Microsoft Defender for Business Perth — Perth IT Care
Your Microsoft 365 Business Premium licence includes endpoint protection that most Perth small businesses have never switched on. Not partially configured — completely inactive, while Windows shows a green tick and everyone assumes the job is done.
That gap is where ransomware finds its way in.
This post is part of our Microsoft 365 security overview for Perth businesses — if you want the full picture of what your licence actually covers, start there.
Two Things Called "Defender" — One Massive Difference
The confusion is understandable: Windows Defender and Microsoft Defender for Business share a name, ship on the same operating systems, and both show up as "active" in the Windows Security panel. They are not the same product.
Windows Defender is the built-in antivirus that comes free with every copy of Windows. It runs on a single device, scans for known malware, and reports to nobody. There's no central dashboard, no cross-device visibility, no behavioural rules, and no automated response. If it misses something, you won't know until the damage is visible.
Microsoft Defender for Business is the enterprise-grade endpoint protection platform included in Microsoft 365 Business Premium. It gives you a central portal where you can see every enrolled device, every active threat, every piece of unpatched software across your whole fleet — and set policies that apply uniformly to all of them.
Same name. Completely different capability. And if nobody has configured Defender for Business in your Microsoft 365 tenant, your devices are running Windows Defender only, regardless of what you're paying for.
What the Perth Bookkeeping Firm Found Out the Hard Way
A bookkeeping firm — eight PCs, Microsoft 365 Business Premium across all of them, client financial data going back years. Every machine showed Windows Security as active. The business owner had no reason to think anything was wrong.
A staff member received an Excel file attached to a convincing ATO-branded email. She opened it. The macro ran. Ransomware deployed across the network within minutes.
Windows Defender didn't catch it. Not because it failed exactly — macros executing legitimate-looking Office documents aren't something signature-based antivirus reliably intercepts. It's a behavioural problem, not a malware signature problem.
Defender for Business, properly configured, includes attack surface reduction rules that block untrusted macros from running by default. That rule alone would have stopped this specific attack. It was included in their licence. Nobody had ever turned it on.
The Notifiable Data Breaches scheme applies to businesses that hold client financial or personal data. A ransomware event involving eight years of client records isn't just an IT problem — it's a potential reporting obligation under the Privacy Act 1988. The cost of not configuring a tool you're already paying for turns out to be rather high.
What Microsoft Defender for Business Actually Gives You
When it's properly configured, the Defender for Business portal at security.microsoft.com shows you:
Central Device Inventory
Every onboarded device appears in a single dashboard. You can see what's running, what's been flagged, and what hasn't checked in recently. If a laptop goes missing or starts behaving strangely, you see it.
Threat and Vulnerability Management
The portal surfaces unpatched software across all your devices — not just Windows updates, but third-party applications too. This maps directly to the ACSC Essential Eight's patching requirements. You can see at a glance whether any device is running an outdated version of software with known vulnerabilities. If you're working toward Essential Eight compliance, our Essential Eight guide for Perth businesses explains how these controls fit together.
Attack Surface Reduction Rules
This is what the bookkeeping firm needed. ASR rules let you block specific high-risk behaviours — untrusted macros executing, Office applications spawning child processes, credential theft from LSASS, and others. These are configurable policies that apply across your entire fleet from a single location.
Automated Investigation and Response
When Defender for Business detects a threat, it doesn't just alert you — it begins an automated investigation, traces the attack chain, and can isolate the affected device from the network without waiting for a human to act. That containment speed matters enormously when something is actively spreading.
None of these capabilities exist in standalone Windows Defender.
The Unenrolled Device Problem
This is the part that catches businesses out even after they've started configuring Defender for Business: it only protects the devices that have been onboarded.
A licence doesn't automatically enrol devices. If you set up Defender for Business today, any laptop that was configured before onboarding ran — or that someone connected without going through your standard process — is flying blind. The portal won't show it. No policies will apply to it. And it'll still show Windows Security as active, because Windows Defender is still running on the device locally.
This is also why device management matters beyond just endpoint protection. Mobile device management is how you ensure every device that connects to your business — including personal phones and new additions to the fleet — actually gets enrolled and gets the right policies applied. Without it, onboarding is a manual, easy-to-miss process.
How to Check Whether It's Active in Your Tenant
You don't need us for this first check. You can do it yourself right now.
- Go to security.microsoft.com and log in with your Microsoft 365 admin account.
- Navigate to Assets > Devices.
- If the device list is empty or shows far fewer machines than you actually have, Defender for Business hasn't been onboarded — or hasn't been onboarded completely.
- Check Settings > Endpoints > Onboarding to see whether the onboarding process has been run for your devices.
If you see devices listed, check their status. "Active" means they're reporting in. "Inactive" means the device hasn't checked in for seven or more days — which could mean an unenrolled personal device, a laptop that's been off the network, or something that slipped through your onboarding process.
What you're looking for: every device your staff use for work should appear, show as active, and have policies assigned. If that's not what you're seeing, there's a gap.
What We Do When We Configure This for Perth Businesses
Getting Defender for Business from "technically present in the tenant" to "actually protecting your fleet" involves a few distinct steps that are easy to miss if you're doing it for the first time.
- Onboarding every device — via Intune, Group Policy, or local script depending on your environment. Each method has trade-offs and the right one depends on how your network is structured.
- Configuring baseline policies — Microsoft ships sensible defaults, but attack surface reduction rules are off by default because they can interfere with poorly written software. We audit what's running on your machines before enabling rules that could break something.
- Setting up email notifications — so that when Defender flags something, someone actually finds out about it. The portal is only useful if someone's checking it.
- Verifying the device count — cross-referencing what's enrolled against what we know exists in your environment. This is where the unenrolled stragglers get caught.
- Reviewing vulnerability findings — the first threat and vulnerability scan usually surfaces a handful of outdated applications or missing updates that need addressing.
None of this is especially complicated, but it does require someone to actually do it. It won't happen automatically when you assign a Business Premium licence.
The Short Version
If you're on Microsoft 365 Business Premium and nobody has explicitly configured Defender for Business, you're paying for enterprise endpoint protection and running free antivirus. Those are not the same thing.
The fix is already in your licence. It just needs to be turned on correctly.
If you want us to check your tenant and get it configured properly, get in touch. We're Perth-based, work the same business hours as you, and won't put your ticket in an overnight queue on the other side of the world.

