Microsoft 365 Backup Service
OGEL IT provides the licensing and software to enable buyers to secure and backup their business assets leveraging the power of Datto Cloud Continuity, SaaS Protection and Datto Workplace.
Features
- Cloud PC Backup & Recovery
- Cloud Server Backup & Recovery
- SaaS Content Backup & Recovery
Benefits
- Extend native Cloud backup functionality
- Enhance Business Continuity Plans
- Data storage in purpose built Data Centre
- Support for multiple workloads
Pricing
- Education pricing available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
8 6 7 3 9 6 4 2 2 9 1 5 9 3 0
Contact
OGEL IT LTD
Sam Newman
Telephone: 01438 300335
Email: gcloud@ogelit.com
About your service
- Service categories
-
Applications
Collaborative
- Enterprise community
- Team collaboration
Conferencing and virtual event
- Web Conferencing Applications
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Private cloud
- Service constraints
- Backup services support Microsoft Azure/Office 365 and Google Suite. Some workload backups are not available or functionality restricted, these are limitations determined by the vendor of the system being backed up.
- System requirements
-
- Microsoft 365 / Azure Entra ID
- Google suite
User support
- Email or online ticketing support
- Yes
- Support response times
-
P1 - 30 mins
P2 - 1 hour
P3 - 4 hours
P4 - 1 day - User can manage status and priority of support tickets
- Yes
- Online ticketing support accessibility
- WCAG 2.2 AA
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), 7 days a week
- Web chat support
- No
- Onsite support
- No
- Support levels
- Support for system administrators within the Buyer environment or to business managing backups on their behalf. M-F, 8am - 6pm, excl. UK public holidays, P1 - 30 minutes, P2 - 1 hour, P3 - 4 hours, P4 - 1 day
- Support available to third parties
- Yes
Onboarding and offboarding
- Getting started
- Administrative permissions are required within the environment being backed up to establish the required connectivity and permissions to enabled backups to execute.
- Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
- Data can be exported by the buyer to PST or ZIP depending on the content type.
- End-of-contract process
- Data will be retained for a min of 30 days, maximum of 90 days after which it will be permanently deleted. https://saasprotection.datto.com/help/M365/Content/Troubleshooting/General/KB410000010019.htm
- Documentation accessibility standard
- EN 301 549
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Application to install
- No
- Designed for use on mobile devices
- No
- Service interface
- No
- User support accessibility
- None or don’t know
- API
- No
- Customisation available
- No
Scaling
- Independence of resources
- Our data centres are monitored 24/7 to ensure appropriate capacity is available to meet the ongoing demands. Additional hardware is provisioned as required,
Analytics
- Service usage metrics
- Yes
- Metrics types
- Data backup status, data stored is all provided via the web interface and can be configured to email automatically on a schedule.
- Reporting types
-
- Regular reports
- Reports on request
- Resource tagging
- No
- FOCUS resource tagging
- No
Resellers
- Supplier type
- Reseller providing extra support
- Organisation whose services are being resold
- Datto, NinjaOne
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- Other locations
- User control over data storage and processing locations
- Yes
- Datacentre security standards
- Supplier-defined controls
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- In-house
- Protecting data at rest
- Encryption of all physical media
- Data sanitisation process
- Yes
- Equipment disposal approach
- A third-party destruction service
- Data sanitisation type
- Data Erasure
Data importing and exporting
- Data export approach
- Data can be exported by the buyer to PST or ZIP depending on the content type. https://saasprotection.datto.com/help/M365/Content/Recovering_and_restoring_files/03_Recovering_and_restoring_data.htm
- Data export formats
- Other
- Other data export formats
-
- PST
- ZIP
- Data import formats
- Other
- Other data import formats
-
- PST
- ZIP
Data-in-transit protection
- Data protection between buyer and supplier networks
-
- Private network or public sector network
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
- Data protection within supplier network
-
- TLS (version 1.2 or above)
- IPsec or TLS VPN gateway
Availability and resilience
- Guaranteed availability
- The Datto SaaS Protection services are subject to a uptime of 99.9%.
- Approach to resilience
-
Datto SaaS protection provides 5 copies distributed across different systems and sites to ensure resilience.
At every step along our data-replication process, Datto SaaS Protection uses 256-bit encryption. In particular:
All authenticated user interaction with the Datto SaaS Protection application
Logging in
Configuring services
Altering settings
Accessing archived data
Datto SaaS Protection encrypts your duplicate archives. Each worker node in our system possesses a unique AES 256-bit encryption key assigned to that node. All data written for the user is encrypted using that key at the time of storage, and decrypted on demand when the data is retrieved. The keys are managed by LUKS, with passwords distributed on a strict need-to-know basis. Data in transit is encrypted similarly, using industry-standard SSL communication. - Outage reporting
- Outages are communicated to registered user via email
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
- Interfaces are restricted to certain regions.
- Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
- Datto grants access to stored data internally using the “principle of least privilege through appropriate roles and only on a “need-to-know” basis and manages its systems in line with security industry best practices, including the ISO 27000 series and NIST Security Publications.
- Software Security Code of Practice
- No
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
- Kaseya / Datto complete configuration and change management process to ensure changes are appropriately assessed from a security and operational perspective prior to implementation.
- Vulnerability management type
- Undisclosed
- Vulnerability management approach
- Regular vulnerability assessments are completed to ensure the security of Datto Services.
- Protective monitoring type
- Undisclosed
- Protective monitoring approach
- Please get in contact should you wish to understand more about our internal monitoring processes or to seek assurances.
- Incident management type
- Undisclosed
- Incident management approach
- Buyers can raised incidents with our support team via the portal or email.
- Post-quantum cryptography secure
- No
Secure development
- Approach to secure software development best practice
- Supplier-defined process
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- Yes
- Free trial available
- No
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 1%
- Between £250,000 and £500,000
- 1%
- Between £500,001 and £1,000,000
- 2%
- Between £1,000,001 and £2,500,000
- 2%
- Between £2,500,001 and £5,000,000
- 3%
- Over £5,000,001
- 3%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Peers Quality Assurance Limited
- ISO/IEC 27001 accreditation date
- Tuesday 23 April 2024
- What the ISO/IEC 27001 doesn’t cover
- The services being resold are covered by their own ISO 27001 certification.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Please provide your Cyber Essentials Certificate Number
- 15f64ae8-0b55-404e-85e1-30205266c64d
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials Plus certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials Plus certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Other security certifications
- No
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
- Activities that support an environment where staff are educated about and feel empowered to report and address bullying and harassment
- Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
- Monitoring and reporting of gender and ethnicity pay gaps and plans to address them where necessary
- Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
-