Service Delivery Policy
Version 1.3 | Effective: July 2026
dennis@ncmsp.com.au | 0455 336 685 | ncmsp.com.au
This document describes what Netready Cloud MSP commits to delivering to clients, the boundaries of that service, and what is required from the client to make service delivery possible. It should be read alongside your Managed Services Agreement (MSA).
1. About This Policy
This Service Delivery Policy applies to all clients engaged with Netready Cloud MSP under a Managed Services Agreement. It defines:
- The scope of services included in each service tier
- Service standards, response times, and availability commitments
- Limitations and exclusions that apply to the managed service
- Client obligations that must be met for services to be delivered effectively
- Out-of-scope work and how it is handled
This policy does not replace the Managed Services Agreement, which governs the commercial relationship, pricing, liability, and termination. Where this policy and the MSA conflict, the MSA takes precedence.
2. Service Model Overview
Netready Cloud MSP operates a vendor-neutral managed services model built on the Microsoft cloud stack. Unlike traditional CSP managed service providers, Netready Cloud MSP does not resell Microsoft licences. Instead:
- Clients enroll as Microsoft Partners in their own right through the Microsoft AI Cloud Partner Program
- Clients pay Microsoft directly for their Microsoft 365 Business Premium licences under their own Partner Success Benefits subscription
- Netready Cloud MSP charges a separate monthly retainer for managed IT services — covering configuration, security, monitoring, and support
- All administrative access to client Microsoft environments is conducted via Microsoft’s Granular Delegated Admin Privileges (GDAP) framework
This model means your IT licences belong to your business, not your IT provider. You have full visibility of what you pay Microsoft and what you pay Netready Cloud MSP — separately, with no hidden margins.
2.1 Service Tiers
Services are delivered under one of three tiers, selected at engagement:
| Foundation | Standard | Premium | |
|---|---|---|---|
| Monthly retainer | $50/user/month | $75/user/month | $100/user/month |
| Target client | 5 users | 5–15 users | Up to 35 users |
| M365 management | ✓ | ✓ | ✓ |
| Intune & patch mgmt | ✓ | ✓ | ✓ |
| MFA enforcement | ✓ | ✓ | ✓ |
| Helpdesk support | ✓ Business hours | ✓ Business hours | ✓ Business hours + after hours |
| Conditional Access | — | ✓ | ✓ |
| Defender management | — | ✓ | ✓ |
| Azure monitoring | — | ✓ | ✓ |
| Entra ID P2 features | — | ✓ | ✓ |
| Monthly security report | — | — | ✓ |
| Virtual CIO advisory | — | — | ✓ |
| Compliance framework | — | — | ✓ |
3. What Netready Cloud MSP Will Deliver
3.1 Onboarding
At the commencement of the engagement, Netready Cloud MSP will:
- Guide the client through Microsoft AI Cloud Partner Program enrollment and Partner Success Benefits subscription setup
- Establish Granular Delegated Admin Privileges (GDAP) access to the client’s Microsoft 365 tenant with role-appropriate scoping
- Conduct an initial audit of the existing Microsoft 365 environment — including identity configuration, device compliance, security posture, and licensing
- Document the existing environment baseline
- Deploy security baselines: MFA enforcement, Conditional Access policies (Standard/Premium tiers), Intune compliance policies, and Defender for Endpoint onboarding
- Provide a written onboarding summary identifying any configuration gaps, risks, or remediation items
Onboarding is covered by the one-off onboarding fee of $750–$1,500 (agreed at engagement). Remediation of pre-existing issues identified during onboarding may be quoted separately if the scope is significant.
