Data Privacy Statement  | Terms of Use |  Imprint
© 2026 ALSO Cloud Marketplace

Services on Microsoft 365 Business Premium

Advanced courses*

Services on Microsoft 365 Business Premium

Empowers SMBs with enterprise-grade security, productivity apps, and device management

Our FY27 partner playbookRequest support

Discover how Microsoft 365 Business Premium empowers SMBs with enterprise-grade security, productivity apps, and device management – plus access partner resources, webinars, and ready-to-use campaigns to sell and grow your Microsoft practice

Services on Microsoft 365 Business Premium

A service catalogue

Build Security Services Around Business Premium

  • Business Premium is the security baseline for customers under 300 seats.

  • Microsoft FY27 rewards partners who upgrade, attach, and expand security solutions.

  • Combine Microsoft security licensing with value-added services to increase customer value and generate additional revenue.

Why now?

Prices changed on 1 July 2026 

Microsoft raised the USD list prices of Microsoft 365 Business Basic and Business Standard on 1 July 2026, while Business Premium remained at USD 22 per user per month. The smaller price gap gives partners a clearer route to Business Premium and to the security services built around it.

Prices changed on 1 July 2026

Microsoft raised the USD list prices of Microsoft 365 Business Basic and Business Standard on 1 July 2026, while Business Premium remained at USD 22 per user per month. The smaller price gap gives partners a clearer route to Business Premium and to the security services built around it.

Advanced security is now within reach for smaller customers 

The Defender Suite and the Purview Suite for Business Premium each cost USD 10 per user per month, or USD 15 when purchased together — up to 68 percent less than buying the components separately, and a practical base for higher-value security services.

Advanced security is now within reach for smaller customers

The Defender Suite and the Purview Suite for Business Premium each cost USD 10 per user per month, or USD 15 when purchased together — up to 68 percent less than buying the components separately, and a practical base for higher-value security services. 

AI use creates a new need for governance 

80% of SMB employees bring their own AI tools to work, often without company oversight or data protection. Partners can help customers identify the tools in use, agree which ones to allow, and apply controls to company data.

AI use creates a new need for governance 

80% of SMB employees bring their own AI tools to work, often without company oversight or data protection. Partners can help customers identify the tools in use, agree which ones to allow, and apply controls to company data. 

SMB security needs active management 

One in three SMBs experienced a cyberattack in the previous year, with an average total cost of USD 254,445. Many smaller businesses lack the staff and skills to manage security internally; partners can provide the assessment, deployment, monitoring, and response services they need. 

SMB security needs active management 

One in three SMBs experienced a cyberattack in the previous year, with an average total cost of USD 254,445. Many smaller businesses lack the staff and skills to manage security internally; partners can provide the assessment, deployment, monitoring, and response services they need.

The security and compliance add-ons 

The Defender Suite and Purview Suite 

Defender Suite for Business Premium

Threat Protection

$10 per user / month

Upgrades protection across sign-ins, devices, email and cloud apps.

  • Microsoft Entra ID P2 adds risk-based identity protection, Privileged Identity Management and access reviews.
  • Microsoft Defender for Endpoint Plan 2 adds advanced detection, investigation, threat hunting and response for devices.
  • Microsoft Defender for Office 365 Plan 2 adds attack simulation training, automated investigation and response, advanced hunting and Threat Explorer.
  • Microsoft Defender for Identity provides identity threat detection and response for threats linked to on-premises Active Directory.
  • Microsoft Defender for Cloud Apps makes shadow IT visible, including unapproved AI tools, and controls which cloud apps are used.
Product Documentation ↗

Purview Suite for Business Premium

Data protection

$10 per user / month

Finds, labels and protects company data, including AI tools.

  • Microsoft Purview Information Protection discovers, classifies and protects sensitive information through automatic labelling, advanced classifiers, encryption and access controls.
  • Microsoft Purview Data Loss Prevention monitors sensitive data and can audit or restrict how it is shared across Microsoft 365, managed devices, browsers and supported AI experiences.
  • Microsoft Purview Insider Risk Management identifies risky user activity, while Adaptive Protection can apply stronger controls when a user's risk level changes.
  • Microsoft Purview eDiscovery and Audit (Premium) add custodian management, legal hold notifications, review sets and analytics on top of the standard cases and holds in Business Premium, plus enhanced audit events and longer audit retention.
  • Microsoft Purview Data Lifecycle Management applies retention and deletion policies at label and rule level, while records management supports more formal control of business records.
  • Microsoft Purview Communication Compliance detects potentially risky or non-compliant communications for review.
Product Documentation ↗

Defender + Purview Suites

Threat and data protection

$15 per user / month

The combined offer extends Business Premium across threat protection, identity security, cloud app control, data protection and compliance. It includes the capabilities of both suites under one subscription and costs up to 68 percent less than buying the eligible components separately.

