Microsoft Modern Workplace Services
Akita provides Modern Workplace Software as a Service supporting Microsoft 365 productivity, collaboration, identity, and device management. The service enables secure email, file sharing, user access control, and endpoint management, with configuration, monitoring, and support delivered through cloud-native Microsoft platforms to support secure, scalable day-to-day operations.
Features
- Microsoft 365 tenant configuration and ongoing service optimisation
- Secure identity and access management using Azure Active Directory
- Cloud email, collaboration, and document management services
- Endpoint and device management through Microsoft Intune
- Security policy configuration and baseline enforcement
- User access control and role-based permissions management
- Service monitoring and incident management support
- Integration with existing Microsoft 365 environments
Benefits
- Improves secure collaboration across teams and remote workers
- Reduces operational risk through consistent security configuration
- Simplifies user access and identity management
- Supports scalable growth without service redesign
- Improves productivity through reliable cloud collaboration tools
- Reduces support effort through standardised service management
- Maintains service continuity during organisational change
- Supports compliance with public sector security expectations
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 8 4 7 6 5 9 3 3 8 8 5 4 7 8
Contact
AKITA SYSTEMS LIMITED
Akita
Telephone: 0330 058 8000
Email: info@akita.co.uk
About the service
- Service categories
-
Applications
Collaborative
- Team collaboration
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- The service extends Microsoft 365 cloud services, including Exchange Online, SharePoint Online, OneDrive, Microsoft Teams, Azure Active Directory, and Microsoft Intune, by providing configuration, optimisation, security management, and ongoing operational support within the existing Microsoft tenant.
- Cloud deployment model
- Public cloud
- Service constraints
- The service is delivered remotely and is dependent on Microsoft 365 platform availability. Planned maintenance is governed by Microsoft service update schedules. Functionality depends on the buyer holding appropriate Microsoft 365 licences. The service does not include bespoke software development, non-Microsoft cloud platforms, or on-premise infrastructure management.
- System requirements
-
- Active Microsoft 365 tenant with appropriate user licences
- Supported end user devices and operating systems
- Reliable internet connectivity for cloud access
- Supported web browsers or Microsoft client applications
- Azure Active Directory enabled for identity management
User support
- Email or online ticketing support
- Yes
- Support response times
- Akita provides email and online ticketing support during UK business hours, Monday to Friday. Initial response times are aligned to incident priority, with standard service requests acknowledged within one business day. Critical incidents are prioritised and responded to more rapidly. Weekend and out-of-hours support can be agreed where required as part of a separate support arrangement.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- No
- Support levels
-
Akita provides structured support levels aligned to service criticality and user impact.
Standard Support is included as part of the service and provides email, ticketing, and phone support during UK business hours, Monday to Friday. Incidents are prioritised based on impact and urgency, with defined response targets for service requests and incidents. Support is delivered by experienced cloud support engineers with Microsoft 365 expertise.
Enhanced Support is available at additional cost and provides extended support hours, faster response targets, and proactive service monitoring. This level includes scheduled service reviews and enhanced incident management.
Where required, a named technical account manager can be provided at additional cost. The technical account manager acts as a single point of contact, coordinates support activity, oversees service performance, and supports service optimisation and change planning. Day-to-day technical support continues to be delivered by cloud support engineers.
Support pricing varies based on the selected support level, service scope, and user volumes and is agreed at call-off stage. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Akita supports users to get started through a structured onboarding process delivered remotely. This includes initial service setup, configuration of user access, security policies, and core Microsoft 365 services within the existing tenant.
Users are supported with online guidance and documentation covering access, day-to-day use, and common tasks. Where required, remote onboarding sessions are provided to help administrators and users understand the service, security controls, and collaboration tools.
Akita provides knowledge transfer through walkthroughs and practical guidance rather than bespoke training programmes. Ongoing support is available through email, ticketing, and phone support to help users adopt the service and resolve issues as they arise. Onsite training is not provided as part of the service. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract, users retain full access to their Microsoft 365 tenant and data. Data extraction is supported using standard Microsoft tools and export functionality, including administrative export features for email, documents, and collaboration content.
Akita supports the buyer by providing guidance on data export processes and, where required, assistance with planning and executing data extraction. Data can be exported in standard, widely used formats supported by Microsoft services. No proprietary data formats are used.
Once the contract ends and data extraction is complete, Akita’s access to the tenant is removed in line with agreed offboarding procedures, ensuring continued data ownership and control remains with the buyer. - End-of-contract process
-
At the end of the contract, Akita follows a structured offboarding process agreed with the buyer. This includes confirming contract closure, removing Akita administrative access, and supporting the buyer with service transition planning where required. The buyer retains full ownership and control of their Microsoft 365 tenant, licences, and data.
