Telefónica Tech Microsoft Dynamics 365 Customer Engagement Implementation
Telefónica Tech provides a Customer Relationship Management (CRM) service based on Microsoft Dynamics 365 Customer Engagement to support organisations in managing and improving customer, citizen and member interactions across sales, marketing, customer service and field service functions.
Features
- Microsoft Dynamics365 for Customer Engagement - full CRM platform.
- Pick from CRM modules to create a CRM solution.
- Dynamics365 Sales for classic CRM citizen management.
- Microsoft Dynamics365 Customer Service for case management
- Microsoft Dynamics365 Field Service for mobile workforces.
- Dynamics365 Marketing for lead generation, event s and business development
- Upgrade Dynamics CRM to cloud-based Dynamics365 Customer Engagement.
- Dynamics365 offers role-based CRM capability.
- Single Microsoft CRM platform for all areas of your business.
Benefits
- Provides a 360-degree view of your customer.
- Maintain GDPR compliant contact details for members, suppliers and citizens.
- Run branded, professional marketing campaigns and events.
- Bring your old CRM data into your cloud CRM platform.
- Comprehensive suite of tools for all your customer-facing interactions.
- Real-time access to data through your CRM.
- Available in the Microsoft Cloud and accessible on any device
- Dynamics 365 offers modular licensing for scale-ability of cost.
- A CRM that supports multi-currency transactions.
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
7 2 6 2 9 0 1 2 7 4 3 9 5 0 3
Contact
TELEFÓNICA TECH NORTHERN IRELAND LIMITED
Andrew Knight
Telephone: 028 90454433
Email: Bid.Management@telefonicatech.uk
About your service
- Service categories
-
Application Development and Deployment
Application platforms
- Model driven application platforms
- Multi cloud support
- Yes
Service scope
- Software add-on or extension
- Yes, but can also be used as a standalone service
- What software services is the service an extension to
- Various, including ISVs
- Cloud deployment model
-
- Public cloud
- Private cloud
- Hybrid cloud
- Service constraints
- None
- System requirements
- Licenses
User support
- Email or online ticketing support
- Yes
- Support response times
- Response times dependent on priority level of issue logged and whether via telephone or email.
- User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AAA
- Phone support
- Yes
- Phone support availability
- 24 hours, 7 days a week
- Web chat support
- No
- Onsite support
- Yes
- Support levels
- Support Desk: The Service Desk acts as the single point of contact for all end users, offering support via the Customer Portal, phone, and email. The Service Desk is staffed by highly skilled personnel and retains full lifecycle ownership of all incidents, problems, and changes recorded in the IT Service Management tool. Standard hours of operation are 8am-6pm Mon-Fri (excluding UK Bank Holidays), with 24x7x365 cover for Priority 1 incidents.
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
-
Telefonica Tech will manage the onboarding of services on behalf of the customer.
After receiving a sales order from the customer, a welcome pack, service guide, and provisioning worksheet will be sent. These documents introduce the service and begin the collection of information needed to configure the service.
On termination of the service, Telefonica Tech Transition Management will co-ordinate the offboarding of the service, which will constitute of the following activities at a minimum:
•Provide final billing and reporting to customer.
•Removal of customer IP address space from the platform.
•Request to remove all Telefonica Tech and customer accounts within the platform
•Delete any sensitive customer information and all contact information held that is no longer required.
•Disable service and/or customer within ITSM systems and disable any customer accounts no longer required. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
Upon receiving notification of termination, if data extract has been requested - Telefónica Tech can first provide a raw export of logs (where appropriate).
Telefónica Tech will on a mutually agreed date, simply delete the customer’s data securely from the security platform and disable the customer’s access. - End-of-contract process
-
On termination of the service, Telefonica Tech Transition Management will co-ordinate the offboarding of the service, which will constitute of the following activities at a minimum:
•Provide final billing and reporting to customer.
•Request to remove all Telefonica Tech and customer accounts within the platform
•Removal of customer IP address space from the platform.
•Delete any sensitive customer information and all contact information held that is no longer required.
•Disable service and/or customer within ITSM systems and disable any customer accounts no longer required. - Documentation accessibility standard
- WCAG 2.2 AAA
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Chrome
- Application to install
- Yes
- Compatible operating systems
-
- Android
- IOS
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- None
- Service interface
- Yes
- User support accessibility
- WCAG 2.2 AAA
- Description of service interface
- Portal
- Accessibility standards
- WCAG 2.2 AAA
- Accessibility testing
- Any
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- Telefónica Tech platform services are built upon a multi tenant design and strictly capacity planned to ensure sufficient performance and capacity is always available to the services.
