| Agency: | State Government of Wisconsin |
|---|---|
| State: | Wisconsin |
| Type of Government: | State & Local |
| NAICS Category: |
|
| Posted Date: | Jun 17, 2026 |
| Due Date: | Jul 8, 2026 |
| Solicitation No: | Request for Information: Desktop as a Service (DaaS) Solution |
| Original Source: | Please Login to View Page |
| Contact information: | Please Login to View Page |
| Bid Documents: | Please Login to View Page |
| Solicitation Reference #: | Request for Information: Desktop as a Service (DaaS) Solution | |
| Title: | Request for Information: Desktop as a Service (DaaS) Solution | |
| Available Date: | 6/17/2026 | |
| Due Date: | 7/8/2026 2:00:00 PM | |
| Are faxed Bids acceptable? | No | |
| Are e-mailed bids acceptable? | No | |
| Bid Synopsis: |
Request for Information Desktop as a Service (DaaS) Solution Note: This is not a bid or request for proposal. This Request for Information (RFI) is issued solely for information and planning purposes only and does not constitute a solicitation. Responses to the RFI will not be returned. Responses to this RFI are not an offer and cannot be accepted by the State to form a binding contract.
Questions are due on June 24, 2026. Email questions and completed RFI responses to Caleb Hall at caleb.hall@wisc.edu . |
|
| Agency Contact: |
Lori Pulvermacher
|
|
| Documents: |
|
Request for Information
Desktop as a Service (DaaS) Solution
Note: This is not a bid or request for proposal. This Request for Information (RFI) is issued solely for information and planning purposes only and does not constitute a solicitation. Responses to the RFI will not be returned. Responses to this RFI are not an offer and cannot be accepted by the State to form a binding contract.
Questions concerning this RFI should be directed via email to UW Madison Purchasing Manager Caleb Hall .
RFI Issued Date: June 17, 2026
Questions Due: June 24, 2026
RFI Due Date: July 8, 2026 by 2:00 PM CT
Email questions and completed RFI responses to .
Request for Information (RFI): Desktop as a Service (DaaS) Solution
Project Title: Enterprise Desktop as a Service (DaaS) Enablement
1. Introduction and Purpose
The University of Wisconsin-Madison, a public R1 research institution, is soliciting information regarding an enterprise Desktop as a Service (DaaS) solution. The university operates within a highly decentralized, hub-and-spoke IT governance model, requiring solutions that balance centralized security oversight with strong departmental autonomy.
2. Scope of Requirements
The university seeks a cloud-hosted Desktop as a Service (DaaS) solution capable of delivering secure, scalable, and resilient desktop and application environments to faculty, staff, researchers, clinicians, and students.
Key Objectives
Federated Governance: Central IT defines mandatory security and compliance baselines while departments retain operational control.
Research & Data Protection: Support for FERPA, HIPAA, FedRAMP (Moderate/High), ITAR, and controlled research data.
Zero Trust Alignment: Identity- and device-aware access without traditional VPN reliance.
Cloud Elasticity: On-demand scaling for instruction, research, and administrative workloads.
3. Technical and Functional Requirements
3.1 Administrative Hierarchy and Federated Management
The DaaS platform must support a multi-tenant or hierarchical administrative model that allows central governance while enabling departmental autonomy.
Central Oversight: Ability to enforce non-overridable global security policies such as MFA, encryption, and session logging.
Delegated Administration: Scoped departmental admin access for images, applications, resource pools, and user assignments.
Policy Inheritance: Clear conflict-resolution model between central and departmental policies.
3.2 Desktop and Application Delivery
Support for persistent and non-persistent desktops.
Support for pooled and dedicated desktop models.
Published applications and application streaming.
Windows and Linux desktop operating systems.
GPU-enabled desktops for visualization and research workloads.
User profile management and image lifecycle controls.
3.3 Security and Policy Controls
Clipboard, printing, drive, USB, and peripheral redirection controls.
Screen capture controls and/or session recording.
Encryption of data in transit and at rest.
Integration with institutional DLP or sensitivity labeling solutions.
Malware and ransomware protection within desktop sessions.
Centralized audit logging with SIEM export capability.
3.4 Identity, Access, and Device Context
Federated identity support for SAML 2.0, OIDC, and Microsoft Entra ID (Azure AD).
Just-in-Time provisioning and de-provisioning.
Conditional access based on user roles, device posture, network, and location.
Support for managed and unmanaged (BYOD) endpoints via native or browser-based clients.
3.5 Availability, Performance, and Scalability
High-availability service architecture and resiliency.
Disaster recovery and regional failover options.
Bandwidth optimization and latency tolerance.
Desktop and application performance monitoring.
4. Vendor Questionnaire
A. General Information
Provide an overview of your organization, including history and ownership.
Identify primary technical and contractual contacts.
Provide URLs for product documentation, support, and training.
Describe your experience supporting higher education or regulated research environments.
Provide at least three reference customers similar in size or complexity.
Describe your product roadmap for the next three years and your five-year vision.
Describe your release cycle and customer communication approach.
Describe your cloud platform(s), data center locations, and data residency guarantees.
Describe your patching, maintenance, and SLA model.
