RFP No. 6440 - Microsoft MXDR Services.docx

DOCX document 173 KB Posted

Attached to
RFP 6440 - Microsoft MXDR Services State and local contract opportunity
Solicitation number
RFP 6440
Issued by
Macomb County, Michigan

About this file

This document is a Request for Proposal (RFP) No. 6440 issued by Macomb Community College in Warren, Michigan for Microsoft Managed Extended Detection and Response (MXDR) Services. The college seeks a 36-month contract to establish a comprehensive cybersecurity service that will consolidate threat detection, response, and remediation into a single provider, focusing on Microsoft-based security tools and platforms. The RFP requires vendors to configure and co-manage the college's Microsoft Sentinel SIEM, monitor key assets, provide 24x7x365 security event monitoring, and integrate with existing systems like Microsoft 365, Active Directory, and Palo Alto firewalls. Proposals are due by July 25, 2025, with a proposed contract start date of September 1, 2025.

The RFP covers an environment with approximately 78,527 total Microsoft 365 accounts, including 22,537 students, 675 non-faculty full-time employees, and various part-time and contractor accounts. The total contract value will be determined by the proposed pricing in Appendix A, which includes one-time implementation costs, annual monitoring fees for specific devices and systems, and optional bid alternates for supplemental Microsoft services and limited-scope service desk support. The college has a mature IT security program based on the CIS v8 framework and requires vendors to demonstrate compliance with regulations like FERPA, HIPAA, and GLBA. Preference will be given to proposals from teams with experience in higher education security and formal Microsoft certifications.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

RFP No. 6440 June 23, 2025 Microsoft MXDR Services

REQUEST FOR PROPOSALS

Microsoft MXDR Services (Managed Extended Detection and Response)

RFP No. 6440

MACOMB COMMUNITY COLLEGE

WARREN, MICHIGAN

PROPOSALS DUE NO LATER THAN

FRIDAY, July 25, 2025, at 2:00 P.M.

Submit Proposal To:

Macomb Community College Dennis Costello Purchasing Department costellod@macomb.edu bids@macomb.edu

1. PROJECT OVERVIEW

Macomb Community College wishes to establish a 36-month Microsoft based MXDR (Managed Extended Detection and Response) contract with a firm to provide end-to-end managed detection and response services that identify, investigate and remediate detected cyber threats within Macomb’s Microsoft 365 tenant. The service will replace a multi-provider model where one is focused on Managed Detection & Response (MDR), and another manages our Microsoft 365 and related identity infrastructure. This approach has made SIEM visibility, root cause analysis and timely remediation difficult. Through a combined services strategy, the College seeks to significantly reduce malicious event remediation time and lower overall cost.

Bidders will configure and co-manage a Macomb owned Microsoft based SIEM (Sentinel). At a minimum, the base bid proposed services shall provide:

· Comprehensive onboarding

· Monitor the College’s key assets (equipment/server/systems) listed in the bid form to provide real time analysis of potential malicious or nefarious activity through log aggregation and event correlation analysis

· Security/Audit log archival

· Focus on actionable events for customer notification and real-time monitoring schemes which reduce/prioritize the volume of data that must be quickly analyzed

· Basic containment/account quarantine services 24 x 7 x 365. For example, remediation/block of account compromises the moment it is detected.

· Automated remediation where practical A bid alternate is available for providers who can bundle supplemental, limited off-hour service desk capability with their bid.

Bidders should take great care to fully explain services for the quotes costs and differentiate themselves from their competitors. Bidders are encouraged to use the clarification process defined in section 3 & 4 to fully understand the College’s desire/need/scope.

While it is expected that the SOC team may be concurrently serving other client accounts, a tiered response time SLA model based on urgency or security alert severity will be required to establish and maintain service expectations.

Preference will be given to proposals received where the team lead has at least two years’ experience in a higher education security discipline given the unique software/systems used within the industry.

All proposals MUST be formatted per section 5 (“Proposal Response Format”) of this RFP and accurately provide all information specified. Bids that fail to meet this requirement will be disqualified without any evaluation.

A detailed scope of work is in section 8.

2. PUBLIC STATEMENT

Macomb Community College (MCC) is the largest community college in Michigan serving more than 43,000 degree-credit students. MCC also offers pre-college programs, continuing and professional education programs, customized workforce training and many cultural and community service programs.

3. RECEIPT OF PROPOSALS

To be considered for acceptance, all consultants wishing to submit a proposal must adhere to the following schedule:

Deadline for requesting clarifications
Date: July 3, 2025
Clarifications issued
Date: July 10, 2025
Final Proposals Due
Date: July 25, 2025
Proposed Contract start
Date: Sept 1, 2025

Proposals must be e-mailed by 2:00 P.M. on the Final due date posted above. Proposals should be submitted to:

Dennis Costello, Purchasing Director Macomb Community College

E-mail: costellod@macomb.edu and bids@macomb.edu Proposals should not include any zipped or executable files as these will be blocked by the College’s e-mail security appliance and may not be considered as received on time.

Proposals must be signed by an individual with authority to enter into a binding contract and the authority of the individual signing must be stated thereon.

