Micrososft 365 Solutions Architect, Cole Kaparos, walks through the full range of security capabilities available in Microsoft 365 Business Premium and the add‑ons available to extend it, showing how Microsoft has quietly become a complete, enterprise‑grade security platform for SMBs.
Cole Kaparos walks through the full range of security capabilities available in Microsoft 365 Business Premium and the add‑ons available to extend it, showing how Microsoft has quietly become a complete, enterprise‑grade security platform for SMBs. He explores why additional third‑party tools are no longer a requirement for most customers, and how consolidating on the Microsoft stack can simplify delivery, improve cash flow, increase ROI for MSPs, and maximize the value customers get from licenses they’re already paying for.
Hey, good afternoon everybody. Uh, hope everyone's doing well. Um, can everyone give me a thumbs up in the chat if you're able to hear me? All right, maybe. Cool. I saw Reagan. Thank you. Uh, just going to give everybody one more minute to jump in here, then we'll go ahead and get started.
All right. Um, I appreciate everybody joining with me today. I'm going to go ahead and get started because I know we're at the 1:00 hour, or Eastern time depending on where you're at. So today, I appreciate everyone joining like I said, but we're going to be talking about why business premium should be a standard offering. Uh, I think it's a very interesting conversation now that Microsoft is transitioning to look towards SMBs more and more rather than the enterprise area. So, just going to deep dive into, you know, three different pillars when it comes to business premium, and that's going to be all around Intune, your email protection, your Defender, as well as Entra ID — how this can basically lay the ground, or the foundation, for building out a secure as well as a very well consolidated environment for you as well.
So, who am I? Uh, you guys might be wondering. Um, my name is Cole Capros. I'm one of our solutions architects here at inforcer. So I help with all the pre-sales, post-sales, implementation — uh, you name it — technical questions around inforcer. I come from a licensing background at Pax8, if anybody's familiar with using them as a distributor. So I was on our Microsoft team over there. I worked for the better part of six years with this licensing side, so I understand, you know, the nuances to the product. Uh, hopefully what I'm saying today kind of resonates a little bit with you guys and you understand how you can consolidate your stack into using just business premium as your token license there. So, uh, one thing I do want to point out is I do have the chat open. So if anybody does have questions as we're going along, feel free to fire them in there. I'll try to answer them as best as possible. Um, but yeah, just know I'll have that open if you guys want to ask anything else. By all means, we want to keep this a pretty conversational webinar right now, just so that way everybody can get questions in, we can talk about concepts, things like that as well. So, just know I have that open for you.
All right, so security is now top of mind for SMBs, and that's kind of the biggest thing I think that's super helpful for our industry — knowing that the mom-and-pop shops are now aware that their company can get breached. And you can see right there in the top left corner that 82% of ransomware attacks in the past year targeted small businesses, where it used to be that conversation and people would say, "Well, you know, I'm such a small shop, people aren't going to look at me for targeting us for a ransomware attack. What's the purpose of going after us?" That's making that security sell a lot harder. But now you can see that 82% of people are going after those because they know they don't have that security in place. You know, that's something — cyber attacks are on the rise, SMBs are increasingly infected. The research shows that one in three SMBs have been victims of cyber attacks such as ransomware, phishing, data breaches. Um, recognizing the critical importance of cyber security, now 94% of SMBs consider it central to their operations. This is making it a lot easier for you guys to have that sell, and you have statistics behind it that show this is why it's important that we need to move away from things like business standard, business basic — even though those are great solutions, we need to move into more of a security focus. That's the mindset. You know, if your data gets taken from you, um, that's kind of your whole company at this point. So it's something that you can help use these facts to basically implement into maybe your talk tracks, or when you're having those conversations with people, that hey, cyber security needs to be of the utmost importance. You've got to think about this stuff. You know, people are asking for like cyber insurance premiums at this point. This is just all helping you guys move towards a more secure environment by using something like business premium.
