Blog Post

Microsoft 365 Blog
5 MIN READ

Introducing Microsoft Defender for Business

Jon Maunder's avatar
Jon Maunder
Iron Contributor
Nov 02, 2021

UPDATE 2nd May 2022. Microsoft Defender for Business is now generally available. Please see New endpoint security for small and medium businesses now available with Defender for Business. - Mi...

 

Security remains one of the biggest concerns and most challenging responsibilities facing businesses today. With a rise in cyberattacks targeting small and medium-sized businesses, threats are becoming increasingly automated and indiscriminate, and striking at a significantly higher rate. In the last year, we’ve seen a 300% increase in ransomware attacks with over 50% reaching small businesses1. To address this, Microsoft is investing in security solutions purposefully designed to help protect them.

 

We’re excited to introduce Microsoft Defender for Business, a new endpoint security solution that’s now generally available within Microsoft 365 Business Premium, and Standalone solution in preview. Microsoft Defender for Business is specially built to bring enterprise-grade endpoint security to businesses with up to 300 employees, in a solution that is easy-to-use and cost-effective.

 

Let’s look at Defender for Business in more detail.

 

Elevate your security with Microsoft Defender for Business

Today's top security threats are extortion or disruption from ransomware. Your business needs increased protection from these and other threats at an affordable price, so you can have peace of mind.

 

Defender for Business elevates security from traditional antivirus to next-generation protection, endpoint detection and response, threat and vulnerability management, and more. It offers simplified configuration and management with intelligent, automated investigation and remediation. Defender for Business helps you to protect against cybersecurity threats including malware and ransomware across Windows, macOS, iOS, and Android devices.

 

Enterprise-grade endpoint security

We’re bringing capabilities from our industry-leading Microsoft Defender for Endpoint solution and optimizing them for businesses with up to 300 employees.

Figure 1: Microsoft Defender for Business brings enterprise-grade capabilities to help protect your business.

Defender for Business will include the following capabilities:

  • Threat and vulnerability management – Helps you to prioritize and focus on the weaknesses that pose the most urgent and the highest risk to your business. By discovering, prioritizing, and remediating software vulnerabilities and misconfigurations you can proactively build a secure foundation for your environment.
  • Attack surface reduction – Reduces your attack surface (places that your company is vulnerable to a cyberattacks) across your devices and applications using capabilities such as ransomware mitigation, application control, web protection, network protection, network firewall, and attack surface reduction rules.
Figure 2: Threat and Vulnerability management dashboard helps you to proactively discover, prioritize and remediate software vulnerabilities and misconfigurations.
  • Next-generation protection – Helps to prevent and protect against threats at your front door with antimalware and antivirus protection—on your devices and in the cloud.
  • Endpoint detection and response (EDR) – Get behavioral-based detection and response alerts allowing you to identify persistent threats and remove them from your environment. Manual response actions within Defender for Business will allow you to take action on processes and files, while live response will put you in direct control of a device to help ensure it’s remediated, secured, and ready to go.
  • Automated investigation and remediation - Helps to scale your security operations by examining alerts and taking immediate action to resolve attacks for you. By reducing alert volume and remediating threats, Defender for Business allows you to prioritize tasks and focus on more sophisticated threats.
  • APIs and integration - Automate workflows and integrate security data into your existing security platforms and reporting tools. For example, you can pull detections from Defender for Business into your security information and event management tool.
Figure 3: Endpoint detection and response dashboard helps to identify persistent threats and remove them from your environment.

Easy to use, manage, and configure

No specialist security knowledge is required to install and manage Defender for Business. It offers streamlined experiences that guide you to action with recommendations and insights into the security of your endpoints. It allows you to secure endpoints with less complexity and fewer gaps that can be exploited by bad actors.

 

The product includes simplified client configuration with wizard-driven set up and recommended security policies activated out-of-the-box, allowing you to quickly secure devices. Easy-to-use management controls and actionable insights help you to save time and prioritize tasks.

