For most SA small businesses, Microsoft 365 Business Premium is the security stack.

Alex Macklin
Alex MacklinJune 2026 · Director, InterIntra

The question I hear most often from SA businesses reviewing their IT spend is a variation of this: "We're already paying for Microsoft 365. Do we really need to pay separately for an antivirus, an MDM tool, and an email security product on top of that?"

Usually the answer is no — but only if they're on Business Premium and have actually configured the security features that come with it. That second condition is where most businesses are getting caught out.

What's actually included in Business Premium

Microsoft 365 Business Premium is currently priced at $34.55 AUD per user per month on an annual commitment (as of mid-2026). The plan most SA SMBs are on, Business Standard, is $16.10 per user per month on the same commitment. That $18.45/user/month gap is where the conversation needs to start, because Business Premium bundles the following security products that most businesses are buying separately:

The cost comparison is straightforward. Price up a 30-user business running Business Standard, a standalone EDR product, a standalone MDM solution, and a third-party email security gateway, then compare it to Business Premium. In most cases, upgrading to Premium and retiring the separate products comes out cheaper — sometimes significantly cheaper.

The catch: out of the box, these tools are not protecting you

This is the part that matters. Business Premium gives you access to all of those security tools. It does not configure them for you. The default state of a new Microsoft 365 tenant is not secure — Microsoft sets conservative defaults to avoid breaking things, not to maximise your protection.

Specifically: Defender for Business needs to be deployed and onboarded to your endpoints. Conditional access policies in Entra ID need to be designed and activated. Safe Links and Safe Attachments in Defender for Office 365 need to be turned on and tuned. Intune needs enrolment profiles created and policies applied. Azure Information Protection needs sensitivity labels defined and published.

None of this is automatic. If you're on Business Premium but no one has touched the security configuration, you have paid for a security stack that is sitting idle. This is more common than most businesses realise — and it's part of what our Microsoft 365 management work typically surfaces when we take over from another provider or run an initial assessment.

Essential Eight alignment

If your business is working toward ACSC Essential Eight compliance, Business Premium properly configured addresses several controls directly:

It doesn't cover everything. Application control and backup sit outside what Business Premium handles natively. But for a business starting from scratch on Essential Eight, Business Premium is the most efficient foundation we've found at this price point.

When Business Premium isn't enough

There are businesses where sticking with — or investing in — a separate security stack makes sense:

For everyone else — which is most SA businesses in the 5 to 200 seat range — the question is worth asking before you renew that Sophos or Acronis contract.

The practical starting point

If you're currently on Business Basic or Business Standard and paying separately for security tools, the first thing to do is price up the upgrade. The delta is around $10/user/month. Then add up what you're currently spending on Sophos, Webroot, a standalone MDM, or whatever email security product you're running. In most cases, the maths tells you to upgrade.

If you're already on Business Premium, the question is whether those security features are actually deployed. A managed services review can tell you in a few hours. We run a standard configuration assessment as part of onboarding that checks Defender deployment status, conditional access policies, Safe Links and Safe Attachments activation, and Intune enrolment coverage. Most of the time, something is missing.

The licensing cost is the easy part. Getting it configured correctly is where the value is.

Frequently Asked Questions

Business Standard gives you the Office apps, Teams, Exchange, and SharePoint. Business Premium adds a full security layer on top: Microsoft Defender for Business (EDR/antivirus), Intune (device management), Entra ID P1 (conditional access and MFA enforcement), Defender for Office 365 Plan 1 (email security), and Azure Information Protection Plan 1 (data classification and DLP). The productivity tools are identical. The difference is everything underneath that protects them.

Yes, for most SMBs it does. Microsoft Defender for Business, included in Business Premium, is a genuine endpoint detection and response (EDR) product — not just a basic antivirus. It includes threat and vulnerability management, automated investigation, and integration with the rest of the Microsoft security stack. For businesses running Sophos, CrowdStrike, or similar third-party EDR solutions, Business Premium is worth pricing up as a replacement, because the per-device cost savings are often significant.

Business Premium properly configured gets you a long way toward Essential Eight Maturity Level 1 and Level 2. It directly supports patch application (Intune manages patching policy), multi-factor authentication (Entra ID P1 with conditional access), application hardening (Defender policies), restricting admin privileges (Entra ID privileged access management), and Microsoft Defender. It doesn't cover everything in the Essential Eight — you still need to address application control and backup separately — but it's the most efficient starting point we've found for SA businesses working toward ML1 or ML2.

As of mid-2026, Microsoft 365 Business Premium is $34.55 AUD per user per month (excluding GST) on an annual commitment. Business Standard is $16.10 per user per month on the same commitment. The $18.45/user/month gap is the question to evaluate against what you're currently spending on separate security products. For a 20-user business paying for a standalone EDR product, Intune, and an email security gateway, the maths almost always favours Business Premium.

Talk to the team

Want to discuss this for your business?

Book a discovery call and let's talk through what's relevant to your specific situation.

Book a Discovery Call More Articles