
o Deploying the sensor to your multi-forest environment.
o Configuring the Windows Event Collector.
• Configuring the portal, including:
o Integrating Defender for Identity with Microsoft Cloud App Security (Cloud App
Security licensing isn't required).
o Configuring entity tags.
o Tagging sensitive accounts.
o Receiving email notifications for health issues and security alerts.
o Configuring alert exclusions.
• Providing deployment guidance, configuration assistance, and education on:
o Understanding the Identity Security Posture Assessment report.
o Understanding the User Investigation Priority Score and User Investigation
ranking report.
o Understanding the inactive user report.
o Explanation of the remediation options on a compromised account.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 8 of 26
• Facilitating the migration from Advanced Threat Analytics (ATA) to Defender for
Identity.
The following is out of scope:
• Project management of the customer's remediation activities.
• Ongoing management, threat response, and remediation.
• Deploying Defender for Identity as a proof of concept.
• Supporting GCC-High or GCC-DoD (Office 365 US Government).
• Deploying or performing the following Defender for Identity sensor activities:
o Manual capacity planning.
o Running the Auditing tool.
o Deploying the standalone sensor.
o Deploying to Active Directory Federation Services (AD FS) servers.
o Deploying the sensor using a Network Interface Card (NIC) Teaming adaptor.
o Deploying the sensor through a third-party tool.
o Connecting to the Defender for Identity cloud service through a web proxy
connection.
• Configuring the Microsoft account (MSA) in Active Directory.
• Creation and management of honeytokens.
• Enabling Network Name Resolution (NNR).
• Configuration of Deleted Objects container.
• Deployment guidance or education on:
o Remediating or interpreting various alert types and monitored activities.
o Investigating a user, computer, lateral movement path, or entity.
o Threat or advanced hunting.
o Incident response.
• Providing a security alert lab tutorial for Defender for Identity.
• Providing notification when Defender for Identity detects suspicious activities by sending
security alerts to your syslog server through a nominated sensor.
• Configuring Defender for Identity to perform queries using security account manager
remote (SAMR) protocol to identify local admins on specific machines.
• Configuring VPN solutions to add information from the VPN connection to a user’s profile
page.
• Security information and event management (SIEM) or API integration (including Azure
Sentinel).
Microsoft Defender for Cloud Apps
Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides rich
visibility, control over data travel, and sophisticated analytics to identify and combat cyber threats
across all your Microsoft and third-party cloud services. We provide remote guidance for:
• Configuring the portal, including:
o Importing user groups.
o Managing admin access and settings.
o Scoping your deployment to select certain user groups to monitor or exclude from
monitoring.
o How to set up IP ranges and tags.
o Personalizing the end-user experience with your logo and custom messaging.
• Integrating first-party services including:
o Microsoft Defender for Endpoint.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 9 of 26
o Microsoft Defender for Identity.
o Azure AD Identity Protection.
o Microsoft Information Protection.
• Setting up cloud discovery using:
o Microsoft Defender for Endpoints.
o Zscaler.
o iboss.
• Creating app tags and categories.
• Customizing app risk scores based on your organization’s priorities.
• Sanctioning and unsanctioning apps.
• Reviewing the Defender for Cloud Apps and Cloud Discovery dashboards.
• Enabling the app governance add-on.
o Guide the customer through the overview page and create up to five (5) app
governance policies.
• Connecting featured apps using app connectors.
• Protecting apps with Conditional Access App Control in the Conditional Access within
Azure AD and Defender for Cloud Apps portals.
• Deploying Conditional Access App Control for featured apps.
• Using the activity and file logs.
• Managing OAuth apps.
• Reviewing and configuring policy templates.
• Providing configuration assistance with the top 20 use cases for CASBs (including the
creation or updating of up to six (6) policies) except:
o Auditing the configuration of your internet as a service (IaaS) environments
(#18).
o Monitoring user activities to protect against threats in your IaaS environments
(#19).
• Understanding incident correlation in the Microsoft 365 Defender portal.
The following is out of scope:
• Project management of the customer's remediation activities.
• Ongoing management, threat response, and remediation.
• Discussions comparing Defender for Cloud Apps to other CASB offerings.
• Configuring Defender for Cloud Apps to meet specific compliance or regulatory
requirements.
• Deploying the service to a non-production test environment.
• Deploying Cloud App Discovery as a proof of concept.
• Supporting GCC-High or GCC-DoD (Office 365 US Government).
• Setting up the infrastructure, installation, or deployment of automatic log uploads for
continuous reports using Docker or a log collector.
• Creating a Cloud Discovery snapshot report.
• Blocking app usage using block scripts.
• Adding custom apps to Cloud Discovery.
• Connecting custom apps with Conditional Access App Control.
• Onboarding and deploying Conditional Access App Control for any app.
• Integrating with third-party identity providers (IdPs) and data loss prevention (DLP)
providers.
