Active SLED Opportunity · MICHIGAN · OAKLAND UNIVERSITY
AI Summary
Oakland University seeks proposals to modernize its Identity and Access Management system, transitioning to an Entra ID-centered architecture with Banner as the system of record. Proposals due by August 20, 2026.
Oakland University (OU) is modernizing our Identity Access Management environment as we transition from legacy on-premises directory and authentication infrastructure toward an Entra ID-centered architecture. Banner is (and will remain) the primary system of record. Target-state direction: Entra ID becomes the primary authentication and directly backbone, Banner... **Solicitation Type**: RFP - Request for Proposal (Formal) **Source ID**: PU.AC.USA.2447854.C24187951 **Piggyback Contract**: No **Question Acceptance Deadline**: 07/20/2026 05:00 PM EDT **Questions are submitted online**: Yes **Bid Submission Type**: Electronic Bid Submission **Owner Organization**: University Technology Services **Solicitation Number**: FILE 00309 IAMM **Reference Number**: 0000429702 **Pricing**: In attached document **Bid Documents List**: | Item Name | Description | Mandatory | Limited to 1 file | |---|---|---|---| | Bid Documents | Documents defining the proposal | Yes | No | **Pre-Bidding Events**: Event: Prebid Conference | Date: 07/10/2026 01:00 PM EDT | Location: Zoom **Questions and Answers**: | Question | Answer | |---|---| | Section 5.01 states "The document shall be 8 1⁄2” x 11” format, no smaller than 11-point font, up to 35 pages, and should not contain unnecessary elaborate brochures or other presentations beyond those minimally required to present a complete and effective quotation. " Does the 35 page limit include the questions/answers from the Schedule C spreadsheet, as well as Schedules A, B, C and Terms and Conditions? | Answered in Addendum 2 | | 1. Which platforms currently host non-human identities in scope for governance — service accounts in Active Directory/389DS, Azure/Entra service principals and managed identities, AWS IAM roles, RPA tools (e.g., Automation Anywhere, which appears in your environment), scheduled batch jobs, API keys, or LLM/agent frameworks specifically?2. Approximately how many non-human identities exist today across these platforms, and is there an owner/inventory system currently tracking them, or is this itself part of the gap being addressed? | Answered in Addendum 2 | | 2. For REQ-1208 ("generates, assigns, authenticates, and manages... AI agents, LLM-driven workflows, and automated microservices") — does OU currently have any AI agents or LLM-driven workflows in production, in pilot, or only anticipated? | Answered in Addendum 2 | | For REQ-1209 ("prevents, detects, and restricts unauthorized automated or 'robotic' account activity") — is this primarily about credential misuse/compromised service accounts, or about detecting unauthorized creation of new automated identities (shadow automation)? | Answered in Addendum 2 | | Should non-human identities go through the same lifecycle model as sponsored/non-Banner human identities (owner, expiration, recertification), or does OU expect a distinct governance model for machine identities? Would OU want non-human identity behavior (usage patterns, access drift, anomalous activity) surfaced through the same reporting/certification workflows as human access, or through a separate dashboard/audience (e.g., security/SOC team via Splunk only)? | Answered in Addendum 2 | | Fewer than 50 admin-rights users and fewer than 10 IAM platform administrators (REQ-707) are referenced. Does that count include service/non-human privileged accounts (e.g., database service accounts, automation credentials), or human admins only? | Answered in Addendum 2 | | For REQ-705 (session recording, credential vaulting, check-in/check-out) — is OU open to PAM components integrated with the IGA platform, or is a single-vendor unified PAM+IGA platform required? | Answered in Addendum 2 | | Which systems specifically need PAM coverage at go-live vs. which are acceptable for a later phase? Do Linux/SSH, Windows/RDP, database admin, and cloud admin (Azure/AWS/Google) all mentioned in REQ-706, have equal priority? | Answered in Addendum 2 | | Is there an existing PAM tool anywhere in OU's environment today (even partial or deprecated) that the new solution needs to coexist with or replace? | Answered in Addendum 2 | | REQ-001/002 require higher-education references "with comparable hybrid complexity." Would OU consider references from adjacent regulated, complex hybrid-identity environments (e.g., large multi-entity financial institutions with equivalent directory/federation complexity) as partially responsive if paired with a clear discussion of transferable architecture patterns, or is higher-ed specifically non-negotiable? | Answered in Addendum 2 | | Is HECVAT submission expected as part of this RFP response, or only if shortlisted? Also, regarding REQ-1204 (semi-enclave for HIPAA/DOD/NIH research workloads), does OU currently have any research workloads with these requirements in production, or is this more an optional capability? | Answered in Addendum 2 | | Can OU confirm whether the two Active Directory environments (REQ-202) differ in forest/domain trust structure, schema, or are simply two independent AD instances? | Answered in Addendum 2 | | For 389DS/Red Hat Directory Server (REQ-201): is custom schema or custom ACI logic in use beyond standard LDAP object classes that a vendor should be aware of during discovery? | Answered in Addendum 2 | | Is Google Workspace expected to remain directly LDAP/SCIM-provisioned, or fully migrated to Entra-based authentication with the IGA platform only handling attribute governance (per REQ-204's framing of "Entra-based authentication to Google post-migration")? | Answered in Addendum 2 | | Is there a documented Splunk schema/CIM (Common Information Model) mapping OU expects vendors to conform to, or is schema design part of the vendor's proposed implementation? For OU's Splunk AI initiative (REQ-1102): is this an existing, running capability the platform's logs need to feed into, or a parallel initiative still being built out? | Answered in Addendum 2 | | Of the named populations (high school visitors, dual-enrolled, OCC dorm students, visiting scholars, vendors, volunteers), which currently has the largest volume, and which is the most operationally complex? Who are the expected "sponsors" in practice, individual faculty/staff, department heads, or a centralized office (e.g., Registrar, Research Administration), for each population? | Answered in Addendum 2 | | Regarding the ~150 fraudulent/ghost accounts identified, is there an existing fraud-detection effort or vendor OU has already evaluated, is this workstream expected to be delivered by the IAM/IGA vendor, or is OU open to a separate, complementary tool feeding signals into Splunk? Is "Meet Your Class" participation (REQ-1007) an OU-managed data source the vendor would simply consume via API, or something the vendor is expected to help integrate? | Answered in Addendum 2 | | What is the current state/fidelity of the existing Banner and IAM test environments referenced in REQ-1302: do they contain representative (anonymized) production-like data volumes, or data that would need supplementing for the POC? Is the July 31 Entra/Cirrus SSO cutover target (REQ-1307) already committed to another vendor or internal team, or does it depend in part on sequencing with this IGA/PAM procurement? | Answered in Addendum 2 | | Can OU clarify what qualifies as an acceptable "exception" to onshore-only support (REQ-006) , e.g., is after-hours triage by an offshore team acceptable if all data access and resolution authority stays onshore, or must all support staff be physically US-based regardless of function? | Answered in Addendum 2 | | REQ-014 lists cyber liability as "$[X]M" (placeholder never filled). Schedule B lists Cyber Risk Liability at $5M/$5M. Is REQ-014 also $5M, or higher? | Answered in Addendum 2 | | REQ-503 and REQ-504 