...

In this article, we will talk about the best ways to address important security and compliance issues with SaaS products, and review some solutions available within plans like Microsoft E5 or E3.

Table of contents

  1. The paradox of reducing cost while maintaining high compliance and security standards
  2. The range of solutions within Microsoft licenses E3 and E5
  3. Is the Microsoft E5 license really worth the money?
  4. Alternatives to a Microsoft E5 License
  5. AGAT’s SphereShield for compliance
This image has an empty alt attribute; its file name is image3.png

1- The paradox of reducing costs while maintaining high compliance and security standards

It’s 2022 and the global scenario is one of economic uncertainty. Companies are starting to pull back on developments while others look for ways into reducing operational costs before starting to lay off employees.

While the global stagflation keeps on developing, many chiefs of compliance, security, and technology officers are facing the same question: How is it possible to reduce the overall SAAS spending while not sacrificing any security or compliance requirements?

On one hand, it’s impossible to get rid of essential paid services such as corporate emails, servers, cybersecurity, collaboration software, and the like. But on the other hand, there is a tremendous risk associated with the idea of replacing functioning solutions developed by well-known vendors with home-made not-so-effective patches.

2- The range of solutions within Microsoft licenses E3 and E5  

Microsoft 365 is the market leader in SaaS, offering a complete suite of business productivity tools for easier communication and collaboration. We know that Microsoft 365 includes Windows OS and the whole Office product line in its subscription, also allowing the use of diverse cloud-based services for business environments, such as hosted Exchange Server, Skype for Business, MS Teams and SharePoint, among others.

With a good price/value ratio, the E3 license is one of the most popular options between small to mid-sized organizations. But Microsoft E3 offers only limited solutions around identity and access management, threat protection and information protection, and it lacks compliance solutions.

Then there’s Microsoft E5, a more than significant step-up from Microsoft 365 E3 that includes important security features such as, Identity Management, Cloud App security, Auto Labeling for sensitive content, etc., as well as it can address some compliance requirements. But this plan also includes other functionalities like Power BI and Teams Phone that add up to the price unnecessarily for companies if they won’t use them.

This image has an empty alt attribute; its file name is image2-1024x390.png

3- Is the Microsoft E5 license really worth the money?

The difference between the features provided by E3 and E5 is clearly reflected in the monthly subscriptions price jump of $21. Taking a look at their published prices, if a company with 500 employees decides to contract E3 it would incur an annual cost of 216,000.00 USD, and that price ascends to 342,000.00 for the Microsoft E5 plan.

But the bottom line is, getting access to the newest compliance and data governance technology developments by Microsoft demands high-end licensesThe Microsoft 365 Enterprise packages E3 and E5 are aimed at organizations that need more information protection and compliance capabilities.

Microsoft E3 and E5 licenses prices list

Microsoft also offers separate plans for security and compliance that can be added to an E3 license. There’s the Microsoft 365 E5 Security add-on (formerly Identity & Threat Protection) priced at $12/user/month, and the Microsoft 365 E5 Compliance add-on, also priced at $12/user/month, both requiring annual commitments.

It’s not necessary to dive into the details of the solutions provided by each of those add-ons knowing that, by adding the two of them to an E3 plan, the total price ends up paired to E5. So if your organization is interested in both the security and the compliance solutions by Microsoft it’s still preferable to purchase the complete E5 bundle.

I know what you’re thinking, is it possible to purchase the E5 security and compliance add-ons for a cheaper license than E3? No, Microsoft makes these packages available only for E3-level subscriptions. Smaller companies with plans like Business Premium (limited to 300 hundred users) don’t get the option of incorporating Microsoft’s wider compliance and security features.

For the case of Office 365 (the subscriptions without Windows and EMS) the conclusion remains the same, an Office 365 E5 license will give you a better bundle than adding security and compliance separately to Office 365 E3.

4- Alternatives to a Microsoft E5 License

Ultimately, decision makers should know that it’s not impossible to drop down and optimize SaaS software licensing if certain features aren’t essential for their organization’s particular needs. More so, many users choose to turn to third party providers for alternatives to some of Microsoft’s native capabilities.

It’s also important to address that organizations with specific needs, like the ones in tightly regulated sectors or those subject to data protection legislation need to secure their environments with the right technology to manage and protect sensitive data, and even though the E5 license offers a good complete set of security and risk mitigation features it’s not necessarily the only way, or the most effective, to address your compliance needs.

In past articles, we have taken a look into the limitations that the native capabilities of products such as Microsoft Teams have when it comes to compliance. You may find that important functionalities, for example the ones regarding Information Barriers, are very limited with a Microsoft E5 license and not available in E3.

5- AGAT’s SphereShield for compliance

With costs that represent only 10% of a Microsoft E5 license, AGAT’s SphereShield offers a complete compliance set of solutions that can be integrated to Microsoft Teams, expanding some crucial functionalities.

This image has an empty alt attribute; its file name is image4-1024x446.png

Among its most important characteristics there’s the inclusion of an advanced information barriers solution: SphereShield’s Ethical Wall, that allows extra control over guest user capabilities, granular control over specific operations, incident auditing for compliance awareness, and more.

We have addressed before how Microsoft’s DLP solution is only near-real time, and the risks involved in that kind of reactive approach. AGAT’s SphereShield DLP engine offers real-time inspection of content and context-aware policies for data loss prevention, identifying and blocking sensitive data before it reaches the end user.

AGAT has also developed features that extend Microsoft Teams’ governance capabilities for better control over user permissions and preventing information leakage. SphereShield also offers eDiscoveryadvanced search capabilities that can be implemented online or on-site.

Finally, the whole range of compliance solutions developed by AGAT can be licensed separately, allowing companies to further tailor their subscription plans to meet their exact needs.

We encourage you to contact us to get a free trial of AGAT’s SphereShield