• Training or guidance covering advanced hunting.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 10 of 26
• Automated investigation and remediation including Microsoft Power Automate
playbooks.
• Security information and event management (SIEM) or API integration (including
Azure Sentinel).
Microsoft 365 Defender
Microsoft 365 Defender is a unified pre- and post-breach enterprise defense suite that natively
coordinates detection, prevention, investigation, and response across endpoints, identities, email,
and apps to provide integrated protection against sophisticated attacks. We provide remote
guidance for:
• Providing an overview of the Microsoft 365 security center.
• Reviewing cross-product incidents, including focusing on what's critical by ensuring the
full attack scope, impacted assets, and automated remediation actions that are grouped
together.
• Demonstrating how Microsoft 365 Defender can orchestrate the investigation of assets,
users, devices, and mailboxes that might have been compromised through automated self-
healing.
• Explaining and providing examples of how customers can proactively hunt for intrusion
attempts and breach activity affecting your email, data, devices, and accounts across
multiple data sets.
• Showing customers how they can review and improve their security posture holistically
using Microsoft Secure Score.
The following is out of scope:
• Project management of the customer's remediation activities.
• Ongoing management, threat response, and remediation.
• Deployment guidance or education on:
o How to remediate or interpret the various alert types and monitored activities.
o How to investigate a user, computer, lateral movement path, or entity.
• Custom threat hunting.
• Supporting GCC-High or GCC-DoD (Office 365 US Government).
• Security information and event management (SIEM) or API integration (including Azure
Sentinel).
Microsoft Defender for Office 365
Microsoft Defender for Office 365 safeguards your organization against malicious threats posed by
email messages, links (URLs), and collaboration tools. Defender for Office 365 includes:
• Threat protection policies: Define threat-protection policies to set the appropriate level of
protection for your organization.
• Reports: View real-time reports to monitor Defender for Office 365 performance in your
organization.
• Threat investigation and response capabilities: Use leading-edge tools to investigate,
understand, simulate, and prevent threats.
• Automated investigation and response capabilities: Save time and effort investigating and
mitigating threats.
We provide remote guidance for:
• Reviewing Defender for Office 365 Recommended Configuration Analyzer
(ORCA).
• Setting up evaluation mode.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 11 of 26
• Enabling Safe Links (including Safe Documents), Safe Attachments, anti-phishing,
pre-set security, and quarantine policies.
• Understanding reporting and threat analytics.
• Reviewing automation, investigation, and response.
• Using Attack Simulator.
• Configuring user-reported message settings.
• Understanding incident correlation in the Microsoft 365 Defender portal.
The following is out of scope:
• Project management of the customer's remediation activities.
• Ongoing management, threat response, and remediation.
• Supporting GCC-High or GCC-DoD (Office 365 US Government).
• Discussions comparing Defender for Office 365 to other security offerings.
• Deploying Defender for Office 365 as a proof of concept.
• Advanced delivery and enhanced filtering.
• Training or guidance covering advanced hunting.
• Integration with Microsoft Power Automate playbooks.
• Security information and event management (SIEM) or API integration (including
Azure Sentinel).
Microsoft Defender for Endpoint
Microsoft Defender for Endpoint is a platform designed to help enterprise networks prevent,
detect, investigate, and respond to advanced threats.
We provide remote guidance for:
• Assessing the OS version and device management (including Microsoft Endpoint
Manager, Microsoft Endpoint Configuration Manager, Group Policy Objects
(GPOs), and third-party configurations) as well as the status of your Windows
Defender AV services or other endpoint security software.
• Onboarding Microsoft Defender for Endpoint P1 and P2 customers (including those
with Windows 365 Cloud PC).
• Providing recommended configuration guidance for Microsoft traffic to travel
through proxies and firewalls restricting network traffic for devices that are not able
to connect directly to the internet.
• Enabling the Microsoft Defender for Endpoint service by explaining how to deploy
a Microsoft Defender for Endpoint endpoint detection and response (EDR) agent
profile using one of the supported management methods.
• Deployment guidance, configuration assistance, and education on:
o Threat and vulnerability management.
o Attack surface reduction.*
o Next-generation protection.
o EDR.
o Automated investigation and remediation.
o Secure score for devices.
o Microsoft Defender SmartScreen configuration using Microsoft
Endpoint Manager.
o Device discovery.**
o Providing Windows 365 Cloud PC security baseline guidance
specifically for:
Attack surface reduction rules.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 12 of 26
Microsoft Defender.
Microsoft Defender Antivirus.
Microsoft Defender Antivirus exclusions.
Microsoft Defender SmartScreen
• Reviewing simulations and tutorials (like practice scenarios, fake malware, and
automated investigations).
• Overview of reporting and threat analytics features.
• Integrating Microsoft Defender for Office 365, Microsoft Defender for Identity, and
Microsoft Defender for Cloud Apps with Microsoft Defender for Endpoint.
• Conduct walkthroughs of the Microsoft 365 Defender portal.
