Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Review

Buying Microsoft 365 and Antivirus Together: Overlap Worth Avoiding

11 min read Updated October 5, 2026 Buying & Decision Guides

Fix it now

The overlap is real and it sits on the endpoint, but only one Microsoft 365 tier contains a managed endpoint product. On Business Premium a third-party endpoint suite is duplicate spend unless you can name what it adds. On Basic or Standard there is nothing to duplicate, so the question is which one to buy.

  1. Buy one owner for the endpoint layer, never two. On a client not onboarded to Defender for Endpoint, registering a third-party antivirus puts Microsoft Defender Antivirus into disabled mode – you are replacing the Windows scanner, not adding to it.
  2. Skip the third-party suite on Business Premium unless you can name a capability it adds. Defender for Business is included and covers five client devices per user licence.
  3. Buy a managed endpoint layer on Business Basic or Standard. Those plans include none, so the machines run an unmanaged scanner with no console behind it.
  4. Treat mail as a separate purchase. Exchange Online Protection comes with every cloud mailbox; Defender for Office 365 Plan 1 – Safe Links, Safe Attachments, impersonation protection – is in Business Premium.
  5. Buy server coverage explicitly. The Defender for Business servers add-on is one licence per Windows Server or Linux instance, capped at 60 per subscription.
  6. Do not assume a server stands down or comes back. On Windows Server, Defender is disabled by hand and re-enabled by hand.

If you are on Business Premium and the third-party line has no answer to ‘what does it add’, that is the duplicate. Below is where the two stacks actually meet, what each named component contains, and the gaps that genuinely justify a second purchase.

Why it happens

Endpoint security is not one product but a stack of layers: on-access malware scanning, behavioural and ransomware protection, web and content filtering, device and removable media control, firewall policy, endpoint detection and response, and central reporting. Windows provides several of those for nothing. A Microsoft 365 plan adds management, policy and detection on top – but only one tier does. Third-party suites provide the same layers with their own engine, console and support. The comparison only makes sense layer by layer.

The most consequential correction to make here is what Windows actually does when a third-party product arrives. It is widely repeated that Microsoft Defender Antivirus steps into passive mode. On a Windows client that has not been onboarded to Microsoft Defender for Endpoint, it does not: it goes into disabled mode. Passive mode requires that onboarding, and the difference matters to your risk picture, because passive mode still scans and reports while disabled mode does nothing at all. Windows 11 with Smart App Control enabled is the documented exception where passive may apply without onboarding.

Windows Server behaves differently again and this is where estates get into trouble. Nothing is automatic in either direction. Defender must be disabled by hand when a third-party product is deployed, or set to passive with the ForceDefenderPassiveMode registry value where the server is onboarded to Defender for Endpoint. The automatic re-enablement that Microsoft documents – when the non-Microsoft product expires, is uninstalled or stops providing real-time protection – applies to Windows clients only. A lapsed third-party licence on a server therefore leaves that server with nothing running until somebody notices.

On the Microsoft side the components have names, and using them makes the comparison against a quote possible. Microsoft Defender for Business is the endpoint product included in Business Premium: it is built on Defender for Endpoint, is designed for organisations up to 300 users, and covers up to five client devices per user licence. Servers are excluded and need the Microsoft Defender for Business servers add-on, one licence per Windows Server or Linux instance, to a maximum of 60 per subscription.

Mail is a separate stack and it is often the part that decides the answer. Every Microsoft 365 plan with a cloud mailbox includes Exchange Online Protection: anti-malware, anti-spam, spoof anti-phishing, connection filtering, quarantine, zero-hour auto purge, the Tenant Allow/Block List, message trace and audit log search. Microsoft Defender for Office 365 Plan 1 – included in Business Premium and in Microsoft 365 E3 – adds Safe Links, Safe Attachments including files in SharePoint, OneDrive and Teams, user and domain impersonation protection, mailbox intelligence, real-time detections and priority accounts. A third-party endpoint product does not replace any of that, and a mail gateway does not replace endpoint protection, so reason about the two purchases separately rather than as one security budget.

Full reference

Where the two stacks meet, layer by layer

Layer Windows on its own Business Basic or Standard Business Premium Typical third-party suite
Real-time malware scanning Microsoft Defender Antivirus The same, unmanaged Defender for Business Its own engine
Ransomware and behavioural protection Yes Yes, unmanaged Yes, with policy control Yes
Central policy and reporting No No Yes Yes
Endpoint detection and response No No Yes, via Defender for Business Varies by tier
Devices per endpoint licence Not applicable Not applicable Up to five client devices per user Commonly one per device
Server coverage Not applicable Not applicable Separate add-on, one per instance, 60 maximum Separate server product
Mail filtering baseline Not applicable Exchange Online Protection Exchange Online Protection Only if you buy a mail product
Safe Links and Safe Attachments No No Defender for Office 365 Plan 1 Not applicable
Impersonation and mailbox intelligence No No Defender for Office 365 Plan 1 Not applicable
Managed detection and response No No No, bought separately Bought separately

Two real-time scanners is not twice the protection

Running two engines that both hook file operations in real time causes conflicts, performance problems and false positives rather than better detection, which is why Windows stands one of them down automatically. The buying consequence is simple: a third-party suite replaces the Windows scanner, it does not layer on top of it. What is worth knowing precisely is which state it stands down into. Without Defender for Endpoint onboarding on a Windows client, that is disabled mode – nothing scanning, nothing remediating. With onboarding it is passive mode, which stops remediating but keeps endpoint detection and response working alongside the other product. If you are paying for a third-party engine and want Microsoft’s detection signal as well, onboarding is the mechanism, not hope.