have identical text but conflicting types (NOTE vs. HARD REQUIREMENT). Which controls? | Answered in Addendum 2 | | Section 8 has two REQ-904s (one on sponsored delegation, one on MSP audit evidence). Please renumber and confirm both are in scope. | Answered in Addendum 2 | | REQ-707 caps privileged users at "<50 admin-rights, <10 platform admins," but the pricing sheet asks for 100 PAM identities. Which count do we price to? | Answered in Addendum 2 | | FIDO2 quantity is written as "200 | 100 OTP time based / 100 YubiKeys." Is OU procuring 100 YubiKeys, and what's the OTP token type/vendor? | Answered in Addendum 2 | | Overview says ~16K FTE students / 17K in the workbook, but the pricing sheet uses 17K. Please confirm the authoritative FTE count. Same for total identities (75K vs. 85K referenced in 4/29 discovery). | Answered in Addendum 2 | | Section 1.02 requires a joint OEM + implementation-partner response. Can an SI serve as Prime with the OEM as Sub, or does OU require the OEM to be Prime? | Answered in Addendum 2 | | REQ-1307 references a "July 31 SSO migration target." Please confirm the year (2027?) given October 2026 contract start | Answered in Addendum 2 | | What is the current Duo contract term and expiration? This drives the Duo → Authenticator cutover window | Answered in Addendum 2 | | Is Pathify being retained long-term or retired after migration? The scope says "maintained through migration" but the end-state isn't stated | Answered in Addendum 2 | | Post-cutover, is Shibboleth being decommissioned entirely, or retained behind Entra/Cirrus for specific research apps? | Answered in Addendum 2 | | REQ-1208/1209 (agentic AI and non-human identity) are HARD REQUIREMENTS but no population, use case, or timeline is defined. Can OU provide expected count, current AI agent usage, and whether this is day-one or future-state readiness? | Answered in Addendum 2 | | Are Microsoft Entra ID P2 (or Entra Suite / ID Governance) licenses already in place across all 75K identities, or should vendors assume OU still needs to license them and price accordingly? | Answered in Addendum 2 | | Does OU have TeamDynamix iPaaS? | Answered in Addendum 2 | | Does OU require a Project Manager resource from the implementation partner? | Answered in Addendum 2 | | Will there be any onsite requirement as part of implementation? | Answered in Addendum 2 | | Will OU share the full ~600 application inventory (or at least the tiered priority list) before the response due date? Without it, migration effort estimates are guesswork. | Answered in Addendum 2 | | Of the ~500 Shibboleth-authenticated apps, what's the protocol split (SAML vs. CAS vs. OIDC vs. header-based)? | Answered in Addendum 2 | | Beyond Slate, which apps are in the priority tier for provisioning SLA (< 1 hour)? | Answered in Addendum 2 | | What is the Banner version, hosting model (Ellucian SaaS vs. self-hosted Banner 9), and database platform? Which Banner applications? | Answered in Addendum 2 | | Is the Ethos Integration API already licensed and in use, or would it need to be turned on? | Answered in Addendum 2 | | 389DS version and whether OU intends to keep it indefinitely or eventually migrate off Linux LDAP. | Answered in Addendum 2 | | Current forest/domain trust between the two on-prem AD environments, and target consolidation direction (single forest, single domain, or federation)? | Answered in Addendum 2 | | Current YubiKey deployment population and issuance process (self-service vs. desk-side)? | Answered in Addendum 2 | | How are sponsored accounts/non-affiliated OU users entered into your homegrown today? | Answered in Addendum 2 | | Preferred initial contract term (3 vs. 5 years) and whether OU wants firm-fixed or T&M for implementation. | Answered in Addendum 2 | | REQ-013 allows +/- 15% volume without re-pricing. Is that per-year variance from the baseline or cumulative across the contract term? | Answered in Addendum 2 | | Will OU accept implementation pricing on a fixed-fee basis with a documented scope-change process, or is T&M with NTE acceptable? | Answered in Addendum 2 | | Pcard is preferred, but for a multi-year TCO of this size, will OU accept ACH/wire for large annual licensing invoices? | Answered in Addendum 2 | | Does OU leverage Carahsoft as a procurement vehicle? | Answered in Addendum 2 | | Confirm OU's compliance framework mandates today (FERPA, GLBA, PCI) vs. aspirational (CMMC, NIST 800-171, HIPAA). REQ-1207 says framework is TBD, but pricing decisions on enclave tenants (REQ-1204) depend on this. | Answered in Addendum 2 | | Is the 35-page limit inclusive of Schedule A/B/C, cost workbook, VPAT, architecture diagrams, SLAs, sample SOW, and reference letters, or are those excluded from the count? | Answered in Addendum 2 | | What is the demo scoring rubric for the September 14 week, and will it be shared before demos? | Answered in Addendum 2 | | May vendors submit two priced options (e.g., a full IGA platform plus a lighter Entra-native alternative) as part of one response? | Answered in Addendum 2 | | Has the University formally selected Entra ID as the central access management platform for SSO and MFA, or are you open to evaluating alternative solutions? | Answered in Addendum 2 | | Is your HR authoritative source (Banner) deployed on‑premises or hosted in the cloud? | Answered in Addendum 2 | | Can you please confirm the target systems in scope for integration with the IGA solution? This includes any applications expected to receive automated birthright provisioning, baseline entitlements, or lifecycle workflows. | Answered in Addendum 2 | | The RFP references a total user population of 75,000. Can you please provide a breakdown of this population across key user types (e.g., students, staff, faculty, contractors, alumni)? | Answered in Addendum 2 | | Can you please outline the primary use cases you intend to address through a Privileged Access Management (PAM) solution? | Answered in Addendum 2 | | Are you expecting access reviews (attestation/certification campaigns) to be configured and implemented as part of this initiative? | Answered in Addendum 2 | | Do you permit the use of offshore resources (e.g., teams based in India) for implementation and ongoing support activities? | Answered in Addendum 2 | | Can you clarify the expected scope for migrating applications currently using Shibboleth, direct LDAP authentication, or other legacy access methods? Specifically, we would appreciate: - An inventory of applications in scope for integration with Entra ID, including approximate counts. - The authentication/authorization protocols each application currently supports (e.g., SAML, OIDC, OAuth, LDAP, etc.). - Whether the objective of this engagement is to fully migrate all in‑scope applications to Entra ID with MFA enabled, or if you are seeking an implementation partner to establish core onboarding patterns and enable your internal team to operationalize ongoing application migrations as part of long‑term BAU. | Answered in Addendum 2 | | Can you please clarify whether you require any Microsoft Entra licenses as part of this engagement, or if you already have the appropriate user licensing in place to support SSO and MFA for all in‑scope users and applications? | Answered in Addendum 2 | | The SOW states 600 applications in use at the university. Can you clarify if we need to consider all 600 applications in scope for implementation - for access management & IGA? Or is there a pilot count of applications we should consider? | Answered in Addendum 2 | | "For proposals where the core platform is provided directly by a large software publisher rather than a traditional reseller-model OEM, how does OU expect the required Prime/Sub or Joint Venture teaming documentation to be structured, given such publishers typically do not execute per-engagement teaming agreements?" Why it matters: This is the one open question that could affect whether a given submission structure is even compliant with the RFP's joint-proposal requirement. | Answered in