Fix it now
Malwarebytes for Teams is sold in three sizes – three, ten and twenty devices – and Malwarebytes sends anyone above twenty endpoints to ThreatDown. Every plan bundles Privacy VPN and Browser Guard alongside the protection engine, so the decision is mostly a counting exercise with one question attached about how much management you need.
- Buy it if you run a small office, you install software yourself, and you want business licensing rather than a stack of consumer subscriptions.
- Buy it if the bundled VPN and Browser Guard are things your people would use, because they are included rather than extra.
- Count honestly before choosing between the three, ten and twenty-device plans. The machine in the workshop and the director’s laptop that opens the company mailbox are endpoints.
- Skip it if you are already above twenty devices, or will be within the term. Malwarebytes directs you to ThreatDown at that point rather than to a second subscription.
- Skip it if a client contract, an insurer or an auditor requires proof of centrally managed protection, unless you have seen the administration surface produce that evidence.
- Know what the management amounts to before you sign. Malwarebytes’ administrator guide documents an email alert when a device has not been scanned for seven days and an automatic monthly report – not a console listing every endpoint.
Malwarebytes states a 60-day money-back guarantee on Teams and includes priority support at every plan size, which is worth knowing if you are comparing it against a consumer subscription.
If the count settles it you can stop here. If the management question is the one you are stuck on, read on.
Why it happens
Malwarebytes for Teams exists for the gap between a household licence and a managed endpoint platform: a small firm with a handful of machines, nobody whose job is security, and no appetite for a console with policy hierarchies and deployment packages. Malwarebytes describes it as all-in-one cyber security with a built-in VPN for the sole proprietor, boutique business or small office, with no IT skills required.
The plan ladder is published and it is the most useful fact about the product: sole proprietor at three devices, boutique business at ten, small office at twenty. Above twenty endpoints, Malwarebytes points buyers at ThreatDown, its separately branded business range where the managed console, endpoint detection and response and managed services live. That is a clean line and it is worth planning around, because the moment you cross it you are changing product family rather than adding seats.
What arrives with every plan is more than the consumer reputation suggests. Malwarebytes lists the protection engine alongside Malwarebytes Privacy VPN and Malwarebytes Browser Guard, with priority support and a 60-day money-back guarantee. Windows Firewall Control is listed for Windows 11 and Scam Guard for the mobile application. If you were comparing this against a stack of consumer licences on price alone, the bundled VPN changes the comparison.
The protection itself is the consumer engine, and that is the right decision. Real-time file and behaviour scanning, web filtering against malicious and scam domains, ransomware behaviour monitoring, and exploit and brute force protection on Windows. The engine is not the part small firms struggle with; what they struggle with is knowing whether it is still switched on across every machine.
On that question, be careful what you believe. It is widely asserted that there is no policy hierarchy, no deployment tooling, no central alert queue and no reporting worth the name. That is too strong. Malwarebytes publishes a Malwarebytes for Teams Administrator Guide, and it documents a real if modest administration surface: the subscription in your account, adding devices to it, sharing the subscription with team members using activation codes, an alert that emails you if one of your team’s devices has not been scanned in the last seven days, an automatic monthly security report containing detection data, and switches for Brute Force Protection and Tamper Protection on Windows.
What the guide does not describe is the thing people picture when they hear central management: a console listing every endpoint with its current state, a queue of detections to work through, or reports you can shape to a question somebody else has asked. The seven-day scan alert is the check-in mechanism, and it is coarse – a machine can be off for a week before it says anything, and it is telling you about scans rather than about protection being switched off. For three machines in one room, where you would notice a problem by walking over, that is enough. For fifteen machines across two sites it is not, and neither is it the sort of evidence an auditor means when they ask for centrally managed endpoint protection.
The other thing to settle in writing is licensing scope. Consumer antivirus subscriptions are sold for personal use, and a business running them is relying on terms it has not read; moving to a business licence fixes that on paper as well as in practice. Servers are the place people miscount, and Malwarebytes does not publish how server operating systems are licensed in this range, so name every server on the quote rather than assuming a device is a device.
