Microsoft Defender for Endpoint: What UK SMEs Need to Know
Microsoft Defender for Endpoint (MDE) is Microsoft's enterprise-grade endpoint detection and response platform. It is distinct from Microsoft Defender for Business — understanding which product your business has, and whether it is correctly configured, is essential for effective endpoint security.
Overview
Microsoft Defender for Endpoint is the enterprise EDR platform. For SMEs, Microsoft Defender for Business (included in M365 Business Premium) provides equivalent protection. Both require deliberate configuration beyond defaults — default settings do not deliver full security value. AMVIA configures and manages Defender for Business for UK SMEs.
Learn about managed endpoint securityWhat is Microsoft Defender for Endpoint?
Microsoft Defender for Endpoint (MDE) is Microsoft's enterprise-grade EDR platform: it detects, investigates, and responds to threats on Windows, macOS, Linux, iOS, and Android devices. It is distinct from the free Windows Defender Antivirus built into Windows, and from Microsoft Defender for Business, the SME-scoped edition.
The Defender brand causes genuine confusion because three different products share the name:
- Windows Defender Antivirus — consumer-grade signature-based malware protection built into Windows 10 and 11. No centralised management, no behavioural EDR.
- Microsoft Defender for Endpoint — the enterprise EDR platform, licensed standalone or via Microsoft 365 E5.
- Microsoft Defender for Business — a separate product for SMEs with up to 300 users, included in Microsoft 365 Business Premium.
According to the DSIT Cyber Security Breaches Survey 2025, 43% of UK businesses experienced a cybersecurity breach or attack in the past 12 months, which makes properly configured endpoint protection a baseline control, not a luxury.
What do the Defender for Endpoint plans include?
Microsoft Defender for Endpoint ships in two tiers. Plan 1 covers prevention and basic response; Plan 2 adds full EDR, automated investigation, and threat hunting. Plan 2 is included in Microsoft 365 E5, which is why standalone MDE is primarily an enterprise choice.
- Plan 1 (MDE P1): next-generation antivirus, attack surface reduction rules, device control, and manual response actions.
- Plan 2 (MDE P2): everything in P1 plus endpoint detection and response with full telemetry, automated investigation and remediation, threat and vulnerability management, and proactive threat hunting.
The vulnerability management module in P2 continuously assesses enrolled endpoints — flagging unpatched software, weak configurations, and known exposures — and ranks them by exploitability so teams fix what matters first. Microsoft documents the full capability set in its endpoint security guidance.
Key MDE Plan 2 capabilities
- Behavioural detection using machine learning and Microsoft's global threat intelligence
- EDR with device isolation, process termination, and file quarantine
- Automated investigation that analyses alert chains and recommends or executes remediation
- Threat and vulnerability management for continuous posture assessment
- Proactive threat hunting with advanced queries across endpoint telemetry
- Integration with Microsoft Sentinel for SIEM and extended detection and response (XDR)
Is Defender for Business the right choice for an SME?
For most UK SMEs, yes. Microsoft Defender for Business — included in Microsoft 365 Business Premium for organisations with up to 300 users — provides protection equivalent to MDE Plan 2, packaged for businesses without a dedicated security team. It is one of the most cost-effective routes to enterprise-grade endpoint security available.
Defender for Business includes next-generation antivirus, endpoint detection and response, attack surface reduction, automated investigation, and centralised management through the Microsoft 365 Defender portal. Its detection draws on Microsoft's cloud threat intelligence, built from telemetry across hundreds of millions of endpoints. When a new threat appears anywhere in that network, indicators reach connected endpoints within minutes — far faster than antivirus that waits for a scheduled signature update.
| Capability | Windows Defender AV | Defender for Business | Defender for Endpoint P2 |
|---|---|---|---|
| Built-in antivirus | Yes | Yes | Yes |
| Centralised management | No | Yes | Yes |
| Endpoint detection & response (EDR) | No | Yes | Yes |
| Attack surface reduction rules | Limited | Yes | Yes |
| Automated investigation | No | Yes | Yes |
| Threat & vulnerability management | No | Yes | Yes |
| Proactive threat hunting | No | No | Yes |
| Licensing | Free with Windows | M365 Business Premium | M365 E5 / standalone |
How much does Microsoft Defender for Business cost?
Defender for Business carries no separate endpoint-security line item when you buy Microsoft 365 Business Premium, listed at £16.90 per user/month (ex VAT, annual commitment). Businesses on Business Basic (£4.60) or Standard (£9.60) do not receive Defender for Business.
That makes Business Premium the most direct upgrade path for an SME that wants EDR. Standalone Defender for Business is also available as an add-on for tenants that cannot move to Premium. Whichever route fits, the cost of the licence is trivial against the downside: the average cost of a data breach for UK organisations was £3.58 million in 2024 (IBM 2024).
Why does Defender need configuration beyond the defaults?
Because the defaults protect the basics, not the business. Defender for Business and MDE ship with sensible starting settings, but the controls that stop real attacks — attack surface reduction, controlled folder access, network protection — are off or in audit mode until someone deliberately turns them on.
