Loading...
HomeMy WebLinkAbout2023-135-E-IT Dept-Catapult Systems, LLC, a Quisitive Company-Fast Track SupportRevised 06/21 1 [Departmental Use Only] TITLE FastTrack FY 23 NORTH CAROLINA SERVICES AGREEMENT NO RFP/RFQ ORANGE COUNTY This Services Agreement (hereinafter “Agreement”), made and entered into this 22nd day of March, 2023, (“Effective Date”) by and between Orange County, North Carolina a political subdivision of the State of North Carolina (hereinafter, the "County") and Quisitive Company, (hereinafter, the "Provider"). WITNESSETH: That the County and Provider, for the consideration herein named, do hereby agree as follows: 1. Services a. Scope of Work. i) This Agreement is for services to be rendered by Provider to County with respect to (insert type of project): Microsoft M365 Fast Track Services (see Attachment A) ii) By executing this Agreement, the Provider represents and agrees that Provider is qualified to perform and fully capable of performing and providing the services required or necessary under this Agreement in a fully competent, professional and timely manner. iii) Time is of the essence with respect to this Agreement. iv) The services to be performed under this Agreement consist of Basic Services, as described and designated in Section 3 hereof. Compensation to the Provider for Basic Services under this Agreement shall be as set forth herein. 2. Responsibilities of the Provider a. Services to be provided. The Provider shall provide the County with all services required in Section 3 to satisfactorily complete the Project within the time limitations set forth herein and in accordance with the highest professional standards. b. Standard of Care. i) The Provider shall exercise reasonable care and diligence in performing services under this Agreement in accordance with the highest generally accepted standards of this type of Provider practice throughout the United States and in accordance with applicable federal, state and local laws and regulations applicable to the performance of these services. Provider is solely responsible for the professional DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Revised 06/21 2 quality, accuracy and timely completion and submission of all work related to the Basic Services. ii) Provider shall be responsible for all errors or omissions of its agents, contractors, employees, or assigns in the performance of the Agreement. Provider shall correct any and all errors, omissions, discrepancies, ambiguities, mistakes or conflicts at no additional cost to the County. iii) The Provider shall not, except as otherwise provided for in this Agreement, subcontract the performance of any work under this Agreement without prior written permission of the County. No permission for subcontracting shall create, between the County and the subcontractor, any contract or any other relationship. iv) Provider is an independent contractor of County. Any and all employees of the Provider engaged by the Provider in the performance of any work or services required of the Provider under this Agreement, shall be considered employees or agents of the Provider only and not of the County, and any and all claims that may or might arise under any workers compensation or other law or contract on behalf of said employees while so engaged shall be the sole obligation and responsibility of the Provider. v) If activities related to the performance of this Agreement require specific licenses, certifications, or related credentials Provider represents that it or its employees, agents and subcontractors engaged in such activities possess such licenses, certifications, or credentials and that such licenses certifications, or credentials are current, active, and not in a state of suspension or revocation. vi) In determining the Basic Services to be provided, should any documents be referenced in this Agreement, the terms of this Agreement shall have priority in any conflict between the terms of referenced documents and the terms of this Agreement. vii) Should this Agreement involve project designs, the construction or creation of which is to be bid out or fulfilled by other contractors, and bidding or negotiation with contractors produce prices which, when added to the other elements of the approved total project cost, produce a cost that is in excess of the approved total project cost, the Provider shall participate with the County in negotiation and design adjustments to the extent such are necessary to obtain prices within the approved total project cost. All activity of the Provider with respect to these matters shall constitute Basic Services and shall be performed by the Provider without additional compensation. If negotiation and design adjustments fail to bring costs within the total project cost the County may reject all bids and Provider will redesign or reduce portions of the project in an effort to reduce the bid prices to within the total project cost and rebid the project. One such redesign is included within Basic Services. If this second letting for bids does not produce bids that are within the approved total project cost initially or after negotiations with the contractor the cost is not reduced to an amount within the total project cost, the Provider is not obligated to engage in further redesign. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Revised 06/21 3 3. Basic Services a. Basic Services. The Services to be rendered pursuant to this Agreement are as follows (fully describe services to be provided): Microsoft M365 Consulting 4. Duration of Services a. Term. The term of this Agreement shall be from March 22, 2023 to March 22, 2024. b. Scheduling of Services. i) The Provider shall schedule and perform its activities in a timely manner. ii) Should the County determine that the Provider is behind schedule, it may require the Provider to expedite and accelerate its efforts, including providing additional resources and working overtime, as necessary, to perform its services in accordance with the approved project schedule at no additional cost to the County. iii) The Commencement Date for the Provider's Basic Services shall be March 22, 2023. 5. Compensation a. Compensation for Basic Services. Compensation for Basic Services shall include all compensation due the Provider from the County for all services satisfactorily (as determined by the County) performed pursuant to this Agreement. The maximum amount payable for Basic Services shall not exceed Zero Dollars ($0.00). Payment for satisfactorily performed Basic Services shall become due and payable within thirty (30) days of Provider properly invoicing County. Payment shall be subject to provisions of Section 5(b). b. Disputes. In the event the amount stated on an invoice is disputed by the County, the County may withhold payment of all or a portion of the amount stated on an invoice until the parties resolve the dispute. Should Provider fail to perform its duties under the terms of this Agreement, County may, without fault or penalty, withhold any payment associated with the work to be performed until such time as said work is completed. c. Additional Services. County shall not be responsible for costs related to any services in addition to the Basic Services performed by Provider unless County requests such additional services in writing and such additional services are evidenced by a written amendment to this Agreement. 6. Responsibilities of the County a. Cooperation and Coordination. The County has designated (Jim Northrup) to act as the County's representative with respect to the Project who shall have the authority to render decisions within guidelines established by the County Manager or the County Board of Commissioners and who shall be available during working hours as often as may be reasonably required to render decisions and to furnish information. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Revised 06/21 4 7. Insurance a. General Requirements. Provider shall obtain, at its sole expense, Commercial General Liability Insurance, Automobile Insurance, Workers’ Compensation Insurance, and any additional insurance as may be required by County’s Risk Manager as such insurance requirements are described in the Orange County Risk Transfer Policy and Orange County Minimum Insurance Coverage Requirements (each document is incorporated herein by reference and may be viewed at http://www.orangecountync.gov/departments/purchasing_division/contracts.php). If County’s Risk Manager determines additional insurance coverage is required such additional insurance shall consist of N/A (if no additional insurance required mark N/A as being not applicable). Provider shall not commence work until such insurance is in effect and certification thereof has been received by the County's Risk Manager. 8. Indemnity a. Indemnity. To the extent authorized by North Carolina law the Provider agrees, without limitation, to defend, indemnify and hold harmless the County from all loss, liability, claims or expense, including attorney's fees, arising out of or related to the Project and arising from property damage or bodily injury including death to any person or persons caused in whole or in part by the negligence or misconduct of the Provider except to the extent same are caused by the negligence or willful misconduct of the County. It is the intent of this provision to require the Provider to indemnify the County to the fullest extent permitted under North Carolina law. 9. Amendments to the Agreement a. Changes in Basic Services. Changes in the Basic Services and entitlement to additional compensation or a change in duration of this Agreement shall be made by a written Amendment to this Agreement executed by the County and the Provider. The Provider shall proceed to perform the Services required by the Amendment only after receiving a fully executed Amendment from the County. 