Organizations are shifting from reactive cybersecurity—waiting for audit failures—to proactive, strategically planned security programs built around real-time analytics and dynamic account control. In response, Microsoft introduced a simplified licensing approach for its security portfolio through the Enterprise Mobility + Security (EMS) suite, designed to help organizations choose capabilities aligned to their requirements while supporting hybrid environments across endpoints and cloud services.
Microsoft’s cross-platform strategy emphasizes consistent access and protection across PCs, tablets, and smartphones, extending to servers and document stores through centralized, policy-based management and rights management. EMS integrates three core security pillars: behavioral analytics (learning “normal” usage and flagging anomalies), threat intelligence (research-driven detection of phishing and ransomware precursors), and information protection (classification, labeling, and rights enforcement to enable secure internal and external sharing). The suite is offered in two tiers: EMS E3 as the core identity-driven security and management bundle, and EMS E5 adding expanded document classification/protection, risk-based identity protection, and improved cloud app management.
Key components include Azure Active Directory Identity Protection, which applies heuristic and machine-learning-driven risk evaluation to authentication events and can permit, notify, deny, or step-up authentication using MFA, device enrollment, or password reset. Microsoft Intune provides consolidated device and app management across Windows, macOS, iOS, and Android, enabling policy enforcement and app-based data loss controls. Azure Information Protection enables end-to-end document security—classification through protection—where labels and usage rights travel with files across devices, locations, cloud storage, and external partners. Advanced Threat Analytics (on-premises) monitors domain controller traffic to detect suspicious patterns and known attack techniques, while Cloud App Security (CASB) discovers and scores cloud apps using log-based analysis and policy controls.
Microsoft’s main challenges are harmonizing historically disparate products, reducing console sprawl, enabling integration with existing security stacks, and clarifying EMS licensing.
See All Locations
See All Locations