• Onboarding and configuration of the following operating systems:
o Windows 10.
o Windows Server 2012 R2.***
o Windows Server 2016.***
o Windows Server 2019.***
o Windows Server 2019 Core Edition.***
o Windows Server Semi-Annual Channel (SAC) version 1803.***
o Supported macOS versions (see System requirements for more details).
o Mobile devices (Android and iOS).****
*Only attack surface reduction rules, controlled folder access, and network protection are
supported. All other attack surface reduction capabilities aren't in scope. See the following out of
scope section for more details.
**Only some aspects are device discovery are supported. See the following out of scope section
for more details.
***Windows Server 2012 R2 and 2016 support is limited to the onboarding and configuration of
the unified agent. All Windows versions must be managed by Configuration Manager or
Microsoft.
The following is out of scope:
• Onboarding and enablement guidance for preview features.
• Project management of the customer's remediation activities.
• Troubleshooting issues encountered during engagement (including devices that fail
to onboard).
• Management of break/fix issues.
• Supporting GCC-High or GCC-DoD (Office 365 US Government).
• Supporting Microsoft Defender for Business.
• On-site support.
• Ongoing management and threat response.
• Onboarding or configuration for the following Microsoft Defender for Endpoint
agents:
o Windows Server 2008.
o Linux.
o Mobile devices (Android and iOS).
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 13 of 26
o Virtual Desktop Infrastructure (VDI) (persistent or non-persistent).
• Server onboarding and configuration:
o Configuring a proxy server for offline communications.
o Configuring Configuration Manager deployment packages on down-
level Configuration Manager instances and versions.
o Onboarding servers to Defender for Cloud Apps.
o Servers not managed by Configuration Manager.
• macOS onboarding and configuration:
o JAMF-based deployment.
o Other mobile device management (MDM) product-based deployment.
o Manual deployment.
• Configuration of the following attack surface reduction capabilities:
o Hardware-based app and browser isolation (including Application
Guard).
o App control.
o Device control.
o Exploit protection.
o Network and endpoint firewalls.
• Configuration or management of account protection features like:
o Credential Guard.
o Local user group membership.
• Configuration or management of BitLocker. Note: For information on BitLocker
assistance with Windows 11, see Windows 11.
• Configuration or management of network device discovery.
• Configuration or management of the following device discovery capabilities:
o Onboarding of unmanaged devices not in scope for FastTrack (like
Linux).
o Configuring or remediating internet-of-things (IoT) devices including
vulnerability assessments of IoT devices through Defender for IoT.
o Integration with third-party tooling.
o Exclusions for device discovery.
o Preliminary networking assistance.
o Troubleshooting network issues.
• Mobile devices, including:
o Attack surface reduction rules.
o Extended detection and response.
o Automated investigation and remediation (including live response)
o Secure configuration assessment and Secure Score.
o Web content filtering.
• Attack simulations (including penetration testing).
• Enrollment or configuration of Microsoft Threat Experts.
• Configuration or training reviewing API or security information and event
management (SIEM) connections.
• Training or guidance covering advanced hunting.
• Training or guidance covering the use of or creation of Kusto queries.
• Training or guidance covering Microsoft Defender SmartScreen configuration using
Group Policy Objects (GPOs), Windows Security, or Microsoft Edge.
• Some Windows 365 features including:
o Troubleshooting project management of customer Windows 365
deployment.
o Configuration of Windows 365 Cloud PC.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 14 of 26
o Third-party app virtualization and deployment.
o Custom images.
o All other areas not listed as in-scope for Windows 365.
Microsoft Intune:
We provide remote guidance on getting ready to use Intune as the cloud-based mobile device
management (MDM) and mobile app management (MAM) provider for your apps and devices.
The exact steps depend on your source environment and are based on your mobile device and
mobile app management needs. Remote guidance can include:
• Licensing your end users.
• Configuring identities to be used by Intune by leveraging either your on-premises Active
Directory or cloud identities (Azure AD).
• Adding users to your Intune subscription, defining IT admin roles, and creating user and
device groups.
• Configuring your MDM authority, based on your management needs, including:
o Setting Intune as your MDM authority when Intune is your only MDM solution.
• Providing MDM guidance for:
o Configuring tests groups to be used to validate MDM management policies.
o Configuring MDM management policies and services like:
App deployment for each supported platform through web links or deep
links.
Conditional Access policies.
Deployment of email, wireless networks, and VPN profiles if you have an
existing certificate authority, wireless network, or VPN infrastructure in
your organization.
Connecting to the Intune Data Warehouse.
Integrating Intune with:
Team Viewer for remote assistance (a Team Viewer subscription
is required).
Mobile Threat Defense (MTD) partner solutions (an MTD
subscription is required).
A telecom expense management solution (a telecom expense
management solution subscription is required).
Enrolling devices of each supported platform to Intune.
