
Desktop Management Plan Services Schedule
Atrio Pty Ltd (ACN 631 222 592)
Last Updated 29th June 2026
Important Things to Know (please read)
This Desktop Management Plan Services Schedule forms part of your Agreement with Atrio Pty Ltd and must be read together with our Terms of Service and your Order. This Services Schedule applies only where your Order expressly includes desktop management plan.
What we support is defined by your Order. Our obligations only extend to the supported items and services expressly listed there. If it is not in your Order, it is not covered.
We want this Desktop Management Plan Services Schedule to work for both of us. If there is something you would like to change before placing an Order, we are happy to consider reasonable amendments, just let us know.
1. About this Services Schedule
1.1. This Desktop Management Plan Services Schedule (Services Schedule) applies to any Order under which we agree to provide a desktop management plan to you.
1.2. This Services Schedule forms part of an Agreement and must be read together with the Terms of Service and the Order.
1.3. If there is any inconsistency between this Services Schedule, the Order and the Terms of Service, the Terms of Service prevail, then the Order, then this Services Schedule, to the extent of the inconsistency.
1.4. In this Services Schedule, some words are defined in bold and brackets. Definitions in the Terms of Service also apply to this Services Schedule.
2. Overview of desktop management plans
2.1 If a desktop management plan is included in your Order, we provide ongoing management, monitoring and support of your desktop operating environment (DoE) as described in the Order and this Services Schedule.
2.2. The desktop management plan is intended to:
(a) support the operation of your systems on a day-to-day basis;
(b) reduce the likelihood and impact of system issues and downtime; and
(c) maintain the security and stability of your environment.
2.3. The specific services provided, and the extent of those services, depend on the desktop management plan set out in your Order.
3. Desktop management plans
3.1. Our desktop management plans are designed to give you and your end users a fully managed, secure and productive desktop environment. We offer the following three plans, each building on the last:
(a) Essentials Plan;
(b) SecureSmart Plan; and
(c) SecureSmart Premium Plan.
3.2. What’s included in every desktop management plan
All desktop management plans include the following, to the extent specified in the Order:
(a) Microsoft Subscription Management
(i) We will procure a software licence or subscription for Microsoft services for you and your end users. Our Microsoft services include:
• procurement and management of your Microsoft subscriptions on your behalf for your end users;
• setting up and acting as the administrator of your Microsoft tenant, including configuring domain names, managing end user accounts, resetting passwords, purchasing subscriptions on your behalf and allocating them to end users;
• installing Microsoft software on your end users’ hardware (subject to you arranging remote access for us); and
• creating Microsoft groups and teams, setting aliases and managing associated user permissions.
(ii) Microsoft subscriptions are billed by us from the go live date, not from the date you start using them.
(iii) Your use of Microsoft services is subject to Microsoft’s own terms and policies, including their Services Agreement between you and Microsoft at https://www.microsoft.com/en-au/servicesagreement/, Microsoft’s Privacy Statement at https://privacy.microsoft.com/en-us/privacystatement (collectively, Microsoft Terms). By using Microsoft services, you agree to be bound by the Microsoft Terms as published and updated by Microsoft from time to time.
(b) Cloud Backup
(i) We provide a cloud backup service that performs up to six incremental backups per day of your Microsoft cloud data, including:
• Exchange Online (email and calendars);
• OneDrive; and
• SharePoint
(ii) Our cloud backup service only backs up Microsoft cloud data from the time we take over the relevant service. It does not back up, recreate or otherwise cover historical data created, stored or deleted before that time. Our cloud backup service also does not back up local files stored on individual computers or hardware. If you need local or hardware-level backups, please speak with us about additional backup options.
(iii) Upon termination or expiry of the Agreement of the Agreement, you will no longer be able to access or retrieve any backed-up data held through the cloud backup service.
