Microsoft Dynamics 365 for Sales
Microsoft partners providing business analysis, development, training, consultancy, implementation and support for Dynamics 365. Microsoft Dynamics 365 specialists and licensing provider. Cantarus have extensive experience integrating Dynamics CRM with Veolia (CIS/Echo).
Features
- Lead and Opportunity Management
- Sales Insights (AI-Driven)
- Sales Forecasting and Pipeline Analytics
- Customer 360° View (Dataverse Integration)
- Relationship Intelligence and Activity Tracking
- Seamless Microsoft 365 Integration, such as Outlook and Teams
- Guided Selling and Sales Playbooks
- Customisation and Extensibility - Low-Code / No-Code
- Enterprise Security and Compliance
Benefits
- Improvements to sales productivity
- Faster deal closure
- Improved accuracy for forecasting
- Enhance customer engagement
- Data-driven decision making
- Better collaboration across teams
- Maintain consistent sales processes
- Make improvements to customer retention
- Ability to scale sales operations
- Lower Total Cost of Ownership (TOC)
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
1 5 8 2 8 8 9 3 9 7 0 5 5 3 6
Contact
CANTARUS LIMITED
Lee Adams
Telephone: 0161 971 3200
Email: enquiries@cantarus.com
About your service
- Service categories
-
Applications
Customer relationship management
- Sales force productivity and management
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- None
- System requirements
-
- Supported web browser
- Microsoft Entra ID (formerly Azure AD) tenant
- Internet connectivity and bandwidth
- Supported operating systems
- Microsoft 365 integrations pre-requisites
- Power Platform and Dataverse availability
- Mobile app device requirements
- Security, identity and access controls
- Regional datacentre availability
- Licensing and subscription requirements
User support
- Email or online ticketing support
- Yes
- Support response times
-
Our standard support is provided between the hours of 0900 and 1730 British time, Monday to Friday excluding public holidays.
Service level targets – specifically the time within which we aim to be actively working on a resolution – for support are as follows (excluding on-site support):
Business Critical Within 1 business hour
High Priority Within 4 business hours
Medium Priority Within 2 business days
Low Priority Within 5 business days - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Our standard support is provided between the hours of 0900 and 1730 British time, Monday to Friday excluding public holidays. 24-Hour Severity 1 support is also available on some hosting packages. Standard timebank support is purchased on a per man-day basis and can be used across any of the Cantarus service offerings - any purchased time which is unused during the month can be rolled over for up to 3 months. Standard Timebank charged at £995/day with a 1 day minimum.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Starting with a discovery and audit (via surveys / interviews and workshops with stakeholders) to understand your business and how investment into the CRM will support and accelerate your goals. We run 'Show & Tell' sessions with super users allowing input during product development; adopting an agile project management style for implementation. End users are involved throughout development to adapt to any new requirements and we provide robust testing environments for QA and identification of features to optimise before delivery. We can continue to offer ongoing support for the CRM.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- Other
- Other documentation formats
- DOCX
- End-of-contract data extraction
- Data is saved in Microsoft's datacentre and a SQL back-up can be requested or data can be extracted using a number of different tools - including native functionality to export data to Excel.
- End-of-contract process
- Ahead of commencing the project, we will discuss and agree the end of contract scenarios.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Documentation for both onboarding and offboarding is designed to be as accessible as possible. We provide materials in commonly used formats (Word, PDF), allowing user to open them on a variety of devices without additional software.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Similar to responsive principles for websites i.e. optimisation of viewing across screen sizes / devices, the UI uses responsive design to make Microsoft 365 portable; allowing records and forms to be viewed either on large screen devices or smaller mobile devices.
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AA
- Description of service interface
- With a clean and role -based workspace, Microsoft Dynamics 365's app interface is designed for customer service teams and layout is adaptive to the device being viewed upon. Key actions can be accessed by the command bar and there is also navigation for entities such as cases, contacts and knowledge articles. The dashboard also displays real-time metrics and queues. Cases can be quickly updated via interactive forms and related records can be organised via sub grids and tabs. Features integrated search, filters and AI suggestions to assist workflow and allows for in-app collaboration with Microsoft 365 and Teams integration.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Microsoft Dynamics 365 is committed to accessible and inclusive design, for example, keyboard shortcuts and high-contrast settings. Further information about the accessibility of apps, add-ins can be found here:https://docs.microsoft.com/en-gb/dynamics365/get-started/accessibility; plus Microsoft's wider approach to accessibility standards here: https://www.microsoft.com/en-us/accessibility
- API
- Yes
- What users can and can't do using the API
-
Dynamics 365 API Capabilities and Limitations Users can interact with Dynamics 365 via the Dataverse Web API and OData/REST endpoints to automate, integrate, and extend functionality.
