Microsoft 365
Services in designing, implementing, and supporting Microsoft 365 and the Office portfolio. A comprehensive suite of services tailored to meet the diverse productivity and collaboration needs, ensuring seamless integration and optimal usage of Microsoft's powerful suite of tools, supported by expert guidance and ongoing support to drive productivity,
Features
- Word
- Excel
- PowerPoint
- OneDrive for Business
- OneNote
- Outlook
Benefits
- Cloud Storage / File Sharing
- Enterprise Mobility
Pricing
£3.30 a user a month
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
1 9 7 1 6 3 1 5 3 5 7 1 4 3 2
Contact
Transputec Limited
G-Cloud Team
Telephone: 0203 5886570
Email: G-cloud@transputec.com
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Microsoft 365, Office 365
- Cloud deployment model
-
- Public cloud
- Hybrid cloud
- Service constraints
- None
- System requirements
- None
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- Subject to agreement, 24x7x365
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes, at an extra cost
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- WCAG 2.1 AAA
- Web chat accessibility testing
- None
- Onsite support
- Yes, at extra cost
- Support levels
-
Subject to the agreement 24x7x365
Fully Managed Service
Co-Managed Service (in collaboration with client existing IT team)
Technical Account Manager
Strategic Advisor - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Onsite training, online training and documentation and user guides
- Service documentation
- Yes
- Documentation formats
-
- HTML
- Other
- Other documentation formats
- Online Video
- End-of-contract data extraction
- Migrate application data to a new service. Methods and frameworks prescribed by the vendor.
- End-of-contract process
- Option to renew or cancel the contract. Agreement on data to be anonymised or deleted. Transfer of any data subject to the data source and destination
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Linux or Unix
- MacOS
- Windows
- Windows Phone
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Microsoft 365 includes various cloud services which offer mobile device capabilities. Most Microsoft cloud services such as Office 365, Teams, SharePoint, Power BI etc. have a mobile app which has reduced functionality. Where a native mobile app is not available, most commonly used browsers are supported. More details can be provided upon request.
- Service interface
- Yes
- User support accessibility
- WCAG 2.1 AA or EN 301 549
- Description of service interface
- Microsoft 365 uses various web portals which allows users and administrators to administer, configure and manage its cloud services. One of the main portals that would be used is https://portal.office.com.
- Accessibility standards
- WCAG 2.1 AA or EN 301 549
- Accessibility testing
- Microsoft performed these tests to achieve their WCAG certification. Because Microsoft is a major software and cloud-services provider to states and governments around the world, it is committed to complying with all relevant international standards and compliance controls. By adhering to these wide-ranging accessibility standards, Microsoft ensures that all customers—both inside and outside of government—can use Microsoft services and products.
- API
- Yes
- What users can and can't do using the API
-
Depending on service contract, up to full administration of the service.
Microsoft Graph is a unified API endpoint for accessing data across Microsoft 365, which includes Office 365, Enterprise Mobility, and Security and Windows services. It provides a simplified developer experience, with one endpoint and a single authentication token that gives your app access to data across all these services.
Further information can be found at: https://docs.microsoft.com/en-us/graph/overview
API documentation is publicly available - API documentation
- Yes
- API documentation formats
-
- HTML
- ODF
- Other
- API sandbox or test environment
- No
- Customisation available
- Yes
- Description of customisation
- Depending on service contract, Microsoft 365 cloud services can be configured and customised to conform to most business needs, even when they are complex. The customisation can be done by authorised users from within the portals available upon purchasing the product. End users can also customise the desktop applications such as Office apps and Teams, to fit their user preferences. If technical services are required, we can look at technical resource available and any associated costs.
