When a customer uplifts to M365 Business Premium (or E3) they are after one or two features, whether that be Intune to manage their fleet of devices or Defender for business because their Anti-virus solution is due for renewal. M365 BP offers so much more!
In this blog post, I’ll list what you get with Microsoft 365 Business Premium and what Settings/features I turn on immediately so the customer gets immediate benefits and some protection on day 1.
What you get with M365 Business Premium:
- Microsoft Intune Plan 1
- Microsoft Defender for Business
- Defender for Office 365 Plan 1
- Microsoft Entra ID P1
- Purview & Information Protection
Microsoft Intune
Enrollment restrictions
Enrolment restriction depends on the customer and what devices they allow on their environment. Following a zero trust model, I block everything (except Windows) to begin with before explicitly (in writing) given permission from the customer to allow other devices. Even if you know a customer very well, always ask the question to cover yourself.

Device Enrolment Settings
Once the enrolment restrictions are in place I then configure the enrolment scope and for a specific set of pilot users and then ‘Disable MDM enrollment when adding work or school account on Windows’ to stop accidental device enrolment. This gives me control over who and what get’s enrolled.

Microsoft Defender for Business
Onboarding
When you open Defender for the first time, Microsoft thankfully bring you through an initial configuration steps to onboard devices. Although not required, I tend to onboard devices that are enrolled into Intune. You can of course use a GPO or a configuration script to onboard devices.

Alerting Policy (High only)
Microsoft turn on all type of severity alerting by default, however the alerts by default send to the tenant admins group, which generally don’t have an email address associated to them. For customers, I setup a shared mailbox so they can track the alerts, but it’s also good proactive to send the alerts elsewhere, like a SIEM solution and/or the ticketing system if you work for an MSP like I do.

Microsoft Defender for Cloud Apps
Under system -> settings -> General: Advanced Features, you will see that the Microsoft Defender for Cloud Apps is toggled off by default.

Although the subtext mentions ‘This feature is available with an E5 license for Enterprise Mobility + Security on devices’, you can still receive the telemetry data (Cloud App Discover data) from Defender for Cloud Apps by turning it on.
Defender for Office 365
There are many features of Defender for Office that I could talk about, however, that’s another blog post. Microsoft provides you with preset security policies that you can enable from day 1. The standard protection preset suits in most instances, I’ve yet to break anything by turning this on immediately, however as always, test on a pilot group of users first before broader deployment.


Microsoft Entra ID P1
I covered many features of Entra in a previous blog post: Enhancing IAM Controls so I’m not going to expand on them further. However there are some settings that I enable immediately at the tenant level when a customer is uplifting to Business Premium or E3 licenses.
User Settings
Here’s a before (default) and after User Settings Configurations that I like to configure on day 1.


Device Settings
Similarly, there are device settings that by default are enabled but generally aren’t desirable to have configured on a customers tenant. Again, here’s a before and after device settings:


As I always recommend, test before making changes to any environment!
To learn more about business premium visit: Microsoft 365 Business Premium resources | Microsoft Learn


Leave a Reply