Through the API, users can create, read, update, and delete (CRUD) records for entities like Accounts, Contacts, Leads, Cases, and custom entities. They can also query data using FetchXML or OData, trigger workflow or business process flows, and integrate with external applications or services.
Service Setup via API: Users can configure certain aspects programmatically, such as creating custom entities, fields, relationships, and security roles, or provisioning environments via Power Platform admin APIs.
Making Changes via API: Users can update record data, assign ownership, update status, and link related records. Automation and bulk operations are supported using batch requests.
Limitations: Some system-level settings, such as environment-wide configurations, licensing, or core Dynamics 365 feature toggles, cannot be changed via the API. Complex UI customizations, dashboards, and reports must be done through the Power Platform or UI designer. API limits apply to request volume and execution time, and some operations require proper security roles and permissions. This makes the API powerful for data operations but limited for full system administration. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Dynamics can be highly customisable and a vast amount of changes can be made using 'point and click' configuration via the in-built management tool. Further customisations and extensions can also be built using the API, .NET code or Power Automate.
Scaling
- Independence of resources
- Microsoft guarantees consistent performance through multi-tenant Azure architecture, auto-scaling resources, and load balancing. Each tenant’s data and operations are isolated, ensuring one customer’s usage doesn’t impact another’s. Microsoft monitors service health, capacity, and throttling limits to prevent overuse, and enforces API and request quotas per user. Critical background processes are prioritised, and updates are staged to minimise disruption. This combination of isolation, scaling, and monitoring ensures individual users experience stable, reliable performance regardless of overall system demand.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Service usage metrics are provided through the Power Platform admin centre and Dynamics 365 analytics tools. Service metrics are available via pre-built dashboards, Power BI reports or audit logs. Access to these metrics can be role-based and end users will also be able to see usage through dashboards within the app.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Microsoft
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- Never
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Users can export data using the built-in Export to Excel feature for individual views, grids, or reports, allowing immediate download in Excel or CSV formats. For larger or automated exports, users can leverage the Data Export Service or Power Automate flows to sync data to Azure SQL, Dataverse, or other storage. Additionally, the Dataverse Web API enables programmatic extraction of records for integration or backup purposes. Export permissions depend on the user’s security roles and access rights within Dynamics 365.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XLSX
- DOCX
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Availability is guaranteed by Microsoft as part of its SaaS Service hosted on Azure and designed with redundancy, failover, and geographically distributed data centres. Microsoft provides a 99.9% uptime SLA for most applications (measured monthly) covering accessibility via supported browsers and APIs. Service health is monitored continuously, and customers can view current status via the Microsoft Service Health dashboard.
If Microsoft fails to meet SLA targets, customers may claim service credits. The credit is calculated as a percentage of the monthly subscription fee based on the level of SLA breach (e.g., uptime below 99.9% triggers partial credit) However, the downtime calculation excludes planned maintenance and agreed-upon downtime. Customers must submit claims within a defined period per the SLA terms.
This approach ensures customers experience reliable access, with financial accountability if availability targets are not met, while Microsoft continually invests in resilient architecture, monitoring, and disaster recovery to maintain uptime. - Approach to resilience
- Dynamics 365 is built on Microsoft Azure’s resilient cloud infrastructure to ensure continuity, data protection, and high availability. Key design features include: geographically distributed datacentres with redundant power, networking, and storage, allowing failover in case of localised outages. Multi-region replication of critical customer data within Azure, ensuring automatic backup and recovery. Redundant compute and network paths within each datacentre to prevent single points of failure. Automated monitoring and self-healing systems detect and mitigate failures before they impact users. Disaster recovery and backup procedures comply with regulatory and compliance standards, including periodic testing. For sensitive or detailed datacentre architecture information, Microsoft provides specifics on request to verified customers or partners. This design ensures that Dynamics 365 meets the government’s “Asset Protection and Resilience” principle, maintaining service continuity, data integrity, and rapid recovery from hardware, software, or network failures.
