Enquiries: +44 (0) 20 8584 1400

CONTACT

What Is Microsoft Defender for Business?

microsoft defender for business

If you run Microsoft 365 and someone has asked whether you still need a separate antivirus product, this guide is for you. It covers what Microsoft Defender for Business is, what’s in it, what it costs in the UK and where it stops.

Microsoft Defender for Business is Microsoft’s endpoint security product for organisations with up to 300 users. It’s built on Microsoft Defender for Endpoint and protects Windows, Mac, iOS and Android devices against ransomware, malware and phishing. You get it inside Microsoft 365 Business Premium, or as a standalone licence at £2.30 per user per month.

Microsoft Defender for Business is the version of Defender for Endpoint built for small and medium-sized businesses. It includes next-generation antivirus, endpoint detection and response, automated investigation and remediation, and vulnerability management for up to 300 users. It’s included in Microsoft 365 Business Premium and sold separately for other plans.

Who Should Use Defender for Business?

Any organisation with up to 300 users that wants enterprise-grade endpoint protection without an enterprise security team. Microsoft designed it for businesses that may not have a security specialist, so it ships with default policies and wizard-driven setup. If you have more than 300 users, Microsoft points you to Defender for Endpoint or Microsoft 365 E3 and E5 instead.

There are two ways to license it. Microsoft 365 Business Premium includes Defender for Business. If you’re on Business Basic, Business Standard or Office 365 E1, or you don’t use Microsoft 365 at all, you buy the standalone version. Our guide to Microsoft 365 licensing for SMEs explains where each plan stops. Transputec holds Microsoft Solutions Partner designations for Modern Work and Security, and runs Microsoft 365 tenant operations for over 350 UK organisations.

What Is Included in Defender for Business?

Defender for Business includes the whole of Defender for Endpoint Plan 1, some of Plan 2 and a few features built only for smaller organisations. According to Microsoft’s own Defender for Business overview, that means next-generation protection, attack surface reduction, endpoint detection and response, automated investigation and remediation, and automatic attack disruption.

In full, what is included in Defender for Business is:

  • Next-generation protection: Microsoft Defender Antivirus with cloud-delivered protection.
  • Attack surface reduction: the built-in rules. Custom rules need Microsoft Intune.
  • Endpoint detection and response (EDR): a record of what happens on each device, so an attack can be traced and stopped.
  • Automated investigation and remediation: alerts are investigated and cleaned up without a person on every one.
  • Automatic attack disruption: containment of an attack that’s already under way.
  • Vulnerability management: the core capabilities, the same ones Defender for Endpoint Plan 2 includes.
  • Threat analytics and a monthly security summary report.
  • Cross-platform support for Windows, Mac, iOS/iPadOS and Android, with up to five devices per user.
  • Simplified firewall and antivirus configuration for Windows, which only Defender for Business has.

What it doesn’t include: six months of data retention, 30 days of advanced hunting and Microsoft Threat Experts. Those stay in Defender for Endpoint Plan 2. Servers need their own licence, which we cover below.

Rolling Out Defender for Business? Get the Configuration Right

Transputec's Microsoft 365 services cover licence right-sizing, Intune device compliance and Conditional Access, and our managed detection and response service monitors Microsoft Defender for Endpoint 24/7 from a UK-staffed team. Talk to our team about the security work behind your endpoints.

Get a Strategic Consultation

Is Microsoft Defender Good Enough for Business?

For most organisations under 300 users, yes. Microsoft Defender for Business gives you antivirus, endpoint detection and response and vulnerability management in one licence. Where it falls short is usually the configuration and monitoring around it, and the devices it sits on, and those are yours to manage.

Three checks before you call it done:

  • Supported devices. Defender for Business manages Windows 10 and 11 Business, Pro and Enterprise, and the three most recent macOS releases. Windows 10 reached end of support on 14 October 2025, so a Windows 10 laptop with Defender on it is still an unsupported device.
  • Cyber Essentials. The NCSC’s Requirements for IT Infrastructure v3.3 (April 2026) says anti-malware software must be updated in line with vendor recommendations, prevent malware from running, prevent the execution of malicious code and prevent connections to malicious websites. Defender for Business can meet that control, provided real-time protection stays on and the device is onboarded and updating. Transputec holds Cyber Essentials Plus, and our guide to the 5 Cyber Essentials controls covers the other four.
  • Someone watching it. EDR produces alerts. If nobody reads them at 2am on a Saturday, the detection happened and the response didn’t. UK insurers ask for endpoint detection and response on their proposal forms, and our post on cyber insurance requirements explains what evidence they want.

Defender for Business vs Defender for Endpoint: What Is the Difference?

