ALIRA - Unified Entra Identity and Access Management Portal
Kocho’s Alira Access Portal is a cloud-native, end-user-centric SaaS solution built to augment Microsoft Entra ID. It centralises and standardises all application access into one interface and experience, enabling self-service requests, automated approvals, real-time access reporting, and licence management to improve security, compliance, and operational efficiency.
Features
- Unified portal integrates with Microsoft Entra for access management.
- Self-service access requests reduce reliance on IT helpdesk tickets.
- Automated approvals and JML workflows manage user lifecycle efficiently.
- Licence tools assign, monitor, and reclaim software licences easily.
- Real-time reporting and audits support governance and compliance needs.
- Centralised view of user access entitlements in one interface.
- Supports Entra Access Packages and PIM for privileged access.
- Manages Azure, AWS, GCP admin roles in one platform.
- Fully customisable interface with corporate branding and colour options.
- Enforces Entra SSO and conditional access for secure authentication.
Benefits
- Reduces helpdesk workload by automating access and provisioning tasks.
- Speeds up onboarding with instant access to required resources.
- Improves productivity by reducing delays in application access.
- Minimises shadow IT by centralising approved application access.
- Strengthens compliance through consistent access policy enforcement.
- Cuts licence waste by reclaiming unused or misallocated licences.
- Frees IT staff for strategic, high-value business initiatives.
- Enhances user satisfaction with fast, self-service access tools.
- Increases Entra ROI by improving adoption and reducing overhead.
- Delivers audit trails for transparency and regulatory compliance reporting.
Pricing
- Education pricing available
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
6 2 3 3 1 4 3 3 6 5 0 8 6 9 2
Contact
KOCHO GROUP LIMITED
Steve Marshall
Telephone: 07967388226
Email: G-Cloud@kocho.co.uk
About your service
- Service categories
-
Applications
Content workflow and management
Enterprise portals and digital workspaces
- Multi-Audience Portals
- Integrated Employee Workspaces
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes
- What software services is the service an extension to
- Entra IdAM
- Cloud deployment model
-
- Public cloud
- Private cloud
- Service constraints
- Works with Entra ID / M365 Only
- System requirements
- Definied organisational units in Entra
User support
- Email or online ticketing support
- Yes
- Support response times
- 24/7
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- None or don’t know
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- Yes
- Web chat support availability
- 24 hours, 7 days a week
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- N/A
- Web chat accessibility testing
- N/A
- Onsite support
- Yes, at extra cost
- Support levels
- P1 - Response up to 4 hours, Resolution within 4 hours P2- Response up to 6 hours, Resolution within 1-day P3 - Response up to 24 hours, Resolution within 3-days P4 - Resolution within 5-days Technical Account Manager will be appointed
- Support available to third parties
- Yes
- AI chatbot
- Yes
Onboarding and offboarding
- Getting started
- Kocho would implement the solution and provide training, support for IT, and provide user documentation.
- Service documentation
- Yes
- Documentation formats
- End-of-contract data extraction
- Kocho will work with organisation to either export data or agree on deletion.
- End-of-contract process
- Login privileges will be removed and Kocho will provide guidance on how to clean up their Entra tenant.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
- Online and via email
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Opera
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- None
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- Yes
- What users can and can't do using the API
- The API enables the same functionality to be actioned within Entra ID
- API documentation
- Yes
- API documentation formats
- API sandbox or test environment
- Yes
- Customisation available
- Yes
- Description of customisation
- Customise the branding and UI Choose what users can see/access Toogle settings for app behaviour
Scaling
- Independence of resources
- Autoscaling and brut force protection via Microsoft Azure service
Analytics
- Service usage metrics
- Yes
- Metrics types
- Uptime availability
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- Yes
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CREST-approved service provider
- Protecting data at rest
- Other
- Other data at rest protection approach
- Encryption
- Data sanitisation process
- No
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
Data importing and exporting
- Data export approach
- N/A
- Data export formats
-
- CSV
- ODF
- Data import formats
-
- CSV
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- TLS (version 1.2 or above)
- Other
- Other protection between networks
- Country Geofencing
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- Other
- Other protection within supplier network
- Data encryption at rest and in-transit. Azure Secret Manager
Availability and resilience
- Guaranteed availability
- 99.9%
- Approach to resilience
- Containerisation with autoscaling and microservices architecture.
- Outage reporting
- Email alerts
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Access restrictions in management interfaces and support channels
- Role Based Access
- Access restriction testing frequency
- At least every 6 months
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
Audit information for users
- Access to user activity audit information
- Users have access to real-time audit information
- How long user audit data is stored for
- User-defined
- Access to supplier activity audit information
- Users have access to real-time audit information
- How long supplier audit data is stored for
- User-defined
- How long system logs are stored for
- User-defined
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- ISO/IEC 27001
- Other
- Other security governance standards
- Cyber Essentials Plus
- Information security policies and processes
- ISO27001 and Cyber Essentials Plus
- Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Assessed and managed via Azure DevOps
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Managed via Microsoft Defender and Sentinel. In-house SOC team to identity and resolve vulnerabilities
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
- In-house SOC team, using Defender and Sentinel
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- Ervice Desk with pre-agreed SLAs and reporting processes. Can be bespoke and 24/7/365.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- Yes
- Description of free trial
- Provided for a defined subset of users. Please contact us for additional information.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 2.5%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 7.5%
- Over £5,000,001
- 10%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- BSI
- ISO/IEC 27001 accreditation date
- Thursday 25 May 2023
- What the ISO/IEC 27001 doesn’t cover
- Our certification covers all areas as detailed in the associated Statement of Applicability.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- British Assessment Bureau
- ISO 9001 accreditation date
- Tuesday 30 September 2025
- What the ISO 9001 doesn’t cover
- The scope does not include the professional services teams as it concerns a QMS for the SOC team, the managed service desk and the service delivery managers.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- C3418dff-f6ac-411c-84ab-a2a4d176f33a
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- E4bcca11-f5b6-41e3-82ca-05b84e497db4
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.
- Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
- Support for educational attainment relevant to the contract, including training schemes that address skills gaps and result in recognised qualifications
- Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
- Delivery of apprenticeships, supported internships and T Level industry placement opportunities (Level 2, 3 and 4+) in relation to the contract
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
- Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
- Inclusive and accessible development practices, including guidance for line managers on recruiting, managing and developing people with a disability or health condition
-