Video, Cybersecurity, Microsoft Purview

Microsoft Purview Licensing: The breakdown SMBs actually NEED

Table of Contents

Microsoft Purview Licensing Explained: Business Premium vs E3 vs E5

If you’ve looked into Microsoft Purview and come away confused about which license you actually need, you’re not alone. It’s the single biggest blocker CloudGuard sees when SMBs and mid-sized organisations start a data governance project, not the technology, the licensing.

In Episode 1 of Purview Perfection, CloudGuard’s Head of Advisory Jamie and Senior Security Architect Nick sat down on LinkedIn Live to close that gap. Here’s what they covered.

Why Purview Matters for SMBs

Here are four reasons SMBs are actually looking at Purview right now:

  • Protecting IP and commercially sensitive information from accidental or deliberate sharing
  • AI governance: making sure generative AI tools aren’t accessing or training on sensitive data
  • Compliance: putting data controls in place that support existing policy and make audits easier
  • Reducing blast radius: if an attacker does get into your SharePoint, properly labelled and protected data limits what they can actually extract or share

Most security spend goes on keeping attackers out. Purview is about limiting the damage once someone’s already in, closing the Data Gap that perimeter tools were never built to cover.

You Don’t Need E5 for Full Purview Anymore

Historically, Business Premium and E3 customers who wanted the full Purview suite had to upgrade all the way to E5. That’s no longer true.

Microsoft now offers two add-ons:

  • The E3 Compliance add-on
  • The Business Premium Purview Suite add-on

Both do the same thing for their respective license tier: they unlock full access to the Purview suite without requiring a jump to E5.

What You Get at Each License Tier, and What It Costs

Business Premium (typically under 300 users): core M365 apps and Teams, Defender for Business and Intune, sensitivity labels and basic DLP.

E3 (300+ users): full enterprise Office apps, Microsoft Entra ID P1, baseline retention and eDiscovery.

  • Base license: ÂŁ33.50 per user/month
  • Plus Compliance add-on: ÂŁ9.17 per user/month
  • Total: ÂŁ42.67 per user/month for full Purview

E5 / Enterprise (300+ users): full Purview compliance suite included as standard, plus Defender for Office 365 P2, Power BI Pro, and Teams Phone.

A Business Premium organisation can get the full Purview suite for ÂŁ32.30 per user/month, roughly ÂŁ19 less per user/month than going straight to E5, and without paying for E5 extras (Power BI Pro, Teams Phone) it may not need at all.

What “base” vs “full suite” actually means feature-wise:

Base Business Premium or E3, no add-on:

  • Sensitivity labels: you can define labels and start rolling them out to users
  • Limited Data Loss Prevention (DLP): policies apply only to cloud workloads, namely Exchange Online, SharePoint Online, and Teams

Full Purview Suite, via add-on or E5:

  • DLP everywhere, not just cloud. Using the Purview scanner, you can extend labelling and DLP policies to on-premise file shares and databases, plus auto-labelling at scale
  • Insider Risk Management: covering both data leaks (accidental sharing) and data theft (deliberate exfiltration, such as a user copying hundreds of files to a personal OneDrive), with adaptive protection policies that respond to changes in user behaviour across cloud and endpoint
  • DSPM for AI: visibility and control over what generative AI tools can access

One detail that catches people out: Purview licensing doesn’t work like some Microsoft products, where one high-tier user unlocks features tenant-wide.

With Purview, every user you want in scope of a policy, Insider Risk Management, for example, needs the right license assigned individually. That per-user cost is exactly why the sequencing advice below matters: you’re paying per head, so timing when you add the license is a real lever on cost, not just a technicality.

Pricing shown is per user/month and may vary by region, currency, and Microsoft’s current price list at time of purchase. Confirm current rates before budgeting.

When Should You Actually Upgrade?

This is the part most licensing guides skip, and it’s the most useful piece of advice in the whole session: don’t upgrade on day one.

Purview isn’t a technical deployment in the way traditional security tooling is.

The hard part isn’t configuration itself, it’s knowing what data matters and where it lives, and getting your users comfortable with labelling it correctly.

That groundwork typically takes three to six months, and you can do all of it on your existing Business Premium or E3 license.

CloudGuard’s Advice

Spend that three to six months maximising what you’ve already got. Only add the upgrade or add-on once you’ve hit the ceiling of your current license and you’re ready for the next phase, such as rolling out Insider Risk Management, which needs its own round of training on sensitive information types.

Upgrade too early, and you’re paying for features your organisation isn’t ready to use yet.

Three Mistakes That Kill Purview Rollouts

Here’s three patterns CloudGuard sees repeatedly with customers who come to them after a failed first attempt:

  1. Treating it as a pure technical exercise.
    Buying the license for everyone and switching everything on at once, without any user adoption plan. The result is employees can’t share or collaborate the way they used to, don’t understand the labels, IT gets flooded with complaints, and everything gets switched back off. Purview picks up a bad reputation internally that’s hard to shake.
  2. Treating it as an IT-only project.
    The real adoption work means bringing in every department, explaining the benefit to them directly, and involving them in defining labels and protection before anything goes live, not deploying it at them.
  3. Buying all the licenses upfront and figuring out deployment later.
    This creates a large spike in monthly licensing cost with no business benefit to show for it until deployment actually starts.

