Skip to main content

Help us improve the Digital Marketplace - send your feedback

Essential Computing

ProvisionPoint Audit for Microsoft 365

Audit delivers comprehensive monitoring and auditing for Microsoft 365. It tracks user activity across SharePoint, Teams, OneDrive and Exchange with detailed logs, automatic alerts, and compliance-focused reporting. Audit helps security teams identify suspicious behaviour, demonstrate regulatory compliance such as GDPR, and maintain a secure, well-monitored digital workspace..

Features

  • Monitor activity across SharePoint, Teams, OneDrive and Exchange environments
  • Track user file access, modifications, sharing and permission change
  • Detailed audit logs with configurable retention policy settings.
  • Generate compliance reports for GDPR.
  • Send automatic alerts for suspicious activity and high-risk behaviour.
  • Analyse user activity across Microsoft 365 for security insights.
  • Support audit requirements across SharePoint, Teams, OneDrive, Exchange.
  • Demonstrate regulatory compliance with structured, exportable reports.
  • Centralise monitoring for Microsoft 365 security and compliance teams.
  • Maintain comprehensive activity history to support forensic investigations.

Benefits

  • Provide comprehensive activity monitoring across your Microsoft 365 environment.
  • Help detect suspicious activity to bolster security assurance.
  • Support regulatory compliance with detailed, exportable reporting.
  • Audit log history; flexible retention and tracking options.
  • Track file access, changes, sharing, permission updates.
  • Enable security teams to analyse user activity in depth.
  • Provide visibility across SharePoint, Teams, OneDrive and Exchange.
  • Reduce risk through better insight into user behaviour.
  • Generate compliance reports aligned to GDPR.
  • Strengthen governance with real-time auditing and alerts.

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@essential.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 5 3 3 9 6 9 7 6 9 6 1 5 2 3

Contact

Essential Computing Clare Knight
Telephone: 01275 343199
Email: info@essential.co.uk

About your service

Service categories

Applications

Enterprise resource management

  • Asset life-cycle management
Multi cloud support
No

Service scope

Software add-on or extension
Yes
What software services is the service an extension to
Microsoft 365
Cloud deployment model
Private cloud
Service constraints
No
System requirements
Microsoft 365

User support

Email or online ticketing support
Yes
Support response times
Web based support- response within one hour Monday- Friday 9am-5.30-pm UK time (UK office hours).
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
9 to 5 (UK time), Monday to Friday
Web chat support
No
Onsite support
Yes, at extra cost
Support levels
Our Support Service, which includes: email, phone and remote access support from our Bristol based offices is available Mon-Fri, 9-5.30pm . Support is provided by our trained technical support team. Installation services are carried out by our Technical Consultants, who hand over to the support and customer care team following planning, install and configuration to suit your organisations needs. Where subsequent on site support is needed this would be quoted as needed on a day rate basis. Your customer account manager will work closely with Support to help and advise following initial technical installation and setup. In addition, the vendor provides out of UK hours support via email Monday-Friday.
Support available to third parties
Yes

Onboarding and offboarding

Getting started
We take care to help plan, install, configure and support the 'go live' process through our experienced, dedicated technical consulting and support teams. Through a combination of remote and on-site services (for workshops- always best face to face), we'll support your team in getting up and running as effectively as possible. We are available to support and offer advice via Teams and on the phone or email throughout the on-boarding process, as well as for the lifecycle of the subscription.
Service documentation
Yes
Documentation formats
PDF
End-of-contract data extraction
Via the comprehensive reporting capability. ALl data is retained within the customer's tenant.
End-of-contract process
At the end of the contract, the buyer needs to advise in writing (email) of intent to not renew, within 90 days of the contract end date.

Essential support can provide support and advice for extraction of any reports or information wthin ProvisionPoint. In addition we can advise and assist with removal of the ProvisionPoint Application from your tenant.

Once the contract ends, any access to the application will cease. Any data held within ProvisionPoint will be deleted within 60 days.
Documentation accessibility standard
WCAG 2.2 A

Using the service

Web browser interface
No
Application to install
Yes
Compatible operating systems
Windows
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
Access via Teams.
Service interface
Yes
User support accessibility
None or don’t know
Description of service interface
Administrative application accessed via Teams App.
Accessibility standards
WCAG 2.2 A
Accessibility testing
None
API
Yes
What users can and can't do using the API
Importing existing workspaces
Bulk Creation
Bulk Changes
Management of the Job Queue
API documentation
Yes
API documentation formats
  • HTML
  • PDF
API sandbox or test environment
No
Customisation available
Yes
Description of customisation
ProvisionPoint can be customised to create templates and governance plans to suit each organisation's requirement.

Essential will support customers with understanding and configuring all elements of the environment to suit their needs.

Scaling

Independence of resources
The app is installed within the client's own Microsoft365 tenant.

