Skip to main content

Help us improve the Digital Marketplace - send your feedback

CLARANET LIMITED

Extended Detection & Response for Microsoft

Claranet’s Managed XDR for Microsoft provides 24/7 detection, investigation, and response across Defender and Sentinel. Using correlated telemetry from endpoints, identities, cloud applications and infrastructure, our SOC proactively identifies threats, performs expert analysis, executes response actions, and continuously tunes detections to improve visibility, reduce risk, and strengthen customers’ security posture.

Features

  • 24/7 SOC monitoring across Microsoft Defender and Sentinel telemetry
  • Unified detection correlation across endpoint, identity, cloud, applications
  • Proactive threat hunting using MITRE ATT&CK methodologies
  • Continuous tuning to minimise false positives and alert noise
  • Custom detection rule creation aligned to customer environment
  • Assisted onboarding for log sources and agent deployment
  • Incident triage, investigation, and root‑cause analysis included
  • Automated and analyst‑led response actions when authorised
  • Monthly reporting and quarterly service optimisation reviews
  • Integrated threat intelligence enrichment for faster incident understanding

Benefits

  • Faster detection and containment of advanced cyber threats
  • Reduced operational load through fully managed SOC capability
  • Improved security posture through continuous detection tuning
  • Enhanced visibility across full Microsoft security ecosystem
  • Rapid incident response supported by expert triage
  • Reduced false positives and operational distractions
  • Clear insights through structured monthly reporting
  • Strengthened resilience via proactive threat hunting
  • Consistent security governance and expert guidance
  • Improved ROI on Microsoft Defender and Sentinel investments

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at Uk-bidteam@claranet.com. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

3 7 5 8 3 2 0 8 1 3 5 3 7 1 9

Contact

CLARANET LIMITED Claranet UK Bid Team
Telephone: 020 7685 8000
Email: Uk-bidteam@claranet.com

About your service

Service categories

Applications

Production and operations

  • Other operations
Multi cloud support
Yes

Service scope

Software add-on or extension
Yes
What software services is the service an extension to
Microsoft Defender XDR (Defender for Endpoint, Identity, Cloud Apps, Cloud)
Microsoft Sentinel (SIEM + Automation)
Microsoft 365 security telemetry sources
Azure log sources integrated via Sentinel
Optional third‑party telemetry if supported by Sentinel connectors
Cloud deployment model
  • Public cloud
  • Hybrid cloud
Service constraints
The service relies on customers maintaining correct Microsoft licences, ensuring Defender agents are deployed, and granting Claranet authorised access via Lighthouse and GDAP. Delays in access, permissions, or log‑source readiness may postpone onboarding. Scheduled Microsoft or customer maintenance windows may affect data ingestion. Mobile devices are currently out of scope for response actions. Customer‑initiated penetration testing must be pre‑approved to avoid alert overload. Some response actions require explicit tenant permissions and may not be available in restricted environments. Data retention limits follow the customer’s Microsoft licensing unless upgraded separately. Connectivity or licence issues outside Claranet’s control may impact service.
System requirements
  • Microsoft Defender licences for in‑scope endpoints and identities
  • Microsoft Sentinel workspace deployed within customer Azure tenant
  • Log Analytics capacity sized for chosen data ingestion volume
  • Defender agents deployed to all monitored endpoints
  • Azure Lighthouse onboarding script executed by customer admin
  • GDAP “Security Admin” role delegated to Claranet
  • Customer provides up‑to‑date contact and escalation details
  • Secure mechanism (e.g., Intune) for agent deployment
  • Customer-approved authorisation for automated response actions
  • Supported operating systems for Defender agent compatibility

User support

Email or online ticketing support
Yes
Support response times
All customer queries and incident notifications are handled via Claranet Online, supported 24/7 by our SOC. Standard operational questions are typically reviewed during business hours (Monday–Friday, 09:00–17:30 GMT), while incident‑related communication follows the service’s defined priority matrix. Priority 1 and 2 incidents include rapid notification (15–30 minutes after classification). Non‑urgent questions submitted via the portal are acknowledged in line with ticket priority and addressed as soon as possible. SLA‑backed response times apply to security incidents; general questions follow best‑effort handling aligned to workload and severity.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
EN 301 549
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Claranet provides tiered support integrated into the managed XDR service.
Support is delivered primarily through:

24/7 Security Operations Centre (SOC) for incident triage, investigation, and response
Platform Support Engineers (business hours) for onboarding, agent deployment, and troubleshooting
Security Optimisation Manager (SOM) for quarterly reviews and service quality
Claranet Online for ticketing, reporting, and communication

Included support:

Incident analysis, notification, containment guidance and response actions
Continuous tuning and rule management
Threat hunting
Monthly reports and quarterly service reviews
Assisted onboarding for log sources