(c) Antivirus Protection
(i) All plans include deployment and management of antivirus software on your supported items. We will select the solution that we consider most appropriate for your environment and configuration.
(ii) Antivirus software is designed to detect computer viruses.
(iii) No antivirus solution can guarantee to identify or eliminate every virus. These solutions are designed to significantly reduce your exposure, but you should maintain good security hygiene practices regardless.
(iv) While we use commercially recognised antivirus solutions, we do not represent, warrant or guarantee that they will detect, prevent or remove all viruses, malware or other malicious software.
(v) We reserve the right to:
• select and manage our antivirus software vendor; and
• change our antivirus software vendor where necessary (for example, due to product changes or service improvements) without affecting your service entitlements under this Services Schedule.
(d) Email Filtering
(i) All plans include email filtering to protect your end users from spam and phishing. The specific product used will depend on your plan. We reserve the right to change the underlying product where we determine this is appropriate or necessary.
(ii) Email filtering reduces risk but cannot guarantee that every harmful or unwanted email will be blocked, or that every legitimate email will be delivered. Occasionally, legitimate emails may be quarantined or filtered. We are not liable for email delivery failures caused by filtering policies, third-party mail issues, or reasons outside our control. If you notice unexpected issues with email delivery, please raise a support request promptly.
(e) Proactive Monitoring (RMM)
All plans include remote monitoring and management (RMM) software to proactively monitor your supported items. Where issues are detected, we triage and respond in line with our support process.
(f) Helpdesk Access
All desktop management plans include access to our helpdesk. The specific support inclusions, hours of support, response targets, escalation process and any limitations that apply to your plan are set out in our support services guide.
3.3. SecureSmart and SecureSmart Premium desktop management plans
In addition to everything included in clause 3.2, SecureSmart and SecureSmart Premium include the following security-focused services:
(a) DNS filtering
DNS filtering blocks access to known malicious websites and categories of harmful content at the network level, before a connection is even made. This adds a meaningful layer of protection that works alongside your antivirus and email filtering. DNS filtering is available only where we provide managed network services for your network. You are not required to purchase managed network services from us. However, if your network is managed by another provider, DNS filtering is not included as part of your desktop management plan.
(b) Dark web monitoring
(i) We use a specialist dark web monitoring service to scan known dark web sources for your business’s credentials, including compromised email addresses that may have been exposed in data breaches. If a match is found, we notify you with remediation steps during business hours.
(ii) Dark web monitoring is not comprehensive. Our monitoring service scans a wide range of dark web sources, but no tool can access every corner of the dark web or capture every breach or credential leak. Results may differ from other products on the market. We monitor your primary domain only, unless your Order specifies that additional domains are included. Additional domains may be available for a separate fee as set out in your Order.
(iii) We also rely on the domain configuration you provide. If a domain is set up incorrectly in the monitoring tool, we may be monitoring the wrong domain. We will provide you with a monthly dark web monitoring report, and you are responsible for reviewing it and promptly notifying us if any domain details, monitoring results or other information appear to be inaccurate or incomplete.
(c) Simulated phishing campaigns
We run automated simulated phishing campaigns using our security awareness platform. These are sent to your users on an ongoing, automated schedule to test their ability to recognise phishing emails and reinforce good security habits.
(d) Security awareness video training
Linked to the simulated phishing campaigns, we provide short security awareness training videos to users who interact with simulated phishing emails. These are automated and delivered through the same security awareness platform as part of the campaign workflow.
3.4. SecureSmart Premium
In addition to everything included in clauses 3.2 and 3.3, SecureSmart Premium also includes the following:
(a) Device Compliance
Device compliance ensures that only approved and secure hardware can access business systems by enforcing security requirements such as encryption, antivirus, operating system updates and other compliance standards. We will use reasonable endeavours to block non-compliant hardware from accessing company resources until remediated.
