Aurora Identity and Access Management (IDAM) - CoreGov
Aurora is a cloud-based Identity and Access Management platform. It contains Role Based Access and engines for enterprise level policy/rule based provisioning, update and de-provisioning, user synchronisation and workflow based authorisation and escalation notifications. Aurora can be branded and scripting is available for any customised policy or workflow requirements.
Features
- Identity Vault for single authoritative identity and authentication
- Enterprise role based access control (RBAC) with query-based views
- Manage Office365 Users, Groups and Mailboxes
- Automated user provisioning and de-provisioning from AD and HR systems
- Secure web based access from any browser on any device
- Secure 2 factor authentication from hard or soft tokens
- User self-service password reset via traditional Q&A or 2factor token
- Self-service portals for user attributes and group membership
- Over 50 enterprise level audit reports out of the box
- User identity workflow, authorisation workflow and full lifecycle management
Benefits
- One username and one password for your users to remember
- Empower user self-service with access from any device or browser
- Put the business back in charge of group membership
- Reduce admin mistakes/workload with automated workflows
- Reduce admin mistakes with locked value drop-down lists
- Workflows can automate typical manual changes during the provisioning/deprovisiong cycles
- All user and group changes are audited with before/after values
- Automated user synchronisation from multiple source systems
- We’re always at hand with 24/7 multi-lingual support
- Reduced cost of ownership of cloud SaaS based applications
Pricing
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
3 7 6 4 6 9 9 8 7 5 7 9 0 3 0
Contact
CORE TECHNOLOGY SYSTEMS (U.K.) LIMITED
Paul Saer
Telephone: +44 (0) 207 626 0516
Email: tenders@core.co.uk
About your service
- Service categories
-
Systems Infrastructure Software
Security
Identity and access management
- Access
- Privilege
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- No
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- Aurora is deployed exclusively within Microsoft Azure and requires appropriate customer‑side configuration, including network connectivity, service‑account permissions, certificate chains (for LDAPS where needed), and access to HR import/export locations. The service depends on correct AD or legacy‑domain configuration for synchronisation. Core performs scheduled updates, patches and vulnerability remediation, which may require planned maintenance windows. Where customers choose a self‑managed model, they are responsible for their own support and environment upkeep. Service needs to be Azure based but can manage identities in other platforms including AWS.
- System requirements
-
- Microsoft Azure subscription for dedicated Aurora service deployment.
- Network connectivity to all integrated HR and identity systems.
- Service‑account permissions for directory and domain operations.
- Certificate chain available for secure LDAPS connections.
- Accessible HR data import and export file locations.
- Configured Active Directory or legacy domain OU structures.
- Firewall rules permitting Aurora connectivity to target systems.
- Azure environment maintained per buyer security baselines.
- API‑enabled SaaS applications for provisioning and synchronisation.
- Stable VPN or ExpressRoute links for hybrid deployments.
User support
- Email or online ticketing support
- Yes
- Support response times
- Response times are dependent on the nature of the request. For Managed Services tickets, the response times for different request types are listed in the Service Description document.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- Our webchat solution is configurable, allowing us to tailor the interface by enabling or disabling features for different clients. This can help simplify navigation for users who need a less cluttered interface. Security roles can be configured to limit or expand access to certain features, which can help create simpler experiences for users who might struggle with complex navigation. Users can submit tickets, access knowledge bases, and use service catalogues without direct staff interaction, which could benefit users who prefer asynchronous communication. Our platform also supports integrations with Teams, Slack, and chat applications, which may allow users to choose communication channels that work best for them.
- Web chat accessibility testing
- None
- Onsite support
- Yes, at extra cost
- Support levels
- Core run an ITIL aligned Service Desk and incident management approach. All service requests can be made directly to our 24/7 ServiceDesk function. First line or Second Line technical analyst or engineers engage with all service tickets until successfully closed. All customers can also engage with a named Account Manager and Customer Success Manager. Core typically structures Managed Services into modular SKUs, allowing customers to select the level of support they need - for example Service Desk, End User Compute, Microsoft365 Support, Infrastructure Support and Azure Managed Services. All of these SKU's are individually priced and pricing is referenced in the relevant Service Definition document
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- We provide a structured onboarding and training approach. This includes online and onsite training workshops, role‑based training modules for administrators and support teams, and refreshed user guides and on‑demand how‑to videos. We deliver portal training, reporting and audit training, and knowledge‑transfer sessions during deployment. Documentation, quick‑reference guides and recorded materials are provided for ongoing use. Early‑life support and service desk onboarding are also included to ensure users can begin using Aurora confidently and effectively.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- ODF
- End-of-contract data extraction
-
Users can extract their data at the end of the contract through several supported mechanisms. Aurora provides full export of identity data, configuration, audit history, RBAC models, workflow metadata, and integration mappings. Data is exported in open, portable formats including CSV, SQL extracts, and document‑based reports (PDF/DOCX).