Full reference
The three plans, and the line above them
| Plan | Devices | When it fits |
|---|---|---|
| Sole proprietor | 3 | One person, a laptop, a desktop and a phone |
| Boutique business | 10 | A single-site office where you know every machine by sight |
| Small office | 20 | The largest Malwarebytes will sell in this range |
| ThreatDown | More than 20 | Where Malwarebytes directs buyers above the ceiling, with the managed console and endpoint detection and response |
Plan for the ceiling rather than discovering it. Twenty is not a soft limit you negotiate past; it is the point at which the vendor’s own page hands you to a different brand. If you expect to hire during the term, work out now whether that puts you over, because moving family mid-term is more disruptive than starting in the right one.
What is bundled at every plan size
- The protection engine, with malware, ransomware, scam and web protection, and exploit and brute force protection on Windows.
- Malwarebytes Privacy VPN, which the vendor advertises with this product. This is the component most often missing from comparisons against consumer licences.
- Malwarebytes Browser Guard, the ad and scam blocking browser extension.
- Windows Firewall Control on Windows 11, and Scam Guard in the mobile application.
- Priority support, and a 60-day money-back guarantee.
Questions to answer before you sign
- Switch on the not-scanned-in-seven-days alert on day one, and decide who receives it and the monthly report. That is the whole of the published monitoring, so it only works if somebody reads it.
- Count every endpoint, including laptops that rarely come to the office, the tablet used for stocktakes and any machine a contractor uses to touch your systems.
- Name every server on the quote. Malwarebytes does not publish server licensing for this range, so get the answer in writing rather than assuming.
- Ask what happens if you need to add devices mid-term, because no rule about seat extension is published.
- If an insurer or a customer has asked you to demonstrate managed endpoint protection, read their exact wording first and check it against what the administration surface can actually show.
Where this product stops being the right answer
- At twenty-one devices. That is not a judgement, it is the vendor’s own boundary.
- When you need evidence rather than protection. A questionnaire asking for centrally managed endpoint security with reporting is asking for something you must confirm this product produces.
- When machines are spread across sites and nobody walks past them. The whole case for this tier rests on noticing a problem informally.
- When you need endpoint detection and response by name. That lives in ThreatDown, not here.
The comparison that actually matters
Do not compare this against a consumer subscription on price. Compare it on three things: whether the licence terms cover business use, whether the bundled VPN and Browser Guard are things you would otherwise buy, and whether the administration surface answers the question of which machines are protected today. The first is a compliance answer, the second is a value answer, and the third is the one that decides whether you have outgrown the tier.
When a licence is the actual fix
If you have three to twenty machines, no dedicated administrator and no requirement to prove central control to a third party, Malwarebytes for Teams is the licence that matches your situation, and Arco supplies it. Tell us the real device count, including laptops that leave the building, and tell us whether any of those machines are servers, and we will confirm which of the three plans fits. If the count is over twenty, or will be during the term, we will quote ThreatDown instead, because that is where Malwarebytes sends buyers above the ceiling and stacking a second Teams subscription is not the intended path. We would rather tell you before you buy that you have outgrown this tier than sell you a licence you will replace in six months.
Questions people ask about this
How many devices does it cover?
Three plans: sole proprietor at three devices, boutique business at ten, and small office at twenty. Twenty is the top of the range – Malwarebytes directs anyone needing to secure more than twenty endpoints to ThreatDown, its separate business brand.
Does it include a VPN?
Yes. Malwarebytes advertises Teams as all-in-one cyber security with a built-in VPN, and every plan includes Malwarebytes Privacy VPN and Browser Guard alongside the protection engine, with priority support and a 60-day money-back guarantee.
Is there any central management?
Some, and it is documented rather than a mystery. Malwarebytes’ Teams Administrator Guide describes adding devices to the subscription, sharing it with team members by activation code, an email alert when one of your devices has not been scanned in the last seven days, an automatic monthly security report, and Brute Force and Tamper Protection switches on Windows. What it does not describe is a console listing every endpoint with its live state, or a central detection queue. Treat it as a subscription you can watch loosely, not an estate you can manage.
Can I just buy consumer licences for the office?
They would install, but consumer subscriptions are sold for personal use and a business estate running them is relying on terms it has not read. Malwarebytes sells this business range for exactly this situation, and the step up is modest.
Does this cover our file server?
Do not assume so. Malwarebytes does not publish how server operating systems are licensed in this range, so name every server on the quote and get the answer in writing before you order.
