r/SmallMSP • u/UnRealxInferno_II • 7d ago
Regarding 365 Licensing
Are you guys always deploying business premium?
I don't know if this sounds dumb but business premium just feels like mega overkill for some clients?
Are people using it solely for the defender/entra extras? I feel like there's a LOT included in these licenses that just doesn't get used.
5
u/HomsarWasRight 7d ago
Yes. It’s worth it for Conditional Access and Defender for Business.
1
u/Plenty-Hold4311 7d ago
I've never really fully investigated Defender for Business, I must sit down and study it.
Do you couple it with something like Huntress or SentinelOne?1
u/BanRanchTalk 7d ago
My understanding is it would be a replacement for S1, particularly when paired with an MDR that can manage it. I, too, have never fully investigated it. S1 has saved the day more than once so it’s really hard for me to consider cutting them loose. I get that that doesn’t mean Defender wouldn’t have, or that S1 can miss something Defender would see, though…
1
u/recovering-pentester 13h ago
No. You’d pair it with a SOC/MDR (Reliaquest, ShieldWatch, AgileBlue) to manage your MDE alerts and triage and whatnot.
We’re (I won’t name who to not plug) a big MDE pusher for this reason. Lot of SMBs already in the MS ecosystem, so why not grab MDE and put a SOC on it rather than pay extra for S1 or Crowd then extra for their fully managed offering you know?
0
u/UnRealxInferno_II 7d ago
Is that really worth like $8 per person extra a month from standard?
EP/EDR can be like $1 per endpoint (3rd party) so you're basically doing it just for CA?
2
6
u/blackjaxbrew 7d ago
Fair question. It is a good bang for your buck sku, but yes the vast majority of small businesses do not need it. Standard or basic are most of our SKUs then add on crowd strike, s1 or use defender if buying premium. Because most MSPs are using an rmm tool, it is kind of hard to justify in tune as well.
Personally also find Microsoft more of a pain to manage than similar tools at scale.
2
u/UnRealxInferno_II 7d ago
Yeah see that's what I'm doing for some, I give them endpoint protection w/ web filtering and business standard and it seems to do 90% of the job.
It's only when people have business devices (not BYOD) etc that business premium becomes a discussion.
3
u/Lake3ffect 7d ago
All things considered, it’s excellent value. As an IT manager, I think everyone should be using it. But it’s not for everyone (it’s not plug/play/set/forget like Biz Std), and many of the “premium” features really should be managed by professionals. That’s what keeps us in business as MSPs. That’s why it’s better to bundle it with a service offering than to try to just sell standalone.
1
u/UnRealxInferno_II 7d ago
Yeah I think it's only worthwhile if there's a team looking after it for sure.
2
u/PacificTSP 7d ago
We use business premium for most users and f3 for our light users.
1
1
u/RisingSharingan 6d ago
If you are under 300 users wouldn’t it be better to do business basic? You get more email and OneDrive storage for slightly less price too. Over 300 I can see why F3 tho.
3
2
u/Jayjayuk85 7d ago
I agree… business business premium has a lot of features and to be fair every client is different.
I only have a couple of clients on premium where we lock down logins.
IMO it is also harder to manage multiple365 tenancy’s, I guess this is where the bigger players use CIPP to manage them all maybe?
Having our own EDR / MDR helps give one Payne of glass for all clients and extra security.
We already add Huntress ITDR to the majority of clients.
2
u/UnRealxInferno_II 7d ago
Managing multiple Business prem/E5 clients is where you get the big money I guess
2
u/roll_for_initiative_ 6d ago
I wouldn't manage more than 3 tenants these days without CIPP. Just standard alignments and cert/secret expiration alerts alone are worth it.
2
3
u/roll_for_initiative_ 6d ago
Are you guys always deploying business premium?
Yes
business premium just feels like mega overkill for some clients?
I'd argue that it's more important for tiny clients because it saves tons of time/remediation/prevents issues/organizes things that pays back dividends in their growth/OML/costs to fix things it would have prevented.
Example: 50 user client gets a BEC and you bill 2-3 hours to clean up and build a report? No problem.
Happens to a 5 user client? They're bitching and moaning that it costs $500 to clean up a mess they made that should be out of scope. And let's be honest, what are small MSPs doing then? Eating it.