10. Termination a. Termination for Convenience of the County. This Agreement may be terminated without cause by the County and for its convenience upon seven (7) days’ prior written notice to the Provider. b. Other Termination. The Provider may terminate this Agreement based upon the County's material breach of this Agreement; provided, the County has not taken all reasonable actions to remedy the breach. The Provider shall give the County seven (7) days' prior written notice of its intent to terminate this Agreement for cause. Either party may terminate this Agreement upon notice to the other party that obligations pursuant to this Agreement are made impractical due to declarations of emergency by Orange County or by North Carolina due to events directly impacting Orange County. Both parties shall remain responsible for all payment and performance due up to the receipt of such notice, but shall have no further obligation or responsibility beyond that date provided the DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Revised 06/21 5 terminating party has taken all reasonable steps to complete the performance of its obligations. c. Compensation After Termination. i) In the event of termination, the Provider shall be paid that portion of the fees and expenses that it has earned to the date of termination, less any costs or expenses incurred or anticipated to be incurred by the County due to errors or omissions of the Provider. Upon request of the County, the Provider shall submit to County all relevant documentation, including but not limited to, job cost records, to support its claims for final compensation. ii) Should this Agreement be terminated, the Provider shall deliver to the County within seven (7) days, at no additional cost, all deliverables including any electronic data or files relating to the Project. d. Waiver. The payment of any sums by the County under this Agreement or the failure of the County to require compliance by the Provider with any provisions of this Agreement or the waiver by the County of any breach of this Agreement shall not constitute a waiver of any claim for damages by the County for any breach of this Agreement or a waiver of any other required compliance with this Agreement. e. Suspension. County may suspend the Basic Services and this Agreement at any time for County’s convenience and without penalty to County upon three (3) days’ notice to Provider. Upon any suspension by County, Provider shall discontinue work on the Basic Services and shall not resume the Basic Services until notified to proceed by County. 11. Additional Provisions a. Limitation and Assignment. The County and the Provider each bind themselves, their successors, assigns and legal representatives to the terms of this Agreement. Neither the County nor the Provider shall assign or transfer its interest in this Agreement without the written consent of the other. b. Governing Law. This Agreement and the duties, responsibilities, obligations and rights of respective parties hereunder shall be governed by the laws of the State of North Carolina. By executing this Agreement Provider affirms that Provider and any subcontractors of Provider are and shall remain in compliance with Article 2 of Chapter 64 of the North Carolina General Statutes. By executing this Agreement Provider certifies that Provider has not been identified, and has not utilized the services of any agent or subcontractor identified, on the list created by the State Treasurer pursuant to G.S. 147-86.58. By executing this Agreement Provider certifies that Provider has not been identified, and has not utilized the services of any agent or subcontractor identified, on the list created by the State Treasurer pursuant to G.S. 147-86.81. c. Non-Discrimination. Provider shall at all times remain in compliance with all applicable local, state, and federal laws, rules, and regulations including but not limited to all state and federal non-discrimination laws, policies, rules, and regulations and the Orange County Non-Discrimination Policy and Orange County Living Wage Policy (each policy DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Revised 06/21 6 is incorporated herein by reference and may be viewed at http://www.orangecountync.gov/departments/purchasing_division/contracts.php.) Any violation of the Orange County Non-Discrimination Policy is a breach of this Agreement and County may immediately terminate this Agreement without further obligation on the part of the County. This paragraph is not intended to limit and does not limit the definition of breach to discrimination. d. Dispute Resolution. Any and all suits or actions to enforce, interpret or seek damages with respect to any provision of, or the performance or non-performance of, this Agreement shall be brought in the General Court of Justice of North Carolina sitting in Orange County, North Carolina. It is agreed by the parties that no other court shall have jurisdiction or venue with respect to such suits or actions. Binding arbitration may not be initiated by either Party, however, the Parties may agree to nonbinding mediation of any dispute prior to the bringing of such suit or action. e. Entire Agreement. This Agreement represents the entire and integrated agreement between the County and the Provider and supersedes all prior negotiations, representations or agreements, either written or oral. This Agreement may be amended only by written instrument signed by both parties. Modifications may be evidenced by facsimile signatures. f. Severability. If any provision of this Agreement is held as a matter of law to be unenforceable, the remainder of this Agreement shall be valid and binding upon the Parties. g. Ownership of Work Product. Should Provider’s performance of this Agreement generate documents, items or things that are specific to this Project such documents, items or things shall become the property of the County and may be used on any other project without additional compensation to the Provider. The use of the documents, items or things by the County or by any person or entity for any purpose other than the Project as set forth in this Agreement shall be at the full risk of the County. h. Non-Appropriation. Provider acknowledges that County is a governmental entity, and the validity of this Agreement is based upon the availability of public funding under the authority of its statutory mandate. In the event that public funds are unavailable or not appropriated for the performance of County’s obligations under this Agreement, then this Agreement shall automatically expire without penalty to County immediately upon written noti ce to Provider of the unavailability or non-appropriation of public funds. It is expressly agreed that County shall not activate this non-appropriation provision for its convenience or to circumvent the requirements of this Agreement. In the event of a change in the County’s statutory authority, mandate or mandated functions, by state or federal legislative or regulatory action, which adversely affects County’s authority to continue its obligations under this Agreement, then this Agreement shall automatically terminate without penalty to County upon written notice to Provider of such limitation or change in County’s legal authority. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Revised 06/21 7 i. Signatures. This Agreement together with any amendments or modifications may be executed electronically. All electronic signatures affixed hereto evidence the consent of the Parties to utilize electronic signatures and the intent of the Parties to comply with Article 11A and Article 40 of North Carolina General Statute Chapter 66. j. Notices. Any notice required by this Agreement shall be in writing and delivered by certified or registered mail, return receipt requested to the following: Orange County Provider’s Name Attention:Jim Northrup Quisitive, LLC P.O. Box 8181 1431 Greenway Drive, #1000 Hillsborough, NC 27278 Irving, Texas 75038 [SIGNATURE PAGE TO FOLLOW] DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Revised 06/21 8 IN WITNESS WHEREOF, the Parties, by and through their authorized agents, have hereunder set their hands and seal, all as of the day and year first above written. ORANGE COUNTY: PROVIDER: By: _________________________________ Jim Northrup, Chief Information Officer By: __________________________________ Syed Hasan, VP of Management Services & Operations Printed Name and Title DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 3/23/20233/28/2023 Revised 06/21 9 ORANGE COUNTY—DEPARTMENT USE ONLY ______________________________________________________________________________ Party/Vendor Name: Catapult Systems, LLC, a Quisitive Company Party/Vendor Contact Person: Syed Hasan Contact Phone: Party/Vendor Address: 5301 Southwest Parkway, Bldg 1, Suite 425 City Austin State: TX Zip: 78735 Department: Information Technologies Amount: $0.00 Purpose: Fast Track Support Budget Code(s): N/A Vendor # N/A (N/A if new vendor) Vendor is a BOCC consultant? Yes No Contract Type: (Check one) New Renewal Amendment Effective Date 3/22/2023 Approved by Board Yes No Agenda Date: --- For Section XIV. c. contracts only, Approved by Board in Current FY Budget Yes No This agreement is approved as to technical form and content and I as Department Director affirmatively state work on this project has not been initiated prior to execution of the agreement: Department Director’s Signature ________________________________________ Date: ________ Agreements for emergency services or repair are not subject to the above affirmation. If services related to this agreement have already begun or been completed please briefly describe the nature of the emergency condition that was addressed: N/A Information Technologies (Applicable only to hardware/software purchases or related services) This agreement has been reviewed and is approved as to information technology content and specifications: Office of the Chief Information Officer___________________________________ Date: ________ Risk Management This agreement is approved for sufficiency of insurance standards, specifications, and requirements: Office of the Risk Management Officer___________________________________ Date: _________ Financial Services This instrument has been pre-audited in the manner required by the Local Government Budget and Fiscal Control Act: Office of the Chief Financial Officer ____________________________________ Date: _________ Legal Services This agreement is approved as to legal form and sufficiency: Office of the County Attorney __________________________________________Date: ________ Clerk to the Board Received for record retention: All Docusign contracts must be copied to the Clerk upon completion: occlerkdocs@orangecountync.gov The following signature block is for hard copies only and is not required for Docusign contracts: Office of the Clerk to the Board __________________________________________Date:_________ DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 3/23/2023 3/23/2023 3/24/2023 3/24/2023 Statement of Work Orange County NC v20221005 March 8, 2023 p. 1 of 26 FastTrack Benefit Services 1. Objective This statement of work (hereinafter “SOW”) represents an agreement between Quisitive (hereinafter “Quisitive”) and Orange County NC (hereinafter “Client”). The purpose of this engagement is to deliver the Microsoft FastTrack Benefit for eligible products and plans as defined by the Microsoft FastTrack benefit guidance by workload. 