• Providing app protection guidance on:
o Configuring app protection policies for each supported platform.
o Configuring Conditional Access policies for managed apps.
o Targeting the appropriate user groups with the previously mentioned MAM
policies.
o Using managed-apps usage reports.
• Providing migration guidance from legacy PC management to Intune MDM.
Certificate delivery
We provide remote guidance for:
• Simple Certificate Enrollment Protocol (SCEP) and the Network Device
Enrollment Service (NDES).
• Configuring Enterprise Certificate Authority-related items.
• Creating and issuing a SCEP certificate template.
• Installing and configuring NDES.
• Installing and configuring the Microsoft Intune Connector for SCEP.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 15 of 26
• Installing and configuring Azure AD Application Proxy and Azure AD
Application connectors.
• Creating and assigning a trusted certificate device configuration profile in
Microsoft Endpoint Manager.
• Creating and assigning a SCEP certificate device configuration profile on
Microsoft Endpoint Manager.
• Public-Key Cryptography Standards (PKCS) and PFX (PKCS#12) certificates.
• Configuring enterprise Certificate Authority-related items.
• Creating and issuing a PKCS certificate template.
• Installing and configuring a PFX certificate connector.
• Creating and assigning a trusted certificate device configuration profile in
Microsoft Endpoint Manager.
• Creating and assigning a PKCS certificate device configuration profile in
Microsoft Endpoint Manager.
The following is out of scope:
• Helping customers with their public key infrastructure (PKI) certificates or enterprise
Certificate Authority.
• Supporting advanced scenarios, including:
• Placing the NDES server in the customer's DMZ.
• Configuring or using a Web Application Proxy server to publish the NDES URL
externally to the corporate network. We recommend and provide guidance for using the
Azure AD Application Proxy to accomplish this.
• Using imported PKCS certificates.
• Configuring Intune certification deployment using a hardware security module (HSM).
Cloud-attach
We guide you through getting ready to cloud-attach existing Configuration Manager environments
with Intune. The exact steps depend on your source environment. Remote guidance can include:
• Licensing your end users.
• Configuring identities to be used by Intune by leveraging your on-premises Active
Directory and cloud identities.
• Adding users to your Intune subscription, defining IT admin roles, and creating user and
device groups.
• Providing guidance setting up hybrid Azure AD join.
• Providing guidance on setting up Azure AD for MDM auto-enrollment.
• Providing guidance on how to set up cloud management gateway when used as a solution
for co-management of remote internet-based device management.
• Configuring supported workloads that you want to switch to Intune.
• Installing the Configuration Manager client on Intune-enrolled devices.
Deploy Outlook mobile for iOS and Android securely
We provide guidance to help you deploy Outlook mobile for iOS and Android securely in your
organization to ensure your users have all the required apps installed.
The steps to securely deploy Outlook mobile for iOS and Android with Intune depends on your
source environment. Remote guidance can include:
• Downloading the Outlook for iOS and Android, Microsoft Authenticator, and Intune
Company Portal apps through the Apple App Store or Google Play Store.
• Providing guidance on setting up:
o The Outlook for iOS and Android, Microsoft Authenticator, and Intune Company
Portal apps deployment with Intune.
o App protection policies.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 16 of 26
o Conditional Access policies.
o App configuration policies.
Endpoint analytics
We can provide guidance to help you enable Endpoint analytics for your organization. The steps to
do so depend on your source environment. They can include:
• Confirming the licenses for your endpoints and users.
• Confirming your organizational environments meet the prerequisites for Endpoint
analytics features.
• Configuring endpoints with correct policies to enable Endpoint analytics features.
• Setting organizational baselines to track progress.
• Providing guidance on using Proactive remediation within Endpoint analytics, including:
• Using Microsoft-authored remediation scripts.
• Creating custom remediation scripts.
Power BI
We provide remote guidance for:
• Assigning Power BI licenses.
• Deploying the Power BI Desktop app.
Project Online
We provide remote guidance for:
• Verifying basic SharePoint functionality that Project Online relies on.
• Adding the Project Online service to your tenant (including adding subscriptions to
users).
• Setting up the Enterprise Resource Pool (ERP).
• Creating your first project.
Project Online Professional and Premium
We provide remote guidance for:
• Addressing deployment issues.
• Assigning end-user licenses using the Microsoft 365 admin center and Windows
PowerShell.
• Installing Project Online Desktop Client from the Office 365 portal using Click-to-Run.
• Configuring update settings using the Office 365 Deployment Tool.
• Setting up a single on-site distribution server for Project Online Desktop Client, including
assistance with the creation of a configuration.xml file for use with the Office 365
Deployment Tool.
• Connecting Project Online Desktop Client to Project Online Professional or Project Online
Premium.
Exchange Online
Provide remote guidance on:
• Setting up Exchange Online Protection (EOP) features for all mail-enabled domains
validated in Office 365.
• Pointing your mail exchange (MX) records to Office 365.