Optional chargeable support:

Additional professional services
Custom integrations beyond core Microsoft sources
Increased data retention costs (from Microsoft)
Out‑of‑scope engineering tasks requiring SOW
Onsite support (if required)

A dedicated SOM functions similarly to a Technical Account Manager, coordinating service governance, reporting, and improvements. SOC engineers and analysts act as cloud security specialists for live investigations. Pricing varies depending on data tier, endpoint volume, and optional modules but all service levels include 24/7 SOC response.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
Onboarding begins with a planning workshop to define scope, log sources, access requirements, and escalation procedures. Claranet provides guidance on agent deployment, Lighthouse onboarding, GDAP access, and Sentinel workspace configuration. A project manager coordinates onboarding tasks and ensures all prerequisites are fulfilled. Assisted onboarding includes deployment validation for one instance of each log‑source type. Customers receive access to Claranet Online, along with documentation on incident handling, response processes, and service controls.
Claranet provides user documentation for Claranet Online, Sentinel access, and escalation guidance. Training sessions can be conducted remotely to familiarise operational teams with incident workflows, reporting features, and required customer responsibilities. When onboarding completes, tuning begins immediately, supported by ongoing engineering assistance.
Service documentation
Yes
Documentation formats
  • HTML
  • PDF
End-of-contract data extraction
Because all customer log data is held within their own Microsoft Sentinel and Defender tenants, customers retain full ownership and control of all raw and enriched data throughout the contract. At contract end, customers can export all stored log data, incident information, alerts, and workbooks directly via the Microsoft portals or APIs. Claranet Online tickets can be exported by the customer before decommissioning. No proprietary data is held in Claranet systems beyond ticket metadata, which can be exported by request.
Claranet follows a structured offboarding process where customer access is transitioned, permissions revoked, and SOC monitoring ceased. Customers should extract any reporting archives or ticket histories they require before account closure.
End-of-contract process
Upon contract expiry or termination, Claranet disables monitoring and access to Claranet Online once offboarding is complete. Customers retain all data in Microsoft Sentinel, Defender, and related Azure resources, as these are owned within the customer’s tenant. Included in the contract price is offboarding coordination, revocation of delegated access (Lighthouse/GDAP), and a summary closure report.
Chargeable items at end of contract may include professional services for extended offboarding support, custom exports (if required), or assistance migrating to another provider. Claranet ensures response actions are discontinued safely and that no automated playbooks remain authorised. Customers must remove any remaining Defender agents if discontinuing the service. No additional charge applies for closing user accounts or disabling the service interface.
Documentation accessibility standard
EN 301 549

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Application to install
No
Designed for use on mobile devices
No
Service interface
Yes
User support accessibility
EN 301 549
Description of service interface
Claranet Online is a secure web portal through which customers receive incident notifications, access reports, raise queries, request custom detection rules, and view ticket history. It provides a centralised interface for communicating with SOC analysts, platform engineers, and the Service Optimisation Manager. Incident tickets contain detailed investigation notes, recommended actions, and response outcomes. Monthly and quarterly reports are accessible directly through the portal. Customers can submit change requests, update escalation contacts, and review log‑source onboarding status.
Accessibility standards
EN 301 549
Accessibility testing
Claranet Online follows standard web accessibility practices and supports common assistive technologies through browser compatibility. Testing has included use with screen readers, browser zoom, high‑contrast display modes, and keyboard‑only navigation. These tests ensure core actions—raising tickets, reviewing incident notes, downloading reports, and adding comments—remain accessible. Users relying on assistive tools such as NVDA, JAWS, or VoiceOver can navigate the portal interface because it is HTML‑based and uses semantic labelling for key fields.
Within the Microsoft Defender and Sentinel portals, accessibility is ensured by Microsoft’s own conformity with WCAG 2.1 AA standards. As part of service delivery, Claranet verifies that customers relying on Microsoft interfaces can access incident details, alerts, and dashboards using native accessibility settings.
No specialist software is required, and customers can access the interface using standard supported browsers. As accessibility needs vary across user groups, Claranet provides assistance during onboarding to ensure that individuals with specific requirements have suitable access paths. Customers may request additional guidance or walkthrough sessions where Claranet support teams will help validate compatible accessibility tools and ensure the solution is usable for all operational roles.
API
Yes
What users can and can't do using the API
Customers can use Microsoft Sentinel and Defender APIs to query incidents, retrieve alert details, pull telemetry, trigger approved automation rules, and export data for integration into third‑party platforms such as SIEMs or ITSM systems. These APIs support automation of reporting, correlation workflows, and customised dashboards. Customers may manage their own analytic rules, workbooks, and logic app automations where they have administrative rights.
Through Claranet Online’s API integrations (where offered), customers may retrieve ticket metadata and incident summaries for internal dashboards. However, customers cannot alter Claranet’s internal triage notes, investigation methods, or SOC workflows. They also cannot initiate any response actions directly through Claranet’s API layer; these remain governed by SOC approval and customer permissions.
Customers cannot onboard new log sources, adjust detection tuning, or perform Lighthouse/GDAP configuration through an API; these tasks require Claranet’s engineering processes. Likewise, customers cannot manipulate service-level parameters or modify service-internal SLAs.
APIs enable visibility, querying, automation, and export—but not direct alteration of the managed security service or SOC operational processes.
API documentation
Yes
API documentation formats
HTML
API sandbox or test environment
Yes
Customisation available
Yes
Description of customisation
Customers have flexibility over log-source selection, detection coverage, escalation procedures, and response authorisations. Through Claranet Online, they may request custom detection rules tailored to specific applications, behaviours, or compliance needs. Customers may also provide whitelists, business‑context information, and operational constraints to refine tuning. Data retention periods in Microsoft Sentinel may be extended by purchasing additional Microsoft capacity.
Escalation flows (e.g., who receives P1 alerts) can be customised during onboarding and updated at any time through change requests. Customers may choose which response actions Claranet is authorised to execute directly, including device isolation, user suspension, or automated playbook execution. They can also customise reporting distribution lists and add multiple stakeholders to incident notifications.
Customisations must be requested by authorised customer contacts. Claranet reviews requests for suitability, ensures they do not compromise security operations, and applies them through SOC engineering teams. Custom detection rules undergo quality checks to ensure they avoid excessive false positives and align with the MITRE ATT&CK framework.

