Microsoft Defender for Business Setup Guide: Fortifying SMB Endpoints

In today's dynamic threat landscape, small and medium-sized businesses (SMBs) are increasingly targeted by sophisticated cyberattacks, including ransomware, malware, and phishing. Traditional antivirus solutions often fall short, leaving critical data and operations vulnerable. As a senior Azure architect at SkyCore Solutions, we understand these challenges, and we're here to guide you through implementing a robust, enterprise-grade solution tailored for SMBs: Microsoft Defender for Business.
Microsoft Defender for Business brings powerful endpoint security capabilities from the industry-leading Microsoft Defender for Endpoint, optimized for organizations with up to 300 users. It provides next-generation protection, endpoint detection and response (EDR), automated investigation and remediation, and attack surface reduction capabilities, all managed from a streamlined portal. By following this Microsoft Defender for Business setup guide, you will successfully deploy and configure this essential service, ensuring your company's Windows, Mac, and mobile devices are protected from day one.
Prerequisites
- Licensing: An active Microsoft 365 Business Premium subscription or a standalone Microsoft Defender for Business license. For server protection, additional licenses are required.
- Administrative Roles: You must have the Global Administrator or Security Administrator role assigned in your Microsoft 365 tenant to perform the initial setup and configuration.
- Access: Access to the Microsoft 365 admin center and the Microsoft Defender portal.
- User Information: A list of your IT security team members (names and email addresses) who require access to the Microsoft Defender portal for management and monitoring.
- Tools: A modern web browser (Microsoft Edge is recommended for optimal experience). For device onboarding and advanced user management, PowerShell (version 5.1 or newer) is beneficial, along with the Azure AD or Microsoft Graph PowerShell modules.
- Estimated Cost: Microsoft Defender for Business is included with Microsoft 365 Business Premium, providing excellent value. If purchased standalone, costs are per user, per month. Server protection requires separate Defender for Servers licensing.
Step 1: Verify Subscription and Access the Microsoft Defender Portal
Before you begin the setup, it's crucial to confirm that your organization has the correct licensing and to initiate the provisioning of Microsoft Defender for Business. While there isn't a direct CLI command to 'start' the service, the process begins by accessing the Microsoft Defender portal, which triggers the provisioning if it hasn't already occurred.
Portal alternative: Navigate to the Microsoft Defender portal. Upon signing in with an appropriate administrator account, select Assets > Devices from the navigation pane. If Defender for Business has not yet been provisioned for your tenant, this action will typically trigger the automatic provisioning process. You should then see the setup wizard home screen.
Confirmation: After a brief moment, you should be presented with the Microsoft Defender for Business setup wizard or the Device inventory dashboard, indicating that the service is active and ready for configuration.
Step 2: Add Users and Assign Licenses
For your devices to be protected by Microsoft Defender for Business, each user associated with those devices must have a valid license assigned. This step ensures that all endpoint protection features are available to their devices.
For bulk user management, especially in larger SMBs or for automation, PowerShell offers efficiency. Ensure you have the Microsoft Graph PowerShell module installed (Install-Module Microsoft.Graph -Scope CurrentUser).
# Connect to Microsoft Graph
Connect-MgGraph -Scopes "User.ReadWrite.All", "LicenseAssignment.ReadWrite.All"
# Get the SKU ID for your Defender for Business or Microsoft 365 Business Premium license
# Use 'Get-MgSubscribedSku | Format-Table SkuPartNumber, SkuId, ServicePlans' to find exact values
# Example for Microsoft 365 Business Premium (SkuPartNumber will vary, adjust filter)
$licenseSkuId = (Get-MgSubscribedSku | Where-Object { $_.SkuPartNumber -like "*BUSINESS_PREMIUM*" -or $_.SkuPartNumber -like "*MDB_STANDALONE*" }).SkuId
# Example: Assign license to a specific user
$userPrincipalName = "user@yourdomain.com"
$userObjectId = (Get-MgUser -Filter "userPrincipalName eq '$userPrincipalName'").Id
Set-MgUserLicense -UserId $userObjectId -AddLicenses @{SkuId = $licenseSkuId}
# Example: Assign license to a group of unlicensed users (use with caution in production!)
# Get-MgUser -Filter "assignedLicenses/any(a:a/skuId eq null)" -All | ForEach-Object {
# Set-MgUserLicense -UserId $_.Id -AddLicenses @{SkuId = $licenseSkuId}
# }
Connect-MgGraph -Scopes "User.ReadWrite.All", "LicenseAssignment.ReadWrite.All": Establishes a connection to Microsoft Graph with the necessary permissions to read and write user and license assignments.Get-MgSubscribedSku: Retrieves all available license SKUs in your tenant. You'll need to filter to find the specific SKU ID for your Defender for Business or Microsoft 365 Business Premium license. CommonSkuPartNumbervalues for Business Premium might includeSMB_BUS_PREMor similar. For standalone Defender for Business, look forMDB_STANDALONEor equivalent.Set-MgUserLicense: Assigns the specified license SKU to a user using their unique object ID.