2.Scope of Services FastTrack services provide a recommended approach, guidance, and best practices for technical onboarding (core onboarding, service onboarding, and data migration) and user adoption. User adoption services provide guidance and templates to ensure your users are aware of the eligible services and can use them to drive business value. All in scope FastTrack services are delivered remotely via scheduled online meetings between the Client and Quisitive FastTrack Specialists. Workload Designation Utilizing their FastTrack benefits, Orange County NC will be provided guidance as outlined by workload per the FastTrack process and expectations. Orange County NC selects Quisitive as their FastTrack partner for the following workloads designated by a ☒: Office 365 ☒Exchange Online ☒Microsoft Teams – Platform/Core enablement☒SharePoint Online & OneDrive ☒Microsoft Teams – Phone Systems☒Microsoft 365 Apps ☒Microsoft Teams – Meetings☒Yammer ☒PowerBI☒Project Online ☒Project Online Pro and Premium Discover and Respond ☒Purview eDiscovery ☒Purview Audit☒Compliance Manager ☒Purview Insider Risk Management Security and Compliance ☒Azure Active Directory Premium ☒Microsoft Purview Information Protection☒Microsoft Information Governance ☒Microsoft Intune☒Microsoft Defender for Identity (MDI)☒Microsoft Defender for Cloud Apps☒Microsoft Defender for Office 365 ☒Microsoft Defender for EndPoint☒Microsoft 365 Defender ☒Azure Information Protection☒Microsoft Purview Data Lifecycle Management Employee Experience ☒Employee Experience using Microsoft Viva ☒Microsoft Viva Connections☒Microsoft Viva Insights ☒Microsoft Viva Topics Attachment ADocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 2 of 26 ☒ Microsoft Viva Learning Windows ☒ Windows 10 ☒ Windows 365 Enterprise ☒ Windows 11 ☒ App Assure ☒ Universal Print ☒ Microsoft Edge Tenant’s sub-domain name, e.g. yourcompany.onmicrosoft.com Required: orangecountync.onmicrosoft.com Directory ID/Tenant ID (Found in Azure Active Directory under "Manage", "Properties") Required: b507459c-743d-4f3f-ae6e-d1526b7a62ad FastTrack benefits guidance (this APS updated 1/23/2023) Updated Monthly Online (https://docs.microsoft.com/en-us/fasttrack/products-and-capabilities) Migration FastTrack Migration Services, as described in the Data Migration section of the FastTrack Center Benefit for Microsoft 365 are provided directly by Microsoft for this Program and are not part of FastTrack Benefit Services to be provided by Program Partners. FastTrack Core Onboarding We provide remote guidance on core onboarding, which involves service provisioning, tenant, and identity integration. It also includes steps for providing a foundation for onboarding services like Exchange Online, SharePoint Online, and Microsoft Teams, including a discussion on security, network connectivity, and compliance. Onboarding for one or more eligible services can begin once core onboarding is finished. Identity Integration Provide remote guidance for: • Preparing on-premises Active Directory Identities for synchronization to Azure Active Directory (Azure AD) including installing and configuring Azure AD Connect (single- or multi-forest) and licensing (including group-based licensing). • Creating cloud identities including bulk import and licensing including using group-based licensing. • Choosing and enabling the correct authentication method for your cloud journey, Password Hash Sync, Pass-through Authentication, or Active Directory Federation Services (AD FS). • Choosing and enabling a more convenient authentication experience for your users with passwordless authentication using Fast Identity Online (FIDO)2, Microsoft Authenticator App, or Windows Hello for Business cloud trust. • Providing planning guidance for Windows Hello for Business hybrid key or certificate trust. • Enabling AD FS for customers with a single Active Directory forest and identities synchronized with the Azure AD Connect tool. This requires Windows Server 2012 R2 Active Directory Federation Services 2.0 or greater. • Migrating authentication from AD FS to Azure AD using Password Hash Sync or Pass- through Authentication. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 3 of 26 • Migrating pre-integrated apps (like Azure AD gallery software-as-a-service (SaaS) apps) from AD FS to Azure AD for single sign-on (SSO). • Enabling SaaS app integrations with SSO from the Azure AD gallery. • Enabling automatic user provisioning for pre-integrated SaaS apps as listed in the App integration tutorial list (limited to Azure AD gallery SaaS apps and outbound provisioning only). Microsoft 365 Apps Provide remote deployment guidance for: • Addressing deployment issues. • Assigning end-user and device-based licenses using the Microsoft 365 admin center and Windows PowerShell. • Installing Microsoft 365 Apps from the Office 365 portal using Click-to-Run. • Installing Office Mobile apps (like Outlook Mobile, Word Mobile, Excel Mobile, and PowerPoint Mobile) on your iOS or Android devices. • Configuring update settings using the Office 365 Deployment Tool. • Selection and setup of a local or cloud installation. • Creation of the Office Deployment Tool configuration XML with the Office Customization Tool or native XML to configure the deployment package. • Deployment using Microsoft Endpoint Configuration Manager, including assistance with the creation of Microsoft Endpoint Configuration Manager packaging. Additionally, if you have a macro or add-in that worked with prior versions of Office and you experience compatibility issues, we provide guidance to remediate the compatibility issue at no additional cost through the App Assure program. Network Health • We provide remote guidance with obtaining and interpreting key network connectivity data from your environment showing how aligned your organization’s sites are to Microsoft’s principles of network connectivity. This highlights your network score which directly impacts migration velocity, user experience, service performance, and reliability. We also guide you through any remediation steps highlighted by this data to help you improve your network score. FASTTRACK BENEFIT FOR SECURITY AND COMPLIANCE: Microsoft Azure Active Directory and Azure AD Premium Provide remote guidance on: • Configuring and enabling strong authentication for your identities, including protecting with Azure Multi-Factor Authentication (MFA) (cloud only), the Microsoft Authenticator app, and combined registration for Azure MFA and self-service password reset (SSPR). • For non-Azure AD Premium customers, guidance is provided to secure your identities using security defaults. • For Azure AD premium customers, guidance is provided to secure your identities with Conditional Access. • Detecting and blocking the use of weak passwords with Azure AD Password Protection. • Securing remote access to on-premises web apps with Azure AD Application Proxy. • Enabling risk-based detection and remediation with Azure Identity Protection. • Enabling a customized sign-in screen, including logo, text, and images with custom branding. • Securely sharing apps and services with guest users using Azure AD B2B. • Managing access for your Office 365 admins using role-based access control (RBAC) built-in administrative roles and to reduce the number of privileged admin accounts. • Configuring hybrid Azure AD join. • Configuring Azure AD join. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 4 of 26 • Enabling remote monitoring for AD FS, Azure AD Connect, and domain controllers with Azure AD Connect Health. • Managing your Azure AD identity and access lifecycle at scale with Azure AD entitlement management. • Managing Azure AD group memberships, enterprise app access, and role assignments with Azure AD access reviews. • Reviewing Azure AD Terms of Use. • Managing and controlling access to privileged admin accounts with Azure AD Privileged Identity Management. • Enabling Azure AD SSPR. • Allowing users to create and manage their own cloud security or Office 365 groups with Azure AD self-service group management. • Managing delegated access to enterprise apps with Azure AD delegated group management. • Enabling Azure AD dynamic groups. • Organizing apps in the My Apps portal using collections. Purview eDiscovery (Premium) We provide remote guidance for: • Creating a new case. • Putting custodians on hold. • Performing searches. • Adding search results to a review set. • Running analytics on a review set. • Reviewing and tagging documents. • Exporting data from the review set. • Importing non-Office 365 data. Purview Audit (only supported in E5) We provide remote guidance for: • Enabling advanced auditing. • Performing a search audit log UI and basic audit PowerShell commands. Purview Compliance Manager We provide remote guidance for: • Reviewing role types. • Adding and configuring assessments. • Assessing compliance by implementing improvement actions and determining how this impacts your compliance score. • Reviewing built-in control mapping and assessing controls. • Generating a report within an assessment. The following is out of scope: • Custom scripting or coding. • Purview eDiscovery API. • Data connectors. • Compliance boundaries and security filters. • Data investigations. • Data subject requests. • Design, architect, and third-party document review. • Compliance with industry and regional regulations and requirements. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 5 of 26 Hands-on implementation of recommended improvement actions for assessments in Purview Compliance Manager. Purview Insider Risk Management We provide remote guidance for: • Creating policies and reviewing settings. • Accessing reports and alerts. • Creating cases. • Creating notice templates. • Guidance on creating the human resources (HR) connector. Purview Communication Compliance We provide remote guidance for: • Creating policies and reviewing settings. • Accessing reports and alerts. • Creating notice templates. Purview Compliance Manager We provide remote guidance for: • Reviewing role types. • Adding and configuring assessments. • Assessing compliance by implementing improvement actions and determining how this impacts your compliance score. • Reviewing built-in control mapping and assessing controls. • Generating a report within an assessment. The following is out of scope: • Creating and managing Power Automate flows. • Data connectors (beyond the HR connector). • Custom regular expression (RegEx) configurations. • Design, architect, and third-party document review. • Information barriers. • Privileged access management. • Compliance with industry and regional regulations and requirements. • Hands-on implementation of recommended improvement actions for assessments in Purview Compliance Manager. Microsoft Purview Data Lifecycle We provide remote guidance for: • Creating and applying retention policies (supported in E3 and E5). • Creating and publishing retention labels (supported in E3 and E5). • Creating and applying event-based retention labels (supported in E5). • Creating and applying adaptive policy scopes (supported in E5). • Reviewing file plan creation (supported in E5). • Reviewing dispositions (supported in E5). • Policy lookups (supported in E5). Purview Compliance Manager Provide remote guidance on: • Reviewing role types. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 6 of 26 • Adding and configuring assessments. • Assessing compliance by implementing improvement actions and determining how this impacts your compliance score. • Reviewing built-in control mapping and assessing controls. • Generating a report within an assessment. The following is out of scope: • Development of a records management file plan. • Data connectors. • Development of information architecture in SharePoint. • Custom scripting and coding. • Design, architect, and third-party document review. • Compliance with industry and regional regulations and requirements. • Hands-on implementation of recommended improvement actions for assessments in Purview Compliance Manager. • Importing PST files to Office 365. Microsoft Purview Information Protection We provide remote guidance for: • Data classification (supported in E3 and E5). • Sensitive information types (supported in E3 and E5). • Creating sensitivity labels (supported in E3 and E5). • Applying sensitivity labels (supported in E3 and E5). • Trainable classifiers (supported in E5). • Exact Data Match (EDM) custom sensitive information types (supported in E5). • Knowing your data with content explorer and activity explorer (supported in E5). • Publishing labels using policies (manual and automatic) (supported in E5). • Creating Endpoint data loss prevention (DLP) policies for Windows 10 devices (supported in E5). • Creating DLP policies for Microsoft Teams chats and channels. Purview Compliance Manager We provide remote guidance for: • Reviewing role types. • Adding and configuring assessments. • Assessing compliance by implementing improvement actions and determining how this impacts your compliance score. • Reviewing built-in control mapping and assessing controls. • Generating a report within an assessment. Microsoft Purview Information Protection We provide remote guidance for: • Activating and configuring your tenant. • Creating and setting up labels and policies (supported in P1 and P2). • Applying information protection to documents (supported in P1 and P2). • Automatically classifying and labeling information in Office apps (like Word, PowerPoint, Excel, and Outlook) running on Windows and using the Microsoft Purview Information Protection client (supported in P2). DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 7 of 26 • Discovering and labeling files at rest using the Microsoft Purview Information Protection scanner (supported in P1 and P2). • Monitoring emails in transit using Exchange Online mail flow rules. • Migration guidance from Azure Information Protection add-in to built-in labeling for Office apps. • We also provide guidance if you want to apply protection using Microsoft Azure Rights Management Services (Azure RMS), Office 365 Message Encryption (OME), and data loss prevention (DLP). The following is out of scope: • Customer key. • Custom regular expressions (RegEx) development for sensitive information types. • Creation or modification of keyword dictionaries. • Interacting with customer data or specific guidelines for configuration of EDM- sensitive information types. • Custom scripting and coding. • Azure Purview. • Design, architect, and third-party document review. • Compliance with industry and regional regulations and requirements. • Hands-on implementation of recommended improvement actions for assessments in Purview Compliance Manager. Microsoft Defender for Identity Microsoft Defender for Identity is a cloud-based security solution that leverages your on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at your organization. We provide remote guidance for: • Running the sizing tool for resource capacity planning. • Creating your instance of Defender for Identity. • Connecting Defender for Identity to Active Directory. • Deploying the sensor to capture and parse network traffic and Windows events directly from your domain controllers, including: o Downloading the sensor package. o Configuring the sensor. o Installing the sensor on your domain controller silently. o Deploying the sensor to your multi-forest environment. o Configuring the Windows Event Collector. • Configuring the portal, including: o Integrating Defender for Identity with Microsoft Cloud App Security (Cloud App Security licensing isn't required). o Configuring entity tags. o Tagging sensitive accounts. o Receiving email notifications for health issues and security alerts. o Configuring alert exclusions. • Providing deployment guidance, configuration assistance, and education on: o Understanding the Identity Security Posture Assessment report. o Understanding the User Investigation Priority Score and User Investigation ranking report. o Understanding the inactive user report. o Explanation of the remediation options on a compromised account. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 8 of 26 • Facilitating the migration from Advanced Threat Analytics (ATA) to Defender for Identity. The following is out of scope: • Project management of the customer's remediation activities. • Ongoing management, threat response, and remediation. • Deploying Defender for Identity as a proof of concept. • Supporting GCC-High or GCC-DoD (Office 365 US Government). • Deploying or performing the following Defender for Identity sensor activities: o Manual capacity planning. o Running the Auditing tool. o Deploying the standalone sensor. o Deploying to Active Directory Federation Services (AD FS) servers. o Deploying the sensor using a Network Interface Card (NIC) Teaming adaptor. o Deploying the sensor through a third-party tool. o Connecting to the Defender for Identity cloud service through a web proxy connection. • Configuring the Microsoft account (MSA) in Active Directory. • Creation and management of honeytokens. • Enabling Network Name Resolution (NNR). • Configuration of Deleted Objects container. • Deployment guidance or education on: o Remediating or interpreting various alert types and monitored activities. o Investigating a user, computer, lateral movement path, or entity. o Threat or advanced hunting. o Incident response. • Providing a security alert lab tutorial for Defender for Identity. • Providing notification when Defender for Identity detects suspicious activities by sending security alerts to your syslog server through a nominated sensor. • Configuring Defender for Identity to perform queries using security account manager remote (SAMR) protocol to identify local admins on specific machines. • Configuring VPN solutions to add information from the VPN connection to a user’s profile page. • Security information and event management (SIEM) or API integration (including Azure Sentinel). Microsoft Defender for Cloud Apps Microsoft Defender for Cloud Apps is a Cloud Access Security Broker (CASB) that provides rich visibility, control over data travel, and sophisticated analytics to identify and combat cyber threats across all your Microsoft and third-party cloud services. We provide remote guidance for: • Configuring the portal, including: o Importing user groups. o Managing admin access and settings. o Scoping your deployment to select certain user groups to monitor or exclude from monitoring. o How to set up IP ranges and tags. o Personalizing the end-user experience with your logo and custom messaging. • Integrating first-party services including: o Microsoft Defender for Endpoint. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 9 of 26 o Microsoft Defender for Identity. o Azure AD Identity Protection. o Microsoft Information Protection. • Setting up cloud discovery using: o Microsoft Defender for Endpoints. o Zscaler. o iboss. • Creating app tags and categories. • Customizing app risk scores based on your organization’s priorities. • Sanctioning and unsanctioning apps. • Reviewing the Defender for Cloud Apps and Cloud Discovery dashboards. • Enabling the app governance add-on. o Guide the customer through the overview page and create up to five (5) app governance policies. • Connecting featured apps using app connectors. • Protecting apps with Conditional Access App Control in the Conditional Access within Azure AD and Defender for Cloud Apps portals. • Deploying Conditional Access App Control for featured apps. • Using the activity and file logs. • Managing OAuth apps. • Reviewing and configuring policy templates. • Providing configuration assistance with the top 20 use cases for CASBs (including the creation or updating of up to six (6) policies) except: o Auditing the configuration of your internet as a service (IaaS) environments (#18). o Monitoring user activities to protect against threats in your IaaS environments (#19). • Understanding incident correlation in the Microsoft 365 Defender portal. The following is out of scope: • Project management of the customer's remediation activities. • Ongoing management, threat response, and remediation. • Discussions comparing Defender for Cloud Apps to other CASB offerings. • Configuring Defender for Cloud Apps to meet specific compliance or regulatory requirements. • Deploying the service to a non-production test environment. • Deploying Cloud App Discovery as a proof of concept. • Supporting GCC-High or GCC-DoD (Office 365 US Government). • Setting up the infrastructure, installation, or deployment of automatic log uploads for continuous reports using Docker or a log collector. • Creating a Cloud Discovery snapshot report. • Blocking app usage using block scripts. • Adding custom apps to Cloud Discovery. • Connecting custom apps with Conditional Access App Control. • Onboarding and deploying Conditional Access App Control for any app. • Integrating with third-party identity providers (IdPs) and data loss prevention (DLP) providers. • Training or guidance covering advanced hunting. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 10 of 26 • Automated investigation and remediation including Microsoft Power Automate playbooks. • Security information and event management (SIEM) or API integration (including Azure Sentinel). Microsoft 365 Defender Microsoft 365 Defender is a unified pre- and post-breach enterprise defense suite that natively coordinates detection, prevention, investigation, and response across endpoints, identities, email, and apps to provide integrated protection against sophisticated attacks. We provide remote guidance for: • Providing an overview of the Microsoft 365 security center. • Reviewing cross-product incidents, including focusing on what's critical by ensuring the full attack scope, impacted assets, and automated remediation actions that are grouped together. • Demonstrating how Microsoft 365 Defender can orchestrate the investigation of assets, users, devices, and mailboxes that might have been compromised through automated self- healing. • Explaining and providing examples of how customers can proactively hunt for intrusion attempts and breach activity affecting your email, data, devices, and accounts across multiple data sets. • Showing customers how they can review and improve their security posture holistically using Microsoft Secure Score. The following is out of scope: • Project management of the customer's remediation activities. • Ongoing management, threat response, and remediation. • Deployment guidance or education on: o How to remediate or interpret the various alert types and monitored activities. o How to investigate a user, computer, lateral movement path, or entity. • Custom threat hunting. • Supporting GCC-High or GCC-DoD (Office 365 US Government). • Security information and event management (SIEM) or API integration (including Azure Sentinel). Microsoft Defender for Office 365 Microsoft Defender for Office 365 safeguards your organization against malicious threats posed by email messages, links (URLs), and collaboration tools. Defender for Office 365 includes: • Threat protection policies: Define threat-protection policies to set the appropriate level of protection for your organization. • Reports: View real-time reports to monitor Defender for Office 365 performance in your organization. • Threat investigation and response capabilities: Use leading-edge tools to investigate, understand, simulate, and prevent threats. • Automated investigation and response capabilities: Save time and effort investigating and mitigating threats. We provide remote guidance for: • Reviewing Defender for Office 365 Recommended Configuration Analyzer (ORCA). • Setting up evaluation mode. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 11 of 26 • Enabling Safe Links (including Safe Documents), Safe Attachments, anti-phishing, pre-set security, and quarantine policies. • Understanding reporting and threat analytics. • Reviewing automation, investigation, and response. • Using Attack Simulator. • Configuring user-reported message settings. • Understanding incident correlation in the Microsoft 365 Defender portal. The following is out of scope: • Project management of the customer's remediation activities. • Ongoing management, threat response, and remediation. • Supporting GCC-High or GCC-DoD (Office 365 US Government). • Discussions comparing Defender for Office 365 to other security offerings. • Deploying Defender for Office 365 as a proof of concept. • Advanced delivery and enhanced filtering. • Training or guidance covering advanced hunting. • Integration with Microsoft Power Automate playbooks. • Security information and event management (SIEM) or API integration (including Azure Sentinel). Microsoft Defender for Endpoint Microsoft Defender for Endpoint is a platform designed to help enterprise networks prevent, detect, investigate, and respond to advanced threats. We provide remote guidance for: • Assessing the OS version and device management (including Microsoft Endpoint Manager, Microsoft Endpoint Configuration Manager, Group Policy Objects (GPOs), and third-party configurations) as well as the status of your Windows Defender AV services or other endpoint security software. • Onboarding Microsoft Defender for Endpoint P1 and P2 customers (including those with Windows 365 Cloud PC). • Providing recommended configuration guidance for Microsoft traffic to travel through proxies and firewalls restricting network traffic for devices that are not able to connect directly to the internet. • Enabling the Microsoft Defender for Endpoint service by explaining how to deploy a Microsoft Defender for Endpoint endpoint detection and response (EDR) agent profile using one of the supported management methods. • Deployment guidance, configuration assistance, and education on: o Threat and vulnerability management. o Attack surface reduction.* o Next-generation protection. o EDR. o Automated investigation and remediation. o Secure score for devices. o Microsoft Defender SmartScreen configuration using Microsoft Endpoint Manager. o Device discovery.** o Providing Windows 365 Cloud PC security baseline guidance specifically for:  Attack surface reduction rules. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 12 of 26  Microsoft Defender.  Microsoft Defender Antivirus.  Microsoft Defender Antivirus exclusions.  Microsoft Defender SmartScreen • Reviewing simulations and tutorials (like practice scenarios, fake malware, and automated investigations). • Overview of reporting and threat analytics features. • Integrating Microsoft Defender for Office 365, Microsoft Defender for Identity, and Microsoft Defender for Cloud Apps with Microsoft Defender for Endpoint. • Conduct walkthroughs of the Microsoft 365 Defender portal. • Onboarding and configuration of the following operating systems: o Windows 10. o Windows Server 2012 R2.*** o Windows Server 2016.*** o Windows Server 2019.*** o Windows Server 2019 Core Edition.*** o Windows Server Semi-Annual Channel (SAC) version 1803.*** o Supported macOS versions (see System requirements for more details). o Mobile devices (Android and iOS).**** *Only attack surface reduction rules, controlled folder access, and network protection are supported. All other attack surface reduction capabilities aren't in scope. See the following out of scope section for more details. **Only some aspects are device discovery are supported. See the following out of scope section for more details. ***Windows Server 2012 R2 and 2016 support is limited to the onboarding and configuration of the unified agent. All Windows versions must be managed by Configuration Manager or Microsoft. The following is out of scope: • Onboarding and enablement guidance for preview features. • Project management of the customer's remediation activities. • Troubleshooting issues encountered during engagement (including devices that fail to onboard). • Management of break/fix issues. • Supporting GCC-High or GCC-DoD (Office 365 US Government). • Supporting Microsoft Defender for Business. • On-site support. • Ongoing management and threat response. • Onboarding or configuration for the following Microsoft Defender for Endpoint agents: o Windows Server 2008. o Linux. o Mobile devices (Android and iOS). DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 13 of 26 o Virtual Desktop Infrastructure (VDI) (persistent or non-persistent). • Server onboarding and configuration: o Configuring a proxy server for offline communications. o Configuring Configuration Manager deployment packages on down- level Configuration Manager instances and versions. o Onboarding servers to Defender for Cloud Apps. o Servers not managed by Configuration Manager. • macOS onboarding and configuration: o JAMF-based deployment. o Other mobile device management (MDM) product-based deployment. o Manual deployment. • Configuration of the following attack surface reduction capabilities: o Hardware-based app and browser isolation (including Application Guard). o App control. o Device control. o Exploit protection. o Network and endpoint firewalls. • Configuration or management of account protection features like: o Credential Guard. o Local user group membership. • Configuration or management of BitLocker. Note: For information on BitLocker assistance with Windows 11, see Windows 11. • Configuration or management of network device discovery. • Configuration or management of the following device discovery capabilities: o Onboarding of unmanaged devices not in scope for FastTrack (like Linux). o Configuring or remediating internet-of-things (IoT) devices including vulnerability assessments of IoT devices through Defender for IoT. o Integration with third-party tooling. o Exclusions for device discovery. o Preliminary networking assistance. o Troubleshooting network issues. • Mobile devices, including: o Attack surface reduction rules. o Extended detection and response. o Automated investigation and remediation (including live response) o Secure configuration assessment and Secure Score. o Web content filtering. • Attack simulations (including penetration testing). • Enrollment or configuration of Microsoft Threat Experts. • Configuration or training reviewing API or security information and event management (SIEM) connections. • Training or guidance covering advanced hunting. • Training or guidance covering the use of or creation of Kusto queries. • Training or guidance covering Microsoft Defender SmartScreen configuration using Group Policy Objects (GPOs), Windows Security, or Microsoft Edge. • Some Windows 365 features including: o Troubleshooting project management of customer Windows 365 deployment. o Configuration of Windows 365 Cloud PC. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 14 of 26 o Third-party app virtualization and deployment. o Custom images. o All other areas not listed as in-scope for Windows 365. Microsoft Intune: We provide remote guidance on getting ready to use Intune as the cloud-based mobile device management (MDM) and mobile app management (MAM) provider for your apps and devices. The exact steps depend on your source environment and are based on your mobile device and mobile app management needs. Remote guidance can include: • Licensing your end users. • Configuring identities to be used by Intune by leveraging either your on-premises Active Directory or cloud identities (Azure AD). • Adding users to your Intune subscription, defining IT admin roles, and creating user and device groups. • Configuring your MDM authority, based on your management needs, including: o Setting Intune as your MDM authority when Intune is your only MDM solution. • Providing MDM guidance for: o Configuring tests groups to be used to validate MDM management policies. o Configuring MDM management policies and services like:  App deployment for each supported platform through web links or deep links.  Conditional Access policies.  Deployment of email, wireless networks, and VPN profiles if you have an existing certificate authority, wireless network, or VPN infrastructure in your organization.  Connecting to the Intune Data Warehouse.  Integrating Intune with:  Team Viewer for remote assistance (a Team Viewer subscription is required).  Mobile Threat Defense (MTD) partner solutions (an MTD subscription is required).  A telecom expense management solution (a telecom expense management solution subscription is required).  Enrolling devices of each supported platform to Intune. • Providing app protection guidance on: o Configuring app protection policies for each supported platform. o Configuring Conditional Access policies for managed apps. o Targeting the appropriate user groups with the previously mentioned MAM policies. o Using managed-apps usage reports. • Providing migration guidance from legacy PC management to Intune MDM. Certificate delivery We provide remote guidance for: • Simple Certificate Enrollment Protocol (SCEP) and the Network Device Enrollment Service (NDES). • Configuring Enterprise Certificate Authority-related items. • Creating and issuing a SCEP certificate template. • Installing and configuring NDES. • Installing and configuring the Microsoft Intune Connector for SCEP. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 15 of 26 • Installing and configuring Azure AD Application Proxy and Azure AD Application connectors. • Creating and assigning a trusted certificate device configuration profile in Microsoft Endpoint Manager. • Creating and assigning a SCEP certificate device configuration profile on Microsoft Endpoint Manager. • Public-Key Cryptography Standards (PKCS) and PFX (PKCS#12) certificates. • Configuring enterprise Certificate Authority-related items. • Creating and issuing a PKCS certificate template. • Installing and configuring a PFX certificate connector. • Creating and assigning a trusted certificate device configuration profile in Microsoft Endpoint Manager. • Creating and assigning a PKCS certificate device configuration profile in Microsoft Endpoint Manager. The following is out of scope: • Helping customers with their public key infrastructure (PKI) certificates or enterprise Certificate Authority. • Supporting advanced scenarios, including: • Placing the NDES server in the customer's DMZ. • Configuring or using a Web Application Proxy server to publish the NDES URL externally to the corporate network. We recommend and provide guidance for using the Azure AD Application Proxy to accomplish this. • Using imported PKCS certificates. • Configuring Intune certification deployment using a hardware security module (HSM). Cloud-attach We guide you through getting ready to cloud-attach existing Configuration Manager environments with Intune. The exact steps depend on your source environment. Remote guidance can include: • Licensing your end users. • Configuring identities to be used by Intune by leveraging your on-premises Active Directory and cloud identities. • Adding users to your Intune subscription, defining IT admin roles, and creating user and device groups. • Providing guidance setting up hybrid Azure AD join. • Providing guidance on setting up Azure AD for MDM auto-enrollment. • Providing guidance on how to set up cloud management gateway when used as a solution for co-management of remote internet-based device management. • Configuring supported workloads that you want to switch to Intune. • Installing the Configuration Manager client on Intune-enrolled devices. Deploy Outlook mobile for iOS and Android securely We provide guidance to help you deploy Outlook mobile for iOS and Android securely in your organization to ensure your users have all the required apps installed. The steps to securely deploy Outlook mobile for iOS and Android with Intune depends on your source environment. Remote guidance can include: • Downloading the Outlook for iOS and Android, Microsoft Authenticator, and Intune Company Portal apps through the Apple App Store or Google Play Store. • Providing guidance on setting up: o The Outlook for iOS and Android, Microsoft Authenticator, and Intune Company Portal apps deployment with Intune. o App protection policies. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 16 of 26 o Conditional Access policies. o App configuration policies. Endpoint analytics We can provide guidance to help you enable Endpoint analytics for your organization. The steps to do so depend on your source environment. They can include: • Confirming the licenses for your endpoints and users. • Confirming your organizational environments meet the prerequisites for Endpoint analytics features. • Configuring endpoints with correct policies to enable Endpoint analytics features. • Setting organizational baselines to track progress. • Providing guidance on using Proactive remediation within Endpoint analytics, including: • Using Microsoft-authored remediation scripts. • Creating custom remediation scripts. Power BI We provide remote guidance for: • Assigning Power BI licenses. • Deploying the Power BI Desktop app. Project Online We provide remote guidance for: • Verifying basic SharePoint functionality that Project Online relies on. • Adding the Project Online service to your tenant (including adding subscriptions to users). • Setting up the Enterprise Resource Pool (ERP). • Creating your first project. Project Online Professional and Premium We provide remote guidance for: • Addressing deployment issues. • Assigning end-user licenses using the Microsoft 365 admin center and Windows PowerShell. • Installing Project Online Desktop Client from the Office 365 portal using Click-to-Run. • Configuring update settings using the Office 365 Deployment Tool. • Setting up a single on-site distribution server for Project Online Desktop Client, including assistance with the creation of a configuration.xml file for use with the Office 365 Deployment Tool. • Connecting Project Online Desktop Client to Project Online Professional or Project Online Premium. Exchange Online Provide remote guidance on: • Setting up Exchange Online Protection (EOP) features for all mail-enabled domains validated in Office 365. • Pointing your mail exchange (MX) records to Office 365. • Setting up the Microsoft Defender for Office 365 feature if it’s a part of your subscription service. For more information, see the Microsoft Defender for Office 365 portion of this table. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 17 of 26 • Setting up the data loss prevention (DLP) feature for all mail-enabled domains validated in Office 365 as part of your subscription service. • Setting up Office 365 Message Encryption (OME) for all mail-enabled domains validated in Office 365 as part of your subscription service. • Configuring firewall ports. • Setting up DNS, including the required Autodiscover, sender policy framework (SPF), DomainKeys Identified Mail (DKIM), Domain-based Message Authentication, Reporting and Conformance (DMARC) and MX records (as needed). • Setting up email flow between your source messaging environment and Exchange Online (as needed). • If client is eligible for data migration, undertaking mail migration from your source messaging environment to Office 365. • Configuring mailbox clients (Outlook for Windows, Outlook on the web, and Outlook for iOS and Android). SharePoint Online and OneDrive for Business We provide remote guidance for: • Planning site collections. • Securing content and managing permissions. • Configuring SharePoint Online features. • Configuring SharePoint hybrid features, like hybrid search, hybrid sites, hybrid taxonomy, content types, hybrid self-service site creation (SharePoint Server 2013 only), extended app launcher, hybrid OneDrive for Business, and extranet sites. • Your migration approach. • External user sharing. • Conditional Access. Additional guidance is provided for OneDrive for Business like: • Redirecting or moving known folders to OneDrive. • Deploying the OneDrive for Business sync client. Data migration For information on using the FastTrack benefit for data migration to Office 365, see Data Migration. Microsoft Teams Provide remote guidance on: • Confirming minimum requirements in Exchange Online, SharePoint Online, Office 365 Groups, and Azure AD to support Teams. • Configuring firewall ports. • Setting up DNS. • Confirming Teams is enabled on your Office 365 tenant. • Enabling or disabling user licenses. • Network assessment for Teams: o Port and endpoint checks. o Connection quality checks. o Bandwidth estimates. o Configuring Teams app policy (Teams web app, Teams Desktop app, and Teams for iOS and Android app). • Microsoft Teams Rooms: o Network preparation, including ports and firewall, proxy settings, optimization recommendations, and reporting guidance. o Creation and configuration of resource accounts needed for supported Teams Rooms devices including license assignment and mailbox settings. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 18 of 26 o Managing Teams Rooms devices including Teams admin center configurations and policies and Teams Rooms-managed services. o Develop governance and compliance policies including hardware security and account security (like multi-factor authentication (MFA) guidance and password policies). • Microsoft Teams Phone: o Network preparation, including ports and firewall, proxy settings, optimization recommendations, and reporting guidance. o Developing governance and compliance policies including hardware security and account security (like MFA guidance and password policies). o Configuring Teams Phone features, including call queues, auto attendants, Calling Plan E911, voicemail, and voice policies. o Configuring Microsoft PowerBI with Call Quality Dashboard (CQD) templates. o Public Switched Telephone Network (PSTN) Connectivity: o Calling Plans guidance including number porting, Operator Connect (where available), and Direct Routing (including Media Bypass and Local Media Optimization). o Migration from Skype for Business on-premises to Teams Phone. The following is out of scope: • A/V and conference rooms design and installation. • Device procurement. • Third-party integrations (like Cloud Video Interop (CVI)). • Session Border Controller (SBC) trunking to carrier or legacy PBX. • Troubleshooting existing deployments. • End-user training. • Hands-on keyboard support. Employee Experience scenario featuring Microsoft Viva Microsoft Viva is an employee experience platform that brings together communications, knowledge, learning, resources, and insights. Powered by Microsoft 365 and experienced primarily through Microsoft Teams, Microsoft Viva fosters a culture where people and teams are empowered to be their best from anywhere. The Employee Experience scenario featuring Microsoft Viva includes: • Connection featuring Viva Connections and Viva Engage. • Insight featuring Viva Insights. • Growth featuring Viva Topics and Learning. We provide remote guidance for: • Confirming which modules and features within Microsoft Viva you want to support your business objectives. • Assessing your source environment and scenario requirements. • How to run the Employee Experience Wizard, specifically what actions you need to take to bring your source environment up to the minimum requirements for successful scenario configuration and guide you through scenario configuration. The following is out of scope: • Customer project management. • On-site support. • Customer development support DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 19 of 26 Viva Connections Viva Connections encourages meaningful connections while fostering a culture of inclusion and aligning the entire organization around your vision, mission, and strategic priorities. We provide remote guidance for: • Creating a modern communication site for Viva Connections. • Branding of the SharePoint home site. • Configuring a news framework (for example, news posts, audience targeting, an d Yammer integration). • Configuring your SharePoint home site, global navigation, and app bar. • Enabling the Viva Connections feed. • Deploying the Viva Connections Teams app. Viva Engage Viva Engage delivers high-value experiences including community building, leadership engagement, knowledge sharing, and self-expression. We provide remote guidance for: • Configuring your Yammer networks. • Customizing the look of your Yammer network. • Enforcing Office 365 identity for Yammer users. • Configuring native mode for Microsoft 365. • Configuring security settings in Yammer. • Configuring a Yammer usage policy. • Managing Yammer admins. • Working with Azure Active Directory (Azure AD) business-to-business (B2B) guests in Yammer communities. • Joining and creating a community in Yammer. • Managing communities. • Creating a dynamic group in Yammer. • Managing live events in Yammer. • Monitoring Yammer usage. • Including a Yammer feed on a SharePoint page. • Configuring Storyline. • Rolling out the Viva Engage app for Microsoft Teams. Viva Insights Viva Insights helps individuals, managers, and business leaders gain personalized insights and actionable recommendations. We provide remote guidance for: • Assigning licenses to end users. • Assigning roles for admins. • Enabling personal insights. • Enabling teamwork habits and organization trends. • Deploying the Viva Insights Teams app. Viva Topics Viva Topics empowers employees to find answers and experts and connect with others in their department and beyond. We provide remote guidance for: • Assigning licenses to end users. • Assigning roles for knowledge managers and admins. • Creating and configuring a topics center. • Setting up and managing topics. • Security trimming of SharePoint Online sites. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 20 of 26 • Deploying the Viva Topics Teams app. Viva Learning Viva Learning enables employees to discover, share, and track learning from various content sources. It enables business leaders to drive a culture of learning through empowered time management and coaching. We provide remote guidance for: • Assigning licenses to end users. • Assigning roles for knowledge admins. • Configuring settings for the learning content sources. • Configuring SharePoint as a learning content source. • Deploying the Viva Learning Teams app. Microsoft Edge Provide remote guidance on: • Deploying Microsoft Edge on Windows 10 with Microsoft Endpoint Manager (Microsoft Endpoint Configuration Manager or Intune). • Configuring Microsoft Edge (using group policies or Intune app configuration and app policies). • Inventorying the list of sites that may require use in Internet Explorer mode. • Enabling Internet Explorer mode with the existing Enterprise Site List. Additionally, if you have a web app or site that works with Internet Explorer or Google Chrome and you experience compatibility issues, we provide guidance to resolve the issue at no additional cost. • Planning guidance for Edge adoption and configuration guidance for Microsoft Search bookmarks. The following is out of scope: • Project management of the customer's Microsoft Edge deployment. • On-site support. Yammer Enterprise • We provide remote deployment guidance for: • Configuring your Yammer network. • Customizing the look of your Yammer network. • Enforcing Office 365 identity for Yammer users. • Configuring Native Mode for Microsoft 365. • Configuring security and compliance in Yammer. • Configuring a Yammer usage policy. • Managing Yammer admins. • Working with Azure AD-business-to-business (B2B) guests in Yammer communities. • Joining and creating a community in Yammer. • Managing communities. • Creating a dynamic group in Yammer. • Configuring live events in Yammer. • Monitoring Yammer usage. • Including a Yammer feed in a SharePoint page. • Installing the Yammer Communities app for Microsoft Teams. Windows 11 We provide guidance for updating to Windows 11 Enterprise from Windows 7 Professional, Windows 8.1 Professional, and Windows 10 Enterprise. Note: PCs must meet Windows 11 hardware requirements. We provide remote guidance for: • Understanding your Windows 11 intention. • Assessing your source environment and the requirements (ensure that Microsoft Endpoint Configuration Manager is upgraded to the required level to support the Windows 11 deployment). DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 21 of 26 • Deploying Windows 11 Enterprise and Microsoft 365 Apps using Microsoft Endpoint Configuration Manager or Microsoft 365. • Recommending options for you to assess your Windows 11 apps. • Microsoft 365 Apps compatibility assessment by leveraging the Office 365 readiness dashboard in Configuration Manager or with the stand-alone Readiness Toolkit for Office plus assistance deploying Microsoft 365 Apps. • Creating a remediation checklist on what you need to do to bring your source environment up to the minimum requirements for a successful deployment. • Providing update guidance for your existing devices to Windows 11 Enterprise if they meet the needed device hardware requirements. • Providing update guidance to support your existing deployment motion. FastTrack recommends and provides guidance for an in-place upgrade to Windows 11. Guidance is also available for Windows clean image installation and Windows Autopilot deployment scenarios. • Deploying Microsoft 365 Apps using Configuration Manager as part of the Windows 11 deployment. • Providing guidance to help your organization stay up to date with Windows 11 Enterprise and Microsoft 365 Apps using your existing Configuration Manager environment or Microsoft 365. BitLocker We provide remote guidance for: • Assessing your Windows 11 environment and hardware for BitLocker configuration. • Recommending best practices for configuring BitLocker policies from Microsoft Endpoint Manager. • Enabling compliance reporting of BitLocker from Microsoft Endpoint Manager and Microsoft Endpoint Configuration Manager. • Providing guidance on configuring BitLocker for Windows Autopilot scenarios. • Providing guidance on BitLocker key recovery best practices. Windows Hello for Business We provide remote guidance for: • Assessing your Windows 10/11 environment and hardware for Windows Hello for Business configuration. • Enabling Windows passwordless authentication using Windows Hello for Business cloud trust. • Planning guidance for Windows Hello for Business hybrid key or certificate trust. The following is out of scope: • Upgrading Configuration Manager to Current Branch. • Creating custom images for Windows 11 deployment. • Creating and supporting deployment scripts for Windows 11 deployment. • Converting a Windows 11 system from BIOS to Unified Extensible Firmware Interface (UEFI). • Enabling Windows 11 security features. • Configuring Windows Deployment Services (WDS) for Preboot Execution Environment (PXE) booting. • Using the Microsoft Deployment Toolkit (MDT) to capture and deploy Windows 11 images. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 22 of 26 • Using the User State Migration Tool (USMT). Windows Autopatch We provide remote guidance for: • Helping you understand the features of the Windows Autopatch service, validating environment prerequisites, and how the service relates to other Microsoft update tools. • Assessing your readiness for Windows Autopatch onboarding using the Readiness Assessment tool and addressing issues identified by the tool. • Understanding the process to enroll into the Windows Autopatch service. • Registering physical and virtual devices into the Windows Autopatch service. • Validating device updates and understanding reports. Windows 365 Enterprise Remote deployment guidance is provided to Microsoft customers for onboarding to Windows 365 Enterprise. Windows 365 takes the operating system to the Microsoft Cloud, securely streaming the full Windows experience—including all your apps, data, and settings—to your personal or corporate devices. You can provision Cloud PCs (devices that are deployed on the Windows 365 service) instantly across the globe and manage them seamlessly alongside your physical PC estate using Microsoft Endpoint Manager. This desktop-as-a-service (DaaS) solution combines the benefits of desktop cloud hosting with the simplicity, security, and insights of Microsoft 365. We provide remote guidance for the following: • Assigning licenses to users. • Creating and modifying on-premises network connections (OPNCs). • Adding and deleting device images, including standard Azure Marketplace gallery images and custom images. Some guidance may be provided around deploying language packs using the Windows 365 language installer script. • Creating, editing, and deleting provisioning policies. • Assisting with dynamic query expressions for dynamic groups and filtering. • Deploying Windows Update policies for Cloud PCs using Intune. • Deploying apps (including Microsoft 365 Apps for enterprise and Microsoft Teams with media optimizations) to Cloud PCs using Intune. • Securing Cloud PCs, including Conditional Access, multi-factor authentication (MFA), and managing Remote Desktop Protocol (RDP) device redirections. • Managing Cloud PCs on Microsoft Endpoint Manager, including remote management, reprovision, resizing, and End grace period. • Optimizing end user experience. • Finding additional support for Windows 365. Note: See the Microsoft 365 Defender and Microsoft Defender for Endpoint sections in Security and Compliance for details about Microsoft Defender for Endpoint and the security baseline scope as it applies to Windows 365. The following is out of scope: • Project management of the customer’s Windows 365 deployment. • On-site support. • Creation of Azure subscription features including Azure Virtual Networks (VNets), ExpressRoute, and Site-to-Site (S2S) VPN. • Support for advanced networking topics. • Customizing images for a Cloud PC on behalf of customers. • Standalone use of Configuration Manager for managing Cloud PCs. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 23 of 26 • Deploying Windows updates for Cloud PCs using Configuration Manager. • Migrating virtual desktop infrastructure (VDI) or Azure Virtual Desktop virtual machines to Windows 365. • Migrating Configuration Manager or Microsoft Deployment Toolkit (MDT) images to Azure. • Migrating user profiles to or from Windows PCs. • Configuring network appliances on behalf of customers. • Support for third party integrations. Universal Print We provide remote guidance for: • Onboarding and configuring Universal Print. • Universal Print connector. • Universal Print-ready printers. • Deploying printers with Microsoft Endpoint Manager. • Printer and print job management.  • Configuring the Universal Print PowerShell module. The following is out of scope: • Partner integrations. • Third-party app virtualization and deployment. • Creating custom scripts with the Universal Print PowerShell module. • Universal Print developer features (including API). • Configuring Windows servers for printing. App Assure App Assure is a service designed to address issues with Windows and Microsoft 365 Apps app compatibility and is available to all Microsoft customers. When you request the App Assure service, we work with you to address valid app issues. To request App Assure assistance, complete the App Assure service request. We also provide guidance to customers who face compatibility issues when deploying Windows 365 Cloud PC, Windows Virtual Desktop, and Microsoft Edge and make every reasonable effort to resolve compatibility issues. We provide remediation assistance for apps deployed on the following Microsoft products: • Windows 10/11 (including ARM64 devices). • Microsoft 365 Apps. • Microsoft Edge For deployment guidance, see Overview of the Microsoft Edge channels. • Windows Virtual Desktop - For more information, see What is Windows Virtual Desktop? and Windows 10 Enterprise multi-session FAQ. • Windows 365 Cloud PC – For more information, see Introducing a new era of hybrid personal computing: the Windows 365 Cloud PC. Note: FastTrack’s eligibility criteria doesn't apply to App Assure services, subject to Microsoft’s discretion. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 24 of 26 The following is out of scope: • App inventory and testing to determine what does and doesn't work on Windows and Microsoft 365 Apps. For more guidance on this process, see the Windows and Office 365 deployment lab kit. If you're interested in guidance for modernizing endpoints or deploying Windows 11, request assistance from FastTrack. • Researching third-party ISV apps for Windows compatibility and support statements. • App packaging-only services. However, the App Assure team packages apps that we have remediated for Windows to ensure they can be deployed in the customer's environment. • Although Android apps on Windows 11 are available to Windows Insiders, App Assure doesn't currently support Android apps or devices, including Surface Duo devices. Customer responsibilities include: • Creating an app inventory. • Validating those apps on Windows and Microsoft 365 Apps. • Validating your apps with Test Base for Microsoft 365. Note: Microsoft can't make changes to your source code. However, the App Assure team can provide guidance to app developers if the source code is available for your apps. Contact a Microsoft Partner for assistance with these services. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 25 of 26 3. Out of Scope Areas that are out of scope for this engagement include, but are not limited to the following: • Modifications to the Office 365 Service. • Managing end-user and organizational communications, documentation, training, and change management processes. • Help-desk documentation and training. • Formal user training (such as workshops, classroom, and books) or development of custom training courses or materials, except as explicitly defined as in-scope. • Producing customer-specific reports, presentations, or meeting minutes. • Pre-work required at the customer site. • Architectural and technical documentation specific to the customer, except as explicitly defined as in-scope. • Design, procurement, installation, and configuration of hardware and networking. • Procurement, installation, and configuration of software, except as explicitly defined as in- scope. • Configuration, packaging, and distribution of client software required for the Office 365 service. • Management, configuration, and activation of mobile devices. • Applying security policies on mobile devices. • Implementing network configuration, analysis, bandwidth validation, testing, and monitoring. • Approval of technical change management process and producing supporting documentation. • Rationalization and definition of group policies for user, workstation, and server management. • Modification of a current operational model and operation guide. • Co-branding of Office 365 user interfaces. • Decommissioning and removal of on-premises environments (such as messaging and collaboration). • Construction and maintenance of the customer test environment. • Installing service packs and any required updates on infrastructure servers. 4. Schedule Quisitive will work with the Client to establish a mutually agreeable schedule for FastTrack online meetings and conference calls. 5. Professional Service Fees Quisitive will provide these services at no charge to Client. DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6 Statement of Work Orange County NC v20221005 March 8, 2023 p. 26 of 26 6. Terms and Conditions This Statement of Work is subject to the terms and conditions of the NC Orange Quisitive Services Contract in effect at the time of this contract. Microsoft Online Services Partner Incentives Disclosure for Public Sector Entities - As a Microsoft Gold Partner in Cloud Platform and Cloud Productivity, Quisitive participates in a variety of Microsoft programs and initiatives which reward partners for enabling and enhancing the success of our mutual customers. The Microsoft Partner Incentives Portfolio includes incentive programs through which Microsoft may provide the Partner with fees, commissions, or other compensation in connection with Microsoft products or services purchased or utilized by the customer. The Microsoft Partner Incentive program participation terms require that the Partner provide this information in writing when the customer is a US governmental or public sector entity. As such, this disclosure is being provided to you in accordance with program terms. 7. Acceptance Completion of this form acknowledges you have selected Quisitive as your FastTrack partner. Quisitive Orange County NC SIGNATURE SIGNATURE Syed Hasan  PRINTED NAME VP Management Services & Operations TITLE DATE DATE DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6