Analytics
- Service usage metrics
- Yes
- Metrics types
- The service provides a range of usage, performance, and operational metrics to support service management and continuous improvement. Metrics include user activity and adoption, workflow and case volumes, processing and turnaround times, system availability, and performance trends. Dashboards provide visibility of key metrics in near real time, with regular and ad hoc reports available as required. Where applicable, analytics are used to identify trends, exceptions, and areas for optimisation. These metrics enable customers to monitor service performance, understand how the service is being used, and support reporting, planning, and ongoing improvement activities.
- Reporting types
-
- Real-time dashboards
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra features and support
- Organisation whose services are being resold
- Microsoft
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Developed Vetting (DV)
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
- United Kingdom
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least every 6 months
- Penetration testing approach
- ‘IT Health Check’ performed by a CHECK service provider
- Protecting data at rest
-
- Physical access control, complying with CSA CCM v4.0
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Data Erasure
- Physical Destruction / Hardware containing data is completely destroyed
Data importing and exporting
- Data export approach
-
Upon receiving notification of termination, if data extract has been requested - Telefónica Tech can first provide a raw export of logs (where appropriate).
Telefónica Tech will on a mutually agreed date, simply delete the customer’s data securely from the security platform and disable the customer’s access. - Data export formats
-
- CSV
- ODF
- Data import formats
-
- CSV
- ODF
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Legacy SSL and TLS (under version 1.2)
Availability and resilience
- Guaranteed availability
-
Telefónica Tech has SLA’s and Penalties (service credits) as standard offerings for each of our managed services.
Dependent on the provided service, services shall be deemed available when the customer is able to access and use the services hosted or provided by Telefónica Tech. This may include periods where the customer is unable to access applications and services, where it is demonstrated by Telefónica Tech to the customer’s satisfaction, or where any inability to access the customer’s applications and services is the result of permitted downtime.
Any reduced charges under this Service Level Agreement will be confirmed by credit note issued by Telefónica Tech to our customers, confirming any adjustment to be made to the following monthly charge.
99.95% availability is guaranteed. - Approach to resilience
-
The Telefónica Tech datacentres and the services provided from within have been architected in meticulous detail from the ground up, built upon enterprise class best of breed hardware and technology, ensuring services are provided from a fully resilient infrastructure of at least N+1 with no single points of failure, across geographically-diverse Tier 3+ datacentres.
From the power feeds from separate power grids, multiple generators and UPS's all tested weekly, to the fire suppression systems, resilient networking and WAN links, storage and compute clusters, all aspects have been carefully considered using best of breed technology with no single points of failure. - Outage reporting
-
Telefónica Tech follow our Corrective action of Events & Incidents policy, which is in scope of our ISO27001, ISO9001, ISO20000, ISO27018 and ISO22301 certifications, following standard ITIL conformant Major Incident Management processes.
This includes informing stakeholders immediately without delay.
Identity and authentication
- User authentication needed
- Yes
- User authentication
- Multi-Factor Authentication (MFA)
- Access restrictions in management interfaces and support channels
- Access to management interfaces and support channels is strictly controlled using role-based access controls and the principle of least privilege. User access is authenticated using Multi-Factor Authentication, with integration to Microsoft identity services where applicable. Administrative access is limited to authorised personnel and is logged and monitored. Support access is restricted to named users and granted only where required to deliver support activities. All access to management interfaces and support systems is auditable, with actions recorded and retained in line with service policies to support monitoring, investigation, and compliance requirements.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
-
- CSA CSM version 4.0
- ISO/IEC 27001
- Information security policies and processes
-
A full-time compliance team is employed to manage and maintain our certifications and accreditations. Staff are fully trained and competent to work within our management systems, which are mature and continually improved, as proven in regular internal and external audits.
An overview of the diverse set of the externally assessed ISO standards and best practice accreditations Telefónica Tech adheres to are as follows:
ISO27001 (Information Security)
ISO22301 (Business Continuity Management System)
ISO20000 (ITIL Service Management)
ISO9001 (Quality)
ISO27018 Code of Practise (Protection of Personally Identifiable Information in the Cloud)
Government OFFICIAL Classification Supplier
Approved G Cloud Supplier
Approved Commercial N3 Aggregator transitioning to a HSCN Supplier
Health & Social Care Network (HSCN) Compliant
Cyber Essentials Certificate of Assurance
IASME Information Security Standard Certificate of Assurance - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Configuration and change management approach
- Our methodology minimises the impact of change-related incidents on service quality and improves the day-to-day operations of the organisation. The procedures are designed to ensure that all changes are correctly planned, interested parties are notified and any service interruption is controlled. Changes can be initiated by the client or internally within Telefónica Tech. A robust Change Control process minimises the risk associated with changes. It enables all parties to keep track of changes made to systems, ensures implications of changes are assessed and that interdependencies are explored. A back-out process is also considered before any change is implemented.
