Orange County NC Website
Statement of Work <br />Orange County NC <br />v20221005 March 8, 2023 p. 15 of 26 <br />• Installing and configuring Azure AD Application Proxy and Azure AD <br />Application connectors. <br />• Creating and assigning a trusted certificate device configuration profile in <br />Microsoft Endpoint Manager. <br />• Creating and assigning a SCEP certificate device configuration profile on <br />Microsoft Endpoint Manager. <br />• Public-Key Cryptography Standards (PKCS) and PFX (PKCS#12) certificates. <br />• Configuring enterprise Certificate Authority-related items. <br />• Creating and issuing a PKCS certificate template. <br />• Installing and configuring a PFX certificate connector. <br />• Creating and assigning a trusted certificate device configuration profile in <br />Microsoft Endpoint Manager. <br />• Creating and assigning a PKCS certificate device configuration profile in <br />Microsoft Endpoint Manager. <br /> <br />The following is out of scope: <br />• Helping customers with their public key infrastructure (PKI) certificates or enterprise <br />Certificate Authority. <br />• Supporting advanced scenarios, including: <br />• Placing the NDES server in the customer's DMZ. <br />• Configuring or using a Web Application Proxy server to publish the NDES URL <br />externally to the corporate network. We recommend and provide guidance for using the <br />Azure AD Application Proxy to accomplish this. <br />• Using imported PKCS certificates. <br />• Configuring Intune certification deployment using a hardware security module (HSM). <br />Cloud-attach <br />We guide you through getting ready to cloud-attach existing Configuration Manager environments <br />with Intune. The exact steps depend on your source environment. Remote guidance can include: <br />• Licensing your end users. <br />• Configuring identities to be used by Intune by leveraging your on-premises Active <br />Directory and cloud identities. <br />• Adding users to your Intune subscription, defining IT admin roles, and creating user and <br />device groups. <br />• Providing guidance setting up hybrid Azure AD join. <br />• Providing guidance on setting up Azure AD for MDM auto-enrollment. <br />• Providing guidance on how to set up cloud management gateway when used as a solution <br />for co-management of remote internet-based device management. <br />• Configuring supported workloads that you want to switch to Intune. <br />• Installing the Configuration Manager client on Intune-enrolled devices. <br />Deploy Outlook mobile for iOS and Android securely <br />We provide guidance to help you deploy Outlook mobile for iOS and Android securely in your <br />organization to ensure your users have all the required apps installed. <br />The steps to securely deploy Outlook mobile for iOS and Android with Intune depends on your <br />source environment. Remote guidance can include: <br />• Downloading the Outlook for iOS and Android, Microsoft Authenticator, and Intune <br />Company Portal apps through the Apple App Store or Google Play Store. <br />• Providing guidance on setting up: <br />o The Outlook for iOS and Android, Microsoft Authenticator, and Intune Company <br />Portal apps deployment with Intune. <br />o App protection policies. <br />DocuSign Envelope ID: 4F8CE7A2-004B-4516-AE7C-0C68141E2FF6