Product Documentation ↗

Customer Scenarios

The moment Business Premium alone With the suites
An employee clicks a phishing mail
  • Defender for Office 365 Plan 1 checks links at click time and blocks known threats.
  • When a new lure gets through, finding who else received it is manual work, mailbox by mailbox.
Plan 2 investigates automatically, removes the mail from every inbox and records the full incident.
An attacker signs in with a stolen password MFA and Conditional Access stop most of this, once the policies are properly configured, but spotting suspicious sign-ins means reading logs.
  • Entra ID P2 scores every sign-in and can block or force a password reset on risk, automatically.
  • The incident ties the account to what was touched.
Ransomware encrypts a laptop
  • Defender for Business detects it and can isolate the device.
  • Working out what happened before the alarm, and what else it spread, still takes investigation skill and time.
Defender for Endpoint Plan 2 adds threat hunting, live response and six months of extended retention — so you can see the attack's full evidence.
An employee pastes customer data into a free AI tool Labels and DLP cover mail and files, but the browser and the AI tool sit outside, i.e. nobody sees the paste. Purview DLP extends to managed devices, browsers and supported AI experiences: the action is logged, warned or blocked, and shadow AI appears in discovery.
A resigning employee exports the customer database The audit log records it, if someone thinks to look, after the fact. Insider Risk Management flags the pattern as it happens, and Adaptive Protection can tighten the user's DLP controls automatically.
An insurer or auditor asks how data is protected Manual labels, core DLP, standard audit and eDiscovery, but the evidence must be assembled by hand, every time. Automatic classification, premium Audit with longer retention and richer reporting produce the evidence on demand.
Someone has to run security every day The tools live in several portals, joiners and leavers, and score drift become your unpaid follow-up — or nobody's. Defender XDR and Purview put the signals in one queue with guided actions.
Scenario Business Premium alone With the suites
An employee clicks a phishing mail
  • Defender for Office 365 Plan 1 checks links at click time and blocks known threats.
  • When a new lure gets through, finding who else received it is manual work, mailbox by mailbox.
Plan 2 investigates automatically, removes the mail from every inbox and shows the full path as one incident.
An attacker signs in with a stolen password MFA and Conditional Access stop most of this, once the policies are properly configured, but spotting suspicious sign-ins means reading logs.
  • Entra ID P2 scores every sign-in and can block or force a password reset on risk, automatically.
  • The incident ties the account to what was touched.
Ransomware encrypts a laptop
  • Defender for Business detects it and can isolate the device.
  • Working out what happened before the alarm, and whether it spread, still takes investigation skill and time.
Defender for Endpoint Plan 2 adds threat hunting, live response and six months of data retention on the device, so the full path is answered with evidence.
An employee pastes customer data into a free AI tool Labels and DLP cover mail and files, but the browser and the AI tool sit outside, i.e. nobody sees the paste. Purview DLP extends to managed devices, browsers and supported AI experiences: the action is logged, warned or blocked, and shadow AI appears in discovery.
A resigning employee exports the customer database The audit log records it, if someone thinks to look, after the fact. Insider Risk Management flags the pattern as it happens, and Adaptive Protection can tighten the user's DLP controls automatically.
An insurer or auditor asks how data is protected Manual labels, core DLP, standard audit and eDiscovery, but the evidence must be assembled by hand, every time. Automatic classification, premium Audit with longer retention and richer reporting produce the evidence on demand.
Someone has to run security every day. The tools live in several portals. Alerts, joiners and leavers, and score drift become your unpaid follow-up, or nobody's. Defender XDR and Purview put the signals in one queue with guided actions.
The moment Business Premium alone With the suites
An employee clicks a phishing mail
  • Defender for Office 365 Plan 1 checks links at click time and blocks known threats.
  • When a new lure gets through, finding who else received it is manual work, mailbox by mailbox.
Plan 2 investigates automatically, removes the mail from every inbox and records the full incident.
An attacker signs in with a stolen password MFA and Conditional Access stop most of this, once the policies are properly configured, but spotting suspicious sign-ins means reading logs.
  • Entra ID P2 scores every sign-in and can block or force a password reset on risk, automatically.
  • The incident ties the account to what was touched.
Ransomware encrypts a laptop
  • Defender for Business detects it and can isolate the device.
  • Working out what happened before the alarm, and what else it spread, still takes investigation skill and time.
Defender for Endpoint Plan 2 adds threat hunting, live response and six months of extended retention — so you can see the attack's full evidence.
An employee pastes customer data into a free AI tool Labels and DLP cover mail and files, but the browser and the AI tool sit outside, i.e. nobody sees the paste. Purview DLP extends to managed devices, browsers and supported AI experiences: the action is logged, warned or blocked, and shadow AI appears in discovery.
A resigning employee exports the customer database The audit log records it, if someone thinks to look, after the fact. Insider Risk Management flags the pattern as it happens, and Adaptive Protection can tighten the user's DLP controls automatically.
An insurer or auditor asks how data is protected Manual labels, core DLP, standard audit and eDiscovery, but the evidence must be assembled by hand, every time. Automatic classification, premium Audit with longer retention and richer reporting produce the evidence on demand.
Someone has to run security every day The tools live in several portals, joiners and leavers, and score drift become your unpaid follow-up — or nobody's. Defender XDR and Purview put the signals in one queue with guided actions.