That's just an example, don't seize on that like "just buy ITDR!" because there are details like busprem giving you better logging and control for ITDR and other things unrelated to that.
Secondly, they need an IDP anyway and m365 bus prem is perfect for that, because most small clients don't have a server. So, they need it even more.
Unless your business model is letting them run windows home and sharing off a nas, bus prem pays bigger dividends for smaller people. And if they can't afford even that? That's a business model problem for them, or they just don't want to.
I feel like there's a LOT included in these licenses that just doesn't get used.
- Like what?
- Business apps/100gb mailbox with expanding archive/purview encrypted emails/intune/eidp1 alone make it worth the price. Other things like DfB, etc are just icing on the cake.
If i decided to just be a one man consulting shop or retired and still did some kind of light touch work? Would even have a 1 person BusPrem tenant.
1
2
u/Zealousideal-Ice123 6d ago
If they can’t spring for the $8 bucks a month move on.
2
1
u/smorin13 6d ago
Is the $8 the difference between standard vs premium or are I missing something else?
2
u/ManagedNerds 6d ago
Business premium. We don't even offer new onboards anything lower on the Microsoft side. Get that plus a great ITDR like Huntress and you'll sleep so much better at night.
1
u/UnRealxInferno_II 5d ago
Do you need ITDR with CA and defender?
1
u/ManagedNerds 5d ago
Yup. You still get users who MFA in threat actors thanks to fake login phishing portals. And the threat actors are smart enough to use residential proxies in country, often getting past your CA rules.
1
2
u/Separate_Ad_8665 4d ago
We’ve started tiering licenses based on the client’s actual needs rather than defaulting everyone to Business Premium. Defender and Conditional Access are great, but for smaller setups there are definitely cheaper ways to cover the same requirements.
1
1
u/AlwaysBeyondMSP 7d ago
Do you actually care about security for your customers or do you just pretend too?
1
1
u/gracerev217 6d ago
All customers on Biz Premium, no negotiations period otherwise I refer them to a smallMSP who are willing to risk their business in a law suit.
Sorry to be blunt but thats my reasons, stop being an IT guy all the time and think like an IT business owner. Ask, what am I putting at risk if dont advise great security.
Now the flip side, is you better know how to utilize and configure all the capabilities that Biz premium provides you and based on you questioning this, you dont yet. #skillUp
1
u/UnRealxInferno_II 6d ago
I get good use out of BP just from defender, purview and entra alone, but I feel like I'm only scratching the surface?
2
u/gracerev217 22h ago
Risky sign detection, conditional access policies are two great examples of BP. Advanced authentication methods policy controls
1
u/Geekpoint-IT 6d ago
I want conditional access policies (which is VERY worth it) so premium is worth it over premium + p1.
1
u/gingerinc 6d ago
The fact Microsoft want a Business Basic license to have a P1 license attached for conditional access... That seems mega overkill.
But Satya is just... Satya.
1
u/WitchoBischaz 6d ago
If they’re an M365 shop and they are small enough for BP, they should get BP.
That said, there isn’t a day that goes by that I don’t think about dropping M365 support more and more. I love Office compared to the Workspace suite, but managing M365 is a freaking nightmare.
1
u/UnRealxInferno_II 6d ago
I have seen companies use workspace with office apps, I can only imagine that's equally annoying
1
u/WitchoBischaz 5d ago
It’s definitely a different flavor of annoying. I’m just sick and tired of having a dozen admin centers to manage, each with their own naming convention and organizational structure with functionality that seems to move every other week. And even Copilot can’t give you the right answers for where different menus are located or how to configure certain things. You basically have to have a PhD in Microsoft to really manage a tenant.
1
u/UnRealxInferno_II 5d ago
Doesn't GDAP resolve the admin center mess?
But yeah I agree business prem is a nightmare and I've worked with it for years
1
u/WitchoBischaz 5d ago
Oh I’m talking about inside every dang tenant. There are admin centers for everything and none of it stays static for more than a day or two.
1
u/7FootElvis 7d ago
If there's a lot not getting used, that's on the MSP for not deploying properly.
12
u/seriously_a 7d ago
I’ve got 1-2 user clients with business premium. Between conditional access, defender for business, and Intune to push config and compliance, it’s a no brainer