Microsoft 365 Business Premium includes five security layers that the cheaper business plans do not: Microsoft Entra ID P1 for Conditional Access, Microsoft Defender for Office 365 Plan 1 for Safe Links and Safe Attachments, Microsoft Defender for Business for endpoint detection and response, Microsoft Intune Plan 1 for device management, and Microsoft Purview for sensitivity labels, data loss prevention and message encryption. Almost none of it protects anything until an administrator configures it.
That second sentence is the one that matters. Business Premium is the best-value security licence Microsoft sells to an Australian business under 300 seats, at AU$32.90 per user per month ex GST on an annual commitment (checked September 2026). It is also the licence Frontrow most often finds paid for and switched off. This guide lists what the subscription entitles you to, what each capability does, what it does not cover, and how to check the state of your own tenant.
Included, enabled, configured, monitored: the four states
Most arguments about Microsoft 365 security are really arguments about which of four states a control is in. Separating them is the single most useful thing an owner or an internal IT lead can do before reading any entitlement list, because a licence audit answers only the first question.
| State | What it means | How it goes wrong |
|---|---|---|
| Included | The capability is in the subscription you pay for each month. | Nothing happens. A licence is a right to use a feature, not a feature in use. |
| Enabled | Someone has turned the capability on in the tenant. | Defender for Business is licensed but no device has ever been onboarded to it. |
| Configured | The settings match how your business actually operates and who your risky users are. | Conditional Access exists but excludes a group that quietly grew to cover half the company. |
| Monitored | Someone reads the alerts, and someone would notice if the control stopped working. | An endpoint detection and response alert fires on a Friday and is opened the following Wednesday. |
Buying Business Premium moves every capability below into state one. Everything after that is work. When a cyber insurer or a tender questionnaire asks whether you have multifactor authentication, endpoint detection and response or data loss prevention, they are asking about state three or four, and answering from the licence sheet is how businesses end up making a claim that does not hold.
What Business Premium adds over Business Basic and Standard
Every Microsoft 365 business plan with a cloud mailbox gets the built-in email protections: anti-spam, anti-malware and anti-phishing spoof protection, quarantine, zero-hour auto purge, and security defaults for multifactor authentication. Those are genuine protections and they are on by default in tenants created since late 2019. The table below covers what changes when you move up to Premium, drawn from Microsoft's own business security best-practice matrix.
| Capability | Business Basic | Business Standard | Business Premium |
|---|---|---|---|
| Security defaults (baseline MFA) | Yes | Yes | Yes |
| Built-in anti-spam, anti-malware, anti-phishing (spoof) | Yes | Yes | Yes |
| Conditional Access (Microsoft Entra ID P1) | No | No | Yes |
| Defender for Office 365 Plan 1: Safe Links, Safe Attachments, impersonation protection | No | No | Yes |
| Microsoft Intune Plan 1 (device and app management) | Basic Mobility and Security only | Basic Mobility and Security only | Yes |
| Microsoft Defender for Business (endpoint detection and response) | No | No | Yes |
| Microsoft Purview Data Loss Prevention | No | No | Yes |
| Sensitivity labels | No | No | Yes |
| Purview Message Encryption | No | No | Yes |
| Desktop Office apps installed on user devices | No | Yes | Yes |
The gap between Standard and Premium is almost entirely security and device management. A business that moved to Standard for the desktop Office apps and has been treating the difference as a nice-to-have is paying about AU$12 per user per month less and going without every layer in the list above.
The identity layer: Microsoft Entra ID P1
Business Premium includes Microsoft Entra ID P1, and the reason that matters is Conditional Access. Security defaults give every user multifactor authentication (MFA) with number matching, which stops the overwhelming majority of password-only attacks and is genuinely good for a small tenant. What security defaults cannot do is make a rule. Conditional Access can: require phishing-resistant MFA for administrators and finance staff, block legacy authentication protocols that cannot perform MFA at all, require a compliant or Entra-joined device for access to company data, or block sign-ins from countries the business never operates in.
Entra ID P1 also brings self-service password reset with writeback to on-premises Active Directory, MFA for on-premises applications, custom directory roles, administrative units and Entra Connect Health.
