New SMB security suites for Microsoft 365 Business Premium

October is Cyber ​​Security Awareness Month, and there's never been a more important time to help small and medium-sized businesses (SMBs) strengthen their defenses, as cyber threats are rapidly increasing and SMBs are increasingly targeted.

Throughout October, we're making it easier for partners to reach customers and build meaningful conversations about security. You'll get new resources, ready-to-use marketing tools, and an events calendar with skills-building sessions designed to help you grow your security expertise and fully support your customers.

Security and Compliance Guidance

Small and medium-sized businesses (SMBs) are facing more pressure than ever before, from rapidly changing cyber threats and increasingly complex regulatory requirements. To support this need, Microsoft offers Microsoft 365 Business Premium, an all-in-one productivity and security solution designed for organizations with 1–300 users. This package includes Office apps, Teams, advanced security features like Microsoft Defender for Business, and device management—all within a cost-effective subscription model.

Microsoft recently expanded the capabilities of this solution with the launch of three new Microsoft 365 Business Premium add-ons aimed at strengthening security and governance. Designed for mid-market organizations, these add-ons deliver enterprise-grade security, governance, and identity protection capabilities to enhance the Business Premium experience without the cost of an Enterprise solution.

Microsoft Defender Suite

$10

/user/month

(Values ​​over $28 if purchased individually by license)

Microsoft Defender

  • Defender for Endpoint P2
  • Defender for Office 365 P2
  • Defender for Identity
  • Defender for Cloud Apps

Microsoft Entra

  • Entra ID Plan 2

Microsoft Purview Suite

$10

/user/month

(Values ​​more than $19 if purchased individually by license)

Microsoft Purview

  • E5 eDiscovery & Audit
  • E5 Insider Risk Management
  • E5 Info Protection & Governance

Microsoft Defender and Purview Suites

$15

per user per month

(Values ​​over $47 if purchased individually by license)

Microsoft Defender

  • Defender for Endpoint P2
  • Defender for Office 365 P2
  • Defender for Identity
  • Defender for Cloud Apps

Microsoft Entra

  • Entra ID Plan 2

Microsoft Purview

  • E5 eDiscovery & Audit
  • E5 Insider Risk Management
  • E5 Info Protection & Governance
b1ba8e7e-ea1d-46fd-9099-c6afe1f2f631

Customers can save up to 68% when they choose new SKUs for SMBs instead of purchasing standalone security components.

Defender Suite

Microsoft Defender Suite for Business Premium – $10/user/month

With cyberattacks becoming increasingly sophisticated, small and medium-sized businesses (SMBs) need comprehensive protection without unnecessary complexity. Microsoft Defender Suite for Business Premium delivers end-to-end protection against identity-based threats, device exploits, phishing, and risky cloud applications. It's designed to help organizations mitigate risk, respond quickly, and maintain a strong security posture. It includes:

  • Identity protection and governance:
    Microsoft Entra ID P2 delivers advanced security features like Entra ID Protection and Entra ID Governance, which use behavioral analytics and machine learning to block suspicious logins in real time, detect password spray attacks, and simplify employee onboarding with automated workflows. Microsoft Defender for Identity also provides visibility into your identity system, recommends security postures, and correlates signals within Defender XDR to provide incident-level insights.
  • Device security:
    Microsoft Defender for Endpoint Plan 2 delivers advanced malware protection, attack surface reduction, endpoint detection and response (EDR), device-based conditional access, and advanced threat hunting capabilities — helping SMBs effectively protect their devices and improve their overall Secure Score.
  • Email and collaboration security:
    Microsoft Defender for Office 365 P2 protects communication channels with phishing attack simulation, post-incident investigation, automated response, and detailed reports on employee email and link activity.
  • Cloud application protection:
    Microsoft Defender for Cloud Apps helps IT teams discover, manage, and secure SaaS deployments across the organization, protecting against Shadow IT, OAuth attacks, and risky Generative AI app deployments, and providing SaaS Security Posture Management to reduce errors and risk.
Purview Suite

Microsoft Purview Suite for Business Premium – $10/user/month

Microsoft Purview Suite for Business Premium focuses on data protection, governance management, and insider risk mitigation, bringing enterprise-grade compliance tools to SMBs in an accessible, cost-effective way. It covers:

  • Insider risk management:
    Microsoft Purview Insider Risk Management Use behavioral analytics to detect unusual user activity, such as downloading large files before leaving the office, while also protecting employee privacy.
  • Data protection:
    Microsoft Purview Information Protection assigns persistent labels to sensitive data so that security policies can track files whether they are shared, stored, or emailed. Data Loss Prevention (DLP) prevents accidental sharing of sensitive data, while Message Encryption and Customer Key enhance email security and compliance.
  • Communication compliance and AI security:
    Purview Communication Compliance monitors messages for potential policy violations, and the new Data Security Posture Management (DSPM) for AI provides visibility into how AI is being used on sensitive data, helping organizations detect oversharing and enforce policies in real time.
  • Information Lifecycle and Investigations:
    Purview Records and Data Lifecycle Management automates data retention and deletion, while eDiscovery (Premium) and Audit (Premium) provide advanced tools for investigation, incident response, and governance readiness.
  • Compliance Management:
    Purview Compliance Manager integrates compliance tracking, risk assessment, and corrective actions into a single dashboard, making it easier for SMBs to manage.

Microsoft Defender and Purview Suites for Business Premium – $15/user/month

For organizations looking for the most comprehensive solution suite, the Microsoft Defender and Purview Suites option combines all of the security, governance, and data protection features into one cost-effective package. For just $15 per user per month, this option saves SMBs up to 68% compared to purchasing the tools individually — giving them access to an enterprise-grade security and governance solution without impacting their budget.

998b3e08-cd4d-44ca-b206-d598083d8b72

Frequently Asked Questions (FAQs)

Add-ons will be available for purchase in addition to Business Premium starting in September 2025.

A: You can purchase these add-ons in addition to your Business Premium Subscription through the Microsoft Security for SMBs website or through your Partner.

Customers can purchase a mix of add-ons, but the total number of seats for all add-ons is limited to 300 per customer.

Microsoft Defender for Business does not support mixed licensing. Therefore, if a tenant uses Defender for Business (included in Microsoft 365 Business Premium) together with Defender for Endpoint Plan 2 (included in Microsoft 365 Security), they will automatically be set to Defender for Business. For example, if you have 80 users with Microsoft 365 Business Premium licenses and add Microsoft Defender Suite for 30 of them, all users will still receive the Defender for Business experience. If you want to switch to the Defender for Endpoint Plan 2 experience, you must license Defender for Endpoint Plan 2 to all users (either standalone or through Microsoft Defender Suite). Then, contact Microsoft Support to change your tenant settings. You can learn more here.

Yes, customers who are already using the Microsoft 365 E5 Security add-on with Microsoft 365 Business Premium can transition to the new Defender Suite starting with their October billing cycle. For detailed instructions, see the Guidelines here.

For Partners or customers looking to build a Security Operations Center (SOC) with MDR, Defender for Business supports streaming device events (such as device files, registry, network, logon events, and more) to Azure Event Hub, Azure Storage, and Microsoft Sentinel to support Advanced Threat Hunting and attack detection. If this is your first time using Streaming APIs, you can find step-by-step instructions in the Microsoft 365 Streaming API Guide on setting up the Microsoft 365 Streaming API to stream events to your Azure Event Hubs or Azure Storage Account.