Cyber attacks on Swiss SMBs have more than tripled since 2023. Phishing, ransomware and supply-chain attacks make endpoint security mandatory. Microsoft Defender for Business is the endpoint security solution included in Microsoft 365 Business Premium – designed for organisations up to 300 employees. This guide shows the CNEXT setup for Swiss SMBs.
What is Microsoft Defender for Business?
Microsoft Defender for Business (MDB) is the SMB version of Microsoft Defender for Endpoint Plan 2 – with simplified configuration. It covers:
- Next-generation antivirus with cloud-based threat detection
- Endpoint Detection & Response (EDR) with behaviour-based detection
- Attack Surface Reduction (ASR) rules
- Web content filtering (anti-phishing, blocking malicious URLs)
- Vulnerability management (Microsoft Defender Vulnerability Management)
- Automated Investigation & Response (AIR)
Supported: Windows 10/11, macOS, iOS and Android.
Licensing in Switzerland
| Licence | Defender for Business included? |
|---|---|
| Microsoft 365 Business Basic | ❌ |
| Microsoft 365 Business Standard | ❌ |
| Microsoft 365 Business Premium | ✅ |
| Microsoft Defender for Business standalone | ✅ (~CHF 3 / user / month) |
| M365 E3 + Defender for Endpoint Plan 1 / 2 | ✅ Plan 1 or 2 |
| M365 E5 | ✅ Defender for Endpoint Plan 2 |
For Swiss SMBs, Microsoft 365 Business Premium is usually the best choice – Defender for Business plus Intune are included.
Onboarding options
Defender for Business supports several onboarding paths:
- 1Intune (recommended) – devices auto-onboarded via compliance policy
- 2Local script – manual onboarding for pilot devices
- 3Group Policy (for hybrid AD) – classic Windows onboarding
- 4Microsoft 365 Defender wizard – SMB setup assistant (max 800 devices)
CNEXT recommends Intune-based onboarding combined with the M365 Defender wizard.
The six phases of a Defender rollout
1. Pre-setup (1 week)
- Licence check and activation
- Defender for Business tenant activation
- Enable Intune integration
- Configure notifications and alerts (email to IT team / SIEM)
2. Pilot (2 weeks)
- 5–10 pilot devices (mix of IT, power user, standard)
- Test onboarding via Intune
- Analyse first detections
- Helpdesk feedback
3. Policies (2 weeks)
- Next-gen protection policy (cloud protection, PUA, network protection)
- Firewall policy (domain / private / public)
- ASR rules in audit mode first
- Web content filtering with Swiss-specific categories
- Attack Surface Reduction for Office macros and scripts
4. ASR rules in block mode (2 weeks)
After 1–2 weeks of audit observation, switch to block mode:
- Block executable content from email and webmail
- Block JavaScript or VBScript from launching downloaded executable content
- Block Office applications from creating child processes
- Block credential stealing from Windows local security authority
- Block process creations from PSExec and WMI commands
5. Tenant-wide rollout (4 weeks)
- Wave onboarding (e.g. 50 devices / week)
- Helpdesk training
- Activate Microsoft Defender Vulnerability Management
- Roll out first vulnerability patches via Intune
6. Operations (ongoing)
- Weekly Defender dashboard review
- Monthly management report
- Quarterly tabletop exercise (incident response)
- SIEM integration (Microsoft Sentinel or third party)
Swiss compliance aspects
- Data residency: Defender data sits in the EU Data Boundary, not primarily in Switzerland
- FADP: Defender processes telemetry and security data – include in Art. 12 processing register
- Employee information: for BYOD and personal smartphones, inform employees clearly
- FINMA / ISO 27001: Defender for Business covers endpoint detection requirements
Integration with Microsoft Sentinel
Swiss midmarket and enterprise customers often integrate Defender into Microsoft Sentinel (cloud SIEM):
- All Defender alerts in one dashboard
- Correlation with Entra ID, Exchange Online Protection and third-party sources
- Automated response via Logic Apps
- Log retention for 1+ year (compliance)
CNEXT delivers the Sentinel integration as an extension.
FAQ
Is Defender for Business enough against ransomware? Defender provides multiple layers (antivirus, EDR, ASR, cloud protection) and stops most known ransomware families. You also need backup (Microsoft 365 Backup), phishing training and Conditional Access.
Can Defender for Business protect macOS and mobile devices? Yes – Windows, macOS, iOS, Android and Linux servers are supported.
What happens if we move to Defender for Endpoint Plan 2 later? Defender for Business covers most features already. Plan 2 adds threat hunting (KQL), Threat & Vulnerability Management Pro and Microsoft Threat Experts.
What does a Defender setup with CNEXT cost? Onboarding and policies for a 50-device SMB typically CHF 10,000–20,000. Managed service options from CHF 1,500 / month.
Conclusion
Microsoft Defender for Business is the most efficient endpoint security solution for Swiss SMBs in 2026 – already included in Microsoft 365 Business Premium. With the right configuration and integration with Intune, it becomes a complete security baseline. CNEXT delivers setup, training and operations for Swiss enterprises.