A structured offboarding plan is included with every deployment, outlining how all customer data is extracted, transferred, or returned. All exports use non‑proprietary formats and can be consumed by successor IDAM/IGA platforms or retained for audit and compliance purposes. - End-of-contract process
-
At the end of the contract, the customer receives a full offboarding process, including export of all identity data, audit history, RBAC models, workflow information, and configuration details in open formats (CSV, SQL extracts, PDF/DOCX reports). A high‑level offboarding plan is provided as standard. Core supports a structured and safe handover, including deprovisioning of identities, removal of integrations, and providing documentation to the incoming supplier.
Included in the price: use of the Aurora platform, standard reporting, audit logs, platform updates, admin portal access, and the high‑level offboarding plan.
Additional costs: execution of offboarding activities (decommissioning and transition), 24×7 support uplifts, bespoke workflow/report development, RBAC redesign, legacy system decommissioning, and optional additional environments. - Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Our onboarding and offboarding documentation is provided in standard digital formats (DOCX and PDF). While these formats are widely compatible with common screen‑readers and assistive technologies, the documentation itself is not currently authored to a formal accessibility standard such as WCAG 2.1.
Alternative accessible formats (e.g., ODF, large‑print, Easy Read, HTML, audio) are not currently produced by default but may be made available on request.
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Other
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- There are no functional differences between mobile and desktop access. Aurora is fully browser‑based and designed to provide the same user experience, features, and self‑service capabilities on smartphones and tablets as on desktop devices. Screen layout naturally adapts to suit smaller displays, but all core functions remain available.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Aurora provides a fully browser‑based user and administration interface, as well as API‑level integration interfaces for connecting with third‑party systems and automating identity lifecycle actions.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Aurora provides a fully browser‑based interface designed for accessibility across devices, screen sizes, and operating systems. The service uses responsive layouts, supports all major browsers, and enables access from desktops, laptops, tablets and smartphones. While Aurora has not been formally certified against accessibility standards (such as WCAG or EN 301 549), its web‑based design supports inclusive access for a wide range of users and devices.
- Accessibility testing
- No formal assistive technology user testing has been carried out. Aurora is delivered through a responsive, browser‑based interface designed to function on a wide range of devices and screen sizes, but it has not yet been tested with assistive technology users.
- API
- Yes
- What users can and can't do using the API
- Aurora provides API‑based integration capabilities that allow external systems to create, update and deprovision identities, trigger Joiner/Mover/Leaver events, and apply RBAC permissions across connected SaaS and cloud applications. Users can set up the service by configuring REST API integrations from authoritative systems such as Workday or ServiceNow, and can make changes by updating data sent to Aurora via these integrations. Aurora does not expose APIs for configuring internal workflows, altering policies, managing the admin portal or performing self‑service functions. All platform configuration and manual administration is completed through the Aurora portal.
- API documentation
- No
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
-
Aurora allows buyers to customise elements of the service through configuration. Buyers can customise branding, workflow rules, identity lifecycle automation, attribute mappings, RBAC models and integrations with HR, AD/Entra ID and third‑party SaaS applications.
Customisation is completed through configuration during implementation using the Aurora administration portal and integration settings. Day‑to‑day changes - such as updating workflow rules, role mappings or integration inputs, are performed by authorised administrators within the buyer’s organisation. Core platform code, user interface structure and API endpoints cannot be customised, as Aurora remains a managed service with controlled configuration options.
Scaling
- Independence of resources
-
Aurora is deployed as a a single‑tenant solution for each customer, decentralised architecture in which each customer receives their own dedicated instance. Workloads are fully isolated and cannot impact or be impacted by other organisations. The platform is deployed in the customer’s Azure subscription, benefiting from Azure-native scaling, redundancy, and resource isolation.
Aurora includes workload‑protection features such as transaction thresholds and mass‑update limits, preventing any one process from consuming excessive system capacity. Continuous diagnostics, Log Analytics monitoring, and 24×7 engineering alerting ensure any performance issues are identified and remediated before users experience impact.
Analytics
- Service usage metrics
- Yes
- Metrics types
- Yes, we provide detailed service usage metrics. Aurora includes full audit trails, operational performance metrics, job execution statistics, identity lifecycle volumes (JML), access governance metrics, and capacity indicators. These metrics are available through the Aurora reporting suite, nightly CSV exports, the SQL audit store, and optional Power BI dashboards. Customers can schedule reports or access real‑time operational insights directly through the admin portal.
- Reporting types
-
- API access
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Microsoft
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
- Users export their data via open, portable formats generated directly by Aurora. The platform provides nightly CSV audit exports, full extraction of the SQL audit store, scheduled reporting datasets, and documented exports of RBAC models, workflow definitions and configuration data. These exports can be consumed by any successor IDAM/IGA system. A high‑level offboarding plan is provided to guide the customer through data extraction and decommissioning.
- Data export formats
- CSV
- Data import formats
- CSV
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
- We guarantee 99.95% service availability for Aurora in its recommended configuration. The service includes defined incident response and resolution SLAs (for example, Priority 1 incidents receive a 15‑minute response and 120‑minute resolution target). Aurora does not include financial refunds or service credits if availability falls below the guaranteed level.