So this is premium as a whole. Um, it's very similar — I mean, not very similar; it has its similarities to business standard and business basic. You know it as a productivity suite, and I think that's kind of what the SMB version of Microsoft has always been known as — a productivity suite. You get your Word, you get your Excel, you get your PowerPoint, Outlook, Teams, you name it. But where it separates is the managed security aspect that you get on top of it. So this is where business premium kind of sets itself apart and becomes that hero SKU that Microsoft knows and loves to say it is. Um, you get your Intune, you get your Purview, you get Defender for — or you get Microsoft Defender for Business, which is even better than just Defender — and you get Entra ID. So the point that I'm pointing out for this is this is going to help you guys consolidate your stack. Um, I know, coming from the licensing standpoint, about five-ish years ago there was a huge push to have all these different products, and I think as we go through this today, the point you'll see that I'm talking about is consolidating that into, you know, one specific solution that can do everything for you. And now that we have the research behind it, Microsoft can back the fact that these products are going to be able to do exactly what everybody's looking for.
So the layered security improves your posture. So let's talk about the five different layers that are going to be kind of the way that you'd want to set up a Microsoft environment, and why it's important to use business premium for this specifically. So the first layer is going to be your Entra ID. That's going to be your multifactor authentication, your passwordless sign-ins, your self-service password reset, your conditional access, and your control to how data is going to be reached — meaning it's your user management page. This is going to be the initial layer that you need to set up. Um, again, all this is included with business premium. As we go through it, think about maybe if you have different products, how you could consolidate this into one. But Entra ID P1 needs to be where you kind of break the ground on creating security for your customers. Um, I always say this when we're talking with, you know, our partners here at inforcer — that the user management piece needs to be done correctly, and it needs to be done securely, in a way that if anybody were to push on — let's say, think of it as a door almost — you want these threat actors to push on that door, see that there's a lock on it, and continue to move on. That's going to be the goal here: to make sure they can't compromise those users, because if they get into their identity, that opens up the gateways to all the data within that tenant. So think about layering as such. But Entra ID, that's kind of something that we harp on a lot — getting that correct and setting that up right the first time can prevent basically 99% of the threat actors getting in. And then from there, you're going to move over to Intune. So keeping your devices patched, allowing some secure access from personal devices — so if it's a BYOD situation, you can securely add those into the environment and secure them in the right measures. So that way you're not pushing, you know, too much restriction onto them, because they are somebody's personal device, but you're allowing them to access some sort of data. So Intune is going to allow you to do that. Keep all your apps patched as well. Um, things like autopilot are going to make it easy out of the box, being able to roll out a laptop to somebody, ship it out there — you don't have that access when it comes to business standard. The third is going to be Defender for Business. So AI-powered detection response with automatic attack disruption, next-gen antivirus. Um, covers Windows, Mac, Linux, iOS, Android. This is going to be your new EDR, um, MDR, whatever Microsoft's acronyms they call it these days, where they change it every single day. Um, but you can see, you know, this is going to be your new security solution in the background that ties in directly to Defender, which is going to be that fourth pillar. And then last but not least is going to be Purview. I think Purview is kind of the new — it's a new avenue that we're kind of walking down together, because this is all tied towards data governance as well as data leakage. So this is going to be huge if you're trying to look towards AI, start rolling out Copilot. You need to make sure you have sensitivity labels set up. You need to make sure you have things on app protection where, you know, if somebody sends over safe attachments, safe links, you're able to quickly remediate that. Purview is able to make sure that nothing else is getting breached with the data loss, as well as creating specific rules around that, like PII or, um, you know, different compliance you might need to meet. So data security is going to be that last foundational piece, but it is super important, and there's ways, you know, we can help out with securing that environment specifically.
