Start here
What Business Premium is #
Business Premium is the top tier of Microsoft's small business plans. If you are on Business Standard today, it is the next step up, and the difference is not what your staff see.
You already get the good bits of Microsoft 365: Word, Excel, Outlook, Teams, SharePoint, OneDrive. Business Premium includes all of that unchanged. Nobody has to learn anything new and nothing moves.
What it adds is the security and management layer: extra checking on your email, rules about who can sign in and from where, protection that watches for an attack rather than only known bad files, a safety net under your data, and the ability to manage your computers centrally. Without those we are advising; with them we are actually able to act.
Business Standard gives your team the software. Business Premium gives us the tools to look after it.
We recommend it to every customer we look after. There is a section further down setting out why, along with the objections we hear most often and our honest answers to them.
The detail
What you get on top #
Seven things. The names are Microsoft's and they are not helpful, so here is what each one is actually for.
| What Microsoft calls it | What it actually does |
|---|---|
| Entra ID P1 | Lets us set rules about sign in. Trusted person on a company laptop in the office gets waved through; the same account from an unrecognised device abroad does not. Also lets us stop sign ins from countries you simply do not operate in. |
| Intune | Central device management. New machines set themselves up, settings and software are pushed out automatically, and a lost laptop can be wiped remotely from wherever you are. |
| Defender for Business | Proper endpoint protection rather than plain antivirus. It watches for the behaviour of an attack rather than only known bad files, and it lets us cut a machine off the network from a dashboard if something is wrong. |
| Defender for Office 365 | Extra checking on email. Attachments are opened in a safe environment before they reach you, links are re-checked at the moment you click rather than only when the message arrived, and it learns to spot someone impersonating your directors. |
| Information Protection | Labels for sensitive documents, and rules that can spot company information heading somewhere it should not. It is the safety net under an honest mistake. |
| Exchange Online Archiving | Long term mail storage and retention. Mailboxes stop filling up, and you can keep or hold mail where you need to. |
| Autopilot and Windows 11 Business | New computers configure themselves the first time they are switched on, rather than being built by hand. It also includes Windows 11 Business upgrade rights, which add business features to a machine already running Windows Pro. |
The reason this is bundled rather than sold piecemeal is that the parts reinforce each other. Device management is what makes conditional sign in rules meaningful, because the system can tell a company laptop from an unknown one. On their own each piece is useful; together they are considerably more than the sum.
The Windows rights here upgrade a machine that is already on Windows Pro. They do not turn a Windows Home machine into a Pro one, and Home cannot be centrally managed. If any of your computers came from a high street shop they are quite likely on Home, and upgrading those is a separate purchase. We will tell you which of yours are affected before you commit to anything.
The detail
What changes day to day #
The feature list is abstract. Here is what it looks like in the actual week to week running of a business.
An email arrives that looks like it is from your MD
Asking accounts to pay a new supplier, or to change the bank details on an existing one. This is the most common way money leaves a business that did not intend to send it.
Business Premium learns what genuine internal mail looks like and flags the impersonation. It is not infallible, but it turns a convincing message into one carrying a visible warning, which is usually enough for somebody to stop and check.
Somebody enters their password into a fake sign in page
It happens to careful people. The difference is what the attacker can do next.
With conditional access, a working password is no longer enough on its own. A sign in from an unrecognised device, or from a country you do not operate in, gets blocked rather than waved through. The stolen password becomes a nuisance instead of an incident.
Something nasty lands on a machine anyway
Ordinary antivirus checks whether a file is already known to be bad. Defender for Business watches for behaviour instead: files being encrypted in bulk, credentials being harvested, one machine reaching for another.
That means problems get spotted while they are still one machine rather than all of them, and we can isolate that machine from the network remotely while we deal with it.
The salary spreadsheet goes to the wrong Dave
Autocomplete picks the wrong contact and something confidential goes to someone outside the company. Nobody did anything malicious and everybody is mortified.
Information protection puts a check in the way: a warning before it goes, or a block, depending on how you want it set. It is the safety net under an honest mistake, and honest mistakes are far more common than attacks.
Signing in gets less irritating
This is the one people do not expect. Because the system can recognise a managed company device, we can relax the prompting on those and tighten it everywhere else. Staff on their normal machine get asked for a code less often, not more. Better security and less friction usually pull in opposite directions; this is one of the rare cases where they do not.