• Setting up the Microsoft Defender for Office 365 feature if it’s a part of your subscription
service. For more information, see the Microsoft Defender for Office 365 portion of this
table.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 17 of 26
• Setting up the data loss prevention (DLP) feature for all mail-enabled domains validated in
Office 365 as part of your subscription service.
• Setting up Office 365 Message Encryption (OME) for all mail-enabled domains validated
in Office 365 as part of your subscription service.
• Configuring firewall ports.
• Setting up DNS, including the required Autodiscover, sender policy framework (SPF),
DomainKeys Identified Mail (DKIM), Domain-based Message Authentication, Reporting
and Conformance (DMARC) and MX records (as needed).
• Setting up email flow between your source messaging environment and Exchange Online
(as needed).
• If client is eligible for data migration, undertaking mail migration from your source
messaging environment to Office 365.
• Configuring mailbox clients (Outlook for Windows, Outlook on the web, and Outlook for
iOS and Android).
SharePoint Online and OneDrive for Business
We provide remote guidance for:
• Planning site collections.
• Securing content and managing permissions.
• Configuring SharePoint Online features.
• Configuring SharePoint hybrid features, like hybrid search, hybrid sites, hybrid
taxonomy, content types, hybrid self-service site creation (SharePoint Server 2013
only), extended app launcher, hybrid OneDrive for Business, and extranet sites.
• Your migration approach.
• External user sharing.
• Conditional Access.
Additional guidance is provided for OneDrive for Business like:
• Redirecting or moving known folders to OneDrive.
• Deploying the OneDrive for Business sync client.
Data migration
For information on using the FastTrack benefit for data migration to Office 365, see Data
Migration.
Microsoft Teams
Provide remote guidance on:
• Confirming minimum requirements in Exchange Online, SharePoint Online, Office 365
Groups, and Azure AD to support Teams.
• Configuring firewall ports.
• Setting up DNS.
• Confirming Teams is enabled on your Office 365 tenant.
• Enabling or disabling user licenses.
• Network assessment for Teams:
o Port and endpoint checks.
o Connection quality checks.
o Bandwidth estimates.
o Configuring Teams app policy (Teams web app, Teams Desktop app, and Teams
for iOS and Android app).
• Microsoft Teams Rooms:
o Network preparation, including ports and firewall, proxy settings, optimization
recommendations, and reporting guidance.
o Creation and configuration of resource accounts needed for supported Teams
Rooms devices including license assignment and mailbox settings.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 18 of 26
o Managing Teams Rooms devices including Teams admin center configurations
and policies and Teams Rooms-managed services.
o Develop governance and compliance policies including hardware security and
account security (like multi-factor authentication (MFA) guidance and password
policies).
• Microsoft Teams Phone:
o Network preparation, including ports and firewall, proxy settings, optimization
recommendations, and reporting guidance.
o Developing governance and compliance policies including hardware security and
account security (like MFA guidance and password policies).
o Configuring Teams Phone features, including call queues, auto attendants, Calling
Plan E911, voicemail, and voice policies.
o Configuring Microsoft PowerBI with Call Quality Dashboard (CQD) templates.
o Public Switched Telephone Network (PSTN) Connectivity:
o Calling Plans guidance including number porting, Operator Connect (where
available), and Direct Routing (including Media Bypass and Local Media
Optimization).
o Migration from Skype for Business on-premises to Teams Phone.
The following is out of scope:
• A/V and conference rooms design and installation.
• Device procurement.
• Third-party integrations (like Cloud Video Interop (CVI)).
• Session Border Controller (SBC) trunking to carrier or legacy PBX.
• Troubleshooting existing deployments.
• End-user training.
• Hands-on keyboard support.
Employee Experience scenario featuring Microsoft Viva
Microsoft Viva is an employee experience platform that brings together communications,
knowledge, learning, resources, and insights. Powered by Microsoft 365 and experienced primarily
through Microsoft Teams, Microsoft Viva fosters a culture where people and teams are empowered
to be their best from anywhere. The Employee Experience scenario featuring Microsoft Viva
includes:
• Connection featuring Viva Connections and Viva Engage.
• Insight featuring Viva Insights.
• Growth featuring Viva Topics and Learning.
We provide remote guidance for:
• Confirming which modules and features within Microsoft Viva you want to support
your business objectives.
• Assessing your source environment and scenario requirements.
• How to run the Employee Experience Wizard, specifically what actions you need to
take to bring your source environment up to the minimum requirements for
successful scenario configuration and guide you through scenario configuration.
The following is out of scope:
• Customer project management.
• On-site support.
• Customer development support
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 19 of 26
Viva Connections
Viva Connections encourages meaningful connections while fostering a culture of inclusion and
aligning the entire organization around your vision, mission, and strategic priorities. We provide
remote guidance for:
• Creating a modern communication site for Viva Connections.
• Branding of the SharePoint home site.
• Configuring a news framework (for example, news posts, audience targeting, an d
Yammer integration).
