Cybersecurity incidents are increasing by the day and affecting all organizations, regardless of size or industry. Vendors have stepped in with different advanced cybersecurity products to help organizations fight these cybersecurity threats. One of these advanced cybersecurity solutions is Defender XDR (Extended Detection and Response).
Microsoft Defender XDR is one of the most popular XDRs in the industry and serves as a container for many of the security solutions that Microsoft has developed for its M365 suite, such as Microsoft Endpoint Detection and Response (EDR), Microsoft Defender for Office (MDO), and Microsoft Defender for Identity (MDI).
While Defender XDR contains a lot of components and security features, different M365 licensing modules provide customers with different sets of Defender XDR capabilities, and it can often be difficult to understand all these modules or tell the difference between them. Notably, one of these M365 licensing modules is M365 Business Premium, which is often confused with M365 Business Defender for Business.
In this article, we shed light on the M365 Business Premium license and discuss how it is superior to the standard Microsoft Defender for Business plan. We also discuss how to enhance M365 Business Premium with other security packages to significantly enhance your cybersecurity protection without needing to acquire more expensive licenses, such as Microsoft E3 or E5.
The table below lists the main components that are included in the M365 Business Premium licensing model.
Component | Description |
---|---|
M365 Defender for Business (MDfB) |
MDfB contains Microsoft's EDR solution, attack surface reduction, threat and vulnerability management, and more. |
Microsoft Intune | Included with the premium license, Microsoft Intune is the cloud-based unified service for managing both corporate and BYOD devices. |
Exchange Online Archiving (EOA) | EOA helps organizations manage their email data securely in the cloud, provides users with additional mailbox storage for their email content, and specifies email retention policies. |
Windows 10/11 Business | Windows 10/11 Business is a set of device management capabilities that complement Windows 10 Pro for the centralized management and security control of devices that are part of Microsoft 365 Business Premium licensing. |
Enhancement possibilities | Despite M365 Business Premium being a premium license, it can be further enhanced with add-on packages or other third-party email security solutions to improve your security defense as a whole. |
MDfB (standalone) is the standard Defender XDR licensing model that Microsoft offers for small and mid-sized organizations; it is often confused with “M365 Business Defender Premium,” which doesn’t actually exist. The premium license for businesses is actually named “M365 Business Premium” (note the missing word “Defender”). That’s because M365 Business Premium doesn’t provide any extra Defender XDR features compared to the MDfB license; rather, it complements it with other necessary solutions, which we will see in this article, e.g., Microsoft Intune.
MDfB as part of the M365 Business Premium license (source)
Despite M365 Business Premium not providing any additional advanced features for Defender XDR, MDfB alone provides many of the crucial security features of Defender XDR and is often enough for most small and medium-sized companies:
List of AIR investigations in Defender XDR
Microsoft Intune is Microsoft’s cloud-based management solution for all kinds of devices—including on-premises or cloud, corporate, or BYOD devices—and with support for a variety of underlying operating systems. Here are some of its benefits:
Overview of Microsoft Intune capabilities (source)
EOA is a cloud-based archiving solution and part of the M365 suite. It helps organizations manage and store their email data securely in the cloud, providing several helpful features for organizations to make it easier to handle email data, such as these:
There is, however, some confusion in the market about EOA archiving and the possibility that employees can delete emails from the archive, which are often important for legal/compliance use cases. In EOA, once an employee deletes an email, the email will be placed in a special folder called “Recoverable Items,” where it will remain for at least 14-30 days, depending on the configuration.
This special folder is hidden, so employees cannot find or interact with it from their mailboxes. They also cannot delete an email from the archive, i.e., from this hidden folder, unless they have administrator permissions on their computers or can connect to the Exchange Online server via PowerShell. This helps organizations with legal/compliance cases by ensuring that no unprivileged employee can permanently delete an email from the archive.
Windows 10/11 Business should not be confused with Windows 10/11 editions, such as Home, Professional, or Pro. Windows 10/11 Business is a set of additional cloud services and device management capabilities for Windows 10 Pro. It enables the centralized management and security controls of Windows devices with a valid Microsoft 365 Business Premium license.
While Microsoft doesn’t expand more on this, according to different administrators and blogs on the Internet, one of the few benefits of Windows 10/11 Business for endpoints is the ability to centrally manage them easily via Microsoft Intune.
Microsoft 365 Business Premium lays a solid foundation for protecting your small or mid-sized business. Yet, by integrating specialized add-ons—either from Microsoft or other trusted partners—you can bolster your defenses, filling in any gaps and enhancing the robust security features Business Premium offers.
The Microsoft 365 Business Premium license only covers endpoints. If your organization operates business-critical servers, consider the Microsoft 365 Business for Server add-on package to benefit from all the security features that Microsoft offers for servers. Additionally, other add-on packages that can be integrated with the premium license include Microsoft Teams Phone (a cloud-based phone system) and audio conferencing, which allows you to join Microsoft Teams meetings even if you don’t have an internet connection.
With phishing attacks being the main initial attack vector in most cyberattacks and often leading to ransomware, investing in email security is crucial for the success of your cyber defense. IRONSCALES provides several products to aid your company in combating the phishing threat:
IRONSCALES Themis CoPilot Phishing Button (source)
Microsoft has invested a lot in many security products for its M365 suite. However, providing numerous licensing models for the same security tools makes it often difficult to understand the differences between the various licensing models it offers.
In this article, we covered Microsoft’s Business Premium license for small or mid-sized companies in detail. We clarified the difference between it and Microsoft Defender for Business, with Microsoft Business Premium being the most comprehensive of the two. We also looked into how to enhance it with add-on packages from Microsoft or comprehensive email security solutions in the market without needing a more expensive solution (Microsoft E3 or E5).