Business Premium is the best value security licence Microsoft sells to small businesses, and the most consistently wasted.

The waste is not the customer’s fault. Buying it feels like buying protection, because that is how it is sold: a bundle of security products, one price per user, done. What arrives is a set of capabilities, most of them inert until somebody configures them. The gap between the two is where almost every finding in a Microsoft 365 review lives.

IncludedCapabilities you are already paying for
InertMost of them, until deliberately configured
BothCyber Essentials asks about the settings, not the licence

What you are actually paying for

Business Premium bundles several things that are sold separately at higher tiers, which is why it is good value and also why it is rarely used fully. The security components most relevant to a smaller organisation:

ComponentWhat it gives youState on day one
Entra ID Plan 1Conditional Access, self-service password reset, group-based licensingAvailable, but policies must be built
Multi-factor authenticationPhishing-resistant options including passkeys and Windows HelloBaseline protection applies to new tenants; not equivalent to a considered policy
IntuneDevice management, compliance policies, application protection for phonesNothing enrolled until you enrol it
Defender for Office 365 Plan 1Safe Links, Safe Attachments, anti-phishing policiesSome defaults on, tuning absent
Defender for BusinessEndpoint detection and response across devicesRequires onboarding per device
Azure Information Protection and sensitivity labelsClassification and protection of documents and mailNo labels exist until you create them
Windows Autopatch and update policiesManaged update ringsNot configured
Exchange Online Archiving and retentionRetention and litigation holdOff unless enabled

Microsoft does apply a baseline of protection to new tenants, and that baseline is worth having. It is not the same as a configuration built around how your organisation actually works, and for most businesses it is not sufficient on its own.

The three that matter most, and are most often missed

Conditional Access. The single most valuable thing in the bundle, and the most commonly left at defaults. Without policies, you have authentication but no rules about the circumstances in which it is accepted: no device compliance requirement, no restriction on legacy protocols, no separation of administrative access. The licence pays for the ability to say “not from an unmanaged device”, and saying it is the part people skip.

Intune, for phones as much as laptops. Most smaller organisations think of Intune as laptop management and never apply application protection policies to mobile devices. Meanwhile a significant proportion of work email is read on personal phones. Application protection can require a PIN for the work app, prevent copying company data into personal applications, and wipe organisational data without touching anything personal. That capability is included, and it directly addresses the personal device question that comes up in every Cyber Essentials assessment.

Defender for Business. Endpoint detection and response is included, and it does nothing for a device that has never been onboarded. Check the device inventory against your actual estate rather than assuming, because the two are rarely the same number.

The point

A licence is a receipt for capability. Security is what happens when someone configures it, keeps it configured, and checks it is still configured a year later. Nobody is breached because they bought the wrong bundle; plenty are breached because the right bundle was never switched on.

Ten things to check this week

  • Are there any Conditional Access policies at all, and are they in enforce mode rather than report only?
  • Is legacy authentication blocked? It bypasses modern authentication controls entirely and remains present in tenants that were migrated rather than built new.
  • Are administrator accounts separate from daily-use accounts, and excluded from nothing they should not be excluded from?
  • Do you have emergency access accounts, excluded from Conditional Access, with credentials stored somewhere that is not the tenant they unlock?
  • Are devices enrolled in Intune, and does the enrolled count match the number of devices your people actually use?
  • Are application protection policies applied to mobile devices, including personally owned phones reading work email?
  • Is Defender for Business onboarded across the estate, with alerts going somewhere a human reads?
  • Are Safe Links and Safe Attachments tuned, or running on defaults nobody has revisited?
  • Is external sharing configured deliberately, rather than at whatever the tenant was created with?
  • Is audit logging enabled and retained long enough to investigate something you discover two months late?

Where this meets certification

Cyber Essentials asks what your controls are, not what your licence is. Several of its questions are answered directly by Business Premium features, but only where those features are configured: multi-factor authentication on cloud services, separation of administrative accounts, malware protection, security update management, and secure configuration of devices.

An organisation holding Business Premium and answering honestly can find itself failing on controls it has already paid for. That is a frustrating way to fail, and an easy one to avoid: our preparation guide covers what the assessment actually asks, and the scope guide covers which devices and services are in the boundary.

Finding out what state you are actually in

The honest answer for most businesses is that nobody knows, because nobody has looked since the tenant was set up, and the person who set it up was solving a migration problem rather than a security one.

An independent Microsoft 365 Security review establishes what is configured, what is available and unused, and what would need to change, in that order. If you would rather find out before a customer’s questionnaire does, get in touch or call 01722 445972.