Business Premium costs roughly twice what Business Standard does, and in most of the tenancies we look at, the difference is being used for approximately nothing. The applications work, email arrives and the entire security layer that justifies the price sits at its defaults.

Here is what is in there, what each part actually does and roughly what it takes to switch on.

1. Intune: device management

What it does. Lets you set conditions a device must meet before it can reach company data, push settings and applications to laptops without touching them and remove company data from a lost or departing device.

Why it matters. Almost every small business has staff reading work email on personal phones. Without device management there is no encryption requirement, no screen lock requirement, no route to remove access when somebody leaves and no way to respond to a phone left in a taxi beyond hoping.

The selective wipe is the feature worth understanding, because it is the one people fear. Configured properly, Intune removes the company mailbox and company files and leaves personal photographs, messages and applications entirely alone. Saying that clearly in your device policy converts most of the resistance.

Effort. A day to set up sensible compliance policies, then enrolment as people come through.

2. Conditional access

What it does. Applies rules based on circumstance rather than applying the same friction to everybody all the time.

Why it matters. It is the difference between security that people work around and security they barely notice. A sensible starting set:

  • Require multi-factor authentication for all users.
  • Block sign-in from countries you do not operate in.
  • Require a compliant device for administrative access.
  • Block access to sensitive resources from unmanaged devices.
  • Require reauthentication for risky sign-ins.

One rule of the trade: always keep a break-glass administrator account excluded from conditional access, with its credentials somewhere physical and its use alerted on. Locking yourself out of your own tenancy at four on a Friday is a formative experience.

Effort. Half a day, plus a fortnight in report-only mode before enforcing.

3. Defender for Office 365 and Defender for Business

What they do. The first checks attachments by opening them in isolation and checks links at the moment of clicking. The second is endpoint detection and response on your laptops and servers — not just signature-based antivirus but behavioural detection with an investigation trail.

Why it matters. Attackers routinely send a clean link and make it malicious after delivery, precisely to defeat scanning at the point of arrival. Click-time checking is the part that catches that.

Defender for Business is genuinely good enough that most small businesses running Premium can stop paying separately for endpoint protection, which frequently recovers a meaningful part of the price difference between Standard and Premium.

A surprising number of businesses pay for Business Premium and a third-party antivirus product, and use neither properly. Consolidating is usually both cheaper and better.

Effort. A few hours to configure policies, then ongoing attention to what it reports.

4. Sensitivity labels

What they do. Attach protection to a document rather than to the folder it happens to sit in, so a file marked confidential stays restricted after somebody emails it outside the business.

Why it matters. Folder permissions stop applying the moment a file is copied, downloaded or attached. Labels travel with the file.

Keep the scheme small. Three labels that people apply — Public, Internal, Confidential — beat seven that they ignore. And apply labels automatically where you can, because manual classification decays within months.

Effort. Half a day for a simple scheme, more if you want automatic classification.

What this adds up to

Configured properly, Business Premium answers most of what a client security questionnaire asks, covers the technical half of Cyber Essentials comfortably, and closes the gaps that most small-business incidents actually walk through.

Unconfigured, it is Business Standard with a larger invoice.

A sensible order

  1. Conditional access with MFA for everyone. Highest impact, half a day.
  2. Defender policies for mail and endpoints.
  3. Intune compliance policies and enrolment for phones first, then laptops.
  4. Sensitivity labels once the rest is settled.

Two to three days of work in total for a business of ten to thirty people, and it is the highest-return security spend available to most UK small businesses because the licence is already paid for.

If nobody in your business has the time or the appetite to do it, that is exactly what our security solutions service exists for. Ask us what is currently switched off in your tenancy — the review is quick and the answer is usually surprising.