Portal alternative: For most SMBs, managing users and licenses through the Microsoft 365 admin center is simpler. Go to Users > Active users. Select the user(s) you wish to license, then click Manage product licenses. Check the box next to your Microsoft 365 Business Premium or Microsoft Defender for Business license, and click Save changes.
Confirmation: In the Microsoft 365 admin center, verify that the users you've assigned licenses to now show the correct license under their product license details. This confirms the entitlement for Defender for Business.
Step 3: Assign Security Roles
Access to the Microsoft Defender portal should be restricted based on the principle of least privilege. Assigning appropriate security roles ensures that your IT team can manage and monitor threats effectively without having excessive permissions. The setup wizard offers a simplified way to grant these roles.
For more granular or programmatic role assignments outside the wizard, you can use PowerShell to manage Entra ID (Azure AD) roles. Ensure you're connected to Microsoft Graph as shown in Step 2.
# Find the Security Administrator role template ID
$securityAdminRoleTemplateId = (Get-MgDirectoryRoleTemplate | Where-Object { $_.DisplayName -eq "Security Administrator" }).Id
# Create a new instance of the role (if it doesn't exist already, typically it does)
# $role = New-MgDirectoryRole -DirectoryRoleTemplateId $securityAdminRoleTemplateId
# Find the existing Security Administrator role object ID (if already instantiated)
$securityAdminRoleId = (Get-MgDirectoryRole | Where-Object { $_.DisplayName -eq "Security Administrator" }).Id
# Find the user object ID for the person you want to assign the role
$userPrincipalName = "securityadmin@yourdomain.com"
$userObjectId = (Get-MgUser -Filter "userPrincipalName eq '$userPrincipalName'").Id
# Assign the Security Administrator role to the user
New-MgDirectoryRoleMember -DirectoryRoleId $securityAdminRoleId -UserId $userObjectId
# To assign Security Reader role:
# $securityReaderRoleTemplateId = (Get-MgDirectoryRoleTemplate | Where-Object { $_.DisplayName -eq "Security Reader" }).Id
# $securityReaderRoleId = (Get-MgDirectoryRole | Where-Object { $_.DisplayName -eq "Security Reader" }).Id
# New-MgDirectoryRoleMember -DirectoryRoleId $securityReaderRoleId -UserId $userObjectId
Get-MgDirectoryRoleTemplate: Retrieves a list of available directory roles in Entra ID by their templates. We filter to find 'Security Administrator' or 'Security Reader'.Get-MgDirectoryRole: Retrieves instantiated roles in your tenant to get their unique object IDs.Get-MgUser: Fetches the user's object ID, which is required for role assignment.New-MgDirectoryRoleMember: Assigns the specified directory role (using its object ID) to the specified user (using their object ID).
Portal alternative: During the initial setup wizard in the Microsoft Defender portal, you will be prompted to grant access to your security team. You can assign either Security Administrator (view and edit) or Security Reader (view only) roles to selected users. If you're not using the wizard, or need to adjust later, go to Microsoft 365 admin center > Users > Active users, select a user, and under Account, click Manage roles. Assign the appropriate Entra ID security role there.
Confirmation: Have a user who was assigned the 'Security Reader' role attempt to access the Microsoft Defender portal. They should be able to view dashboards and alerts but should be blocked from making any configuration changes, confirming correct role assignment.
Step 4: Configure Email Notifications for Security Alerts
Timely awareness of security incidents is paramount. Setting up email notifications ensures that your security team is immediately informed when an alert is generated or a new vulnerability is discovered, even when they are away from the Defender portal.
While direct CLI/PowerShell commands for MDB's email notification settings are not typically used for this specific feature in an SMB context (as the portal provides a user-friendly interface), it's a critical configuration done via the UI.
Portal steps: During the setup wizard in the Microsoft Defender portal, you will reach the 'Set up email notifications' step. Enter the email addresses of your security team members who should receive alerts. If you're configuring this outside the wizard, navigate to Settings > Endpoints > Email notifications. Here you can add or modify notification rules, specifying the alert types and recipients.
Confirmation: Configure a test notification rule for a low-severity alert, if possible, and trigger a test alert (e.g., by creating a harmless EICAR test file on a protected device) to ensure emails are received by the designated recipients.
Step 5: Onboard Windows Devices
Onboarding your Windows devices is the most critical step to begin protecting your endpoints. Microsoft Defender for Business supports various onboarding methods for Windows 10 and 11 devices. For most SMBs without an existing Microsoft Intune deployment, using the local script method is often the simplest and most recommended approach for initial deployments, as it also enrolls the device into Intune automatically.
The local script method performs three key actions: it creates a trust with Microsoft Entra ID (if none exists), enrolls the device in Microsoft Intune, and onboards it to Defender for Business. We recommend onboarding up to 10 devices at a time using this script for smooth deployment.
