Skip to main content

Help us improve the Digital Marketplace - send your feedback

CORE TECHNOLOGY SYSTEMS (U.K.) LIMITED

Microsoft Windows Enterprise Licenses - CoreGov

Core supplies Microsoft Windows Enterprise licences—E3, E5 and Windows 10/11 Enterprise—through our Tier‑1 CSP programme. Designed to enable secure, compliant, and centrally managed endpoints, this service provides flexible subscription options, empowering organisations to strengthen device security, simplify management, and support hybrid working environments.

Features

  • Supplies Windows 10/11 Enterprise licences via CSP.
  • Supports E3 and E5 enterprise-grade licensing models.
  • Provides flexible monthly or annual commitment terms.
  • Activates licences directly in customer tenants.
  • Enables advanced security and compliance features.
  • Integrates with Intune for device management.
  • Supports Azure AD join and modern authentication.
  • Enhances device encryption and protection capabilities.
  • Offers transparent CSP pricing governance.
  • Aligns with Microsoft 365 endpoint requirements.

Benefits

  • Improves device security and endpoint resilience.
  • Enables enterprise-wide device standardisation.
  • Supports secure hybrid and remote working.
  • Simplifies compliance and governance controls.
  • Enhances identity and access protection.
  • Reduces operational overhead of managing devices.
  • Ensures predictable licensing expenditure.
  • Integrates seamlessly with Microsoft 365 services.
  • Supports modern management with Intune.
  • Provides scalable endpoint licensing.

Pricing

  • Education pricing available
  • Free trial available

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@core.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.

Framework

G-Cloud 15

Service ID

9 6 7 8 8 3 1 6 6 4 3 0 9 9 4

Contact

CORE TECHNOLOGY SYSTEMS (U.K.) LIMITED Paul Saer
Telephone: +44 (0) 207 626 0516
Email: tenders@core.co.uk

About your service

Service categories

Applications

Collaborative

  • Team collaboration
Multi cloud support
No

Service scope

Software add-on or extension
No
Cloud deployment model
Public cloud
Service constraints
Windows Enterprise licensing is subscription-based under the CSP programme and requires compatible hardware and a Microsoft 365 tenant for deployment. Some features,such as advanced threat protection, application control, or security baselines,require E3 or E5 licensing tiers. Additional Microsoft services (e.g., Intune, Azure AD P1) may be required to fully utilise modern management and security capabilities, requiring Windows 10/11 Pro or Enterprise alongside Azure AD and Intune. Pricing and licence availability may change under Microsoft CSP terms, though “price not to exceed” controls apply to Windows licensing. This service covers licensing only; configuration, deployment, or device management are out of scope.
System requirements
  • Active Microsoft 365 tenant required.
  • Azure AD identities for authentication.
  • Supported device hardware for Windows Enterprise.
  • Endpoint Manager (Intune) for centralised management.
  • Modern authentication enabled.
  • Internet connectivity for cloud-based activation.
  • TPM support for security features.
  • Admin ability to assign licences.
  • Compatibility with Windows 10/11 Enterprise editions.
  • Conditional Access recommended for security enforcement.

User support

Email or online ticketing support
Yes
Support response times
Response times are dependent on the nature of the request. For Managed Services tickets, the response times for different request types are listed in the Service Description document.
User can manage status and priority of support tickets
Yes
Online ticketing support accessibility
None or don’t know
Phone support
Yes
Phone support availability
24 hours, 7 days a week
Web chat support
Yes
Web chat support availability
24 hours, 7 days a week
Web chat support accessibility standard
None or don’t know
How the web chat support is accessible
Our webchat solution is configurable, allowing us to tailor the interface by enabling or disabling features for different clients. This can help simplify navigation for users who need a less cluttered interface. Security roles can be configured to limit or expand access to certain features, which can help create simpler experiences for users who might struggle with complex navigation. Users can submit tickets, access knowledge bases, and use service catalogues without direct staff interaction, which could benefit users who prefer asynchronous communication. Our platform also supports integrations with Teams, Slack, and chat applications, which may allow users to choose communication channels that work best for them.
Web chat accessibility testing
None
Onsite support
Yes, at extra cost
Support levels
Core run an ITIL aligned Service Desk and incident management approach. All service requests can be made directly to our 24/7 ServiceDesk function. First line or Second Line technical analyst or engineers engage with all service tickets until successfully closed. All customers can also engage with a named Account Manager and Customer Success Manager. Core typically structures Managed Services into modular SKUs, allowing customers to select the level of support they need - for example Service Desk, End User Compute, Microsoft365 Support, Infrastructure Support and Azure Managed Services. All of these SKU's are individually priced and pricing is referenced in the relevant Service Definition document
Support available to third parties
Yes
AI chatbot
Yes

