Microsoft SharePoint Online (SPOL) Licenses- CoreGov
Core supplies Microsoft SharePoint Online licences through our Tier‑1 CSP programme, enabling organisations to create, share and manage content securely across Microsoft 365. This service provides flexible, compliant subscription options with transparent pricing and supports collaboration, document management, and modern intranet experiences within your Microsoft 365 tenant.
Features
- Supplies SharePoint Online licences through Core’s Tier‑1 CSP.
- Enables secure document storage and collaboration in Microsoft 365.
- Supports modern intranet and site collection creation.
- Provides flexible monthly or annual licensing commitments.
- Activates licences directly in the customer tenant.
- Integrates SPOL with Teams and OneDrive environments.
- Offers scalable storage options via Microsoft 365 plans.
- Supports external sharing capabilities when licensed.
- Provides transparent CSP pricing and governance.
- Aligns with Microsoft security and compliance features.
Benefits
- Enhances organisational collaboration and content sharing securely.
- Enables modern intranet and workspace structures.
- Supports consistent document governance and lifecycle management.
- Reduces complexity of licensing procurement.
- Provides predictable, manageable subscription costs.
- Improves teamwork through integrated Microsoft 365 experience.
- Ensures compliant access to SharePoint features.
- Scales easily as user needs grow.
- Supports remote and hybrid working effectively.
- Reduces operational burden of managing SPOL licensing.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
2 9 8 2 4 1 1 4 4 1 2 8 9 4 7
Contact
CORE TECHNOLOGY SYSTEMS (U.K.) LIMITED
Paul Saer
Telephone: +44 (0) 207 626 0516
Email: tenders@core.co.uk
About your service
- Service categories
-
Applications
Collaborative
- Team collaboration
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- SharePoint Online licensing is provided on a per‑user basis and requires an active Microsoft 365 tenant. Some features depend on the specific Microsoft 365 plan assigned, and “top‑up” licences may require additional Microsoft subscriptions to function. Licensing availability, product names, and feature tiers can change under Microsoft’s CSP programme. Pricing is subject to Microsoft’s updates, though CSP models apply a “price not to exceed” principle, charging the lower of the current sale price or the published ceiling during the framework term. This service includes licence supply only; configuration, migration, administration, or support must be procured separately - via Lot3.
- System requirements
-
- Active Microsoft 365 tenant required.
- Azure AD identities for user authentication.
- Supported browser for SharePoint Online access.
- Internet connectivity for cloud services.
- Appropriate Microsoft 365 plan including SharePoint entitlement.
- Admin capable of assigning licences.
- Modern authentication enabled.
- Devices must meet browser compatibility standards.
- Tenant storage allocation must be managed.
- External sharing requires policy configuration.
User support
- Email or online ticketing support
- Yes
- Support response times
- Response times are dependent on the nature of the request. For Managed Services tickets, the response times for different request types are listed in the Service Description document.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Our webchat solution is configurable, allowing us to tailor the interface by enabling or disabling features for different clients. This can help simplify navigation for users who need a less cluttered interface. Security roles can be configured to limit or expand access to certain features, which can help create simpler experiences for users who might struggle with complex navigation. Users can submit tickets, access knowledge bases, and use service catalogues without direct staff interaction, which could benefit users who prefer asynchronous communication. Our platform also supports integrations with Teams, Slack, and chat applications, which may allow users to choose communication channels that work best for them.
- Web chat accessibility testing
- None
- Onsite support
- Yes, at extra cost
- Support levels
- Core run an ITIL aligned Service Desk and incident management approach. All service requests can be made directly to our 24/7 ServiceDesk function. First line or Second Line technical analyst or engineers engage with all service tickets until successfully closed. All customers can also engage with a named Account Manager and Customer Success Manager. Core typically structures Managed Services into modular SKUs, allowing customers to select the level of support they need - for example Service Desk, End User Compute, Microsoft365 Support, Infrastructure Support and Azure Managed Services. All of these SKU's are individually priced and pricing is referenced in the relevant Service Definition document
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- Core helps users begin using the licensing service through a structured onboarding process, including clear documentation and guided steps for establishing the CSP relationship. Users receive access to a dedicated Account Manager, Core’s Service Desk for ongoing assistance, and early‑life support immediately after go‑live. Core also provides the Customer Success Hub—an online training and adoption portal containing videos and guidance materials. Workshops and remote enablement sessions are offered where required. Core does not provide onsite training for licensing.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
-
Core’s Microsoft licensing service does not store, process, or generate customer data. All customer information, files, settings and audit logs remain entirely within the customer’s own Microsoft 365/Azure tenant, controlled directly by the customer.