So one of the common things that we hear all the time is, "I don't want to put all my eggs in one basket." And that's a fair statement. I think that was kind of the emotion, the thought behind it a few years ago — that if you put everything invested into Microsoft, what happens if that goes down? I think the way that we look at it now is Microsoft is such a big company, and they have such — you know, they have everything behind them — that if this were to happen, you know, you are going to be protected by Microsoft. That's the real, realistic truth of it all. But one thing I do like to point out right here is not all baskets are built equal. That's just the reality of it. So, um, the way that we're going to look at this, obviously, is the basket phrase — I think it's easy, but it's a little corny, but it also makes sense — where, you know, you can have all these different solutions. You're like, "Oh, I can spread it all out." But if you don't actually build out that basket the right way, it's going to break. That's just the reality of it, and that's how it is with every solution. So the real risk isn't putting it into one basket and putting all your data, putting all your users in there. The risk comes if you don't configure it the right way. And time and time again, you see that happening when people put out these different solutions — they have nine different things in their stack and they think it's great and they can do all these different things with it. But at the end of the day, if you don't have it well configured, you know, you're kind of not off to a good start to begin with. So, something does go down, you hop in between four different platforms, try to figure this out — that's where it comes into looking at business premium as your one stack right there. You basically consolidate all those tools into one license. We get it right the first time, so that way you always have that fallback and say, "Okay, well, I know I just need to log into Microsoft, we can take a look at this, this is maybe where something had gone wrong." But end of the day, if you have to do that across five different platforms, that's going to take way longer than just going into one device or one platform there.
So this is also a really good example — I like to think of this, you know, and it kind of reiterates that point that I was just talking to. Where if you are looking at all your different products, think about it as a car. You know, you wouldn't want to build whatever said car — let's say we'll go with a Lamborghini — and you want to put in, um, you know, a Ferrari engine, you want to put in a Mercedes gear kit, things like that. That's just going to make it counterintuitive to how you're going to build out this model car. What you want to do is use the pieces that you can get. Um, why not take, you know, what's best to offer at one place, and then use the upgrades after the fact? I think that's the best way to look at it. Microsoft has invested $60-ish billion dollars into Defender as a security product. That's something that you can take head-on and say, "Well, you know, we can get this configured the right way the first time, and not have to worry about using all these different SOC providers or EDR providers." This allowed me to use that one pane of glass, that one platform, and build it out to become that perfect product that, you know, we can eventually get it to.
So, um, let's talk about some attacks. And you might be able to see, when it comes to not using business premium, where this might actually come up and why you can utilize this as a scenario for your customers. So this is a real-world scenario. Um, if anybody's familiar with what device code flow is, this is an example of how this happens. So what ends up happening is, if you don't have business premium in place and you're using something like business standard, and you don't have a way to prevent this with conditional access, somebody might send over a fake phishing page. It could look like an exact URL of Microsoft and say, "Please scan this for your token to be able to get into your account." In the case that you don't have a device code block in place, they're stealing that — that's a token, or token session theft, right there, and somebody's going to be able to breach that account. Now, when you're using something like business premium, what ends up happening is you can use Entra P1 to prevent this from actually going through. What would happen is it would scan it, take a look at it, and the code, or URL code, would then run against Microsoft and say, "Well, this isn't a known actual address." From there it spins, it spins, it spins, it gets reported as a threat, and then this way it actually prevents it from happening. So this is one of those things that, if you use a real-world example and say, "Look, this could happen to anybody just by not fully understanding what a URL page needs to look like, or if you're reading the www or the https, whatever." Um, but this is something that's very easily missed, and people will be able to get breached if they don't have the right things in place when it comes to business premium, or like Entra P1. So this example is pretty easy to, you know, one, replicate, but also to explain to end users and say, "Look, how often are you guys getting emails you just don't necessarily know if they're real or not? That could be token theft right there." If you might not know what that is, you can go on further and explain it, but then it allows you guys to have that conversation of upselling it to business premium.