Onboarding and offboarding

Getting started
Core helps users begin using the licensing service through a structured onboarding process, including clear documentation and guided steps for establishing the CSP relationship. Users receive access to a dedicated Account Manager, Core’s Service Desk for ongoing assistance, and early‑life support immediately after go‑live. Core also provides the Customer Success Hub—an online training and adoption portal containing videos and guidance materials. Workshops and remote enablement sessions are offered where required. Core does not provide onsite training for licensing.
Service documentation
Yes
Documentation formats
  • HTML
  • ODF
  • PDF
End-of-contract data extraction
Core’s Microsoft licensing service does not store, process, or generate customer data. All customer information, files, settings and audit logs remain entirely within the customer’s own Microsoft 365/Azure tenant, controlled directly by the customer.
Ending the licensing contract does not affect access to customer data. Customers retain full ability to export, extract, or manage their data using native Microsoft tools at all times. No data extraction from Core is required.
End-of-contract process
The customer retains full ownership and access to all data within their Microsoft tenant. Core does not store or process customer data. At contract end, the customer removes Core as their CSP partner. Licences remain active and may be transferred to another CSP or managed directly. No data extraction is required.

Microsoft subscription licences, CSP management, licence changes, billing management, access to Core’s Service Desk for licensing issues, regular licence optimisation reviews, Account Manager support, onboarding/offboarding, and access to the Customer Success Hub, are services included in the price.

Professional services, workshops, migrations, managed services, Azure consumption, bespoke training, and any project-based work fall outside the core licensing fee and would be considered as additional cost.
Documentation accessibility standard
None or don’t know
How the documentation is accessible
Our onboarding and offboarding documentation is provided in standard digital formats (DOCX and PDF). While these formats are widely compatible with common screen readers and assistive technologies, the documentation itself is not currently authored to a formal accessibility standard such as WCAG 2.1. Alternative accessible formats (e.g., ODF, large print, Easy Read, HTML, audio) are not currently produced by default but may be made available on request.

Using the service

Web browser interface
Yes
Supported browsers
  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
  • Opera
  • Other
Application to install
No
Designed for use on mobile devices
Yes
Differences between the mobile and desktop service
The licensing service can be accessed on mobile devices; however, the mobile experience is limited to basic viewing and user-level interactions. Full administrative licensing functions—such as assigning licences, managing subscriptions, or accessing billing—are only available via a supported desktop browser. Some advanced pages and administrative tools are not available or are restricted on mobile browsers. Mobile apps support the use of licensed Microsoft 365 services but do not provide licensing administration capability.
Service interface
Yes
User support accessibility
EN 301 549
Description of service interface
The service interface for Core’s licensing service is Microsoft’s own cloud administration portals (Microsoft 365 Admin Center, Microsoft Partner Center, and Azure Portal). No proprietary Core interface or application is required or provided. Buyers access the service through standard Microsoft web interfaces using a supported browser.
Accessibility standards
EN 301 549
Accessibility testing
None
API
No
Customisation available
No

Scaling

Independence of resources
Core does not host or operate the Microsoft licensing platform. All licence management takes place within Microsoft’s own globally scaled, highly available cloud portals. Because the platform is provided and managed entirely by Microsoft, no customer’s usage or demand can impact another customer’s experience. There is no shared infrastructure, no performance dependency, and no contention risk.