The contract price includes standard offboarding activities such as knowledge handover, guidance on data extraction, and confirmation of access removal. No proprietary systems or data formats are used, enabling a straightforward exit.
Additional support beyond standard offboarding, such as extended transition assistance, bespoke reporting, or additional support hours, can be provided at extra cost if requested by the buyer. All additional costs are agreed in advance at call-off stage. - Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The mobile service provides access to core Microsoft 365 functionality, including email, document access, and collaboration tools, optimised for smaller screens and touch interfaces. Some advanced configuration, administration, and reporting features are only available through desktop browsers or client applications. The mobile experience is designed for productivity and access, while desktop access supports full management and administrative functionality.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- The service interface is provided through Microsoft 365 web portals and standard Microsoft client applications. Users access email, documents, and collaboration tools via browser-based interfaces and mobile or desktop applications. Administrators manage users, security, and configuration through Microsoft admin centres. The interface is cloud-based, role-driven, and accessible from supported devices without requiring bespoke software.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
-
Describe any interface testing you’ve done with users of assistive technology
Accessibility assurance is supported through Microsoft’s published accessibility conformance and ongoing testing of Microsoft 365 services against recognised accessibility standards. Microsoft carries out regular testing with assistive technologies such as screen readers, keyboard navigation, and voice control tools. Akita configures and supports the service in line with these accessibility features and responds to accessibility-related support requests to help users use built-in assistive functionality effectively. - API
- No
- Customisation available
- Yes
- Description of customisation
-
Users can customise the service through configuration within their Microsoft 365 tenant. Customisable elements include user access and permissions, security and compliance policies, collaboration settings, device management rules, and service governance controls.
Customisation is carried out through Microsoft administrative portals using role-based access. Administrators can configure settings directly or request changes through Akita’s support channels. Changes are managed using controlled change processes to reduce risk and maintain service stability.
Customisation is restricted to authorised buyer administrators and approved Akita support engineers. End users can personalise aspects of their own experience, such as collaboration settings and device preferences, within the limits defined by organisational policies. This approach allows flexibility while maintaining security, compliance, and operational consistency.
Scaling
- Independence of resources
- The service is delivered using Microsoft 365 multi-tenant cloud architecture designed to scale automatically based on demand. Microsoft manages capacity, performance, and resource allocation to ensure consistent service levels across tenants. Akita supports this by configuring services in line with best practice and monitoring service health. Buyer tenants are logically isolated, and usage by other organisations does not affect availability or performance of individual services.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides usage and activity metrics available through Microsoft 365 administrative reporting. Metrics include user activity, service adoption, storage usage, collaboration activity, and service health information. These metrics help buyers monitor service usage, identify trends, and support capacity and governance decisions.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Supplier type
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Microsoft Corporation
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Baseline Personnel Security Standard (BPSS)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users export their data using standard Microsoft 365 administrative tools and built-in export functionality. Data such as emails, documents, and collaboration content can be exported in widely used, non-proprietary formats supported by Microsoft services. Akita provides guidance on export processes where required but does not restrict or control data export.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service is delivered using Microsoft 365 SaaS platforms, which are covered by Microsoft’s published service availability commitments. Microsoft provides financially backed SLAs for core services, with typical monthly uptime targets of 99.9% or higher, depending on the specific service component.
Availability is monitored continuously through Microsoft service health reporting. Where Microsoft does not meet its published availability commitments, service credits may be available in line with Microsoft’s SLA terms.
Akita supports buyers by monitoring service health, communicating service incidents, and assisting with incident management and escalation where required. Any service credits applicable under Microsoft’s SLA are passed through to the buyer in accordance with the underlying service terms. Akita does not apply additional penalties beyond those defined by the platform provider but works with buyers to minimise disruption and restore service as quickly as possible. - Approach to resilience
-
The service is built on Microsoft 365 cloud infrastructure designed for high availability and resilience. Microsoft operates geographically distributed datacentres with built-in redundancy, automated failover, and capacity management to maintain service continuity during component or site failures.
Data is replicated across multiple systems within the Microsoft cloud, reducing the risk of data loss and supporting service recovery. Platform resilience is supported by continuous monitoring, automated recovery processes, and regular testing of resilience controls.