What is your incident notification timeline?
Who leads incident response- Vendor, customer, or shared?
What events trigger billing (login, idle VM, powered-off state, profile storage)?
Can costs be allocated or broken out by user departments?
Are there minimum commitments or sustained-use discounts?
Are there data egress charges?
How can desktops, images, and profiles be exported?
What happens to backups and snapshots after contract termination?
B. Governance & Multi-Tenancy
Describe support for hierarchical or parent-child organizational structures.
Are there limits on tenants, sub-tenants, or administrative scopes?
How is policy and data isolation enforced between departments?
Describe audit and reporting capabilities available to central administrators.
Describe RBAC granularity and customization.
C. Deployment & Architecture
Describe supported deployment models (public cloud, hybrid, multi-cloud).
Which cloud providers are supported?
Describe network and firewall requirements.
Describe client requirements and supported operating systems.
Describe API availability and automation capabilities.
Describe upgrade, migration, and rollback processes.
D. Research & Compliance
How does your solution support NIST 800-171, CMMC, HIPAA, and FedRAMP-aligned environments?
Describe isolated research enclave capabilities.
Describe audit logging and compliance reporting features.
Describe integrations with enterprise security tooling.
Does the platform support data classification or sensitivity awareness?
E. Virtual Desktop Storage & Data Protection
How does your DaaS platform protect virtual desktop storage (OS disks, user profiles, application data) that may contain HIPAA- or FERPA- regulated information?
Are all virtual disks encrypted at rest by default? Can encryption be disabled by a tenant administrator?
Who controls the encryption keys (vendor, cloud provider, customer), and what key-rotation options exist?
Can storage be logically or cryptographically isolated by department or research enclaves?
How are temporary files, swap files, crash dumps, and cached credentials handled?
Describe secure wipe and destruction guarantees when storage is released.
Can storage and deletion events be logged and exported for compliance audits?
Can sessions or disks be preserved ("frozen") for investigation?
Can data ever transit or be accessed from outside the U.S.?
Describe how your DaaS platform maintains security and protects institutional, research, or regulated data under these conditions.
How the platform determines whether a client device is trusted, untrusted, or of unknown posture.
What default security controls are automatically enforced when a device cannot be verified.
Whether access can be limited to browser-based or restricted-session experiences.
How the platform prevents persistence of data on untrusted client devices
How identity, conditional access signals, or risk scoring are used to adapt session privileges.
Any security limitations or residual risks that remain when supporting unverified endpoints.
Data protection controls available at the session level, including:
Clipboard and copy/paste behavior
File upload/download controls
Local printing and redirection
Screen capture or session recording
F. Accessibility
Does your solution conform to WCAG 2.1 (A/AA) and Section 508 requirements?
Has the solution been tested with assistive technologies? If so, which?
Describe your accessibility testing and QA methodology.
How are accessibility regressions prevented during upgrades?
Describe known accessibility limitations and remediation plans.
Describe how accessibility issues are reported and addressed.
5. Submission Instructions
Send a completed response via email by 2:00 p.m. July 8, 2026, to:
Caleb Hall, Purchasing Manager
UW Madison
caleb.hall@.edu
Include in your response:
Executive summary.
Completed responses to Section 4, including references requested in 4.A.5.
Architecture diagrams.
Product roadmap for 2026-2027.
Detailed pricing and licensing, including add-ons and higher education discounts.
6. Anticipated Timeline
The anticipated schedule for this RFI process is as follows:
RFI Issued June 17, 2026
Questions Due June 24, 2026
Information Due by July 8, 2026 2:00PM (CDT)
The University reserves the right to modify this schedule.
7. Questions
Questions regarding this RFI should be submitted via email by June 24, 2026, at 2:00 pm (CDT) to:
Caleb Hall, Purchasing Manager
UW Madison
8. Disclaimer
This Request for Information is issued for informational and planning purposes only. It does not
constitute a solicitation for proposals and does not obligate the University to issue a subsequent procurement document or enter into any agreement. Responses to this RFI are not an offer and cannot be accepted by the State to form a binding contract.
The University reserves the right to:
* Modify or cancel this RFI at any time
* Request additional information from respondents
* Conduct interviews with respondents
* Use information received to structure a future procurement process
The University is not responsible for any costs incurred by respondents in preparing responses to this RFI.
With Free Trial, you can:
You will have a full access to bids, website, and receive daily bid report via email and web.
CONTRACT NUMBER: 8820 CONTRACT: Euclid Ave, Birch Ave Recon Percentage of Contract Completed:
City of Madison
Bid Due: 9/24/2026
Solicitation Reference #: 2026-GRBALL-01355-RFB Title: UW-Green Bay Campus Calendar Software Available Date: 7/14/2026
State Government of Wisconsin
Bid Due: 8/14/2026
CONTRACT NUMBER: 8819 CONTRACT: Milwaukee St Recon Percentage of Contract Completed: Not Available
City of Madison
Bid Due: 11/05/2026
CONTRACT NUMBER: 8819 CONTRACT: Milwaukee St Recon Percentage of Contract Completed: Not Available
City of Madison
Bid Due: 11/05/2026