How to protect email on Business Basic or Standard
The July 2026 packaging change gave these plans link checking at time of click. It is useful, and it is not the same as Defender for Office 365.
Business Basic and Business Standard have always been the awkward plans to secure. You get Exchange Online Protection, which handles bulk spam and known malware competently, and beyond that you are on your own. The July 2026 changes moved that line slightly, and a fair amount of what has been written about them is wrong.
What actually changed in July 2026
Microsoft raised the price of Business Standard by USD3 per user per month and added capabilities to the Business plans. Basic and Standard gained an extra 50GB of mailbox storage, Copilot Chat improvements, and URL time-of-click protection — links are re-checked at the moment somebody clicks them rather than only when the message arrived.
A number of articles reported that Business Standard now includes Defender for Office 365 Plan 1. It does not. Microsoft described the addition as a subset of Safe Links functionality, not the full product. Defender for Office 365 P1 was added to E3, not to the Business plans. Business Premium already had it.
The distinction matters because time-of-click URL checking is one feature. Defender for Office 365 P1 also brings Safe Attachments detonation, anti-phishing policies with impersonation protection, Safe Links across Teams and Office apps, and the threat reporting that tells you what was blocked and who clicked.
What to do on Basic or Standard
Most of the meaningful work here costs nothing. In rough order of value:
- Enforce MFA on every account, without exception for executives. Security defaults will do it if you have nothing better; Conditional Access is better but needs Entra ID P1.
- Disable legacy authentication. Basic auth protocols bypass MFA entirely and are still the route used in most password spray attacks we see.
- Configure SPF, DKIM and DMARC properly, and move DMARC to a reject policy once you have watched the reports for a few weeks. Without this, anyone can send mail that appears to come from your domain, and your clients are the target.
- Block automatic external forwarding. This is the single control that most often turns a mailbox compromise into a contained incident rather than months of quiet interception.
- Turn on unified audit logging and make sure mailbox auditing is on. If you ever need to establish what an attacker touched, this is the difference between an answer and a guess.
- Restrict who can consent to third-party applications, so a staff member cannot grant a malicious app permanent access to their mailbox.
- Tighten the anti-spam and anti-malware policies in the Defender portal. The defaults are permissive.
Then decide about the gap
Once that is done you have closed most of the free ground, and what remains is attachment detonation, impersonation protection and visibility. Three options:
- Add Defender for Office 365 P1 as an add-on. Around USD2 per user per month. The cheapest way to close the specific gap.
- Move to Business Premium. Standard is now USD14 and Premium is unchanged at USD22, so the gap is USD8 — for which you also get Intune, Entra ID P1 with Conditional Access, Defender for Business as EDR, and Azure Information Protection. Bought separately those cost considerably more.
- A third-party mail security layer. Occasionally the right answer, usually not, because it adds a vendor and a console for a job Microsoft now does adequately.
What we would say
If your renewal is coming and you are on Standard, run the Premium comparison again with the new numbers. The narrowing gap is deliberate on Microsoft's part, and for most businesses the arithmetic now favors the upgrade. But do the free configuration work either way — an unconfigured Premium tenant is less secure than a well-configured Standard one.