B08_-_RFQ_140M0124Q0011_Attachment_A.pdf
PDF 519 KB Posted
- Attached to
- BOEM GSIS-C IDIQ Federal contract opportunity
- Solicitation number
- 140M0124Q0011
About this file
This document provides guidelines for vendors proposing information technology systems that will reside or interface with the Department of the Interior's Microsoft Azure tenant. It outlines the common Azure architecture components utilized, including the DOI-managed Azure tenant, subscriptions tied to individual bureaus/offices, approved regions for workload deployment within the continental US, and network access via redundant ExpressRoutes. Identity management via Azure Active Directory is also addressed, covering user and privileged accounts, guest access, and service principals. Networking guidelines define the hub-and-spoke architecture with centralized hubs in US East and West, ExpressRoute connectivity to on-premises networks, internet access through the hubs, and IP addressing and DNS resolution. Compliance and security recommendations are provided regarding baseline Azure policies, required logging, and restrictions on certain security tools.
The related federal contract opportunity is a combined synopsis/solicitation from the Bureau of Safety and Environmental Enforcement on behalf of the Bureau of Ocean Energy Management. It seeks a commercial off-the-shelf geoscience and geophysical software package that can be hosted in accordance with the DOI cloud mandate. The estimated five-year period of performance begins from date of award.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Sol_140M0124Q0011_Amd_0001.pdf | ||
| B09_-_RFQ_140M0124Q0011_Addendum_0001.docx | DOCX document | |
| B09_-_RFQ_140M0124Q0011_Amend_0001_Q_A_0001.pdf | ||
| Sol_140M0124Q0011.pdf | ||
| B08_-_RFQ_140M0124Q0011_Addendum.pdf | ||
| B08_-_140M0124Q0011_Combined_Synopsis_Solicitation.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Microsoft Azure Environment Guide
Azure Environment 1 For reference
The Department of the Interior, Office of the Chief Information Officer (OCIO) provides the following guidelines for prospectus vendors who are submitting proposals for Information Technology Systems that will reside or interface with the DOI Enterprise Microsoft Azure Tenant. Prospectus vendors may propose one or more of their personnel to become a contractor agent or Bureau/Office technician. When the descriptions below stipulate “Bureaus/Offices are responsible”, this extends to include prospectus vendor personnel.
This document is provided as a guide to common Azure implementations within the US Department of the Interior (DOI) and is intended to steer discussions and configuration for new Azure deployments with potential Vendors. Unless otherwise noted, the information provided should be considered as DOI Best Practices and not as hard requirements.
Common Azure Architecture Components Azure Tenant - DOI provides a single tenant where all workloads should be placed. The Office of Chief Information Officer (OCIO) maintains the Azure Active Directory infrastructure and core network connectivity for all Bureaus/Offices.
The root Management Group is maintained by OCIO, each Bureau/Office has a subgroup.
Permissions on the Bureau/Office subgroups are delegated to the Bureau/Office’s primary Azure points of contact. This allows the Bureau/Office to setup their subgroups and permissions as they see fit.
Each Bureau/Office has a small list of designated Points of Contacts that act as liaisons between OCIO and the Bureau/Office. Information on the Azure environment and upcoming changes to that environment are communicated from OCIO through those designated contacts.
OCIO has a small group of Azure Architects that oversee the DOI Azure environment and provide consultation to vendors and Bureaus/Offices on an as needed basis.
Requirements:
Enterprise Agreements - Bureaus/Offices are responsible for their own licensing and Enterprise Agreements (EA) and federal employees are directed to order from a DOI Microsoft Blank Purchase Agreement (BPA). Bureaus/Offices are required to be owners on the EA before they can be connected to the DOI Azure Tenant. The BPA is license only and does not provide technical, development, nor integration types of support services.
Azure Environment 2 For reference
Subscriptions - Bureau/Office employees and contractors are responsible for the role-based access on the subscriptions. Each subscription requires at least one Bureau/Office employee to have the “owner” role on the subscription, often this is inherited from the Management Group.
Azure Regions - All workloads must be deployed within the Continental United States (CONUS). Any region within CONUS is available for use without restrictions. US East and US West are considered primary regions and where most network connectivity centralized.
Network Access - OCIO provides all network access to and from the Azure Tenant via redundant ExpressRoute circuits. For more information see the Microsoft Azure Networking section below.
Azure Active Directory & Identity OCIO manages and maintains all aspects of Azure Active Directory within the DOI tenant.
Global Administrator roles are restricted to employees and contractors within OCIO. Vendors and Bureau Administrators will not be granted administrative access within Azure Active Directory. OCIO works closely through a documented change management process with the Bureaus/Offices to facilitate and accommodate changes.
Apart from SCIM, OCIO does not support synchronizing Active Directory to any other Cloud provider or Azure Tenant for the purposes of direct authentication.
