Part one: your people and their machines
Where your company’s core email and identity live. Even if you use multiple platforms, mail is delivered to one place first.
How do your people work? Count each person exactly once, based on their primary device.
How do your people work? Count each person exactly once, based on their primary device.
In the Google environment, Windows Virtual Desktops and App Streaming are add-ons to the Single-Cloud Google mandate, not standalone items.
Anyone using a second suite, whether exclusively or alongside the primary one, automatically upgrades to our cross-platform mandate.
Which suite is it? One answer. Each ecosystem carries a one-time foundation of its own.
How many people touch this second environment? Count anyone who uses this secondary suite, whether they use it exclusively or alongside your primary one. These people are in addition to your primary count.
For staff who already have a company computer but require a secondary, high-availability, high-compute, or isolated environment delivered via Virtual Desktop or App Streaming. Count each person once, in whichever of the two fits.
Why organizations need this:
- Enabling secure access from unmanaged or untrusted endpoints without exposing the corporate network.
- Delivering scalable compute for resource-heavy applications without deploying expensive local workstations.
- Ensuring immediate business continuity when physical hardware is lost, stolen, or compromised.
- Enforcing strict compliance through controlled data egress, centralized logging, and a unified security baseline across every session.
- Provisioning secure desktop environments for contractors and BYOD users without assuming hardware liability.
- Isolating sensitive management and R&D workflows within strictly controlled, dedicated enclaves.
- Guaranteeing data residency and geographic sovereignty by confining virtual workloads to specific regional borders.
- Scaling workforce headcount elastically without the capital expense or logistical friction of shipping hardware.
- Achieving zero-day productivity by granting new hires immediate, fully configured access on any available device.
- Streaming mission-critical Windows applications securely to ChromeOS, macOS, or other non-native endpoints.
- Accelerating legacy client-server application performance by eliminating VPN latency.
- Accelerating M&A IT integration by instantly provisioning secure workspaces for acquired teams, deferring complex network domain and hardware mergers.
- Streamlining application lifecycle management by updating a single master image, ensuring all users receive patched, verified environments upon login.
Why organizations need this:
- Web-enabling legacy or server-resident systems that lack native browser support or previously required an office network connection.
- Streaming Windows applications to non-native endpoints (such as ChromeOS or macOS) to decouple critical software from endpoint hardware.
- Provisioning targeted application access for contractors and external vendors without the risk or cost of exposing a full desktop environment.
- Preventing data exfiltration to unmanaged drives by executing the workload centrally while preserving a seamless, locally installed user experience.
- Reducing infrastructure overhead by isolating and streaming specific applications rather than provisioning full virtual operating systems per user.
- Centralizing application lifecycle management by applying updates and patches to a single cloud instance rather than distributing them across individual endpoints.
- Delivering high-performance compute to standard office laptops by offloading resource-heavy processing to the cloud on a strict per-application basis.
Secondary machines, hot and cold spares, shared desks, lobby terminals, or conference room hardware. Count all of them, including the ones sitting in a cupboard, because every device that can be powered on carries the full security stack.
We automatically cover secondary and ancillary company computers up to 20% of your total user count at no extra charge. You only need a separate mandate for machines beyond this allowance.
Part two: your infrastructure. Only if applicable.
The stewardship of your primary office network is included in your Full Concierge mandates. For additional sites, a managed network is only required if the equipment there cannot defend itself using modern Zero Trust security.
Anything still running on a physical box in your office(s) rather than as a native cloud app.
Do these systems have to stay on your local network?
How do your teams connect to this legacy infrastructure?
Any servers, virtual machines or infrastructure you rent in a datacenter or public cloud, such as AWS or Azure. Include self-hosted web servers.
Your scope