What P1 does not include: risk-based Conditional Access. Sign-in risk and user risk conditions are powered by Microsoft Entra ID Protection, which is a P2 feature, along with Privileged Identity Management and the full risky-users and risky-sign-ins reports. P1 tenants see a limited view of risky users with no details drawer and no risk history. Microsoft sells a Defender Suite add-on for Microsoft 365 Business Premium that carries Entra ID P2, which is the supported route for an SMB that needs those controls without moving to E5.
Try it
Check your Conditional Access baseline for the usual gaps
Score your policy set against the misconfigurations Frontrow finds most often in Australian tenants, including the half-finished migration off security defaults.
10 questions · 5 domains
Conditional Access Misconfiguration Self-Check
The five Conditional Access failure patterns we find in nearly every AU tenant. Score yours against each one and see which fixes will move the needle. Pick the option closest to how your tenant is configured today.
Domain 1
Report-only purgatory
Whether new policies move out of report-only mode within a defined window, or stay there forever (and therefore enforce nothing).
What's the maximum time a Conditional Access policy stays in report-only mode before promotion or removal?
Source: Microsoft Learn: Conditional Access policy report-only mode.
When was the last audit of which CA policies are in report-only versus enforced?
Source: Microsoft Learn: Manage Microsoft Entra Conditional Access policies; Microsoft Sentinel CA workbook.
Domain 2
Break-glass account hygiene
Whether emergency access accounts exist, are excluded from every Conditional Access policy, are alerted on use, and are tested.
How many emergency access (break-glass) accounts does your tenant have?
Source: Microsoft Learn: Manage emergency access accounts in Microsoft Entra ID.
When were the break-glass accounts last successfully tested?
Source: Microsoft Learn: Manage emergency access accounts; ASD Essential Eight Maturity Model — Restrict Administrative Privileges.
Domain 3
Device compliance trust assumption
Whether 'require compliant device' policies actually require Intune compliance, or just check that the device is Entra-joined.
Where you have a 'require compliant device' Conditional Access policy, is there an Intune device compliance policy that actually evaluates compliance?
Source: Microsoft Learn: Use compliance policies to set rules for devices you manage with Intune.
What proportion of devices accessing M365 are evaluated by an Intune compliance policy?
Source: Microsoft Learn: Microsoft Intune device enrolment; App protection policies overview.
Domain 4
Location-based bypass scope
Whether 'trusted location' or 'corporate IP' bypasses are scoped narrowly, or applied tenant-wide such that any office IP exempts users from MFA.
Are any of your CA policies set to bypass MFA when the user is on a 'trusted location' (e.g. corporate office IP)?
Source: Microsoft Learn: Using the location condition in a Conditional Access policy; Microsoft Zero Trust guidance.
How do you handle access from outside Australia for travelling staff?
Source: Microsoft Learn: Configure named locations in Microsoft Entra ID; Microsoft Entra ID Protection risk policies.
Domain 5
Legacy authentication blocking
Whether legacy authentication protocols (basic auth on IMAP, POP, SMTP AUTH, MAPI) are blocked tenant-wide.
Is legacy authentication blocked at the Conditional Access layer?
Source: Microsoft Learn: Block legacy authentication with Conditional Access; Microsoft retirement of basic authentication in Exchange Online.
Is SMTP AUTH enabled for any user mailboxes in your tenant?
Source: Microsoft Learn: Authenticated SMTP submission in Exchange Online; Disable SMTP AUTH for the entire organisation.
This is an indicative self-assessment. It is not a substitute for a tenant-level Conditional Access review. For verified results Frontrow Technology runs an in-tenant CA policy review and produces a remediated policy set.
The email layer: Defender for Office 365 Plan 1
Business Premium carries Defender for Office 365 Plan 1, which sits above the built-in mailbox protections that every plan gets. Plan 1 adds four things worth knowing by name.
- Safe Links: URLs in email, Office apps and Teams are checked at the moment the user clicks, not only when the message arrived. This is what catches a link that was harmless at delivery and weaponised an hour later.
- Safe Attachments: attachments are detonated in an isolated environment before delivery, and files in SharePoint, OneDrive and Teams are checked too.
- Impersonation protection: anti-phishing policies can be told which people and which domains matter, so a message from a lookalike domain claiming to be the managing director is treated differently from ordinary mail. Mailbox intelligence learns normal sender patterns for each user.
- Real-time detections and the email entity page: the investigation surface that lets an administrator see where a specific message went and what happened to it.
