In this guide
Basic, Standard or Premium: what is the difference?
All three plans are for businesses with up to 300 users. All three give you business email with a 50 GB mailbox, Teams, 1 TB of OneDrive storage per person, and Copilot Chat. Where they differ is in two things: whether you get the desktop Office apps, and how much security and device management is built in.
| Business Basic | Business Standard | Business Premium | |
|---|---|---|---|
| Office apps | Web and mobile versions only | Full desktop apps for PC and Mac (five devices per user) | Full desktop apps for PC and Mac |
| Email, Teams, OneDrive | Yes | Yes | Yes |
| Email protection | Built-in anti-spam, anti-malware and spoof protection (Exchange Online Protection) | Same built-in protection | Built-in protection plus Defender for Office 365 Plan 1: Safe Links, Safe Attachments, and impersonation protection against emails pretending to be your MD or your suppliers |
| Identity and sign-in | Entra ID Free: security defaults (MFA on by default) | Entra ID Free: security defaults | Entra ID P1: Conditional Access, so you can require MFA and a managed device for sensitive things, block sign-ins from countries you never trade with, and set different rules for admins |
| Device management | Basic Mobility and Security (a limited subset of Intune) | Basic Mobility and Security | Intune Plan 1: full management of Windows, Mac, iOS and Android; compliance rules; remote wipe; protect company data on personal phones |
| Endpoint security (laptops, desktops, phones) | Whatever antivirus you buy separately | Whatever antivirus you buy separately | Microsoft Defender for Business: next-generation antivirus, endpoint detection and response, attack surface reduction, automated investigation, vulnerability management |
| Data protection | Basic | Basic | Purview Information Protection and data loss prevention: sensitivity labels, encryption, rules that stop card numbers or personal data leaving by email |
| Other | Webinars, Clipchamp, Loop | Plus Windows Autopilot, Azure Virtual Desktop rights, Exchange Online Archiving | |
| UK price (per user/month, annual, ex VAT) | [TO CONFIRM against Microsoft's current UK list; approx. £4.60] | [TO CONFIRM; approx. £12.90 after the July 2026 change] | £16.90 (Microsoft UK, 10 Sep 2026); £14.40 without Teams |
Sources: Microsoft Learn, "Microsoft 365 for business security overview" (updated December 2025) and "Microsoft 365 for business overview" (May 2026); Microsoft UK Defender for Business page for the Business Premium price.
Who each plan suits
Business Basic is the right answer for people who genuinely only need email and Teams and work in a browser: front-line staff, a shared inbox, a part-timer who never opens Excel. It is not a defective product. It is a small one.
Business Standard is the classic "email and Office" plan, and for many years it was what a small business bought without thinking. It is still fine for a business that has strong security elsewhere and someone to manage it, or for businesses that need the desktop apps but have very few devices to look after.
Business Premium is the one to buy when the business owns laptops, holds client or personal data, has people working from home or on the move, or has to answer a supplier, insurer or Cyber Essentials questionnaire about how it protects itself. That is most businesses we meet, which is why the next section exists.
None of these is a legal requirement. Microsoft does not require you to buy Premium, and neither does any UK regulation. What follows is our professional recommendation, and we will tell you if we think it does not apply to you.
Not sure which of these applies to your business? Ask an engineer.
Book a Discovery CallWhat the additional Defender offering adds
The add-on is called Microsoft Defender Suite for Business Premium. Until late 2025 it was sold as "Microsoft 365 E5 Security for Business Premium", and you will still see that name in older quotes. It can only be added to Business Premium licences, and it is not the same thing as Defender for Business, which Premium already includes.
The simplest way to understand it: Business Premium gives you the "Plan 1" versions of Microsoft's security products. The Defender Suite upgrades them to the "Plan 2" versions used by large enterprises, and adds two products Premium does not have at all.
| Area | Business Premium includes | The Defender Suite upgrades it to | What that adds, in plain English |
|---|---|---|---|
| Devices | Defender for Business | Defender for Endpoint Plan 2 | Six months of investigation data instead of 30 days, threat hunting across every device, "live response" to a compromised machine, and coverage for IoT devices. For our SOC analysts, this is the difference between seeing an alert and being able to reconstruct what happened. |
| Email and collaboration | Defender for Office 365 Plan 1 | Defender for Office 365 Plan 2 | Automated investigation and response when a phishing email lands, Threat Explorer for tracing a campaign across every mailbox, and built-in phishing simulation training for staff. |
| Identity | Entra ID P1 | Entra ID P2 | Identity Protection: risk-based sign-in rules that step up MFA when a login looks wrong, and privileged access management so admins hold elevated rights only when they need them. |
| Identity threats | Not included | Defender for Identity (new) | Watches for the account-compromise techniques attackers use once they are inside, including against any on-premises Active Directory you still run. |
| Cloud apps | Not included | Defender for Cloud Apps (new) | Finds the unsanctioned SaaS your staff are using with company data ("shadow IT") and lets you control it. |
Source: Microsoft Learn, "Add Microsoft Defender Suite for Business Premium to your subscription" (September 2025, updated April 2026).
