Empowering SMB Security with Microsoft 365 Business Premium

In today’s digital landscape, small and medium-sized businesses (SMBs) face increasing cybersecurity threats that require robust solutions tailored to their needs. Microsoft 365 Business Premium emerges as a comprehensive solution, seamlessly integrating productivity tools with advanced security features specifically designed for SMB clients. In this blog post, we’ll explore the key security offerings of Microsoft 365 Business Premium, including Intune, Safe Links, and Safe Email Attachments, and elucidate the advantages it offers over the standard license. Additionally, we’ll highlight the cost difference between Microsoft 365 Business Premium and Business Standard licenses to help SMBs make informed decisions.

Overview: Microsoft 365 Business Premium for SMBs

Microsoft 365 Business Premium is purpose-built for small and medium-sized businesses (300 users or less), offering a powerful combination of productivity and security features. It provides SMBs with access to familiar Office applications, collaboration tools like Teams, and advanced security capabilities—all within a single subscription. This integrated approach enables SMBs to enhance productivity, streamline workflows, and fortify their defenses against cyber threats effectively.

Top Security Features of Microsoft 365 Business Premium:

  • Microsoft Defender for Business: Microsoft 365 Business Premium includes Microsoft Defender for Business, a comprehensive security solution that protects against a wide range of threats, including viruses, malware, and ransomware. Defender for Business provides real-time threat detection and response, proactive threat hunting, advanced security analytics, and endpoint protection capabilities. It offers centralized management, allowing administrators to monitor and manage security across devices and platforms seamlessly. With automated security updates and AI-driven threat intelligence, Defender for Business ensures that SMBs stay ahead of emerging threats and maintain a robust security posture.
    • Features associated with Microsoft Defender for Business:
      • Real-time threat detection and response
      • Proactive threat hunting
      • Advanced security analytics
      • Endpoint protection capabilities
      • Centralized management for monitoring and managing security across devices and platforms
      • Automated security updates and AI-driven threat intelligence
  • Data Loss Prevention (DLP): Protecting sensitive information is paramount, and Microsoft 365 Business Premium’s Data Loss Prevention (DLP) feature provides proactive safeguards against data leaks and unauthorized access. DLP enables organizations to define and enforce policies for identifying, monitoring, and protecting sensitive data across various platforms.
  • Azure Information Protection (AIP): With Azure Information Protection, Microsoft 365 Business Premium empowers organizations to classify, label, and protect documents and emails based on their sensitivity level. AIP ensures granular control over data access and usage rights, safeguarding confidential information both within and outside the organization’s boundaries.
  • Microsoft Entra ID P1: Entra ID P1 offers an array of powerful features designed to enhance security and streamline access management within organizations. Key features include self-service password reset, multi-factor authentication (MFA), conditional access, identity protection, Azure AD Join, group-based access management, and application proxy. These features collectively enable organizations to strengthen their security posture, mitigate identity-based risks and threats, enforce access policies based on specific conditions, simplify access management, and provide secure access to resources and applications.

Enhanced Security with Intune:

Microsoft 365 Business Premium includes Intune, a powerful mobile device management (MDM) and mobile application management (MAM) solution. Intune enables organizations to manage and secure mobile devices, applications, and data across the organization. With Intune, administrators can enforce device compliance policies, remotely wipe lost or stolen devices, and protect corporate data on both company-owned and BYOD devices.

Safe Links and Safe Email Attachments:

Microsoft 365 Business Premium’s Safe Links and Safe Email Attachments features add an extra layer of security to email communications. Safe Links automatically checks links in emails and Office documents for malicious content, blocking access to potentially harmful websites. Safe Email Attachments scans email attachments for malware and malicious content, preventing users from accessing or downloading harmful files.

Cost Comparison: Microsoft 365 Business Premium vs. Business Standard

FeatureM365 Business PremiumM365 Business Standard
Microsoft Defender for BusinessIncludedNot Included
Data Loss Prevention (DLP)IncludedNot Included
Azure Information Protection (AIP)IncludedNot Included
Microsoft Entra ID P1IncludedNot Included
IntuneIncludedNot Included
Safe LinksIncludedNot Included
Safe Email AttachmentsIncludedNot Included
Monthly Cost (per user)£18.10£10.30

If you’re currently using Business Standard licenses, it’s time to explore the additional benefits that come with Microsoft 365 Business Premium, especially when it comes to enhancing your security posture. With features like Microsoft Defender for Business, Data Loss Prevention, Identity and Access Management, and comprehensive vulnerability management capabilities, Business Premium offers a comprehensive solution to safeguard your business against cyber threats. Making the switch could be just what your business needs to level up its security game while streamlining operations.

https://www.microsoft.com/en-gb/microsoft-365/business/compare-all-microsoft-365-business-products

Microsoft 365 Backup (Preview)

Ever since Microsoft unveiled its plan to introduce a native backup solution for M365, I’ve been eagerly anticipating the chance to put it to the test. Despite being in the public preview stage, it is showing promise. Securing your Microsoft 365 (M365) environment through backups is essential for protecting data and defending against cyber threats. It enables swift recovery from accidental deletions, cyber attacks, and unforeseen incidents, guaranteeing continuous operations and instilling confidence in the integrity of your data.

Requirements

In order to configure the you need to link it to an Azure PAYG subscription is required, and a resource group.

Initial Setup

Login into the M365 Admin Centre browse to:

  • Setup
  • Files and content
  • User Content AI with Microsoft Syntex

Click on Set up Billing and add your Azure subscription and resource group. The resource group will not contain the backups, or any data, I suspect it would be used for billing purposes.

On the Manage Microsoft Syntex section, click on the Backup (Preview) and turn it on.

Backup

We are not ready to set up some backup policies and do some testing.

Select the service you would like to backup. In my case it will be OneDrive, but its the same process for all of them.

The backup and retention policy is shown below. The maximum current retention is one year.

Add the scope of the backup. You have a few different options, in this case i will be adding a single user.

Once you have confirmed the policy, you will get a confirmation screen, you will also notice a status of processing, while everything has been setup and configured. Backups will now be taking place every 15 mins.

Microsoft have included a nice little option to pause a backup policy if required. You can also edit the scope of policy, by adding or removing users.

Restoring a Backup

Restoring from backup is pretty straightforward, select the service you would like to restore and click restore.

Select the account you would like to restore:

Select the date and time to restore from. Depending on the data and time of your restore Microsoft may suggest a specific retore point for faster restores.

https://learn.microsoft.com/en-us/microsoft-365/syntex/backup/backup-restore-data?tabs=onedrive

After confirming the restore point, you can select to restore the data to the original OneDrive account, or to create a new SharePoint site to restore the data. Restoring to OneDrive will replace all the data in the account. Therefore if you select this option it should only be done when a user is not storing new data to the account. Ideally this would be done out of hours.

You can view the restored data from the restoration task page.

Once complete you will receive confirmation.

Restoring Emails

When restoring emails, you do have the option to do a restore in place, or to restore to a new folder in the mailbox.

Conclusion

If you’re looking for a straightforward native M365 backup solution without unnecessary complexities, your search ends here. While I anticipate a few adjustments before general availability (GA) release and anticipate further enhancements in the coming months, Microsoft has done a pretty good job..

https://learn.microsoft.com/en-us/microsoft-365/syntex/backup/backup-overview

https://learn.microsoft.com/en-us/microsoft-365/syntex/backup/backup-pricing

https://learn.microsoft.com/en-us/microsoft-365/syntex/backup/backup-faq