• Configuring your SharePoint home site, global navigation, and app bar.
• Enabling the Viva Connections feed.
• Deploying the Viva Connections Teams app.
Viva Engage
Viva Engage delivers high-value experiences including community building, leadership
engagement, knowledge sharing, and self-expression. We provide remote guidance for:
• Configuring your Yammer networks.
• Customizing the look of your Yammer network.
• Enforcing Office 365 identity for Yammer users.
• Configuring native mode for Microsoft 365.
• Configuring security settings in Yammer.
• Configuring a Yammer usage policy.
• Managing Yammer admins.
• Working with Azure Active Directory (Azure AD) business-to-business (B2B) guests in
Yammer communities.
• Joining and creating a community in Yammer.
• Managing communities.
• Creating a dynamic group in Yammer.
• Managing live events in Yammer.
• Monitoring Yammer usage.
• Including a Yammer feed on a SharePoint page.
• Configuring Storyline.
• Rolling out the Viva Engage app for Microsoft Teams.
Viva Insights
Viva Insights helps individuals, managers, and business leaders gain personalized insights and
actionable recommendations.
We provide remote guidance for:
• Assigning licenses to end users.
• Assigning roles for admins.
• Enabling personal insights.
• Enabling teamwork habits and organization trends.
• Deploying the Viva Insights Teams app.
Viva Topics
Viva Topics empowers employees to find answers and experts and connect with others in their
department and beyond. We provide remote guidance for:
• Assigning licenses to end users.
• Assigning roles for knowledge managers and admins.
• Creating and configuring a topics center.
• Setting up and managing topics.
• Security trimming of SharePoint Online sites.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 20 of 26
• Deploying the Viva Topics Teams app.
Viva Learning
Viva Learning enables employees to discover, share, and track learning from various content
sources. It enables business leaders to drive a culture of learning through empowered time
management and coaching. We provide remote guidance for:
• Assigning licenses to end users.
• Assigning roles for knowledge admins.
• Configuring settings for the learning content sources.
• Configuring SharePoint as a learning content source.
• Deploying the Viva Learning Teams app.
Microsoft Edge
Provide remote guidance on:
• Deploying Microsoft Edge on Windows 10 with Microsoft Endpoint Manager (Microsoft
Endpoint Configuration Manager or Intune).
• Configuring Microsoft Edge (using group policies or Intune app configuration and app
policies).
• Inventorying the list of sites that may require use in Internet Explorer mode.
• Enabling Internet Explorer mode with the existing Enterprise Site List. Additionally, if you
have a web app or site that works with Internet Explorer or Google Chrome and you
experience compatibility issues, we provide guidance to resolve the issue at no additional
cost.
• Planning guidance for Edge adoption and configuration guidance for Microsoft Search
bookmarks.
The following is out of scope:
• Project management of the customer's Microsoft Edge deployment.
• On-site support.
Yammer Enterprise
• We provide remote deployment guidance for:
• Configuring your Yammer network.
• Customizing the look of your Yammer network.
• Enforcing Office 365 identity for Yammer users.
• Configuring Native Mode for Microsoft 365.
• Configuring security and compliance in Yammer.
• Configuring a Yammer usage policy.
• Managing Yammer admins.
• Working with Azure AD-business-to-business (B2B) guests in Yammer communities.
• Joining and creating a community in Yammer.
• Managing communities.
• Creating a dynamic group in Yammer.
• Configuring live events in Yammer.
• Monitoring Yammer usage.
• Including a Yammer feed in a SharePoint page.
• Installing the Yammer Communities app for Microsoft Teams.
Windows 11
We provide guidance for updating to Windows 11 Enterprise from Windows 7 Professional,
Windows 8.1 Professional, and Windows 10 Enterprise. Note: PCs must meet Windows 11
hardware requirements. We provide remote guidance for:
• Understanding your Windows 11 intention.
• Assessing your source environment and the requirements (ensure that Microsoft Endpoint
Configuration Manager is upgraded to the required level to support the Windows 11
deployment).
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 21 of 26
• Deploying Windows 11 Enterprise and Microsoft 365 Apps using Microsoft Endpoint
Configuration Manager or Microsoft 365.
• Recommending options for you to assess your Windows 11 apps.
• Microsoft 365 Apps compatibility assessment by leveraging the Office 365 readiness
dashboard in Configuration Manager or with the stand-alone Readiness Toolkit for Office
plus assistance deploying Microsoft 365 Apps.
• Creating a remediation checklist on what you need to do to bring your source environment
up to the minimum requirements for a successful deployment.
• Providing update guidance for your existing devices to Windows 11 Enterprise if they
meet the needed device hardware requirements.
• Providing update guidance to support your existing deployment motion. FastTrack
recommends and provides guidance for an in-place upgrade to Windows 11. Guidance is
also available for Windows clean image installation and Windows Autopilot deployment
scenarios.
• Deploying Microsoft 365 Apps using Configuration Manager as part of the Windows 11
deployment.
