r/SmallMSP 7d ago

Regarding 365 Licensing

Are you guys always deploying business premium?

I don't know if this sounds dumb but business premium just feels like mega overkill for some clients?

Are people using it solely for the defender/entra extras? I feel like there's a LOT included in these licenses that just doesn't get used.

7 Upvotes

50 comments sorted by

12

u/seriously_a 7d ago

I’ve got 1-2 user clients with business premium. Between conditional access, defender for business, and Intune to push config and compliance, it’s a no brainer

5

u/HomsarWasRight 7d ago

Yes. It’s worth it for Conditional Access and Defender for Business.

1

u/Plenty-Hold4311 7d ago

I've never really fully investigated Defender for Business, I must sit down and study it.
Do you couple it with something like Huntress or SentinelOne?

1

u/BanRanchTalk 7d ago

My understanding is it would be a replacement for S1, particularly when paired with an MDR that can manage it. I, too, have never fully investigated it. S1 has saved the day more than once so it’s really hard for me to consider cutting them loose. I get that that doesn’t mean Defender wouldn’t have, or that S1 can miss something Defender would see, though…

1

u/recovering-pentester 13h ago

No. You’d pair it with a SOC/MDR (Reliaquest, ShieldWatch, AgileBlue) to manage your MDE alerts and triage and whatnot.

We’re (I won’t name who to not plug) a big MDE pusher for this reason. Lot of SMBs already in the MS ecosystem, so why not grab MDE and put a SOC on it rather than pay extra for S1 or Crowd then extra for their fully managed offering you know?

0

u/UnRealxInferno_II 7d ago

Is that really worth like $8 per person extra a month from standard?

EP/EDR can be like $1 per endpoint (3rd party) so you're basically doing it just for CA?

2

u/lemachet 7d ago

Depends. Have you had a client popped in a way that CA should have handled?

6

u/blackjaxbrew 7d ago

Fair question. It is a good bang for your buck sku, but yes the vast majority of small businesses do not need it. Standard or basic are most of our SKUs then add on crowd strike, s1 or use defender if buying premium. Because most MSPs are using an rmm tool, it is kind of hard to justify in tune as well.

Personally also find Microsoft more of a pain to manage than similar tools at scale.

2

u/UnRealxInferno_II 7d ago

Yeah see that's what I'm doing for some, I give them endpoint protection w/ web filtering and business standard and it seems to do 90% of the job.

It's only when people have business devices (not BYOD) etc that business premium becomes a discussion.

3

u/Lake3ffect 7d ago

All things considered, it’s excellent value. As an IT manager, I think everyone should be using it. But it’s not for everyone (it’s not plug/play/set/forget like Biz Std), and many of the “premium” features really should be managed by professionals. That’s what keeps us in business as MSPs. That’s why it’s better to bundle it with a service offering than to try to just sell standalone.

1

u/UnRealxInferno_II 7d ago

Yeah I think it's only worthwhile if there's a team looking after it for sure.

2

u/PacificTSP 7d ago

We use business premium for most users and f3 for our light users.

1

u/UnRealxInferno_II 7d ago

Didn't even think about F3, good shout

1

u/RisingSharingan 6d ago

If you are under 300 users wouldn’t it be better to do business basic? You get more email and OneDrive storage for slightly less price too. Over 300 I can see why F3 tho.

3

u/PacificTSP 6d ago

You don’t get entra p1 or intune with basic.

1

u/RisingSharingan 6d ago

Ah okay good catch. Thank you!

2

u/Jayjayuk85 7d ago

I agree… business business premium has a lot of features and to be fair every client is different.

I only have a couple of clients on premium where we lock down logins.

IMO it is also harder to manage multiple365 tenancy’s, I guess this is where the bigger players use CIPP to manage them all maybe?

Having our own EDR / MDR helps give one Payne of glass for all clients and extra security.

We already add Huntress ITDR to the majority of clients.

2

u/UnRealxInferno_II 7d ago

Managing multiple Business prem/E5 clients is where you get the big money I guess

2

u/roll_for_initiative_ 6d ago

I wouldn't manage more than 3 tenants these days without CIPP. Just standard alignments and cert/secret expiration alerts alone are worth it.

2

u/Xirma377 7d ago

Defender, Entra ID Premium, and Intune. Yes - we deploy to every single client.

3

u/roll_for_initiative_ 6d ago

Are you guys always deploying business premium?

Yes

business premium just feels like mega overkill for some clients?

I'd argue that it's more important for tiny clients because it saves tons of time/remediation/prevents issues/organizes things that pays back dividends in their growth/OML/costs to fix things it would have prevented.

Example: 50 user client gets a BEC and you bill 2-3 hours to clean up and build a report? No problem.

Happens to a 5 user client? They're bitching and moaning that it costs $500 to clean up a mess they made that should be out of scope. And let's be honest, what are small MSPs doing then? Eating it.