Level 3 

Advanced services on the Defender Suite 

The Defender Suite brings Defender for Endpoint Plan 2, Defender for Office 365 Plan 2, Defender for Identity, Defender for Cloud Apps and Entra ID P2. 

The Problem

Admin rights that never expire, former employees still in groups and forgotten guest accounts are among the first findings of any audit.

Privileged Identity Management grants admin rights on request instead of permanently, access reviews create recorded sign-off, and Identity Protection responds to risky sign-ins.

Service you could deliver

  • Privileged Identity Management for the customer's admin roles.
  • Quarterly access reviews.
  • Automatic response policies for risky sign-ins.

License

Entra ID P2, part of the Defender Suite for Business Premium.

Documentation

What is Microsoft Entra Privileged Identity Management? ↗

Access reviews overview ↗

Microsoft Entra ID Protection ↗

Suggested Next Steps

  • Move privileged roles to PIM eligible assignments, Global Administrators first.
  • Start one access review on guest accounts and record the sign-off.
  • Run the risk policies in report-only mode, then enforce for high risk.

The Problem

Built-in protection stops common malware, but an attacker who moves quietly through the environment requires investigation capability.

Defender for Endpoint Plan 2 adds threat hunting, live response and six months of device history, so incidents can be reconstructed with evidence.

Service you could deliver

  • Configure attack surface reduction rules.
  • Enable automated investigation and add vulnerability findings to a monthly report.

License

Defender for Endpoint Plan 2, in the Defender Suite.

Attack surface reduction can already be configured on Defender for Business, included in Business Premium.

Documentation

Microsoft Defender for Endpoint overview ↗

Attack surface reduction capabilities ↗

Configure Microsoft Defender for Endpoint capabilities ↗

Overview of automated investigations ↗

Prepare to deploy Microsoft Defender for Endpoint ↗

Suggested Next Steps

  • Onboard a pilot group of devices to Plan 2 and verify the telemetry.
  • Run attack surface reduction rules in audit mode and review the detections.
  • Move the rules to block mode and set automated investigation to full remediation.

The Problem

Invoice fraud can arrive as a reply within a genuine supplier thread, with new bank details and no malware for a filter to detect. At the same time, employees can connect unknown apps and AI tools to company data.

Defender for Office 365 Plan 2 adds automated investigation and attack simulation training, and Defender for Cloud Apps makes unknown app usage visible.

Service you could deliver

  • Strict preset security policies, with priority account protection for finance and leadership mailboxes.
  • Phishing simulations, reports and training.
  • App discovery to surface shadow IT and unapproved AI, followed by a sanction-or-block decision taken together with the customer.

License

Defender for Office 365 Plan 1 is included in Business Premium, Plan 2 and Defender for Cloud Apps come with the Defender Suite.

