Published:

What defensible IT actually means
A defensible environment is not one with zero incidents. It is one where the business can answer four practical questions clearly: what is our baseline, where is it in place, who owns each part, and how do we know it is maintained.
For owner-managed SMEs on Microsoft 365, defensibility is an ownership problem, not a technology problem. The platform provides the controls. The business has to configure them, name the owners, and review them on a rhythm.
The licensing floor: why the right subscription matters
Not every Microsoft 365 plan can support a defensible environment. Microsoft 365 Business Basic and Business Standard include Exchange Online, Office apps, and OneDrive or SharePoint, but they stop short of the security controls that make a tenant genuinely hardened.
Microsoft 365 Business Premium is the licensing floor where a defensible configuration becomes possible. It includes Microsoft Entra ID P1 (Conditional Access), Microsoft Intune (device compliance and management), Microsoft Defender for Business (endpoint detection and response), and Microsoft Defender for Office 365 Plan 1 (Safe Links, Safe Attachments, anti-phishing).
Identity: the first line of defence
Identity is the most frequently compromised surface in Microsoft 365, and it is also the one where SMEs most commonly leave default settings in place.
Multi-factor authentication
Microsoft reports that multi-factor authentication blocks the majority of automated credential attacks. Every Microsoft 365 for business subscription includes Security Defaults, which enforce basic MFA for all users and block legacy authentication protocols.
Break-glass accounts
Every defensible tenant needs two cloud-only Global Admin accounts that are excluded from all Conditional Access policies. They exist solely for recovery when a misconfiguration locks the normal administrators out.
Phishing-resistant authentication
The only MFA factor that survives AiTM attacks is one bound to the origin of the login. In 2026, three options meet this bar: FIDO2 hardware keys, Windows Hello for Business on managed Windows endpoints, and Entra passkeys.
Device management: proving the endpoint is trusted
Microsoft Intune is included in Business Premium. Without it, the business has no way to prove that devices accessing Microsoft 365 are encrypted, patched, or running security software.
Intune compliance policies set the criteria a device must meet before it is considered trustworthy. The most common controls are disk encryption, current OS patches, and Defender for Endpoint enrollment.
Email and collaboration: the most exploited surface
Out of the box, Microsoft 365 applies baseline anti-spam and anti-malware policies to every mailbox. Business Premium adds Microsoft Defender for Office 365 Plan 1, which includes Safe Links and Safe Attachments.
Anti-phishing policies with impersonation protection are separate from the baseline. They need to be tuned to the organisation's domain and executive names to catch the BEC (business email compromise) messages that mimic internal senders.
Backup and recovery: the independence question
Microsoft's shared responsibility model is often misunderstood. Microsoft maintains the platform, the data centres, and the service availability. The customer owns the data and the controls that protect it.
A genuinely defensible backup strategy requires independent storage outside the Microsoft 365 tenant, controlled by separate credentials, and not subject to the same propagation path as the primary environment.
Maintenance: the control that drifts
The most common cause of security degradation in SME Microsoft 365 environments is not a technical failure. It is drift. Drift happens when someone changes a setting, disables a policy, adds an exception, or skips an update without a review process.
FAQ
Does Microsoft 365 include a backup by default?
No. Microsoft 365 provides platform-level retention features such as the Recycle Bin, version history, and litigation hold. A genuine backup requires independent storage outside the Microsoft 365 tenant.
What is the minimum Microsoft 365 plan for a defensible environment?
Microsoft 365 Business Premium is the practical floor. It is the first plan that includes Microsoft Entra ID P1, Microsoft Intune, Microsoft Defender for Business, and Microsoft Defender for Office 365 Plan 1.
Why is Conditional Access important beyond basic MFA?
Conditional Access applies policy-based rules to every sign-in. It can block legacy authentication protocols, require compliant devices, restrict sign-in to expected geographies, and enforce session timeouts.
How often should a Microsoft 365 security baseline be reviewed?
A monthly review cadence is the standard for defensible environments. The review should cover new admin accounts, Conditional Access exceptions, policy drift, backup test results, and alert ownership.
Is Defender for Business enough endpoint protection for a small business?
For a typical 10–50 person SME on a Microsoft-centric stack, Defender for Business is the appropriate endpoint layer. It includes EDR, automated investigation and response, and attack surface reduction.
This article was generated with AI assistance and reviewed by the Infinite Cloud IT marketing team.

Modern Workplace
Microsoft 365 for Kent SMEs: Backup, Security and CE

Cyber Security
Cyber Essentials Last Chance for 2026: Can SMEs Still Certify Before Year-End?

Managed IT Services
IT Budget Mid-Year Review: What SMEs Should Check in September

Cyber Security
September IT Security Review: A Practical Guide for UK SMEs

Managed IT Services