Fix it now
Defender for Business is Microsoft’s endpoint security product for organisations of up to 300 users, and it is included with Microsoft 365 Business Premium. It is not a cut-down antivirus: it carries endpoint detection and response, automated investigation and remediation, automatic attack disruption, threat analytics and core vulnerability management. What it leaves out is the analyst tooling.
- Buy it if you are under 300 users, already on Business Premium, and still paying separately for a third-party endpoint suite. Check the licence you hold before buying anything at all.
- Buy it if you want one console covering Windows, Mac, iOS and Android with no extra agent to deploy on Windows.
- Buy it if attack surface reduction rules and device control matter more to you than writing hunting queries.
- Skip it if you will pass 300 users soon. The move to Defender for Endpoint is not an upgrade in place, and Microsoft does not support running the two side by side.
- Skip it if your provider needs multi-tenant tooling and custom detection logic, which is Defender for Endpoint Plan 2 territory.
- Count your servers separately. Server protection needs the Defender for Business servers add-on, and above 60 servers Microsoft directs you to a different licence entirely.
Microsoft states that Defender for Business does not support mixed licensing. A tenant holding both Defender for Business and Defender for Endpoint Plan 2 defaults to the Defender for Business experience, and switching requires every user to be licensed for Plan 2 and a request to Microsoft Support.
If that settles it you can stop here. If you want the capability comparison and the honest case for dropping a third-party suite, read on.
Why it happens
On Windows the agent is already in the operating system, so onboarding is a matter of enrolling the device so its telemetry reports to the Defender portal. You do that through Intune, a Group Policy or a local script depending on how the estate is managed. Mac, iOS, Android and Linux need a package installed. Servers are not covered by the base licence at all; they need the separate per-server add-on, and that is worth knowing before you count seats rather than after.
What arrives when you switch it on is more than the reputation suggests. Next-generation protection with cloud-delivered lookups and tamper protection. Attack surface reduction. Endpoint detection and response with behavioural alerts grouped into incidents. Automated investigation and remediation. Automatic attack disruption, which contains an attack in progress rather than waiting for a human. Threat analytics. Core vulnerability management showing outdated software and misconfigurations per device. Centralised management with a simplified configuration path that applies sensible defaults, so a small firm is protected on day one without writing policy.
Attack surface reduction is the part worth the most and the part most often left switched off. These are rules that block behaviour rather than files: Office applications spawning child processes, script interpreters launching downloaded content, credential theft from the LSASS process, executables running from mail and webmail clients. They stop whole classes of attack that no signature catches. Turn them on in audit mode first, read what would have been blocked for a fortnight, then enforce. That fortnight is the difference between a clean rollout and a helpdesk queue.
Where it stops is consistent. There is no advanced hunting, so you cannot query raw endpoint telemetry and therefore cannot answer a question the product did not anticipate. There are no custom detection rules, so you cannot turn something you found into a standing alert. Device grouping is simpler and reporting is shallower. If your response process is reimage and move on, none of that matters. If somebody has to explain to a client exactly what happened, it matters a great deal.
The ceiling deserves more attention than it usually gets, because the transition is not smooth. Microsoft designs Defender for Business for up to 300 users and, above that, points at Defender for Endpoint, Microsoft Defender XDR or a Microsoft 365 enterprise subscription. It also states that mixed licensing is not supported: a tenant that holds both Defender for Business and Defender for Endpoint Plan 2 defaults to the Defender for Business experience, and getting the Plan 2 experience requires licensing every user for Plan 2 and contacting Microsoft Support to request the switch. Plan that before a hiring push, not during one.
On whether it is enough to drop a specialist suite, the answer for most small organisations is yes, and the reasoning is not about the scanner. What decides it is that Defender sits inside the operating system rather than bolted to it, so attack surface rules, tamper protection and device control reach places a third-party agent has to negotiate for; and that alerts land in the same portal as your identity and mail signals rather than in a separate console nobody opens. There are honest reasons to stay with a specialist, including a console that also covers network appliances, a provider whose practice is built on another vendor’s tooling, or legacy operating systems Microsoft no longer onboards. None of those is the same as doubting detection quality.