Addendum 2 | | "The RFP references a minimum cyber liability aggregate coverage requirement, but the specific dollar figure appears to be a placeholder in the published document. Can OU confirm the actual required minimum aggregate limit?" Why it matters: This is a genuine blank in OU's own RFP. Getting a confirmed figure now avoids a late compliance surprise. | Answered in Addendum 2 | | "Given the RFP's own procurement schedule (contract commencement anticipated around October 2026), can OU confirm whether the stated July 31 SSO/federation migration target refers to July 31, 2027?" Why it matters: Prevents vendors from pricing and committing to a date that may be a full year earlier than OU intended. | Answered in Addendum 2 | | "Does OU currently have Ellucian's Ethos API/Ethos Integration licensed and deployed, or would that require separate procurement as part of this project?" Why it matters: Banner integration approaches commonly assume Ethos availability. If it isn't currently licensed, that is a real cost and timeline item that needs to be priced rather than assumed. | Answered in Addendum 2 | | "Can OU provide even a rough current estimate of non-Banner and sponsored populations (visiting scholars, dual-enrolled students, vendors, volunteers) so vendor pricing is not built on an unbounded assumption?" Why it matters: This population count is currently unconfirmed in the RFP; a rough number turns vendor estimates into something defensible rather than speculative. | Answered in Addendum 2 | | "Does OU currently hold Microsoft 365 E5, EMS E5, or standalone Microsoft Entra ID P1/P2 licensing that may already include identity governance entitlements relevant to this RFP's scope?" Why it matters: Avoids vendors proposing and pricing licensing OU may already own — a credibility point either way once evaluated. | Answered in Addendum 2 | | "Can OU provide additional detail on the “Meet Your Class” service referenced in the RFP, including the nature of the existing contract, so vendors can determine whether and how to integrate it as an additional fraud-detection signal?" Why it matters: The RFP notes a 3-year contract may already be in place for this service. That directly affects the fraud-detection design and isn't addressed anywhere in the original question set. | Answered in Addendum 2 | | "Beyond password reset, does OU's current custom password portal provide additional functionality — such as account unlock or username recovery — that vendors should account for in scoping a replacement?" Why it matters: Asking now, rather than waiting for post-award discovery, reduces the risk of a feature-parity gap surfacing after the legacy portal is already being retired. | Answered in Addendum 2 | | "Is OU's current Splunk Cloud subscription sized with sufficient ingest capacity for the additional identity and access management log volume this project will generate, does OU have an existing log schema or CIM standard vendors should align new log sources to, and is 13 months also OU's required retention period within Splunk itself, or does OU maintain a different retention policy vendors should design to?" Why it matters: Reduces risk of an unplanned capacity, schema-alignment, or retention-mismatch conversation surfacing mid-implementation. The retention clause was added because the RFP's 13-month minimum needs to be checked against OU's actual Splunk policy, not assumed. | Answered in Addendum 2 | | "Is any preliminary version of the prioritized application list referenced in the RFP available now, even in partial form, to support more accurate integration-method scoping in vendor proposals?" Why it matters: Application-by-application integration method (API/SCIM/batch/manual) materially affects both phasing and pricing. | Answered in Addendum 2 | | "Does the 35-page limit specified in the RFP's proposal requirements apply to the narrative proposal document specifically, or to the complete submission package including the Excel Solution Questionnaire and Pricing/TCO workbook?" Why it matters: Removes any ambiguity before final assembly of the submission package. | Answered in Addendum 2 | | Will an OEM authorization letter satisfy the OEM partnership requirement, or is a formal teaming agreement required with the proposal? | Answered in Addendum 2 | | 1. The RFP requires a joint proposal from an OEM and an authorized implementation partner. Can the implementation partner act as the Prime Contractor with the OEM as a subcontractor, or must the OEM be the Prime Contractor? 2. Is an OEM authorization letter sufficient for proposal submission, or is a formal teaming/joint venture agreement required? 3. Should software licensing be procured directly from the OEM, or can licensing be supplied and invoiced through the implementation partner as part of a single contract? 4. Please confirm Oakland University's current Microsoft licensing (e.g., Microsoft 365 A3/A5, Entra ID P1/P2, Entra Suite) that should be considered while preparing licensing and commercial pricing. 5. Can Oakland University provide a prioritized inventory of the approximately 600 in-scope applications, including authentication protocols (SAML, OIDC, LDAP, SCIM, OAuth, CAS) and migration priority, to support accurate implementation planning and pricing? 6. For items currently identified as TBD (AWS scope, Non-Banner identities, PAM users, Premium Connectors, Alumni population), should vendors use the preliminary quantities provided in Schedule C or propose their own sizing assumptions? 7.Please clarify the expected scope, duration, success criteria, acceptance criteria, and deliverables for the mandatory Proof of Concept phase. 8. Beyond the targeted July 31 Entra/Cirrus SSO migration milestone, is there an expected overall project completion date or preferred implementation duration for the complete IAM modernization program? 9. Should vendors assume Oakland University intends to procure optional managed services immediately following go-live, or should managed services be priced solely as an optional future capability? 10.Should the proposal include a single consolidated commercial response covering both OEM software and implementation services or should OEM licensing and implementation services be submitted as separate commercial aspect? | Answered in Addendum 2 | | Your T&Cs Acceptance page indicates that vendors must review and accept Oakland University's Terms and Conditions as stated on the University web page. Please provide the correct URL for the most up to date T&Cs. | Answered in Addendum 2 | | Please confirm whether the completed Supplemental Excel workbook constitutes the complete technical response, or whether vendors must also submit a separate narrative proposal covering the Plan of Action, Qualifications/Experience, implementation approach, and other requirements stated in Sections 3.01 through 3.04. | Answered in Addendum 2 | | Please confirm what all is included in the the 35-page proposal limit - signed RFP and schedules, W-9, insurance documentation, architecture diagrams, security documentation, references, resumes, and other supplemental attachments? | Answered in Addendum 2 | | Please confirm that diagrams, architecture drawings, implementation plans, and other supporting materials may be submitted as separate attachments in the supplemental PDF proposal and referenced by attachment name, page number, and figure number within the applicable Excel responses. | Answered in Addendum 2 | | Please identify all documents requiring an authorized signature, including the RFP Acceptance Acknowledgement, Schedule A, Schedule B, Schedule C, the pricing workbook, and any issued addenda. | Answered in Addendum 2 | | Does Oakland University require a separate redacted/public proposal copy? Additionally, may sensitive security materials, including SOC 2 reports and detailed architecture documents, be submitted separately and marked confidential or security-sensitive? | Answered in Addendum 2 | | With regards to Schedule C's Pricing tab, several of the formulas include