Microsoft 365 Services
OGEL IT provides licensing, management and support for Microsoft 365 and Azure services. We are a Microsoft partner and approved Microsoft Cloud Solution provider (CSP) with a wealth of experiences in designing and delivering solutions built upon Microsoft technology and services within the public sector.
Features
- File storage and sharing with 1TB storage/user
- Business class email, calendar and contacts with a 50GB inbox
- Office Applications including Outlook, Word, Excel, PowerPoint, Publisher and OneNote
- Online services including Planner, Flow, PowerBI and Teams
- Microsoft Teams/Skype for Business video conferencing, VoIP & instant messaging
- Online collaboration tools and services with OneDrive and SharePoint Online
- Self-service portal for licensing provisioning and removal
Benefits
- Flexible licensing options
- Enterprise solutions at an affordable price point
- Support from highly experienced staff
- Discounts for educational and charitable organisations
- Access to discounted consultancy resources
- Access from anywhere from multiple platforms and operating systems
- UK and European hosted services
- Microsoft Partner / CSP
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 5 5 5 7 3 1 6 5 8 9 1 0 4 8
Contact
OGEL IT LTD
Sam Newman
Telephone: 01438 300335
Email: gcloud@ogelit.com
About your service
- Service categories
-
Applications
Collaborative
- Enterprise community
- Team collaboration
Conferencing and virtual event
- Web Conferencing Applications
- Virtual Event Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- .
- System requirements
-
- Safari, Chrome, Edge, Firefox browser
- Microsoft Edge, Google Chrome for Microsoft Teams
- Supported iOS or Android Operating System
- Supported Windows or MacOS Operating System
- Internet connectivity
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- M-F, 8am - 6pm, excl. UK public holidays, P1 - 30 minutes, P2 - 1 hour, P3 - 1 hours, P4 - 1 day
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- //Level 0 - Base license only (online portal access, priority 3 response time only) //Level 1 - Base license plus 15% (online portal access, Priority response times apply but resolution times do not) //Level 2 - Base license plus 25% (Online portal access, phone access for priority 1 only, Priority response times apply resolution times for priority 3 only apply) //Level 3 - Base license plus 45% (minimum of 200 seats) (Online portal support, phone access for priority 1 and 2 only, Priority response times and resolution times apply to all) //Incident Priority Definitions Priority 1 - Response within 1 hour, resolution within 4 hours Priority 2 - Response within 4 hours, resolution by end of next business day Priority 3 - Response by end of next business day, resolution within 5 days.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Microsoft provides all M365 customers with 24/7 self-help resources, including Microsoft Learn, how-to videos, documentation, and community support.
OGEL IT provides an initial call for 1 hour with one of our experienced technicians to help get customer up and running. Existing M365 customers are migrated to our licensing platform by our support team as part of the onboarding process. - Service documentation
- Yes
- Documentation formats
- HTML
- End-of-contract data extraction
- Data extractions needs to be completed by the end user or contracting organisation before the expiry of online services. Consultancy and offboarding services can be provided on a rate card basis. Please note some services are integral to the Microsoft Office 365 platform and extraction of this data may not be possible. We provide Office 365 migration tooling and support via our supplementary service offerings.
- End-of-contract process
- The contracted price covers the provision of online services for the duration of the contract, termination of the contract or failure to make timely payments could result in the loss of access to or retention of data. All offboarding services are chargeable at the published day rates and offboarding commitments can be made at the before or during the contract term.
- Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Many of the Microsoft 365 applications are available as installable applications on mobile devices and via a mobile browser. Both the apps and mobile view are designed for mobile access, smaller screen, different aspect ratio and touch screen.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- The Microsoft 365 services has web based administrative interfaces.
- Accessibility standards
- WCAG 2.2 AA
- Accessibility testing
- Microsoft provides details information regarding accessibility tools across the various applications and services at https://support.microsoft.com/en-us/office/accessibility-tools-for-microsoft-365-b5087b20-1387-4686-a0a5-8e11c5f46cdf
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- Microsoft maintain high levels of performance within Office 365 services by Monitoring databases for Blocked processes, Packet loss, Queued processes and Query latency and adjusting the backend infrastructure based on demand. Office 365 is accessed over the internet and therefore customers need to ensure their WAN bandwidth is appropriately scaled and configured based upon the number of users.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The administrative interfaces for the platform and each service component provides several reporting options and access to dashboards.
- Reporting types
-
- Real-time dashboards
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Microsoft
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- Never
- Protecting data at rest
- Other
- Other data at rest protection approach
- Physical access control, complying with CSA CCM v3.0
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- The administration interface provides facilities for users to export their data.