4. INQUIRIES

Inquiries pertaining to this RFP are to be directed to:

Dennis Costello, Purchasing Director costellod@macomb.edu and bids@macomb.edu Responses to clarifications will be shared with all organizations that were invited to submit a proposal. MCC will not be bound by any oral responses.

5. PROPOSAL RESPONSE FORMAT

Responses should be submitted in electronic format to the contact listed above in Section 3. Acceptable electronic formats include Microsoft Word or PDF. All proposals shall be organized into seven sections as follows.

Section Description

1. Completed bid response form found in Appendix “A”.

2. Provide a company overview including core services. This section must detail:

a) The scope of services; the size of the team and its’ geographic distribution; general team member competencies; internal process delivery strategy and staffing plan.

b) A tiered response SLA model based on urgency or security alert severity. The SLA proposed in section 8 of this RFP is meant to be the starting point.

c) The number of years you have been providing MXDR services and your annual rate or percentage of new, renewing, and terminating contracts over the last three years.

d) The number of security operation centers (SOCs) you have and where each is located.

e) Third-party organization(s) responsible for conducting your latest security risk evaluation, security audit, and vulnerability assessment. Denote how often they are performed.

3. Describe your approach to supporting 24x7x365 remote security event monitoring and device/agent management. The College views these deliverables as a key differentiator between vendors/bids. This section must:

a) Clearly explain how the bidders’ services meet the College’s monitoring and containment objectives, specifically 24/7 threat detection capabilities, human-led threat hunting practices, SIEM/SOAR platform integrations (Microsoft Sentinel only) and techniques for false positive reduction and tuning.

b) Detail how the vendor identifies the proper logs/data required for each asset to assure optimum threat hunting and correlation performance.

c) Explain how the vendor sets up Microsoft Sentinel for the contracted scope.

d) Describe how you build and execute playbooks and other automation events, including real-time containment capabilities (during off-hours, holidays, weekends), digital forensics and malware analysis.

e) Detail how the vendor coaches the College through objective development and how those objectives are maintained throughout the life of the contract.

f) Describe the expected impact on Azure storage, bandwidth, latency, and any firewall or routing changes we must make.

g) Describe how information security risks are assessed, periodically and in relationship to the major changes in technology, internal or external threats, or your systems and operations.

h) Please describe your standard service-level agreement (SLA) performance assessment and reporting process and your problem resolution and escalation procedure, including escalation thresholds and timing.

i) Describe the personnel screening process and the level of background checks performed for prospective employees, for monitoring security operations center (SOC) personnel, and for providing initial and ongoing staff training.

j) Provide documentation by example of your methodology for collecting, analyzing and reporting critical alerts of external threats, vulnerabilities in our environment, and possible intrusions or attacks. Include your capability to analyze data from various security products/sensors and provide correlation among data sources and explain your methodology and process for reducing false positives/negatives. Include a detailed architectural diagram and explanation of software used if your solution utilizes third party products.

k) Explain how you use external information to analyze potential threats to our environment and describe what access to this information we will have. Do you use your own dedicated threat intel teams to build detection content, or do you rely on external/open source threat intel?

l) Describe the level of interaction and support that our staff can expect from your security analysts to assess, investigate and respond to incidents. Explain how it is not a “throw it over the wall” approach.

m) Describe your incident response plan and what the engagement looks like when dealing with escalated security incidents.

n) Explain how the upgrade of current monitored devices or addition/removal of monitored sources affects the scope of services and recurring costs. For example, the College is highly likely to migrate its on-premises Ellucian Colleague environment to its fully SaaS version during the life of the contract; describe how your services will accommodate and support that major change.

4. Resumes of the primary support individuals (no more than six, names may be redacted) specifically related to the scope of services section of this RFP illustrating:

a) Overall experience. The proposed engagement team lead and their backup must be included and identified.

b) Education and certifications. Formal Microsoft certifications required.

5. List ALL deviations to bid specs listed in section 8. Unless specifically denoted in this section of your response, the College assumes the proposal to FULLY provide the services listed and the vendor shall be contractually bound to them if awarded a contract.

6. Provide three customer references, with contact information, of similar work performed. Experience in the Higher education space is required.

7. Provide a sample of the services contract (or MSA and SOW) for review if one is not already in place with the College.

6. CONTACT PERSON

Please identify by name, telephone number and e-mail address, the person or persons whom the College can address questions to during the evaluation of proposals.

7. AWARD OF PROPOSAL

The college may contact respondents to this RFP to arrange interview(s) to validate specific team member qualifications, technical skill requirements and the bidders’ ability to mesh with the College’s culture, values and staff. The College may further require bid finalists to sign an NDA before technical details of the College’s environment that might be necessary for the bidder to accurately answer bid interview questions are shared.

Bid evaluation focus will be on provider differentiation, which is not found in the underlying technology, but rather in the deliverables and how well bidders understand the College’s requirements. Formal Microsoft certifications of team members will heavily influence the selection process.

The College may award a contract based upon the initial proposal without further discussion of such proposals. Accordingly, each initial proposal should be submitted with each respondent’s most favorable fee and service capabilities.