Akita supports service resilience by configuring services in line with Microsoft best practice, monitoring service health, and responding to incidents in coordination with Microsoft where required. Detailed datacentre architecture and resilience design are documented by Microsoft and can be made available to buyers on request where appropriate. - Outage reporting
-
The service reports outages through Microsoft’s Service Health Dashboard, which provides real-time visibility of service status, incidents, and planned maintenance. Administrators can view current issues, affected services, and progress updates through the Microsoft 365 admin portal.
Email notifications are available to alert administrators to service incidents and changes in service status. Akita monitors service health and communicates relevant outages or incidents to buyers, providing updates and guidance where required.
Outage information is provided through dashboards and notifications rather than a dedicated Akita API. Buyers can access detailed incident reports and post-incident summaries through Microsoft service health communications and Akita support channels.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is restricted using role-based access controls. Administrative access is limited to authorised buyer administrators and approved Akita support staff. Authentication is enforced through identity management controls, including Multi-Factor Authentication. Access rights are granted on the principle of least privilege and reviewed regularly. Support channels are protected to ensure only authorised users can raise, view, or manage support requests related to the service.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Akita operates a formal information security management framework aligned to ISO 27001. Information security policies cover access control, data protection, incident management, risk management, supplier assurance, and business continuity. Policies are approved at senior management level and apply to all staff and services.
Security governance is overseen by a board-level individual with responsibility for information security. Day-to-day management is supported by defined roles responsible for policy implementation, monitoring, and incident response. Security risks and incidents are reported through structured internal escalation processes.
Policies are enforced through technical controls, staff training, and regular review. Compliance is monitored through internal checks, audits, and management reviews. Where required, corrective actions are tracked and implemented to ensure continuous improvement. This approach ensures security policies are consistently applied and remain effective across all services. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
-
Akita manages configuration and change through controlled, documented processes aligned to recognised security standards. Service components are tracked using configuration records and service documentation throughout their lifecycle.
Proposed changes are assessed for operational and security impact before approval. Security considerations include access control, data protection, and potential service disruption. Changes are implemented in a controlled manner, with testing where appropriate, and recorded to maintain traceability and accountability. - Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
-
Akita manages vulnerabilities through structured processes aligned to recognised security standards. Potential threats are assessed using platform security alerts, risk assessments, and impact analysis to determine severity and priority.
Patches and security updates are applied in line with Microsoft release cycles and security guidance, with urgent vulnerabilities prioritised for rapid deployment. Akita monitors trusted threat intelligence sources, including Microsoft security advisories and industry vulnerability notifications, to identify emerging risks and respond promptly to protect services. - Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
Protective monitoring is supported through Microsoft security monitoring and service health capabilities, combined with Akita’s operational oversight. Potential compromises are identified through security alerts, audit logs, and anomaly detection within the Microsoft 365 platform.
When a potential compromise is identified, incidents are assessed and prioritised based on impact and risk. Akita responds by investigating alerts, applying containment measures where required, and coordinating with Microsoft support. Response times are aligned to incident severity, with high-risk incidents prioritised for immediate action and escalation. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Akita operates defined incident management processes aligned to recognised security standards. Pre-defined procedures are in place for common service and security incidents to support consistent response.
Users report incidents through email, ticketing, or phone support. Incidents are logged, prioritised, and managed based on impact and urgency. Akita provides incident updates during resolution and supplies post-incident summaries or reports where appropriate, including actions taken and recommendations to prevent recurrence - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 7%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- ISO/IEC 27001 accredited by
- British Assessment Bureau (UKAS accredited)
- ISO/IEC 27001 accreditation date
- Friday 18 January 2019
- What the ISO/IEC 27001 doesn’t cover
- The ISO/IEC 27001 certification does not cover customer-owned systems or infrastructure not managed by Akita Systems Limited, physical security controls at customer premises, end-user devices not under Akita management, or non-IT business activities outside the defined scope of IT support, cloud services, and hosted and recovery services.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- ISO 9001 certification accredited by
- British Assessment Bureau (UKAS accredited)
- ISO 9001 accreditation date
- Thursday 23 April 2015
- What the ISO 9001 doesn’t cover
- The ISO 9001:2015 certification does not cover activities outside the defined scope of IT service delivery, including non-IT business operations, customer-owned systems or processes not managed by Akita Systems Limited, services delivered entirely by third parties outside Akita’s quality management system, and physical site operations at customer premises where Akita does not have operational control.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber Essentials Certificate Number
- 56073cca-376a-486b-a991-0f76b99f23b2
- Cyber essentials plus
- Yes
- Cyber Essentials Plus Certificate Number
- Cc55b424-1c83-4f89-8550-44e6b24ec430
- Other security certifications
- No
Social value
- Mission: Make Britain a clean energy superpower
-
To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement