Power Platform and Microsoft Dynamics 365 for Student Records System
The ANS Power Platform and Dynamics 365 Implementation Service for Student Records is one that enables organisations to deliver digital transformation across the organisation enabling them to reinvent how they do business and serve students, customers, stakeholders, and staff by creating and capturing new interactions amongst people, data and processes.
Features
- Student Lifecycle Management and Student Record Information
- Student Recruitment, Admissions, Enrolment and Event Management
- Curriculum Management and Extra Curricular Activities
- Student Welfare, Student Engagement and Student Retention
- Teaching and Learning
- Adult Education and Alumni Management
- Fundraising and Research
- Out-of-the-box integration with other Microsoft technologies
- Built in security, compliance and governance
- End-to-end business process and workflow automation
Benefits
- Digital marketing and event automation providing hyper personalised student experience
- Consolidated 360 view of the applicant to student lifecycle
- Full lifecycle management and visibility from enquiry through to graduation
- Maximise domestic and student conversion through dedicated portals, multi channel
- Financial savings from consolidating systems/moving legacy infrastructure to cloud
- Improved quality and consistency of communications
- Financial savings from consolidating systems/moving legacy infrastructure to cloud
- Improve overall operational and administrative efficiency
- Deliver proactive reporting/trend analysis to maximise improved service provision
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
5 5 3 0 7 2 5 1 0 4 0 2 4 0 9
Contact
ANS GROUP LIMITED
Steve Carroll
Telephone: +44 (0) 1612271000
Email: tenders@ansgroup.co.uk
About your service
- Service categories
-
Application Development and Deployment
Application platforms
Deployment centric application platforms
- Application Server Software Platforms
- Cloud Deployment-Centric Application Platforms
- Multi cloud support
- No
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Microsoft Dynamics 365 and Microsoft Azure
- Cloud deployment model
- Public cloud
- Service constraints
- Need internet access to connect to the application(s)
- System requirements
- Cloud-based so the most up-to-date web browser is needed
User support
- Email or online ticketing support
- Yes
- Support response times
-
Customers will be able to take advantage of industry leading certified engineers and experts on the end of the phone 24x7x365.The service desk is backed by ITIL aligned process and provides comprehensive Response SLAs from P1 to P5:
P1 - 30 Mins
P2 - 1 Hour
P3 - 4 Hours
P4 - 1 Day
P5 - 2 Days
All incidents are recorded in ANS’ Service Desk ITSM system under the Incident Management workflow. ANS records the name of the person reporting the incident, call time and any pertinent information, along with resolution criteria ensuring that the workflow is initiated correctly. - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes, at extra cost
- Support levels
-
Support levels, start at £18,000 per annum.
All ANS customers have access to ticket and telephone-based support, unless they choose to take an unmanaged service. Customers have access to a named Account Manager who takes overall responsibility for the customer's commercial, technical and support relationship with ANS. Customers are assigned a support "pod" based on the type of solution they have with ANS. This ensures customers will always be supported by the same core team of support engineers who are technical experts in their particular solution. Enterprise and public sector customers also have access to a named Customer Success Manager in addition to their Account Manager.
Standard support is provided 08:00 to 18:00 Monday to Friday and includes 1st line (User support) through to system management, monitoring and administration. Support levels are in line with customer Azure Consumed Revenue. Additional support is available to extend the service support to 24/7 at additional cost. - Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
At ANS, we believe that helping our clients prepare for, implement and manage organisational change is paramount if they are to achieve long-term success. ANS are highly focused on helping customers to achieve full user adoption and our implementation methodology has been proven to create an environment that makes success much more likely by focusing on ongoing knowledge transfer and training.
Whilst ANS is not a training provider, there are multiple knowledge sharing opportunities throughout this engagement. - Service documentation
- Yes
- Documentation formats
-
- Other
- Other documentation formats
-
- Word
- Microsoft Excel
- Microsoft PowerPoint
- End-of-contract data extraction
- Should the contract end for any reason, ANS will need to assess what steps need to be followed to ensure data is extracted efficiently.
- End-of-contract process
- This scenario will need to be discussed on a case by case basis. Access to the support service will end when the contract does. The deployment of Dynamics 365 will be as per the agreed deliverables, scope and costs of the project.