3.2 Microsoft 365 Management
On an ongoing basis, Netready Cloud MSP will manage the client’s Microsoft 365 environment, including:
Exchange Online
- User mailbox creation, modification, and deactivation (on request)
- Shared mailbox and distribution group management
- Mail flow rule management
- Anti-spam and anti-phishing policy management
- Email retention policy configuration
Microsoft Teams & SharePoint
- Teams creation and management (on request)
- SharePoint site provisioning and permission management (on request)
- OneDrive for Business configuration and access management
Entra ID (Azure Active Directory)
- User account lifecycle management — creation, modification, offboarding
- Group and role assignment management
- MFA registration enforcement and exception management
- Self-Service Password Reset (SSPR) configuration
- Conditional Access policy creation, monitoring, and tuning (Standard/Premium)
- Entra ID P2 features: Identity Protection, Privileged Identity Management (PIM) (Standard/Premium)
3.3 Endpoint Management (Intune)
- Windows device enrolment and compliance policy deployment
- Device configuration profile management
- Windows Update ring management — patch scheduling and compliance reporting
- Application deployment via Intune (for applications available through the Microsoft Store or provided as deployable packages)
- Device compliance monitoring and remediation alerts
- BitLocker encryption enforcement and key management
- Remote device wipe on authorised request (e.g. lost or stolen device)
3.4 Security Management
Netready Cloud MSP will actively manage the client’s Microsoft security stack:
Microsoft Defender for Endpoint (Standard/Premium)
- Endpoint threat protection policy management
- Monitoring of active alerts and incidents within the Microsoft Defender portal
- Response to confirmed security incidents — triage, containment, and remediation guidance
- Attack surface reduction rule management
- Defender Vulnerability Management — monitoring and prioritising remediation of identified vulnerabilities
Defender for Cloud / Azure Monitor (Standard/Premium)
- Azure resource security posture monitoring via Microsoft Defender for Cloud
- Secure Score monitoring and improvement recommendations
- Azure Monitor alert configuration for key infrastructure metrics
- Log Analytics workspace management for security event collection
3.5 Helpdesk Support
Netready Cloud MSP provides direct helpdesk support to the client and their staff for issues related to the managed Microsoft environment.
| Priority | Description | Initial Response | Target Resolution |
|---|---|---|---|
| P1 — Critical | Complete service outage, security breach, or business-stopping issue | 2 business hours | Same business day |
| P2 — High | Significant issue affecting multiple users or key business functions | 4 business hours | 1–2 business days |
| P3 — Standard | Single user issue, degraded performance, or service request | 1 business day | 3–5 business days |
| P4 — Low | General enquiry, change request, or non-urgent configuration task | 2 business days | Scheduled |
Business hours are defined as Monday to Friday, 8:00 AM to 6:00 PM AEST/AEDT, excluding Australian and Victorian public holidays.
After hours emergency support (P1 only) is available to Premium tier clients. Standard and Foundation clients may request after hours assistance on a best-endeavours basis, billed at the out-of-scope hourly rate.
3.6 Proactive Monitoring
- Continuous monitoring of security alerts from Defender for Endpoint and Entra ID Identity Protection
- Monitoring of Windows patch compliance status across enrolled devices
- Monitoring of Entra ID sign-in risk alerts and responding to confirmed risky sign-ins
- Monitoring of Microsoft 365 service health for issues affecting the client’s tenant
- Azure resource health and cost anomaly alerts (where Azure resources are within scope)
3.7 Reporting
- Foundation/Standard: Summary of significant incidents or changes provided on request
- Premium: Monthly written security and service report covering — Defender alerts summary, patch compliance status, Secure Score movement, Conditional Access policy activity, and key incidents
- All tiers: Ad hoc reporting available on request (may attract out-of-scope charges for complex reports)
3.8 Virtual CIO Advisory (Premium only)
- Quarterly strategic IT review — assessment of current environment against business needs
- Technology roadmap input — recommendations on Microsoft product adoption (e.g. Copilot, Teams Phone, Azure services)
- Advice on Microsoft licensing optimisation and tier transitions
- Input on IT-related compliance requirements relevant to the client’s industry
4. Limitations and Exclusions
The managed service retainer covers the Microsoft cloud stack described in Section 3. The following items are explicitly outside the scope of the monthly retainer and will be quoted separately as out-of-scope work.