UK price: [TO CONFIRM. Microsoft does not publish a UK web price for the add-on; UK resellers list it at around £9.24 per user per month on an annual commitment (Nov 2025). Quote from the current CSP price list.]
Do you need it? Not to start. Business Premium, properly configured and monitored, is a strong baseline for a typical small business. The Defender Suite is the next step for businesses that hold sensitive data, run any on-premises Active Directory, face regulatory or insurer expectations for detection and response, or want the automation that makes a small security team look like a larger one. Because it is priced per user, it can be applied to the finance team and the directors first.
How the three layers fit together
Microsoft 365 Business Premium
- Desktop Office apps, email, Teams, OneDrive
- Entra ID P1 and Conditional Access
- Intune device management
- Defender for Business (endpoints)
- Defender for Office 365 Plan 1 (email)
- Purview Information Protection and DLP
Microsoft Defender Suite for Business Premium
- Defender for Endpoint Plan 2
- Defender for Office 365 Plan 2
- Entra ID P2 with Identity Protection
- Defender for Identity
- Defender for Cloud Apps
Configuration, management and 24/7/365 SOC monitoring
- Security review and baseline configuration
- Conditional Access, Intune, email and data policies
- Ongoing changes, reviews and reporting
- Alerts triaged and investigated around the clock
- Escalation and response [TO CONFIRM scope]
Grey: Microsoft products you license. Orange: the Black Sheep Support service that configures, manages and monitors them.
The most powerful part: Black Sheep Support
Buying the licence is the easy bit. Microsoft ships these tools with defaults that are safe to switch on, which is not the same as configured to protect a specific business. The work that turns a Premium licence into protection is ours, and it is the reason clients choose us over buying the same licences from a web form.
We're outstanding in our field for a reason: our engineers do this configuration every week, across many tenants, and we see which settings stop real attacks and which ones generate noise. [TO CONFIRM: proof points to insert here, e.g. certifications such as Cyber Essentials Plus or ISO 27001, Microsoft partner status, number of tenants under management, named client testimonials.]
What we configure [TO CONFIRM against our service scope]
- Identity and access. MFA for everyone with phishing-resistant methods for admins, Conditional Access policies that match how your people actually work (office, home, travelling), separate admin accounts, and a break-glass account that is tested.
- Devices. Every laptop and phone enrolled in Intune, disk encryption enforced, updates managed, compliance rules that block an out-of-date or unencrypted device from reaching company data, and a tested remote wipe.
- Email protection. The Defender for Office 365 preset policies applied and tuned, impersonation protection listing your directors and key suppliers, Safe Links and Safe Attachments on, and SPF, DKIM and DMARC set correctly so your own domain cannot be spoofed. You can check your domain's current state with our free domain security audit.
- Data. Sensitivity labels that match how you talk about information ("internal", "client confidential"), and DLP rules for the data you are most worried about losing.
- Policies and alerts. Alerting tuned so that a real incident is unmistakable and a false alarm does not wake anyone. The alerts are then routed to our SOC, which is the next section.
Why it has to be maintained
Microsoft changes these products monthly. New Conditional Access options appear, defaults shift, features are renamed, and every new starter, leaver and laptop is a change to your security posture. A configuration that was excellent in January is merely adequate by summer if nobody has touched it.
Our managed service keeps it current: changes are reviewed rather than accidental, new capabilities are adopted deliberately, joiners and leavers are handled the same way every time, and you get a plain-English report on where you stand. Secure Score, Microsoft's own measure of a tenant's configuration, is one of the numbers we track for clients over time. [TO CONFIRM: reporting cadence and format.]
Want a second opinion before you buy licences?
We will look at your tenant, tell you who would actually benefit, and what needs fixing first. An engineer, not a salesperson.
