The Right Protection Starts With the Right Licensing

 

Microsoft Defender is not a single product. It is a suite of security tools that each require their own licensing, deployment, and configuration before they provide any meaningful protection. What your business has access to depends entirely on which Microsoft licences you are running, and most businesses do not have a clear picture of which Defender products their licensing includes or which require an upgrade.

We start with a licensing assessment before anything else, reviewing what you currently have, identifying what is missing, and giving you a clear recommendation on what needs to be added. Once licensing is confirmed and any gaps are closed, every Defender tool we touch is fully deployed, tuned to your environment, and connected to your Microsoft Defender XDR portal before we consider the job done.

Threat Protection Coverage

30%

Full deployment across every endpoint.

What We Deploy and Why It Matters

Defender for Endpoint and Servers

Defender for Endpoint provides threat detection, automated investigation, and response across Windows, macOS, iOS, and Android devices, going well beyond traditional antivirus. Defender for Servers extends the same engine to your Azure hosted and on premises server infrastructure, so threats on a domain controller or file server are not invisible to the rest of your stack. Which plan you have access to for each depends on your current Microsoft licensing, which we confirm before deployment.

We onboard devices via Intune, configure attack surface reduction rules, and set detection and response to active mode. For servers, we confirm the appropriate plan, onboard through Defender for Cloud, and integrate server alerts into your Defender XDR console alongside your other signals.

Defender for Office 365

Email remains the primary entry point for attacks on small and mid sized businesses. Defender for Office 365 provides protection against phishing, business email compromise, malicious attachments, and weaponised links that bypass standard email filtering, though the default configuration Microsoft ships does not enable these capabilities at a level that blocks sophisticated attacks.

We configure Defender for Office 365 properly across every mailbox, tune anti phishing policies to detect impersonation of your executives and suppliers, and enable zero hour auto purge to remove malicious emails already sitting in inboxes.

Defender for Identity

Defender for Identity monitors your Active Directory and Entra ID environment for indicators of identity based attacks, detecting techniques like pass the hash, lateral movement, privilege escalation, and reconnaissance activity that endpoint protection alone will not catch. For businesses running on premises Active Directory or a hybrid environment, it is one of the most valuable security investments available, since without it, attacks moving through your identity infrastructure are invisible to every other security tool in your stack.

We confirm whether your current licensing includes Defender for Identity, advise on the most practical path forward if it does not, and deploy sensors on your domain controllers once licensing is in place.

Do we need to buy additional Microsoft licensing to deploy Defender properly?

It depends on your current Microsoft licensing and which Defender products you need. We start with a licensing assessment to review what you already have access to and give you a clear recommendation on what is worth adding based on your environment and risk profile, before any deployment work begins.

What is the difference between Defender for Endpoint Plan 1 and Plan 2?

Plan 1 covers core endpoint protection including attack surface reduction and next generation antivirus. Plan 2 adds full endpoint detection and response, automated investigation, advanced threat hunting, and extended data retention.

Does Defender protect our on premises servers, or only cloud infrastructure?

Both. Defender for Servers covers Azure hosted servers and on premises servers connected via Azure Arc, integrating with Defender for Endpoint so server threats appear in the same console as your endpoint and identity signals.

We use hybrid Active Directory, does Defender cover that?

Yes. Defender for Identity monitors both Active Directory and Entra ID for identity based attacks like pass the hash and lateral movement, which is one of the most valuable protections available for businesses running on premises or hybrid Active Directory.

How long does it take to deploy Defender across our organisation?

We start in audit mode, monitoring activity without blocking anything, before switching policies to block mode once we are confident they will not disrupt legitimate business activity. Timelines depend on the size of your organisation, and can take up to 12 weeks for larger environments.

Tired of Wondering if Your IT is Set Up Right?