4.1 Hardware and Physical Infrastructure
- Supply, configuration, or repair of physical hardware (computers, printers, networking equipment, servers)
- On-site cabling, networking, or infrastructure work
- Physical server management or on-premises Active Directory management (unless specifically agreed in writing)
- Hardware procurement or asset management
Netready Cloud MSP is a cloud-first managed service. Physical infrastructure support is not included in the retainer but can be provided at the standard consultation rate. Clients requiring on-premises infrastructure management should contact us for a quotation.
4.2 Non-Microsoft Software and Applications
- Support for, or management of, third-party business applications (accounting software, CRM, ERP, industry-specific platforms)
- Support for non-Microsoft email platforms or collaboration tools
- macOS, iOS, Android, or Linux device management (beyond basic Intune enrolment where supported)
- Third-party backup solutions (beyond Microsoft’s native backup capabilities within M365)
4.3 Major Projects and Migrations
- Migration from an existing email platform to Microsoft 365
- Tenant-to-tenant migrations
- Major SharePoint or Teams restructures
- Deployment of new line-of-business applications
- Azure infrastructure deployments or significant Azure architecture changes
- Domain transfers or DNS migrations
Major project work will be scoped, quoted, and delivered separately from the managed service retainer. A written statement of work will be provided for any project exceeding 4 hours of effort.
4.4 Training and User Education
- Formal end-user training sessions on Microsoft 365 applications
- Security awareness training programs
- Documentation creation for client internal use
Brief, incidental guidance provided during helpdesk interactions (e.g. explaining how a feature works) is included. Structured training sessions are quoted separately.
4.5 Compliance and Legal Obligations
- Legal or regulatory compliance consulting (e.g. ASD Essential Eight formal assessments, ISO 27001 certification, Privacy Act compliance audits)
- Formal penetration testing or third-party security audits
- Provision of compliance reports required by third parties (e.g. for insurance, legal proceedings, or government contracts) — these may be provided on request but are quoted per engagement
Netready Cloud MSP can advise on Microsoft’s built-in compliance tooling and assist with technical implementation of compliance controls. However, we are not compliance consultants or legal advisors, and formal compliance assessments or certifications require engagement of a specialist.
4.6 Microsoft Service Limitations
Netready Cloud MSP manages services within the Microsoft 365 and Azure platforms. We are subject to the same platform limitations as any Microsoft customer. We cannot:
- Guarantee Microsoft platform availability (Microsoft’s own SLA governs uptime for M365 and Azure services)
- Override Microsoft licensing restrictions or entitlements
- Recover data that was permanently deleted prior to backup or retention policy activation
- Resolve issues that are caused by Microsoft platform bugs, outages, or changes to Microsoft’s own products
In the event of a Microsoft platform outage or service degradation, Netready Cloud MSP will monitor the situation, communicate updates to the client, and assist with any workarounds available within the platform. We will escalate to Microsoft Support on the client’s behalf where the issue warrants it.
4.7 Security Incident Limitations
While Netready Cloud MSP implements industry-standard security controls and actively monitors for threats, we cannot guarantee that a security incident will never occur. Our obligations in the event of a security incident are:
- To detect and respond to confirmed incidents as promptly as reasonably possible
- To contain and remediate the incident within our administrative scope
- To notify the client promptly of confirmed incidents affecting their environment
- To provide reasonable guidance on recovery steps
Netready Cloud MSP is not liable for losses, damages, or costs arising from security incidents caused by:
- Client staff action or inaction (including clicking phishing links, sharing credentials, or bypassing security controls)
- Vulnerabilities in third-party software or hardware not within our management scope
- Microsoft platform vulnerabilities or zero-day exploits
- Client failure to meet the client obligations set out in Section 5
5. Client Obligations
Effective service delivery is a partnership. The following obligations must be met by the client for Netready Cloud MSP to deliver services to the standard described in this policy. Failure to meet these obligations may affect service quality, response times, and — in serious cases — our ability to continue delivering the service.