Azure Active Directory is positioned as the primary authentication provider for all cloud services and providers, this includes but is not limited, SAML and OAuth for 3rd parties.
User Accounts - On-Premises Active Directory user accounts are synchronized with the DOI Azure tenant, this does not include service accounts or privileged accounts. In general, user accounts require Multi Factor Authentication using PIV access cards.
Guest Accounts - Guests accounts are allowed within the tenant and can be invited under approved applications. Guest accounts that are inactive for 90 days are automatically disabled and deleted.
Elevated Privilege Accounts - Elevated Privilege accounts are required to manage Azure resources and are created/maintained by OCIO. All contractors requiring access shall
Azure Environment 3 For reference undergo a standard level federal background check per HSPD-12 regulations to meet authentication requirements before being given access to DOI resources. Elevated Privilege accounts are required to satisfy multifactor authentication which may include the use of PIV access cards and Government Furnished Equipment.
Service Principals - Service Principals in the form of Service Accounts, Application Registrations, and Enterprise Applications are managed by OCIO and are required to undergo security risk analysis before being provisioned. Bureaus/Offices can request Service Principals as needed using an established change management procedure with OCIO.
Administrative Units - Each Bureau/Office has a designated Administrative Unit (AU) within Azure Active Directory. Permissions to create and manage groups within those AUs are assigned to Bureau/Office personnel.
Groups - Security, Dynamic, Office 365 and Distribution groups can be created and managed within Azure Active Directory via Administrative Units. In some cases, on-premises Active Directory groups are synced to Azure Active Directory.
Microsoft Azure Networking Network Architecture - Generally, the Hub and Spoke network architecture is currently in place within the DOI Azure Tenant. The centralized Hubs act as peering locations for traffic to cross over between spokes, the Internet, or on-premises networks. Peering between spokes within the same subscription and/or Bureau is allowed. Centralized hubs are in US East, and US West regions and are managed by OCIO.
ExpressRoute - Both centralized hubs have fully redundant ExpressRoute circuits for access to DOI on-premises networks and are managed by OCIO. The ExpressRoute endpoints are designated solely for use with the DOI Azure tenant and are not shared with other Tenants.
Route tables that include IP Address space for on-premises resources via ExpressRoute are propagated to all peered virtual networks.
Internet Access - Forced tunnelling to the internet on Azure resources is in place to comply with governmental security mandates. All traffic from/to the internet should flow through the centralized traffic hubs before being routed through the appropriate crossover points.
Private endpoints should be utilized whenever possible to limit exposure to the Internet edge. Trusted Internet Connection (TIC) versions 2 and 3 are supported in the environment via the central traffic hubs. Route tables that include the default 0.0.0.0 route and to the
Azure Environment 4 For reference
Internet are propagated to all virtual networks.
IP address space - IP v4 & v6 addresses for virtual networks peered to the central hubs in Azure are provided by OCIO to each Bureau/Office and are treated as extensions of their on-premises network. IPv4 spaces are limited in nature and should be a consideration in architecture.
DNS Resolution - OCIO employs centralized DNS servers that perform DNS forwarding for Azure domain spaces both within Azure and the on-premises environments. Private endpoint zones are located centrally to allow all Bureaus/Offices to easily manage custom DNS entries.
Compliance and Security DOI encourages innovation and cloud adoption by taking a minimalist approach to hardening the resources found within the Bureau/Office subscriptions and leaves many of the decisions within the Bureau/Offices purview.
The requirements for Compliance and Security can shift quickly based on Government mandates and memo’s, please check with the Bureau/Office for any last-minute shifts to the information presented below.
Azure Policy - OCIO maintains a minimal list of enterprise-wide Azure Policies that are enforced across the entire tenant. Generally, they are targeted to secure the internet boundaries of the environment and are not a comprehensive list of recommended policies.
Exemptions to the existing OCIO policies can be requested through the OCIO Change Management system and are evaluated on a case-by-case basis. The latest list of OCIO Azure Policies can be requested by the Bureau/Office designated Azure points of contact.
Bureaus/Offices are encouraged to layer additional Azure policies on their environments to fully secure their workloads.
Required Logging - OCIO currently retains centralized logs for Azure Active Directory, Azure Activity Logs and the centralized Firewalls in each hub. Logs for individual applications, virtual machines, databases, workloads etc. are the responsibility of each Bureau/Office.
Security Tools - While OCIO recommends security tools like Defender for Cloud, Azure Policy, and Azure Monitor, there are currently no centralized enforcement for specific security tools.
Tools that have Enterprise-wide data access plugins (ie: Sentinel) can be deployed for specific
Azure Environment 5 For reference subscriptions, but Azure Active Directory plugins, Office365 plugins or other data sources that could expose the entire enterprise to the tool, are prohibited for use outside of OCIO.
File details come from the government source that posted it. Updated .