TBD which is causing an error with value calculation and preventing the total tabulation in the TCO section. Can we remove the TBD if not applicable or alter the numbers in order to allow the table to correctly tabulate the costs? | Answered in Addendum 2 | | Please clarify whether the US-based, onshore-only requirement applies only to production support resources or also to implementation, professional services, engineering escalation, managed services, and other project resources. | Answered in Addendum 2 | | The RFP requires proposals to remain firm for 120 days and also states that unit prices and labor costs must be held for three years. Please confirm whether all pricing must remain unchanged throughout the three-year contract period or whether vendors may specify annual increases for Years 2 and 3. | Answered in Addendum 2 | | The pricing workbook requests both account-based and IPEDS/FTE-based pricing. Please confirm whether both models are mandatory and which model will be used for the evaluated three-year TCO. | Answered in Addendum 2 | | Section 6.08 states that residual rights to patents, licenses, and royalties may revert to Oakland University at the end of the agreement. Please confirm that this provision does not transfer ownership of the OEM’s pre-existing software, SaaS platform, tools, methodologies, or other intellectual property to Oakland University. | Answered in Addendum 2 | | Can the university confirm if external auxiliary attachments such as sample IAM dashboard views, visual weekly implementation report templates, and standalone technical vendor sheets are permitted as part of the electronic submission on BidNet Direct and if they count toward the strict 35-page proposal limit? | Answered in Addendum 2 | | Will Oakland University provide a formal confirmation of receipt through the portal or via email once the sealed electronic proposal is submitted? | Answered in Addendum 2 | | Since the addendum answering vendor questions is scheduled to be issued on July 21, 2026, which is the day after questions are due, will the university allow additional follow-up questions if the addendum introduces new identity-related technical or structural parameters? | Answered in Addendum 2 | | Does Oakland University expect the vendor to bundle and absorb the cost of all required third-party software licensing, subscription components, or OEM platform fees within the turnkey pricing model, or will the university procure the necessary Entra ID, Cirrus Identity Bridge, and target IAM platform licenses directly? | Answered in Addendum 2 | | Regarding the extension of MFA and strong controls to infrastructure access points like SSH, RDP, and Linux systems, what is the exact footprint, server count, or endpoint count that requires direct identity agent installation or proxy integration? | Answered in Addendum 2 | | For the non-traditional identities that do not have full ERP records, such as high school visitors, vendors, volunteers, and OCC students, is there a pre-existing database or software footprint used to track them today, or must the new IAM solution provide a standalone guest registration repository? | Answered in Addendum 2 | | Is the current Google Workspace and Microsoft 365 / Entra ID tenant structure consolidated under a single domain, or will the solution need to support multi-tenant synchronization and identity lifecycle management across disparate cloud environments? | Answered in Addendum 2 | | Schedule B outlines a requirement for 5,000,000 USD in Cyber Risk Liability and 5,000,000 USD in Professional Liability. Will the university permit the successful vendor to provide their standard baseline certificate of insurance at submission and finalize any tailored higher-limit policy endorsements post-award during final contract execution? | Answered in Addendum 2 | | The RFP states that the Prime contractor shall be wholly responsible for the total performance of the contract, including all OEM hardware/software and vendor services. Will Oakland University allow mutual indemnification or liability caps to be negotiated during the final contract phase? | Answered in Addendum 2 | | Given that the university complies with the Michigan Freedom of Information Act (FOIA), what specific protocols should the vendor follow within the electronic PDF submission to ensure that proprietary identity architectures or commercial pricing structures are explicitly marked as exempt from public disclosure under Section z? | Answered in Addendum 2 | | Please provide the total number of active identities by user type (faculty, staff, students, alumni, guests, contractors, sponsored identities, application administrators, visiting faculty/students, and other non-traditional identities). Additionally, how many identities are provisioned and deprovisioned annually, and are there seasonal spikes (such as semester start/end) that significantly increase authentication or provisioning activity? | Answered in Addendum 2 | | What identity repositories currently exist (Entra ID, Active Directory, LDAP, Google Workspace, Banner, or others), and which repository serves as the authoritative source for each identity type? Are identity attributes maintained across multiple repositories? | Answered in Addendum 2 | | What is the current identity retirement process for departing users? Are identities deleted, disabled, or moved into a separate organizational unit or archive? Does the university require continued authentication access for alumni or retirees, and if so, for how long? | Answered in Addendum 2 | | What username and email naming standards are currently in use, and how are duplicate or conflicting usernames managed? | Answered in Addendum 2 | | Approximately 600 applications are identified within the IAM environment. Can the University provide a breakdown by authentication protocol (SAML, OIDC, CAS, LDAP, Active Directory, header-based authentication, or other proprietary methods)? Additionally, how many applications require migration versus simple integration? | Answered in Addendum 2 | | Are there any applications currently utilizing legacy authentication mechanisms (such as header-based authentication or custom authentication methods) that require modernization or special migration planning? | Answered in Addendum 2 | | Banner is identified as the system of record. Are existing API integrations available for Banner, or will the vendor be responsible for rebuilding current integrations, including Axiom, Argos, GoAnywhere, and other automated provisioning workflows? | Answered in Addendum 2 | | What lifecycle automation capabilities currently exist for provisioning, deprovisioning, password management, and role management? Are there documented workflows for the existing custom tools and scripts (PHP, Perl, Java) that will be retired as part of this project? | Answered in Addendum 2 | | Does the University expect the selected vendor to provide ongoing operational support for identity automation workflows, including routine maintenance, conflict resolution, workflow enhancements, and operational administration following implementation? | Answered in Addendum 2 | | Does the University anticipate moving toward a fully passwordless authentication strategy during the lifecycle of this solution? If so, what is the anticipated timeline? | Answered in Addendum 2 | | Which MFA methods are expected to be supported (Microsoft Authenticator, FIDO2 security keys, passkeys, biometrics, SMS, or others), and are there user populations requiring different authentication methods? | Answered in Addendum 2 | | Please provide the estimated number of concurrent users during: Normal operating periods Peak periods, including back-to-school Please also confirm whether “concurrent users” refers to authenticated users, active sessions, or total simultaneous transactions. | Answered in Addendum 2 | | What infrastructure systems (Windows servers, Linux servers, SSH, RDP, VPN, network devices, privileged systems, etc.) require MFA integration, and approximately how