Ending the licensing contract does not affect access to customer data. Customers retain full ability to export, extract, or manage their data using native Microsoft tools at all times. No data extraction from Core is required. - End-of-contract process
-
The customer retains full ownership and access to all data within their Microsoft tenant. Core does not store or process customer data. At contract end, the customer removes Core as their CSP partner. Licences remain active and may be transferred to another CSP or managed directly. No data extraction is required.
Microsoft subscription licences, CSP management, licence changes, billing management, access to Core’s Service Desk for licensing issues, regular licence optimisation reviews, Account Manager support, onboarding/offboarding, and access to the Customer Success Hub, are services included in the price.
Professional services, workshops, migrations, managed services, Azure consumption, bespoke training, and any project-based work fall outside the core licensing fee and would be considered as additional cost. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Our onboarding and offboarding documentation is provided in standard digital formats (DOCX and PDF). While these formats are widely compatible with common screen readers and assistive technologies, the documentation itself is not currently authored to a formal accessibility standard such as WCAG 2.1. Alternative accessible formats (e.g., ODF, large print, Easy Read, HTML, audio) are not currently produced by default but may be made available on request.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The licensing service can be accessed on mobile devices; however, the mobile experience is limited to basic viewing and user-level interactions. Full administrative licensing functions—such as assigning licences, managing subscriptions, or accessing billing—are only available via a supported desktop browser. Some advanced pages and administrative tools are not available or are restricted on mobile browsers. Mobile apps support the use of licensed Microsoft 365 services but do not provide licensing administration capability.
- Service interface
- Yes
- User support accessibility
- EN 301 549
- Description of service interface
- The service interface for Core’s licensing service is Microsoft’s own cloud administration portals (Microsoft 365 Admin Center, Microsoft Partner Center, and Azure Portal). No proprietary Core interface or application is required or provided. Buyers access the service through standard Microsoft web interfaces using a supported browser.
- Accessibility standards
- EN 301 549
- Accessibility testing
- None
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- Core does not host or operate the Microsoft licensing platform. All licence management takes place within Microsoft’s own globally scaled, highly available cloud portals. Because the platform is provided and managed entirely by Microsoft, no customer’s usage or demand can impact another customer’s experience. There is no shared infrastructure, no performance dependency, and no contention risk.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Core does not provide service usage metrics for the licensing service itself, as no user activity or content is processed. However, as part of our CSP value‑add, we provide regular licence‑estate reporting, optimisation reviews, cost analysis, and advisory insights. Customers also continue to have full access to Microsoft’s own usage analytics within the Microsoft 365 Admin Center.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Microsoft
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Other
- Other data at rest protection approach
- There is no customer data at rest within Core’s systems for this service. All customer data is stored in the Microsoft cloud, where Microsoft provides encryption at rest and adheres to global security and compliance certifications.
- Data sanitisation process
- No
- Equipment disposal approach
- A third-party destruction service
Data importing and exporting
- Data export approach
- Not applicable
- Data export formats
- Other
- Other data export formats
- Not applicable
- Data import formats
- Other
- Other data import formats
- Not applicable
Data-in-transit protection
- Data protection between buyer and supplier networks
- Other
- Other protection between networks
-
NOT APPLICABLE - Core’s Microsoft CSP licensing service does not transmit or process any customer data between the buyer’s network and Core’s network. All licence management is performed within Microsoft’s cloud portals (Microsoft 365 Admin Center and Partner Center), where Microsoft provides all security controls, encryption, and network protection.
As no customer data flows to Core, no additional protection mechanisms are required or implemented for this service. - Data protection within supplier network
- Other
- Other protection within supplier network
-
NOT APPLICABLE - Core’s Microsoft CSP licensing service does not transmit or process any customer data between the buyer’s network and Core’s network. All licence management is performed within Microsoft’s cloud portals (Microsoft 365 Admin Center and Partner Center), where Microsoft provides all security controls, encryption, and network protection.
As no customer data flows to Core, no additional protection mechanisms are required or implemented for this service.
Availability and resilience
- Guaranteed availability
- Core does not provide an availability SLA for its licensing service, as all licence management occurs within Microsoft’s own cloud platforms. Service availability and uptime are governed exclusively by Microsoft’s SLA commitments, and Core does not issue refunds linked to availability for this service.
- Approach to resilience
-
This question does not apply to the CSP licensing service.
