Skip to main content
Valto — Keep ahead of tomorrow

Security

Microsoft Defender

Most organisations have more Defender than they have configured, and fewer people watching it than they think. Valto deploys, tunes and helps you run Microsoft Defender for Office 365, Endpoint, Identity and Cloud Apps. We start by establishing which parts your licences already include, configure them properly rather than at default, tune out the noise that stops alerts being read, and agree who acts on what. Where your licensing genuinely does not cover what you need, we will tell you and show you the options.

Microsoft Solutions Partner

Trusted by organisations like yours

Mind
Greene King
Grosvenor
City of London logo
Chester Zoo
ABM
Human Appeal
John Deere
UKTV
Astrazenica
Money Supermarket
Princes
Sony
Shell
BBC
OVERVIEW

Threat protection that somebody is actually acting on

Microsoft Defender is a family of products rather than a single one, and most organisations own an inconsistent slice of it. Some of it arrives with Business Premium. Very little of it arrives with E3. Nearly all of it arrives with E5. Almost nobody can say from memory which parts they have. What follows is predictable. The products that are licensed get switched on at default settings, policies cover part of the estate, alerts go to a shared mailbox, and after a fortnight of false positives people stop opening them. The tooling is present and the protection is theoretical. Valto starts with coverage: which Defender products your licences include, what they are protecting today, and where the gaps are. We then configure and tune them properly, reduce the noise until the alerts that remain are worth reading, and agree explicitly who acts on what and within what hours. Where your licensing genuinely does not cover what you need, we will say so and set out the options, including the honest comparison between add-ons, moving to E5, and a third-party product. We do not resell security software, so we have no reason to prefer one answer.

What Defender do you already have?

Defender is licensed in pieces, and the pieces are not obvious. This is roughly where most organisations stand, and confirming your actual position is the first thing we do.

Microsoft Defender for Office 365

Protects email and collaboration: anti-phishing, impersonation protection, safe links, safe attachments and automated investigation. Plan 1 is included with Business Premium. Plan 2, which adds threat hunting, attack simulation and automated response, comes with E5 or as an add-on.

Microsoft Defender for Endpoint

Protects devices: detection and response, attack surface reduction, and vulnerability management. Defender for Business is included with Business Premium. Plan 1 and Plan 2 differ substantially in detection and investigation capability, and Plan 2 is the one most people assume they have.

Microsoft Defender for Identity

Watches your identity infrastructure for the attack patterns that precede a breach: reconnaissance, credential theft, lateral movement. Requires E5 or a standalone licence, and is the product organisations most often do not realise they are missing.

Microsoft Defender for Cloud Apps

Sees and controls what cloud applications your people are actually using, including the ones nobody approved, and applies policy to the data moving through them. E5 or standalone.

Microsoft Defender XDR

The layer that correlates signals across Office 365, endpoints, identity and cloud apps into single incidents rather than four separate alert queues. This is where the value of holding several Defender products compounds, and it is the argument for consolidating onto Defender rather than running one product from each vendor.

Microsoft Defender Vulnerability Management

Identifies and prioritises unpatched software and misconfiguration across your devices. Partly included with Defender for Endpoint P2, with an add-on for the full capability.

Microsoft Defender for Cloud

Protects Azure and hybrid infrastructure workloads rather than Microsoft 365. Priced by resource.

Our Microsoft Defender services

Establish what you have before buying anything

We confirm which Defender products your licences include, what they are currently protecting, which parts of the estate they do not reach, and where the real gaps are. Where additional licensing is genuinely needed, you get the options costed. Most reviews find a mixture: capability paid for and not switched on, and one or two genuine gaps worth closing.

Three men around a table

Hear from our experts

Watch: From reactive to proactive: Securing Microsoft 365 for AI

In this episode, Rob Thomas (Head of Modern Work), Will Jones (Senior Consultant) and James Belsey (Project Manager) discuss why a proactive security strategy is becoming essential, how Microsoft 365 security has evolved, and what organisations should consider before rolling out AI tools like Microsoft Copilot.

Expertise
Microsoft security and identity specialists
Clarity
Defined coverage, defined ownership
Value
Configured before purchased

Turn Defender into actual protection

Owning Defender and being protected by it are different things. These are the outcomes the work is for.

Organisations running third-party email filtering or endpoint protection alongside a Defender licence they already hold are frequently paying for the same capability twice. Consolidating removes a contract, a console and a supplier.
Impersonation and business email compromise do not usually rely on malicious attachments. Tuned anti-phishing and impersonation protection are what address them, and they are almost never configured properly at default.
Reducing false positives until the remaining alerts are worth acting on is the difference between a monitored environment and a dashboard. It is unglamorous and it matters more than anything else on this list.
Defender XDR correlates signals across email, endpoints, identity and cloud apps, so a single attack appears as one incident with a timeline rather than as separate alerts in separate consoles.
Attack surface reduction, device compliance and conditional access working together mean a stolen credential does not automatically become an incident.
Insurers, customers and auditors ask specifically about endpoint protection, email security and monitoring arrangements. A configured, documented Defender estate is the answer.

How we deliver Defender projects

From establishing what your licences already cover, through to a configured, tuned estate with agreed ownership of what it produces.