- Documentation accessibility standard
- WCAG 2.2 AA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
-
Microsoft provide a mobile application for iOS (10+), Android (4.4+) and Windows (10+) which can be configured to provide access to records within D365.
Alternatively, The unified interface in Dynamics 365 ensures that if you chose to access the application via a web browser on a mobile, desktop or tablet, the experience of using and navigating 365 will be the same. - Service interface
- Yes
- User support accessibility
- EN 301 549
- Description of service interface
-
Microsoft provide a mobile application for iOS (10+), Android (4.4+) and Windows (10+) which can be configured to provide access to records within D365.
Alternatively, The unified interface in Dynamics 365 ensures that if you chose to access the application via a web browser on a mobile, desktop or tablet, the experience of using and navigating 365 will be the same. - Accessibility standards
- EN 301 549
- Accessibility testing
- Though we do not conduct any formal testing with assistive technology users, we have selected both Teams and Slack due to the variety of communication methods that are integrated – text chat, voice and video.
- API
- Yes
- What users can and can't do using the API
- This can be controlled and configured by ANS.
- API documentation
- Yes
- API documentation formats
-
- Other
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Dynamics 365 can be fully configured to suit the customer's specific requirements. As part of our implementation process, ANS will teach your core team how to manage and configure the solution moving forward.
Scaling
- Independence of resources
- Dynamics 365 is hosted by Microsoft. This service includes platform monitoring, allowing you to see in real-time if there are any performance issues.
Analytics
- Service usage metrics
- Yes
- Metrics types
-
Active users
Mode of access
Entity usage
System Jobs
Plug Ins
API Calls
Mailbox Usage
Any custom metrics required - Reporting types
-
- Real-time dashboards
- Regular reports
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Microsoft
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Security Clearance (SC)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Managed by a third party
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- Another external penetration testing organisation
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Deleted data can’t be directly accessed / Cryptographic Erasure
Data importing and exporting
- Data export approach
- Using standard out-of-the box export functionality within Dynamics 365
- Data export formats
- Other
- Other data export formats
-
- XML
- XLSX
- Data import formats
-
- CSV
- Other
- Other data import formats
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
- Microsoft maintain service availability. The admin centre allows you to see any potential downtime or issues that may have caused the system issues for any given reason.
- Approach to resilience
- Multiple data centres within each Azure region creating local availability zones
- Outage reporting
- Dynamics 365 gives you access to the admin centre where users can monitor the availability of applications in real-time.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Other user authentication
- Azure based authentication and authorisation
- Access restrictions in management interfaces and support channels
-
ANS ensure that users assigned to the project can access the system for the duration needed.
The support team will only be able to access the system agreed within the support contract, as and when it's needed - Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Other
- Description of management access authentication
- Azure based authentication and authorisation.
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- ANS also complies with ISO 27017, ISO 27018, ISO 22301, ISO 20000, ISO 9001, ISO 14001, PCI DSS Level 1, PAS 2060, Type 2 SOC 2, Cyber Essentials and Cyber Essentials Plus.
- Information security policies and processes
- Information security policies/ processes are managed by our experienced Head of Information Security and in-house Compliance Team. ANS follows a comprehensive Information Security Management System (ISMS) aligned to internationally recognised standards, ensuring the confidentiality, integrity, and availability of all information assets. Our core Information Security Policies apply across all ANS-operated environments are underpinned by ISO 27001, ISO 9001, Cyber Essentials Plus, PCI DSS, SOC 2, and NCSC-aligned controls. These frameworks guide how risks are identified, assessed, and treated across departments through structured risk management plans. Our policies mandate secure handling of all data processed by ANS, supported by continuous training for staff and relevant third parties. Security governance is maintained through a dedicated Security Working Group led by the Head of Information Security & Compliance, ensuring ongoing effectiveness and continuous improvement of the ISMS. Technical controls include AES 256 encryption, BitLocker encrypted laptops, per file encryption in OneDrive, TLS-secured email, and anti spoofing technologies such as SPF, DKIM and DMARC. We operate IDS/IPS, AV, DDoS protection, and prohibit removable media by policy. ANS also ensures supplier due diligence, requiring third-party adherence to security, data protection, and sustainability standards. Collectively, these measures ensure robust, auditable, and continually improving information security governance.
