Extended Detection & Response for Microsoft
Claranet’s Managed XDR for Microsoft provides 24/7 detection, investigation, and response across Defender and Sentinel. Using correlated telemetry from endpoints, identities, cloud applications and infrastructure, our SOC proactively identifies threats, performs expert analysis, executes response actions, and continuously tunes detections to improve visibility, reduce risk, and strengthen customers’ security posture.
Features
- 24/7 SOC monitoring across Microsoft Defender and Sentinel telemetry
- Unified detection correlation across endpoint, identity, cloud, applications
- Proactive threat hunting using MITRE ATT&CK methodologies
- Continuous tuning to minimise false positives and alert noise
- Custom detection rule creation aligned to customer environment
- Assisted onboarding for log sources and agent deployment
- Incident triage, investigation, and root‑cause analysis included
- Automated and analyst‑led response actions when authorised
- Monthly reporting and quarterly service optimisation reviews
- Integrated threat intelligence enrichment for faster incident understanding
Benefits
- Faster detection and containment of advanced cyber threats
- Reduced operational load through fully managed SOC capability
- Improved security posture through continuous detection tuning
- Enhanced visibility across full Microsoft security ecosystem
- Rapid incident response supported by expert triage
- Reduced false positives and operational distractions
- Clear insights through structured monthly reporting
- Strengthened resilience via proactive threat hunting
- Consistent security governance and expert guidance
- Improved ROI on Microsoft Defender and Sentinel investments
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 7 5 8 3 2 0 8 1 3 5 3 7 1 9
Contact
CLARANET LIMITED
Claranet UK Bid Team
Telephone: 020 7685 8000
Email: Uk-bidteam@claranet.com
About your service
- Service categories
-
Applications
Production and operations
- Other operations
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
-
Microsoft Defender XDR (Defender for Endpoint, Identity, Cloud Apps, Cloud)
Microsoft Sentinel (SIEM + Automation)
Microsoft 365 security telemetry sources
Azure log sources integrated via Sentinel
Optional third‑party telemetry if supported by Sentinel connectors - Cloud deployment model
-
- Public cloud
- Hybrid cloud
- Service constraints
- The service relies on customers maintaining correct Microsoft licences, ensuring Defender agents are deployed, and granting Claranet authorised access via Lighthouse and GDAP. Delays in access, permissions, or log‑source readiness may postpone onboarding. Scheduled Microsoft or customer maintenance windows may affect data ingestion. Mobile devices are currently out of scope for response actions. Customer‑initiated penetration testing must be pre‑approved to avoid alert overload. Some response actions require explicit tenant permissions and may not be available in restricted environments. Data retention limits follow the customer’s Microsoft licensing unless upgraded separately. Connectivity or licence issues outside Claranet’s control may impact service.
- System requirements
-
- Microsoft Defender licences for in‑scope endpoints and identities
- Microsoft Sentinel workspace deployed within customer Azure tenant
- Log Analytics capacity sized for chosen data ingestion volume
- Defender agents deployed to all monitored endpoints
- Azure Lighthouse onboarding script executed by customer admin
- GDAP “Security Admin” role delegated to Claranet
- Customer provides up‑to‑date contact and escalation details
- Secure mechanism (e.g., Intune) for agent deployment
- Customer-approved authorisation for automated response actions
- Supported operating systems for Defender agent compatibility
User support
- Email or online ticketing support
- Yes
- Support response times
- All customer queries and incident notifications are handled via Claranet Online, supported 24/7 by our SOC. Standard operational questions are typically reviewed during business hours (Monday–Friday, 09:00–17:30 GMT), while incident‑related communication follows the service’s defined priority matrix. Priority 1 and 2 incidents include rapid notification (15–30 minutes after classification). Non‑urgent questions submitted via the portal are acknowledged in line with ticket priority and addressed as soon as possible. SLA‑backed response times apply to security incidents; general questions follow best‑effort handling aligned to workload and severity.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- EN 301 549
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Claranet provides tiered support integrated into the managed XDR service.