Documentation

Preset security policies in cloud organizations ↗

Get started with Microsoft Defender for Office 365 ↗

Microsoft Defender for Cloud Apps overview ↗

Get started with Microsoft Defender for Cloud Apps ↗

Suggested Next Steps

  • Apply the Strict preset to a pilot group and tag the priority accounts.
  • Run the first attack simulation and share the results in aggregate only.
  • Extend the preset to all users and start the app discovery.

The Problem

Attacks do not follow office hours, and signals from devices, identities, email and apps only become meaningful when someone connects them. Defender XDR provides the single incident queue, and the response capability is what you can offer on top.

Service you could deliver

  • A scoped service within defined business hours, on Defender XDR, with written out-of-hours playbooks.
  • A white-label or in-house 24/7 service.

License

The Defender Suite for Business Premium. All four Defender products plus Entra ID P2 feed their signals into one incident queue.

Documentation

What is Microsoft Defender XDR? ↗

Incidents and alerts in the Microsoft Defender portal ↗

Suggested Next Steps

  • Define the severities, response times and the out-of-hours playbook.
  • Run a paid pilot with one customer for one quarter.
  • Review the pilot results and set the standing service tiers.

Skilling

Certification Path

  • Start with SC-900, the security fundamentals exam.

  • Deeper tracks follow by area: SC-300 for identity, SC-200 for security operations and SC-401 for data security. 

Preparation Courses

Begin with a Security Health Check

Reach out to your Business Standard, Business Basic and Business Premium customers, and run a security assessment (ALSO's Security Health Check, Microsoft Solution Assessment, or your own Secure Score review). 

Present the findings, and agree on the priority fixes.

Deliver fixes and add monthly recurring revenue through managed services.

Book recurring security posture reviews and draft a security roadmap for your customers. 

Learn more about Security Health Checks

The FY27 partner playbook 

Run your business securely

Twelve pages on the "Run your business securely" motion: the FY27 moves, six numbers that open doors, the economics of one customer, partner proof, the objections answered, the program map, and a 30-day checklist. Read it, then hand it to your sales team.

The ALSO partner playbook · FY27 · August 2026

New to ALSO? 

Whether you're looking to expand into AI, cloud, cybersecurity or other growth areas, success depends on more than access to technology. It requires the right ecosystem, expertise, services and platforms to turn opportunities into profitable business.


As Europe's technology provider, ALSO helps partners identify opportunities, adopt new technologies and build scalable business models through a unique combination of Supply, Solutions and Services. We help you navigate change, reduce complexity and create sustainable growth. 

Become a resellerLearn more

Request a call-back

What You'll Find on This Page

  • Security assessments and initial setup services

  • Ongoing security management

  • Data protection and compliance services

  • Managed detection and response offerings

Every Module Includes

  • What to fix

  • What to deliver

  • Required licensing

  • Recommended next steps

Service Opportunities 

Level 1

Services on Business Premium

If a customer is on Business Basic or Standard, these modules can be your case for the upgrade. 

Business Premium includes Entra ID P1, Intune Plan 1, Defender for Business and Defender for Office 365 Plan 1. These services run on those licenses. 

The Problem

Neither you nor the customer can improve what has not been measured. An assessment establishes which controls are active, which gaps exist and what to fix first, and gives the customer a document they can act on.

Service you could deliver

  • The ALSO Security Health Check offers the Basic QuickScan, which is designed for SMBs with up to 500 employees and connects with Active Directory, Microsoft 365 and Azure services.
  • Microsoft Solutions Assessment provides a fast, data-based report of the customer's vulnerabilities and priorities.
  • Your own Secure Score review can be delivered as a short report in plain language with a quote for the fixes.

License

Secure Score ships with every Microsoft 365 business subscription. The Health Check is offered by ALSO and includes an onboarding and training run.

Documentation

ALSO's Security Health Check ↗ Assess your security posture with Microsoft Secure Score ↗ Zero Trust guidance for small businesses ↗ Microsoft Solution Assessments ↗

Suggested Next Steps

  1. Agree the scope and read-only access with the customer.
  2. Run the assessment and review the findings against Secure Score.
  3. Present the prioritized fixes with a quote and book the next scan.

The Problem

Many customers pay separately for antivirus, VPN, mail filtering and backup, although several of these functions are already included in Business Premium. Overlapping tools raise cost and create additional consoles in which alerts can be missed.

Service you could deliver

  • An inventory of the customer's current tools and licenses, with a factual overlap table against Business Premium.
  • A migration plan and a before-and-after cost summary.

