Two weeks ago, a managing director told me — without looking anything up — exactly what his company pays Microsoft every year. Down to the euro. Then I asked a second question: how much of the security included in that number is actually switched on? He looked at his IT lead. His IT lead looked at his notes. Nobody in the room had an answer.

That moment is not unusual. It is the single most common finding when I review a company that went all-in on Microsoft 365. The invoice is well understood. The coverage behind it is not.

In short

If your company runs on Microsoft 365 with an advanced licence, you very likely own a stronger security posture than the one currently protecting you — and the gap is a settings page, not a purchase order. Onboarding a platform is not the same as switching its capabilities on. The three that matter most at leadership level: device discovery, tamper protection and automatic attack disruption, and the Defender-to-Intune signal connection that no standalone product can replicate.

The invoice you know, the protection you don't

Here is what typically happened in these companies, and none of it was a mistake at the time. A few years ago leadership made a strategic decision: consolidate on one platform. Mail, files, collaboration, identity — all Microsoft. Somewhere along the way the licence tier went up, usually because a specific feature was needed, sometimes because a partner recommended it. The security capabilities came along in the same bundle.

Then the project ended. The migration was declared successful, the consultants moved on, and the environment entered maintenance mode: keep it running, answer tickets, do not break anything. The advanced protection that came with the licence was never on anyone's task list — not because the IT team is careless, but because "review everything we already own" is a project nobody commissions.

The consequence is quiet and expensive. Some companies pay twice, buying third-party tools that duplicate what the existing licence already covers. Others simply carry the gap. And if something does happen, the uncomfortable question will not come from me — it will come from the insurer, asking why protection you demonstrably paid for was demonstrably off.

"But we have it running" — the dangerous half-truth

When I raise this, the answer is almost always the same: we onboarded that years ago, it is running. And it is — in the same way a car with disabled airbags is running. It drives. It gets you to work. The difference only shows on the one day it matters.

Onboarding a security platform means the devices report in. It does not mean the capabilities are working for you. Between those two states sits a settings page most people have opened exactly once, during initial setup, under time pressure, with a go-live date breathing down their neck. I keep finding the same picture there: half the platform dark. Paid for. Never touched.

What actually changes when you switch it on

In a Microsoft-365-first company the platform in question is Defender for Endpoint, and its unused capabilities fall into three groups that matter at leadership level.

You see what you actually own. Device discovery turns your existing managed machines into sensors that find the unmanaged ones — the old laptop in the warehouse, the printer nobody inventoried, the switch a contractor left behind. No new hardware, no new agent. The fleet maps itself, and anything appearing where it should not triggers an alert. Most companies I visit discover devices in the first week that nobody knew existed.

Attackers lose their favourite move. Tamper protection prevents anyone — including malware running with admin rights — from quietly disabling your protection or excluding entire drives from scanning. In real ransomware cases, switching off the defences is step one of the playbook. This single toggle takes that step away. Automatic attack disruption goes further: when telemetry recognises an active attack chain with high confidence, the compromised device is contained within minutes, before a human has read the alert. At 2 a.m. on a Saturday, that is the difference between one encrypted laptop and an encrypted company.

The platform talks to itself. This is the part no standalone product replicates, and the real answer to "why M365-first." Connect Defender to Intune and a device's risk score feeds directly into your access rules: a laptop that looks compromised loses access to sensitive systems automatically and regains it when clean. Endpoint signals flow into cloud app discovery, so shadow IT becomes visible from telemetry you already collect. No integration project, no middleware, no additional vendor contract. The signals connect because it is one platform — that connection is what the higher licence tier actually buys, and it is precisely the part that stays off most often. It is the same wiring described in the Devices pillar.

Why this is a leadership topic, not a ticket

None of the toggles above require new budget. What they require is a decision: someone has to own the question "are we using what we pay for?" — and in my experience that question only gets answered when it comes from the top. IT teams optimise for stability, and rightly so; every activated feature is a change, and change carries risk. That is a legitimate concern, which is why some capabilities should be piloted before a global rollout. But "we might break a legacy script" is a scheduling problem. "Our paid protection was off during the incident" is a liability problem. Those two do not weigh the same.

Key takeaway

If your company runs on Microsoft 365 with an advanced licence, there is a good chance you own a meaningfully stronger security posture than the one currently protecting you — and the gap between the two is a settings page, not a purchase order. The honest first step costs one meeting: ask your IT lead to walk you through what is on, what is off, and why. If the answer to "why is this off" is silence, you have found your starting point.

If you would rather have an outside pair of eyes on that settings page first, get in touch — reviewing it takes half a day, and you will know exactly where you stand.

Glossary

Defender for Endpoint
Microsoft's endpoint detection and response platform, included in Microsoft 365 E5 and available as an add-on. Onboarding a device is not the same as enabling its capabilities.
Device discovery
Uses already-managed endpoints as sensors to find unmanaged devices on the same network — no additional hardware or agent required.
Tamper protection
Prevents security settings from being disabled or scan exclusions added, even by processes running with administrative rights.
Automatic attack disruption
Contains a compromised device automatically when an active attack chain is recognised with high confidence, without waiting for an analyst.
Device risk score
A Defender-calculated risk value for an endpoint that can be consumed by Intune compliance and Conditional Access to gate access automatically.

Frequently Asked Questions

Is Microsoft Defender for Endpoint included in what we already pay for?

If you hold Microsoft 365 E5 it is included; it is also available as a standalone add-on. The more common finding is not a missing licence but an owned licence whose capabilities were never enabled after onboarding.

What is the difference between onboarding Defender and actually using it?

Onboarding means devices report telemetry. Using it means capabilities like tamper protection, device discovery, attack disruption and the Intune risk-signal connection are switched on and configured. Most tenants have done the first and not the second.

Which Defender capabilities should we switch on first?

Tamper protection is the highest value per minute of effort, because disabling defences is step one in most ransomware playbooks. Device discovery is the fastest way to learn what is actually on your network. The Intune risk-signal connection delivers the most long-term value and is most often left off.

Do we still need a third-party endpoint tool if we are Microsoft 365-first?

Often not — many companies pay twice for capabilities their existing licence already covers. Check what your current tier includes and what is actually enabled before adding another vendor. A third-party tool is justified by a specific capability gap, not by a Defender configuration nobody has reviewed.


References

  1. Microsoft Learn: Microsoft Defender for Endpoint overview
  2. Microsoft Learn: Protect security settings with tamper protection
  3. Microsoft Learn: Automatic attack disruption in Microsoft Defender XDR
  4. Microsoft Learn: Device discovery overview