Business Premium: paid-for security features nobody has switched on
Conditional Access, Intune, Defender and archiving are included in Business Premium but barely set up after purchase. What the licence contains, where I start and why PIM needs an add-on licence.
Microsoft 365 Business Premium includes a whole range of security features that smaller companies would otherwise have to buy one by one. Yet in a first tenant review I find the same thing almost every time: the licence is paid for, but the features are not set up. This article covers what the licence contains, where I start, and where Business Premium reaches its limits. The observations come from tenant reviews, most recently in 2026.
What I usually find on a first look at the tenant
The most common surprise is not an exotic gap but basic settings. Licences are paid for but not assigned to anyone, or kept on for people who have left. The tenant runs in its default configuration, where the security features exist but are not switched on.
- Multi-factor authentication is active for only some accounts, or none at all.
- Individual accounts hold permanent global admin rights and are used that way day to day.
- Accounts of former staff are still active or licensed.
- SPF, DKIM and DMARC for the email domain are incomplete.
- Sharing with external people is possible without restriction, and it is being used.
- There is no Microsoft 365 backup beyond the recycle bin.
None of these can be fixed with a single switch. Each feature has to be adapted once to the way the company works, its devices and its responsibilities. That is exactly the step that is often skipped after the licence is bought.
What Business Premium contains and what often goes unused
Part of Entra ID P1. Rules for who may sign in from where, with which device and under which conditions. The basis for everything else.
Management of Windows, macOS, iOS and Android: encryption, updates, apps and compliance. Access rules only become effective once devices are managed.
Endpoint protection with detection and response (EDR) and automated investigation, designed for companies with up to 300 users.
Safe Links and Safe Attachments check links and attachments in email as well as files in SharePoint, OneDrive and Teams, plus extended phishing protection.
Sensitivity labels and data loss prevention policies for email and files through Microsoft Purview.
Exchange Online Archiving is included, but the archive mailbox has to be enabled for each user.
New Windows devices set themselves up with applications and policies as soon as the user signs in.
Staff reset their own passwords, and with an on-premises Active Directory the change is written back there too. Writeback is missing from Basic and Standard.
Then there is Windows LAPS, which rotates the passwords of local administrator accounts regularly and stores them centrally. LAPS itself is free; in practice it is controlled through Intune. I rarely find this set up at Business Premium customers either.
Why the security defaults are not enough
Every new tenant starts with Microsoft’s security defaults. They enforce multi-factor authentication and block legacy sign-in methods. That is better than nothing, but it cannot be adjusted: no exclusions for emergency accounts, no rules by device or location, no graded treatment of administrators. With Business Premium I therefore replace the security defaults with Conditional Access as early as possible. That happens during the initial assessment, not at the end of a project.
Where I start
- Emergency accounts and Conditional Access. First I create two emergency access accounts that are excluded from the access rules and specially protected. Then come the rules themselves: multi-factor authentication for everyone, legacy sign-in blocked, stricter requirements for administrators.
- Time-limited admin rights. I replace permanent global administrators with rights that are activated when needed for a limited time, with a justification and an audit trail. This is what Privileged Identity Management (PIM) does.
- Defender for Office 365. Safe Links, Safe Attachments and extended phishing protection are switched on through the preset security policies and then adapted to the environment.
After that come Intune with encryption and compliance policies, Defender for Business on the devices, LAPS, archiving and information protection. The order depends on what I find. The first three steps, however, are almost always at the start.
Basic and Standard are no longer enough
Many clients still work with Business Basic or Business Standard. Both licences only include the free tier of Entra ID, and so no Conditional Access, no device management with Intune and no endpoint protection with EDR. If devices are to be managed centrally, I advise against buying Business Standard.
The same applies the other way round. For companies with fewer than 300 users I usually consider E3 or E5 unnecessary. Business Premium for staff and targeted add-on licences such as Entra ID P1 or P2 for IT cover most requirements. What Business Premium costs by comparison, and how Copilot fits in, I have worked through in the article on the Copilot and Business Premium bundle price.
What can be dropped afterwards
Once the included features are set up, the question is which additional products are still needed. For some clients, a separate endpoint protection product and an upstream mail gateway could be cancelled afterwards. I mainly use additional email protection where the licence does not include Defender for Office 365. That is not a general recommendation: where an additional service adds clear value, it stays. But I only make that decision once it is clear what the licence you already pay for can do.
Sources
- Security features by licence: Microsoft Learn – Microsoft 365 for business security overview
- Conditional Access: Microsoft Learn – What is Conditional Access?
- Security defaults: Microsoft Learn – Security defaults in Microsoft Entra ID
- Emergency access accounts: Microsoft Learn – Manage emergency access accounts
- Licence requirements for PIM: Microsoft Learn – Microsoft Entra ID Governance licensing fundamentals
- Defender for Business: Microsoft Learn – Microsoft Defender for Business overview
- Defender for Office 365: Microsoft Learn – Microsoft Defender for Office 365 overview
- Sensitivity labels: Microsoft Learn – Learn about sensitivity labels
- Archiving: Microsoft Learn – Exchange Online Archiving service description
- Autopilot: Microsoft Learn – Overview of Windows Autopilot
- Self-service password reset: Microsoft Learn – Licensing requirements for Microsoft Entra self-service password reset
- Windows LAPS: Microsoft Learn – What is Windows LAPS?
Server move in one day: why the preparation takes longer than the move
A new server, a new domain, every workstation moved across and normal work the next morning. What has to happen beforehand, what the schedule and fallback plan look like, and where the time really goes.
Read→
Several companies, one site: how to share a network cleanly
A shared internet connection and firewall, separate networks and a Microsoft 365 tenant for each company. What is shared, what stays separate, how costs are split and where such projects are most likely to snag.
Read→
Company phones that set themselves up: iPhone and Android with Intune
How iPhones enrol in Intune through Apple Business Manager and Android devices through zero-touch the first time they are switched on, how personal phones are protected with app protection policies, and what to watch for with privately bought devices.
Read→