Microsoft Defender Suite for Business Premium: stronger protection, with people watching it.

Your business runs on email, shared documents, connected devices and people who need to work from anywhere. Protecting all of that takes security that works together, and people who know what to do when it spots something suspicious. We configure the Defender Suite properly, monitor it through our Defender Monitoring as a Service, and back that with Barracuda's Security Operations Centre.

Adds to Microsoft 365 Business Premium Configured, then monitored, not just licensed Barracuda SOC cover 24/7/365

Who this is for

Businesses already on Microsoft 365 Business Premium that want to strengthen their security without building an internal security team. Typically 20 to 250 people, remote or hybrid, with client data worth protecting, or with an insurer, customer or regulator asking about detection and response.

Building on Business Premium's strong foundations

Microsoft 365 Business Premium already includes valuable protection for devices, email, identities and business information. Microsoft Defender Suite for Business Premium is an additional subscription that extends those capabilities with more advanced detection, investigation and response across your organisation.

For businesses that want to strengthen their security without building an internal security team, it is a compelling next step. With Black Sheep Support handling implementation and providing ongoing monitoring backed by Barracuda SOC, those capabilities become part of a managed approach to protecting your business.

Source: Microsoft's suite overview

Better protection against phishing and malicious email

A convincing email can put a busy employee under pressure to click, open an attachment or hand over sensitive information.

Microsoft Defender for Office 365 Plan 2 builds on the email protection in Business Premium. Safe Links, Safe Attachments and impersonation protection help defend against dangerous content, while the additional investigation and automation tools help security teams understand and respond to attacks.

  • Automated investigation and response, helping investigate suspicious activity and identify remediation actions.
  • Threat Explorer and campaign insights, giving investigators a clearer view of malicious messages and related attacks.
  • Attack simulation training, allowing realistic phishing exercises that help staff recognise warning signs.

Source: Microsoft Defender for Office 365 features

Advanced security for business devices

Laptops and desktops hold valuable information and provide access to the systems your business depends on.

The suite includes Microsoft Defender for Endpoint Plan 2, adding capabilities such as advanced threat hunting and live response. These give security specialists more ways to investigate suspicious behaviour and understand what happened on an affected device.

Getting the intended protection also requires the right licensing and configuration. Microsoft documents specific considerations when moving from Defender for Business to Defender for Endpoint Plan 2, another reason to have the deployment handled carefully.

Source: Microsoft's upgrade overview, Licensing guidance

Stronger protection for accounts and access

A stolen password can give an attacker a foothold inside a business.

Microsoft Entra ID P2 adds identity risk capabilities that help identify potentially compromised accounts and suspicious sign-ins. Risk-based access policies can require additional verification or block access when the circumstances warrant it. Privileged Identity Management also helps control powerful administrator permissions, including limiting when those permissions are active.

The suite also includes Microsoft Defender for Identity, extending identity threat detection into supported identity infrastructure. For businesses with on-premises Active Directory, this adds another valuable layer of visibility into potential compromise.

Source: Microsoft Entra licensing and capabilities, Microsoft's suite overview

Visibility into cloud applications

Staff can start using new cloud tools long before IT knows about them. That can make it harder to understand where company information is going and who can access it.

Microsoft Defender for Cloud Apps helps discover cloud application use, assess risks and identify suspicious behaviour. It also provides controls for supported applications and sessions, helping businesses make informed decisions about how cloud services are used.

Source: Microsoft Defender for Cloud Apps overview

The Black Sheep Support difference

Buying a licence is the beginning. The real value comes from making the protection work for your business.

A successful deployment needs the right users licensed, devices brought under protection, security policies configured and relevant services connected. It also needs a clear process for investigating alerts and deciding what happens next.

With Black Sheep Support, the focus is on turning those capabilities into practical protection: a considered implementation, monitoring that has a purpose, and support from people who understand your environment. That matters because security settings affect everyday work. The aim is to protect your business while helping your team stay productive.

Defender Monitoring as a Service, backed by Barracuda SOC

Our Defender Monitoring as a Service adds ongoing oversight of the alerts and incidents the suite produces, backed by Barracuda's Security Operations Centre.

Barracuda provides 24/7/365 security operations, bringing specialist analysts, threat investigation and response guidance to supported, connected systems. Its published integrations include Microsoft Defender for Endpoint and Microsoft 365 Defender, supporting endpoint investigations and visibility into email alerts, incidents and events. Monitoring coverage and available response actions depend on the services connected and the agreed service scope.