Documentation

Suggested Next Steps

  1. Collect the customer's current tool contracts and license lists.
  2. Map each tool against Business Premium in an overlap table.
  3. Present the savings, the migration order and your service fee on one page.

The Problem

A stolen password can give an attacker access to email, files and other company resources. Multi-factor authentication adds another check at sign-in, while blocking legacy authentication removes older sign-in methods that do not support modern security controls.

For customers without Microsoft Entra ID P1, security defaults provide a Microsoft-managed baseline.

Service you could deliver

  • Multifactor authentication for every user with Microsoft Authenticator
  • Block legacy sign-in methods and separate admin accounts from daily accounts
  • Handover documentation to the customer

License

Every Microsoft 365 Business plan, enforcement policies need Entra ID P1 (included in Business Premium).

Documentation

Suggested Next Steps

  1. Review the current authentication methods and sign-in logs.
  2. Register users in waves with Microsoft Authenticator, admins first.
  3. Enforce on the agreed date, with documented exceptions and a support path.

The Problem

Multi-factor authentication confirms more than one factor at sign-in, but customers may also need to consider the user, application, device and location before granting access. Conditional Access applies those requirements through defined policies instead of treating every sign-in the same way.

Service you could deliver

  • Design and deliver a small set of policies that match the customer's needs.
  • Configure and document emergency access accounts, test the policies in report-only mode, review the results with the customer and move approved policies into enforcement.

License

Entra ID P1 is included in Business Premium.

Documentation

Plan a Conditional Access deployment ↗ Microsoft Entra Conditional Access documentation ↗ Microsoft Entra ID setup guide ↗

Suggested Next Steps

  1. Create and test two emergency access accounts.
  2. Run the policies in report-only mode and review the sign-in impact.
  3. Enforce policy by policy, recording the exclusions.

The Problem

Organizations need visibility and control over devices accessing company resources.

Service you could deliver

Configure Microsoft Intune policies to manage devices, applications and security settings.

Level 2 

Data services on the Purview Suite 

Standard eDiscovery and Audit are included in Business Premium, the Purview Suite adds Premium eDiscovery and Audit, records management and Communication Compliance.

The Problem

Employees move sensitive data outside the company without intending harm: a client list mailed to a private address, or customer data pasted into a free AI tool. DLP policies detect sensitive information and can warn, log or block the action.

Service you could deliver

  • Policies that first observe and then restrict sensitive data leaving by mail, Teams, managed devices, browsers and supported AI experiences.
  • Start in audit simulation mode, review the findings with the customer, then enforce step by step with policy tips, so legitimate business mail is not blocked while policies are tuned.

License

Mail and file DLP is included in Business Premium, Purview Suite adds device, browser and AI coverage.

Documentation

Learn about data loss prevention ↗

Suggested Next Steps

  • Enable the default detections in simulation mode.
  • Review a few weeks of matches with the customer and tune the false positives.
  • Enforce the most important policies with policy tips; keep the rest in simulation.

The Problem

When no one can say which documents are confidential, everything is shared in the same way. Sensitivity labels classify documents and mail, and can apply encryption and access controls; with the Purview Suite, labelling can happen automatically through advanced classifiers.

Service you could deliver

  • A set of labels agreed with the customer.
  • Manual labels on Business Premium, automatic labelling with the Purview Suite, and encryption on the most sensitive label.
  • Employee enablement and change management, since labelling is a working habit supported by software.

License

Manual labels are included in Business Premium, the Purview Suite adds automatic labelling.

Documentation

Get started with sensitivity labels ↗

Learn about sensitivity labels ↗

Create and configure sensitivity labels and their policies ↗

Suggested Next Steps

  • Agree the set of labels to implement.
  • Publish the labels to a pilot group and collect feedback.
  • Run one auto-label rule in simulation, then enforce it.

The Problem

Data can leave through people who are entitled to access it, for example an employee who exports the customer database during a notice period. Insider Risk Management detects such patterns, and Adaptive Protection can tighten Data Loss Prevention controls for users whose risk level rises.

Service you could deliver

  • Tune policies to employee departures and unusual data movement, with pseudonymized alerts enabled by default.

License

Purview Suite for Business Premium.

Documentation

Learn about insider risk management ↗

Configure Insider Risk Management ↗

Plan for Insider Risk Management ↗

Suggested Next Steps

  • Confirm the privacy settings and who reviews the alerts.
  • Enable the departing-employee template with pseudonymization.
  • Review the alerts weekly at first, then agree the standing cadence.