(b) Phishing-Resistant MFA
Phishing-resistant multi-factor authentication (MFA) provides stronger authentication methods, such as Microsoft Authenticator, biometrics or security keys, to reduce the risk of account compromise from phishing and credential theft. Less secure authentication methods may be restricted where appropriate.
(c) Application Whitelisting
Application whitelisting allows only approved software to be installed or run on managed hardware. This helps reduce the risk of malware, ransomware and unauthorised software while providing a controlled process for approving legitimate business applications.
The specific features included are set out in your Order.
4. Support services
4.1. Proactive support services
We will remotely review the logs and error notifications generated by your supported items and action any issues identified without you needing to raise a support request. This may include:
(a) reviewing system alerts, logs and performance data;
(b) applying updates and patches where appropriate; and
(c) taking preventative action to minimise disruption or performance issues.
5. Responsive support services (Helpdesk)
You may request remote support for your supported items by contacting our helpdesk (support request).
5.1. How the helpdesk works
(a) Upon receiving a support request, we will use reasonable endeavours to:
(i) acknowledge receipt and assign a priority based on the severity of the issue;
(ii) keep you updated on progress and the expected timeframe for resolution; and
(iii) investigate and resolve the issue or restore functionality.
(b) You acknowledge and agree that despite our reasonable endeavours, we may not be able to resolve every issue or restore all functionality.
(c) Support is provided remotely during Business Days between 8:00am – 6:00pm AEST/AEDT unless otherwise agreed in writing. Support requests lodged outside of these hours will be treated as having been received at 8:00am on the next Business Day.
5.2. Scope of support services
(a) We will provide support services only in respect of systems, services and hardware that are expressly identified in the Order as supported (supported items). We are not obliged to support hardware, software or services that are not expressly listed there. Support under the desktop management plan is also limited to the Windows environment. Where support depends on a third-party vendor, manufacturer, software provider or other supplier, our ability to provide support is subject to that vendor’s support arrangements, processes, response times, availability, warranty requirements and any other applicable limitations.
(b) We are not responsible to provide support services in respect of an error caused by:
(i) your use of a supported item in combination with hardware or software the supported item is not compatible with;
(ii) use of a supported item from a location other than any designated location specified in your Order;
(iii) your modification of a supported item,
(iv) unsupported configurations; or
(v) out-of-warranty hardware or software.
(c) We do not provide support for your practice management software and are not responsible for any compatibility, performance or other issues that arise from installing or operating multiple practice management software platforms on the same supported item.
(d) Unless your Order specifies otherwise, we will provide support services remotely. Support services delivered on site at your premises can be arranged under a separate agreement with us for an additional fee. From time to time, we may attend your premises at our discretion and provide limited support or remediation while we are there without charging an additional fee. This is an exception only and does not mean on-site support is included in your desktop management plan. If we intend to charge you for any on-site support or remediation, we will tell you before carrying out that work.
(e) If we provide support in relation to a location, configuration, hardware, software or other item that is not covered by your Order, whether on a one-off basis or otherwise, that does not mean we have agreed to continue supporting such location, configuration, hardware, software or other item or that it becomes a supported item.
6. Mobile device management (MDM) services
6.1. Only SecureSmart and SecureSmart Premium plans include mobile device management services as part of their desktop management plan. If your Order specifies that we will provide you with mobile device management services as part of the desktop management plan, we will manage the configuration and administration of one mobile device plus one mobile phone for each user account listed in your Order as being covered by this service (MDM device).
6.2. MDM gives us visibility and control over the MDM devices used to access your business systems and helps enforce security policies across your mobile fleet.
6.3. Our MDM services include:
(a) configuring the settings on each category of MDM device in line with our standard set of configurations;
(b) installing and uninstalling applications on MDM devices, and reassigning application access and subscriptions; and
(c) remotely wiping an MDM device during business hours if it is lost or stolen, or if you instruct us to do so.