many systems or endpoints are included? | Answered in Addendum 2 | | Which SIEM platform currently receives authentication and identity logs, and are there any specific logging, monitoring, or compliance requirements that the IAM solution must support? | Answered in Addendum 2 | | Is the University's Microsoft 365/Entra ID and Google Workspace environment managed within a single tenant/domain, or must the IAM solution support synchronization across multiple tenants, forests, or domains? | Answered in Addendum 2 | | For guest users, contractors, vendors, OCC students, volunteers, and other non-traditional identities, does the University currently maintain a dedicated registration repository, or should the new IAM platform provide guest identity registration and lifecycle management capabilities? | Answered in Addendum 2 | | Will Oakland University procure all required software licensing (such as Microsoft Entra ID, Cirrus Identity Bridge, and the selected IAM platform), or should vendors include all software, subscription, and OEM licensing costs within their turnkey proposal pricing? | Answered in Addendum 2 | | Does the University have a preferred implementation schedule, blackout periods, or mandatory production deployment windows that vendors should incorporate into their project plans? | Answered in Addendum 2 | | Will all of the answers to all of the questions be available to all vendors? | Answered in Addendum 2 | | What Microsoft Entra ID licensing does Oakland University currently hold (for example, Entra ID P1/P2, Entra ID Governance, or Entra Suite)? | Answered in Addendum 2 | | For each of the three areas — lifecycle automation, access governance and certification, and privileged access — does OU intend to rely on native Entra ID Governance, a separate commercially-supported IAM platform, or a combination? | Answered in Addendum 2 | | Should this proposal include all three capability areas — authentication/Entra, identity governance and lifecycle, and privileged access management — even if delivered in stages, or are one or more out of scope for this response? | Answered in Addendum 2 | | Which objectives in this RFP are OU's highest priorities for this engagement, and are there any that are lower priority or could be deferred? | Answered in Addendum 2 | | How many OU IAM administrators and technical staff will be dedicated to this project, and for activities such as SSO configuration and migration, user acceptance testing, and data cleansing, does OU expect the integrator to deliver end-to-end or to co-deliver with OU staff? | Answered in Addendum 2 | | Of the approximately 600 in-scope applications (roughly 500 currently behind Shibboleth), how many is OU targeting for migration in this engagement versus later phases, and will OU provide an application inventory identifying each application's authentication protocol and integration method? | Answered in Addendum 2 | | Is Cirrus Identity Bridge already deployed and licensed at Oakland University, or is implementing it part of the scope of this project? | Answered in Addendum 2 | | Is there a single reliable unique identifier (for example, a university ID) consistently present across Banner, 389DS, both Active Directory environments, and Google Workspace? And approximately how many identities hold multiple affiliations (for example, staff who are also students)? | Answered in Addendum 2 | | What is the known volume of duplicate or orphaned accounts requiring remediation before migration? | Answered in Addendum 2 | | Are the current provisioning and deprovisioning business rules documented, or will replacing the 20-year-old custom system require reverse-engineering the embedded logic? | Answered in Addendum 2 | | Is there a current audit finding, regulatory requirement, or internal control mandate driving the access certification and segregation-of-duties requirements? | Answered in Addendum 2 | | At go-live, approximately how many segregation-of-duties conflict rules does OU expect to enforce, and how many applications and which populations are in the first access certification campaign? | Answered in Addendum 2 | | Credential vaulting and session recording (REQ-705) are tagged a Hard Requirement in the Project Scope tab, but treated as optional, separately-priced items in the Solution Questionnaire (Section 8.02) and the Pricing tab. Is full privileged access management — vaulting, session recording, and coverage of SSH/RDP/database/cloud admin — a hard requirement or an optional priced tier? | Answered in Addendum 2 | | Is management of non-human and machine identities — service and application accounts, SSH keys, database and integration credentials, and secrets embedded in the legacy code slated for retirement — in scope for this project? If so, can OU estimate the size of that credential surface beyond the approximately 50 privileged admin users? | Answered in Addendum 2 | | Alumni and non-Banner / sponsored populations are both listed as to-be-determined. Which alumni are in scope for identities and MFA, and at what lifecycle stage (for example, at graduation or on request)? And what is the approximate magnitude of the sponsored population (high school visitors, dual-enrolled students, visiting scholars, vendors, volunteers, and guests)? | Answered in Addendum 2 | | After go-live, is OU interested in a managed operations and support model, or does it plan to operate the platform in-house? | Answered in Addendum 2 | | For the applicant and continuing-education fraud problem (approximately 150 ghost accounts), does OU expect identity proofing at the admissions front door — for example, third-party document/ID verification or device and behavioral fraud signals — or is enhanced authentication on existing accounts the intended approach? | Answered in Addendum 2 | | Does Oakland intend the selected vendor to provide the long-term identity data store (meta-directory) itself, or will Entra ID serve as the authoritative directory with meta-directory capabilities supplied by Microsoft? | Answered in Addendum 2 | | Please confirm the current Banner provisioning interface method (file drops, API, Banner Event Publisher, etc.) and whether real-time change events are in scope. | Answered in Addendum 2 | | Approximately how many of the ~600 in-scope applications rely on Shibboleth SAML versus direct LDAP binds, and should the vendor plan to replace Shibboleth entirely or maintain it for federation edge cases? | Answered in Addendum 2 | | For pricing comparison, what is the total unique user population (students, faculty, staff, alumni, guests) that must be licensed for MFA on day 1, and are alumni expected to require MFA? | Answered in Addendum 2 | | Please confirm that FedRamp is required or if SOC II Type II will suffice. | Answered in Addendum 2 | | Are both pricing models, account and FTE required or just one method. Some vendors only provide one approach to pricing. | Answered in Addendum 2 | | Confirm that you require vendor provide an authoritative source for those that do not exist in Banner. Also, please provide the number of individuals this would entail. | Answered in Addendum 2 | | Section 6.01 refers vendors to Oakland University’s General Terms and Conditions for Agreement through the “OU Terms & Conditions” link. However, the hyperlink provided in the RFP PDF is not active and does not provide a web address. Please provide a working link to, or a copy of, the complete Terms and Conditions applicable to this solicitation. | Answered in Addendum 2 | | The RFP differentiates between managing 'traditional machine identities and autonomous Agentic AI identities' (REQ-1208) and preventing 'unauthorized automated or robotic account activity' (REQ-1209). Can Oakland University clarify if the requirement for detecting and restricting unauthorized robotic activity extends to specific User and Entity Behavior Analytics (UEBA) or advanced bot detection capabilities, distinct from the governance of known and legitimate AI agents? | Answered in Addendum 2 | | If non-human identities