8. SCOPE OF SERVICES REQUIRED

Macomb Community College wishes to establish a 36-month Microsoft based MXDR Service that provides end-to-end managed detection and response service that identifies, investigates and remediates detected cyber threats within Macomb’s Microsoft 365 tenant and ingests data from key security logs, such as the College’s PaloAlto environment (full scope explained in table # A.1.4.a in the bid response form). If the vendor requires the use of a supplementary SIEM or data import tool, those costs should be included in the bid response form. The ecosystem must be configured to provide security log management and archival of the College’s critical systems denoted in table A.1.4 of the mandatory bid response form; continuous threat monitoring; threat detection; incident response (limited to the College’s Microsoft 365 tenant); and reporting. The service will replace the College’s currently separate MDR/MSSP and Microsoft 365 account management services provided by two separate firms. Through a combined services strategy, the College seeks to reduce malicious event remediation time such as remediation/block of attack or account compromise the moment it is detected.

Vendor services must focus on automated and actionable events for customer notification and real-time monitoring schemes which reduce/prioritize the volume of data that must be quickly analyzed. The vendor must be able to apply their knowledge of external threats and of the types and numbers of attacks they encounter across the devices monitored for all of their customers to add value to the analysis of alerts for Macomb Community College. Vendor must know how and when to obtain data from other sources to validate a potential threat.

The major goals of the new engagement:

· Consolidate threat detection, response, and remediation into a single, accountable service provider to eliminate operational gaps and ensure unified incident handling.

· Improve mean time to detect (MTTD) and mean time to respond (MTTR) and enable real-time containment, including during off-hours and weekends.

· Enhance protection against identity-based attacks within the College’s Microsoft 365, Entra AD, and Microsoft Defender for Identity ecosystem. A focus on MFA enforcement, credential hygiene, and token misuse monitoring is required.

· Integrate after-hours support into the security operations framework, ensuring that Tier-1 support functions are informed by current threat activity and that escalation is seamless and immediate.

· Establish full visibility into detection rules, SIEM/SOAR logic, SOC dashboards, and playbooks, allowing the Colleges internal IT team to participate in, audit, and validate ongoing security activity.

· Automated remediation where practical Bidders will configure and provide primary management of the College’s Microsoft based SIEM (Sentinel). That environment is not configured or in use. The College intends to provide secondary/co-management of the environment to establish full visibility and optimize the environment’s health, configuration and monitoring effectiveness. The vendor's team shall be led by a primary engineer/consultant who will report to the College’s Senior Security Analyst. The primary team member must have a backup who can step in without notice should the primary team lead not be available. The support team shall consist of certified security engineers, Microsoft 365 experts, and security analysts. The team lead (or their backup) shall be available during the College’s normal business hours (8AM – 5 PM EST Monday-Friday). While it is expected that the vendors SoC team may be concurrently serving other client accounts, a tiered response time SLA based on urgency or security alert severity will be required in the contract.

Contract deliverables shall be defined by outcomes, not tasks and shall not be limited to a specified number of hours in the contract. During onboarding, the vendor shall lead the development of a table defining outcome expectations, who would be responsible for remediation, and how priorities are set.

SLA benchmarks:

· MTTD: ≤ 10 minutes for critical threats

· Containment initiation: ≤ 30 minutes

· Root Cause Analysis (RCA) and forensic report: within 48 hours of incident closure Services required:

1. Stand up and configure the College’s Microsoft based SIEM (Sentinel). The cost of Sentinel, its storage and transaction costs shall be the responsibility of the college.

2. Co-manage the College’s Microsoft-based SIEM (Sentinel). The vendor will assume primary responsibility, but College Information Security Staff intend to use and/or augment Sentinel data to further reduce security vulnerability risks.

3. Use vendor SOC library threat intelligence to qualify security event/log correlation

4. Tune alerts to reduce false positives

5. Monitor the College’s key assets (equipment/server/systems) listed in the bid form to provide real time analysis of potential malicious or nefarious activity through log aggregation and event correlation analysis.

The vendor’s configuration and service strategy must gather data from monitored devices; filter/data mine this data in real time, and report findings or trigger alerts based upon predefined trigger/escalation thresholds. At a minimum, the College expects the vendor to identify and map system-level event messages to high-level events by monitoring the following activities:

a) Endpoint Detection and Response (EDR) - Includes logs like threat detection, system events, file events, and command history.

b) Network Devices - Logs from firewalls, routers, switches, VPNs, and intrusion detection systems.

c) Microsoft Domain Controller - Covers account logon, account management, Kerberos, and policy changes.

d) Active Directory (AD) and Domain Services – Logs related to system integrity, logon/logoff, directory service access, and privileged use.

e) Microsoft Windows Endpoints - Includes application event logs, task scheduler logs, PowerShell logs, and security event logs.

f) Additional Log Sources from Virtualization systems, operational technology, cloud platforms, containers, databases, mobile device management, DNS servers, Linux endpoints, and Apple macOS endpoints where the vendor and College agree vulnerability exists.

g) All actions taken by any individual with root or administrative privileges, including PIM or JIT escalations.

h) Access to all audit logs.

i) Invalid logical access attempts.

j) Use of and changes to identification and authentication mechanisms—including but not limited to creation of new accounts and elevation of privileges—and all changes, additions, or deletions to accounts with root or administrative privileges.

k) Initialization, stopping, or pausing of audit logs.

l) Creation and deletion of system-level objects.

m) Log correlation against a known type of event.

n) Vendor must have well defined library of security events that can be used to correlate logs to pick up on any type of infiltration.