Analytics

Service usage metrics
Yes
Metrics types
Core does not provide service usage metrics for the licensing service itself, as no user activity or content is processed. However, as part of our CSP value‑add, we provide regular licence‑estate reporting, optimisation reviews, cost analysis, and advisory insights. Customers also continue to have full access to Microsoft’s own usage analytics within the Microsoft 365 Admin Center.
Reporting types
  • Regular reports
  • Reports on request
Resource tagging
No
FOCUS resource tagging
No

Resellers

Supplier type
Reseller providing extra support
Organisation whose services are being resold
Microsoft

Staff security

Staff security clearance
Other security clearance
Government security clearance
Security Clearance (SC)

Asset protection

Knowledge of data storage and processing locations
Yes
Data storage and processing locations
  • United Kingdom
  • European Economic Area (EEA)
User control over data storage and processing locations
No
Datacentre security standards
Complies with a recognised standard (for example CSA CCM version 4.0)
Penetration testing frequency
At least once a year
Penetration testing approach
Another external penetration testing organisation
Protecting data at rest
Other
Other data at rest protection approach
There is no customer data at rest within Core’s systems for this service. All customer data is stored in the Microsoft cloud, where Microsoft provides encryption at rest and adheres to global security and compliance certifications.
Data sanitisation process
No
Equipment disposal approach
A third-party destruction service

Data importing and exporting

Data export approach
Not applicable
Data export formats
Other
Other data export formats
Not applicable
Data import formats
Other
Other data import formats
Not applicable

Data-in-transit protection

Data protection between buyer and supplier networks
Other
Other protection between networks
NOT APPLICABLE - Core’s Microsoft CSP licensing service does not transmit or process any customer data between the buyer’s network and Core’s network. All licence management is performed within Microsoft’s cloud portals (Microsoft 365 Admin Center and Partner Center), where Microsoft provides all security controls, encryption, and network protection.
As no customer data flows to Core, no additional protection mechanisms are required or implemented for this service.
Data protection within supplier network
Other
Other protection within supplier network
NOT APPLICABLE - Core’s Microsoft CSP licensing service does not transmit or process any customer data between the buyer’s network and Core’s network. All licence management is performed within Microsoft’s cloud portals (Microsoft 365 Admin Center and Partner Center), where Microsoft provides all security controls, encryption, and network protection.
As no customer data flows to Core, no additional protection mechanisms are required or implemented for this service.

Availability and resilience

Guaranteed availability
Core does not provide an availability SLA for its licensing service, as all licence management occurs within Microsoft’s own cloud platforms. Service availability and uptime are governed exclusively by Microsoft’s SLA commitments, and Core does not issue refunds linked to availability for this service.
Approach to resilience
This question does not apply to the CSP licensing service.
Core does not host or run the licensing platform; all resilience, datacentre redundancy and service continuity are provided by Microsoft’s globally distributed cloud infrastructure.
Outage reporting
Not applicable — Core does not operate the service platform. Outage reporting is provided directly by Microsoft through Microsoft 365 and Partner Center service health dashboards.

Identity and authentication

User authentication needed
Yes
User authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Other user authentication
Core sends a CSP reseller‑relationship invitation; customers must authenticate and approve this in the Microsoft 365 tenant before Core can transact licences. This is not a separate authentication method, but it is a required authorisation flow unique to CSP.
Access restrictions in management interfaces and support channels
Core restricts access to management interfaces and support channels through RBAC, SSO with mandatory MFA, privileged‑access controls aligned to NCSC secure administration, and strict identity verification for all licensing‑related requests. Only authorised personnel can access licensing management functions within our ITSM platforms, with encrypted data exchange and role‑segregated permissions ensuring least‑privilege operation. Customers authenticate through Microsoft 365 identity to approve CSP relationships and licence changes, ensuring end‑to‑end governance and prevention of unauthorised access.
Access restriction testing frequency
At least once a year
Management access authentication
  • Multi-Factor Authentication (MFA)
  • Identity federation with existing provider (for example Google Apps)
  • Username or password
  • Other
Description of management access authentication
Role‑based access control (RBAC), authorised‑contact validation and privileged‑access controls aligned to NCSC secure administration