  1. Security assessments
    1

    Coverage review

    Establish what you have and what it reaches

    We confirm which Defender products your licences include, how they are currently configured, and which parts of the estate they do not cover. Where additional licensing is genuinely needed, you get the options costed rather than assumed.

  2. Power Apps Envisioning Workshop
    2

    Design

    Agree the policy set and the ownership model

    We define the policies, baselines and automated response actions appropriate to your organisation, and agree at this stage who acts on what, within what hours, and what gets escalated.

  3. People working on computers
    3

    Deployment

    Configure and roll out in phases

    We configure the products and apply policies in controlled waves, piloting anything that could affect mail flow or device behaviour before it reaches everybody.

  4. Woman working at a computer
    4

    Tuning

    Reduce the noise until the alerts are worth reading

    We work through false positives, adjust policy against real activity, and consolidate signals through Defender XDR. This continues for a period after go-live, because tuning cannot be completed in advance.

  5. 5

    Operation

    Review coverage, policy and Microsoft's changes

    Ongoing monitoring where that is part of your service, and periodic review of coverage, policy and new Defender capability, which Microsoft adds frequently.

We're one of the UK's few Microsoft partners to hold all Microsoft Solution Partner designation badges, across all Solution Partner designation pathways. For our clients, that means working with specialists who understand how identity, devices, email and data fit together rather than treating threat protection as a product to install. Whether you're enabling Defender for the first time, tuning an estate that generates more noise than it should, or working out what your licences already cover, we help organisations get real protection from tools they largely already own.

WHY ORGANISATIONS CHOOSE VALTO

Microsoft Solutions Partner
Apps on a phone

Connected, across Microsoft

Defender is only as good as the identity model underneath it

Defender detects and responds. What it can prevent depends on conditional access, device compliance, privileged access and how content is shared, none of which are Defender. An organisation with well-tuned detection and standing global administrator accounts has bought a better view of an avoidable problem. Valto brings together expertise across Microsoft 365, Azure, Entra ID, Intune, Purview and Microsoft 365 Copilot. That lets our consultants configure Defender in the context of the identity and access model it is protecting, and recognise when the right answer is a configuration change elsewhere rather than another detection rule. The result is threat protection that sits on top of an estate designed to give it less to detect.

The team driving your forward

Rob Thomas
Rob ThomasMS365 & Azure Business Unit Lead
SharePoint Consultant hosting a requirements workshop
Harry BarnettPre-Sales Consultant
Girl with trophy
Will JonesSenior Cloud Consultant
James BelseySenior Project Manager

Questions, answered plainly

Practical answers on which Defender products your licences include, what happens to alerts, whether Defender replaces your existing security tools, and who acts on what.

It depends on your licensing and it is genuinely hard to work out, which is why we offer a coverage review. Broadly: Business Premium includes Defender for Office 365 Plan 1 and Defender for Business, Microsoft 365 E3 includes very little of the Defender stack, and E5 includes almost all of it. Defender for Identity and Defender for Cloud Apps are the two people most often assume they have and do not. We confirm your actual position rather than working from the plan name.
Possibly, and it is worth costing properly rather than assuming either way. E5 bundles the Defender stack with Entra ID P2 and Purview, which often makes it better value than buying three add-ons separately, but not always, and it depends on user count and what you would actually use. We set out both options costed. We do not resell security software, so we have no preference.
For most organisations, yes, and this is where the cost case usually sits. Plenty of organisations pay separately for email filtering or endpoint protection while already holding a Defender licence that covers the same ground. We will be honest about the exceptions: if a specific requirement is genuinely better served by your current product, we would rather say so than force a consolidation.
It was renamed. Office 365 ATP became Microsoft Defender for Office 365 and Microsoft Defender ATP became Microsoft Defender for Endpoint, both in 2020. The capability did not go away and has been extended considerably since. If you are working from documentation or a supplier proposal that still says ATP, it is worth checking how current the rest of it is.
The coverage review is short. Configuration and rollout for a typical mid-sized organisation runs over a small number of weeks, phased so nothing affecting mail flow or device behaviour reaches everyone at once. Tuning then continues for a period after go-live, because false positives can only be assessed against real activity.
Yes, and it needs to be. Default policy is a starting point that suits nobody exactly. Impersonation protection needs to know who your executives and finance staff are, attack surface reduction rules need testing against your actual applications, and access policies need to reflect how and where people work. That configuration is the majority of the value.
Microsoft Defender is Microsoft's family of threat protection products, covering email and collaboration (Defender for Office 365), devices (Defender for Endpoint), identity infrastructure (Defender for Identity), cloud applications (Defender for Cloud Apps) and Azure workloads (Defender for Cloud), with Defender XDR correlating signals across them. It is licensed in parts across the Microsoft 365 plans rather than as a single product, which is why most organisations own an inconsistent slice of it.

FREE DEFENDER COVERAGE REVIEW

Find out what you already have, and what it is actually covering

Whether you are enabling Defender for the first time, weighing an E5 move against add-ons, paying separately for protection you may already own, or dealing with an alert queue nobody reads, start by establishing your actual position.

  • Microsoft security specialists

    Speak directly with consultants who configure and tune these environments every day.

  • Clear about who does what

    Monitoring commitments state the hours, the response actions and the escalation path.

  1. 1
  2. 2
What is your enquiry about?*