You are probably paying for more Microsoft security than you have ever switched on.
Assess enough tenants and the pattern stops varying. The problem is never a product nobody bought. It is a product nobody finished configuring. Defender licensed and sitting in monitor mode two years later. Three conditional access policies and an exclusion group that keeps quietly growing. Purview purchased for a compliance push that died at the classification stage. Entra P2 on the invoice while every administrator still holds permanent rights. Before we recommend buying anything, we tell you what the subscription you already renew actually includes, because for most American companies the fastest available improvement carries no cost at all.

- License-firstUse what you already own
- 5 minP1 response for managed clients
- 24/7Coverage on managed engagements
- FreeTenant security assessment
Six things we do before anyone mentions a new license.
Establish what your license already includes
The security capability inside Business Premium, E3, and E5 differs enormously, and almost nobody can describe their own accurately. We map what you are entitled to against what is genuinely deployed and hand back three lists: what you pay for and never touch, what you use but do not need, and what you are actually missing. That single document tends to reshape the budget conversation, because the honest answer very often turns out to be that no new licensing is needed this year at all.
Close the identity basics first
Multi-factor enforced on every account, administrators very much included. Legacy authentication blocked outright. Administrative accounts kept separate from the mailbox somebody reads email in. Emergency accounts that genuinely exist and raise an alert whenever they are used. Phishing-resistant methods for anyone privileged. None of this requires a purchase order, all of it closes the routes attackers actually take, and it is incomplete in the overwhelming majority of tenants we look at.
Get Defender doing what it was bought for
Every device onboarded, not most of them. Attack surface reduction rules moved out of audit and into enforcement after a genuine tuning period rather than on day one. Automated investigation actually configured. And alerts landing somewhere a person will read them. Licensed and unconfigured, Defender is an expense line rather than a control.
Classification before data protection
Loss prevention, retention, and insider risk in Purview all rest on classification existing first, and none of them work without it. We deploy a deliberately small set of labels that people will genuinely apply, let automatic labeling carry most of the load, and then build protection around the labels that actually matter. The ambitious taxonomy designed in a two-day workshop stalls before deployment every single time.
Make sure somebody is watching
Detecting without responding leaves you with an expensive log file. We connect the estate to monitoring, tune away the noise that causes people to stop reading alerts, and pair the detection with response cover at any hour, either through our own managed service or by backing your internal team. This is the step companies skip most often and regret most often.
Produce evidence continuously, not annually
Multi-factor coverage, privileged access reviews, how current patching is, whether loss prevention actually ran, incident records, and access recertification, all kept as a standing pack rather than assembled in a panic the week before fieldwork. SOC 2 auditors, cyber carriers, HIPAA assessors, and enterprise customers now ask overlapping versions of the same questions, and answering from a maintained document beats reconstructing the year from memory.
Which product does what, and where to read more.
Identity, the perimeter that actually matters
When most people are not on an office network most of the time, the account itself becomes the perimeter. This is where the majority of successful attacks on American companies start.
- Microsoft EntraConditional access, just-in-time administrative rights, risk-based identity protection, and the P1 against P2 licensing question.
- MFA solutionsRolling out multi-factor, and why a plain approval prompt has stopped being enough by itself.
- Entra Conditional AccessThe policy engine that decides who gets in, from where, on what device, and under what conditions.
- Entra Identity ProtectionRisk-based detection of compromised credentials and risky sign-ins, acted on automatically.
- Privileged Identity ManagementStanding admin rights replaced with just-in-time elevation, approvals, and an audit trail.
- Active DirectoryThe directory still sitting in your server room, hybrid identity, and the attack paths that continue to run straight through it.
Endpoint and device threat protection
Catching what reaches the endpoint, stopping it, and knowing fast on the occasions something got past.
- Microsoft DefenderWhich Defender product is which, and how the family fits together across your estate.
- Defender for EndpointThe plan decision: Defender for Business, Plan 1 or Plan 2, and what each actually gives you.
- Defender Vulnerability ManagementContinuous vulnerability assessment plus the certificate, firmware and browser extension inventories nobody has.
- Mobile Threat DefenseDevice threat risk feeding compliance and Conditional Access, including on unenrolled personal phones.
- Endpoint securityThe broader endpoint practice across every platform, including an honest view of where Defender sits against its competitors.
Email, identity threats and SaaS
The entry points attackers actually use: a convincing email, a stolen credential, and an OAuth grant nobody reviewed.
- Defender for Office 365Impersonation protection, Safe Links and Safe Attachments, and the ten-second check that tells you which plan you hold.
- Defender for IdentityThe layer that notices somebody already inside: reconnaissance, credential abuse and lateral movement.
- Defender for Cloud AppsSaaS activity, OAuth applications and shadow IT, brought under one policy view.
Detection, response and the people behind it
Products generate alerts. Somebody still has to read them at three in the morning, and that has always been a staffing problem rather than a licensing one.
- Microsoft Defender XDRThe correlation layer: one incident instead of alerts in four consoles, plus automatic attack disruption.
- Microsoft SentinelA cloud-native SIEM, the connectors that feed it, automation on top, and keeping the ingestion bill from running away.
- Sentinel in the Defender portalWhere SIEM and XDR converge, and what the portal transition means for your operation.
- SOC as a serviceThe human layer: triage and response at any hour, which is the gap almost every Microsoft security deployment leaves wide open.
- Managed security servicesThe complete managed engagement across the whole stack rather than one product in isolation.
- Microsoft Copilot for SecurityUseful acceleration for a team already doing this work, and frankly not where anyone should start.
Cloud workloads and the external surface
What you run in Azure, AWS and GCP, and the internet-facing assets you forgot you had.
- Defender for CloudCloud posture management with a free tier most subscriptions never enable, plus workload protection plans.
- Defender EASMExternal attack surface discovery: the assets your scanner was never told about.
- Defender for ServersServer protection across Azure, AWS, GCP and on-premises, licensed separately from user plans.
- Defender for ContainersKubernetes hardening, vulnerability assessment and runtime protection.
- Defender for StorageMalware, sensitive data leakage and SAS token misuse on the storage accounts holding your data.
- Defender for SQLThreat detection for the databases where the business actually lives.
- Defender for APIsVisibility and threat detection for the business-critical APIs behind your applications.
Data protection, privacy and compliance evidence
Knowing what data you actually hold, limiting where it can travel, keeping it no longer than you should, and being able to prove all three.
- Microsoft PurviewClassification, loss prevention, retention, insider risk, and discovery. Nothing works until classification exists.
- Microsoft PrivaPrivacy risk and subject-rights requests, mapped to CCPA/CPRA and state privacy law obligations.
- DLP solutionsLoss prevention across the whole estate, rolled out in simulation first so it survives its first week with real users.
- Endpoint DLPThe same data protection extended to what users copy, paste, print and upload from their devices.
- Compliance ManagerMapping controls and scoring improvement against whichever frameworks actually apply to you.
- M365 reporting and auditingHow long audit data is kept, the specific reports regulated American firms get asked to produce, and alerting when something high-risk changes.
Devices, because an unmanaged endpoint undoes the rest
A policy can insist on a compliant device only when something is deciding what compliant means.
- Microsoft IntuneDevice management, zero-touch provisioning, compliance policies, patching, and app protection on personally owned phones.
- Apple Business ManagerThe free foundation underneath every Apple fleet, and why the place you buy a Mac determines whether you can ever manage it.
- Jamf ProDedicated Apple management, plus a straight answer about when Intune is the better choice.
Assessment, baseline and audit
Independent confirmation that the controls you believe are running actually are.
- Cybersecurity audit and compliancePosture assessment and the evidence pack insurers, auditors and enterprise customers ask for.
- Tenant security baselineThe written, enforced security configuration for your tenant, and the evidence behind it.
- Compliance servicesHIPAA, SOC 2, CMMC, GLBA and state privacy law readiness, built on the controls this stack provides.
Four things that shape how we approach Microsoft security.
We audit the license before proposing a purchase
The first thing we hand over is a list of what you own and are not using. That routinely shrinks the engagement we could otherwise have sold, and it is precisely why clients believe whatever we recommend afterwards. An advisor whose every assessment ends in an upgrade is not assessing anything.
We pair the tooling with people who respond
Almost none of the Microsoft security failures we investigate were detection failures. The product spotted it correctly and dropped the alert into a mailbox nobody was watching at two in the morning. Managed engagements carry cover at every hour with a five-minute response on critical alerts, so the response side is contracted rather than quietly assumed.
Built for the audit and insurance conversation
Evidence comes out of every deployment as a by-product rather than as a separate project six months later. SOC 2, HIPAA, CMMC, the FTC Safeguards Rule, NYDFS Part 500, and your insurance renewal all ask overlapping versions of the same questions, and one maintained pack answers every one of them.
We run it afterwards, which is where posture decays
Settings drift, Microsoft alters defaults on its own schedule, exclusion groups quietly expand, and every departure leaves a privileged account nobody removed. A tenant hardened once and then left alone measurably weakens over two years. Holding the posture is the ongoing work, and it is what we run across the 800+ systems under our management.
The upgrade is usually not the answer, and the license audit usually is.
A great many of the Microsoft security conversations we have begin with a decision already made to move to E5. Occasionally that is the right call. Far more often the company is not using what Business Premium or E3 already hands them, and upgrading adds cost while adding no protection whatsoever, because the constraint was never the license in the first place.
- Business Premium already carries Entra ID P1 with conditional access, Intune, Defender for Business, Defender for Office 365 Plan 1, sensitivity labels, and the foundations of loss prevention and retention. Configured properly, that is a genuinely strong position for a company under three hundred people. Most companies holding it have configured perhaps half.
- E5 adds the sophisticated end of the range: Entra P2 with just-in-time administration and risk-based policy, Defender for Endpoint Plan 2 with threat hunting, the full Purview suite including insider risk and premium discovery, and Sentinel benefits. Every single one of those requires a human being to operate it. Buying capability nobody has time to use is the most reliable way to waste a security budget.
- Our test is straightforward. Take each E5 capability, name the person who will run it, and state the question it answers for your business. Where you cannot do both, that capability will sit unused exactly as the currently unconfigured ones do, and the money does more good spent on deploying, tuning, and monitoring what you already hold.
- E5 genuinely pays for itself in three situations: a regulated firm that needs just-in-time administration and premium audit data as evidence, a company with an actual security team who will use threat hunting, or a case where the bundle simply costs less than buying the parts. We model that honestly, and we have told clients to stay where they are and spend the difference on monitoring instead.
Six US profiles and what drives the security scope.
Financial services and fintech
GLBA and FTC Safeguards obligations, NYDFS Part 500 where New York licensed, and bank partners running their own vendor due diligence. Usually the clients who need Entra P2, privileged identity management and premium audit for genuine reasons.
Healthcare and clinics
Patient data under HIPAA, a Business Associate Agreement to make real through tenant controls, retention obligations, and clinical devices that must be encrypted and evidenced alongside everything else.
Defense contractors and their suppliers
CMMC and NIST 800-171 drive specific configuration: controlled unclassified information handled deliberately, access control evidenced, and a tenant that can survive an assessor reading the settings rather than the policy binder.
Companies facing their first SOC 2
SaaS and services businesses whose enterprise customers now require SOC 2 or a completed security questionnaire before signing. Most of the controls the auditor asks about are Microsoft stack configuration, and most are already licensed.
Businesses that move money on email approval
Compromised business email is the single largest source of actual financial loss for American small and mid-size companies. Mail authentication, impersonation protection, and a verification step before any payment detail changes matter more here than anything else in the stack.
Professional services firms
Client confidentiality, document control and a small IT function. The organizations that benefit most from configuring what they already own, and the ones cyber insurers question hardest at renewal.
Four steps, and the first one frequently makes the project smaller.
- 1
License and posture assessment
Week 1
What the subscription entitles you to, what has genuinely been deployed, and the distance between those two lists. Alongside that, the basics get checked: how far multi-factor actually reaches, whether legacy authentication is still open, who holds privileged rights, which accounts are dormant, and how long audit data is kept. The findings come in writing regardless of what happens next.
- 2
Close the free wins
Weeks 1-3
Multi-factor enforced, legacy authentication blocked, administrative accounts separated, emergency access established, dormant accounts removed, audit retention extended, and every device Defender is already licensed for actually onboarded. All configuration, no purchasing, and it improves your posture more than anything that comes after it.
- 3
Deploy the capability you own but have not used
Months 1-3
A deliberately small set of conditional access policies rather than a sprawling one. Attack surface reduction taken through audit into enforcement at a sensible pace. Intune compliance feeding those access decisions. Classification in Purview, and loss prevention run in simulation before anything blocks. Sequenced so that adoption survives the rollout.
- 4
Monitoring, evidence and ongoing operation
Ongoing
Alerts land somewhere a person actually reads them. Access and privileged rights are reviewed every quarter. Patching and compliance get reported. The evidence pack stays current rather than being rebuilt annually. And the whole posture is revisited as Microsoft changes defaults underneath you and your company changes shape around it.
What US buyers ask about the Microsoft security stack.
The three pages most buyers read next.
Microsoft Entra
Attacks overwhelmingly start at identity, and identity is also where improvement comes fastest.
Defender for Endpoint
The plan decision that surprises almost everyone: which Defender product your licensing already gives you.
SOC as a service
The human layer. Detection with nobody reading the alerts is just an expensive log file.
Start by finding out what you are paying for and never switched on.
We map your license entitlement against what is actually deployed, check MFA coverage, legacy authentication, privileged and dormant accounts, and audit retention. You get the findings in writing at no cost. A fair proportion of these assessments conclude that no new license is needed this year.
Related Services
Explore more solutions that work great with this service
Microsoft Defender for Endpoint Services
EDR plan selection, onboarding and zero-gap AV migration
Learn moreMicrosoft Defender XDR Services
One incident queue across endpoint, email and identity
Learn moreMicrosoft Defender for Office 365 Services
Anti-phishing, Safe Links and Safe Attachments done right
Learn moreMicrosoft Defender for Identity Services
Identity threat detection for Active Directory and Entra
Learn moreMicrosoft Defender for Cloud Services
Defender for Cloud deployment for US organizations: enabling free
Learn moreSOC-as-a-Service
24/7 security operations delivered as a service
Learn more