So let's look at an attack timeline. I always like to bring this up when I'm having conversations, and the reason for this is where inforcer sits — which is "left of boom," and technically now a "right of boom" product as well, since we have our TDR out. But what we want to focus on is that left-of-boom side right here. So when it comes to building out an environment, as long as you get Entra ID and the Intune section part right, we can prevent 99% of the threat actors from getting in ahead of time. So that way, when you guys are looking at right of boom when it comes to threat detection and response, that 1% that gets through is allowing you to have a SOC or an EDR solution to pick up everything that maybe was missed between the Entra ID or the Intune section. So the whole point that I want to get at is: one, inforcer is going to help you standardize across the board on all these different areas, but we need to make sure we're getting the left of boom right ahead of time, so that way it opens up and frees your other tools to be able to do the detection and response factor too.
So let's talk about the first pillar. This is going to be leading endpoint protection and AV — this is going to be Defender for you. So, a bit of history, because I think it matters for the credibility of this conversation: Microsoft's antivirus used to be somewhat of a joke. I'll be the first to admit, trying to sell that back in the day was not easy. People didn't believe you that it can do what it's supposed to do. Um, and this timeline kind of proves that point. So, um, Windows Defender shipped with Windows 10 in 2015, and then they launched ATP in 2017, and Microsoft built out and renamed Defender for the P1 and P2 in 2020, and then they launched Defender for Business. And this was, you know, as an SMB market, this was crucial for us, because this is where you got Defender for Business. This is Microsoft saying, "We're taking our SMB customers seriously. We want to give you an enterprise-grade solution at an SMB cost." It's allowing you guys to deploy this. But at the same time, we still needed to understand, like, how was Defender going to work? You know, we needed some proof behind the pudding — that's the name of the game. It's like, "Hey, I can't use this product unless I fully trust it myself," right? So now what Microsoft has done is they're an industry leader in endpoint security. That's what I was saying earlier — they've invested roughly $60 billion into this product, and it's year-over-year growth, that they're trying to mitigate the risk for the SMBs but continue to grow this product so everybody can use it. I think the biggest one that you're looking at on the screen, what's highlighted there, is Gartner's named Microsoft the leaders six times consecutive, and you can see it on this map right here. They're right behind CrowdStrike. You know, SentinelOne, the Palo Altos, the Trend Micros, the Sophos — CrowdStrike is probably the biggest security name in the game right now. Microsoft's right behind them, they're toe-to-toe with them. Over the last six years, six times consecutive per Gartner, um, they are, you know, head-in-head with CrowdStrike. So if I can't get across the point to you that Defender is going to be a leading product in the industry within the next, I don't know, two, three years, I would say take Gartner for it as well. And this just shows you that, you know, with business premium and Defender for Business, you don't need to get something like E5. I'm not going to tell you not to use E5 — if you use it, there's tons of benefits that come with it. But what we're showing right here is even with Microsoft's threat detection, um, and intelligence they provide with business premium, it's going toe-to-toe with the best providers in the world.
So, with that being said, you know, Defender for Endpoint is a centralized security operations experience for Windows and non-Windows platforms. So what you can see is that they do support virtually every single platform that you might need it to. So I know that used to be a huge factor in the past — it's like, "I can't get Defender on this because it's not supported across these different networks." That's no longer the case. They've added it to, you know, all those different network devices. I think that was the biggest area that we were running into — with Cisco, the Palo Altos, the HPs, wasn't able to connect with it. Now that they've invested so much money into it, you're able to put it across all your popular operating systems right there.
