Business Premium is the best value security licence Microsoft sells to small businesses, and the most consistently wasted.
The waste is not the customer’s fault. Buying it feels like buying protection, because that is how it is sold: a bundle of security products, one price per user, done. What arrives is a set of capabilities, most of them inert until somebody configures them. The gap between the two is where almost every finding in a Microsoft 365 review lives.
What you are actually paying for
Business Premium bundles several things that are sold separately at higher tiers, which is why it is good value and also why it is rarely used fully. The security components most relevant to a smaller organisation:
| Component | What it gives you | State on day one |
|---|---|---|
| Entra ID Plan 1 | Conditional Access, self-service password reset, group-based licensing | Available, but policies must be built |
| Multi-factor authentication | Phishing-resistant options including passkeys and Windows Hello | Baseline protection applies to new tenants; not equivalent to a considered policy |
| Intune | Device management, compliance policies, application protection for phones | Nothing enrolled until you enrol it |
| Defender for Office 365 Plan 1 | Safe Links, Safe Attachments, anti-phishing policies | Some defaults on, tuning absent |
| Defender for Business | Endpoint detection and response across devices | Requires onboarding per device |
| Azure Information Protection and sensitivity labels | Classification and protection of documents and mail | No labels exist until you create them |
| Windows Autopatch and update policies | Managed update rings | Not configured |
| Exchange Online Archiving and retention | Retention and litigation hold | Off unless enabled |
Microsoft does apply a baseline of protection to new tenants, and that baseline is worth having. It is not the same as a configuration built around how your organisation actually works, and for most businesses it is not sufficient on its own.
The three that matter most, and are most often missed
Conditional Access. The single most valuable thing in the bundle, and the most commonly left at defaults. Without policies, you have authentication but no rules about the circumstances in which it is accepted: no device compliance requirement, no restriction on legacy protocols, no separation of administrative access. The licence pays for the ability to say “not from an unmanaged device”, and saying it is the part people skip.
Intune, for phones as much as laptops. Most smaller organisations think of Intune as laptop management and never apply application protection policies to mobile devices. Meanwhile a significant proportion of work email is read on personal phones. Application protection can require a PIN for the work app, prevent copying company data into personal applications, and wipe organisational data without touching anything personal. That capability is included, and it directly addresses the personal device question that comes up in every Cyber Essentials assessment.
Defender for Business. Endpoint detection and response is included, and it does nothing for a device that has never been onboarded. Check the device inventory against your actual estate rather than assuming, because the two are rarely the same number.
A licence is a receipt for capability. Security is what happens when someone configures it, keeps it configured, and checks it is still configured a year later. Nobody is breached because they bought the wrong bundle; plenty are breached because the right bundle was never switched on.
Ten things to check this week
- Are there any Conditional Access policies at all, and are they in enforce mode rather than report only?
- Is legacy authentication blocked? It bypasses modern authentication controls entirely and remains present in tenants that were migrated rather than built new.
- Are administrator accounts separate from daily-use accounts, and excluded from nothing they should not be excluded from?
- Do you have emergency access accounts, excluded from Conditional Access, with credentials stored somewhere that is not the tenant they unlock?
- Are devices enrolled in Intune, and does the enrolled count match the number of devices your people actually use?
- Are application protection policies applied to mobile devices, including personally owned phones reading work email?
- Is Defender for Business onboarded across the estate, with alerts going somewhere a human reads?
- Are Safe Links and Safe Attachments tuned, or running on defaults nobody has revisited?
- Is external sharing configured deliberately, rather than at whatever the tenant was created with?
- Is audit logging enabled and retained long enough to investigate something you discover two months late?
Where this meets certification
Cyber Essentials asks what your controls are, not what your licence is. Several of its questions are answered directly by Business Premium features, but only where those features are configured: multi-factor authentication on cloud services, separation of administrative accounts, malware protection, security update management, and secure configuration of devices.
An organisation holding Business Premium and answering honestly can find itself failing on controls it has already paid for. That is a frustrating way to fail, and an easy one to avoid: our preparation guide covers what the assessment actually asks, and the scope guide covers which devices and services are in the boundary.
Finding out what state you are actually in
The honest answer for most businesses is that nobody knows, because nobody has looked since the tenant was set up, and the person who set it up was solving a migration problem rather than a security one.
An independent Microsoft 365 Security review establishes what is configured, what is available and unused, and what would need to change, in that order. If you would rather find out before a customer’s questionnaire does, get in touch or call 01722 445972.