Why 24/7/365 monitoring matters
A Security Operations Centre, or SOC, is a team of people whose job is to watch the alerts your security tools produce, decide which ones matter, and act on the ones that do. The tools generate the signals; the SOC supplies the judgement and the urgency.
Small businesses have historically had no SOC at all. Defender, Entra and Intune generate alerts, but if nobody reads them at two in the morning the alert is a diary entry, not a defence. Attackers know this. Account takeovers and ransomware deployments cluster in the evenings, at weekends and over bank holidays precisely because that is when nobody is looking.
Our 24/7/365 SOC service closes that gap. In outline:
- Monitoring. Alerts from Defender, Entra ID and the wider Microsoft 365 tenant flow to our SOC platform around the clock. [TO CONFIRM: exact sources monitored, and whether the service requires Business Premium, the Defender Suite, or both.]
- Investigation. An analyst looks at the alert in context: is this the finance director logging in from a hotel, or an attacker with her password? Most alerts end here, closed as benign, without disturbing you.
- Escalation and response. Confirmed incidents are escalated to you and to our engineers according to an agreed procedure. [TO CONFIRM: containment actions the SOC is authorised to take directly, such as isolating a device with Defender, revoking sessions or disabling an account, versus actions that require your approval; response-time commitments; who is contacted and how.]
An illustrative out-of-hours incident
This scenario is illustrative. It is not a customer story.
It is 11:40 on a Saturday night. A member of staff, on holiday, taps a link in a text message that looks like a parcel notification and enters their Microsoft 365 password on a convincing fake page. Because MFA is enforced, the attacker cannot simply log in, so they try again and again, hoping the user approves a push notification by reflex.
Entra ID flags the unfamiliar sign-in attempts and the pattern of MFA prompts. The alert reaches our SOC within minutes. An analyst confirms the sign-ins originate from an address and country the user has never used, sees the failed MFA attempts, and escalates. Under the agreed procedure [TO CONFIRM], the account's active sessions are revoked and the password is reset so the stolen credential is useless, and the user is contacted on Sunday morning to re-enrol. An engineer checks the mailbox on Monday for forwarding rules or other tampering.
The point of the story is not that the attack was stopped, though in this case it was. It is that the alert was read, at 11:40 on a Saturday, by someone who knew what it meant. No system prevents every attack, and we will never tell you otherwise. Monitoring means that when something gets through, you find out in minutes rather than in the invoice fraud three weeks later.
Realistic business scenarios
Four situations we see in real businesses. Each one shows the Microsoft technology involved, the configuration it needs to actually work, and the part our managed service plays. None of these are customer stories and there are no invented statistics.
| Scenario | The technology | The configuration it needs | Our role |
|---|---|---|---|
| A convincing phishing email arrives asking the finance assistant to change a supplier's bank details. | Defender for Office 365 Plan 1: impersonation protection, Safe Links, Safe Attachments. Exchange Online Protection underneath. | Preset security policies applied; your directors and key suppliers listed for impersonation protection; DMARC on your own domain; staff know how to report a message. | We configure and tune the policies, maintain the impersonation lists as suppliers change, review reported messages, and (with the Defender Suite) use Threat Explorer to find and remove the same email from every other mailbox. |
| A compromised account: a password is phished or reused from another breach. | Entra ID P1 Conditional Access and MFA; Entra ID P2 Identity Protection with the Defender Suite. | MFA required for all users; sign-in risk policies; legacy authentication blocked; admin accounts separated. | Our SOC investigates the risky sign-in, and under the agreed procedure revokes sessions and resets credentials [TO CONFIRM]. Engineers check for mailbox rules and persistence afterwards. |
| A lost laptop left on a train with client files on it. | Intune device management with BitLocker enforcement; Conditional Access requiring a compliant device. | Every device enrolled and encrypted before it is handed out; compliance policy in place; a tested remote-wipe process; a clear reporting route for staff. | We enrol and encrypt devices, keep compliance policies current, and carry out the remote wipe and access revocation when a loss is reported. The data on the device is unreadable to whoever finds it. |
| Suspicious endpoint activity: a workstation starts encrypting files or running tools nobody installed. | Defender for Business: EDR, attack surface reduction, automated investigation and attack disruption. Defender for Endpoint Plan 2 with the Suite. | Attack surface reduction rules enabled in block mode; automated response set to act, not just notify; device groups defined so isolation is possible. | Our SOC sees the alert, confirms it, and the device is isolated from the network [TO CONFIRM: automatic vs analyst-initiated]. Engineers investigate the cause, restore from backup if needed, and close the gap that let it in. |
The common thread: in every case the technology already exists in the licence, the configuration is what makes it work, and the managed service is what turns an alert into an outcome.