Servers, which is where this most often goes wrong

Microsoft Defender Antivirus applies automatic exclusions on Windows Server based on the roles installed, covering things like the Active Directory database and transaction logs, DHCP, DNS, file services, Hyper-V virtual disk files, print services, IIS and WSUS. Two details are worth carrying into any deployment plan. Those automatic exclusions apply only to real-time protection – they do not apply to quick, full or custom scans, or to network inspection and behaviour monitoring, so anything you need excluded from scheduled scanning must be added as a custom exclusion. And Microsoft warns explicitly that opting out of automatic exclusions can adversely affect performance or result in data corruption, so turning them off is not a tidying exercise.

What Microsoft 365 does not cover

The honest gaps are worth naming because they are the only justification for a second purchase. Managed detection and response – humans watching your alerts around the clock – is not included in any of these plans and is bought separately from whichever vendor you prefer. Breadth of platform coverage varies, particularly for older systems, network appliances and specialist server workloads. Some third-party consoles offer device control, application allow-listing and reporting depth that suit particular compliance regimes better. And there is the question of who runs it: a managed provider with an established console, playbooks and staff who know it will often deliver better outcomes with their product than you will get from an unfamiliar one. That is a legitimate reason to keep a third-party suite. Wanting a second engine for its own sake is not.

What happens when the third-party licence lapses

This belongs in the buying decision rather than in the support queue. Bitdefender publishes that when a GravityZone licence expires the protection modules of the installed agents are disabled, endpoints are no longer protected and scan tasks cannot be run. On a Windows client, Microsoft Defender Antivirus re-enables itself automatically when a non-Microsoft product expires, is uninstalled or otherwise stops providing real-time protection – so a client lapse degrades to an unmanaged Microsoft scanner rather than to nothing. On Windows Server there is no such recovery, and the machine stays unprotected until somebody re-enables Defender by hand. If you run servers on a third-party product, treat its renewal date as a server-availability date.

How to buy, by situation

  • Already on Business Premium: use Defender for Business and drop the third-party endpoint line unless you can name a specific capability it adds.
  • On Business Basic or Standard: you have no managed endpoint layer. Add one from Microsoft, buy a third-party suite, or accept an unmanaged Microsoft scanner and understand what that means for reporting.
  • Servers in the estate: licence them explicitly. Client endpoint licences do not reach a server on either side of this comparison.
  • Mixed Windows, Mac and mobile: compare platform coverage carefully, because this is where the two options genuinely differ.
  • Working with a managed provider: let them use the console they operate well, and remove the duplicate rather than running both.
  • Needing round-the-clock monitoring: that is a separate purchase from either side. No plan tier includes it.

When a licence is the actual fix

Microsoft 365 Business Premium is the plan where the overlap question resolves, because the components it adds are the ones most businesses were otherwise buying separately: Microsoft Defender for Business on the endpoint at up to five client devices per user, Microsoft Defender for Office 365 Plan 1 on the mail with Safe Links, Safe Attachments and impersonation protection, plus Intune and Microsoft Entra ID P1 for the device and identity layers. Arco can put your current Microsoft 365 line and your antivirus renewal side by side, name which capabilities you are paying for twice, and quote whichever direction is right for your mix of platforms – including the Defender for Business servers add-on, at one licence per instance, if you have servers that neither product currently covers. If you run a small Windows-only estate with no requirement for a central console, the Microsoft Defender Antivirus already in Windows is free and may be all you need.

Questions people ask about this

Should I run Microsoft and third-party antivirus together?

No, and Windows will not let you in any useful sense. On a client that is not onboarded to Defender for Endpoint, installing a third-party antivirus puts Microsoft Defender Antivirus into disabled mode – not passive mode, which requires that onboarding. Forcing two active engines causes conflicts and performance problems rather than better detection. Choose one owner of the endpoint layer, and if you want Microsoft’s detection signal alongside a third-party engine, onboard the device so Defender sits in passive mode instead of disabled.

Is the antivirus built into Windows good enough on its own?

For a small Windows-only estate with no central management requirement it is a legitimate choice and it costs nothing. What it does not give you unmanaged is central policy, alerting, reporting and endpoint detection and response – which is what you are actually buying when you pay for an endpoint product from either vendor. If nobody would notice an alert, the paid tier is not yet earning its place.

Does Business Premium cover our servers?

No. Defender for Business client licences cover up to five client devices per user and do not extend to servers. Server protection is the Microsoft Defender for Business servers add-on, and Microsoft publishes the rule and the ceiling: one licence for each instance of Windows Server or Linux, up to a maximum of 60 servers licences per subscription. Licence the shortfall explicitly rather than assuming coverage.

We are on Business Standard. What are we missing?

Business Standard gives you the applications, the mailbox and Exchange Online Protection on the mail. It does not include Defender for Business, Defender for Office 365 Plan 1, Intune or Microsoft Entra ID P1. Your machines are running the Windows scanner with no console behind them, your mail has the baseline filtering but not Safe Links, Safe Attachments or impersonation protection, and there is no conditional access on sign-in. That is the gap to price, and it is why the comparison between Standard plus a third-party suite and Premium is usually closer than people expect.

What happens to our servers if the third-party antivirus licence lapses?

They stay unprotected until somebody intervenes. Bitdefender, for example, publishes that expiry disables the protection modules on installed agents. Microsoft Defender Antivirus re-enables itself automatically on a Windows client when the third-party product expires or is removed, but Microsoft is explicit that this applies to clients and not to servers – server behaviour is manual in both directions. Treat a server antivirus renewal date as an availability date, not a billing date.

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Review Replacing Twenty Ageing PCs: Which Licences Come With Them? Review Headcount Dropped? Right-Size Licences Without Breaking Anything Review How Many CALs Do You Actually Need? Counting Users Without Guessing Review The Essential Security Stack for a Ten-Person Business, Ranked
โ† Back to Knowledge Base