Skip to content
Call +49 40 88192642 Send an email [email protected] Chat in Teams [email protected]
← All articles ·Unkategorisiert · ·7 min read

Business Premium: paid-for security features nobody has switched on

Conditional Access, Intune, Defender and archiving are included in Business Premium but barely set up after purchase. What the licence contains, where I start and why PIM needs an add-on licence.

Sicherheitsfunktionen als Schalter, von denen erst wenige eingeschaltet sind

Microsoft 365 Business Premium includes a whole range of security features that smaller companies would otherwise have to buy one by one. Yet in a first tenant review I find the same thing almost every time: the licence is paid for, but the features are not set up. This article covers what the licence contains, where I start, and where Business Premium reaches its limits. The observations come from tenant reviews, most recently in 2026.

What I usually find on a first look at the tenant

The most common surprise is not an exotic gap but basic settings. Licences are paid for but not assigned to anyone, or kept on for people who have left. The tenant runs in its default configuration, where the security features exist but are not switched on.

  • Multi-factor authentication is active for only some accounts, or none at all.
  • Individual accounts hold permanent global admin rights and are used that way day to day.
  • Accounts of former staff are still active or licensed.
  • SPF, DKIM and DMARC for the email domain are incomplete.
  • Sharing with external people is possible without restriction, and it is being used.
  • There is no Microsoft 365 backup beyond the recycle bin.

None of these can be fixed with a single switch. Each feature has to be adapted once to the way the company works, its devices and its responsibilities. That is exactly the step that is often skipped after the licence is bought.

What Business Premium contains and what often goes unused

Conditional Access

Part of Entra ID P1. Rules for who may sign in from where, with which device and under which conditions. The basis for everything else.

Intune

Management of Windows, macOS, iOS and Android: encryption, updates, apps and compliance. Access rules only become effective once devices are managed.

Defender for Business

Endpoint protection with detection and response (EDR) and automated investigation, designed for companies with up to 300 users.

Defender for Office 365 Plan 1

Safe Links and Safe Attachments check links and attachments in email as well as files in SharePoint, OneDrive and Teams, plus extended phishing protection.

Information protection

Sensitivity labels and data loss prevention policies for email and files through Microsoft Purview.

Archiving

Exchange Online Archiving is included, but the archive mailbox has to be enabled for each user.

Autopilot

New Windows devices set themselves up with applications and policies as soon as the user signs in.

Self-service password reset

Staff reset their own passwords, and with an on-premises Active Directory the change is written back there too. Writeback is missing from Basic and Standard.

Then there is Windows LAPS, which rotates the passwords of local administrator accounts regularly and stores them centrally. LAPS itself is free; in practice it is controlled through Intune. I rarely find this set up at Business Premium customers either.

Why the security defaults are not enough

Every new tenant starts with Microsoft’s security defaults. They enforce multi-factor authentication and block legacy sign-in methods. That is better than nothing, but it cannot be adjusted: no exclusions for emergency accounts, no rules by device or location, no graded treatment of administrators. With Business Premium I therefore replace the security defaults with Conditional Access as early as possible. That happens during the initial assessment, not at the end of a project.

Where I start

  1. Emergency accounts and Conditional Access. First I create two emergency access accounts that are excluded from the access rules and specially protected. Then come the rules themselves: multi-factor authentication for everyone, legacy sign-in blocked, stricter requirements for administrators.
  2. Time-limited admin rights. I replace permanent global administrators with rights that are activated when needed for a limited time, with a justification and an audit trail. This is what Privileged Identity Management (PIM) does.
  3. Defender for Office 365. Safe Links, Safe Attachments and extended phishing protection are switched on through the preset security policies and then adapted to the environment.

After that come Intune with encryption and compliance policies, Defender for Business on the devices, LAPS, archiving and information protection. The order depends on what I find. The first three steps, however, are almost always at the start.

Basic and Standard are no longer enough

Many clients still work with Business Basic or Business Standard. Both licences only include the free tier of Entra ID, and so no Conditional Access, no device management with Intune and no endpoint protection with EDR. If devices are to be managed centrally, I advise against buying Business Standard.

The same applies the other way round. For companies with fewer than 300 users I usually consider E3 or E5 unnecessary. Business Premium for staff and targeted add-on licences such as Entra ID P1 or P2 for IT cover most requirements. What Business Premium costs by comparison, and how Copilot fits in, I have worked through in the article on the Copilot and Business Premium bundle price.

What can be dropped afterwards

Once the included features are set up, the question is which additional products are still needed. For some clients, a separate endpoint protection product and an upstream mail gateway could be cancelled afterwards. I mainly use additional email protection where the licence does not include Defender for Office 365. That is not a general recommendation: where an additional service adds clear value, it stays. But I only make that decision once it is clear what the licence you already pay for can do.

Sources