No device management (Intune)
CriticalDesktop Office apps are installed on unmanaged devices. If a laptop is stolen, the Office apps and cached documents are fully accessible. No remote wipe capability.
Build the deliverable — mid-cycle assembly
Features in matrix
Across all M365 products
SoW output formats
Tailored to engagement type
Deliverable formats
Business case builder
M365 SKUs mapped
Feature matrix coverage
Business Standard customers already have desktop Office apps, Teams, and SharePoint. They feel productive and don't think they're missing anything. But they have the same security gaps as Basic — no endpoint protection, no device management, no advanced email security, no conditional access. The conversation shifts from 'what do I get' to 'what am I risking.'
What they have today
Security gaps without the upgrade
Desktop Office apps are installed on unmanaged devices. If a laptop is stolen, the Office apps and cached documents are fully accessible. No remote wipe capability.
Desktop apps increase the attack surface — malicious macros in Word/Excel, infected files opened in desktop apps bypass web-only protections
Same as Basic — no ability to enforce MFA conditionally, block legacy auth, or require device compliance
Same basic EOP filtering. Desktop Outlook opens attachments directly — no sandbox detonation, no time-of-click URL protection
Users can save sensitive documents locally, copy to USB, print freely, email externally. Desktop apps expand the ways data can leave the organization
No conditional access, no self-service password reset, no dynamic groups