7. Other ordered services
7.1. If your Order includes any other services as part of the desktop management plan, we will supply or procure the supply of those services to you, in each case in accordance with the Order, this Services Schedule and the Terms of Service.
8. Access and administration rights
8.1. For security and operational reasons, we retain Global Administrator access to your IT environment for the duration of the Agreement. This is necessary for us to effectively manage, monitor and support your environment.
8.2. Access to management portals (including our service management platform, subscription and licensing portals, security dashboards and network management tools) is restricted to our authorised personnel only. We may revoke or restrict portal access if unauthorised use is detected.
8.3. Subject to clause 8.5, you and any third parties you engage will not be provided with Global Administrator credentials while the Agreement is active. This is to preserve the security and integrity of your systems.
8.4. Administrator credentials will be provided to you once all accounts are settled and the offboarding process is complete
8.5. You may request in writing, and we may agree to in our discretion, that we give a third-party consultant (Third-Party Consultant), access to specified parts of your IT environment, including access to administration rights. Before we provide access:
(a) you must complete and sign our access authorisation form, identifying each Third-Party Consultant, the purpose for which access is required, the systems and information to which access is required, the level of access requested and the period for which access is required;
(b) you must ensure that each Third-Party Consultant executes a Confidentiality, Intellectual Property and Data Security Deed Poll approved by us, and any other documents we reasonably require in a form approved by us, and provide the executed documents to us; and
(c) we may determine the method, scope, duration and conditions of access, grant only the minimum access we consider reasonably necessary, and refuse, suspend or revoke access where we reasonably consider this necessary to protect the security, integrity or operation of your IT environment or our systems.
You must engage and authorise each Third-Party Consultant at your own risk. You are responsible for their acts and omissions, including their use or misuse of access or credentials and any changes they make to your IT environment. To the extent permitted by law, we are not responsible for any loss, damage, disclosure, security incident, service interruption, corruption, configuration issue or other consequence arising from or in connection with a Third-Party Consultant’s access, acts or omissions. Providing access, including Global Administrator access, during the term of the Agreement does not make us responsible for supervising, managing or verifying the Third-Party Consultant’s work.
9. Your responsibilities
9.1. Our ability to provide desktop management plans depends on your cooperation and on your environment and hardware meeting the minimum requirements we specify to you in writing from time to time. If you do not meet those requirements, or do not provide timely access, information or assistance, the desktop management plan may be delayed, limited or unavailable, we may suspend part or all of the desktop management plan until those requirements are met, and we are not responsible for any resulting failure to meet service levels, delays or degradation. Any additional work required because those requirements are not met may be charged separately.
9.2. You are responsible for:
(a) maintaining a reliable internet connection (except where we have provided internet services under your Order);
(b) keeping your premises and cabling in good working order and compliant with Australian industry standards; and
(c) not doing anything that interferes with the proper functioning of the ordered products and services.
9.3. You must:
(a) ensure that supported items meet the minimum technical and compatibility requirements set out in our support services guide;
(b) maintain appropriate licensing and authorised use of all systems;
(c) provide timely access, information and cooperation as reasonably required by us; and
(d) ensure that your users comply with reasonable security and acceptable use practices.
10. Bring your own hardware
10.1. If we provide a desktop management plan for hardware that you own and that was not supplied to you by us or our finance partners (i.e. client-owned hardware or bring your own device) (BYOD), you agree to the following:
(a) You must ensure that all BYODs presented for support meet our minimum technical standards set out in our support services guide or specified by us in writing from time to time.
(b) Windows BYODs must be running Windows Pro or higher (Windows Home is not supported).
(c) Our support services guide may specify the types or brands of BYODs that are supported under our desktop management plans. Any BYOD not identified as supported will be excluded from the desktop management plans unless we agree otherwise in writing.
(d) If a BYOD or configuration does not meet these standards, we may still provide support, but additional fees may apply. We will let you know before proceeding if that is the case.
