1 min read
Microsoft 365 Backup: What Every Business Needs to Know
Many organisations assume their Microsoft 365 data is automatically backed up by Microsoft.
If your business runs Microsoft 365 Business Premium, E3, or E5, there's a good chance you're already paying for a far more capable security toolkit than the one you're actually using. Most organisations treat Microsoft Defender as antivirus: something that runs quietly in the background and occasionally pops up a notification. In reality, the Defender suite includes attack prevention, vulnerability scanning, automated response, and even built-in phishing simulation, all sitting inside licences many businesses already hold.
The gap isn't budget. It's configuration. Below are five specific Defender capabilities we regularly find switched off, ignored, or left in a default state during endpoint protection reviews, what each one actually does, and how to check whether yours are active.
What it does: ASR rules block specific, well-documented attack techniques before they can execute, rather than waiting to detect malicious activity after the fact. Examples include stopping Office applications from launching child processes, blocking credential theft from the LSASS process, and preventing executable content from running in email attachments or removable USB drives.
Why it's overlooked: ASR rules are not enabled by default. They live inside the Microsoft Defender portal or Intune and require someone to deliberately turn them on, often in "audit mode" first to check for false positives, then in "block mode" once confirmed. Many businesses enable audit mode during initial setup, then never return to switch it to enforcement.
Real-world impact: A large share of ransomware and living-off-the-land attacks rely on exactly the techniques ASR rules target, such as abusing legitimate tools like PowerShell or WMI to move laterally. Enforcing these rules closes off common entry points without needing a human to spot anything first.
Where to check it: Microsoft Defender portal → Reports → Attack surface reduction rules. This shows which rules are active, in audit mode, or not configured at all across your device estate.
Licensing: Included in Microsoft Defender for Business, Defender for Endpoint Plan 1 and 2.
What it does: Continuously scans every enrolled device for missing patches, outdated software, risky browser extensions, and security misconfigurations, then ranks them by real-world exploitability rather than presenting a raw list of CVEs. It also flags expiring digital certificates and vulnerable network shares.
Why it's overlooked: This sits under a separate area of the Defender portal from the antivirus dashboard IT teams check daily, so it's easy to licence it and never open it. Many businesses still rely on manual patch checks or assume Windows Update alone covers this.
Real-world impact: Gives your team a prioritised, evidence-based patching queue instead of guesswork, closing the gap between "a vulnerability exists" and "someone actually knew about it."
Where to check it: Microsoft Defender portal → Vulnerability management → Dashboard.
Licensing: Included in Defender for Endpoint Plan 2 and Defender for Business; available as an add-on for Plan 1.
What it does: When an alert fires, AIR automatically investigates it, correlating related evidence across the device, then takes remediation action such as isolating the device, killing a malicious process, or quarantining a file, without waiting for an analyst to act first.
Why it's overlooked: AIR is often left in a semi-automatic mode that requires manual approval for every single remediation action. For a small IT team without a 24/7 security operations centre, that approval queue backs up fast, and by the time someone reviews it, the automation has provided no real speed advantage.
Real-world impact: Properly configured, AIR can isolate a compromised device in minutes rather than hours, which is often the difference between a contained incident and a wider breach.
Where to check it: Microsoft Defender portal → Settings → Endpoints → Advanced features, and device group automation levels under Device configuration.
Licensing: Included in Defender for Business and Defender for Endpoint Plan 2.
What it does: A query-based threat hunting tool inside Defender XDR that lets you search across endpoint, email, identity, and cloud app signals using Kusto Query Language (KQL), rather than relying only on the alerts Microsoft's own detections generate.
Why it's overlooked: It looks like a data analyst's tool, not a security setting, so smaller IT teams assume it's out of scope for them and never open it. In practice, Microsoft publishes a shared library of ready-made queries, so no KQL experience is required to get value from it on day one.
