This Appendix describes the scope and features of the MANAGED CMMC ENCLAVE services offered by Intech Hawaii. This Appendix is incorporated by reference into the Services Guide and is subject to all terms and conditions of the Services Guide and the Master Services Agreement ("MSA"). Only the specific services listed in your Quote will be provided; all other services described in this Appendix are available but not included unless expressly added to your Quote. Intech Hawaii reserves the right to update this Appendix from time to time to reflect changes in available services; material changes that negatively impact services already included in your Quote will be communicated to you by email.
MANAGED CMMC ENCLAVE
Managed CMMC Enclave provides an isolated, cloud-hosted environment on Microsoft Azure Government (GCC High) for handling Controlled Unclassified Information (CUI). The enclave is designed to help reduce CMMC Level 2 scope by confining CUI to a dedicated, zero-trust segment with strong identity, access, and logging controls. This Appendix governs the ongoing management of a CMMC enclave that has already been implemented under a separate project scope.
Included Ongoing Services
Azure Enclave Infrastructure Management
- Management of Azure Virtual Desktop (AVD) host pools and session hosts used for CUI access
- Management of Azure storage used within the enclave (e.g., Azure Files Premium, FSLogix profile storage, etc.)
- Management of Azure Backup or equivalent for enclave workloads, including monitoring of backup jobs and basic troubleshooting
- Management of enclave networking components (virtual networks, subnets, network security groups, Azure Firewall)
- Management of Azure Monitor, Log Analytics, and related monitoring services for enclave resources
- Management of Azure Update Manager or equivalent for enclave servers and session hosts (patch scheduling, deployment, and basic reporting)
Identity, Access, and Conditional Access
- Administration of cloud-only identities for enclave users via Entra ID (GCC High)
- Management of Multi-Factor Authentication and Conditional Access policies specific to the enclave
- Role-Based Access Control (RBAC) administration for enclave resources, following least-privilege principles
- Management of enclave-specific service accounts and managed identities
Security Monitoring and Logging
- Ongoing operation of security logging and monitoring for enclave resources (e.g., collection of security logs into a central workspace)
- Application of agreed alert rules and notifications for enclave-critical events
- Periodic review of security alerts and basic triage, with escalation to Client for approval of remediation actions
- Management of log retention and archival policies for enclave logs, consistent with CMMC evidence requirements
Configuration Management and Maintenance
- Maintenance of enclave “golden images” for AVD session hosts, including application and agent updates
- Configuration drift monitoring for key enclave components (where supported by tools)
- Implementation of approved configuration changes within the enclave pursuant to Client’s change management process
- Coordination of scheduled maintenance windows for enclave patches and updates
Exclusions and Client Responsibilities
The following items are not included in Managed CMMC Enclave and, if requested, will be scoped and billed separately:
- Initial design, build, or major redesign of the enclave environment
- Migration of data, applications, or users into or out of the enclave
- Development or management of CMMC policies, procedures, or System Security Plans (covered under separate compliance services, if purchased)
- Incident response, forensics, or post-breach remediation inside the enclave (see Breach/Cybersecurity Incident Recovery)
- Support for workloads or identities outside the defined enclave boundary
Client Responsibility and CMMC Attestation
Client is solely responsible for achieving and maintaining its own CMMC compliance. Intech Hawaii's role is limited to managing the technical infrastructure of the enclave as described in this Appendix. Client acknowledges and agrees that Intech Hawaii's provision of the Managed CMMC Enclave service does not constitute CMMC compliance, certification, or readiness, and does not relieve Client of any obligation under applicable DoD regulations or contractual requirements. Client represents that it will independently satisfy, attest to, and maintain all CMMC requirements applicable to its business, including any requirements not addressed by the enclave infrastructure. Intech Hawaii shall have no liability for Client's failure to achieve or maintain CMMC compliance or certification.
Last Updated: April 7, 2026