Full reference
What sits in which plan
| Capability | Defender for Business | Defender for Endpoint Plan 1 | Defender for Endpoint Plan 2 |
|---|---|---|---|
| Next-generation protection | Yes | Yes | Yes |
| Attack surface reduction and device control | Yes | Yes | Yes |
| Manual response actions on a device | Yes | Yes | Yes |
| Endpoint detection and response | Yes, simplified | No | Yes |
| Automated investigation and remediation | Yes | No | Yes |
| Automatic attack disruption | Yes | No | Yes |
| Threat analytics | Yes | No | Yes |
| Vulnerability management | Core capabilities | No | Yes |
| Advanced hunting and custom detections | No | No | Yes |
| User ceiling | 300 | None | None |
Servers, and where the add-on stops
- Windows and Linux servers are not covered by the base licence and need the Microsoft Defender for Business servers add-on.
- That add-on requires Defender for Business or Microsoft 365 Business Premium in the tenant. It is not sold on its own.
- Above 60 servers, Microsoft directs you to a different licence: Defender for Endpoint Server, or Defender for Servers Plan 1 or Plan 2 through Defender for Cloud.
- Count servers before you count seats. This is the line item most commonly missing from a first quote.
The 300-user ceiling, and how to cross it
- Establish where you actually are. The ceiling applies to the organisation, not to the number of devices onboarded.
- If you expect to cross it inside the licence term, plan the move now rather than at the point of breach.
- Understand that mixed licensing is not supported here: a tenant with Defender for Business and Defender for Endpoint Plan 2 defaults to the Defender for Business experience.
- To get the Plan 2 experience, licence all users for Plan 2, through the standalone subscription or a suite that includes it, then contact Microsoft Support to request the switch.
- Rebuild policy and device group structure deliberately during that move. The two products organise devices differently and a straight lift produces gaps.
The first month, in order
- Onboard a pilot group and confirm telemetry is arriving in the Defender portal before touching policy.
- Turn on tamper protection everywhere. It costs nothing and it is what stops an attacker disabling the rest.
- Enable attack surface reduction rules in audit mode and read the results for two weeks.
- Enforce the rules that produced no legitimate blocks, and investigate the ones that did rather than excluding them permanently.
- Configure device control for removable storage, which is the cheapest real risk reduction in the product.
- Assign the console to a named person with a defined rhythm. The failure mode here is not weak protection, it is nobody looking.
Do not run two real-time scanners on the same machine. If you deploy alongside another suite, remove the other one properly with its vendor removal tool. Half-removed security products cause boot failures and file-system stalls that look like hardware faults and get diagnosed as such for weeks.
When a licence is the actual fix
Microsoft Defender for Business is the right purchase for an organisation under the 300-user ceiling that wants managed endpoint security with response capability rather than a scanner. Check first whether you already own it: it is included with Microsoft 365 Business Premium, and a surprising number of firms pay for a third-party suite alongside a licence that already covers this. If you are on Business Basic or Business Standard, the two honest routes are the standalone Defender for Business subscription, or moving to Business Premium if you also want Intune and Entra ID P1 in the same step. Arco can price both against your current seat count and add the servers licence where you have Windows Server or Linux machines to cover, remembering that above 60 servers Microsoft points at a different licence. If you are close to 300 users, tell us, because the move up is a project rather than a change of line item.
Questions people ask about this
Do I need Business Premium to get it?
No. It is sold standalone as well, to organisations with up to 300 users. Business Premium is usually better value if you also want Intune, Entra ID P1 and the Office applications, because those separately cost more than the step up.
What happens when we pass 300 users?
Microsoft points you at Defender for Endpoint, Microsoft Defender XDR or a Microsoft 365 enterprise subscription. The awkward part is that mixed licensing is not supported: a tenant holding both defaults to the Defender for Business experience, so getting Plan 2 means licensing every user for Plan 2 and contacting Microsoft Support to request the switch. Plan that before a hiring push.
Does it cover servers?
Not with the base licence. There is a separate per-server subscription that requires Defender for Business or Business Premium in the tenant, and above 60 servers Microsoft directs you to Defender for Endpoint Server or Defender for Servers instead. Budget servers separately from seats.
Is it really enough to replace a third-party suite?
For most small organisations, yes, and the reason is integration rather than detection. Defender is inside the operating system, so attack surface rules, tamper protection and device control reach places an add-on agent negotiates for, and alerts land beside your identity and mail signals. Stay with a specialist if you need one console across machines and network appliances, if your provider’s practice is built on another vendor, or if you run operating systems Microsoft no longer onboards.
Can our IT provider manage it across several clients?
Yes, through Microsoft’s multi-tenant tooling for partners, and Defender for Business is designed to integrate with the remote monitoring and professional services tools providers already use. Ask your provider how they will actually work the alerts, and on what schedule, before you switch.