- Outage reporting
- Available via multiple channels, Microsoft maintains a Service Health dashboard to display current service status, planned maintenance and historical incidents for all Dynamics 364 services. Users can view real-time updates for their region and service. Administrators can subscribe to email notifications for their environments, planned maintenance, service incidents and updates. Alerts include: impact, scope and estimated resolution times. The Service Communications API also allows users to programmatically retrieve service health and incident information to integrate with internal monitoring systems. Outage reporting is designed to provide timely, actionable information for administrators to respond and communicate internally. The system distinguishes between planned maintenance and unplanned outages; helping to plan and maintain business continuity. Where required, Power Automate or alerts to push notifications to Teams (or other tools) when incidents occur can be configured.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to Dynamics 365 management interfaces and support channels is restricted using Azure Active Directory authentication, role-based access control (RBAC), and least-privilege principles. Administrative access requires strong authentication, including multi-factor authentication (MFA). Access is logged and monitored, with audit trails enabled. Support access is tightly controlled, time-bound, and approved, following Microsoft security and privacy policies, with customer data access granted only when explicitly authorised
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- All details are available in the Cantarus Information Security Policy which is available on request. If a security issue is identified, then it should immediately be reported to the Cantarus information Security Manager, who will escalate this to the board of directors. Depending on the scope of the issue identified, a small team will be allocated to deal with the issue. The exact makeup of this team will depend on the skills required in order appropriately identify and resolve the issue, however all reports from this team will be returned to the Information Security Manager. Staff are regularly provided with updates on security trends and training on how to deal with them.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Microsoft follow a documented change management process as audited by Deloitte & Touche LLP including: CA-18- All changes to the Dynamics 365 environment follow document change management procedures and are tracked in a change management database. CA-19- Key stakeholders approve major and minor changes prior to release into production. CA20- Emergency changes to production environment follow the emergency change approval process
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Both internal-trusted and external-untrusted network and system scanning are performed to check patch compliance and exposure to known technical vulnerabilities. Dynamics 365 has established recurring processes to review scan results produced by both Azure and Dynamics 365 and remediate any identified non-compliance or vulnerabilities. Dynamics 365 is notified by the Cyber Defence Operations Centre (CDOC) team upon identification of technical vulnerabilities associated with Dynamics 365 assets using the Microsoft Security Response Centre (MSRC) and other security forums; this includes the notification of the latest patches released.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Dynamics 365 employs sophisticated software-defined service instrumentation and monitoring that integrates at the component or server level, the datacentre edge, our network backbone, Internet exchange sites, and at the real or simulated user level, providing visibility when a service disruption is occurring and pinpointing its cause. Proactive monitoring continuously measures the performance of key subsystems of the Dynamics 365 services platform against the established boundaries for acceptable service performance and availability. When a threshold is reached, or an irregular event occurs, the monitoring system generates warnings so that operations staff can address the threshold or event.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Microsoft has developed robust processes to facilitate a coordinated response to incidents. Identification – System and security alerts may be harvested, correlated, and analysed. Containment – The escalation team evaluates the scope and impact of an incident. Eradication – The escalation team eradicates any damage caused by the security breach, identifies root cause for why the security issue occurred. Recovery – During recovery, software or configuration updates are applied to the system and services are returned to a full working capacity. Lessons Learned – Each security incident is analysed to protect against future reoccurrence. More information http://aka.ms/Office365SIM
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
- Public Services Network (PSN)
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- We can provide a Microsoft Dynamics 365 instance for a free 30 day trial.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 15%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Peers Quality Assurance Ltd
- ISO/IEC 27001 accreditation date
- Wednesday 27 August 2025
- What the ISO/IEC 27001 doesn’t cover
-
ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Peers Quality Assurance Ltd
ISO/IEC 27001 accreditation date
Wednesday 27 August 2025
What the ISO/IEC 27001 doesn’t cover
Cantarus Limited’s ISO27001 certification does not cover Cantarus CRM Limited, which is a separate legal entity and therefore excluded from the scope of certification. All information security controls and audited processes apply only to the in-scope operations of Cantarus Limited as defined in the ISMS scope statement. - ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Peers Quality Assurance Ltd
- ISO 9001 accreditation date
- Wednesday 27 August 2025
- What the ISO 9001 doesn’t cover
- Cantarus Limited’s ISO9001 certification does not cover Cantarus CRM Limited, which is a separate legal entity and therefore excluded from the scope of certification.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Cb4ae068-17cb-4f67-89f9-0ea82c6e1dfc
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- B8bb923e-c4b1-4a2e-9c78-0ab290fa9e49
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
- Delivery of additional environmental benefits through the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Inclusive and accessible recruitment practices, and retention-focused activities, including those provided in the Guide for line managers on recruiting, managing and developing people with a disability or health condition
- Working conditions which promote an inclusive working environment and promote retention and progression
- Other measures to provide equality of opportunity for disabled people and those with health conditions into employment, including becoming a Disability Confident employer and inclusion of supported businesses in the contract supply chain
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-