Microsoft 365 licensing looks like a simple choice from the sign-up page: pick a tier, assign it to everyone, done. In practice it's one of the most common sources of quiet overspend we find when we review a business's Microsoft estate, not because anyone made an obviously wrong decision, but because the right tier for a 12-person business at sign-up isn't the right tier for the same business three years and forty hires later, and nobody's gone back to check.
In short: Business Basic, Standard and Premium (capped at 300 users) cover the vast majority of UK SMBs, and Business Premium's added Defender, Intune and conditional access features are worth the jump for most businesses handling any sensitive data. The Enterprise tiers, E3, E5 and F3, matter once you outgrow 300 seats or need specific enterprise-only compliance and device management capabilities; E5 adds real advanced security and compliance value, but at real extra cost, and it's not something every business needs by default. Microsoft 365 Copilot sits on top as a separate per-user add-on, worth evaluating on adoption readiness and concentrated use cases, not blanket rollout. And the biggest cost lever for most businesses isn't which tier you pick once, it's whether anyone keeps that assignment right as the team changes.
This guide covers what each tier actually includes, where Copilot fits, the licensing mistakes we see most often, and the difference between choosing a tier once and keeping your licensing under control on an ongoing basis, which are two different problems that get treated as one far too often.
What are you actually choosing between?
Microsoft splits its Microsoft 365 plans into two families, and which one applies to you is mostly decided by headcount and complexity, not preference.
Business Basic, Standard and Premium (up to 300 users)
These three tiers are built for small and mid-sized organisations and are capped at 300 licensed users per tenant. Business Basic gives you Exchange, Teams, SharePoint and OneDrive along with the web and mobile versions of the Office apps, but not the installed desktop apps, it suits roles that live mostly in a browser. Business Standard adds the full desktop versions of Word, Excel, Outlook and PowerPoint plus Teams webinar and some collaboration features, and is the tier most knowledge-worker roles actually need day to day. Business Premium adds a meaningful step up in security and device management on top of Standard: Microsoft Defender for Business, Intune for mobile device and app management, Windows Autopilot for automated device provisioning, and conditional access policies that let you gate sign-in on device compliance and risk signals. For any business handling client data, financial information or anything you'd genuinely mind losing, Business Premium's added protection is usually worth the extra cost over Standard, it's a small percentage increase in licence spend for a real reduction in your most common attack surface: compromised accounts and unmanaged devices.
E3, E5 and F3 (Enterprise, no seat cap)
The Enterprise tiers have no 300-user ceiling and are built for larger or more complex organisations. Microsoft 365 E3 includes the full desktop Office apps, Windows 11 Enterprise upgrade rights, and a deeper set of Intune device management and baseline compliance features (retention policies, basic eDiscovery) than the Business tiers offer. It's the natural landing point once you outgrow 300 seats, or need enterprise-specific device and compliance controls Business Premium doesn't include, even below that threshold. Microsoft 365 E5 adds Microsoft's most advanced security and compliance capabilities on top of E3: Defender for Office 365 Plan 2, Defender for Identity, Defender for Cloud Apps, Insider Risk Management, Advanced eDiscovery, Communication Compliance, Power BI Pro, and Teams Phone calling plans. This is genuinely strong tooling, and for businesses in regulated sectors, or with a real, current need for advanced threat protection and compliance evidence, it earns its cost. It's also the tier we see oversold most often, bought because it's the top of the list rather than because a specific capability in it is actually going to be used. Microsoft 365 F3 is the frontline worker plan: built for shift-based staff, retail, warehouse or clinical roles who need core Teams, Outlook and SharePoint access without a full desk-based licence, priced well below E3 to reflect that narrower scope.
Where Microsoft 365 Copilot fits
Copilot for Microsoft 365 sits on top of whichever tier you're already on, as a separate per-user, per-month add-on rather than a replacement for any of them. It doesn't change which base tier is right for a role, it's a second decision layered on top, and the two shouldn't be conflated: getting the base tier right is about what each role needs to do its job; adding Copilot is about whether that specific person has a task Copilot genuinely accelerates, often enough to justify the ongoing cost.
The two things worth checking before adding seats are cost and adoption readiness. On cost, Microsoft has adjusted Copilot's packaging and pricing more than once since launch, so treat any figure you've seen as a starting point to verify, not a fixed number, your Microsoft partner or your current agreement will have the live price. On adoption readiness, the return on a Copilot licence comes overwhelmingly from a smaller number of people using it heavily on tasks it's actually good at, not from spreading a licence thinly across everyone in the business "to see who uses it." We've written a fuller framework on this in is Microsoft 365 Copilot worth it?, and if data hygiene and access control are the open question before you commit to seats, our free Copilot readiness assessment scores exactly where your tenant stands first.
"The tier decision and the Copilot decision get made together far too often. They're separate questions: one is about what a role needs to do its job, the other is about whether a specific person has a task Copilot genuinely speeds up, often enough to be worth paying for every month whether they use it or not."
The full comparison
Prices below are Microsoft's own published list pricing at the time of writing, per user per month, and are given as rough bands rather than exact figures: Microsoft's pricing, currency and promotions vary by region, agreement type and time, and change more often than this page will be updated. Confirm current pricing for your tenant and region before budgeting against any of these.
| Tier | Family | Best suited to | Added beyond the base apps | Rough monthly cost per user* |
|---|---|---|---|---|
| Business Basic | SMB (≤300 users) | Browser-first roles, light collaboration needs | Web/mobile Office apps, Exchange, Teams, SharePoint | Low, roughly £4-5 |
| Business Standard | SMB (≤300 users) | Most knowledge-worker roles | Full desktop Office apps, Teams webinars | Mid, roughly £9-11 |
| Business Premium | SMB (≤300 users) | Any role handling sensitive data or a managed device | Defender for Business, Intune, Autopilot, conditional access | Higher, roughly £19-21 |
| F3 | Enterprise (no cap) | Frontline, shift-based staff | Core Teams/Outlook/SharePoint access, no desktop apps | Low, roughly £7-8 |
| E3 | Enterprise (no cap) | Larger or more complex estates, 300+ seats | Windows 11 Enterprise rights, deeper Intune and compliance | High, roughly £29-32 |
| E5 | Enterprise (no cap) | Advanced security/compliance/voice needs specifically | Defender suite, Insider Risk, Advanced eDiscovery, Teams Phone | Highest, roughly £50-54 |
*Approximate bands based on Microsoft's published list pricing, per user/month, at time of writing. Actual pricing depends on region, currency, agreement type (CSP, EA, direct) and any current promotions, and Microsoft revises these regularly, treat this table as directional, not a quote.
The licensing mistakes that actually drive overspend
Most Microsoft 365 overspend we find during a licensing review doesn't come from picking the "wrong" tier at the outset. It comes from what happens to that decision over the following one to three years, while headcount, roles and risk all change and the licensing assignment doesn't keep up.
Shelfware is the single most common and easiest issue to find: licences still assigned to disabled accounts, leavers who were offboarded from email but never unlicensed, or shared mailboxes and service accounts sitting on a full user licence they don't need. On any tenant we review that hasn't had a recent audit, this is where we look first, and it's rarely a small number.
Over-licensing is paying for E5, or Business Premium's full security stack, on roles that will never use most of what it adds. It's not wrong to standardise a tier across a team for simplicity, but it's worth being honest about whether that's a deliberate trade-off (simplicity is worth the extra spend) or an assumption nobody's tested (we've always given everyone E5, so we still do).
Under-licensing is the mirror image and the one that's easy to miss because it doesn't show up as a cost until something goes wrong: a finance or HR role on Business Basic with no conditional access, no managed device policy and no advanced threat protection, handling exactly the kind of data an account compromise would be most damaging to lose. The licence itself looks cheaper. The incident it doesn't prevent almost never is.
Inconsistent tier assignment across a growing team is what happens when the first three problems compound: new starters get whatever tier IT had spare capacity for at the time, promotions and role changes don't trigger a licensing review, and eighteen months later nobody can explain why two people doing the same job are on different tiers with different security postures. None of this is negligence, it's what happens by default when licensing is treated as a one-off setup task rather than something that needs revisiting as the business changes.
Picking a tier vs keeping it under control
Everything above answers one question: which tier fits which role, right now. That's a real decision and worth getting right, but it's a different problem from keeping licensing right over time as your team grows, roles change and Microsoft itself revises what each tier includes. A one-off licensing review fixes the picture on the day it happens; it doesn't stop shelfware or inconsistent assignment creeping back in six months later, which is exactly what tends to happen without someone actively watching for it.
That ongoing piece is what our licensing and cost management service is built for: not a single audit, but continuous oversight of tier assignment, shelfware and renewal timing, so the gap between what you're paying for and what you're actually using stays closed rather than reopening every time someone joins, leaves or changes role. If the immediate question is a broader Microsoft 365 tenant setup or governance project rather than ongoing cost control specifically, our Microsoft 365 services cover migration, governance and Intune configuration directly. And if Azure spend is part of the same conversation as your licensing, our cost optimisation team looks at both together, since the two are usually reviewed at the same time in practice.
How to decide
Start with headcount and complexity: under 300 seats with straightforward needs, the Business tiers cover almost everyone, and Business Premium is worth the step up from Standard for any role touching sensitive data. Above 300 seats, or with specific enterprise compliance or device management requirements, E3 is the natural baseline. From there, only add E5 where a specific capability in it, advanced threat protection, Insider Risk Management, Advanced eDiscovery, Teams Phone, is something you'd actually use, not because it's the most complete tier on the page. Treat Copilot as a separate decision layered on top, sized to genuine use cases rather than headcount. And whichever combination you land on, put a date in the diary to check it again, because the tier that's right today is rarely the tier that's still right in two years without anyone looking.
If your desktop and device strategy is the next question alongside licensing, our AVD vs Windows 365 vs traditional desktops comparison covers that decision in the same straight, neutral way. For further reading on the tiers themselves, Microsoft's own plans for Enterprise page and its security and compliance licensing guidance are worth reading directly, along with the Copilot for Microsoft 365 overview if you're weighing that decision too.
Frequently asked
What's the difference between Business Premium and E3?
Business Premium is capped at 300 users and built for SMBs: it adds Defender for Business, Intune device management, Autopilot and conditional access on top of the full desktop Office apps, at a fraction of E3's cost. Microsoft 365 E3 has no seat cap, adds Windows 11 Enterprise upgrade rights and a deeper set of Intune and compliance capabilities aimed at larger, more complex estates, but its baseline security add-ons aren't as complete as Business Premium's out of the box. For a business under 300 seats, Business Premium usually covers the same practical security ground as E3 for meaningfully less per user; the main reasons to move to E3 are outgrowing the 300-seat cap or needing specific enterprise-only compliance or device management features Business Premium doesn't include.
Do I need E5 for security?
Almost never as a first step, and often not at all. E5's security value is real, Defender for Office 365 Plan 2, Defender for Identity, Defender for Cloud Apps and advanced compliance tooling are genuinely strong, but most businesses get more security improvement per pound spent by properly configuring what Business Premium or E3 already includes: conditional access, MFA everywhere, Defender for Business or Defender for Endpoint, and a real oversharing review. E5 earns its cost when a specific capability it adds is something you'd actually use and can't get any other way, not as a blanket upgrade because it's the top tier and sounds safer.
Can I mix licence tiers across my team?
Yes, and for most businesses beyond a handful of people, you should. Assigning every user the same tier regardless of role is one of the most common sources of overspend on one end (paying for E5 features a receptionist never touches) and under-protection on the other (a finance director on Business Basic with no advanced threat protection). Frontline or shift-based staff who only need core Teams and Outlook access are often better suited to F3 than a full desk-based licence. The only real constraint is keeping the mix deliberate and documented, based on what each role actually needs, rather than whatever tier someone happened to be assigned when they joined.
How much does Microsoft 365 Copilot cost on top?
It's sold as a per-user, per-month add-on on top of an existing qualifying Microsoft 365 licence, and Microsoft has adjusted its packaging, eligibility and pricing more than once over the past couple of years, so a specific figure printed here would likely be wrong by the time you read it. What matters more for planning is the shape of the cost: it's flat per seat regardless of how much that person actually uses it, so the return depends entirely on concentrating licences on people with a genuine, frequent use case rather than spreading them thinly across the whole business. Check your current Microsoft 365 agreement for the live price and eligibility before committing to seat numbers.
How do I stop paying for licences nobody uses?
Start with a straightforward audit: cross-reference assigned licences against active sign-ins over the last 60-90 days, and against your leavers list, shelfware (licences left on disabled or departed accounts) is usually the single biggest and easiest win to reclaim. After that, check whether anyone's on a higher tier than their role justifies, and whether anyone's missing security features their role genuinely needs. The harder part isn't finding the waste once, it's stopping it from creeping back in after every starter, leaver and promotion, which is a process problem more than a one-off clean-up.