So Intune is going to be pillar two right here. This is your device management solution. Uh, we always joke, but if you don't understand what's happening in this picture, you're lucky. Um, in the case that anybody does — feel for you. But if you don't — this is how you used to get customers prepared on their devices. So there's a golden image on that computer in the middle, and you're basically copying and pasting it over to different customers, or to the different laptops that anybody was setting up. This was a time-suck. Uh, I don't envy anybody having to do that, because that does not sound fun to have to do. But, um, it's always a funny picture to pull up on these kinds of conversations. And same thing goes along the board if you understand what this picture is doing. Again, if you don't understand what it's doing, consider yourself lucky. Um, this means you're probably not designing on-prem services — but if you do, again, feel for you. But we're in the modern age of technology where we can help you migrate to the cloud, so you don't have to worry about doing all this different stuff anymore.
That being said, now let's take a look at the afterthought of this. So this is how much cleaner I think a cloud-native picture looks. Users simply can log in, endpoints connect to the internet, pull down everything they need. Identity management comes from your Entra, security from Defender, data protection from your Purview, and device management from Intune — no on-prem servers to maintain anything. The same outcomes — honestly, probably better outcomes — you get it quicker, with a fraction of the complexity that you get with the other service.
So when it comes to setting up a device, instead of having to go on site, copy that golden image over to everybody, you know, what's the new way of doing this? That's going to be through autopilot — again, a service that's provided within Intune. So the device arrives from the factory ready for an employee to log in. And when they do, they get their apps, they get their policies, they get their profiles, they get everything they need to connect to their company resources. They can check their emails, they can be getting productive immediately right out of the box. So — and I always like to say this — if this was the only reason to go cloud-native, it would be worth it. I mean, I wouldn't want to drive on site to have to replicate all those golden images again. But, um, this is going to allow you guys to basically ship boxes over to people and say, "Hey, you're going to be good to go the moment you log into your computer."
So let's zoom out — why this matters. Right now, IT teams are wrestling with growing attack surfaces and a rising frequency of breaches, an increasingly complex mix of corporate devices, BYOD, shared devices. The future, powered by Intune, it looks different: best-in-class Windows update management through auto patch, risk-based conditional access policies being applied to end users, threat protection across every platform, integrated endpoint security, and compliance built around zero trust. And this — I mean, think about it — people are a little scared to move from a hybrid to a fully on-cloud, um, on-premise basically — they just don't want to do it. It's going to take a lot of work, it's something that just makes people nervous. I think that's just the nature of making a move like that. This is going to be how you'll be able to basically manage your hybrid environments and ease that control into moving into a fully cloud-based solution. So, um, just know that Intune is going to be kind of your gateway to be able to get everybody over there. You have that security, and it's allowing you to roll that out to every device that's in the system.
So the last pillar that we're going to talk about is your email protection — that is going to be your Defender for Office stack. So, Defender for Office, we're going to start, and then we're going to talk about the safe attachments, your safe links, and basically go into each one of those, understand why it's important to have this built into your system. So, um, the two headlines, like I said, we're going to talk about safe links and safe attachments. We'll look at them in turn. And if you're an inforcer partner, this is why the platform helps you harden and standardize this across all your customers, rather than configure them tenant by tenant. So, um, I always like to point that out — but that's kind of the point of inforcer. If you guys aren't familiar, you're joining this webinar, just kind of understanding who we are: we take your Microsoft stack and we're going to help you standardize across the board for all your customers, so that way there's no missing gaps between their security. Biggest and one of the hardest ones to get right is Defender, and that's something that we can help you specialize in getting — with everything done, with your safe attachments, your safe links, making sure Defender for Office is ready to go.
So we'll start with safe links. When you're looking at it, a malicious URL in an email or Teams message just opens — the user lands in it, they click on it, that's how malicious content is displayed. Somebody just got breached by just clicking a URL. So what happens with safe links is, when an email gets sent over and somebody clicks on the URL, at that moment the URL is checked against Microsoft's global threat intelligence. So if it's a bad or a known URL, it's automatically stopped and prevented from opening. But the thing that's important about this is it's, uh, at time of click. So by the time it's actually looking at that, the moment you click on that URL — so that way it's not actually preventing an additional threat where people can just breach the system from sending over malicious emails. But this is saying, you know, a lot of times people get these links sent to them, the links become weaponized the moment of the click — that's what I was trying to get at right there. And it's part of Defender for Office Plan 1, included with business premium, that you can prevent these URLs from having that threat breaching the tenant because somebody just clicked on something. And a lot of times, if you're not using anything in place, this is how breaching attacks happen — phishing attempts happen all the time. So business premium is going to be the one that's going to help you stop that with safe links.