Three Steps to Get Started

If you’re at the beginning of a Purview project, our advice comes down to this, done in order:

  1. Find out exactly what license you’re on
    Whether Business Premium, E3, or E5, and remember licensing needs to be applied per user for the features you want them in scope of.
  2. Identify where your important data lives.
    Start with your most sensitive data first, such as HR data, financial data, or anything with PII, since it’s usually the easiest to locate and the highest-risk if it leaks.
  3. Roll out sensitivity labels manually before you touch auto-labelling.
    Get users used to labelling their own documents first. Auto-labelling comes later.

Alongside all three: invest in user communications.

For most organisations, Purview changes how everyone handles data day to day, not just what IT can see. Treating that as a comms and change management exercise, not just a licensing and configuration one, is what separates the rollouts that stick from the ones that get switched back off.

Coming Up in Episode 2

Jamie and Nick will cover how to identify who in your business actually owns your data, and how to get the right people involved in defining it, without needing a CISO to do it (although it helps if you have one). Make sure you’re following CloudGuard on LinkedIn so you don’t miss out!

Need help rolling out Purview?

Know exactly what your data is exposed to, before a board, auditor, or customer asks you to prove it. CloudGuard’s Microsoft Purview Assess gives you a clear, expert-validated view of your Purview configuration and data protection posture, using non-intrusive, audit-only policies. No disruption to your environment.

Author: Jen Begue
Share:
Author: Jen Begue
Share:

Related Resources

Microsoft Project Perception, Explained: Why Multi-Model Security Changes Everything
Why Multi-Model Security Changes Everything  Six years building an agentic SOC analyst (ANSEL) teaches you something quickly: more data is critical but not the answer. Better understanding through context of what it means is.   Microsoft Project Perception is built on exactly that insight. It’s not another security product. It’s a different way of thinking about how AI should reason, with context, consequence, and...
A glowing vendor evaluation checklist on a dark purple background
Why Your Vendor Evaluation Process Is Failing You (do this BEFORE YOU SIGN)
Most vendor evaluation processes are built to survive procurement, not to protect you eighteen months after go-live. Here’s the gap almost nobody catches before signing. Outlining The Problem The majority of security technologies need 90 days just to establish an accurate behavioural baseline and fair comparison. Please remember your existing...
Understanding Microsoft Purview licensing: The breakdown SMBs actually NEED
two men talking on a podcast posted on linkedin with a red arrow pointing towards a deepfake
Why Social Engineering Always Works: How Hackers Use Phishing & Deepfakes
We’ve all done the training, so why are attackers still getting through? Attackers no longer rely on bad spelling or suspicious links, they use AI-generated deepfakes and psychological profiling to manipulate people with astonishing precision. By exploiting the brain’s emergency response system, they trigger fear, urgency, or authority to override...
Dark purple background with claude logo and words pro, team and enterprise.
Claude Business Security: Choosing the Right Account for SMBs
When I shared my last article, a few people got in touch asking for a more practical follow-up, specifically around how small teams can use Claude Pro without putting business data at risk. This piece goes step by step through exactly that. Understand what you’re actually adopting Claude Pro is...
Two analysts looking surprised. Purple cyber background with phishing hook.
What Happens After a Phishing Attack? A Real Microsoft 365 Incident Walkthrough
If your organisation thinks a password reset or MFA alone are enough, think again. In this phishing attack breakdown by CloudGuard’s SOC team, Conor and Jon reveal the reality behind an actual breach involving a UK law firm, exposing how hackers use four methods to regain access long after initial...
purple background with computer that says threat from the field in cartoon like design
Cyber Threat Trends Q1 2026: Data Theft, AI Attacks and Emerging Risks
Executive Summary Every 90 days, we review the latest cyber threat trends to identify what IT leaders should learn, where resilience gaps are widening, and what practical actions organisations should take next.  The first quarter of 2026 has been intense. The UK threat picture is not defined by one single...
Microsoft Defender for Cloud
Microsoft Defender for Cloud Cloud environments change fast. New workloads, new services and new risks appear daily, often without full visibility or clear ownership. Microsoft Defender for Cloud provides continuous assessment across Azure, hybrid and multi-cloud environments to help organisations understand and reduce cloud security risk. CloudGuard ensures your cloud...
Woman looking at tablet with cyber imagery across the top.
The Limitations of External Penetration Testing (And What to Do About Them)
Core argument  Traditional internal penetration tests gives executives false confidence because it’s typically scope-limited, scheduled, doesn’t reflect real attacker behaviour and ignores the AI threats with user access. Would you feel comfortable boarding a plane if the pilot had practised emergency landings but had never actually simulated an engine failure?  So, why do businesses specifically exclude their...
Get In Touch

Our Cybersecurity Services Can Instantly Improve Your Business’ Security Posture

Complete the form to find out more about any of our one-off or managed cybersecurity services. Not seeing what you’re looking for? Our cybersecurity consultants and MXDR experts are always on-hand to provide the guidance and support you need.