Real-world impact: Advanced Hunting catches patterns that generic alerts miss, for example, an unusual sign-in location followed by a new mailbox forwarding rule, a classic pattern in business email compromise that no single alert typically flags on its own.
Where to check it: Microsoft Defender portal → Hunting → Advanced hunting → Query library (start here rather than writing queries from scratch).
Licensing: Included with Defender for Endpoint Plan 2 and Defender for Office 365 Plan 2 combined, or Microsoft 365 E5 / E5 Security.
What it does: Launches real, safe phishing, credential-harvesting, and malware-attachment simulations against your own staff directly from Defender, then automatically enrols anyone who clicks into short, targeted training modules.
Why it's overlooked: Businesses often buy a separate third-party phishing simulation tool without realising an equivalent is already included in their Microsoft 365 licence, simply because it's tucked inside the Defender for Office 365 admin area rather than marketed as a standalone product.
Real-world impact: Turns an annual, one-off training session into an ongoing, measurable programme, and gives you a concrete click-rate metric to report to leadership rather than a vague sense that "staff have been trained."
Where to check it: Microsoft Defender portal → Email & collaboration → Attack simulation training.
Licensing: Included in Defender for Office 365 Plan 2, Microsoft 365 E5, or as an add-on to Business Premium.
| Feature | What it prevents or reveals | Minimum licence |
|---|---|---|
| Attack Surface Reduction Rules | Common ransomware and living-off-the-land techniques | Defender for Business, Defender for Endpoint P1 |
| Vulnerability Management | Unpatched software, risky extensions, misconfigurations | Defender for Endpoint P2, Defender for Business |
| Automated Investigation and Response | Slow manual response to confirmed threats | Defender for Business, Defender for Endpoint P2 |
| Advanced Hunting | Multi-stage attacks that single alerts miss | Defender for Endpoint P2 + Office 365 P2, or E5 |
| Attack Simulation Training | Untested, unmeasured phishing awareness | Defender for Office 365 P2, E5, or Premium add-on |
Do I need Microsoft 365 E5 to get these features? No. Attack Surface Reduction, Vulnerability Management, and Automated Investigation and Response are all included in Microsoft Defender for Business, which is bundled into Microsoft 365 Business Premium (around $22 per user, per month) or available as a standalone add-on from around $3 per user, per month for businesses on Business Basic or Standard. Advanced Hunting and Attack Simulation Training typically require Plan 2-level licensing or E5.
How do I find out which of these are already switched on for my organisation? Start with your Microsoft Secure Score in the Defender portal, which flags major gaps, then check each feature's dedicated settings page listed above. This takes most IT teams under an hour to audit across a typical SMB environment.
Is Microsoft Defender enough on its own, or do we still need other tools? For most SMBs, a fully configured Defender suite covers endpoint, email, and identity threats to a genuinely strong standard. Larger or higher-risk organisations often still layer in dedicated email gateways, network segmentation, and a tested incident response plan alongside it, rather than relying on Defender in isolation.
We already pay for Microsoft 365 Business Premium. Are we already covered? Licensed, yes. Configured, not necessarily. Business Premium includes Defender for Business and Defender for Office 365 Plan 1, but none of the five features above turn themselves on automatically; each requires deliberate setup.
Can Protrona check and configure this for us? Yes. We regularly carry out Defender configuration reviews as part of our managed cybersecurity and device management services, and can benchmark your current setup against your Secure Score as a starting point.
Most businesses we review are licensed for more security than they're using. A short audit of your current Microsoft 365 tenant will tell you exactly which of these five features are active, which are sitting dormant, and what switching them on would involve. Get in touch to arrange one.
1 min read
Many organisations assume their Microsoft 365 data is automatically backed up by Microsoft.
1 min read
As organisations increasingly adopt AI tools to improve productivity, one question comes up time and time again:
1 min read
Security awareness training has long focused on helping employees identify suspicious emails. Staff were taught to look for spelling mistakes, poor...