Last updated: 23 July 2026. View change log.
This Schedule forms part of the IT Master Services Agreement between you and Cultrix Limited (“Cultrix”, “we”, “us”), and sets out the scope, responsibilities and limits that apply to administration and licensing support for cloud productivity platforms we manage.
These services include administration, configuration, licensing management, governance alignment, user lifecycle management, security controls, and ongoing support for supported cloud productivity tenants (for example Microsoft 365 and Google Workspace).
Cloud Productivity Platform Services are optional and only apply where they are included in your Order.
1. Service overview
Cloud Productivity Platform Services give you centralised management of your supported tenant(s), including user and licence administration, email and collaboration configuration, baseline security policies (where included in your package), and integration with incident, monitoring and backup tooling.
The service is designed to keep your cloud productivity environment secure, managed and aligned with what your organisation needs.
2. In-scope services
The following administration activities are included unless we state otherwise:
- User lifecycle management – creating, changing and removing user accounts;
- Licence assignment – assigning, removing and optimising licences in line with your subscription;
- Email configuration – mailbox creation, forwarding, groups/distribution lists, shared mailboxes (where supported), and related settings;
- Collaboration administration – workspace/team creation, membership changes and settings adjustments (for example Microsoft Teams or Google Chat/Spaces);
- File and sharing configuration – permissions and sharing controls aligned to your business structure (for example SharePoint/OneDrive or Google Drive);
- Baseline security & MFA – enforcing MFA and enabling and maintaining baseline security policies within the platform;
- Conditional access / context-aware access (Support + Shield and Guardian, where supported) – creating and managing access policies;
- Device compliance policies (where your package includes them, and where your licensing supports them);
- Monitoring and alerts – linking your tenant to managed SaaS monitoring and native security alerting for automated security event monitoring;
- Backup & retention – integration and monitoring of cloud-to-cloud backup for supported platforms (covered separately in the Backup and Recovery Schedule);
- Tenant optimisation – best-practice alignment around policies, permissions and data governance.
3. Supported environments
The service may apply to the following (as listed in your Order):
- Microsoft 365 business and enterprise plans (including standalone components such as Exchange Online and SharePoint Online);
- Google Workspace business and enterprise plans (including Gmail, Drive and related services);
- tenants linked to us for delegated administration (for example via partner/delegated access).
Where you get licences through us or an authorised cloud solution provider (CSP), we can usually manage licence assignment and optimisation directly. Where you source licences through a third party, our administration may be limited, depending on the permissions available.
4. Security configuration
We deliver security configuration in line with your support package and what the platform and licensing you use can do:
- Support – MFA enforcement and baseline security settings;
- Support + Shield – MFA, baseline security settings, access policy support (where supported), and device compliance policy support (where supported);
- Guardian – MFA, enhanced policies, access policies (where supported), and SIEM/SOC integration.
We can provide additional security work (for example advanced access rules, privileged access controls, or complex governance changes), but it may be chargeable depending on the complexity and licensing needed.
5. User onboarding and offboarding
- Onboarding includes account creation, licence assignment, MFA configuration and email setup;
- Offboarding includes disabling the account, retaining or transferring data, adjusting licences and reviewing access;
- additional actions (for example legal hold, data export or advanced eDiscovery) may be chargeable if they are not part of your plan or licensing.
Onboarding and offboarding of devices (rather than users) is covered in the relevant device support or patching schedules.
6. Licensing management
We manage licensing in line with your subscription. This includes:
- assigning and reclaiming licences;
- recommending ways to reduce unused or underused licences;
- helping with licence changes or renewals where you buy licences through us or an authorised provider;
- telling you when licences are incompatible with the security features you need.
You remain responsible for buying licences and keeping an active subscription unless we agree otherwise.
7. Monitoring and security alerting
To strengthen your security posture, we may connect your tenant to:
- SaaS monitoring platform – suspicious activity, failed logins, risky sign-in patterns and MFA anomalies;
- Native security tooling (where available and included) – alerts about malware, phishing attempts and policy violations;
- Security information and event management (SIEM) – event correlation across endpoints and cloud services;
- Managed security operations centre (SOC) – triage and escalation (where included in your plan).
We handle responses to alerts under the Incident Response Policy and, where appropriate, the IT Support or Security Services Schedules.
8. Customer responsibilities
- Keep active licences for the supported platform(s) you use.
- Make sure users follow MFA and password requirements.
- Tell us about changes in staffing so accounts and licences stay accurate.
- Avoid tenant-level changes that could disrupt security or administration.
- Tell us promptly about suspected compromise or unusual behaviour.
9. Service boundaries and exclusions
Cloud Productivity Platform Services do not include:
- support for third-party add-ins or integrations unless we agree it;
- content creation or management (for example Teams channels/SharePoint pages or Drive folder structures beyond basic permissions);
- line-of-business application support unless another Schedule specifies it;
- tenant-to-tenant migrations (available as projects);
- licence purchasing (unless through an authorised provider under separate agreements);
- security architecture, Zero Trust implementation, firewall rule design, segmentation work, policy creation, and any MDM/BYOD rollout, unless we agree it as a chargeable project.
10. Changes to this Schedule
We may update this Schedule to reflect platform changes or best practice. We will tell you about material changes with reasonable notice.