• Providing guidance to help your organization stay up to date with Windows 11 Enterprise
and Microsoft 365 Apps using your existing Configuration Manager environment or
Microsoft 365.
BitLocker
We provide remote guidance for:
• Assessing your Windows 11 environment and hardware for BitLocker configuration.
• Recommending best practices for configuring BitLocker policies from Microsoft Endpoint
Manager.
• Enabling compliance reporting of BitLocker from Microsoft Endpoint Manager and
Microsoft Endpoint Configuration Manager.
• Providing guidance on configuring BitLocker for Windows Autopilot scenarios.
• Providing guidance on BitLocker key recovery best practices.
Windows Hello for Business
We provide remote guidance for:
• Assessing your Windows 10/11 environment and hardware for Windows Hello for
Business configuration.
• Enabling Windows passwordless authentication using Windows Hello for Business cloud
trust.
• Planning guidance for Windows Hello for Business hybrid key or certificate trust.
The following is out of scope:
• Upgrading Configuration Manager to Current Branch.
• Creating custom images for Windows 11 deployment.
• Creating and supporting deployment scripts for Windows 11 deployment.
• Converting a Windows 11 system from BIOS to Unified Extensible Firmware
Interface (UEFI).
• Enabling Windows 11 security features.
• Configuring Windows Deployment Services (WDS) for Preboot Execution
Environment (PXE) booting.
• Using the Microsoft Deployment Toolkit (MDT) to capture and deploy Windows 11
images.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 22 of 26
• Using the User State Migration Tool (USMT).
Windows Autopatch
We provide remote guidance for:
• Helping you understand the features of the Windows Autopatch service, validating
environment prerequisites, and how the service relates to other Microsoft update tools.
• Assessing your readiness for Windows Autopatch onboarding using the Readiness
Assessment tool and addressing issues identified by the tool.
• Understanding the process to enroll into the Windows Autopatch service.
• Registering physical and virtual devices into the Windows Autopatch service.
• Validating device updates and understanding reports.
Windows 365 Enterprise
Remote deployment guidance is provided to Microsoft customers for onboarding to Windows 365
Enterprise. Windows 365 takes the operating system to the Microsoft Cloud, securely streaming
the full Windows experience—including all your apps, data, and settings—to your personal or
corporate devices. You can provision Cloud PCs (devices that are deployed on the Windows 365
service) instantly across the globe and manage them seamlessly alongside your physical PC estate
using Microsoft Endpoint Manager. This desktop-as-a-service (DaaS) solution combines the
benefits of desktop cloud hosting with the simplicity, security, and insights of Microsoft 365. We
provide remote guidance for the following:
• Assigning licenses to users.
• Creating and modifying on-premises network connections (OPNCs).
• Adding and deleting device images, including standard Azure Marketplace gallery images
and custom images. Some guidance may be provided around deploying language packs
using the Windows 365 language installer script.
• Creating, editing, and deleting provisioning policies.
• Assisting with dynamic query expressions for dynamic groups and filtering.
• Deploying Windows Update policies for Cloud PCs using Intune.
• Deploying apps (including Microsoft 365 Apps for enterprise and Microsoft Teams with
media optimizations) to Cloud PCs using Intune.
• Securing Cloud PCs, including Conditional Access, multi-factor authentication (MFA),
and managing Remote Desktop Protocol (RDP) device redirections.
• Managing Cloud PCs on Microsoft Endpoint Manager, including remote management,
reprovision, resizing, and End grace period.
• Optimizing end user experience.
• Finding additional support for Windows 365.
Note: See the Microsoft 365 Defender and Microsoft Defender for Endpoint sections
in Security and Compliance for details about Microsoft Defender for Endpoint and the
security baseline scope as it applies to Windows 365.
The following is out of scope:
• Project management of the customer’s Windows 365 deployment.
• On-site support.
• Creation of Azure subscription features including Azure Virtual Networks (VNets),
ExpressRoute, and Site-to-Site (S2S) VPN.
• Support for advanced networking topics.
• Customizing images for a Cloud PC on behalf of customers.
• Standalone use of Configuration Manager for managing Cloud PCs.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 23 of 26
• Deploying Windows updates for Cloud PCs using Configuration Manager.
• Migrating virtual desktop infrastructure (VDI) or Azure Virtual Desktop virtual
machines to Windows 365.
• Migrating Configuration Manager or Microsoft Deployment Toolkit (MDT) images
to Azure.
• Migrating user profiles to or from Windows PCs.
• Configuring network appliances on behalf of customers.
• Support for third party integrations.
Universal Print
We provide remote guidance for:
• Onboarding and configuring Universal Print.
• Universal Print connector.
• Universal Print-ready printers.
• Deploying printers with Microsoft Endpoint Manager.
• Printer and print job management.
• Configuring the Universal Print PowerShell module.
The following is out of scope:
• Partner integrations.
• Third-party app virtualization and deployment.