- Data export formats
- Other
- Other data export formats
-
- PST
- ZIP
- Native file types
- Data import formats
- Other
- Other data import formats
-
- PST
- Native file types
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- Microsoft provides detailed service level agreement (SLA) metrics for all of cloud services. Uptime percentages and associated service credits are are detailed at https://www.microsoft.com/licensing/docs/view/Service-Level-Agreements-SLA-for-Online-Services. Service credit information is also detailed within the page. Credit requests are raised by the buyer, the reseller will then handle the process with Microsoft. As part of the request the buyer should confirm whether they would like credit applied to the account or a refund.
- Approach to resilience
-
Microsoft provides comprehensive information regarding the approach to resilience for its data centres, applications and services online. This ensure the latest information is available to all customers. Please see https://learn.microsoft.com/en-us/compliance/assurance/assurance-resiliency-and-continuity?source=recommendations#how-does-microsoft-test-business-continuity-and-disaster-recovery-plans for additional details.
With regards to Microsoft 365 services the following external audits are completed as associated certifications held to provide assurances to customers regarding resilience and contingency plans. FedRAMP, ISO27001, SOC1, SOC2, SOC 3. - Outage reporting
-
Microsoft provide a public dashboard to indicate the Health Status of Microsoft Services, this can be found at https://status.cloud.microsoft.
Microsoft provides the Microsoft 365 Availability Status API (https://learn.microsoft.com/en-us/office/office-365-management-api/office-365-service-communications-api-reference) to enable integration with external systems. Email alerts can be configured by administrators of individual customer tenants.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- 2-factor authentication Public key authentication (including by TLS client certificate) Identity federation with existing provider (for example Google Apps) Limited access network (for example PSN) Dedicated link (for example VPN) Username or password
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Limited access network (for example PSN)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- OGEL IT maintains an ISMS as part of ISO27001. The ISMS and processes within are reviewed internally and externally once per year as part of accreditation process.
- Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Azure’s change management practices are guided by Microsoft’s configuration management policy. This policy is executed through SOPs, including the Microsoft Change Management Standard, and Azure’s Software and Hardware Change and Release Management SOPs. The Azure SOPs cover the change management process around information system design, development, and implementation of changes and align with Microsoft’s Security Development Lifecycle process. Except for pre-approved ones, all Azure production changes require review approval, the type of which depends on the team and change. Changes are tracked in an automated system. For additional details please refer to: https://servicetrust.microsoft.com/viewpage/FedRAMP
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Azure uses integrated deployment systems to manage the distribution and installation of security updates for Microsoft software. Azure also drawd on the resources of the Microsoft Security Response Center (MSRC). The MSRC identifies, monitors, responds to, and resolves security incidents and cloud vulnerabilities around-the-clock, every day of the year. Vulnerability scanning is performed on server operating systems, databases, and network devices. The vulnerability scans are performed on a quarterly basis at a minimum. Azure contracts with independent assessors to perform penetration testing of the Azure boundary. Red-team exercises are routinely performed, and the results are used to make security improvements.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Azure security uses active monitoring tools like the Microsoft Monitoring Agent and System Center Operations Manager, configured to alert personnel in urgent situations. Azure continuously monitors and detects risks using machine learning algorithms, even when devices are offline. Upon detecting potential compromises, Microsoft follows a structured incident response process, conducting thorough investigations and taking immediate action to contain the exposure. Security controls are implemented across workloads to protect assets. The Initial Response Time varies with both the support plan and the Business Impact of the request (Severity). Please visit: https://azure.microsoft.com/en-us/support/plans/response/
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Microsoft implements a security incident management process to facilitate a coordinated response to incidents. If unauthorized access to customer data occurs, Microsoft takes the following actions: - Promptly notifies the customer of the security incident. - Promptly investigates the security incident and provides customers detailed information about the security incident. - Takes reasonable and prompt steps to mitigate the effects and minimize any damage resulting from the security incident. We have an incident management framework that defines roles and allocates responsibilities. The Azure security incident management team manages security incidents, including escalation, and involving specialist teams when necessary.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 1%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 2%
- Between £2,500,001 and £5,000,000
- 3%
- Over £5,000,001
- 3%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Peers Quality Assurance Limited
- ISO/IEC 27001 accreditation date
- Tuesday 23 April 2024
- What the ISO/IEC 27001 doesn’t cover
- The services being resold are covered by their own ISO 27001 certification.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 15f64ae8-0b55-404e-85e1-30205266c64d
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
-