Plan 1 is not switched on by default in any useful sense. Microsoft's recommended route is the preset security policies at security.microsoft.com/presetSecurityPolicies. Standard protection is the baseline profile for most users; Strict protection is more aggressive and is intended for high-value targets such as executives and finance. Both are off until an administrator turns them on and assigns users. A third preset, Built-in protection, is on by default for every recipient and provides basic Safe Links and Safe Attachments only, which is why a tenant can look protected in a spot check while nobody is covered by Standard or Strict.
What Plan 1 does not include: attack simulation training, Threat Explorer, Threat Trackers, campaign views, automated investigation and response for email, and priority account protection. Those are Defender for Office 365 Plan 2, which comes with E5 rather than Business Premium. The quickest way to tell which plan a tenant holds is the Microsoft Defender portal: Plan 1 shows Real-time detections under Email and collaboration, Plan 2 shows Explorer.
The device layer: Defender for Business and Intune
Microsoft Defender for Business is the capability most often left in state one. It is a genuine endpoint detection and response (EDR) product built on the Defender for Endpoint engine, packaged for organisations up to 300 users, and it is included in Business Premium at no extra cost. Microsoft's own comparison puts it above Defender for Endpoint Plan 1 on the capabilities that matter after prevention fails.
| Capability | Defender for Business | Defender for Endpoint P1 | Defender for Endpoint P2 |
|---|---|---|---|
| Next-generation protection | Yes | Yes | Yes |
| Attack surface reduction | Yes | Yes | Yes |
| Endpoint detection and response | Yes (optimised) | No | Yes |
| Automated investigation and remediation | Yes | No | Yes |
| Automatic attack disruption | Yes | No | Yes |
| Vulnerability management (core) | Yes | No | Yes |
| Threat analytics | Yes (optimised) | No | Yes |
| Advanced hunting and six-month data retention | No | No | Yes |
| Microsoft Threat Experts | No | No | Yes |
| Simplified firewall and antivirus configuration | Yes | No | No |
| Server protection | Extra licence | Extra licence | Extra licence |
Two practical consequences. First, a 400-seat organisation on Microsoft 365 E3 has Defender for Endpoint Plan 1 and therefore no EDR, while a 30-person business on Business Premium has one; the cheaper licence is the stronger endpoint licence in that specific respect. Second, servers are never included. Windows and Linux server protection requires a separate licence under every plan in that table, which is the gap Frontrow finds most often in businesses still running a file server or a line-of-business application server.
Microsoft Intune Plan 1 is the other half of the device layer. It handles enrolment, compliance policies, application protection for personal phones, BitLocker and disk encryption policy, and the device compliance signal that Conditional Access reads when you write a policy requiring a managed device. Business Basic and Standard get Basic Mobility and Security instead, which manages mobile devices only and does not manage applications.
The data layer: Purview labels, DLP and message encryption
Business Premium includes the Microsoft Purview capabilities most small businesses need and few switch on. Sensitivity labels mark documents and emails, and can apply encryption and access restrictions that travel with the file after it leaves the tenant. Data loss prevention policies detect content such as credit card numbers, tax file numbers and Medicare numbers in email, Teams and SharePoint, and can warn the user or block the send. Purview Message Encryption lets a user send an encrypted message to an external recipient, either manually or automatically through an Exchange mail flow rule.
This layer is where the Australian regulatory obligations land. The Notifiable Data Breaches scheme requires an assessment within 30 days of becoming aware of a suspected eligible breach, and an organisation that cannot tell which documents held personal information has a much harder assessment. Sensitivity labels are also the control that makes Microsoft 365 Copilot safe to switch on, because Copilot honours the permissions and labels already applied to a file.
What Business Premium does not include on the data side: eDiscovery (Premium), Insider Risk Management, Communication Compliance and Customer Key. Those are E5-class capabilities, available to Business Premium tenants through the Purview Suite add-on rather than the base licence.
What Business Premium does not cover at all
Five gaps are worth stating plainly, because each one gets assumed into the licence by businesses that have not read the fine print.
- Backup. Microsoft replicates your data for availability and provides finite recycle bins. It does not take a restorable long-term backup. Microsoft 365 Backup is a separate pay-as-you-go product, and third-party immutable backup is a separate purchase again.
- Servers. Defender for Business covers workstations, Macs and mobile devices. Windows Server and Linux server protection needs an add-on licence.
- Security awareness training and phishing simulations. Attack simulation training is a Defender for Office 365 Plan 2 capability. Business Premium tenants use a third-party platform or an E5-class add-on.