- Vulnerability management type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Vulnerability management approach
- Annual IT Health Checks are completed by a CHECK accredited independent organisation under the CHECK Scheme. The CHECK scheme enables penetration testing by CESG approved companies, employing penetration testing personnel, qualified to assess HMG and other public and private sector bodies. The testing personnel are CHECK Team Leaders who have proven their technical competency through lab examinations and written exams, they are skilled in application and infrastructure testing. They have also undergone thorough background checking. This technical compliance review is an extensive internal and external examination of operational systems to ensure that hardware and software controls have been correctly implemented.
- Protective monitoring type
- Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
- Protective monitoring approach
-
This is achieved through continuous monitoring of events and logs, advanced SIEM platforms and expert teams. Proactive threat detection and continuous risk assessment are carried out using xDR platforms and proprietary developments, with security event monitoring extended across all environments (on-premise/cloud).
When a potential compromise is found, the SOC team performs initial triage and analysis, followed by alerting and response, incident management, root cause analysis, and remediation escalation as required.
Incident response times are structured by alert severity, starting from 5=minutes for P1/P2 (high-severity) incidents. Level-1 analysts verify alerts and escalate, ensuring prompt and effective action for critical events. - Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
- The Telefónica Tech Service Desk enables our team to co-ordinate the work of restoring supported systems as soon as possible and within agreed SLAs. The Service Desk determines the nature of incidents so they can be sent to appropriately skilled engineers for resolution. An IMS is incorporated within the Service Desk. When logging calls via the telephone Service Desk, the call operative uses the same call logging software that the customer will have access to via our secure web portal. Integrated with this functionality is our knowledge base, which is used to capture information and provide accurate incident reports.
- Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- Yes
- Connected networks
-
- Public Services Network (PSN)
- Police National Network (PNN)
- Health and Social Care Network (HSCN)
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- A free trial can be provided for applicable Microsoft Dynamics 365 Customer Engagement and Power Platform services, subject to Microsoft licensing terms. The trial provides access to the software within the customer’s own tenant for evaluation purposes. Microsoft Dynamics365 Finance & Supply Chain Management is excluded from the free trial.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 0%
- Between £250,000 and £500,000
- 0%
- Between £500,001 and £1,000,000
- 0%
- Between £1,000,001 and £2,500,000
- 0%
- Between £2,500,001 and £5,000,000
- 0%
- Over £5,000,001
- 0%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- LRQA
- ISO/IEC 27001 accreditation date
- Wednesday 20 August 2025
- What the ISO/IEC 27001 doesn’t cover
- N/a - The scope includes provision of digital solutions in five key areas: Cloud, Data & AI, Business Applications, Digital Workplace and Cyber Security, within Europe and India.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- Yes
- Who accredited the ISO 9001 certification
- LRQA
- ISO 9001 accreditation date
- Tuesday 16 September 2025
- What the ISO 9001 doesn’t cover
- N/a - The scope includes the Provision of IT Managed Services, Cyber Security, Cloud Services, Professional Services and Business Applications as detailed within our Service Catalogue and Supply and Warehousing for IT Products.
- Quality management systems (QMS)
- Yes
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- D51C6CFF-E4BF-41FF-9FA5-C8CDCBDA64E3
- Cyber essentials plus
- Yes
- Please provide your Cyber Essentials Plus Certificate Number
- 55D3458E-A2EF-47BD-8518-71E8AD19FDEF
- Other security certifications
- Yes
- Any other security certifications
-
- ICO Data Protection
- HSCN
- ISO22301
- ISO2000-1
- ISO14001
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- New apprenticeships on the contract workforce in the relevant area that meet the criteria set out in MAC 1b
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
- Activities that support an environment where staff are educated about, and feel empowered to, address their physical wellbeing
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
- Understanding of in-work progression issues affecting the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
- Volunteering opportunities for staff
- Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
- Measures to identify, mitigate and manage modern slavery risks relating to the contract and how these will be implemented
-