Skip to main content

Help us improve the Digital Marketplace - send your feedback

CLARANET LIMITED

Managed EDR for Microsoft Defender

Claranet’s Managed EDR for Microsoft Defender delivers 24×7 analyst‑led monitoring, investigation, and guided response for endpoint threats. We configure and operate Defender for Endpoint in the buyer’s tenant, triage alerts, contain threats, and provide remediation actions and reporting - reducing dwell time and strengthening endpoint security.

Features

  • 24×7 alert triage by CREST‑accredited SOC analysts.
  • Rapid investigation with defined response matrix and runbooks.
  • Threat containment: isolate devices, kill processes, block indicators.
  • Policy baselining, tuning, and continuous optimisation.
  • Monthly reporting and executive summaries.
  • Guided remediation with clear, prioritised actions.
  • Proactive threat hunting where enabled.
  • Buyer‑tenant operation via GDAP least‑privilege access.
  • Integration with ITSM/ticketing workflows.
  • Onboarding playbook and SOC Customer Handbook.

Benefits

  • Faster detection and response to endpoint threats.
  • Reduced dwell time and business impact.
  • Clear actions, less alert fatigue.
  • Expert SOC without in‑house overhead.
  • Improved endpoint visibility and control.
  • Continuous optimisation and tuning.
  • Evidence for audits and assurance.
  • Alignment with Microsoft security ecosystem.
  • Predictable subscription pricing.
  • Scalable across diverse estates.

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at Uk-bidteam@claranet.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

2 3 1 3 1 0 3 2 9 4 0 6 1 3 1

Contact

CLARANET LIMITED Claranet UK Bid Team
Telephone: 020 7685 8000
Email: Uk-bidteam@claranet.com

About your service

Service categories

Applications

Production and operations

  • Other operations
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes
What software services is the service an extension to
Primarily Microsoft Defender for Endpoint; optionally integrated with Microsoft 365 Defender / Defender XDR and ticketing/SIEM as agreed during onboarding.
Cloud deployment model
Public cloud
Service constraints
Service operates in the buyer’s Microsoft tenant; prerequisite Microsoft licensing and supported OSes are required. SOC access is granted via GDAP with least‑privilege roles; buyer approvals are needed for certain response actions. Change windows for policy updates may apply. Microsoft service maintenance is governed by Microsoft; Claranet planned maintenance for supporting systems is communicated in advance. Coverage depends on successful agent deployment and network reachability; devices offline or unsupported are out of scope. Where third‑party security tools conflict with Defender components, remediation may be required before onboarding.
System requirements
  • Microsoft Defender for Endpoint licensing (Plan 2 recommended).
  • Supported Windows, Windows Server, macOS, Linux endpoint operating systems.
  • Buyer grants GDAP access for SOC roles.
  • Network egress allowing Defender telemetry to Microsoft services.
  • Endpoint connectivity for policy updates and response actions.
  • Buyer change authority for device isolation or containment
  • Agreed escalation contacts and incident communications matrix.
  • ITSM/ticketing integration details if required.
  • Admin credentials for initial configuration tasks.
  • Removal of conflicting AV/EDR agents if present.