Figure 4: Simplified onboarding of devices and easy-to-use administration controls allow you to add clients in a few simple steps with recommended security policies activated out-of-the-box.

Cost-effective

Defender for Business is designed to deliver maximum security value at a price point that works for your business. The simplicity of it allows you to onboard and manage endpoint security with low operational overhead, and less burden to learn complex cybersecurity concepts to get your business secured.

 

Defender for Business protects your endpoints whether your email and productivity are on-premises, Microsoft 365, or other solution. So, we’ve made the licensing model flexible and simple. Upon general availability, you will be able to buy direct from Microsoft and via Microsoft Partner Cloud Solution Provider (CSP) channels. It will be available for purchase:

 

  • As a standalone offering, priced at $3 per user per month.
  • Included as part of Microsoft 365 Business Premium, our comprehensive security and productivity solution that brings together Microsoft Teams and Office 365 with the essential security tools for small- and medium-sized businesses.

 

Microsoft 365 Lighthouse integration for IT Partners

If you are an IT partner serving small and medium-sized businesses, you can use Microsoft 365 Lighthouse to secure your customers at scale. Microsoft 365 Lighthouse integration with Defender for Business gives you a view of security incidents and alerts across customers onboarded into Lighthouse. Additional management capabilities for Defender for Business in Lighthouse are also on the roadmap.

Figure 5: Security incident queue within Microsoft 365 Lighthouse helps IT partners identify security incidents and alerts across multiple customers.

Learn more

We are excited to introduce you to Microsoft Defender for Business and deliver these powerful endpoint security capabilities to help you secure your business.

 

Preview will launch with an initial set of scenarios to test and we will be rolling out to customers and partners in phases, adding new capabilities regularly. You can learn more about the about the preview experience and sign-up process for customers and partners in the latest blog

 

Additional resources are available:

References

1.Homeland Security Secretary Alejandro Mayorkas, 06 May 2021 ABC report

 

Updated Apr 17, 2025
Version 5.0

50 Comments

  • That's a long awaited feature and I'm glad it's here.

     

    I hope the integration with Lighthouse to offer a centralised overview since it's very important to have everything in one piece.

     

    Having to log in to different platforms isn't helpful and it's counter productive.

     

    Really looking forward to this one!

  • joeyvldn's avatar
    joeyvldn
    Brass Contributor

    Can't wait to be generally available! Great news for M365BP users.

  • Daniel Kaufmann's avatar
    Daniel Kaufmann
    Copper Contributor

    Jon Maunder Very interesting! Especially the printscreen with the configuration settings. (It shows settings like "Turn on realtime protection" or "Scheduled Scan Type")

    This leads me to the assumption, that Microsoft Defender for Business will allow to configure Microsoft Defender Antivirus Settings? 

    Consequently, it allows the case to manage Defender Antivirus on Server Operation Systems without additional need of System Center Suite (ConfigMgr), Group Policy and Powershell? 

     

    EDIT: Have just read this article https://docs.microsoft.com/en-us/mem/intune/protect/mde-security-integration

    This solves a big blocker! GREAT! 

     

  • Love it. This addition is hugely valuable for increasing the overall client experience and more opportunities for Partners.

  • It's odd that the new "Business" SKU with EDR is not in the full M365 E3. Same with ATP P1. It's $32 vs. $20 (pre increase) but it's missing key security options that Business Premium has. 

  • I love it... I just love it...  🙂 ...It totally explains the price increase of that license... This feature was number 1 on my whish list to be added to the ms 365 business premium license for a long long time

  • p-d-b2265's avatar
    p-d-b2265
    Copper Contributor

    there are rumours that 365 will become much more restrictive in licencing rules, not allowing tenants to deprovision users before their expiry date or to alter users as easily, putting huge load on resellers keeping tabs on every user licence expiry. which does make me a little twitchy about signing up for or recommending anything 365 based until that been confirmed or disproved. 

  • KrisDeb's avatar
    KrisDeb
    Iron Contributor

    Fantastic product and idea. Congratulations Microsoft, now it will be easier to explain the M365B price change for both new and existing customers.