Microsoft 365
Microsoft 365 provides industry leading productivity and collaboration tools for teams. Delivering the power of cloud productivity to organisations of all sizes, combining Microsoft Office desktop suite with cloud-based versions of next-generation communications and collaboration services, including Exchange, SharePoint, Teams & OneDrive, Entra ID and Intune.
Features
- Enterprise social networking within Microsoft 365
- Team sites within Microsoft 365
- Internal content publishing within Microsoft 365
- Access to essential technical support from a Microsoft Solutions Partner
- Business class email, calendars and web browser
- Host online meetings, Teams - IM/presence/voice/video calls
- File storage and sharing; share, track and control documents
- Team sites, project collaboration; organise documents, tasks and conversations
- Yammer collaboration software and business applications, corporate social network
- Office Online, Word, OneNote, PowerPoint and Excel within browser
Benefits
- Generate greater productivity
- Access from anywhere
- Robust security and reliability
- Provides IT control and efficiency
- Seamlessly connected to enterprise software living out in the cloud
- Versions always up to date
- No longer have to buy and configure a server
- Reliability if an outage at datacenter, another acts as backup
- Compliance with government and industry regulations.
- Single sign-on allowing users to be automatically authenticated
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 1 1 5 1 5 2 6 6 2 0 7 8 3 0
Contact
SYNERGI SOFTWARE LIMITED
Team Synergi
Telephone: 01914770365
Email: paul.burns@teamsynergi.co.uk
About your service
- Service categories
-
Applications
Collaborative
- Enterprise community
- Team collaboration
Conferencing and virtual event
- Web Conferencing Applications
- Virtual Event Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Hybrid cloud
- Service constraints
- Microsoft 365 Business SKUs have a 300 seat limit
- System requirements
-
- Microsoft 365 Licensing
- Windows 11
- Internet Connectivity
- Relevant 3rd Party licensing
User support
- Email or online ticketing support
- Yes, at extra cost
- Support response times
- Response time is between 30 mins for critical incidents and 6 hours for service requests during normal support business hours 8am to 6pm Monday - Friday.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
- Typically, 08:00-18.00 UK hours, Monday to Friday, excluding public holidays. Flat rate service is provided along with a support contract, can be tailored to the needs of the customer, including development hours. All support contracts are flexible and priced to your needs. The support desk is manned by a technical support analyst, and supported by technical consultants and account managers.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
End-User Adoption
Learning and adoption represent an active component of each phase of a Synergi Client Project Engagement. Inclusive focus on the complete learning and adoption for users is the best way to ensure ultimate success.
Sponsorship and Leadership: Recognising that executive-level sponsorship is a key success factor, Synergi will seek the participation of a director or mid-level executives from each business unit. This component also forms an organisational change management team to address the process changes that accompany the new implementation.
Adoption Strategy: Synergi will determine at a high level what types of training and support are most likely to accelerate end user adoption of the new platform and processes included.
Detailed Programme Planning: Taking the strategy to a more practical level, Synergi IT create detailed plans based on users training needs, where they were located, and how to accommodate diverse learning needs and preferences. Synergi will additionally define a communications plan to build awareness and understanding of the changes to come, and a content plan to support all aspects of the adoption program.
Blended Learning: To accommodate individual learning preferences, Synergi IT delivers a blended approach, combining instructor-led classroom and on-demand training, along with over-the-shoulder mentoring. - Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Data can be easily migrated utilising common migration tools readily available in the market.