A new starter begins on Monday
Instead of us building a machine by hand, a laptop is shipped still sealed. They switch it on, sign in, and it configures itself: policies, software, printers, the lot. They are working that morning, and it is the same on the tenth machine as the first. There is a full guide at Your Intune migration.
A laptop is left on a train, or somebody leaves
The laptop can be wiped remotely, and we can demonstrate it was encrypted at the time, which matters a great deal if you ever have to explain the incident to the ICO or to a customer. For a leaver, company data can be removed from their personal phone without touching their photos.
Mailboxes stop being a problem
Archiving means the long running mailbox that has been nagging someone for two years simply stops being an issue, and you can set retention properly rather than relying on people to tidy up.
It is easy to think of this as being about device management, because that is the most visible part. Most of the value is actually in the email checking, the sign in rules and the data protection, and those apply just as much to somebody who never leaves their desk.
The detail
Insurance, certification and winning work #
There is a commercial case as well as a technical one, and for a lot of businesses it turns out to be the one that actually decides it.
Cyber insurance
Insurers have tightened up considerably. Renewal questionnaires now routinely ask whether you enforce multi-factor authentication, whether you run managed endpoint detection, whether backups are tested, and whether you have a documented incident response plan.
With Business Premium properly configured, most of those answers are a straightforward yes, and you can demonstrate it. That tends to make renewal easier and, more importantly, means what you have declared on the form matches what you actually have.
Cyber Essentials
The scheme looks at secure configuration, access control, patching, malware protection and firewalls. Business Premium makes most of that straightforward to implement and, crucially, easy to evidence. It is possible to certify without it, using a combination of third party tools and manual work, but it is noticeably more effort every year.
Customer security questionnaires
If you sell to larger organisations, to the public sector, or into regulated industries, you have probably started seeing security questionnaires attached to tenders. They ask exactly the questions this licence answers well: do you enforce MFA through conditional access, can you remotely wipe a lost device, do you have endpoint detection and response.
Being able to answer yes is increasingly the difference between staying in a procurement process and being filtered out of it early. We have seen this decide contracts.
Dig out your last cyber insurance renewal form and the last customer security questionnaire you filled in. If there were questions you had to answer no to, or answer vaguely, that is the most honest test of whether this is worth it for you. Happy to go through them with you.
The decision
How to think about the cost #
It costs more per person per month than Business Standard. There is no getting around that, so it is worth being clear about what you are comparing it to.
The comparison people usually make is against their current bill, which makes it look like a straight increase. The more useful comparison is against what it would cost to get the same capability separately: a third party endpoint detection product, a mobile device management platform, an email security gateway, an archiving product, and the time to run four consoles instead of one.
Bought that way it is normally more expensive, and it is certainly more work. That is the actual alternative, rather than doing without.
Tell us your headcount and we will give you the real number for your organisation, including anything that changes at your renewal date. We would rather you saw an accurate figure than a general one.
It needs to be everybody
We quote it for your whole company rather than for a selection of people, and that is deliberate. Security that covers most of the organisation is not most of the benefit. An attacker needs one account, and the unprotected one is the one they will find.
It also stops being coherent to manage. Half your machines enrolled and half not, sign in rules that only apply to some people, email protection that covers part of the company: that is harder to run than either extreme and it is difficult to answer an insurer or an auditor honestly about.
The decision
Who we recommend it for #
Everybody. We recommend Business Premium to every customer we look after, and we would rather say that plainly than hedge it.
That is not a sales position, it is what we have concluded from doing this work. The protections here are not really about laptops or remote working. They are about email, sign in and data, and every business has all three regardless of how or where its people work.
The objections we hear, and our honest answers
| What people say | What we would say back |
|---|---|
| We are only a handful of people | Small businesses are targeted more, not less, because attacks are automated and indiscriminate. Nobody picks you off a list. A small team also feels an incident far harder, because there is no spare capacity to absorb a week of disruption. |
| We all work in one office on desktops | Then device management matters less to you, and that is one of seven things. The impersonated invoice, the phished password and the misdirected spreadsheet all still happen at a desk. |
| We have nothing worth stealing | Most incidents are not about stealing your data. They are about using your mailbox to invoice your customers, or encrypting your files and asking you to pay to get them back. Your business running is the thing of value. |
| We already have antivirus | Worth comparing properly, and we will do that honestly. Antivirus covers one of the seven areas, and generally the one attackers have most practice at getting past. |
| Nothing has ever happened to us | Genuinely good, and worth saying. It is also the reasoning behind most of the incidents we get called into, which tend to arrive after a long quiet period rather than instead of one. |
Say so, and we will talk about it properly rather than repeating the recommendation. There is often something to reclaim by dropping tools it replaces, and licence counts can be reviewed at renewal.