Support is delivered primarily through:
24/7 Security Operations Centre (SOC) for incident triage, investigation, and response
Platform Support Engineers (business hours) for onboarding, agent deployment, and troubleshooting
Security Optimisation Manager (SOM) for quarterly reviews and service quality
Claranet Online for ticketing, reporting, and communication
Included support:
Incident analysis, notification, containment guidance and response actions
Continuous tuning and rule management
Threat hunting
Monthly reports and quarterly service reviews
Assisted onboarding for log sources
Optional chargeable support:
Additional professional services
Custom integrations beyond core Microsoft sources
Increased data retention costs (from Microsoft)
Out‑of‑scope engineering tasks requiring SOW
Onsite support (if required)
A dedicated SOM functions similarly to a Technical Account Manager, coordinating service governance, reporting, and improvements. SOC engineers and analysts act as cloud security specialists for live investigations. Pricing varies depending on data tier, endpoint volume, and optional modules but all service levels include 24/7 SOC response. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Onboarding begins with a planning workshop to define scope, log sources, access requirements, and escalation procedures. Claranet provides guidance on agent deployment, Lighthouse onboarding, GDAP access, and Sentinel workspace configuration. A project manager coordinates onboarding tasks and ensures all prerequisites are fulfilled. Assisted onboarding includes deployment validation for one instance of each log‑source type. Customers receive access to Claranet Online, along with documentation on incident handling, response processes, and service controls.
Claranet provides user documentation for Claranet Online, Sentinel access, and escalation guidance. Training sessions can be conducted remotely to familiarise operational teams with incident workflows, reporting features, and required customer responsibilities. When onboarding completes, tuning begins immediately, supported by ongoing engineering assistance. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Because all customer log data is held within their own Microsoft Sentinel and Defender tenants, customers retain full ownership and control of all raw and enriched data throughout the contract. At contract end, customers can export all stored log data, incident information, alerts, and workbooks directly via the Microsoft portals or APIs. Claranet Online tickets can be exported by the customer before decommissioning. No proprietary data is held in Claranet systems beyond ticket metadata, which can be exported by request.
Claranet follows a structured offboarding process where customer access is transitioned, permissions revoked, and SOC monitoring ceased. Customers should extract any reporting archives or ticket histories they require before account closure. - End-of-contract process
-
Upon contract expiry or termination, Claranet disables monitoring and access to Claranet Online once offboarding is complete. Customers retain all data in Microsoft Sentinel, Defender, and related Azure resources, as these are owned within the customer’s tenant. Included in the contract price is offboarding coordination, revocation of delegated access (Lighthouse/GDAP), and a summary closure report.
Chargeable items at end of contract may include professional services for extended offboarding support, custom exports (if required), or assistance migrating to another provider. Claranet ensures response actions are discontinued safely and that no automated playbooks remain authorised. Customers must remove any remaining Defender agents if discontinuing the service. No additional charge applies for closing user accounts or disabling the service interface. - Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- Yes
- User support accessibility
- EN 301 549
- Description of service interface
- Claranet Online is a secure web portal through which customers receive incident notifications, access reports, raise queries, request custom detection rules, and view ticket history. It provides a centralised interface for communicating with SOC analysts, platform engineers, and the Service Optimisation Manager. Incident tickets contain detailed investigation notes, recommended actions, and response outcomes. Monthly and quarterly reports are accessible directly through the portal. Customers can submit change requests, update escalation contacts, and review log‑source onboarding status.
- Accessibility standards
- EN 301 549
- Accessibility testing
-
Claranet Online follows standard web accessibility practices and supports common assistive technologies through browser compatibility. Testing has included use with screen readers, browser zoom, high‑contrast display modes, and keyboard‑only navigation. These tests ensure core actions—raising tickets, reviewing incident notes, downloading reports, and adding comments—remain accessible. Users relying on assistive tools such as NVDA, JAWS, or VoiceOver can navigate the portal interface because it is HTML‑based and uses semantic labelling for key fields.
Within the Microsoft Defender and Sentinel portals, accessibility is ensured by Microsoft’s own conformity with WCAG 2.1 AA standards. As part of service delivery, Claranet verifies that customers relying on Microsoft interfaces can access incident details, alerts, and dashboards using native accessibility settings.
No specialist software is required, and customers can access the interface using standard supported browsers. As accessibility needs vary across user groups, Claranet provides assistance during onboarding to ensure that individuals with specific requirements have suitable access paths. Customers may request additional guidance or walkthrough sessions where Claranet support teams will help validate compatible accessibility tools and ensure the solution is usable for all operational roles. - API
- Yes
- What users can and can't do using the API
-
Customers can use Microsoft Sentinel and Defender APIs to query incidents, retrieve alert details, pull telemetry, trigger approved automation rules, and export data for integration into third‑party platforms such as SIEMs or ITSM systems. These APIs support automation of reporting, correlation workflows, and customised dashboards. Customers may manage their own analytic rules, workbooks, and logic app automations where they have administrative rights.