Not sure which of these applies to your business? Ask an engineer.
Book a Discovery CallCost and value
There are three separate costs, and it helps to keep them apart.
- Microsoft licences. Business Premium is £16.90 per user per month on an annual commitment, excluding VAT, at Microsoft's UK price on 10 September 2026 (£14.40 without Teams). Monthly-commitment billing costs more. Basic and Standard are cheaper; confirm current figures against Microsoft's UK price list or ask us.
- Additional security licences. Microsoft Defender Suite for Business Premium, per user, only where it is justified [TO CONFIRM price]. Defender for Business servers if you still run Windows servers [TO CONFIRM price; a low per-server monthly add-on]. Microsoft 365 Copilot if you want it; see our Copilot guide.
- Our managed service. Configuration, ongoing management and SOC monitoring are priced separately from the licences, per user or per device. [TO CONFIRM: pricing model and starting price.] This is the cost that most often gets compared with "just buying the licence", so it is worth being clear about what it buys: the setup that makes the licence work, the people who keep it working, and someone reading the alerts at night.
Overlapping tools
Moving to Premium often means you can stop paying for things: a third-party antivirus, a separate email-security add-on, a device-management tool, a standalone password or MFA product, sometimes a backup product bundled with the old antivirus. We list these in the licence review. It is common for the removed subscriptions to offset a meaningful part of the Premium uplift, though we will not put a number on that until we have seen your invoices.
A transparent example (illustrative)
A 20-person business currently on Business Standard with a separate antivirus:
| Item | Assumption | Monthly |
|---|---|---|
| Moving 20 users from Standard to Premium | (£16.90 − Standard price [TO CONFIRM, approx. £12.90]) × 20 | approx. £80 |
| Antivirus subscription no longer needed | 20 devices × [TO CONFIRM: your current per-device cost, e.g. £3] | −£60 |
| Net licence change | approx. £20 | |
| Black Sheep Support management and SOC | [TO CONFIRM per-user price] × 20 | [TO CONFIRM] |
The honest summary: the licence uplift is usually smaller than people expect once overlaps are removed, and the managed service is the larger line. What you are paying for is not the software. It is the configuration, the maintenance and the monitoring, which is where the protection actually comes from.
We do not quote breach-cost statistics or "return on investment" for security. The value is a business that keeps trading when something goes wrong, and an honest answer to your insurer's and your customers' questions about how you protect their data.
What moving to our recommended setup involves
[TO CONFIRM: the steps below describe our proposed delivery process and should be checked against how we actually deliver.]
- Discovery call. How your business works, what you have today, what worries you. Outcome: a clear view of your current position and whether this is the right path.
- Licence and security review. We look at your tenant, licences, devices and existing security tools, and score the configuration against Microsoft's recommendations and our baseline. Outcome: a written report: what you have, what is missing, what overlaps, and a costed recommendation.
- Licence changes. Moving users to the right plans, removing overlapping subscriptions, timed around renewals where possible.
- Configuration. Identity, Conditional Access, Intune enrolment, email protection, data labels and alerting, applied in a staged order so nothing breaks on day one. We pilot policies with a small group before they go to everyone.
- Rollout to staff. Device enrolment, MFA re-registration where needed, a short briefing on what changes for them (usually: a new prompt or two) and where to get help.
- Onboarding to monitoring. Alerts connected to our SOC, escalation contacts and procedures agreed and tested.
- Ongoing management. Regular reviews, change control, joiner and leaver processes, and reporting.
Disruption, honestly
Most of this work is invisible to staff. The parts they notice are MFA prompts, device enrolment, and occasionally a policy that blocks something they used to do. We stage changes, pilot them, and give people a route to ask for help. We will not promise that every migration is seamless; older devices, unusual line-of-business applications and personal phones sometimes need individual attention. We will tell you where we expect friction before we start.
Want a second opinion before you buy licences?
We will look at your tenant, tell you who would actually benefit, and what needs fixing first. An engineer, not a salesperson.
Frequently asked questions
We already have Microsoft 365. Do we have to change our licences?
Not necessarily. The review looks at what you have and what you need. Some businesses stay on Standard with a mixed setup; most businesses holding client or personal data end up with Premium for the people who handle it. We will tell you if you do not need to change.