Analytics

Service usage metrics
No

Resellers

Supplier type
Reseller providing extra features and support
Organisation whose services are being resold
Snap On Software Limited

Staff security

Staff security clearance
Conforms to BS7858:2019
Government security clearance
Baseline Personnel Security Standard (BPSS)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
United Kingdom
User control over data storage and processing locations
Yes
Datacentre security standards
Supplier-defined controls
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Scale, obfuscating techniques, or data storage sharding
Data sanitisation process
Yes
Equipment disposal approach
A third-party destruction service
Data sanitisation type
Deleted data can’t be directly accessed / Cryptographic Erasure

Data importing and exporting

Data export approach
Reports are exported to CSV files.
Data export formats
CSV
Data import formats
CSV

Data-in-transit protection

Data protection between buyer and supplier networks
TLS (version 1.2 or above)
Data protection within supplier network
TLS (version 1.2 or above)

Availability and resilience

Guaranteed availability
99.5%
Approach to resilience
Azure high availability configuration.
Outage reporting
Email alerts.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
Access restrictions in management interfaces and support channels
Role based access controls are in place.
Access restriction testing frequency
At least every 6 months
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password

Audit information for users

Access to user activity audit information
You control when users can access audit information
How long user audit data is stored for
User-defined
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
User-defined
How long system logs are stored for
Between 6 months and 12 months

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
ISO27001 certification verifies the ISMS in place to manage and govern IT security. Our network is restricted by an explicit need-to-know basis, uses least privilege, its frequently audited and monitored, and is controlled by our team. Data is stored a secured password vault secured with 2fa. All Production Network systems, networked devices, and circuits are constantly monitored and logically administered by Snap On Software staff 24 / 5. The internal framework includes: Staff education and training, company policy, regular review processes, Director ownership of policy and processes.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Supplier-defined controls
Configuration and change management approach
ProvisionPoint maintains comprehensive IT asset inventories tracking all infrastructure devices, PCs, laptops, and software throughout their lifecycle, including hostname, user/location, make, and serial number. All assets are configured to consistent security specifications.

System changes undergo formal change control with testing before production deployment. Emergency repairs require written notification and subsequent change control compliance. New system acquisitions are reviewed for security requirements, risks, default configurations, and patching alignment.

All configuration changes are logged and tracked. Default passwords and configurations are immediately changed during installation to remove publicly available standards, ensuring secure baseline configurations throughout the asset lifecycle.
Vulnerability management type
Supplier-defined controls
Vulnerability management approach
ProvisionPoint monitors vulnerability alerts from trusted sources to identify potential threats and exposures. Threat intelligence is obtained from trusted sources and analysed to provide insights into existing, new,emerging threats to our systems and applications.

Vulnerability assessments of networks and systems are conducted periodically and when changes occur. An enterprise-wide malicious code and virus protection programme is established and maintained.

All system patching and vulnerability management activities align with existing system management processes. System files are not modified until tested and approved through change control, ensuring patches are deployed systematically whilst maintaining service stability and security throughout the patching lifecycle.
Protective monitoring type
Supplier-defined controls
Protective monitoring approach
ProvisionPoint employs continuous monitoring mechanisms to identify security trends, detect anomalies. Audit trails, application logs, and operating system logs are activated and maintained according to information classification. Vulnerability alerts from trusted sources are monitored to identify potential threats.

All staff must immediately report suspected security incidents, breaches, or anomalies. Upon receipt, incidents are assessed and categorised with responses prioritised by criticality. Management coordinates investigation and remediation, using internal expertise and external specialists when required.

For PI data breaches, the ICO are notified within 72 hours. High-risk breaches trigger immediate data subject notification. All incidents are logged, investigated, and reviewed.
Incident management type
Supplier-defined controls
Incident management approach
ProvisionPoint maintains a formal IS Incident Management Policy with pre-defined processes for common events including ineffective controls, access violations, equipment loss/theft, physical security breaches, and system malfunctions.

Staff report incidents immediately via any appropriate means (written or telephone) to management, providing detailed event information. All reports are logged and categorised as: No Action (Minor), Event (Moderate/Significant), or Incident/Breach (Significant/Severe).

Management investigates, coordinates remediation, and documents all actions. Post-incident reports summarise cause, containment effectiveness, remedial actions, and closure. Material data breaches are reported to the ICO within 72 hours. Incident details are reviewed during management reviews to identify, implement lessons learnt.
Post-quantum cryptography secure
Yes

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Organisations can contact us to arrange a free scan and audit report.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
5%
Between £250,000 and £500,000
5%
Between £500,001 and £1,000,000
5%
Between £1,000,001 and £2,500,000
5%
Between £2,500,001 and £5,000,000
5%
Over £5,000,001
5%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
BSI
ISO/IEC 27001 accreditation date
Friday 27 June 2025
What the ISO/IEC 27001 doesn’t cover
Resource Central and ResourceXpress services
ISO 28000:2022 certification
No
ISO 9001 certification
Yes
Who accredited the ISO 9001 certification
SJENI
ISO 9001 accreditation date
Tuesday 4 March 2025
What the ISO 9001 doesn’t cover
Resource Central and ResourceXpress services.
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
0af2500e-068a-4dca-b31a-9c9a55320510
Cyber essentials plus
No
Cyber Essentials Alternative
None of the criteria
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Employment contracts that reflect actual hours worked; steps taken to ensure employees understand their contracts and have the ability to review and adjust them if actual hours regularly exceed contracted hours
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Entitlement to sick pay for the contract workforce, with provision in place for any staff who do not meet the earnings threshold for statutory sick pay, payment of sick pay from day one of absence and payment of staff on the contract workforce who are off sick a replacement income of 100% of their usual earnings for as long as possible
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Activities to support relevant sector related skills growth and sustainability in the contract workforce. Illustrative examples: careers talks, curriculum support, literacy support, safety talks and volunteering
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Plans to respond flexibly and adapt approaches to community engagement and initiatives
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of how to influence staff, suppliers, customers, communities and/or any other appropriate stakeholders through the delivery of the contract to support climate and nature protection and improvement
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the underlying factors affecting improvements to reduce barriers to entry and training schemes for the target cohort(s) related to the contract workforce
    • Understanding of issues relating to entering the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at info@essential.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.