are in scope, machine and AI, can you please provide the number of non-human identities to be governed? | Answered in Addendum 2 | | The workbook lists Total Identities as 75,000 while referencing ~85,000 from the 4/29 discovery session, and FTE Students as 17,000 while referencing ~16,000 from discovery. Please confirm the correct figures so all vendors price against the same baseline. | Answered in Addendum 2 | | OU has stated a preference for one professional services organization to own the full Entra + IGA + PAM solution. If the IGA and PAM capabilities are provided by different OEM products but delivered and supported under a single accountable implementation partner, does that satisfy this requirement — or must the underlying software itself come from one OEM? | Answered in Addendum 2 | | Does Banner currently expose an Ethos API for identity attribute consumption, or is the existing integration pattern limited to database read / file feed? Please confirm which options are licensed/enabled today. | Answered in Addendum 2 | | What Microsoft 365 / Entra ID licensing tier does OU currently hold (E3 vs. E5, Entra ID P1 vs. P2)? This determines which target-state capabilities (e.g., Entra ID Governance, PIM) are already licensed versus need to be added to the proposed solution. | Answered in Addendum 2 | | Is there a target or budgeted hypercare support duration post go-live, or should vendors propose their own standard recommendation for this scale of deployment? | Answered in Addendum 2 | | Does the synchronization set up between local AD and EntraID today? | Answered in Addendum 2 | | REQ-014 references the cyber liability insurance coverage limit of “$X million.” Please confirm the exact required limit and whether the $5 million per occurrence and $5 million aggregate limits stated in Schedule B are applicable. | Answered in Addendum 2 | | Regarding Proposal Formatting Constraints: Can the University confirm that the required Excel attachments (Schedule C - Solutions Questionnaire and Schedule C - Cost Proposal) are excluded from the 35-page narrative response limit specified in Section 5.01? Given our heavy investment in the Microsoft ecosystem, how much weight should we assign to Microsoft’s native IGA, PAM, and Identity Threat Protection capabilities in your vendor scoring? Regarding Key Personnel Documentation: Section 3.03 details requirements for showing experienced and capable personnel. May comprehensive project team resumes (Enterprise Architect, Technical Lead, Project Manager) be included as an appendix, and will they count against the maximum 35-page threshold? "The RFP states that Oakland University requires a joint proposal from an OEM and an authorized implementation partner, with one designated as the Prime. Our organization is the OEM and we intend to deliver the project services directly via our internal Professional Services organization. However, our corporate public sector go-to-market structure precludes us from contracting directly as the Prime. To satisfy your requirement for single-point accountability, would Oakland University accept a model where an authorized Value-Added Reseller (VAR) acts as the Prime contractor, while we (the OEM) act as the Subcontractor delivering both the technology and the professional implementation services? In this scenario, the Prime would still assume full contractual responsibility for total performance as required." Regarding Core ERP Migration Roadmaps: While Ellucian Banner remains the system of record for this project (REQ-9001), does the University have a formalized roadmap to migrate to a cloud-native ERP/SIS (e.g., Banner SaaS, Workday Student) within the 3-year TCO horizon of this contract? | Answered in Addendum 2 | | Regarding Cloud and Architecture Form Factors: Given the requirement to maintain on-premises 389DS LDAP directories for Linux authentication (REQ-9002), is the University prioritizing a 100% cloud-native architecture that orchestrates down to on-prem agents, or will hybrid/on-prem private cloud software form factors be considered? Regarding 389DS: Other than Linux authentications, what other systems directly read and / or write to the Directory? Regarding Extension & Satellite Campus Scope: Does the scope of this modernization include independent regional campuses, satellite facilities, or academic extensions that operate isolated Active Directory forests, distinct Student Information Systems, or separate domains? Regarding Supplementary Identity Stores: Outside of the directories and systems listed in the environment reference table, are there other centralized data warehouses, database clusters (e.g., Oracle, SQL Server), or identity registries that the platform must sync with to enforce attribute governance? Regarding Active Directory Topography: Regarding the two Active Directory environments in scope (REQ-202): Are these separate domains within a single forest, or entirely isolated forests? Additionally, do these environments utilize deeply nested Organizational Unit (OU) structures that govern group policies, or are they flattened? Regarding Identity Reconciliation Complexity: Does the University currently experience high rates of duplicate identity generation across Banner, 389DS, and Active Directory due to users holding concurrent roles (e.g., a student who is hired as a staff member)? Regarding Native Password Migration Capabilities: To ensure a seamless password migration pattern without forcing a campus-wide password reset, what hashing algorithms (e.g., bcrypt, SHA-256, SSHA) are currently used within the 389DS and custom Java/PHP environments? | Answered in Addendum 2 | | Regarding Pathify Portal Federation Boundaries: The current-state matrix notes a Pathify SSO portal exposing 50+ application tiles. Post-migration, will Pathify federate directly with Entra ID as its upstream identity provider, or is the proposed IAM engine expected to act as the primary identity provider for the Pathify interface? | Answered in Addendum 2 | | Regarding Authentication Policy Orchestration: The RFP notes a target-state direction utilizing Microsoft Authenticator for the general population. Will the University accept an architecture where the proposed IAM engine acts as the central policy orchestrator, letting users utilize Microsoft Authenticator, FIDO2 security keys, and Windows Hello interchangeably based on access context? | Answered in Addendum 2 | | Regarding Legacy and RADIUS Authentication Context: Outside of the 7,500 licensed Duo users and Microsoft Authenticator endpoints mentioned, are there any legacy token systems, RADIUS-based authentication arrays, or physical security key registries (e.g., YubiKeys) that must be integrated into the new architecture on day one? | Answered in Addendum 2 | | Regarding Endpoint and Virtual Workspace Architecture: To assist in configuring context-aware and risk-based access policies, what Endpoint Management (MDM/UEM) systems (e.g., Microsoft Intune, Jamf) and VDI environments (e.g., VMware Horizon, Citrix) are currently in production, and what approximate device operating system breakdowns should be assumed? | Answered in Addendum 2 | | Regarding Desktop Login Controls Extension: Is extending multi-factor authentication down to local workstation desktop logins (Windows, macOS, ChromeOS) a requirement under the infrastructure access scope defined in REQ-401? | Answered in Addendum 2 | | Regarding Architecture and Hybrid Estate Fit: Are the 600 integrated applications currently integrated via SAML, OIDC, or something else? | Answered in Addendum 2 | | Regarding Current Standing Privilege Models: Section 6 notes that privileged access is a current control gap. Are administrative privileges across your 350 Linux and 350 Windows servers currently managed via localized accounts and standing Active Directory groups, or is there an existing legacy vaulting system in place? | Answered in Addendum 2 | | Regarding Privileged Account Vaulting Metrics: Regarding REQ-707 (PAM itemized options): To ensure accurate