6. Monitor Microsoft 365 activity/access/security logs. Monitor Microsoft Purview Compliance Center, Microsoft Defender XDR, and other M365 alerts. Triage the security alerts generated by the platforms or discovered malicious activity and create/update ticket in the College’s TeamDynamix ITSM (ticket) system. Outside of business hours, the vendor shall take immediate action to neutralize the threat and review those actions with the College’s Security/IT team next business day which includes, but is not limited to, the blocking malicious IP’s and suspending compromised accounts. During business hours, the College wishes to operate in a co-management mode where the vendor maintains the lead role and college staff augment/participate in triage and remediation activities.

7. Ellucian Colleague is the College’s business and student information system running on a legacy database platform (Unidata). Transaction monitoring is limited, but it is imperative that those outputs be included in the vendor’s threat hunting and event correlation strategy. Vendors with experience extracting log data from the Ellucian Colleague product line will be scored higher during evaluation.

8. Provide integration with TeamDynamix, the College’s ITSM (ticketing) system. This expectation can be met in one of two ways:

a. Manually creating alert and change management tickets in TeamDynamix via Macomb-issued credentials

b. Bidder created/configured API

9. Configure Sentinel to preserve and archive the College’s Security/Audit logs in the most cost-effective manner. Log history shall be maintained for at least one year, with a minimum of three months immediately available for analysis. The cost of log storage shall be the responsibility of the customer.

10. Focus on automating and actionable events for customer notification and real-time monitoring schemes which reduce/prioritize the volume of data that must be quickly analyzed.

11. Create/provide detailed playbooks documenting all monitoring, alerting and remediation processes and how those tasks are performed within the thresholds defined in the SLA. It is critical the College has a transparent view of how the vendor meets contractual requirements and how to remediate service issues that fall below expectations or SLA terms. The playbooks must clearly document where and/or when a handoff of responsibility occurs and how that handoff is conducted.

12. Apply knowledge of external threats and attacks encountered across the devices/systems monitored for all clients.

13. Manage a Microsoft based multi-layered information technology security environment that detects, contains, and mitigates incidents that may impair system(s) availability, data preservation or information security. This includes, but is not limited to, Active Directory/Azure AD/Entra ID, Defender, authentication systems, suspicious login/MFA behavior, token theft, account takeovers, data loss prevention, sensitivity labeling, retention labeling, coordination of an array of security tools such as antivirus/malware, encryption technologies, PII, PCI, and the remediation of findings that cross thresholds of acceptable risk through delegation to appropriate IT staff and members of the managed services staff. See the “Out of Scope” section for duties/tasks explicitly removed from the RFP services scope.

14. Proactively respond to high-risk events using Automated Hunting in Defender and/or Sentinel in accordance with engagement SLA.

15. Exchange online environment - security, anti-SPAM, configuration to best practices. NOTE: At the time of RFP issue, the College is considering the purchase of a supplemental email security gateway to front-end the Microsoft mail environment to improve detection and filtering of malicious mail. The Microsoft MXDR vendor will not be responsible for the configuration or management of this supplemental system but will be consulted to ensure configuration does not negatively impact the Microsoft systems they are contractually required to support and manage.

16. Manage the day-to-day activities of the College’s Active Directory-based user authentication and authorization management systems (Microsoft MFA/SSPR). This includes the Active Directory related tasks in onboarding and offboarding of staff accounts.

17. Create/monitor Microsoft 365 specific IT security tickets using the College’s incident management system, TeamDynamix. Contractors will be provided individual accounts with access to this system.

18. Provide monthly and quarterly non-technical summaries of incidents with impact framing.

OUT OF SCOPE:

· Vulnerability scanning.

· IT Security training and phishing/attack simulation.

· Penetration testing.

· Providing, configuration, or management of, a supplemental non-Microsoft email security gateway to front-end the Microsoft mail environment to improve detection and filtering of malicious mail.

BASE BID: OTHER GENERAL SPECIFICATIONS

The College has a mature IT security program based on the CIS v8 framework. Adherence to those controls will be a governing factor to engagement success.

The vendor must demonstrate deep integration with the Microsoft Defender suite, including:

· Microsoft Defender for Endpoint

· Microsoft Defender for Office 365

· Microsoft Defender for Identity

· Microsoft Defender for Cloud Apps

· Microsoft Lighthouse

· Proposed services must ingest Defender alerts into the SIEM/SOAR stack and perform alert enrichment with identity and endpoint context; real-time threat scoring and prioritization; automated response workflows for high-fidelity alerts (e.g., credential theft, malware, lateral movement).

The proposed ecosystem must support:

· Azure logs and signals, including Security Center and AD

· On-premises infrastructure logs, including Active Directory, Palo Alto firewalls & VPN, and server security logs

· SaaS platform logs (e.g., M365, Zoom, Canvas, etc.) where applicable

· Third-party security tool ingestion (e.g., Cisco ISE, Tenable Vulnerability Management)

· Normalization and parsing for disparate log sources

· API’s that comply with OAuth2 / token-based authentication, Microsoft Graph and Sentinel API best practices.

The vendor must ensure that all tooling and processes align with applicable legal and regulatory standards, including:

· FERPA – Education records must be protected with strict access controls and breach protocols.