Attack surface reduction (ASR) rules block common attack techniques at source: stopping Office apps from spawning executables (which kills most macro attacks), blocking credential theft from LSASS memory, and blocking executable content from email attachments. With 85% of breaches involving phishing (DSIT 2025), ASR rules that block email-borne techniques earn their keep. But many organisations leave ASR in audit-only mode indefinitely — visibility, zero protection.
AMVIA configures Defender to Microsoft's recommended security baseline:
- ASR rules enabled in block mode, not audit-only
- Controlled folder access configured to resist ransomware encryption
- Network protection enabled to block known malicious domains
- Exclusions reviewed so nothing silently weakens detection
Who investigates the alerts Defender generates?
Detection is only half the job. Defender for Business raises alerts; someone has to triage them, separate noise from genuine threats, and contain what is real. Only 14% of UK businesses have a formal incident response plan (DSIT 2025), so most have no structured process for the alerts their tools produce.
AMVIA monitors Defender for Business alerts through AmviaIQ, investigates significant detections, and takes containment action when a threat is confirmed — turning a detection tool into a managed control. For businesses that want a heavier analyst layer, AMVIA's in-house 24/7 SOC provides a second opinion on endpoint alerts as part of managed detection and response. Where a full analyst function is needed, our managed SOC service sits on top of Defender.
How are Defender devices deployed and managed?
Centrally. Every Defender for Business and MDE device is managed through Microsoft Intune and the Microsoft 365 Defender portal — Intune handles enrolment, policy, and compliance; the Defender portal handles alerts, investigations, and endpoint health. There is no device-by-device fiddling.
Enrolment can be automated with Windows Autopilot for new devices or scripted for an existing estate. Once enrolled, devices receive security baselines automatically, and Intune compliance policies can block non-compliant devices from corporate data via Conditional Access until they are remediated. AMVIA runs the full process — enrolling devices, deploying agents, applying baselines, and validating that every endpoint reports correctly — then manages it on an ongoing basis. Contact AMVIA on 0333 733 8050 to discuss Defender for Business for your business.
Defender for Business configuration checklist
- All managed endpoints enrolled in Defender for Business
- ASR rules enabled in block mode — not left in audit-only
- Controlled folder access configured against ransomware
- Network protection enabled on every endpoint
- Exclusions reviewed — no broad exclusions that weaken detection
- Alerts monitored and investigated — not just collected
Key Points
What UK businesses need to know about Microsoft Defender for Endpoint.
Not the Same as Windows Defender
Windows Defender (built into Windows) provides basic consumer protection. Defender for Endpoint/Business adds EDR, attack surface reduction, and centralised management.
Behavioural Detection
MDE uses Microsoft's global threat intelligence and machine learning to detect threats based on behaviour, effective against novel and fileless attacks.
Defender for Business for SMEs
Microsoft Defender for Business — included in M365 Business Premium — provides MDE-equivalent protection scoped and priced for SMEs.
Centralised Management via Intune
All Defender for Business/MDE devices managed centrally through Microsoft Intune and the M365 Defender portal — not relying on local device management.
Defender for Business Configuration Checklist
All managed endpoints enrolled in Defender for Business
Attack surface reduction rules enabled — not left in audit-only mode
Controlled folder access configured to protect against ransomware
Network protection enabled on all endpoints
Exclusions reviewed — no unnecessarily broad exclusions that weaken detection
Alerts monitored and investigated — not just collected
Frequently Asked Questions
Same engine, different packaging: Defender for Endpoint is the enterprise EDR platform; Defender for Business is the SME edition — bundled into Microsoft 365 Business Premium (£16.90/user/month ex VAT) with the core EDR capability but simplified management and some enterprise features trimmed.
For most SMEs, yes — the modern Defender stack is a genuine EDR product, not the free consumer antivirus people remember. The caveat is operational: it needs configuring past the defaults and its alerts need watching. Unmonitored EDR is a dashboard, not a defence.
You already own the capability; whether you're covered depends on configuration. Most tenants we audit have Defender features paid for but never enabled — policies at defaults, no alert triage. A one-day audit tells you exactly where you stand.
Someone with security context, around the clock — attacks don't keep office hours, and 43% of UK businesses were breached or attacked in the past year (DSIT 2025). AMVIA runs Defender as a managed service: deployment, hardening and 24/7 triage on Enterprise plans.
Get Defender for Business Properly Configured
AMVIA configures Microsoft Defender for Business to its full security potential — enabling attack surface reduction, monitoring alerts, and managing endpoint security as a complete service.
Related Resources
Managed Antivirus for Business
How AMVIA deploys and manages Defender for Business as a managed endpoint protection service.
EDR for UK Businesses
Understanding endpoint detection and response and why it replaces traditional antivirus.
EDR vs Antivirus
Why Defender for Business (EDR) is fundamentally different from Windows Defender Antivirus.
Protect your business → Get Cybersecurity Assessment