Do you still need antivirus if you’ve got Microsoft Defender? The honest answer for UK businesses
Windows comes with Microsoft Defender Antivirus built in, so a lot of businesses are paying for a second antivirus they don't need, and a few are relying on the free one when they need more. Ben, Inology's senior technician, explains the difference between Defender Antivirus and Defender for Business, when the free one is enough, and what Cyber Essentials actually asks for.

Every few weeks I get asked a version of the same question. Usually it comes just after someone has seen a renewal invoice. "We've got Microsoft Defender. Do we still need to pay for this?"
The honest answer is: it depends on which Defender you mean, and most people don't know there's more than one. So let me untangle it, because the right answer saves some businesses a few hundred pounds a year and saves others from a nasty surprise.
There are two things called Defender
Microsoft Defender Antivirus is the free scanner built into every Windows 10 and Windows 11 PC. Microsoft's own documentation describes it plainly: it's built into Windows, and it works with Microsoft Defender for Endpoint to protect the device. It updates itself, it scans files as they're opened, and it's quietly very good at catching known malware. If you bought a laptop from a shop and never installed anything else, this is what's protecting it.
Microsoft Defender for Business is a different product. Microsoft describes it as an endpoint security solution based on Defender for Endpoint, designed for businesses up to 300 users. It uses the same scanning engine, but adds the things a business actually needs and a home user doesn't: endpoint detection and response, attack surface reduction rules, vulnerability management, automated investigation and remediation, and one console where you can see every device at once. It's included in Microsoft 365 Business Premium, which is where most of our clients already are.
When someone says "we've got Defender", they almost always mean the first one. Whether that's enough is the real question.
Is the free one good enough?
For the job of stopping known malware on a single PC, yes. The NCSC's device security guidance says it directly: Windows, macOS and Android include built-in antivirus by default, and these will meet the needs of many organisations. That's the UK government's technical authority on cyber security, not a vendor.
Here's the bit that surprises people. If you install a third-party antivirus on a Windows PC that isn't enrolled in Defender for Endpoint or Defender for Business, Microsoft Defender Antivirus goes into disabled mode automatically. It doesn't run alongside. It switches off. So the business paying for a second antivirus "for extra protection" isn't getting two layers. It's getting one layer, and paying for it.
Where the free Defender genuinely falls short for a business is not detection. It's management. You can't see from one place which of your twenty machines are protected, which one has had an alert sitting unread for a fortnight, and which one had real-time protection switched off by a user who found it annoying. On one PC that doesn't matter. On twenty it does, because the one you can't see is the one that gets you.
What Cyber Essentials actually asks for
A lot of the "we need proper antivirus" anxiety comes from Cyber Essentials. So I checked the current requirements document rather than guessing.
The Cyber Essentials requirements for IT infrastructure (v3.3) say you must make sure a malware protection mechanism is active on all in-scope devices, kept up to date in line with the vendor's instructions, and configured to prevent malware from running, prevent the execution of malicious code, and prevent connections to malicious websites. It then says something that often gets missed: in most modern products these options are built into the software supplied.
Nowhere does it say "paid" or name a vendor. Defender Antivirus, switched on and correctly configured, passes. What fails assessments is a device where it's been turned off, or a device nobody knew about. That's a visibility problem, not a product problem.
So when do you actually need more?
You need more than the free Defender when any of these are true:
- You've got more than a handful of devices. Past about five, you need a central view. That's Defender for Business or an equivalent, not a second scanner.
- You handle data that would hurt if it left. Payroll, client files, patient records. Endpoint detection and response is what tells you something odd is happening before it becomes a incident response exercise.
- You're going for Cyber Essentials Plus. The assessor will test devices. A managed console that proves every device is protected makes that a short conversation.
- Someone in the business keeps turning things off. Managed tooling stops that. Free Defender doesn't.
And you might still want a third-party product if you're mostly on Macs or Linux, if you're stuck on an older Windows that Microsoft no longer supports, if an insurer or contract names a specific tool, or if your IT provider already runs a different endpoint product well and switching would cost more disruption than it saves. Those are real reasons. "We've always had one" isn't.
What I'd actually do
If you're on Microsoft 365 Business Premium: Defender for Business is already in your licence. Check it's switched on and every device is enrolled. Then cancel the third-party antivirus, because right now it's switching off the thing you're already paying for. We find this on about one new client in three. The September Threat Brief covered why Microsoft 365 tenants need this layer more than they used to.
If you're on Business Standard or Basic: the free Defender Antivirus is doing the detection job. Your gap is visibility. Either step up to Premium, which brings Defender for Business and a lot else with it, or make sure whoever looks after your IT has a way of seeing every machine. Don't just buy another scanner.
If you're not sure which licence you're on, or whether Defender for Business is actually enabled rather than just included: that's a ten-minute check, and it's one we do as standard when we take on a managed IT support client. Ask.
Frequently asked
Is Microsoft Defender good enough antivirus for a small business?
For stopping known malware on a Windows PC, yes. Microsoft Defender Antivirus is built into Windows 10 and 11, updates itself, and the NCSC says the built-in protection in Windows, macOS and Android will meet the needs of many organisations. Where it falls short for a business is management: there's no central view of which machines are protected, which have an alert, and which have quietly had it switched off.
What's the difference between Microsoft Defender Antivirus and Defender for Business?
Defender Antivirus is the free scanner inside Windows that catches known malware on one machine. Defender for Business is a separate product, included with Microsoft 365 Business Premium, that adds endpoint detection and response, attack surface reduction rules, vulnerability management and automated investigation across every device in the business, all managed from one console. Same engine underneath, very different amount of visibility and control.
Does Cyber Essentials require a paid antivirus?
No. The requirement is that a malware protection mechanism is active on every in-scope device, kept up to date in line with the vendor's instructions, and configured to prevent malware from running and block connections to malicious websites. The requirements document says that in most modern products these options are built into the software supplied. Defender Antivirus, correctly configured, meets it. The assessor cares that it's on, updated and configured, not who made it.
What happens to Defender if I install another antivirus?
On a Windows 10 or 11 PC that isn't enrolled in Defender for Endpoint or Defender for Business, installing a third-party antivirus puts Microsoft Defender Antivirus into disabled mode automatically. Only one of them runs. So you aren't getting two layers of protection, you're swapping one for the other, and paying for the privilege.
When would I still want a third-party antivirus?
If your business runs mostly Macs or Linux, if you're on an older Windows version Microsoft no longer supports, if a specific contract or insurer names a product, or if your IT provider already manages a different endpoint tool well and switching would cause more disruption than benefit. Those are real reasons. 'We've always had one' isn't.
Should I cancel my antivirus subscription?
Not until you know what's replacing it. Check which Microsoft 365 licence you're on, whether Defender for Business is included and actually switched on, and whether every device is enrolled. If it is, the third-party licence is probably dead money. If it isn't, cancelling first leaves a gap. Order matters.
Not sure which Defender you've got?
It's a ten-minute check: which Microsoft 365 licence you're on, whether Defender for Business is enabled, and whether every device is enrolled. No obligation, no sales pitch.
Ask Ben to check