• Creating custom scripts with the Universal Print PowerShell module.
• Universal Print developer features (including API).
• Configuring Windows servers for printing.
App Assure
App Assure is a service designed to address issues with Windows and Microsoft 365 Apps app
compatibility and is available to all Microsoft customers. When you request the App Assure
service, we work with you to address valid app issues. To request App Assure assistance, complete
the App Assure service request.
We also provide guidance to customers who face compatibility issues when deploying Windows
365 Cloud PC, Windows Virtual Desktop, and Microsoft Edge and make every reasonable effort to
resolve compatibility issues. We provide remediation assistance for apps deployed on the
following Microsoft products:
• Windows 10/11 (including ARM64 devices).
• Microsoft 365 Apps.
• Microsoft Edge For deployment guidance, see Overview of the Microsoft Edge channels.
• Windows Virtual Desktop - For more information, see What is Windows Virtual
Desktop? and Windows 10 Enterprise multi-session FAQ.
• Windows 365 Cloud PC – For more information, see Introducing a new era of hybrid
personal computing: the Windows 365 Cloud PC.
Note: FastTrack’s eligibility criteria doesn't apply to App Assure services, subject to Microsoft’s
discretion.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 24 of 26
The following is out of scope:
• App inventory and testing to determine what does and doesn't work on Windows
and Microsoft 365 Apps. For more guidance on this process, see the Windows and
Office 365 deployment lab kit. If you're interested in guidance for modernizing
endpoints or deploying Windows 11, request assistance from FastTrack.
• Researching third-party ISV apps for Windows compatibility and support
statements.
• App packaging-only services. However, the App Assure team packages apps that we
have remediated for Windows to ensure they can be deployed in the customer's
environment.
• Although Android apps on Windows 11 are available to Windows Insiders, App
Assure doesn't currently support Android apps or devices, including Surface Duo
devices.
Customer responsibilities include:
• Creating an app inventory.
• Validating those apps on Windows and Microsoft 365 Apps.
• Validating your apps with Test Base for Microsoft 365.
Note: Microsoft can't make changes to your source code. However, the App Assure team can
provide guidance to app developers if the source code is available for your apps.
Contact a Microsoft Partner for assistance with these services.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 25 of 26
3. Out of Scope
Areas that are out of scope for this engagement include, but are not limited to the following:
• Modifications to the Office 365 Service.
• Managing end-user and organizational communications, documentation, training, and
change management processes.
• Help-desk documentation and training.
• Formal user training (such as workshops, classroom, and books) or development of custom
training courses or materials, except as explicitly defined as in-scope.
• Producing customer-specific reports, presentations, or meeting minutes.
• Pre-work required at the customer site.
• Architectural and technical documentation specific to the customer, except as explicitly
defined as in-scope.
• Design, procurement, installation, and configuration of hardware and networking.
• Procurement, installation, and configuration of software, except as explicitly defined as in-
scope.
• Configuration, packaging, and distribution of client software required for the Office 365
service.
• Management, configuration, and activation of mobile devices.
• Applying security policies on mobile devices.
• Implementing network configuration, analysis, bandwidth validation, testing, and
monitoring.
• Approval of technical change management process and producing supporting
documentation.
• Rationalization and definition of group policies for user, workstation, and server
management.
• Modification of a current operational model and operation guide.
• Co-branding of Office 365 user interfaces.
• Decommissioning and removal of on-premises environments (such as messaging and
collaboration).
• Construction and maintenance of the customer test environment.
• Installing service packs and any required updates on infrastructure servers.
4. Schedule
Quisitive will work with the Client to establish a mutually agreeable schedule for FastTrack
online meetings and conference calls.
5. Professional Service Fees
Quisitive will provide these services at no charge to Client.
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6
Statement of Work
Orange County NC
v20221005 March 8, 2023 p. 26 of 26
6. Terms and Conditions
This Statement of Work is subject to the terms and conditions of the NC Orange Quisitive Services
Contract in effect at the time of this contract.
Microsoft Online Services Partner Incentives Disclosure for Public Sector Entities - As a Microsoft
Gold Partner in Cloud Platform and Cloud Productivity, Quisitive participates in a variety of
Microsoft programs and initiatives which reward partners for enabling and enhancing the success of
our mutual customers. The Microsoft Partner Incentives Portfolio includes incentive programs
through which Microsoft may provide the Partner with fees, commissions, or other compensation in
connection with Microsoft products or services purchased or utilized by the customer. The
Microsoft Partner Incentive program participation terms require that the Partner provide this
information in writing when the customer is a US governmental or public sector entity. As such,
this disclosure is being provided to you in accordance with program terms.
7. Acceptance
Completion of this form acknowledges you have selected Quisitive as your FastTrack
partner.
Quisitive Orange County NC
SIGNATURE SIGNATURE
Syed Hasan PRINTED NAME
VP Management Services & Operations TITLE
DATE
DATE
DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6