Through Claranet Online’s API integrations (where offered), customers may retrieve ticket metadata and incident summaries for internal dashboards. However, customers cannot alter Claranet’s internal triage notes, investigation methods, or SOC workflows. They also cannot initiate any response actions directly through Claranet’s API layer; these remain governed by SOC approval and customer permissions.
Customers cannot onboard new log sources, adjust detection tuning, or perform Lighthouse/GDAP configuration through an API; these tasks require Claranet’s engineering processes. Likewise, customers cannot manipulate service-level parameters or modify service-internal SLAs.
APIs enable visibility, querying, automation, and export—but not direct alteration of the managed security service or SOC operational processes. - API documentation
- Yes
- API documentation formats
- HTML
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Customers have flexibility over log-source selection, detection coverage, escalation procedures, and response authorisations. Through Claranet Online, they may request custom detection rules tailored to specific applications, behaviours, or compliance needs. Customers may also provide whitelists, business‑context information, and operational constraints to refine tuning. Data retention periods in Microsoft Sentinel may be extended by purchasing additional Microsoft capacity.
Escalation flows (e.g., who receives P1 alerts) can be customised during onboarding and updated at any time through change requests. Customers may choose which response actions Claranet is authorised to execute directly, including device isolation, user suspension, or automated playbook execution. They can also customise reporting distribution lists and add multiple stakeholders to incident notifications.
Customisations must be requested by authorised customer contacts. Claranet reviews requests for suitability, ensures they do not compromise security operations, and applies them through SOC engineering teams. Custom detection rules undergo quality checks to ensure they avoid excessive false positives and align with the MITRE ATT&CK framework.
Scaling
- Independence of resources
- The service uses Microsoft Sentinel’s scalable architecture, ensuring ingestion and analytics performance is not impacted by other customers. Claranet’s SOC is operationally resourced to handle alert volumes across all customers and employs priority‑based routing to ensure critical incidents are addressed immediately. Automation offloads repetitive triage tasks, while tuning reduces unnecessary alerts. Workload is continuously monitored to maintain consistent service delivery.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Monthly reports include incident volumes, priority distribution, false‑positive rates, response actions taken, threat‑hunting outcomes, and rule‑tuning metrics. Additional metrics include log ingestion volumes, data‑tier utilisation, onboarding progress, and SLA attainment. Quarterly reviews provide trend analysis, service improvements, and recommendations based on threat landscape changes. Customers can view ticket activity via Claranet Online.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Explicit overwriting of storage before reallocation / Secure Erase
Data importing and exporting
- Data export approach
- Customers export data directly from Microsoft Sentinel (via KQL, export APIs, or workspace export), Microsoft Defender portals (CSV, JSON, API), or through their own integrated reporting tools. Claranet Online ticket information can be exported manually or requested via support. All telemetry remains in the customer’s Microsoft tenant, enabling full independent export without Claranet involvement. Workbooks, analytics rules, and dashboards can be downloaded as ARM templates.
- Data export formats
-
- CSV
- Other
- Other data export formats
-
- JSON
- XML
- TXT
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- JSON
- Syslog
- CEF
- HTTP POST
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
The service leverages Microsoft’s cloud resilience and Claranet’s 24/7 SOC operations. Availability of Defender, Sentinel, and the underlying Azure services follows Microsoft’s published SLAs (typically up to 99.9% depending on SKU). Claranet Online maintains high availability through redundant hosting and continuous monitoring. SOC services operate continuously with no planned downtime.
If defined service levels for incident notification or triage are not met, service credits apply as stated in the Service Description (up to 25% of monthly fees). SLAs cover triage and notification times but not Microsoft platform uptime or customer-side connectivity. Any unavailability caused by customer configuration, licensing, or third-party issues is excluded. - Approach to resilience
-
Microsoft Sentinel and Defender operate across geo‑redundant Azure regions, supporting high availability and failover. Data ingestion uses scalable Log Analytics infrastructure, while rules and automations replicate across zones. Claranet SOC operations use multi‑location resources, ensuring continuity of monitoring, investigation, and response.