· HIPAA – Where applicable, systems must safeguard any protected health information PHI.

· GLBA – Financial and personally identifiable information must be protected with administrative, technical, and physical safeguards.

· Sensitivity and retention policies that align with institutional data governance standards (stated elsewhere in this RFP)

· Support for log immutability, chain of custody, and forensic-grade storage for investigations.

Macomb Community College will retain primary configuration management of the monitored devices. Vendor’s solution will employ a strategy to gather event data from monitored devices, forward such data to Sentinel, filter/data mine this data, and report findings to the appropriate College personnel based upon predefined trigger/escalation thresholds that are recommended by the Vendor and agreed to by Macomb Community College.

Macomb Community College requires Vendor to designate an account manager for the entire duration of the contract. The account manager may be required to participate in quarterly status meetings, provide the College with SLA and other reports and escalate any issues according to defined escalation procedures, etc.

The bid finalist will be required to provide the College with a completed SOC-2, SIG, CMMC, CIS-CAT, NIST CSF or pre-approved Cyber VRM Service assessment report created for others before a contract is signed.

DEVICES AND SYSTEMS TO BE MONITORED:

As listed in mandatory bid response form. However, bidders are encouraged to make recommendations and/or prioritize the value of including each device in the monitoring pool based on their experience and the firm’s event correlation/forensic capabilities. Lastly, the college may be selective on which assets and systems are included into the final contract based on the value proposition of each.

ENVIRONMENT (for scoping purposes)

User counts

· Non faculty full time – approx. 675 employees

· Approx full and part-time contractors (varies): 125 accounts

· Non faculty part time – approx. 220 employees

· Faculty full time – approx. 215 employees

· Faculty part time – approx. 300 employees

· Students, unduplicated headcount (2024) – 22,537. Note: This is aggregate attendance for an academic year, not the attendance for a semester. The student population varies by semester and is a subset of the unduplicated headcount value. Student accounts are maintained for two years after last semester attended (passwords scrambled after a period of inactivity). The total number of all student accounts is approx. 85,000.

All staff (full and part-time), contractor and student accounts are protected by Microsoft MFA without exception.

Communications and Networking

· Cisco Gigabit Ethernet backbone (currently Dell, but transition to 100% Cisco will be complete by the time this bid is awarded).

· Over 700 actively managed network devices in approx. 65 locations across four (4) campuses including 62 stacks (325+ edge switches).

· 11 VLAN segments per switch stack for edge layer, utilizing Layer 3 for distribution and core layer.

· Dedicated fiber plant between buildings. Dedicated redundant fiber between South and Center campuses. Leased fiber connects other campus and outreach locations.

· Systemax Gigaspeed copper cable from MDF/IDF to office and classroom locations; about 9,000 total drops.

· Extreme 802.11ax wireless AP’s (approx. 1000 AP’s deployed in all public areas). The WiFi environment is managed through the ExtremeCloud IQ management console.

· Cisco IP telephony system (managed by others). Includes Unity voice mail, CER, and Informacast paging application.

· Microsoft Hyper-V Cluster utilizing both data centers. There are approximately 400 network servers in the Hyper-V environment. There are 14 blades in two HP c7000 chassis’ that support this. There are approx. 15 physical servers separate from the Hyper-V cluster for AD, DNS, and other services. All in native-mode Active Directory environment.

· Azure – VPN connected for storage and Virtual Servers.

· Office 365 – Email, Teams and OneDrive for all staff and students.

· Total number of M365 accounts: 78,527

· Active number of users over the past 180 days: 28,500

· Microsoft Entra Active Directory for students and staff (same domain).

· Microsoft Self-Service Password Reset for password management.

· Palo Alto Firewalls – External Perimeter, Internal Server, Wildfire, URL Malware Detection, User-ID, App-ID, antivirus, anti-spyware, IPS.

· Palo Alto Panorama – Logging consolidation and management of Palo Alto firewalls.

· Internet connection is through 2 separate 1 Gb fiber connections. The connections have different paths (south and center campus) with HA/DR setup for both.

· Remote DDoS mitigation services through Merit Network.

On-premises Business Applications

· Ellucian Colleague system used for Finance, Human Resource, Payroll and all Student records sub-systems, such as Admissions, Grading, Registration, etc. This environment is currently on-premises but migration to Ellucian’s fully SaaS platform may be started at some point during the life of the contract. The College acknowledges Ellucian-provided logging is very basic.

· Ellucian Colleague run on a Unidata database system with a Linux operating system. A separate SQL environment is used for reporting.

SaaS Systems

Except for those identified in the bid response form, systems in this list are out of scope for the RFP. Systems denoted with “*” are potential (future) candidates for MXDR monitoring given the type of data stored within them, however. Those additions would be handled via change order if/when the College determines the risk is worthy of the investment.

· TeamDynamix (ITSM/Ticketing/Service catalog).