We already pay for antivirus. Is Defender for Business better?
Defender for Business, included in Business Premium, is built on Microsoft's enterprise endpoint product and includes detection and response, not just antivirus. Whether it is 'better' than what you have depends on what you have and how it is managed. It is usually at least as capable, it is already paid for, and it integrates with the rest of the tenant. Running two endpoint products at once is a bad idea, so we plan the switch.
Can we mix Basic, Standard and Premium in one business?
Yes, and many businesses should. The plans can be assigned per user. The important thing is that the line between them is deliberate: anyone who handles client, financial or personal data, or uses a company laptop, is on Premium.
What about remote and home workers?
This is where Premium earns its keep. Conditional Access and Intune are what let you require a managed, encrypted, up-to-date device and MFA before someone reaches company data from their kitchen table, and protect company data on a personal phone without managing the whole phone.
What does the SOC actually cover?
Alerts from your Microsoft 365 tenant, monitored around the clock, investigated by analysts, and escalated according to an agreed procedure. [TO CONFIRM: sources, response actions the SOC may take directly, response-time commitments, and whether the service requires the Defender Suite.]
Who manages the alerts, and who decides what to do?
Our SOC analysts triage and investigate. Confirmed incidents are escalated to our engineers and to your nominated contacts. Some containment actions may be pre-authorised in your service agreement so they can happen immediately; others wait for your decision. [TO CONFIRM which is which.]
Is Business Premium required for Cyber Essentials?
No. Cyber Essentials is about controls, not products. Premium makes several of those controls much easier to implement and evidence (MFA, device management, patching, malware protection), which is why we usually pair them, but you can be certified on other plans with the right tools. See our [Cyber Essentials guide](/guides/cyber-essentials).
Does the Defender add-on replace Defender for Business?
It upgrades it. Adding Microsoft Defender Suite for Business Premium moves your devices from Defender for Business to Defender for Endpoint Plan 2, your email from Defender for Office 365 Plan 1 to Plan 2, and Entra ID from P1 to P2, and adds Defender for Identity and Defender for Cloud Apps. It can only be added to Business Premium.
Do we still need backups if we have all this?
Yes. Microsoft 365 keeps deleted items for a period, but it is not a backup, and none of these security products restores your data after ransomware or an accidental mass deletion. A separate Microsoft 365 backup is part of our baseline. See our [Microsoft 365 backup guide](/guides/microsoft-365-backup).
What will the review conversation involve?
We will ask about your business, your people and devices, your current licences and security tools, and what keeps you up at night. From that we identify your current position, the gaps, and the appropriate next steps, whether or not that involves us.
Book a Microsoft 365 security and licensing review
You are probably already paying for more protection than you are using. Talk to an engineer about where you stand, what the gaps are, and what the right next step is for your business.
- Your current position: licences, devices, security tools and how they are configured.
- The gaps that matter, in plain English, and which ones are urgent.
- Whether Premium, the Defender Suite or a different approach fits you, with current prices.
- What managed configuration and 24/7 monitoring would involve for a business your size.
Sources
Prices and product facts on this page were checked against the following Microsoft pages on the dates shown.
- 1.Microsoft Learn: Microsoft 365 for business security overview (plan-by-plan security table) · accessed 10 September 2026
- 2.Microsoft Learn: Microsoft 365 for business overview (plan contents) · accessed 10 September 2026
- 3.Microsoft Learn: Add Microsoft Defender Suite for Business Premium to your subscription · accessed 10 September 2026
- 4.Microsoft Learn: What is Microsoft Defender for Business? (comparison with Defender for Endpoint P1/P2) · accessed 10 September 2026
- 5.Microsoft Learn: Why do I need Microsoft Defender for Office 365? (Plan 1 vs Plan 2) · accessed 10 September 2026
- 6.Microsoft Learn: Why choose Microsoft 365 Business Premium? · accessed 10 September 2026
- 7.Microsoft UK: Microsoft Defender for Business (UK prices for Defender for Business and Business Premium) · accessed 10 September 2026
- 8.Microsoft UK: Compare all Microsoft 365 for business plans (Basic and Standard prices; confirm) · accessed 10 September 2026
What has changed on this page
- 10 September 2026Page published. Compares Business Basic, Standard and Premium against Microsoft's current documentation, names the add-on correctly as Microsoft Defender Suite for Business Premium, quotes Microsoft's UK price for Business Premium (£16.90, checked 10 Sep 2026) and explains our configure-manage-monitor model.