Defender for Business is the version for organisations with up to 300 users. Defender for Endpoint is the enterprise product, sold as Plan 1 and Plan 2, and it’s where Microsoft sends you above 300 users. Defender for Business has everything in Plan 1, some of Plan 2 such as EDR and automated remediation, and simpler setup.

The table below is based on Microsoft’s own comparison in its Defender for Business documentation:

CapabilityDefender for BusinessDefender for Endpoint Plan 1Defender for Endpoint Plan 2
Next-generation protection and attack surface reductionYesYesYes
Endpoint detection and response (EDR)Yes (optimised)NoYes
Automated investigation and remediationYesNoYes
Automatic attack disruptionYesNoYes
Vulnerability management (core capabilities)YesNoYes
Threat analytics and monthly security summary reportYes (optimised)NoYes
Six months of data retention and 30 days of advanced huntingNoNoYes
Microsoft Threat ExpertsNoNoYes
Simplified firewall and antivirus configuration for WindowsYesNoNo
Windows Server and Linux supportExtra licenceExtra licenceExtra licence

Two licensing rules matter here. Microsoft doesn’t support mixing the two products. If a tenant holds Defender for Business licences and Defender for Endpoint Plan 2 licences, everyone gets the Defender for Business experience until you license all users for Plan 2 and ask Microsoft Support to switch. And once you pass 300 users, Microsoft’s advice is to move everyone to a plan that includes Defender for Endpoint, such as Microsoft 365 E3 for Plan 1 or E5 for Plan 2.

How Much Does Defender for Business Cost?

Microsoft Defender for Business costs £2.30 per user per month on Microsoft’s UK price list, paid yearly on an annual subscription that auto-renews, before VAT. Each user licence covers up to five devices. Microsoft 365 Business Premium, which includes it, is £16.90 per user per month on the same terms, or £14.40 without Teams.

Defender for Business pricing looks different once you see what Business Premium adds for the extra £14.60 a user. According to Microsoft’s UK pricing page and its Defender for Business FAQ, the Business Premium security bundle adds:

  • Microsoft Intune for device management, which you also need for custom attack surface reduction rules.
  • Microsoft Entra ID P1, which Conditional Access needs. Standalone Defender for Business gives you security defaults.
  • Defender for Office 365 Plan 1 for email and file protection.
  • Azure Information Protection Plan 1, sensitivity labels and data loss prevention for email and files.
  • The Microsoft 365 apps, Exchange, SharePoint, OneDrive and Teams.

Servers are extra. Microsoft Defender for Business servers is an add-on: one licence per Windows Server or Linux instance, up to 60 per subscription, and you need at least one paid Defender for Business or Business Premium licence before you can buy it. Microsoft’s FAQ lists it at $3 per server instance, so ask your reseller for the sterling figure. Above 60 servers you move to Defender for Endpoint Server or Defender for Servers Plan 1 or 2. Our post on Microsoft 365 add-ons covers which extras are already in your plan.

Defender vs Third Party Antivirus: Should You Run Both?

No. Pick one and make it the primary antivirus. Microsoft’s answer to whether you can run non-Microsoft antivirus with Defender for Business is “technically, yes”, with a warning that real-time protection can end up switched off and the device shows as unprotected. On a device onboarded to Defender, a third-party antivirus pushes Microsoft Defender Antivirus into passive mode.

Passive mode matters because of what stops working. Microsoft’s antivirus compatibility guidance lists cloud-delivered protection, network protection, attack surface reduction rules, controlled folder access and potentially unwanted app blocking as off in passive mode. EDR keeps recording, and EDR in block mode can still remediate, but you’re paying for an endpoint platform and running it with several of its protections off.

The reverse is also true. If you already run a third-party EDR platform and your Microsoft 365 plan includes Defender for Business, running both doesn’t give you two full layers. Defender Antivirus stays passive, and Microsoft’s guidance says it can’t be moved back to active mode while another product is providing real-time protection. Decide which product is primary, remove the other, and check the state on each device with the PowerShell command Get-MpComputerStatus, which reports Normal, Passive or EDR Block Mode.

How Do You Set Up and Manage Defender for Business?

You assign licences in the Microsoft 365 admin centre, onboard devices and set policies in the Microsoft Defender portal, and use the Intune admin centre for mobile devices. Setup is wizard-driven and the default policies are designed to protect devices from day one, but they’re a starting point. Someone has to own the alerts that follow.

Four things from Microsoft’s requirements and FAQ that catch people out:

  1. Custom attack surface reduction rules and controlled folder access need Intune. Defender for Business alone gives you the built-in rules.
  2. Conditional Access needs Entra ID P1. Standalone Defender for Business includes security defaults; Business Premium includes P1.
  3. One web content filtering policy per organisation. You can’t set different rules for different teams.
  4. Your data has to sit in a supported region. The UK is one, alongside the EU, the US and Australia.

Then there’s monitoring. Defender for Business integrates with Microsoft 365 Lighthouse and exposes the Defender for Endpoint APIs, which is how a managed service provider watches it across many customers at once. Transputec’s MDR security services run 24/7/365 from a UK-staffed team and list Microsoft Defender for Endpoint among the platforms they monitor, with Microsoft Sentinel for the wider estate. If you’d rather keep it in-house, our Microsoft 365 services team handles licensing, Intune compliance and Conditional Access, and leaves the alerts with you.

Your Microsoft Defender for Business Checklist

Work through these before you call the rollout finished.

  1. Confirm your licence. Business Premium already includes Defender for Business; Basic, Standard and Office 365 E1 need the standalone add-on.
  2. Count users and servers: 300 users maximum, five devices per user, and one server licence per Windows Server or Linux instance, up to 60.
  3. Check every device is on a supported operating system. Windows 10 went out of support on 14 October 2025.
  4. Pick one primary antivirus. Remove the other, then confirm Defender Antivirus is in active mode.
  5. Onboard every device in the Defender portal and apply the default policies.
  6. Add Intune if you need custom attack surface reduction rules or controlled folder access.
  7. Turn on Conditional Access if you have Business Premium, and at least security defaults if you don’t.
  8. Decide who reads the alerts, at what hours, and what they’re allowed to do about them.
  9. Keep the monthly security summary reports. They’re useful evidence for the Cyber Essentials malware protection control and for cyber insurance questionnaires.

Conclusion

Microsoft Defender for Business is a full endpoint security platform priced for organisations under 300 users, and for most of them it’s the right choice: antivirus, EDR, automated remediation and vulnerability management for £2.30 a user, or included in Business Premium. The gaps are the ones Microsoft is open about. Servers cost extra, custom rules need Intune, and above 300 users you move to Defender for Endpoint.

What the licence doesn’t include is someone to run it. Transputec holds Microsoft Solutions Partner designations for Modern Work and Security, and our cyber security services include 24/7 UK-staffed detection and response across Defender for Endpoint and Microsoft Sentinel. The work is the configuration, the monitoring and the evidence that comes out of it, and that’s what we do.

If a Microsoft 365 renewal or a cyber insurance form has raised the Defender question, talk to us about the security work behind your endpoints.

FAQs

Yes. Microsoft 365 Business Premium includes Defender for Business, along with Intune, Entra ID P1 and Defender for Office 365 Plan 1. Business Basic, Business Standard and Office 365 E1 don’t include it, so on those plans you add the standalone licence at £2.30 per user per month, paid yearly.

Defender for Business is capped at 300 users and includes Defender for Endpoint Plan 1 plus some Plan 2 features, such as EDR and automated investigation and remediation, with simplified setup. Defender for Endpoint Plan 2 adds six months of data retention, 30 days of advanced hunting and Microsoft Threat Experts, and it’s the product Microsoft recommends above 300 users.

Not without an add-on. Windows Server and Linux instances need Microsoft Defender for Business servers, one licence per server instance and a maximum of 60 per subscription. Microsoft’s FAQ lists it at $3 per server instance. Beyond 60 servers, Microsoft points you to Defender for Endpoint Server or Defender for Servers Plan 1 or 2.

Microsoft’s answer is “technically, yes”, with a warning that real-time protection can end up switched off and the device shows as unprotected. On onboarded devices, Microsoft Defender Antivirus drops into passive mode, which turns off cloud-delivered protection, network protection and attack surface reduction rules. Run one primary antivirus and remove the other.

Yes, provided it’s configured and kept up to date. The NCSC’s Requirements for IT Infrastructure v3.3 (April 2026) says anti-malware software must be updated in line with vendor recommendations, prevent malware from running, prevent malicious code executing and prevent connections to malicious websites. Microsoft Defender for Business meets those points when real-time protection is on and the device is onboarded and updating. Transputec holds Cyber Essentials Plus itself.

This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.

Ready to experience the Transputec difference?

Turn IT headaches into operational strength. Book a free consultation and see exactly what we can streamline inside your business. 

Get a Strategic Consultation

Sonny Sehgal

CEO & Co-Founder

Since co-founding Transputec, Sonny has guided hundreds of enterprises through every major shift in technology- from the birth of the PC to the rise of Global Cloud and now Generative AI. Known for his “straight-talking” approach to cyber security and IT strategy, he provides the bridge between complex technical infrastructure and boardroom-level business outcomes.

Share Blog »

← Blogs

Contact

Get in Touch