pricing for the optional PAM modules, what is the approximate baseline count of targeted local root/administrator accounts, server connection endpoints, and interactive non-human service accounts that require credential vaulting or rotation? | Answered in Addendum 2 | | Regarding Ephemeral and Just-in-Time Controls: Regarding REQ-703 (Just-in-Time elevation): Is the University looking to completely eliminate standing local administrator privileges on infrastructure endpoints by implementing ephemeral, short-lived certificates or dynamic session elevations via the proposed solution? | Answered in Addendum 2 | | Regarding Non-Human Machine Secret Scopes: Does the scope of the infrastructure and privileged access management platform require governance over programmatic machine-to-machine secrets, API keys, and automated backup service credentials, or is it restricted to human administrative interactions? | Answered in Addendum 2 | | Regarding Security Signal Ecosystem Ingestion: To effectively address the admission/financial aid fraud pattern described in Section 11: What perimeter security platforms (e.g., Cloudflare, Palo Alto Networks) and Endpoint Detection & Response (EDR) agents are deployed today that can feed security telemetry and risk signals directly into the IAM threat engine? | Answered in Addendum 2 | | Regarding Real-Time Continuous Session Revocation: Regarding REQ-1004 (Splunk Integration) and the target for continuous session revocation: Is the University seeking a platform capable of processing continuous risk signals to trigger automated, real-time session termination across both Microsoft and non-Microsoft SaaS environments simultaneously when a compromise signal is identified? | Answered in Addendum 2 | | Regarding Agentic AI Lifecycle State: Regarding REQ-1208 (Agentic AI identities): Can the University clarify if there are active production instances of autonomous AI workflows or LLM API agents that require identity assignment and governance on day one, or is this requirement strictly evaluative for future state capabilities? | Answered in Addendum 2 | | Regarding Non-Microsoft System Vulnerabilities: What is the most business-critical, high-impact workforce system outside the Microsoft stack that, if compromised, would disrupt university operations, and what perimeter or session-level isolation security mechanisms protect it today? | Answered in Addendum 2 | | Regarding Existing Governance Baselines: Outside of the legacy custom Java/PHP/SQL provisioning scripts, does the University utilize any commercial toolsets today to execute access certifications, or are these campaigns currently manually processed via spreadsheets? | Answered in Addendum 2 | | Regarding External ITSM Orchestration Scope: Regarding REQ-603 (Access Request Workflows): Is integration with an external ITSM platform (such as TeamDynamix or ServiceNow) a day-one implementation requirement, or should vendors configure access requests using the IAM platform’s native portal interfaces? | Answered in Addendum 2 | | Regarding Deep Application Provisioning Tiers: Out of the ~600 in-scope applications, how many require advanced automated provisioning capabilities (SCIM, custom API connectors) versus standard Single Sign-On federation (SAML 2.0, OIDC)? | Answered in Addendum 2 | | Regarding Authoritative Sponsor Repositories: Regarding Sponsored Identities (REQ-901): Does an authoritative external registry or database of approved campus sponsors exist today, or should the proposed platform provide the core repository and interface to designate and govern who can act as a sponsor? | Answered in Addendum 2 | | Regarding Operational State Transition Grace Periods: Regarding automated deprovisioning (REQ-505): What are the approved operational grace periods for account state changes across your major populations (e.g., Applicant-to-Student transitions, Employee separations, and Student-to-Alumni graduations)? | Answered in Addendum 2 | | Regarding Fixed-Fee Professional Services Mitigation: Given the 20 years of custom legacy code and technical debt to be retired (REQ-509, REQ-805), will the University accept a Milestone-Based or phased fixed-fee pricing structure tied to explicit project gates (e.g., separating Discovery/Design from Build/Deployment), rather than a single lump-sum fixed fee for the entire deployment? | Answered in Addendum 2 | | Regarding Volume Flexibility Adjustments: Can the University confirm that the +/- 15% volume range flexibility outlined in REQ-013 applies strictly to recurring software/platform licensing, and that any change in actual application counts or directory endpoints that alters the deployment scope will be handled via a standard change-order process? | Answered in Addendum 2 | | Regarding Finalist Presentation Modality: Regarding Section 4.02 (Presentations), will the finalist vendor demonstrations scheduled for the week of September 14, 2026, be conducted completely virtually via Zoom, or should vendors prepare for on-site presentations at the Rochester, MI campus? | Answered in Addendum 2 | | Regarding Capital Allocation Visibility: To assist vendors in proposing an appropriately sized implementation team and matching licensing model, can the University share the approved budget range or capital allocation for this IAM modernization initiative? | Answered in Addendum 2 | | Regarding "TBD" Quantities on the Pricing Tab: Several critical identity populations—specifically Alumni Identities and Non-Banner Sponsored Identities (REQ-901)—are marked as "TBD" in the environment reference table. Because implementation scope scales heavily based on user directories, what baseline or maximum account counts should vendors assume for these populations when calculating the implementation effort? | Answered in Addendum 2 | | Regarding Ongoing Managed Services Sizing: Regarding Ongoing Managed Services (Section 5): If the University opts for the optional vendor-managed service tier (REQ-1401), will the University accept a tiered monthly recurring cost (MRC) model based on ticket volume and integration complexity, or is this expected to be a flat-rate fixed fee? | Answered in Addendum 2 | | Regarding Dynamic Peak Concurrency Sizing: To ensure adequate scale and architecture resilience during peak academic periods (e.g., fall enrollment), what is the maximum expected volume of concurrent identity creations and group membership updates generated within a single 24-hour window? | Answered in Addendum 2 | | Regarding Business Logic Readiness: Regarding REQ-501 and the "Pseudo Workflow" context: Is the provided workflow documentation future or current state? Will the University provide documented Joiner/Mover/Leaver business logic maps during the project kickoff, or should the implementation scope include a comprehensive business process re-engineering phase to define these rules from scratch? | Answered in Addendum 2 | | Regarding the daily morning sync that says it is run manually now while broken. This appears to be a sync from LDAP to Perfections. Is there a limiting reasoon in Perfections that this cannot be real time update to users as they are updated? or Must it be a daily batch? What is the API to update Perfections? is it SCIM, LDAP, Rest API or something else? | Answered in Addendum 2 | | Regarding the sync into ADMNET, what APIs or protocols are used to provision to ADMNET? SCIM, LDAP, Rest API, Other? | Answered in Addendum 2 | | Please confirm that Fedramp is required or if SOC II Type II will suffice. | Answered in Addendum 2 | | Are both pricing models, account and FTE required or just one method. Some vendors only provide one approach to pricing. | Answered in Addendum 2 | | Confirm that you require vendor provide an authoritative source for those that do not exist in Banner. Also, please provide the number of individuals this would entail. | Answered in Addendum 2 | | The RFP differentiates between managing 'traditional machine identities and autonomous Agentic AI identities' (REQ-1208) and preventing 'unauthorized