Skip to content

Blog

Practical Guides

Not all Microsoft 365 licenses are the same.

Most businesses assume Microsoft 365 licensing is a feature checklist. Storage limits, app access, mailbox size. It isn't. The plan a business is on determines whether the tenant has any real security behind it at all.

Dawn SizerDawn Sizer · CEO and Co-Founder, 3rd Element Consulting

The assumption that costs businesses later.

Business Basic, Business Standard, and Business Premium all say "Microsoft 365" on the invoice. Most businesses assume the difference is storage and which desktop apps are included, and pick based on price.

That assumption is wrong in a way that matters. Business Basic and Business Standard give a business email, files, and the Office apps. They do not give the business the tools that actually protect an identity once someone has a username and password, which, eventually, an attacker will.

Business Premium is the plan that adds Microsoft Defender for Business, Intune for device management, and conditional access. Those three are not extras. They are the difference between a login that can be evaluated for risk and a login that can't be.

A business running Standard because it looked like enough is paying for Microsoft 365 without paying for the part of it that stops a stolen password from becoming a stolen account.

Why identity is the attack, not the target.

Most security spending still assumes the attacker is trying to get through a firewall or plant something on a device. For most small and mid-size businesses, that's not how it happens anymore. It happens through identity. A phished password, a reused password from another breach, a convincing email that gets someone to approve an MFA prompt they shouldn't have.

Once an attacker has valid credentials, they don't look like an attacker. They look like an employee logging in. Everything downstream, email, files, financial systems, is reachable through that one identity.

This is why MFA alone gets treated as more protective than it actually is. MFA confirms someone has a second factor at the moment of login. It doesn't evaluate whether the device logging in is managed, whether the location is reasonable, or whether the session itself gets reused later. That evaluation is conditional access, and conditional access is a Business Premium feature.

What conditional access actually does, and why the device matters.

Conditional access is a set of rules that decide whether a login is allowed to proceed, based on more than a password and a code. Is the device managed and known to the business, or is it unmanaged and unknown. Is the sign-in coming from an expected location. Does the risk level of this specific sign-in look normal.

Without conditional access, MFA is a single gate. Pass it once and you're in, from any device, from anywhere. With conditional access, the login is evaluated every time against the actual conditions of that login. A correct password and a correct MFA code from an unmanaged laptop in a country the business doesn't operate in can be blocked automatically, before anyone has to notice and react.

The device matters because Intune, also part of Business Premium, is what makes "managed device" a real, enforceable category instead of an honesty system. A managed device can be checked for encryption, for whether it's up to date, for whether it's the device the business actually issued. An unmanaged device is a black box. Conditional access policies that check for a managed device are only meaningful if managed devices actually exist, which requires Intune, which requires Business Premium.

Token theft: why MFA doesn't always save you.

Token theft is why a business can have MFA turned on everywhere and still get breached. When someone signs in successfully, Microsoft 365 issues a session token, proof the login already happened, so the person isn't asked to authenticate again for every single action. That token lives on the device for a period of time.

If an attacker can steal that token, through a phishing page that sits between the user and the real login, through malware on the device, through a compromised browser, they don't need the password or the MFA code at all. They have a copy of an already-authenticated session. They can use it to get into the account directly, MFA prompt already satisfied, because from Microsoft 365's perspective, the login already happened.

This is the specific thing conditional access is built to catch. A stolen token used from an unmanaged device, an unexpected location, or under conditions that don't match how the real user signs in can be flagged and blocked, even though the token itself is technically valid. Without conditional access evaluating every use of that token, a stolen session can keep working until someone notices something is wrong, which is often after real damage is done.

Why saving passwords in the browser makes this worse.

Browser-saved passwords are a common target for exactly this reason. Malware built to steal credentials looks first at what's saved in the browser, because it's often unencrypted or weakly protected on the device itself, and because browsers autofill it without re-verifying who's asking.

A password saved in the browser also isn't tied to MFA or conditional access at the moment it's used. If the device itself is compromised, saved browser passwords hand over the credential directly, no phishing page or token theft required.

A password manager built for business use is a different thing. It has its own protections and doesn't hand credentials to whatever process on the device asks for them.

What this actually means for a licensing decision.

Choosing Business Standard over Business Premium to save a few dollars per user per month is a real decision with a real consequence. It means running the business on identity protection that stops at a password and an MFA prompt, with no way to evaluate the device, the location, or whether the session itself has been stolen.

The gap doesn't show up on the invoice. It shows up the first time a credential gets phished and there's nothing behind MFA to catch what happens next.

If you don't know which Microsoft 365 plan your business is actually running, or whether conditional access and Intune are configured on it, that's exactly what an IT Environment Review is for.

Common questions

Questions leadership usually asks first.

Next step

Get a clearer view of your IT environment.

Find out what is working, where the risks are, and what needs attention next.