Core does not host or run the licensing platform; all resilience, datacentre redundancy and service continuity are provided by Microsoft’s globally distributed cloud infrastructure. - Outage reporting
- Not applicable — Core does not operate the service platform. Outage reporting is provided directly by Microsoft through Microsoft 365 and Partner Center service health dashboards.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Other user authentication
- Core sends a CSP reseller‑relationship invitation; customers must authenticate and approve this in the Microsoft 365 tenant before Core can transact licences. This is not a separate authentication method, but it is a required authorisation flow unique to CSP.
- Access restrictions in management interfaces and support channels
- Core restricts access to management interfaces and support channels through RBAC, SSO with mandatory MFA, privileged‑access controls aligned to NCSC secure administration, and strict identity verification for all licensing‑related requests. Only authorised personnel can access licensing management functions within our ITSM platforms, with encrypted data exchange and role‑segregated permissions ensuring least‑privilege operation. Customers authenticate through Microsoft 365 identity to approve CSP relationships and licence changes, ensuring end‑to‑end governance and prevention of unauthorised access.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Other
- Description of management access authentication
- Role‑based access control (RBAC), authorised‑contact validation and privileged‑access controls aligned to NCSC secure administration
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- Between 6 months and 12 months
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- Between 6 months and 12 months
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Core operates a fully ISO 27001 certified Information Security Management System (ISMS), supported by formal policies covering confidentiality, integrity, availability, access control, incident management, risk assessment, business continuity and supplier management. All employees receive mandatory security awareness training, with additional specialist training for staff in sensitive roles. Security responsibilities are defined in job descriptions and contracts, and policy breaches are managed under our disciplinary process. The ISMS is overseen by a dedicated Information Security Steering Group chaired by the COO and supported by the CISO, IT Manager and senior risk specialists. Policies are reviewed at least annually and continuously improved through internal audits, external ISO 27001 surveillance audits, risk assessments and automated compliance monitoring. Staff are required to report security incidents or weaknesses immediately via documented procedures.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Core operates ITIL aligned configuration and change management processes, benchmarked at CMM Level 3–4. Configuration items are tracked throughout their lifecycle using customer CMDBs, Intune, Azure and ITSM tooling, ensuring accurate, continually updated records. All changes follow a formal ITIL process, including risk and security assessment, CAB review, client approval, and full auditability. Security impact is evaluated using Microsoft native tooling (Defender, Secure Score) to ensure no adverse effect on identity, access or service integrity. All changes are documented, traceable, and aligned with customer governance.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Core operates a proactive, ITIL aligned vulnerability management process. Threats are continuously assessed using Microsoft Defender, Secure Score, Azure Security Centre, Sentinel SIEM and weekly Nessus scans to identify vulnerabilities and misconfigurations. We deploy critical and security patches within 14 days in line with NCSC guidance, with accelerated deployment for zero day threats using automated Endpoint Manager and Azure Update Management workflows. Threat intelligence is sourced from Microsoft’s security ecosystem, Tenable CVE feeds, NCSC advisories and SIEM driven correlation, ensuring rapid awareness and remediation of emerging risks.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Core delivers continuous protective monitoring using Microsoft Sentinel SIEM, Defender for Endpoint/Servers, and Azure Defender to identify potential compromises through behavioural analytics, real time alerting, threat intelligence and proactive threat hunting. When a potential compromise is detected, alerts are triaged by our security operations processes, with automated containment actions (e.g. isolating devices, disabling accounts) and escalation to our engineers. Incident response follows predefined playbooks and documented communication paths. Core provides rapid response, with 24/7 monitoring and immediate triage, and P1 security incidents responded to within minutes via Sentinel driven alerting.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Core operates ITIL aligned incident management with predefined processes for common events, including a full Major Incident Management (MIM) workflow covering P1 and P2 incidents. Users report incidents via phone, email, or the self service portal, or incidents may be auto raised through monitoring. When an incident is logged, it is triaged, prioritised, and assigned, with automated notifications and, for P1s, initiation of a live bridging call and stakeholder communications. Response times follow strict SLAs, including 30 minute response for P1 incidents. We issue formal incident reports for all major incidents.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Yes — Core provides a 30‑day free trial for eligible Microsoft Cloud subscriptions when 25 or more licences are being evaluated.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau (part of the Amtivo Group)
- ISO/IEC 27001 accreditation date
- Thursday 27 February 2025
- What the ISO/IEC 27001 doesn’t cover
- Nothing
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Ad9ffc7a-28e4-460b-bccb-fc914b3420df
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 13867168-d605-4ed3-9481-13e21f4ae9bc
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-