· Canvas* (Student LMS)

· NeoED* (Job applicant processing)

· Timeclock Plus

· Hyland ImageNow* (Doc Imaging)

· Acalog (Course Catalog)

· Curriculog (Curriculum)

· PerfectForms* (eForms)

· EMS (Room and event scheduling)

· Maxient* (Student conduct)

· BlackBaud Raisers Edge* (Foundation)

· Prospero* (P & L)

· Mongoose (Texting)

· RAVE (Emergency notification)

· Nelnet* (Payment Plans)

· Recruit* (Ellucian)

· Lumens* (WCE)

· Questica* (Budget)

· PrintShop Pro

· The College’s three public websites (hosted externally)

· Interact (externally hosted MyMacomb student/staff portal)

Endpoints

· 5000 Windows 11 endpoints in staff offices, labs, public areas. Endpoint protection via Microsoft Defender for Windows A5 ATP. Note: At time of RFP release, the College is approx. 60% Windows 10 with plans on track to complete migration to Windows 11 by Oct 1, 2025.

8.1 BID ALTERNATE #1 – Manual Account Processing and Purview eDiscovery Case Creation

Most of the College’s accounts are provisioned and deprovisioned automatically. Those not created through scripted workflows require manual processing. This work is currently being handled by one of the two providers described in the project overview section of this RFP. The College will give preference to firms that can provide these services in addition to those specified in the base bid. These services may be bid by the task or included as in-scope work of the base bid. Invoicing shall be per invoice period (monthly or quarterly). Purview tasks are limited to case creation and content analysis using premium eDiscovery features. For scoping purposes, please use the following task definitions:

· Set up new account: Add in AD with permissions described on new request form.

· Disable account: Disable in AD. Provide notice to IAM Specialist so non SSO accounts elsewhere can be suspended (by others).

· Archival, clean up and termination of employee account: (Typically after account has been disabled for 45 days), copy all exchange and OneDrive files to specified archival location. Perform archive per playbook. Create ticket for account deletion via formal account removal script (accounts within this category cannot be deleted manually).

· Purview eDiscovery case – Simple: Create case in Purview to place preservation hold on OneDrive, Sharepoint, Teams and Exchange data for up to three account owners. Perform up to two searches and content exports using search scopes provided by authorized College administration.

· Purview eDiscovery case – Complex: Create case in Purview to place preservation hold on OneDrive, Sharepoint, Teams and Exchange data for up to 8 account owners. Perform up to five searches and content exports using search scopes provided by authorized College administration.

8.2 BID ALTERNATE #2 – SUPPLEMENTAL, LIMITED SCOPE SERVICE DESK

Bidders with existing capabilities are encouraged to include a proposal for remote and off-hour service desk services. The College believes this to be a natural extension of base bid services since the SOC will already have off-hour staff with intimate knowledge of the College’s environment and access to the security tools necessary to triage and solve user access issues after caller identity has been confirmed. This service would provide students and staff with an off-hour support channel for basic tier one support services such as:

· Password reset assistance/Microsoft SSPR/account lockout assistance

· Escalation to SOC team during incidents

· Account access problems, including detected risky account lockout

· Microsoft MFA configuration support

· Reporting service outage

· Basic triage for user-reported security incidents Specific application support and College hardware troubleshooting is out of scope. This service is not intended to duplicate the College’s normal service desk operations, but to provide basic support (scope limited as listed above) after business hours, and pre-arranged overflow support on limited occasions during normal business hours.

Seamless integration with the vendors’ SOC operations proposed in the Base Bid, using shared documentation, threat context, and escalation protocols is expected. Similarly, shared use of the College’s TeamDynamix ITSM platform is required for unified ticketing.

The College has provided this service for many years and the historical metrics below are expected to hold for the foreseeable future.

· 38 calls (average) per week for the period Jan 3, 2025, through May 15, 2025. 40 of those calls (during the entire five-month period) were on Saturday or Sunday.

The bid alternate shall propose a phased approach:

· Assess: 30-day assessment phase to determine automation opportunity of ‘low hanging fruit’ SD calls with ChatBot or AI agents and use these tools to replace simple support requests with automation.

· Automate: Develop and test automation. The College has an extensive knowledge base that can be used to build AI based agents/chatbots. Microsoft Copilot Agents/chat-based solution preferred. Automation shall include confirmation of caller identity before services are provided. Note: at the time of RFP issue, the College is evaluating commercial identity validation tools and would permit the vendor to use/interface with that tool (once selected) as a college-sponsored third party if the vendor does not have/prefer one of their own.

· Production launch:

· No more than 60 days from contract inception, regardless of automation completed

· Provide live agent where automated support of simple requests does not exist or fails. Expected first contact resolution: 85%

· Primary service hours (where a live agent must be available when automated support is not sufficient to the caller: 5 PM – 10 PM M-F and 9 AM – 5 PM Saturday and Sunday.

· Pre-arranged overflow support during business hours no more than five occasions throughout a calendar year.

· No live agent service will be provided on US holidays.