What we will not do is quietly recommend half of it to make the number look better. Covering some of your people leaves the gap an attacker needs and makes the whole thing harder to run and to evidence. If the answer this year is not yet, we would rather that were an honest not yet than a watered down yes.
That is your call to make and we will respect it without raising it every month. We will ask you to acknowledge the decision in writing, which is simply so there is a clear record of what was recommended and what was chosen, and we will revisit it at your next review or if something changes. In the meantime we will make the most of what you do have and be straight with you about where the gaps are.
Practicalities
What moving to it involves #
The licence change itself is trivial. The value comes from the configuration afterwards, which is a small project rather than a switch.
- We change the licences Quick, and invisible to your staff. Nothing stops working and nobody needs to do anything. At this point you have the capability but not yet the benefit.
- We sort out identity first Multi factor authentication, conditional access rules, and tightening up administrative accounts. This is the highest value part and the least disruptive, so it goes first.
- We turn on the email and endpoint protection The extra checking on attachments and links, impersonation protection, endpoint detection and archiving. This is mostly invisible to your staff and mostly immediate, which makes it the best value stage for the least disruption.
- We bring devices under management Existing machines are enrolled, and new ones start setting themselves up. This is the longest stage and the most visible, and there is a whole guide on it at Your Intune migration.
- We look at data protection with you Labels and data loss rules need to reflect how your business actually works, so this is a conversation rather than something we can simply switch on. It usually comes last, once everything else has settled.
None of this has to happen in one go. Plenty of customers do identity first, live with it for a couple of months, then move on to devices. Spreading it out makes it easier on everybody and gives each stage time to bed in.
That is about the pace of the work, not about who is covered. Everybody is licensed from the start; the stages just decide what gets switched on when.
Support
Common questions #
Will our staff notice any difference?
Very little, and what they do notice tends to be positive. The apps are identical. Over time they get asked for authentication codes less often on their work machines, new laptops arrive ready to go, and email gets marginally cleaner. Device management is the one thing they may notice, and only as their machine being set up for them rather than by them.
Do we have to do everyone?
Yes, and we would rather be straightforward about that than sell you something that only half works. An attacker needs one account, and a part covered company is also considerably harder to manage and to evidence to an insurer. See How to think about the cost.
The rollout can be spread over time, and usually is. That is different from covering only some of your people.
We already pay for antivirus and a backup product. Is this duplication?
Possibly, and that is worth working out before you decide. Business Premium may let you drop one or two things you currently pay for separately, which changes the real cost of moving. Tell us what you have and we will do that comparison honestly, including telling you where your existing product is the better one.
Our support package already includes EDR. Is this the same thing?
No. The endpoint detection included in our support packages is a specialist product we deploy and monitor for you. Defender for Business is Microsoft's own, and it comes with the licence rather than with us. They solve a similar problem in different ways.
If you have both, ask us and we will tell you straight whether you are getting value from both or whether one should go. We would rather have that conversation than have you assume you are paying twice.
Does this replace our backups?
No, and please do not treat it as though it does. Microsoft 365 is not a backup of itself. You still want a proper backup of your mail, SharePoint and OneDrive, and we would say the same regardless of which licence you are on.
Can we see it working before we commit?
Ask us and we will show you, on our own systems or on another customer's with their permission, rather than describing it. What we would avoid is a long trial on a handful of your people, because the parts that matter most are the ones that only work when everybody is covered, so a small sample tends to undersell it.
What if we move and decide it was not worth it?
Licences are not permanent and can be changed at your renewal point. In practice the part people would miss is the device management, because going back to building machines by hand is a noticeable step backwards once you have stopped.
Does it need new hardware?
Generally no, though machines do need to be running Windows Pro rather than Home. If any of yours are on Home we will tell you which, and there is a cost to upgrade them. Worth knowing before you budget rather than after.
Talk it through with us
The most useful next step is usually a short conversation about your actual situation: how many laptops leave the building, what your insurer asked you last time, and whether customers are sending you security questionnaires. That tells us whether this is genuinely worth your money, and we will tell you straight if it is not.