- Approach to resilience
- Aurora is designed to be highly resilient, delivering a guaranteed availability level of 99.95%. The service is deployed as a dedicated, single‑tenant instance within each customer’s Azure subscription, benefiting from Azure Availability Zones, redundant compute, resilient storage, and geo‑redundant disaster recovery. Aurora incorporates continuous monitoring, automated health checks, and 24×7 alerting to ensure issues are identified and resolved before users experience impact. Detailed datacentre resilience arrangements can be provided on request.
- Outage reporting
- Aurora is continuously monitored using live service health checks. If an outage occurs, Core initiates an incident under the service SLAs and provides direct communications to the customer’s nominated contacts. For Priority 1 incidents, updates are sent every 30 minutes; for Priority 2 incidents, updates are issued hourly. We do not use a public status dashboard or a public API for outage reporting—notifications are delivered through our incident management process, typically via email and agreed communication channels.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- Aurora restricts administrative access through Microsoft Entra ID using MFA, Conditional Access and strict role‑based access controls. Only authorised admin identities can access the management portal, and privileged actions require separate, time‑boxed admin accounts elevated via PIM with just‑in‑time approval and full audit trails. All configuration changes, exceptional access and support interventions follow workflow‑based approvals, ensuring least‑privilege access is maintained. Support channels cannot bypass governance; privileged operations are performed only by approved admin identities and all actions remain auditable and policy‑controlled.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Public key authentication (including by TLS client certificate)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Core operates a fully ISO 27001‑certified Information Security Management System (ISMS), supported by formal policies covering confidentiality, integrity, availability, access control, incident management, risk assessment, business continuity and supplier management. All employees receive mandatory security awareness training, with additional specialist training for staff in sensitive roles. Security responsibilities are defined in job descriptions and contracts, and policy breaches are managed under our disciplinary process.
The ISMS is overseen by a dedicated Information Security Steering Group chaired by the COO and supported by the CISO, IT Manager and senior risk specialists. Policies are reviewed at least annually and continuously improved through internal audits, external ISO 27001 surveillance audits, risk assessments and automated compliance monitoring. Staff are required to report security incidents or weaknesses immediately via documented procedures. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Core operates ITIL‑aligned configuration and change management processes, benchmarked at CMM Level 3–4. Configuration items are tracked throughout their lifecycle using customer CMDBs, Intune, Azure and ITSM tooling, ensuring accurate, continually updated records. All changes follow a formal ITIL process, including risk and security assessment, CAB review, client approval, and full auditability. Security impact is evaluated using Microsoft native tooling (Defender, Secure Score) to ensure no adverse effect on identity, access or service integrity. All changes are documented, traceable, and aligned with customer governance.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Core operates a proactive, ITIL‑aligned vulnerability management process. Threats are continuously assessed using Microsoft Defender, Secure Score, Azure Security Centre, Sentinel SIEM and weekly Nessus scans to identify vulnerabilities and misconfigurations. We deploy critical and security patches within 14 days in line with NCSC guidance, with accelerated deployment for zero‑day threats using automated Endpoint Manager and Azure Update Management workflows. Threat intelligence is sourced from Microsoft’s security ecosystem, Tenable CVE feeds, NCSC advisories and SIEM‑driven correlation, ensuring rapid awareness and remediation of emerging risks.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- Core delivers continuous protective monitoring using Microsoft Sentinel SIEM, Defender for Endpoint/Servers, and Azure Defender to identify potential compromises through behavioural analytics, real‑time alerting, threat intelligence and proactive threat hunting. When a potential compromise is detected, alerts are triaged by our security operations processes, with automated containment actions (e.g. isolating devices, disabling accounts) and escalation to our engineers. Incident response follows predefined playbooks and documented communication paths. Core provides rapid response, with 24/7 monitoring and immediate triage, and P1 security incidents responded to within minutes via Sentinel‑driven alerting.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Core operates ITIL‑aligned incident management with predefined processes for common events, including a full Major Incident Management (MIM) workflow covering P1 and P2 incidents. Users report incidents via phone, email, or the self‑service portal, or incidents may be auto‑raised through monitoring. When an incident is logged, it is triaged, prioritised, and assigned, with automated notifications and, for P1s, initiation of a live bridging call and stakeholder communications. Response times follow strict SLAs, including 30‑minute response for P1 incidents. We issue formal incident reports for all major incidents.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Conforms to a recognised standard, but self-assessed
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- British Assessment Bureau (part of the Amtivo Group)
- ISO/IEC 27001 accreditation date
- Thursday 27 February 2025
- What the ISO/IEC 27001 doesn’t cover
- Nothing
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- Ad9ffc7a-28e4-460b-bccb-fc914b3420df
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 13867168-d605-4ed3-9481-13e21f4ae9bc
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
- Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
-
Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero
Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.
- Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Understanding of the issues affecting the development of new skills by target cohort
- Understanding of issues relating to entering the contract workforce
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
-