9. GENERAL CONDITIONS

a) Vendor as Independent Contractor This is not an Agreement of partnership or employment of Vendor or any of Vendor's employees by MCC. Vendor is an independent Vendor for all purposes under this Agreement.

b) Conflict of Interest/Disclosure No company or corporation in which an employee of the College has a direct or indirect interest shall transact business with the College unless such interest is disclosed to the Purchasing Department prior to entering into any contract or agreement with the College. Further, the employee shall not take part in the negotiations for or approval of such contract or agreement.

c) Use of Qualified and Experienced Personnel Vendor agrees to maintain an adequate staff of experienced and qualified employees for efficient performance under this Agreement. Vendor agrees that, at all times, the employees of Vendor furnishing or performing any services shall do so in a professional, work-person like, and dignified manner.

d) Equal Opportunity Employer Vendor shall be an equal opportunity employer and shall conform to all Affirmative Action and other applicable requirements; accordingly, Vendor shall neither discriminate nor permit discrimination in its operations or employment practices against any person or group of persons on the grounds of race, color, religion, national origin, age, or sex in any manner prohibited by law.

e) Compliance with Rules and Regulations Vendor agrees that all persons working for or on behalf of Vendor whose duties bring them upon MCC's premises shall obey the rules and regulations that are established by MCC and shall comply with the reasonable directions of MCC's officers. MCC may, at any time, require the removal and replacement of any of Vendor's employees for good cause.

In the event of such a removal, the Vendor shall, within fifteen (15) days, fill this representative vacancy. Regardless of whom the Vendor has designated as the representative, the Vendor organization remains the ultimate responsible party for performing the tasks and responsibilities presented in this Agreement.

f) Site Damage Vendor shall be responsible for the acts of its employees and agents while on MCC's premises. Accordingly, Vendor agrees to take all necessary measures to prevent injury and loss to persons or property located on MCC's premises. Vendor shall be responsible for all damages to persons or property caused by Vendor or any of its agents or employees. Vendor shall promptly repair, to the specifications of MCC, any damage that it, or its employees or agents, may cause to MCC's premises or equipment; on Vendor's failure to do so, MCC may repair such damage and Vendor shall reimburse MCC promptly for the cost of repair.

g) In the Event of an Accident Vendor agrees that, in the event of an accident of any kind, Vendor will immediately notify the College’s Police Department and furnish a full written report of such accident if requested.

h) Non-interference with Institution Operations College's operations must continue uninterrupted throughout the completion of the work contemplated herein. Certain portions of the work must be performed and completed in such order as directed by MCC's representative as to permit the orderly operation of MCC's activities. Vendor shall review the work to assure that operations will not impede the utilization of the facilities.

i) Campus Identification Required Vendor and its employees are required, each day while work is being performed on campus, to check in with Campus Security and receive the necessary campus identification.

j) Responsibility for Personal Property MCC shall have no responsibility for the loss, theft, mysterious disappearance of, or damage to, equipment, tools, materials, supplies, and other personal property of Vendor, its employees, Subcontractors, or material persons.

k) Copyright Indemnity The awarded Vendor shall indemnify and hold MCC harmless from any claim that a product or accessory or its use, infringes on another person or company’s patent, copyright, trade secret or other property right.

l) General Indemnity To the fullest extent permitted by law, the Vendor shall indemnify, hold harmless, and defend Macomb Community College and its agents, employees, officers and successors, from and against any claims, causes of action, damages, losses and expenses, including but not limited to attorney’s fees, arising out of or resulting in any way from Vendor’s performance of this contract, provided that such claim, cause of action, damage, loss or expense is attributable to bodily injury, sickness, disease or death to any person, including employees or agents of the Vendor, subcontractor, or construction manager, or to injury to or destruction of tangible property including loss of use resulting there from, but only if caused in whole or in part by a negligent act or omission of the Vendor, a subcontractor, the construction manager, anyone directly or indirectly employed by them or any for whose acts they may be liable, regardless of whether or not such claim, cause of action, damage, loss or expense is caused in part by a party indemnified hereunder. Vendor shall not be obligated to hold harmless, indemnify or defend Macomb Community College or its agents, employees, officers, or successors if any claim, cause of action, damage, loss or expense arises from the sole negligence or fault of a party indemnified hereunder.

m) Submitting Disputes to Arbitration Should the parties agree to submit claims, disputes or other matters arising out of this Agreement to arbitration, they may do so only with the specific, written agreement of all parties, including Macomb Community College.

n) Advertising / Permission Vendor shall not use, in its external advertising, marketing programs, or other promotional efforts, any data, pictures, or other representation of MCC except on the specific written authorization in advance of MCC’s Purchasing Agent. Vendor will limit and direct any of its advertising on MCC’s premises to MCC’s student media and bulletin boards, and shall make arrangements for such advertising through the Student Activities Department. Vendor shall not install any signs or other displays anywhere on MCC's premises unless in each instance the prior written approval of MCC's Purchasing Agent has been obtained. However, nothing in this clause shall preclude Vendor from listing MCC on its routine client list for matters of reference.

o) Survival Clause The terms, conditions, representations, and warranties contained in this Agreement shall survive the termination or expiration of this Agreement.

p) Governing Law This Agreement, and all matters or issues collateral to it, shall be governed by, and construed in accordance with, the law of the State of Michigan.

q) Entire Agreement This Agreement constitutes the entire agreement between the parties and supersedes all prior agreements or understandings, written or oral, prior to signing of a contract.