Scaling
- Independence of resources
- Service designed to scale with increased user demand
Analytics
- Service usage metrics
- Yes
- Metrics types
- Provided by vendor
- Reporting types
- Real-time dashboards
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Microsoft, Mimecast
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Up to Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 3.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v3.0
- Encryption of all physical media
- Data sanitisation process
- Yes
- Data sanitisation type
- Explicit overwriting of storage before reallocation
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Data exporting capabilities are available within the Microsoft 365 portals and what can be exported varies by service. For example you can export a list of users and groups from your Office 365 tenant directory, but you cannot export your mailbox data from the Office 365 portal, as Microsoft host the data in their own servers, however mailbox data is cached locally on PST Files and they can be retrieved locally with technical migration tools if required.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Bonded fibre optic connections
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- Microsoft's 365 service level agreements vary by service. Microsoft provide financial backing to our commitment to achieve and maintain the service levels for each service. If they do not achieve and maintain the service levels for each service as described in the Service Level Agreement, then you might be eligible for a credit towards a portion of your monthly service fees
- Approach to resilience
- Multi zone and multi data centre replication configuration Information is available on request.
- Outage reporting
- There is a publicly available dashboard which includes service health information. Email alerts can be configured, and the API can also be used.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- 2-factor authentication
- Username or password
- Access restrictions in management interfaces and support channels
- Role based access provisions
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- 2-factor authentication
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- Users receive audit information on a regular basis
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- Between 6 months and 12 months
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LRGA Limited
- ISO/IEC 27001 accreditation date
- 31st May 2023
- What the ISO/IEC 27001 doesn’t cover
- Nothing relevant to this framework response
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- No
- Other security certifications
- Yes
- Any other security certifications
- OSCP (Offensive Security Certified Professional)
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
ISO/IEC 27001:2013
CyberEssentials
Operational security
- Configuration and change management standard
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Configuration and change management approach
-
Configuration management - subject to agreement full lifecycle management
Change management - RFCs raised for Change Board Authority decision include security impacts including change to availabity, integrity and confidentiality, along with rollback plan - subject to sign-off from a technical, service delivery, security and commercial decision maker - Vulnerability management type
- Conforms to a recognised standard, for example CSA CCM v3.0 or SSAE-16 / ISAE 3402
- Vulnerability management approach
- Microsoft Azure vulnerability management is layered across multiple services: https://learn.microsoft.com/en-us/azure/?product=security
- Protective monitoring type
- Undisclosed
- Protective monitoring approach
- Supplier provides full range of security services, tools and standards which can be enabled and configured.
- Incident management type
- Conforms to a recognised standard, for example, CSA CCM v3.0 or ISO/IEC 27035:2011 or SSAE-16 / ISAE 3402
- Incident management approach
-
Microsoft has developed robust processes to facilitate a coordinated response to incidents.
• Identification – System and security alerts may be harvested, correlated, and analyzed.
• Containment – The escalation team evaluates the scope and impact of an incident.
• Eradication – The escalation team eradicates any damage caused by the security breach, identifies root cause for why the security issue occurred.
• Recovery – During recovery, software or configuration updates are applied to the system and services are returned to a full working capacity.
• Lessons Learned – Each security incident is analysed to protect against future re-occurrence.
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v3.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Public Services Network (PSN)
- Other
- Other public sector networks
- ExpressRoute
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Equal opportunity
- Wellbeing
Fighting climate change
ISO 14001:2013 certified
Science Based Targets Initiative registered
Transputec is committed to managing its CO2 emissions and is focused on working with its clients and suppliers to address Scope 3 emissions For more information please visit https://www.transputec.com/about-us/sustainability/Equal opportunity
Transputec is and always has been a non-discriminatory organisation, employing a global workforce without bias or prejudice and are supportive of gender diversity Transputec is part of the Minority Supplier Development UK (MSDUK) Ethnic Minority Business (EMB) network. As MSDUK EMB suppliers we are part of a broad network of innovative, high growth minority owned businesses, providing an important role in the UK and international IT services supply chain..Wellbeing
Transputec has an open approach to health and wellbeing, encouraging communication and understanding through wellbeing events delivered generally on an annual basis as well as community out reach and our international outreach programme
https://www.transputec.com/about-us/our-charity-partners/
Pricing
- Price
- £3.30 a user a month
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- 30 day free trial