User support

Email or online ticketing support
Yes
Support response times
The SOC operates 24×7. We acknowledge new tickets and questions promptly and triage by priority using our Response Matrix (e.g., P1 security alerts handled immediately and escalated via the agreed paths). Standard service queries raised in hours receive a same‑business‑day response, with progress updates via ticket and email. Out‑of‑hours questions are handled by the SOC duty team; non‑urgent requests may be queued for business‑hours follow‑up.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
We provide a single, 24×7 managed EDR service tier aligned to our Customer Experience for Managed Services (CXMS), with options to tailor escalation, reporting cadence, and response authorisations. Core inclusions: alert triage, investigation, guided remediation, monthly reporting, tuning, and participation in incident bridge calls when required.
SLA approach: security incidents are prioritised using a defined Response Matrix with time‑bound actions for triage, investigation, and buyer notifications.
Costs: included in the per‑endpoint subscription; onboarding/setup is a one‑off fee; bespoke integrations, additional reporting packs, or onsite support are optional extras.
Named contacts: a Service Delivery contact is provided; a dedicated Technical Account Manager can be added as a paid option for complex estates or enhanced governance requirements.
Channels: tickets portal/email, phone for P1, and scheduled reviews. The SOC uses runbooks and the Claranet SOC Customer Handbook to drive consistent outcomes.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We provide a structured onboarding: discovery and scoping, scene‑setting call, solution workshop, and runbook definition. We assist with agent deployment, policy baselining, RBAC and GDAP configuration, and integration to buyer ITSM where required. Enablement includes an admin walkthrough of the Defender portal, incident process and communications, and how to request tuning. We supply onboarding documentation and the SOC Customer Handbook, plus a short online training session for operational contacts. Optional additions: recorded enablement sessions, tailored SOPs, and a remediation playbook for your environment. Service goes live following a short hyper‑care period to validate detections, escalations, and reporting.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Operational data remains in the buyer’s Microsoft tenant. On exit, buyers can export incidents, alerts, device inventories, and advanced hunting results via the Defender portal or APIs, and retrieve Claranet‑authored artefacts (monthly reports, runbooks, tuning notes) from the ticketing system/secure share. We revoke GDAP access and remove any temporary integration apps. If the buyer requires additional export assistance (for example, scripted extraction or bulk artefact packaging), we can provide this as a time‑and‑materials exercise. We will also provide a service summary and lessons learned on request.
End-of-contract process
Included: Access removal (GDAP), handover call, confirmation of last reports delivered, and guidance on uninstalling agents/offboarding devices. Additional (optional): bulk data extraction, bespoke documentation packaging, onsite workshops, or extended hyper‑care. If the buyer transitions to another provider, we’ll support a structured handover (contacts, runbooks, open actions). Charges remain as per contract until the agreed end date; any post‑termination support is time‑and‑materials unless otherwise agreed in the order form.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Our onboarding and offboarding documentation is delivered in accessible, assistive‑technology‑friendly formats, including Microsoft Word, PDF, HTML/online pages, and structured content delivered through ServiceNow. Documentation such as the EDR onboarding SOPs and customer guides is created using clear semantic structure, consistent headings, labelled tables, meaningful link text, and readable contrast to support screen‑reader navigation. Documents are authored with accessibility features enabled and are compatible with commonly used tools such as NVDA, JAWS, VoiceOver, and keyboard‑only navigation.
Where onboarding is supported by materials like the SOP – EDR Complete Onboarding Process and EDR Customer Onboarding Guide, we maintain a consistent layout that aids comprehension, reduces cognitive load, and ensures predictable navigation. Any artefacts shared during onboarding—such as Security Contact Forms, Exclusions documents, runbooks, or escalation matrices—are provided in machine‑readable formats to support parsing, magnification, and alternative colour schemes.
We can supply alternative formats on request, including large‑print versions, simplified layouts, high‑contrast versions, and CSV/JSON extracts for data‑driven content. For offboarding, all final materials (handover notes, configuration summaries, ticket exports) follow the same accessible‑formatting standards, ensuring users with assistive technologies can review and retain information without barriers.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
Yes
Compatible operating systems
  • Linux or Unix
  • MacOS
  • Windows
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The experience is read‑optimised on mobile.

Desktop/laptop: Full administrator experience in Microsoft Defender portals and Claranet ticketing—advanced hunting, bulk actions, policy changes, evidence downloads, and integration management.

Mobile: Quick visibility of alerts/incidents, ticket updates/comments, approvals, and joining bridges; limited or no support for complex, multi‑pane views, bulk operations, large downloads, or live response workflows.