r) Effect of Regulation Should any local, state, or national regulatory authority having jurisdiction over Macomb Community College enter a valid and enforceable order upon the College which has the effect of changing or superseding any term or condition of the Agreement, such order shall be complied with, but only so long as such order remains in effect and only to the extent actually necessary under the law. In such event, this Agreement shall remain in effect, unless the effect of the order is to deprive the College of a material part of its Agreement with the Contractor. In the event this order results in depriving the College of materials or raising their costs beyond that defined in the Agreement, the College shall have the right to rescind all or part of this Agreement (if such a rescission is practical) or to end the Agreement term upon thirty (30) days prior written notice to the Vendor. Should the Agreement be terminated under such circumstances, the College shall be absolved of all penalties and financial assessments related to cancellation of the Agreement.

s) Termination In the event that either party shall fail to maintain or keep in force any of the terms and conditions of this Agreement, the aggrieved party may notify the other party in writing via certified mail of such failure and demand that the same be remedied within ten (10) business days. Should the defaulting party fail to remedy the same within said period, the other party shall thereupon have the right to terminate this Agreement by giving the other party thirty (30) days written notice. Notwithstanding the foregoing, due to lack of State or County funding, MCC may at any time during the life of this Agreement, terminate same by giving thirty (30) days notice in writing via certified mail to Vendor. In addition, if at any time a voluntary petition in bankruptcy shall be filed against the Vendor and shall not be dismissed within thirty (30) days, or if the Vendor shall take advantage of any insolvency law, or if a receiver or trustee of the Vendor's property shall be appointed and such appointment shall not be vacated within thirty (30) days, MCC shall have the right, in addition to any other rights of whatsoever nature that it may have at law or in equity, to terminate the contract by giving (30) days’ notice in writing of such termination.

t) Assignment This Agreement or any part thereof shall not be assigned or subcontracted by Vendor without the prior written permission of MCC; any attempt to do so without said prior permission shall be void and of no effect.

u) Ownership of Documents All plans, studies, documents and other writings prepared by and for Vendor, its officers, employees and agents in the course of implementing this Agreement, except working notes and internal documents, shall become the sole property of MCC upon payment to Vendor for such work, and MCC shall have the sole right to use such materials in its sole discretion without further compensation to Vendor or to any other party.

v) Employment of Other Vendors, Specialists or Experts Vendor will not employ or otherwise incur an obligation to pay other vendors, specialists or experts for services in connection with this Agreement without the prior approval of MCC.

w) Warranty of Fitness for a Particular Purpose The College has presented detailed technical specifications of the particular purpose for which the network and technology is intended. The College has provided detailed descriptions and criteria of how the system can be defined to accomplish a particular purpose. The College has also defined the exact procedures and techniques to be employed in testing whether the system has achieved the defined performance of this particular purpose. Given this advanced preparation concerning, and documentation about the College’s particular purpose, the Vendor at the time this Agreement is in force has (1) reason and opportunity to know the particular purpose for which products are required, and (2) that the College is relying on the Vendor’s experience and knowledge of these products to provide those which are most suitable and appropriate. Therefore, the Vendor warrants that the system is fit for the purpose for which it is intended as described in this document.

x) Non-Collusion Covenant The Vendor hereby represents and agrees that it has in no way entered into any contingent fee arrangement with any firm or person concerning the obtaining of this Agreement. In addition, the Vendor agrees that a duly authorized Vendor representative will sign a non-collusion affidavit, in a form acceptable to the College that the Vendor firm has received from the College no incentive or special payments, or considerations not related to the provision of automation systems and services described in this Agreement.

y) Vendor Not an Agent of Institution Macomb Community College retains all rights of approval and discretion with respect to the projects and undertakings contemplated by this Agreement. Vendor, its officers, employees and agents shall not have any power to bind or commit MCC to any decision.

APPENDIX “A” – MANDATORY PROPOSAL RESPONSE FORM

TO: Macomb Community College July 25, 2025 14500 Twelve Mile Road Warren, MI 48088

ATTENTION: Purchasing Director

The contractor, in compliance with the Request For Proposal for Microsoft based MXDR (Managed Extended Detection and Response) Services, having examined the RFP documents and being familiar with the scope of required services, hereby proposes to furnish all labor and all IT services to provide work described herein in accordance with the RFP documents for the amounts stated below.

Contractor, if awarded a contract, agrees to commence work upon receipt of a written “Notice to Proceed/Letter of Intent” / Purchase Order and to fully complete the work in a mutually agreeable time. Contractor understands that the College reserves the right to reject any or all proposals and to waive any informalities therein.

Proposal pricing shall remain valid for 90 days from the RFP opening to allow for funding authorization and contract review/approval.

The criteria below may be expanded to provide more detail in the categories specified, if needed. All sections must be completed; respondents shall mark non-applicable or zero-cost fields with “0” (zero), N/A or “No Bid”.

Bid Alternates will only be accepted as a supplement to a Base Bid.

A.1 BASE BID: Microsoft MXDR Services

Base Bid pricing shall assume a 36-month contract, invoiced quarterly or monthly (vendor preference). Please complete all table entries and answer all questions.

A.1.1 Does your solution require installation of agent software? Check all that apply: [ ] Server [ ] PC [ ] None A.1.2 Define how your solution is licensed. Check all that apply:

[ ] By device/system [ ] by staff FTE [ ] by staff & student FTE [ ] other (describe): __________________________________________

A.1.3 – COSTS: Start-up, One-time & Implementation Services

One time, all inclusive, installation, set-up and configuration fee(s)
$
Configure the College’s SIEM (Microsoft Sentinel)
$

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .