What Microsoft 365 includes (and doesn't)
Microsoft 365 is a productivity platform, not a security platform. The licenses come with security features, but most of them are off by default. You're responsible for activating them, configuring them properly, and maintaining them over time.
This is the Shared Responsibility Model. Microsoft secures the infrastructure (the data centres, the platform itself). You secure your tenant — the configuration, the users, the data inside.
Buying Microsoft 365 does not make you secure. Configuring Microsoft 365 correctly does.
Business Basic security features
Business Basic is the cheapest plan. Security features included:
- Multi-Factor Authentication (MFA) — included, must be enabled
- Azure AD basic Conditional Access (limited)
- Microsoft Defender for Office 365 Plan 1 — NOT included (this is the antivirus for email)
- Data Loss Prevention (DLP) — NOT included
- Microsoft Intune (mobile device management) — NOT included
- Azure AD P2 features — NOT included
Verdict: Business Basic is fine for very small teams that don't handle sensitive data. But most security features are missing, so you need to add them with third-party tools or upgrade.
Business Standard security features
Business Standard adds the tools most SMBs need:
- Everything in Business Basic
- Microsoft Defender for Office 365 Plan 1 — INCLUDED (email anti-phishing, safe links, safe attachments)
- Azure AD P1 features — INCLUDED (Conditional Access, dynamic groups, self-service password reset)
- Information Protection (sensitivity labels) — basic
- DLP for email and files — basic
Verdict: Business Standard is the sweet spot for most Kosovo SMBs. You get the security essentials built in, without paying for Premium.
Business Premium security features
Business Premium is the full security stack:
- Everything in Business Standard
- Microsoft Defender for Office 365 Plan 2 — INCLUDED (threat hunting, attack simulator, automated investigation)
- Azure AD P2 features — INCLUDED (Identity Protection, Conditional Access with risk signals, PIM)
- Microsoft Intune — INCLUDED (mobile device management, mobile app management)
- Azure Information Protection P2 — advanced
- Microsoft Defender for Identity — INCLUDED (detects identity attacks)
- Microsoft Defender for Cloud Apps — INCLUDED (shadow IT discovery)
Verdict: Business Premium makes sense for SMBs handling sensitive data (financial, healthcare, legal), or for any business that wants the full Microsoft security stack without third-party add-ons.
The 7-step checklist
Regardless of which license plan you have, these are the seven steps to implement right away. None of them require Premium.
Step 1: Enable MFA for every account
Go to Microsoft Entra admin center → Identity → Users → Per-user MFA. Enable MFA for every user. Use the Microsoft Authenticator app — SMS-based MFA is vulnerable to SIM-swapping attacks.
Step 2: Block legacy authentication
Legacy protocols (POP, IMAP, SMTP basic auth) bypass MFA. Block them in Conditional Access: 'Block legacy authentication' policy applied to all users.
Step 3: Enable Security Defaults or Conditional Access
If you have Business Basic, enable Security Defaults (one-click in Entra). If you have Business Standard or Premium, configure Conditional Access policies: require MFA for all users, block sign-ins from unfamiliar locations.
Step 4: Configure email anti-phishing
Defender for Office 365 (included in Standard and Premium) blocks 99% of phishing attempts before they reach inboxes. Verify it's enabled and configured with anti-spoofing, anti-phishing, and safe links policies.
Step 5: Audit user roles and permissions
Every admin role should be reviewed quarterly. Most SMBs have far more Global Admins than they need. Principle of least privilege: every user gets the minimum access required to do their job.
Step 6: Enable audit logging
Microsoft 365 logs every action — logins, file access, admin changes. Verify Unified Audit Logging is enabled and logs are being retained for at least 90 days. Without audit logs, you can't investigate incidents.
Step 7: Set up alerts
Microsoft 365 can alert you on suspicious activity — impossible travel sign-ins, mass file deletions, role elevation. Configure at least these three alert policies in Microsoft Defender.
When to upgrade to Premium
Upgrade to Business Premium when:
- You handle sensitive data (financial, healthcare, legal, personal data of EU citizens)
- Your team is 10+ people with significant remote work
- You need Intune for mobile device management
- Your industry requires advanced compliance (GDPR Article 32, ISO 27001)
- You want Microsoft Defender for Identity (detects lateral movement attacks)
Sources & further reading
- Microsoft — Shared Responsibility in the Cloud
- Microsoft — Microsoft 365 licensing comparison
- Microsoft Digital Defence Report 2024
- NIST SP 800-53 — Security and Privacy Controls
- ENISA — Cloud Computing Security Risk Assessment
Want help configuring Microsoft 365 correctly?
KPX provides Managed Microsoft 365 — licensing, migration, security baselines, ongoing administration. Book a free M365 audit and we'll show you what's configured correctly and what isn't.