5.1 Microsoft Partner Enrollment and Licence Maintenance
- The client must enroll in the Microsoft AI Cloud Partner Program and maintain their Partner Success Benefits subscription (or other applicable Microsoft partner licence tier) throughout the engagement
- The client is solely responsible for paying Microsoft directly for their Partner subscription and any Microsoft licences — this is a client-to-Microsoft commercial relationship
- If the client’s Microsoft Partner subscription lapses, is cancelled, or is terminated, Netready Cloud MSP cannot guarantee continuity of services that depend on the associated licence entitlements
- The client must notify Netready Cloud MSP promptly if there is any change to their Microsoft licensing or Partner enrollment status
If the client’s Microsoft 365 licences are suspended or terminated for any reason, users will lose access to M365 services immediately. Netready Cloud MSP has no ability to restore access and is not liable for data loss or business disruption resulting from a client’s licensing failure.
5.2 GDAP Access and Administrative Access
- The client must maintain the GDAP relationship granted to Netready Cloud MSP at onboarding. Revoking GDAP access without prior written notice will immediately prevent Netready Cloud MSP from delivering managed services
- The client must retain at least one Global Administrator account in their Microsoft 365 tenant that is accessible to the client (independent of Netready Cloud MSP access)
- The client must promptly action any consent requests or approval steps required as part of GDAP setup, renewal, or role changes
- The client must not grant Global Administrator or equivalent access to third parties without informing Netready Cloud MSP, as this may introduce security risks that affect our ability to manage the environment
5.3 Device Enrollment and Intune Compliance
- All Windows devices used by client staff for business purposes must be enrolled in Intune within 30 days of onboarding (or within 30 days of a new device being provisioned)
- Devices must remain enrolled and connected to the internet regularly to receive policy updates, patches, and compliance assessments
- The client must not unenrol devices from Intune without prior approval from Netready Cloud MSP
- Personally owned (BYOD) devices connecting to client Microsoft 365 resources must meet the minimum compliance standards agreed at onboarding
5.4 User Account Management
- The client must notify Netready Cloud MSP promptly (ideally before the departure date, or within one business day) when a staff member leaves the organisation, so that accounts can be appropriately secured or deprovisioned
- The client must notify Netready Cloud MSP when new staff members join, so that accounts, devices, and access rights can be provisioned correctly from the outset
- The client must not create or modify user accounts, security groups, or administrative roles in the Microsoft 365 tenant without prior communication with Netready Cloud MSP, as uncoordinated changes can create security gaps or configuration conflicts
Failure to report staff departures promptly is one of the most common sources of security incidents in small business environments. Departing employees with active accounts and devices represent a significant and avoidable risk.
5.5 Security Baseline Compliance
- The client and all staff must enroll in and use Multi-Factor Authentication (MFA) for Microsoft 365 access. MFA bypass requests will only be granted in exceptional, documented circumstances and with the client’s written acknowledgement of the associated risk
- The client must not disable, circumvent, or request removal of Conditional Access policies, Defender for Endpoint, or other security controls deployed by Netready Cloud MSP without a documented risk acceptance signed by an authorised representative of the client
- The client must ensure staff complete basic security awareness — particularly around phishing recognition — even if formal training is not contracted. Netready Cloud MSP can provide guidance on free Microsoft-provided training resources
- The client must report suspected security incidents, phishing attempts, or unusual account behaviour to Netready Cloud MSP as soon as they are aware of them
5.6 Communication and Responsiveness
- The client must designate a primary point of contact who is authorised to approve changes, accept risk, and communicate on behalf of the organisation
- The client must respond to requests for information, approvals, or decisions from Netready Cloud MSP within a reasonable time. Delays in client response will affect resolution times and are not counted against Netready Cloud MSP’s response time commitments
- The client must provide accurate information about their environment, staff, and business requirements when requested — particularly during onboarding and when requesting changes
5.7 Payment Obligations
- Monthly managed service retainers are payable within 14 days of invoice
- Out-of-scope work invoices are payable within 14 days of invoice
- Onboarding fees are payable prior to or on commencement of the engagement
- Netready Cloud MSP reserves the right to suspend non-emergency services where invoices are overdue by more than 30 days, following written notice to the client
5.8 Acceptable Use
- The client and their staff must use Microsoft 365 and other managed services in accordance with Microsoft’s Terms of Service and Acceptable Use Policy
- The client must not use their Microsoft environment or Netready Cloud MSP’s services for any unlawful purpose
- The client must not share administrative credentials with third parties or grant access to the Microsoft tenant to parties other than their own staff without notifying Netready Cloud MSP
6. Out-of-Scope Work
Work that falls outside the managed service scope described in Sections 3 and 4 will be handled as follows:
- Netready Cloud MSP will provide a written estimate of effort and cost before commencing out-of-scope work
- The client must provide written approval (email is sufficient) before out-of-scope work begins
- Out-of-scope work is billed at the prevailing hourly rate of $150–$185 AUD/hour
- Where out-of-scope work is part of a larger project, a Statement of Work will be prepared
- Emergency out-of-scope work (where client approval cannot be obtained in advance) will be reported to the client immediately and invoiced on completion
Common examples of out-of-scope work: tenant-to-tenant migrations, new Azure environment deployments, domain changes, formal compliance assessments, training sessions, hardware provisioning and setup, and third-party application integrations.