- Risk-based identity protection and Privileged Identity Management. Both are Microsoft Entra ID P2, available through the Defender Suite add-on for Business Premium.
- Anyone watching the alerts. Automated investigation in Defender for Business resolves routine detections on its own, but genuine incidents queue in the portal waiting for a human. Nothing in the licence supplies the human.
How to check what is actually switched on in your tenant
Ten minutes with the right five screens tells you more than any licence report. An administrator with Global Reader can do all of these read-only, which is the right permission level for a check like this.
- 1Microsoft 365 admin center, Billing then Your products: confirm the subscription is Business Premium and count assigned versus purchased seats. Unassigned Business Premium seats are the cheapest security win available, because the capability is already paid for.
- 2Microsoft Entra admin center, Protection then Conditional Access: count enabled policies and check whether security defaults are still on. Zero enabled policies with security defaults off is the worst of both configurations. Open each policy's Users tab and read the exclusions out loud.
- 3Microsoft Defender portal, Email and collaboration then Policies and rules then Threat policies then Preset Security Policies: check whether Standard or Strict protection is toggled on and who is assigned. If both are off, Defender for Office 365 Plan 1 is doing Built-in protection only.
- 4Microsoft Defender portal, Assets then Devices: count onboarded devices against your headcount. A gap here means Defender for Business is licensed and not protecting the machines outside the list. Then check Reports for whether anyone has opened an incident in the last month.
- 5Microsoft Purview portal, Data loss prevention then Policies, and Information protection then Labels: check whether any policy or label exists and is published. An empty list means the data layer is entirely in state one.
Does buying Business Premium make you Essential Eight compliant?
No, and the distinction is worth being precise about because it comes up in tender responses and insurance questionnaires. The Australian Signals Directorate's Essential Eight is a set of eight mitigation strategies assessed at maturity levels zero to three, and maturity is assessed on implementation and evidence, not on entitlement. Business Premium supplies capabilities that map onto several strategies: Intune supports application control and patch management for operating systems and applications, Conditional Access and Entra ID support multifactor authentication and restricting administrative privileges, and Defender for Business supports the hardening controls.
A licence purchase moves none of those strategies off Maturity Level Zero on its own. The assessment asks whether the control is implemented across the whole environment, whether exceptions are documented, and whether there is evidence it held. Frontrow's Essential Eight scorecard walks the eight strategies in the ASD's own terms so the answer to a questionnaire reflects what is running rather than what was bought.
Try it
Score your Essential Eight position against the ASD maturity model
Eight strategies, maturity levels zero to three, in plain English. The output is the evidence gap, not a marketing score.
Score each of the 8 strategies
Where are you on the Essential Eight — honestly?
Eight strategies. Four levels each. Pick the statement closest to your reality today. We'll map it to the Microsoft 365 tooling that closes the gap.
What's your target Maturity Level?
Maturity Level 2 — most orgs' pragmatic target
- 01
Application control
Only approved applications can execute on workstations and servers.
- 02
Patch applications
Internet-facing apps, browsers, Office, PDF readers patched promptly.
- 03
Microsoft Office macros
Macros disabled unless from trusted locations and signed by a trusted publisher.
- 04
User application hardening
Web browsers and productivity apps hardened against the most common attacks.
- 05
Restrict administrative privileges
Admin accounts limited, separated and reviewed — the crown jewels of the tenant.
- 06
Patch operating systems
Operating system patches applied on a schedule that matches the risk.
- 07
Multi-factor authentication
MFA everywhere that matters — privileged accounts, remote access, important data.
- 08
Regular backups
Backups of important data, configuration and software — and restores you have actually tested.
Where to start if most of this is in state one
The sequence Frontrow runs for a Business Premium tenant that has never been configured, in this order, because each step reduces the blast radius of the next failure: finish the Conditional Access baseline and retire security defaults; turn on the Standard preset security policy for everyone and Strict for executives and finance; onboard every device to Defender for Business and confirm the count matches headcount; enrol devices into Intune with a compliance policy that Conditional Access can read; publish one sensitivity label and one data loss prevention policy covering the personal information your business actually holds; then decide who reads the alerts and on what cadence.
Most of that is configuration work rather than procurement, which is the good news in an environment where budgets are tight. The companion guide, the Microsoft 365 security checklist for small business, turns the sequence into a first-week plan with a verification step against each item.