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- ANS operates a structured configuration and change management process. Configuration management maintains a controlled, accurate model of all customer configuration items (CIs) within the CMDB, ensuring traceability, compliance, and efficient impact analysis. ANS identifies, records, verifies and updates CIs through defined naming conventions, status tracking, and CSOC oversight. Change management requires all changes to be submitted via an RFC through the ANS Glass portal, evaluated by engineers, risk‑assessed, approved by SMEs/CAB, and implemented in line with the Managed Services Handbook. Emergency changes are only executed for P1 or major security incidents.
- Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
-
ANS monitor threat sources, including CERT to gain information about potential threats. Vulnerabilities and Remediation activities are assessed to determine the priority, with patches being applied within the hour for critical security issues through to monthly patching for routine updates.
Though these are developed in line with ISO27001 and Cyber Essentials, the vulnerability management approach is dictated by the specific requirements of the Service and customer requirements. - Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- ANS has implemented an Information Security Management System (ISMS), complaint and certified with ISO 27001. This system is supported by the ISMS manual, detailed policies and procedures, and underpinned by the pragmatic application of industry best practice. We assess potential compromises to services via IDS/ IPS, DDoS, AV, FIM - all in place and monitored 24/7. We obtain information regarding potential threats from NCSC and via our vendor partner status. We deploy patches to services - within 7 days for criticals, 14 for high and 30 days for mediums.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- ANS uses defined Problem Management, Standard Changes, automation, runbooks, and knowledge articles to ensure consistent, repeatable handling of common events and to prevent recurrence through root cause identification and controlled process execution. Users report non‑priority incidents through the GLASS portal provided at onboarding. Priority incidents require telephone contact with the ANS Support Desk to ensure immediate triage and rapid engagement of appropriate technical resources. ANS issues formal reports for P1 incidents within 10 working days, detailing root cause and actions. Non‑priority incidents do not receive reports, but full incident information remains accessible via the GLASS portal.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 2.5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 10%
- Between £2,500,001 and £5,000,000
- 10%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LRQA
- ISO/IEC 27001 accreditation date
- Tuesday 24 June 2025
- What the ISO/IEC 27001 doesn’t cover
- N/A - Full scope
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- LRQA
- ISO 9001 accreditation date
- Tuesday 24 June 2025
- What the ISO 9001 doesn’t cover
- N/A - Full Scope
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- Yes
- Who accredited the PCI DSS certification
- PCI Security Standards Council
- PCI DSS accreditation date
- Friday 8 August 2025
- What the PCI DSS doesn’t cover
-
No cardholder data in scope.
No insecure services, protocols, or daemons.
No wireless networks in scope.
ANS does not have access to any cardholder data.
ANS does not have access to any cardholder data.
All in-scope servers have Windows
Defender AV solution installed.
All removable media is disabled by default
No bespoke and custom software development
The only bespoke solution is TechDB
No public-facing web applications in scope.
No pre-production environment
No system development
No application and system accounts in scope.
No user access to query repositories of stored cardholder data.
No remote access to customer premises
No cardholder data or customer access in scope.
MFA system is not susceptible to replay attacks
No application and system accounts that can be used interactively.
No media with cardholder data.
No hard-copy materials with cardholder data.
No POI devices that capture payment card data in scope.
No CHD in scope.
ANS is not a multi-tenant provider.
No payment pages in scope.
No cryptographic suites or protocols in scope.
There are no TPSPs in scope.
There is no cardholder data in scope. - Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- C0b25fab-fa90-4e67-a2eb-851d67f11fd9
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 9f752e61-ca81-49da-a1d0-5b982f14ce38
- Other security certifications
- Yes
- Any other security certifications
-
- ISO27018: 2019
- ISO42001 - AI
- ISO27017: 2015
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Plans to engage the contract workforce in deciding the most important workplace issues to address
- Monitoring of employee engagement rates (by protected characteristic) and, where necessary, the development of actions to ensure all voices are heard across the diversity of the workforce
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Support for the contract workforce by providing career advice, and providing opportunities for staff working on the contract with in-work progression career development into known skills shortages or high growth areas
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Volunteering opportunities for staff
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.
- Advertising, promotional and outreach activities designed to raise awareness of the offer to reach the target cohort
-
Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.
Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.
- Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce
- Actions to invest in the physical and mental health and wellbeing of the contract workforce
-