7. Service Availability and Continuity
7.1 Netready Cloud MSP Availability
As a sole operator, Netready Cloud MSP provides managed services and helpdesk support during business hours as defined in Section 3.5. Dennis Odri is the main point of contact but may assign other technicians as workload dictates.
In the event of planned absence (e.g. annual leave), clients will be notified at least 5 business days in advance and advised of an alternate contact during planned absence.
- Automated monitoring and alerting will continue uninterrupted
- Critical (P1) incidents will be assessed and triaged either remotely or by the alternate technician
- Non-urgent support requests may be queued for attention on return
In the event of unplanned absence (e.g. illness), clients will be notified as soon as practicable. Netready Cloud MSP maintains documentation and runbooks for all managed environments to support continuity.
Clients should consider whether a sole operator model is appropriate for their business continuity requirements. This limitation is reflected in our pricing and is disclosed transparently at the outset of every engagement.
7.2 Microsoft Platform Availability
Microsoft 365 and Azure services are governed by Microsoft’s own Service Level Agreements (SLAs), which provide 99.9% uptime guarantees for most services. Netready Cloud MSP cannot guarantee Microsoft platform availability and is not liable for downtime caused by Microsoft outages.
Microsoft’s current SLAs and service health status are available at: admin.microsoft.com (Service health dashboard) and status.azure.com.
7.3 Disaster Recovery Scope
Netready Cloud MSP configures Microsoft’s native data protection capabilities (including Exchange Online retention, SharePoint version history, and Recycle Bin policies) as part of the managed service. These provide protection against accidental deletion and some ransomware scenarios.
Netready Cloud MSP does not manage or operate a separate third-party backup solution unless this is specifically contracted as an add-on service. Clients requiring extended backup retention, point-in-time recovery beyond Microsoft’s native capabilities, or backup of non-Microsoft data should discuss additional backup options.
8. Changes to This Policy
Netready Cloud MSP may update this Service Delivery Policy from time to time to reflect changes in service scope, Microsoft platform capabilities, or industry practice. When material changes are made:
- Clients will be notified by email at least 30 days before the change takes effect
- An updated version will be published on our website (ncmsp.com.au)
- Clients who do not accept material changes may terminate the engagement in accordance with the notice period in their Managed Services Agreement
Minor clarifications or corrections that do not affect service scope or client obligations may be made without notice.
9. Contact and Escalation
For all service requests, incidents, and general enquiries:
Dennis Odri Founder & Principal IT Consultant, Netready Cloud MSP Email: dennis@ncmsp.com.au Phone: 0455 336 685 Website: ncmsp.com.au
For urgent (P1) incidents outside business hours — Premium clients: Call 0455 336 685. Standard/Foundation clients: Email with subject line URGENT and call if no response within 2 hours.
This Service Delivery Policy is version 1.3, effective July 2026. It should be read alongside your Managed Services Agreement. If you have questions about anything in this document, please contact Dennis directly.