Security is consistent (MFA/conditional access). Per buyer policy, certain elevated admin actions may be restricted to desktop sessions.
Service interface
Yes
User support accessibility
EN 301 549
Description of service interface
Administrators use Microsoft’s Defender portal for alert visibility, device actions (where authorised), advanced hunting, and reporting. Claranet analysts work in the same tenant with GDAP least‑privilege roles, updating the shared ticket with findings and actions. Buyers receive monthly reports and can request tuning changes via tickets. Optional ITSM integration streamlines assignments and status updates.
Accessibility standards
EN 301 549
Accessibility testing
The primary user interfaces for this service are Microsoft Defender’s web portals and ServiceNow. Both platforms publish Accessibility Conformance Reports (ACRs/VPATs) demonstrating conformance with EN 301 549, including testing against screen readers, keyboard‑only navigation, magnification tools, and high‑contrast modes. We rely on this formal testing as part of our accessibility assurance.
Claranet does not modify these vendor interfaces, but we ensure that the materials we produce—such as service reports, onboarding documents, and ticket updates—are compatible with assistive technologies. We follow accessible‑formatting practices, including structured headings, alternative text, descriptive link labels, and machine‑readable formats (CSV/JSON).
Where buyers identify users with specific accessibility needs, we accommodate them by adapting report formats, simplifying layouts, or offering alternative delivery methods. We can also participate in buyer‑led UAT that includes assistive technology users to validate workflows such as incident review, approvals, or ticket updates.
API
Yes
What users can and can't do using the API
Setup: Buyers typically pre‑provision the Microsoft APIs in their tenant; we assist with permissions and app registrations where required.
Changes: Via API, buyers can query alerts/incidents, extract evidence, update incident status, and—subject to role and policy—invoke certain device actions (for example, isolate device). We align API permissions with RBAC and your security delegation model.
Limitations: API capabilities are governed by Microsoft licensing, RBAC, and rate limits; potentially destructive actions (for example, offboard devices) are not automated by Claranet without explicit authorisation in the runbook. Data retention for API queries follows your Microsoft configuration. We do not expose a separate Claranet proprietary API for this service; integrations use Microsoft and ITSM endpoints agreed at onboarding.
API documentation
Yes
API documentation formats
  • Open API (also known as Swagger)
  • HTML
  • Other
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
What: Alerting thresholds, suppression rules, device groups, automated actions, isolation/kill permissions, escalation contacts, communication channels, reporting templates, and integration end‑points (e.g., ServiceNow/Jira).
How: We run a design and onboarding workshop, agree a Rules of Engagement and escalation matrix, then baseline Defender policies per risk profile. Tuning changes are requested via ticket; material changes follow change control.
Who: Buyer security leads approve policy and response authorisations; Claranet SOC engineers implement and test in coordination with the buyer’s change authority. Quarterly reviews assess effectiveness, false positives, and new detections to keep pace with threats and buyer priorities

Scaling

Independence of resources
EDR processing occurs in the buyer’s Microsoft tenant, so compute/storage is isolated by design. Claranet’s SOC is multi‑tenant but capacity‑planned for peak demand with on‑call scaling. We monitor queue lengths and SLA adherence; major incident surges trigger surge procedures and temporary re‑prioritisation to protect P1 handling across all customers.

Analytics

Service usage metrics
Yes
Metrics types
Typical metrics include alert volumes, incidents by severity, MTTD/MTTR, top tactics/techniques, device coverage, tuning actions taken, and open/closed tickets. We also track SLA attainment against the Response Matrix and provide trend analysis plus recommendations. Quarterly reviews include deeper analysis of use‑case performance and coverage gaps.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
Yes
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least every 6 months
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with another standard
  • Encryption of all physical media
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase
  • Physical Destruction / Hardware containing data is completely destroyed

Data importing and exporting

Data export approach
From the Defender portal and advanced hunting, buyers can export CSV/JSON datasets; incidents/alerts are retrievable via the Microsoft Graph Security or Defender APIs. Claranet‑authored reports are downloadable from tickets/secure share. If the buyer uses Sentinel or a data lake, we can assist to route data to that platform for long‑term retention before exit.
Data export formats
  • CSV
  • Other
Other data export formats
JSON
Data import formats
  • CSV
  • Other
Other data import formats
JSON