# Placeholder for the downloaded onboarding script
# This script needs to be downloaded from the Microsoft Defender portal first.
# Example path after extraction: C:\temp\WindowsDefenderATPOnboardingScript.cmd
# Navigate to the directory where you extracted the onboarding package
Set-Location -Path "C:\Path\To\Extracted\OnboardingPackage"
# Run the onboarding script with administrative privileges
Start-Process -FilePath ".\WindowsDefenderATPOnboardingScript.cmd" -Verb RunAs
- Download the script: The primary action here is to download the onboarding package from the Defender portal. The package typically contains a
.cmdscript that orchestrates the onboarding. Set-Location: Changes your current directory to where you've extracted the onboarding script.Start-Process -FilePath ".\WindowsDefenderATPOnboardingScript.cmd" -Verb RunAs: Executes the downloaded onboarding script with administrative privileges. This script handles the installation and configuration of the Defender for Business agent on the local machine.
Portal steps (to get the script): In the Microsoft Defender portal, navigate to Settings > Endpoints > Device management > Onboarding. Select Windows 10 and 11 as the operating system and then choose Local Script from the 'Deployment method' dropdown. Click Download onboarding package. Once downloaded, extract the contents and copy them to the Windows device you wish to onboard. Run the script with administrative privileges.
Alternative (for Intune-managed devices): If your organization already uses Microsoft Intune, Defender for Business offers automatic onboarding. During the setup wizard, or by checking Settings > Endpoints > Configuration management > Enforcement scope, you can select the option to automatically onboard 'all devices enrolled' in Intune. This is the simplest method for Intune-managed environments.
Confirmation: After running the script, allow a few minutes for the device to report back. In the Microsoft Defender portal, go to Assets > Devices. Your newly onboarded device should appear in the list with a healthy status. You can also run the following PowerShell command on the device itself to verify the Defender sensor's status:
Get-Service -Name "Sense" # The 'Sense' service is the Microsoft Defender for Endpoint sensor
Step 6: Review and Customize Security Policies
Microsoft Defender for Business comes with default security policies for next-generation protection (antivirus/antimalware) and firewall protection. These default policies are pre-configured with recommended settings to provide strong protection from day one. However, SkyCore Solutions always recommends reviewing these policies and customizing them to align with your specific organizational needs and security posture.
For SMBs, managing these policies directly within the Microsoft Defender portal offers a simplified experience, abstracting away the complexities of Intune configuration profiles or Group Policy Objects.
Portal steps: In the Microsoft Defender portal, navigate to Settings > Endpoints > Configuration management > Device policies. Here you will find the default policies for Next-generation protection (Antivirus) and Firewall. Select a policy to review its settings. You can edit existing policies, or create new ones, to refine detection levels, exclusions, scheduled scans, and firewall rules. Ensure settings like cloud-delivered protection, real-time protection, and behavioral monitoring are enabled.
Confirmation: After reviewing and making any necessary adjustments, ensure the policies are applied to the correct device groups. Monitor your device health in the Defender portal dashboard to see the impact of your policies. You can verify local client settings on a device using PowerShell:
# Get current Windows Defender Antivirus settings
Get-MpPreference
# Get current Windows Defender Firewall rules (requires admin privileges)
Get-NetFirewallRule -PolicyStore ActiveStore | Where-Object { $_.Enabled -eq 'True' }
Step 7: Onboard Non-Windows Devices and Servers (Optional)
While Windows endpoints are often the primary focus, modern SMBs utilize a diverse range of devices. Microsoft Defender for Business extends protection to macOS, iOS, Android, and even servers (with additional licensing). Expanding protection across your entire device fleet provides a unified security posture.
The onboarding methods for these platforms differ, often leveraging mobile device management (MDM) solutions like Microsoft Intune for mobile devices or specific onboarding scripts for servers.
Portal steps: In the Microsoft Defender portal, go to Settings > Endpoints > Device management > Onboarding. Here you'll find different tabs for each operating system: Mac, Mobile (new capabilities are available for iOS and Android devices!), and Servers (Windows Server or Linux Server). Select the relevant tab and follow the specific guidance to download onboarding packages or integrate with your MDM solution.
- Mac: Typically involves downloading a package and deploying it via a management solution or manually.
- iOS/Android: Requires integration with an MDM solution (like Microsoft Intune) to deploy the Microsoft Defender app and associated policies.
- Servers: For Windows Server or Linux Server, you'll need additional licenses (e.g., Microsoft Defender for Servers Plan 1 or 2, included with Azure Defender or specific server licenses). Onboarding involves downloading a script or connecting to Azure Arc for hybrid servers.
Confirmation: After onboarding, verify that these devices appear in the Assets > Devices list within the Microsoft Defender portal and are reporting their security status correctly.
When to bring in a consultant
While this guide provides a comprehensive pathway for your Microsoft Defender for Business setup, certain scenarios can benefit significantly from expert assistance. If your organization has complex hybrid Active Directory environments, needs integration with existing third-party security solutions, requires advanced compliance reporting (e.g., CMMC, HIPAA), or plans a large-scale migration from legacy endpoint protection, SkyCore Solutions is here to help. Our team specializes in ensuring seamless, secure, and optimized cloud security deployments, allowing you to focus on your core business. Don't hesitate to reach out for tailored support and strategic guidance.
Book a free consultation