ShareGate – Secure Microsoft 365 Migration, Management & Governance
ShareGate is a cloud-based service that enables organisations to securely migrate, manage and govern Microsoft 365 environments. Modernise collaboration while maintaining control, security and compliance.
Designed for IT and digital teams who need visibility, automation and governance without complex scripting or bespoke development.
Features
- Migrate SharePoint, Exchange, OneDrive, Teams, and Planner
- Support for tenant-to-tenant, on-prem to cloud, and reorganisation scenarios
- Pre-migration analysis and post-migration validation
- Visibility into permissions, sharing, and external access
- Identify oversharing and misconfigured workspaces
- Support governance best practices without disrupting users
- Reports for usage, permissions, and lifecycle
- Actionable insights for IT and security teams
- Supports Microsoft 365 best practice and security models
Benefits
- Reduces risk during Microsoft 365 migrations
- Improved Microsoft 365 security posture
- Reduced administrative overhead
- Saves time through automation and standardisation
- Improves visibility and accountability of Teams and sites
- Enables controlled collaboration without restricting users
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 3 8 7 2 2 1 2 3 9 9 6 0 9 0
Contact
INTELOGY LIMITED
Andrew Tomlins
Telephone: 02037473506
Email: info@intelogy.co.uk
About your service
- Service categories
-
Applications
Content workflow and management
Persuasive content management
- Digital Asset Management Applications
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Community cloud
- Hybrid cloud
- Service constraints
-
Requires an active Microsoft 365 tenant
Internet access required
Configuration dependent on Microsoft 365 permissions granted by the customer - System requirements
- Virtual machine required for ShareGate Migrate
User support
- Email or online ticketing support
- No
- Phone support
- No
- Web chat support
- No
- Onsite support
- No
- Support levels
- N/a
- Support available to third parties
- No
Onboarding and offboarding
- Getting started
- Customers onboard by authorising the service to access their Microsoft 365 tenant using Microsoft-supported authentication and permission models. Access is granted using customer-controlled credentials and permissions.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Customer data remains within the customer’s Microsoft 365 tenant. The service does not retain independent copies of customer content. Customers can export reports and logs generated by the service prior to contract end.
- End-of-contract process
- At contract end, the customer revokes Microsoft 365 permissions granted to the service. This immediately removes access. No further action is required. No customer data is retained by the service after access is removed.
- Documentation accessibility standard
- WCAG 2.2 AAA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- Yes
- Compatible operating systems
- Windows
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
-
ShareGate Protect is delivered as a multi-tenant SaaS platform. Customer usage does not require dedicated infrastructure. Scaling is handled automatically by the service without customer intervention.
ShareGate Migrate is installed on customer-owned virtual machine infrastructure and is handled by the customer.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Reseller (no extras)
- Organisation whose services are being resold
- ShareGate
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Customers can export reports and audit information generated by the service using built-in export functionality. Exports are customer-initiated.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- XLSX
- Data import formats
- Other
- Other data import formats
- N/A
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Service availability targets are defined by the service provider. Planned maintenance is communicated in advance where possible.
- Approach to resilience
- Resilience is provided through cloud-based infrastructure, redundancy and monitoring. The service is designed to tolerate component failure without loss of service.
- Outage reporting
- Service issues and outages are communicated through support channels and status notifications where applicable.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- Access is restricted based on role and least-privilege principles.
- Access restriction testing frequency
- At least once a year
- Management access authentication
- Multi-Factor Authentication (MFA)
Audit information for users
- Access to user activity audit information
- No audit information available
- Access to supplier activity audit information
- No audit information available
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- No
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- The supplier maintains documented information security policies covering access control, incident management, vulnerability management and operational security.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Changes are assessed for risk, tested prior to release and deployed using controlled release processes.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Proactive vulnerability management.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Vulnerabilities are identified through monitoring, testing and third-party advisories, and remediated based on severity.
- Incident management type
- Supplier-defined controls
- Incident management approach
- Security incidents are logged, investigated and resolved in line with documented procedures. Customers are informed where relevant.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- You can install a fully-featured trial version of ShareGate that expires after 15 days.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 10%
- Between £1,000,001 and £2,500,000
- 20%
- Between £2,500,001 and £5,000,000
- 30%
- Over £5,000,001
- 40%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 94fe1d5d-42c6-4fd1-9e8a-4354344ecdb4
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 2ea592d2-831b-45df-8786-117854e250a0
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
-