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
Service components: (1) Microsoft Defender SaaS in the buyer’s tenant (Microsoft SLA), and (2) Claranet’s 24×7 SOC operations.
We commit to defined response SLAs (triage/notification) via the Response Matrix rather than a platform uptime SLA we don’t control. If Claranet fails to meet contracted response targets (excluding buyer prerequisites or Microsoft outages), service credits may apply.
Approach to resilience
Platform resilience is provided by Microsoft’s globally redundant Defender service within the buyer’s tenant.
Operational resilience is delivered by Claranet’s dual‑site SOC model, with runbooks for analyst handover, shift cover, and surge capacity.
Ticketing/reporting systems are hosted on resilient cloud infrastructure with multi‑AZ design and regular backups.
Detailed architectural information (for example, Microsoft regional redundancy and Claranet SOC failover procedures) is available under NDA on request.
Outage reporting
For Microsoft platform incidents, we rely on Microsoft’s service health communications; critical advisories are relayed to buyers when relevant to EDR operations.
For Claranet‑operated components, we notify named contacts via email/ticket, including scope, impact, workaround, and updates until resolution. Where appropriate, we schedule a post‑incident report detailing root cause and corrective actions. Buyers can raise P1 tickets by phone for urgent issues.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
We enforce RBAC, least‑privilege, MFA, device hardening, and session logging. Access to buyer tenants is granted via GDAP with time‑bound/scoped roles; sensitive actions (for example, device isolation) require explicit buyer authorisation captured in the runbook.
Support channels authenticate callers and verify contacts against the escalation matrix before discussing incidents.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
  • CSA CSM version 4.0
  • ISO/IEC 27001
Information security policies and processes
We operate an ISMS with security policies covering access control, data handling, incident response, and supplier management.
Governance includes senior security oversight, documented procedures, mandatory training, and periodic audits.
Staff with access to customer data undergo baseline personnel screening; higher clearances (e.g., BPSS/SC) are available when required by call‑off.
Policies are enforced through technical controls (MFA, RBAC, device management), SOC monitoring, and change approval.
We investigate breaches per our incident process and notify buyers under contract terms.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
We track all service components in a CMDB where applicable; EDR policy/config changes follow request, assessment (including security impact), approval, implementation, and verification steps.
Emergency changes use expedited approval with retrospective review.
Buyer‑tenant changes that affect risk (for example, device‑group authorisations or isolation permissions) require buyer approval and ticketed evidence for audit.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
We continuously assess threats via vendor advisories and trusted threat‑intel feeds; severity and exposure determine remediation priority. Patches for Claranet‑operated components are applied under change control; Microsoft platform patches are handled by Microsoft. Where a critical threat affects buyer operations, we issue advisories with recommended mitigations.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Our SOC monitors service telemetry and access logs for anomalous behaviour. Potential compromises trigger investigation, containment where authorised, and buyer notification per the Response Matrix.
We initiate P1 investigations immediately and provide regular updates until closure, followed by recommendations to prevent recurrence.
Incident management type
Supplier-defined controls
Incident management approach
We maintain predefined playbooks for common events (malware outbreak, ransomware behaviour, suspicious tools, data exfiltration indicators). Users report incidents via ticket or P1 phone bridge; confirmed incidents receive a written report with timeline, root cause, and actions. Major incidents include real‑time collaboration and post‑incident review.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Optional, time‑limited PoC (usually 1 month) for a subset of endpoints to validate detections, triage flow, and reporting. Includes onboarding assistance and agreed use‑cases; excludes out‑of‑hours support, bespoke integrations, and incident response beyond guidance. Typical duration 4-5 weeks, subject to scoping and availability.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
1%
Between £500,001 and £1,000,000
2%
Between £1,000,001 and £2,500,000
3%
Between £2,500,001 and £5,000,000
4%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Intertek
ISO/IEC 27001 accreditation date
Wednesday 22 May 2024
What the ISO/IEC 27001 doesn’t cover
This certification covers everything we do applicable to ISO/IEC 27001, no exclusions.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Intertek
ISO 9001 accreditation date
Wednesday 7 June 2023
What the ISO 9001 doesn’t cover
This certification covers everything we do applicable to ISO 9001, no exclusions.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
Pen Test Partners
PCI DSS accreditation date
Friday 13 December 2024
What the PCI DSS doesn’t cover
N/a
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
4377ebef-31ac-49ef-9943-13c7f3e3f9a5
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
66b24695-ed3f-4797-bb2c-65b58932576d
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at Uk-bidteam@claranet.com. Tell them what format you need. It will help if you say what assistive technology you use.