If further architectural detail is required for risk assessments, this can be provided on request under NDA. Claranet’s SOC staffing model ensures uninterrupted coverage, supported by automated enrichment and queue management systems. - Outage reporting
-
Microsoft publishes platform-wide outages on its public status pages and via Azure Service Health. Customers receive email or portal alerts for Sentinel or Defender disruptions. Claranet reports service-affecting issues via Claranet Online announcements or direct notifications for critical incidents. Customers may also subscribe to email alerts or SIEM‑integrated signals.
Customers are notified of significant events impacting ticketing or SOC communication.
If outages affect response actions or ingestion, Claranet escalates to Microsoft and keeps customers informed through ticket updates.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
- Access restrictions in management interfaces and support channels
- Access to Claranet Online is role-based. Only authorised customer contacts can submit or view tickets. SOC and engineering staff use least‑privilege access with audit logging. Sensitive management channels require MFA, and all administrative actions are monitored.
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users receive audit information on a regular basis
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Claranet follows structured information security policies aligned to ISO/IEC 27001, covering access control, incident management, vulnerability management, change management, and asset governance. Policies are reviewed regularly by Claranet’s security leadership and audited internally and externally. Enforcement is overseen by the Information Security team, with reporting lines to senior management. Staff undergo mandatory training, and SOC personnel follow documented operational playbooks.
Policies cover handling of customer data, restricted access, secure logging, and separation of duties. Internal systems follow least‑privilege access and regular monitoring. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- All service components are tracked throughout their lifecycle, including configuration items, log-source inventories, and customer-specific settings. Changes are assessed for security impact, tested in controlled environments, and approved before deployment. SOC engineering manages updates to detection rules, automations, and tuning configurations. Customer-requested changes are captured in Claranet Online and executed following review.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Claranet monitors vendor advisories, threat intelligence feeds, and Microsoft security updates to identify new vulnerabilities. Systems are regularly scanned and patched in line with internal policies. High‑severity vulnerabilities are prioritised for remediation. Claranet also monitors Defender and Sentinel for tenant-specific exposures and alerts customers when action is required. Threat intelligence sources include open-source feeds, government guidance, and Microsoft advisories.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- Protective monitoring includes continuous alert analysis, anomaly detection, and threat hunting. SOC analysts investigate suspicious patterns, correlate telemetry, and escalate incidents following defined workflows. Potential compromises trigger rapid triage and customer notification where required. Response times follow the SLA matrix, with P1 incidents receiving immediate action. Monitoring is 24/7.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Claranet operates an internal incident‑management process aligned to ISO/IEC 27001 and ITIL practices. Incidents are logged, triaged, and classified according to severity, with clear escalation paths to security, technical and management stakeholders. A dedicated incident response team coordinates containment, investigation and recovery activities, supported by documented playbooks and business continuity procedures. All actions are recorded for audit, and post‑incident reviews identify root cause, lessons learned and required control improvements. Processes include strict access controls, change tracking and communication workflows to ensure consistency, accountability and compliance across all operational environments.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- A time‑limited PoC is available, including onboarding of core Defender and Sentinel data sources, sample detection rules, and demonstration investigations. It excludes full response actions, custom rules, and long-term tuning. Customers retain access for a limited evaluation period before deciding on full service adoption.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 3%
- Between £2,500,001 and £5,000,000
- 4%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Intertek
- ISO/IEC 27001 accreditation date
- Wednesday 22 May 2024
- What the ISO/IEC 27001 doesn’t cover
- This certification covers everything we do applicable to ISO/IEC 27001, no exclusions.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- Intertek
- ISO 9001 accreditation date
- Wednesday 7 June 2023
- What the ISO 9001 doesn’t cover
- This certification covers everything we do applicable to ISO 9001, no exclusions.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- Pen Test Partners
- PCI DSS accreditation date
- Friday 13 December 2024
- What the PCI DSS doesn’t cover
- N/a
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 4377ebef-31ac-49ef-9943-13c7f3e3f9a5
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 66b24695-ed3f-4797-bb2c-65b58932576d
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Creation of employment opportunities particularly for those who face barriers to employment, such as prison leavers, care leavers and/or who are located in deprived areas, and for people in industries with known skills shortages or in high growth sectors
- Delivery of training schemes and programmes to address any identified skills gaps and under-representation in the workforce for the contract (e.g. prison leavers, care leavers, kinship carers, disabled people)
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-