Scaling

Independence of resources
The service uses Microsoft Sentinel’s scalable architecture, ensuring ingestion and analytics performance is not impacted by other customers. Claranet’s SOC is operationally resourced to handle alert volumes across all customers and employs priority‑based routing to ensure critical incidents are addressed immediately. Automation offloads repetitive triage tasks, while tuning reduces unnecessary alerts. Workload is continuously monitored to maintain consistent service delivery.

Analytics

Service usage metrics
Yes
Metrics types
Monthly reports include incident volumes, priority distribution, false‑positive rates, response actions taken, threat‑hunting outcomes, and rule‑tuning metrics. Additional metrics include log ingestion volumes, data‑tier utilisation, onboarding progress, and SLA attainment. Quarterly reviews provide trend analysis, service improvements, and recommendations based on threat landscape changes. Customers can view ticket activity via Claranet Online.
Reporting types
  • API access
  • Real-time dashboards
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Not a reseller

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
  • Other locations
User control over data storage and processing locations
Yes
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
In-house
Protecting data at rest
  • Physical access control, complying with CSA CCM v4.0
  • Physical access control, complying with SSAE-18 / ISAE 3402
  • Encryption of all physical media
  • Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data sanitisation type
  • Deleted data can’t be directly accessed / Cryptographic Erasure
  • Explicit overwriting of storage before reallocation / Secure Erase

Data importing and exporting

Data export approach
Customers export data directly from Microsoft Sentinel (via KQL, export APIs, or workspace export), Microsoft Defender portals (CSV, JSON, API), or through their own integrated reporting tools. Claranet Online ticket information can be exported manually or requested via support. All telemetry remains in the customer’s Microsoft tenant, enabling full independent export without Claranet involvement. Workbooks, analytics rules, and dashboards can be downloaded as ARM templates.
Data export formats
  • CSV
  • Other
Other data export formats
  • JSON
  • XML
  • TXT
Data import formats
  • CSV
  • Other
Other data import formats
  • JSON
  • Syslog
  • CEF
  • HTTP POST