Standard included in Business Premium. Purview Suite upgrades it to Premium

The Problem

When a legal request or an audit arrives, searching mailboxes by hand is slow and difficult to defend. Retention policies keep data for defined periods, and eDiscovery supports structured searches and holds. Purview adds custodian management, legal hold notifications, review sets and analytics, plus enhanced audit events and longer audit retention.

Service you could deliver

  • Implement data retention policies for the periods the customer specifies.
  • A demonstration of legal hold and a written runbook for the first real request.

License

Standard eDiscovery and Audit are included in Business Premium, the Purview Suite adds Premium eDiscovery and Audit, records management, Communication Compliance and Compliance Manager.

Documentation

Learn about eDiscovery ↗

Create and configure retention policies ↗

Learn about auditing solutions in Microsoft Purview ↗

Suggested Next Steps

  • Record the retention periods the customer specifies.
  • Apply a small set of broad policies before any exceptions.
  • Walk through one simulated request end to end and file the runbook.

Service built on the Purview Suite

The Problem

Customers want Copilot, or their staff already use free AI tools. Copilot surfaces whatever a user is permitted to open, including folders that were overshared years ago. Before AI is deployed, permissions and data protection need a review.

Service you could deliver

  • An oversharing review of SharePoint and OneDrive with a permission clean-up plan.
  • Labels and Data Loss Prevention policies extended to AI prompts and browsers.
  • Audit and reporting of Copilot interactions, so the customer can see how AI touches company data.

License

Data loss prevention for AI, premium audit of Copilot interactions, the risky-AI-use detection in Insider Risk Management and Communication Compliance for AI interactions come with the Purview Suite. The free Microsoft Security for AI Assessment structures the preparation.

Documentation

Microsoft Purview data security and compliance protections for generative AI apps ↗

Security for AI Assessment ↗

Suggested Next Steps

  • Run the free Security for AI Assessment and review permissions on the priority SharePoint sites.
  • Fix the most critical permission gaps with the data owners.
  • Re-run the assessment and attach the result to a Microsoft 365 Copilot proposal.

ALSO's Security Trainings

Find live and on-demand sales, technical, and business training to grow your expertise.

Sign up

ALSO's Modern Work & Copilot Trainings

Find live, on-demand, and in-person training for your team and customers to grow expertise and drive adoption.

Sign up

Microsoft 365 Business Premium Bootcamp

We run German and English bootcamps twice a year. Check upcoming dates or watch the latest sessions on demand.

Sign up

Level 4 

Beyond M365 - Managed SOC Services

Your customers already have Business Premium and Microsoft Defender? Take the next step with a SOC offering for continuous monitoring, threat detection, and response.

Learn more and find SOC provider

Available Promotions at ALSO

The New-to-Cloud Business Basic and Business Premium promotions was designed specifically for the accounts you've been trying to move for years.

Valid until 31.12.2026

Learn more

30 % Off M365 Business Basic with ALSO

50 % Off Purview with ALSO

This is the largest Purview discount ever offered to SMBs: 50% off Microsoft list price when bundled with Microsoft 365 Copilot.

Valid until 31.12.2026

Learn more

Combine AI, productivity, and security in a single solution while creating opportunities for deeper security adoption and services.

Valid until 31.12.2026

Learn more

5% Off M365 Business Premium with Copilot Promo

Your Customer does NOT have Microsoft 365 Business Premium yet?

A customer on Microsoft 365 Business Basic or Business Standard already has three things:

  • Mailboxes are filtered for malware, spam and spoofing by default.
  • Security defaults switch multifactor authentication on for every user.
  • Basic Mobility and Security can wipe work data from a lost phone.

That is the whole list. There is

  • No Microsoft Entra ID P1, so no Conditional Access.
  • No Microsoft Intune Plan 1, so no application protection policies and no macOS management. 
  • No Microsoft Defender for Business, so no endpoint detection and response
  • No Microsoft Defender for Office 365 Plan 1, so no Safe Links, no Safe Attachments and no impersonation protection. No sensitivity labels and no data loss prevention for mail and files.

The suites are out of each from here as well. 

Microsoft Defender Suite for Business Premium and Microsoft Purview Suite for Business Premium both require a Microsoft 365 Business Premium licence underneath, up to 300 seats.