Audit information for users

Access to user activity audit information
Users have access to real-time audit information
How long user audit data is stored for
Between 6 months and 12 months
Access to supplier activity audit information
Users have access to real-time audit information
How long supplier audit data is stored for
Between 6 months and 12 months
How long system logs are stored for
User-defined

Security governance

Named board-level person responsible for service security
Yes
Security governance certified
Yes
Security governance standards
ISO/IEC 27001
Information security policies and processes
Core operates a fully ISO 27001 certified Information Security Management System (ISMS), supported by formal policies covering confidentiality, integrity, availability, access control, incident management, risk assessment, business continuity and supplier management. All employees receive mandatory security awareness training, with additional specialist training for staff in sensitive roles. Security responsibilities are defined in job descriptions and contracts, and policy breaches are managed under our disciplinary process. The ISMS is overseen by a dedicated Information Security Steering Group chaired by the COO and supported by the CISO, IT Manager and senior risk specialists. Policies are reviewed at least annually and continuously improved through internal audits, external ISO 27001 surveillance audits, risk assessments and automated compliance monitoring. Staff are required to report security incidents or weaknesses immediately via documented procedures.
Software Security Code of Practice
Yes

Operational security

Configuration and change management standard
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Configuration and change management approach
Core operates ITIL aligned configuration and change management processes, benchmarked at CMM Level 3–4. Configuration items are tracked throughout their lifecycle using customer CMDBs, Intune, Azure and ITSM tooling, ensuring accurate, continually updated records. All changes follow a formal ITIL process, including risk and security assessment, CAB review, client approval, and full auditability. Security impact is evaluated using Microsoft native tooling (Defender, Secure Score) to ensure no adverse effect on identity, access or service integrity. All changes are documented, traceable, and aligned with customer governance.
Vulnerability management type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Vulnerability management approach
Core operates a proactive, ITIL aligned vulnerability management process. Threats are continuously assessed using Microsoft Defender, Secure Score, Azure Security Centre, Sentinel SIEM and weekly Nessus scans to identify vulnerabilities and misconfigurations. We deploy critical and security patches within 14 days in line with NCSC guidance, with accelerated deployment for zero day threats using automated Endpoint Manager and Azure Update Management workflows. Threat intelligence is sourced from Microsoft’s security ecosystem, Tenable CVE feeds, NCSC advisories and SIEM driven correlation, ensuring rapid awareness and remediation of emerging risks.
Protective monitoring type
Complies with a recognised standard, for example CSA CCM v4.0 or SSAE-18 / ISAE 3402
Protective monitoring approach
Core delivers continuous protective monitoring using Microsoft Sentinel SIEM, Defender for Endpoint/Servers, and Azure Defender to identify potential compromises through behavioural analytics, real time alerting, threat intelligence and proactive threat hunting. When a potential compromise is detected, alerts are triaged by our security operations processes, with automated containment actions (e.g. isolating devices, disabling accounts) and escalation to our engineers. Incident response follows predefined playbooks and documented communication paths. Core provides rapid response, with 24/7 monitoring and immediate triage, and P1 security incidents responded to within minutes via Sentinel driven alerting.
Incident management type
Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
Incident management approach
Core operates ITIL aligned incident management with predefined processes for common events, including a full Major Incident Management (MIM) workflow covering P1 and P2 incidents. Users report incidents via phone, email, or the self service portal, or incidents may be auto raised through monitoring. When an incident is logged, it is triaged, prioritised, and assigned, with automated notifications and, for P1s, initiation of a live bridging call and stakeholder communications. Response times follow strict SLAs, including 30 minute response for P1 incidents. We issue formal incident reports for all major incidents.
Post-quantum cryptography secure
No

Secure development

Approach to secure software development best practice
Conforms to a recognised standard, but self-assessed

Public sector networks

Connection to public sector networks
No

Pricing

Discount for educational organisations
Yes
Free trial available
Yes
Description of free trial
Yes — Core provides a 30‑day free trial for eligible Microsoft Cloud subscriptions when 25 or more licences are being evaluated.