automated or robotic account activity' (REQ-1209). Can Oakland University clarify if the requirement for detecting and restricting unauthorized robotic activity extends to specific User and Entity Behavior Analytics (UEBA) or advanced bot detection capabilities, distinct from the governance of known and legitimate AI agents? | Answered in Addendum 2 | | If non-human identities are in scope, machine and AI, can you please provide the number of non-human identities to be governed? | Answered in Addendum 2 | | One of the project goals is to, "Support identities for people who are not traditional Banner users (high school visitors, dual-enrolled students, visiting scholars, OCC students in dorms, vendors, volunteers) without requiring full ERP records, while still controlling their access." a. Can you describe how these external user groups are being onboarded now? b. Where are their records, where are the ends of contracts tracked for them, and are they being identity-proofed in any way: | Answered in Addendum 2 | | Req 605 reads that, "Platform must support segregation-of-duties (SoD) controls and conflict detection." a. Which systems are subject to audit requirements that require SOD controls? Do you have existing rulesets and controls defined for FERPA/HIPAA/PCI or COBIT standards for all systems subject to GRC-type audits? b. If so, where are those rules? Do you have an existing GRC tool? Or do you need complete rules installed (if so, for which systems?)? | Answered in Addendum 2 | | Approximately 600 applications are referenced in the RFP. Please clarify: o How many applications are in scope for: Provisioning/deprovisioning SSO/Federation Access governance MFA enforcement o Are all applications expected to be integrated, or only a prioritized subset during initial implementation phases? o What are the required application counts by implementation phase? Please provide a detailed application inventory, including: o Application name o Application owner o Business criticality o User population o Authentication protocol (SAML, OIDC, LDAP, etc.) o Provisioning method o Authoritative source o Retain, replace, or retire designation Is the awarded supplier expected to: o Inventory all applications? o Implement governance controls for all applications? o Migrate authentication for all applications? o Automate provisioning for all applications? o Or only integrate a prioritized subset? | Answered in Addendum 2 | | What are the current and projected identity populations for: o Applicants o Students o Faculty o Staff o Alumni o Contractors o Sponsored affiliates o Vendors o Volunteers o Guests o Shared accounts o Service/workload identities o Privileged accounts What system serves as the authoritative source for each identity population? How should overlapping personas be managed (e.g., student + employee, alumni + contractor, faculty + researcher)? Which populations require: o Lifecycle automation o MFA o Access governance o Recurring licensing What lifecycle events must be automated, and what SLAs are required for: o Joiner o Mover o Leaver o Leave of absence o Graduation o Contractor expiration o Affiliate sponsorship expiration | Answered in Addendum 2 | | What Banner version is currently deployed? What is the Banner deployment model (on-premises, hosted, SaaS)? What integration methods are available? • APIs • Events • Database access • Flat files • Ellucian integration services What database, API, and event-generation capabilities are available? Are there existing custom workflows, scripts, or integrations that must be replaced or preserved? Please provide an inventory of current customization technologies, including: • PHP • Perl • Java • UC4 • Axiom • Argos • GoAnywhere • Database jobs • File feeds • Password/account management processes Which existing integrations include: • Source code • Documentation • Identified support owners • Non-production testing environments | Answered in Addendum 2 | | What Microsoft licensing currently exists? • Microsoft 365 Education licensing • Entra ID P1 • Entra ID P2 • Entra ID Governance • Entra Suite • Privileged Identity Management (PIM) What governance capabilities are mandatory versus optional? • Access reviews • Access requests • Approvals • Entitlement management • Role mining • RBAC • Separation of duties • Access certifications • Just-in-time access Are privileged accounts included in scope? If privileged accounts are included, are any of the following required? • PAM • PIM • Credential rotation • Session monitoring • Privileged account vaulting What identity risk management, fraud detection, SIEM integration, audit reporting, and log retention requirements exist? | Answered in Addendum 2 | | What is the current Duo user population? Which user populations must migrate to Microsoft Authenticator? How should the solution address: • Users without mobile devices • Hardware token users • Shared accounts • Break-glass/emergency access accounts • Alumni • Guests • Accessibility requirements • Account recovery requirements Please quantify the Linux/SSH environment that currently relies on Duo: • Number of systems • Number of users • Administrative groups • Access paths Is the supplier expected to redesign this capability or simply preserve it? | Answered in Addendum 2 | | Please provide the number of: • SAML applications • OIDC applications • CAS integrations • Shibboleth integrations • InCommon federation integrations Which federation relationships must be preserved versus modernized? Is Cirrus Identity Bridge: • Mandatory • Preferred • Optional • Replaceable by an equivalent solution? Would a Microsoft-native Entra-based solution proposed by an authorized Microsoft partner satisfy requirements, or is a separate IAM/IGA platform expected? What constitutes an acceptable OEM and authorized implementation partner response? | Answered in Addendum 2 | | What FERPA requirements must be met? What accessibility standards are required? What data retention requirements apply? What audit and compliance reporting requirements exist? What data handling restrictions apply to implementation resources? Are there production data access limitations? What are the required: • Availability targets • RTOs • RPOs • Disaster recovery objectives • Campus outage operating requirements • Service continuity expectations • Data residency requirements | Answered in Addendum 2 | | What does project success look like from the university's perspective? What are the acceptance criteria for: • Architecture • Lifecycle automation • Provisioning • Governance • Federation • MFA migration • Application integrations • Data conversion • Testing • Documentation • Training • Production readiness Does the October 2026 date represent: • Contract award • Contract commencement • Project kickoff • Start of implementation services • Production go-live Please provide: • Desired project phases • Milestones • Dependencies • Required completion dates What university resources will participate in the project, and what level of availability is expected from: • Banner team • IAM team • Security team • Networking team • Application owners • Help desk • Testing resources • Project governance resources | Answered in Addendum 2 | | What post-production support period is required? | Answered in Addendum 2 | | What period should be used for Total Cost of Ownership calculations? • 3 years • 5 years • 7 years • Other How will out-of-scope requests be handled during the engagement? Can changes outside the agreed base scope be handled through a formal change order process? | Answered in Addendum 2 | **Addendums**: | Addendum | Date | Note | |---|---|---| | Addendum No. 1 | 07/22/2026 11:13 AM EDT | | | Addendum No. 2 | 07/28/2026 11:57 AM EDT | |
SLED stands for State, Local, and Education. These are solicitations issued by state governments, counties, cities, school districts, utilities, and higher education institutions — as opposed to federal agencies.
SamSearch Platform
AI-powered intelligence for the right opportunities, the right leads, and the right time.