And then moving over to safe attachments — it kind of works on the same principle, uh, but it's all around your file base. So without attachment scanning, a malicious file — say something disguised as an encrypt.exe, right — arrives in the inbox, and it's really down to the endpoint antivirus to catch when the user runs it. So if they open it at that point, we need to have something in place that can prevent this from happening. With safe attachments, what ends up happening is you see Microsoft will open this in a sandbox environment. You'll watch its behavior. If it's, you know, not an actual phishing attempt or something that's going to breach your system, it will arrive back in the inbox for somebody to be able to utilize that email, um, or that attachment, in such case. But if it is something that a threat actor is trying to put a phishing attempt into — that attachment, and breach the system — it quarantines it or rejects it, and it sends it back away. So, you know, a lot of different endpoints can do this as well, I'll be the first to say that, but why not use something that's included within that one license that you guys would be able to set this all up from the beginning with.
So consolidation is going to be the last piece of it. And when you're looking at this, it's going to be a little difficult, I would say, to have this conversation sometimes with end users. And the reason for that — a lot of people are kind of stingy when it comes to spending money on software. I think that's just the nature of it. I think anybody in this meeting knows, as an MSP, when you're trying to upsell stuff, it's, "Why do I need all these different things? You know, I just want to pay for the bare minimum, get on with the day." What you can show them is, one, everything that we just covered — I think those are all talking points. You can say, "Look, we need this, this, this, and this because of these reasons." Use the data that we backed it up with, Gartner; show that Microsoft's investing all this money into it; show them that 82% of SMBs were attacked in the last — or they were the most targeted customer base in the last three years. So the biggest thing they can say is show them the consolidation piece. So, meaning, we can consolidate your IT spend — honestly, probably make it cheaper at the end of the day by using something like business premium. Um, helping upsell that with your business basic, business standard customers. You know, when it comes to on-prem and Exchange Online customers, this is the way of the future — that's just the nature of it. Microsoft is moving to the cloud. Um, they're going to start retiring on-prem, you know, different like RDS servers, things like that. So it's something that you might have to have this conversation — it's not going to be fun, but they have to move away from it. And then finally, for people that are going to be renewing, I think it's just something you kind of reinforce — the fact of all these different features they're getting, for why they need to stay with business premium.
So if I were in your position and I was rolling out business premium to all the end users that I was working with, this is going to be the roadmap that I would recommend. So starting with Entra ID, moving through Intune, starting with Defender, SharePoint, OneDrive, and Teams. I always say, kind of put a caveat next to Teams — you probably need to set that up a little bit earlier. People are not going to be happy if they can't communicate with each other. But, uh, you get the idea. It's like, let's work from the top down. Start with Entra, build your base, move on to the devices, and then from there secure the devices as well as everything else. Roll out SharePoint and OneDrive so people have a way of storing data they can use in a centralized location. And then Teams, at the end of the day, is going to be the way that you can communicate with everybody. So, um, yeah, that's going to be the roadmap, the implementation path that I would recommend. Again, everybody works a little differently — I think this one lays out a really good foundation, that way you can get it right the first time and not have to try to go back and fix things from, like, step four to step two, you know, to make sure everything's working the way it needs to be. And then from there, you can start taking a look at whatever else is required — whether you want to add on some solutions, whether you want to move into Purview and start rolling out to, um, Copilot. You know, that's the name of the game, but at least you have your foundation built out, and you can use business premium to do that as such.
So, with that being said, um, if anybody wants to know a little bit more about inforcer as a whole, you can book a demo — that's what the QR code is for. Um, we've been told that we should be adding Defender and Purview onto the BP — that is true. Um, Andy, I would ask what specifically somebody's adding, uh, like, what they need Defender for. Because Defender for Business comes with Defender for Office Plan 1, as well as Defender for Endpoint Plan 1 and Plan 2. So that typically can conclude basically everything you would need for the Defender aspect. Then you do get Purview as well. Um, Entra ID P2, I would say, is mostly if you're doing risk-based conditional access policies — so that's basically, if it triggers a risky sign-in, you're automatically getting a threat there. But, um, sensitivity labels are included; it depends on what sensitivity labels you want. So if you're doing a manual sensitivity label, like they manually apply that, um, that's something that you could use Defender for Business with. Um, if you wanted automatic labeling, that's when you'd have to bump it up to P2, Defender for Endpoint P2. Uh, Paul, we'll send out the webinar after this so everybody has access to the screen share as well, or the slide deck.
Uh, Defender for Business does not include Defender for Endpoint Plan 2, right? So, Neil, it's kind of a two-folded answer. It technically does — it's just bits and pieces of both of them. I think you get the best of both worlds, um, when it comes to it. So, meaning, you get like Endpoint Plan 1 and Endpoint Plan 2 to have full coverage, but you don't get every single feature of P2 within Defender for Business. So that might be the one thing that you might be missing if you're looking at that specifically. Uh, yes, Carlos, I'll reach out to you — I can send you an article on how to configure that correctly as well. Uh, well, cool.
If there's any other additional questions, I will drop my email in the chat so everybody has it. Uh, happy to work with anybody that has any additional questions around inforcer specifically, or if it comes to — yeah, policy, I'll send that over to you as well. Um, and then if anybody has any additional questions around anything, feel free to reach over. Looks like you've got a few people to reach out to, I see that. Wes, uh, how does Defender for Cloud fit into all this? So, Defender for Cloud — with business premium, you get Defender for Cloud Apps discovery. Um, Defender for Cloud's tricky. That actually is an add-on to business premium, so that would be additional. I know that's more of an after-the-fact, I believe. Like, the way that I would look at it is, I'd want to get Defender for Endpoint and Office set up right first, because then Defender for Cloud allows you to do connectors, um — the way that I look at it, if you're building out like AI models, Defender for Cloud works great for that, for doing like shadow AI detection, um, and also it's tailored more towards like servers as well too. So if you have additional questions, I can reach out to you, Joseph, specifically around that, and just kind of let you know how it gets pieced in there together, because there's a few different areas that Defender for Cloud can work with. Uh, but it is technically, I believe, an add-on to business premium as well.
Okay, so what is suggested — Defender for Business? Uh, so, Tim, the answer is just business premium. Um, Defender for Business comes with business premium, so there's no need to purchase anything additional unless there's the use case for it. In that case, I would say reach out to your licensing provider — they probably can tell you what you would need based off the situation. But then again, here at inforcer, we have a whole team of architects, um, and we're able to help out with that, plan two — yeah, so if there's anything that's plan two. Um, if you need risk-based conditional access, um, this is a great one — M365maps.com. That is a great website that shows you all the different feature sets between business premium, the add-ons, E5, you name it. It's M365maps. It's kept up to date by a Microsoft employee, because I think they know how confusing some of their licensing guides can get. So that one really breaks it down. Oh, that's amazing. Well, thank you for creating it, if you guys did — that's been a lifesaver on my end.
Well, cool. Um, if there's any other questions, um, please shoot it my way — we're happy to help answer anything. Um, I appreciate everybody hanging out here for 50 minutes and letting me hold a TED talk session. Um, but if there's anything else, by all means, we can hang out for a little bit longer. But if all is good, then, um, appreciate you guys joining. That's all I got for you. All right.