Many organisations are paying twice for the same security outcomes without realising it.
They’ve already invested in Microsoft security capabilities through their existing licensing, yet continue to pay for third-party tools that provide similar functionality because those capabilities haven’t been fully deployed or adopted.
The latest Forrester Total Economic Impact™ study, commissioned by Microsoft, explored what happens when organisations make better use of the security capabilities already included in Microsoft 365. It found that organisationswere able to reduce costs, simplify operations and strengthen their security posture by consolidating onto Microsoft Security rather than maintaining overlapping security tools.
In this article, we’ll look at the Microsoft security capabilities you may already own, why they often go unused, where the opportunity for consolidation lies, and how to start making better use of your existing Microsoft investment.
What security capabilities could you already own?
Many organisations already license Microsoft security capabilities they haven’t yet fully deployed or adopted.
The capabilities available will depend on your Microsoft licensing. Microsoft 365 E5 includes Microsoft’s broadest set of integrated security and compliance capabilities, including:
Microsoft Defender
Protect users, devices and workloads across email, endpoints and cloud environments.
Microsoft
Entra
Secure identity and access by controlling who can access what, and under which conditions.
Microsoft Intune
Manage and secure corporate devices across laptops, mobile devices and endpoints.
Microsoft Purview
Help protect sensitive information through data security, compliance and information governance.
Microsoft Sentinel
Detect, investigate and respond to threats through a unified security operations platform.
For many organisations, these capabilities overlap with third-party products that remain in place because of historic purchasing decisions, contract renewals or phased migration plans. Understanding what’s already included in your Microsoft licensing is often the first step towards identifying opportunities to simplify your security estate.
Where does the saving come from?
In the Forrester study, the researchers needed a simple way to represent the cost of Microsoft’s security capabilities. To do this, they used the difference in list price between Microsoft 365 E3 and E5, approximately €18 per user per month, as a proxy.
Here’s the important point: for organisations that already licensed Microsoft 365 E5, there was no additional licence cost. The security capabilities were already included. The value came from deploying and making better use of them.
That’s the practical value of consolidation. You’re not always buying something new. Often, you’re making better use of the capabilities you already own and retiring overlapping tools that no longer add value.
Why the value has increased again
In November 2025, Microsoft announced that Security Copilot would be included with Microsoft 365 E5, further increasing the value of the licence for organisations already using it.
One organisation interviewed as part of the Forrester study reported that Security Copilot saved each member of its security team between eight and ten hours a week. Without it, the organisation estimated it would have needed to hire four additional team members.
While every organisation’s experience will differ, the finding highlights an important point. The value of Microsoft 365 E5 extends beyond consolidating licences. When its capabilities are fully adopted, they can help security teams work more efficiently, reduce manual effort and focus on the tasks that require human expertise.
Why does it go unused?
In our experience, there are a few common reasons why organisations don’t make full use of the Microsoft security capabilities they already own:
- Microsoft 365 was originally deployed to support productivity and collaboration, with security capabilities introduced later
- Existing third-party tools remain in place because of contract commitments, operational dependencies or phased migration plans
- Teams don’t always have full visibility of the security capabilities included in their Microsoft licensing
- Organisations rarely review their existing security estate to identify overlapping capabilities and opportunities for consolidation
- Deploying new security capabilities requires planning, testing and change management, so adoption often happens gradually
What does switching it on involve?
Moving to the tools you already own does not need to be a risky, all-at-once project.
In the Forrester study, most organisations fully deployed their Microsoft Security tools in four to nine months, around 36% faster than organisations using a less integrated approach.
A practical approach looks like this:
Map what you own
Understand the Microsoft security capabilities already available within your environment
Identify where capabilities overlap
Compare your existing security tools against what your Microsoft licensing already provides
Configure and prove replacement capabilities
Ensure Microsoft capabilities are properly deployed, tested and ready before replacing existing tools
Retire duplicate tools safely
Remove overlapping tools in a controlled way, taking contracts, dependencies and risk into account
Keep reviewing as your estate evolves
Regularly assess your security stack to take advantage of new capabilities and avoid unnecessary overlap