(e) We will support the BYOD for its desktop operating environment only and the operating system, Microsoft applications and the supported applications listed in your Order.
(f) If a hardware fault is identified, we will recommend that you contact the supplier or manufacturer directly. We are not obligated to provide loan hardware while repairs or a replacement is arranged.
(g) Each new or factory-reset BYOD will need to be set up for the desktop management plan, which requires a BYOD remote installation and payment of the applicable installation fee as further set out in your Order.
(h) If you purchased a BYOD through us and it develops a fault:
(i) we will initiate the returns process with our supplier on your behalf and provide you with the Returns Authority (RA) number and any relevant shipping instructions; and
(ii) where the warranty is handled directly by the manufacturer (for example, Lenovo or AOC), we will register the warranty claim and provide you with the manufacturer’s contact details so they can deal with you directly.
10.2. You agree that:
(a) our support is limited to the configured operating environment and services;
(b) we are not responsible for hardware faults, failures, repair or replacement;
(c) we are not required to provide temporary or replacement BYODs; and
(d) we may provide recommendations in relation to replacement or remediation of BYODs, but those activities are outside our desktop management plan unless otherwise agreed.
(e) You and your users access business applications, including email, on any hardware that is not supported by us entirely at your own risk. To the extent permitted by law, we are not responsible or liable for any loss, damage, disclosure, security incident, unauthorised access, service interruption, data loss or other consequence arising from or in connection with that access or use.
11. Projects and changes
11.1. A desktop management plan does not include:
(a) system migrations;
(b) migration to a new practice management platform (for example, moving from LEAP to Smokeball, or vice versa);
(c) reinstalling or rebuilding an operating system; or reinstalling applications or data following such a rebuild;
(d) advice on what hardware to purchase;
(e) extensive training for your users;
(f) significant upgrades or reconfigurations;
(g) implementation of new systems or environments; or
(h) any other significant changes or implementations.
Such changes or implementations will be treated as project work and will be separately scoped and charged.
12. Offboarding
12.1. Reasonable assistance
On termination or expiry of the desktop management plan, we will provide reasonable transition assistance to facilitate the orderly transfer of services, systems, data or access, subject to payment of our applicable fees and your reasonable cooperation. We are not obliged to continue providing any services after the end of the Agreement except to the extent expressly agreed in writing. We are not responsible for any delay, disruption or issue arising from the acts or omissions of you, your replacement provider or any third party during transition. Transition assistance may include:
(a) assisting with transfer of systems, data or access; and
(b) cooperating with a replacement provider, where applicable.
12.2. Offboarding fees
We will not charge separately for standard offboarding where it is limited to providing administrator credentials and reasonable helpdesk assistance. If you require additional offboarding services, such as preparing documentation, developing a transition plan, providing migration assistance, creating handover materials, or delivering support beyond the provision of administrator credentials and reasonable helpdesk assistance, those services may be treated as project work and separately scoped and charged.
12.3. Timing and process
(a) All hardware must be returned within 7 days after the end of the Agreement. All other offboarding related tasks must be completed during the final month of the Agreement, subject to payment of all outstanding fees. Where an Agreement ends without sufficient prior notice to complete such tasks during the final month, they must be completed as soon as reasonably practicable after termination or expiry, subject to payment of all outstanding fees.
(b) If offboarding is not completed within the period set out in clause 12.3(a) for any reason, including because hardware has not been returned, required information or cooperation has not been provided or payment has not been made, we will continue to bill you for successive one-month periods at the same rate that applied during the last month of the relevant Agreement before its termination or expiry until offboarding is completed.
(c) We will provide access to administrative credentials once all outstanding amounts have been paid and the offboarding process is complete.
12.4. Microsoft licences
Any Microsoft subscriptions that are not aligned with our billing cycle at the time of offboarding must either be paid out for the remainder of the current billing period or transferred to your new IT provider. We will work with you to determine the most practical approach.