Discount percentage by annual call-off contract value (excluding VAT)

Less than £250,000
0%
Between £250,000 and £500,000
0%
Between £500,001 and £1,000,000
0%
Between £1,000,001 and £2,500,000
0%
Between £2,500,001 and £5,000,000
0%
Over £5,000,001
0%

Non-mandatory Standards and certifications

ISO/IEC 27001 certification
Yes
Who accredited the ISO/IEC 27001
British Assessment Bureau (part of the Amtivo Group)
ISO/IEC 27001 accreditation date
Thursday 27 February 2025
What the ISO/IEC 27001 doesn’t cover
Nothing
ISO 28000:2022 certification
No
ISO 9001 certification
No
Quality management systems (QMS)
Yes
CSA STAR certification
No
PCI certification
No
Cyber essentials
Yes
Please provide your Cyber Essentials Certificate Number
Ad9ffc7a-28e4-460b-bccb-fc914b3420df
Cyber essentials plus
Yes
Please provide your Cyber Essentials Plus Certificate Number
13867168-d605-4ed3-9481-13e21f4ae9bc
Other security certifications
No

Social value

Section B - Commitment for Future: Delivery
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority

    • New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
    • Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
    • Payment of more than the National Minimum Wage or National Living Wage (as appropriate) to the contract workforce
    • Measures to support in-work progression to help people in the contract workforce, to move into higher paid work by developing new skills relevant to the contract
    • Volunteering opportunities for staff
    • Understanding of the modern slavery risks and issues affecting the market, industry, sector or country (of origin or of source) relevant to the contract, and the workforce in the supplier’s own organisation and those of its key subcontractors
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 2: Skills for growth: Supporting growth sectors and addressing skills gaps.

    • Understanding of employment and relevant skills issues, and of the education and training issues relating to the contract. Illustrative examples: demographics, skills shortages, new opportunities in high growth sectors, geographic/local community and skills/employment challenges
  • Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.

    Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises

    • Activities to identify opportunities to open up sub-contracts under the prime contract to a diverse range of businesses, including new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
    • Support for community-led initiatives relevant to the contract. Illustrative examples: improving transport links; reducing loneliness; helping with English language proficiency; and facilitating social mixing among people with different backgrounds
  • Mission: Make Britain a clean energy superpower: To cut bills, create jobs and deliver security with cheaper, zero-carbon electricity by 2030, accelerating to net zero

    Policy Outcome 4: Sustainable procurement practices: Reducing carbon footprints, minimising waste, and promoting the use of clean energy and green technologies.

    • Understanding of opportunities for additional environmental benefits delivery in the performance of the contract, including working towards net zero carbon emissions and use of clean energy and green technologies
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 6: Employment and training: For those who face barriers to employment

    • Understanding of employment and skills issues, and of the skills and employment shortages of high growth sectors relating to the contract
    • Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
    • Understanding of the issues affecting inequality in employment, skills and pay in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors. Measures to tackle inequality in employment, skills and pay in the contract workforce
  • Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain

    Policy Outcome 7: Creating a pipeline of opportunities: For the contract workforce, reducing barriers to entry for under-represented groups.

    • Understanding of the issues affecting the development of new skills by target cohort
    • Understanding of issues relating to entering the contract workforce
  • Mission: Build an NHS fit for the future: That is there when people need it; with fewer lives lost to the biggest killers; in a fairer Britain, where everyone lives well for longer.

    Policy Outcome 8: Increasing productivity through physical and mental wellbeing: In the supply chain and communities in the relevant area.

    • Understanding of issues relating to health and wellbeing, including physical and mental health, in the contract workforce

Service documents

Request an accessible format
If you use assistive technology (such as a screen reader) and need versions of these documents in a more accessible format, email the supplier at tenders@core.co.uk. Tell them what format you need. It will help if you say what assistive technology you use.