Data-in-transit protection

Data protection between buyer and supplier networks
  • TLS (version 1.2 or above)
  • IPsec or TLS VPN gateway
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
The service leverages Microsoft’s cloud resilience and Claranet’s 24/7 SOC operations. Availability of Defender, Sentinel, and the underlying Azure services follows Microsoft’s published SLAs (typically up to 99.9% depending on SKU). Claranet Online maintains high availability through redundant hosting and continuous monitoring. SOC services operate continuously with no planned downtime.
If defined service levels for incident notification or triage are not met, service credits apply as stated in the Service Description (up to 25% of monthly fees). SLAs cover triage and notification times but not Microsoft platform uptime or customer-side connectivity. Any unavailability caused by customer configuration, licensing, or third-party issues is excluded.
Approach to resilience
Microsoft Sentinel and Defender operate across geo‑redundant Azure regions, supporting high availability and failover. Data ingestion uses scalable Log Analytics infrastructure, while rules and automations replicate across zones. Claranet SOC operations use multi‑location resources, ensuring continuity of monitoring, investigation, and response.
If further architectural detail is required for risk assessments, this can be provided on request under NDA. Claranet’s SOC staffing model ensures uninterrupted coverage, supported by automated enrichment and queue management systems.
Outage reporting
Microsoft publishes platform-wide outages on its public status pages and via Azure Service Health. Customers receive email or portal alerts for Sentinel or Defender disruptions. Claranet reports service-affecting issues via Claranet Online announcements or direct notifications for critical incidents. Customers may also subscribe to email alerts or SIEM‑integrated signals.
Customers are notified of significant events impacting ticketing or SOC communication.
If outages affect response actions or ingestion, Claranet escalates to Microsoft and keeps customers informed through ticket updates.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password
Access restrictions in management interfaces and support channels
Access to Claranet Online is role-based. Only authorised customer contacts can submit or view tickets. SOC and engineering staff use least‑privilege access with audit logging. Sensitive management channels require MFA, and all administrative actions are monitored.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Public key authentication (including by TLS client certificate)
  • Identity federation with existing provider (for example Google Apps)
  • Dedicated link (for example VPN)
  • Username or password

Audit information for users

Access to user activity audit information
Users receive audit information on a regular basis
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
At least 12 months
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Claranet follows structured information security policies aligned to ISO/IEC 27001, covering access control, incident management, vulnerability management, change management, and asset governance. Policies are reviewed regularly by Claranet’s security leadership and audited internally and externally. Enforcement is overseen by the Information Security team, with reporting lines to senior management. Staff undergo mandatory training, and SOC personnel follow documented operational playbooks.
Policies cover handling of customer data, restricted access, secure logging, and separation of duties. Internal systems follow least‑privilege access and regular monitoring.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
All service components are tracked throughout their lifecycle, including configuration items, log-source inventories, and customer-specific settings. Changes are assessed for security impact, tested in controlled environments, and approved before deployment. SOC engineering manages updates to detection rules, automations, and tuning configurations. Customer-requested changes are captured in Claranet Online and executed following review.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
Claranet monitors vendor advisories, threat intelligence feeds, and Microsoft security updates to identify new vulnerabilities. Systems are regularly scanned and patched in line with internal policies. High‑severity vulnerabilities are prioritised for remediation. Claranet also monitors Defender and Sentinel for tenant-specific exposures and alerts customers when action is required. Threat intelligence sources include open-source feeds, government guidance, and Microsoft advisories.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
Protective monitoring includes continuous alert analysis, anomaly detection, and threat hunting. SOC analysts investigate suspicious patterns, correlate telemetry, and escalate incidents following defined workflows. Potential compromises trigger rapid triage and customer notification where required. Response times follow the SLA matrix, with P1 incidents receiving immediate action. Monitoring is 24/7.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Claranet operates an internal incident‑management process aligned to ISO/IEC 27001 and ITIL practices. Incidents are logged, triaged, and classified according to severity, with clear escalation paths to security, technical and management stakeholders. A dedicated incident response team coordinates containment, investigation and recovery activities, supported by documented playbooks and business continuity procedures. All actions are recorded for audit, and post‑incident reviews identify root cause, lessons learned and required control improvements. Processes include strict access controls, change tracking and communication workflows to ensure consistency, accountability and compliance across all operational environments.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
A time‑limited PoC is available, including onboarding of core Defender and Sentinel data sources, sample detection rules, and demonstration investigations. It excludes full response actions, custom rules, and long-term tuning. Customers retain access for a limited evaluation period before deciding on full service adoption.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
1%
Between £500,001 and £1,000,000
2%
Between £1,000,001 and £2,500,000
3%
Between £2,500,001 and £5,000,000
4%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
Intertek
ISO/IEC 27001 accreditation date
Wednesday 22 May 2024
What the ISO/IEC 27001 doesn’t cover
This certification covers everything we do applicable to ISO/IEC 27001, no exclusions.
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
Intertek
ISO 9001 accreditation date
Wednesday 7 June 2023
What the ISO 9001 doesn’t cover
This certification covers everything we do applicable to ISO 9001, no exclusions.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
Yes
Who accredited the PCI DSS certification
Pen Test Partners
PCI DSS accreditation date
Friday 13 December 2024
What the PCI DSS doesn’t cover
N/a
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
4377ebef-31ac-49ef-9943-13c7f3e3f9a5
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
66b24695-ed3f-4797-bb2c-65b58932576d
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Volunteering opportunities for staff
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
    • Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
    • Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
    • Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
    • Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at Uk-bidteam@claranet.com. Tell them what format you need. It will help if you say what assistive technology you use.