- End-of-contract process
- The associated costs for end of life contract where appropriate will be determined between both parties depending on the level of technical expertise on the client side, these costs are not described in an initial deployment contract.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Our documentation is created in line with UK Government open standards for viewing documents. All files are saved in PDF/A format to ensure long-term accessibility and compatibility. They are fully searchable, with Optical Character Recognition (OCR) applied to any scanned content. Each document includes tagged headings, paragraphs, lists, and tables to support screen readers and maintain a logical reading order. Images contain alternative text, and metadata such as title, author, and language are correctly set. We use high-contrast colours and clear fonts for readability. An HTML version of the content is available if requested as an open format alternative for users who prefer or require it. These measures ensure our documentation is accessible to all users, including those using assistive technologies.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- MacOS
- Windows
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- Microsoft 365 offers similar core functionality across mobile and desktop, including access to email, files, and collaboration tools. However, desktop apps provide full-featured experiences with advanced editing, integration, and administrative controls, while mobile apps are optimised for quick access, viewing, and light editing on smaller screens. Some complex features, such as advanced reporting or configuration, are only available on desktop or web interfaces.
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
-
Users can set up services through the Microsoft Graph API, which allows provisioning of users, groups, and basic configurations programmatically. Changes such as updating user profiles, managing licenses, and configuring security settings can also be made via the API.
However, there are limitations: not all administrative tasks are exposed through the API, and some advanced configurations (e.g., certain compliance or tenant-level settings) require manual setup in the admin portal. API usage is subject to throttling and permission scopes, meaning appropriate admin consent is required. Additionally, complex migrations or bulk data exports are not fully supported through the API alone. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Microsoft 365 is designed to be highly adaptable to individual customer requirements, from a visual or usability point of view.
The ability to customise is less about the inherent technology and more about the users capability
Scaling
- Independence of resources
- As the solution is based on the Microsoft 365 platform, please see https://www.microsoft.com/en-us/trustcenter for details.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Microsoft 365 allows end to end monitoring of services and multiple software features, providing service metrics to give viability to how existing services are used and notifying system administrators.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Microsoft
Staff security
- Staff security clearance
- Staff screening not performed
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Users can export their data from Microsoft 365 using several built-in tools and services. Common options include the Microsoft 365 Compliance Center for exporting emails and documents, eDiscovery tools for legal or compliance needs, and PowerShell scripts for advanced data extraction. Additionally, third-party solutions are available to assist with bulk exports or migration scenarios.
- Data export formats
-
- CSV
- ODF
- Other
- Other data export formats
- Original format
- Data import formats
-
- CSV
- ODF
- Other
- Other data import formats
- Original format
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
- As the solution is based on the Microsoft 365 platform, please see https://www.microsoft.com/en-us/trustcenter for details.
- Approach to resilience
- As the solution is based on the Microsoft 365 platform, please see https://www.microsoft.com/en-us/trustcenter for details.
- Outage reporting
- As the solution is based on the Microsoft 365 platform, please see https://www.microsoft.com/en-us/trustcenter for details.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
- Access restrictions in management interfaces and support channels
- Microsoft 365 restricts access through role-based access control (RBAC), ensuring only authorised administrators can manage settings. Multi-factor authentication (MFA) and conditional access policies add extra security layers. Privileged roles are monitored and can be time-bound using Privileged Access Management (PAM), Privileged Identity Management (PIM) can help ensure that only required roles are available as needed - Just in Time (JIT). Support channels require identity verification and operate under strict compliance standards to prevent unauthorised data exposure.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Username or password
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
- As the solution is based on the Microsoft 365 platform, please see https://www.microsoft.com/en-us/trustcenter for details.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- As the solution is based on the Microsoft 365 platform, please see https://www.microsoft.com/en-us/trustcenter for details.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- As the solution is based on the Microsoft 365 platform, please see https://www.microsoft.com/en-us/trustcenter for details.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- As the solution is based on the Microsoft 365 platform, please see https://www.microsoft.com/en-us/trustcenter for details.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- As the solution is based on the Microsoft 365 platform, please see https://www.microsoft.com/en-us/trustcenter for details.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- No
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 97cf5048-9c9a-4c73-be5a-f056b3c9691e
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 67e908ac-11fc-4164-81f1-f7ce9907ff0a
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-