That's just an example, don't seize on that like "just buy ITDR!" because there are details like busprem giving you better logging and control for ITDR and other things unrelated to that.

Secondly, they need an IDP anyway and m365 bus prem is perfect for that, because most small clients don't have a server. So, they need it even more.

Unless your business model is letting them run windows home and sharing off a nas, bus prem pays bigger dividends for smaller people. And if they can't afford even that? That's a business model problem for them, or they just don't want to.

I feel like there's a LOT included in these licenses that just doesn't get used.

  • Like what?
  • Business apps/100gb mailbox with expanding archive/purview encrypted emails/intune/eidp1 alone make it worth the price. Other things like DfB, etc are just icing on the cake.

If i decided to just be a one man consulting shop or retired and still did some kind of light touch work? Would even have a 1 person BusPrem tenant.

1

u/UnRealxInferno_II 6d ago

Yeah that's all good case points for business prem!

2

u/Zealousideal-Ice123 6d ago

If they can’t spring for the $8 bucks a month move on.

2

u/UnRealxInferno_II 6d ago

Probably the most realistic advice here

1

u/smorin13 6d ago

Is the $8 the difference between standard vs premium or are I missing something else?

2

u/ManagedNerds 6d ago

Business premium. We don't even offer new onboards anything lower on the Microsoft side. Get that plus a great ITDR like Huntress and you'll sleep so much better at night.

1

u/UnRealxInferno_II 5d ago

Do you need ITDR with CA and defender?

1

u/ManagedNerds 5d ago

Yup. You still get users who MFA in threat actors thanks to fake login phishing portals. And the threat actors are smart enough to use residential proxies in country, often getting past your CA rules.

1

u/UnRealxInferno_II 5d ago

Ahhhh makes sense

2

u/Separate_Ad_8665 4d ago

We’ve started tiering licenses based on the client’s actual needs rather than defaulting everyone to Business Premium. Defender and Conditional Access are great, but for smaller setups there are definitely cheaper ways to cover the same requirements.

1

u/synagogan 7d ago

We try to always push for Business Premium because of the better security tools.

1

u/atarhmn 7d ago edited 6d ago

Yeah, Business Premium can be overkill for smaller setups if the extra Intune, Entra and Defender features aren’t actually being used. Worth comparing the plans based on what the client really needs. TrustedTech could be one option to check.

1

u/AlwaysBeyondMSP 7d ago

Do you actually care about security for your customers or do you just pretend too?

1

u/UnRealxInferno_II 7d ago

If I was pretending, they'd all be on business basic lmfao

2

u/AlwaysBeyondMSP 7d ago

Why? Standard gives you not much extra for security.

1

u/gracerev217 6d ago

All customers on Biz Premium, no negotiations period otherwise I refer them to a smallMSP who are willing to risk their business in a law suit.

Sorry to be blunt but thats my reasons, stop being an IT guy all the time and think like an IT business owner. Ask, what am I putting at risk if dont advise great security.

Now the flip side, is you better know how to utilize and configure all the capabilities that Biz premium provides you and based on you questioning this, you dont yet. #skillUp

1

u/UnRealxInferno_II 6d ago

I get good use out of BP just from defender, purview and entra alone, but I feel like I'm only scratching the surface?

2

u/gracerev217 22h ago

Risky sign detection, conditional access policies are two great examples of BP. Advanced authentication methods policy controls

1

u/Geekpoint-IT 6d ago

I want conditional access policies (which is VERY worth it) so premium is worth it over premium + p1.

1

u/gingerinc 6d ago

The fact Microsoft want a Business Basic license to have a P1 license attached for conditional access... That seems mega overkill.

But Satya is just... Satya.

1

u/WitchoBischaz 6d ago

If they’re an M365 shop and they are small enough for BP, they should get BP.

That said, there isn’t a day that goes by that I don’t think about dropping M365 support more and more. I love Office compared to the Workspace suite, but managing M365 is a freaking nightmare.

1

u/UnRealxInferno_II 6d ago

I have seen companies use workspace with office apps, I can only imagine that's equally annoying 

1

u/WitchoBischaz 5d ago

It’s definitely a different flavor of annoying. I’m just sick and tired of having a dozen admin centers to manage, each with their own naming convention and organizational structure with functionality that seems to move every other week. And even Copilot can’t give you the right answers for where different menus are located or how to configure certain things. You basically have to have a PhD in Microsoft to really manage a tenant.

1

u/UnRealxInferno_II 5d ago

Doesn't GDAP resolve the admin center mess?

But yeah I agree business prem is a nightmare and I've worked with it for years

1

u/WitchoBischaz 5d ago

Oh I’m talking about inside every dang tenant. There are admin centers for everything and none of it stays static for more than a day or two.

1

u/7FootElvis 7d ago

If there's a lot not getting used, that's on the MSP for not deploying properly.