For your business, that means expert attention beyond the working day and a clearer route from a security alert to an informed response.

Source: Barracuda SOC services, Barracuda Microsoft integrations

What is included

Microsoft Defender for Office 365 Plan 2

Safe Links, Safe Attachments and impersonation protection, plus automated investigation and response, Threat Explorer, campaign insights and attack simulation training.

Microsoft Defender for Endpoint Plan 2

Advanced threat hunting and live response on laptops and desktops, so an affected device can be investigated and contained rather than just reimaged.

Microsoft Entra ID P2

Identity protection with risk-based conditional access, and Privileged Identity Management so administrator rights are active only when they are needed.

Microsoft Defender for Identity

Identity threat detection extended into on-premises Active Directory where you still have it.

Microsoft Defender for Cloud Apps

Discovery of the cloud applications staff actually use, risk assessment, and controls over supported apps and sessions.

Implementation and monitoring by us

Users licensed, devices onboarded, policies configured and services connected, then watched: Defender Monitoring as a Service in the hours on your quotation, Barracuda SOC around the clock.

What is not included, and why

  • Microsoft 365 Business Premium itself. The suite is an add-on to Business Premium, which every user in scope must hold. Both are shown as their own lines on the quotation.
  • Prevention guarantees. Monitoring detects and escalates; no service can promise that every threat is caught, or caught in time. Coverage and response actions are those stated in your quotation and onboarding documents.
  • Forensic investigation and full incident recovery. Escalation and pre-authorised containment are included; a full investigation or rebuild is scoped and quoted when it happens, and you will know before it starts.

What it costs

The Defender Suite is a per-user monthly Microsoft subscription on top of Business Premium, billed at the price on your quotation. Defender Monitoring as a Service is £16 per user per month, excluding VAT. Barracuda SOC, for 24/7 cover, is priced per user per month and available on request: get in touch or book a call. Implementation is quoted as a fixed piece of work based on users and devices.

How it starts

  1. 1Free IT Health CheckA short online check that benchmarks your security and business risk and tells you where you stand.
  2. 2Discovery callAn engineer, not a salesperson. What you have, what is broken, what it would cost to fix, in writing.
  3. 3OnboardingEverything moves across on a plan, with no gap in cover and nothing lost.

Questions people ask before signing

What does the Defender Suite add to Business Premium?

Business Premium includes Defender for Business, Defender for Office 365 Plan 1 and Entra ID P1. The suite upgrades these to Defender for Endpoint Plan 2, Defender for Office 365 Plan 2 and Entra ID P2, and adds Defender for Identity and Defender for Cloud Apps. In practice: deeper investigation tools, automated response, risk-based sign-in policies, control of admin rights, and visibility of cloud app use.

Do we need the suite, or is Business Premium enough?

For many small businesses Business Premium, configured properly and monitored, is enough. The suite earns its keep where the data is worth a targeted attack, where staff are widely remote, where you still run Active Directory, or where an insurer or customer expects detection and response capability. We will tell you which you are on a discovery call.

What is Defender Monitoring as a Service?

Our engineers monitoring the alerts and logs from Microsoft Defender and Microsoft 365 for your tenant, triaging the noise, investigating the real ones and escalating to your nominated contacts under a procedure agreed at onboarding, during the hours on your quotation.

Where does Barracuda fit?

Barracuda's Security Operations Centre provides the 24/7/365 layer: analysts watching connected Defender for Endpoint and Microsoft 365 Defender alerts overnight and at weekends, with investigation and response guidance. We resell and coordinate it, so escalation still comes to you through the same agreed procedure.

Will the security settings get in the way of work?

They can if they are switched on carelessly, which is why implementation matters. Policies are introduced in stages, tested with a pilot group, and tuned so that the protection is real and the interruptions are rare.

How long does implementation take?

Typically two to four weeks for a business of 20 to 100 users, depending on how many devices need onboarding and whether Active Directory is in scope. Monitoring starts as soon as the first alerts are flowing.

Sources

  1. 1.Add Microsoft Defender Suite to Business Premium (Microsoft Learn)
  2. 2.Microsoft Defender for Office 365 overview (Microsoft Learn)
  3. 3.Microsoft subscription suites licensing guidance
  4. 4.Microsoft Entra ID licensing (Microsoft Learn)
  5. 5.Microsoft Defender for Cloud Apps overview (Microsoft Learn)
  6. 6.Barracuda SOC-powered managed XDR
  7. 7.Barracuda managed XDR integrations

Read before you call