Microsoft 365 for San Antonio Mid-Market Businesses

Microsoft 365 in San Antonio changes shape at 300 users, because the Business plan family is capped at 300 licenses per tenant and the Enterprise plans that replace it carry a weaker endpoint security stack by default. The second half of that sentence is the part nobody budgets for.

Short version. Crossing 300 employees is not a billing event. Microsoft caps the whole Business family at 300 seats per tenant, and Microsoft 365 E3 ships with Defender for Endpoint Plan 1, which carries no EDR. So a routine Microsoft 365 license swap can end endpoint detection and response on the day it completes. Plan the security stack first.

We get this call about twice a year. A San Antonio company crosses 300 employees, somebody in HR tries to onboard the new hire, and the Microsoft 365 admin center refuses to assign the license. Payroll knew. IT did not.

Fixing the license itself takes about 20 minutes. Buy Enterprise seats, assign them, move on. What costs money is the thing sitting underneath the swap, because Microsoft 365 Business Premium and Microsoft 365 E3 are not the same security product sold at 2 different price points. They are different products, and the more expensive one is weaker in the place most companies care about most.

This is written for the middle of the market. Roughly 150 to 900 people, 1 tenant, a small internal IT team, and a headcount curve that is about to turn a licensing question into a security question. If you run 40 seats, most of this is a problem for later. The dated items further down are not.

What Microsoft 365 looks like for a San Antonio mid-market company

Microsoft 365 for a San Antonio mid-market business usually means 1 tenant, a Business Premium or E3 license base, Exchange Online, SharePoint, Teams, Intune device management, and Entra ID. What separates mid-market from small business is not the app list. It is that the license family itself becomes a constraint.

San Antonio is not a uniform IT market either. Healthcare and bioscience account for roughly 180,498 jobs across the metro and trade, transportation and utilities for about 213,300, according to San Antonio Chamber of Commerce figures compiled by SATXtoday. Layer the defense footprint on top of that and you get a region full of companies that grow quickly and carry real regulatory weight while they do it. The Greater SATX regional economic partnership counts more than 400 headquarters and major operations in the region.

Tenant shape is almost always the same. Business Premium on most seats, a handful of E3 or E5 licenses bought years ago for a reason nobody can now recall, Intune half configured, and conditional access rules that were written when the company was a third of its current size. That arrangement works. It keeps working right up until the seat count does something, which is where our San Antonio managed IT team usually gets involved.

The 300 seat cap is a tenant limit, not a plan limit

HR manager and IT administrator discussing headcount growth against the Microsoft 365 Business family 300 seat cap

This lives in the service description rather than the sales material, which is most of why it surprises people. The cap is not per plan. It applies across the whole Business family at once, and it is counted in provisioned licenses rather than in employees.

Microsoft’s exact wording. “If an organization is provisioned for 250 seats of Business Premium, the organization is eligible to provision only 50 more seats in total across the Business family of plans. Microsoft reserves the right to enforce the tenant limit of 300 provisioned licenses across the Business family of plans.” Source, Microsoft 365 and Office 365 plan options.

Read that against what most buyers believe and the gap gets obvious.

The situationWhat buyers assumeWhat Microsoft actually enforces
250 Business Premium seats, 100 more people arrivingBuy 100 more Business Premium seatsOnly 50 more seats are available in total across the entire Business family
Business Basic and Business Standard alongside Business PremiumEach plan carries its own 300 seat allowance1 combined 300 license cap for the tenant, shared across all Business plans
300 Business Premium plus 80 E3 in the same tenantNot permitted, everything has to convertPermitted. Enterprise, Business and standalone plans can be combined in a single account
Sitting at 340 Business Premium seats alreadyGrandfathered in, nobody will noticeMicrosoft reserves the right to enforce the 300 license tenant limit

Row 3 is the one that starts arguments in procurement meetings. Mixing is allowed. Microsoft says so directly in the same document, and there is nothing clever or risky about running Business and Enterprise licenses side by side from a contracts point of view. The problem is not commercial at all. It shows up in the security stack, and it deserves its own section.

The upgrade that quietly downgrades your endpoint protection

Security engineer reviewing endpoint detection and response coverage on a dual monitor workstation after a Microsoft 365 license change

Business Premium includes Microsoft Defender for Business. Microsoft 365 E3 includes Microsoft Defender for Endpoint Plan 1. Those names imply a hierarchy, since Endpoint sounds larger and more serious than Business. They are not ordered that way.

Look at what each one actually includes. Defender for Business includes next generation protection, attack surface reduction, endpoint detection and response, and automated investigation and remediation. Defender for Endpoint Plan 1 includes next generation protection and attack surface reduction capabilities and manual response actions such as sending a file to quarantine. EDR is not on that list. Neither is automated investigation.

Prevention is the whole of Plan 1. If something gets past it, there is no device timeline to investigate with and nothing that acts on its own while your team is asleep.

CapabilityDefender for Business (in Business Premium)Defender for Endpoint Plan 1 (in Microsoft 365 E3)Defender for Endpoint Plan 2 (in Microsoft 365 E5)
Next generation antivirusYesYesYes
Attack surface reductionYes, preconfiguredYes, custom rules require IntuneYes
Endpoint detection and responseYesNoYes
Automated investigation and remediationYesNoYes
Threat hunting and 6 months of data retentionNoNoYes
Seat ceiling300 usersNoneNone

So the 320 person company that moves every seat from Business Premium to E3 has just taken EDR off every endpoint it owns, during a project the board signed off as a licensing consolidation. Nobody misled anybody. The invoice went up, the protection went down, and the change log says the migration completed successfully.

Why mixed licensing does not do what procurement expects

The obvious workaround is to hold 300 seats on Business Premium and put the overflow on E3 or E5. Commercially that is fine. Operationally it does not behave the way the spreadsheet suggests.

Microsoft’s position is a flat no. Defender for Business does not support mixed licensing. An organization running Defender for Business alongside Defender for Endpoint Plan 2 defaults every user to the Defender for Business experience, and Microsoft gives the specific example of 80 Business Premium users plus 30 Microsoft 365 E5 Security users, where all 110 land on Defender for Business.

The part that catches people out. Getting the Defender for Endpoint Plan 2 experience is not just a purchase. Microsoft requires every user in the tenant to be licensed for Plan 2 and then requires you to contact Microsoft Support to request the switch. Budget the support ticket and the lead time, not only the license.

Once you are past 300 users, Microsoft’s own guidance is to stop splitting and choose a subscription that includes Defender for Endpoint for all users, and to do it at renewal rather than mid term. That is sound advice, and it is also the point where the endpoint decision has to lead the licensing decision instead of following it.

What actually changes on the day you cross 300

Here is the practical list, in the order it tends to bite.

  • The endpoint stack changes hands. Defender for Business leaves with the Business Premium licenses, and whatever your Enterprise plan includes takes over the same devices.
  • Preconfigured security policies stop being preconfigured. Defender for Business ships with simplified configuration. On Defender for Endpoint you build the policies yourself, and custom attack surface reduction rules have to be authored in Intune.
  • Server licensing moves. Defender for Business servers is a $3 per server instance add-on tied to Business Premium, and above 60 servers it stops being an option at all.
  • Device allowances differ. Defender for Business covers up to 5 client devices per user license, which is generous and is not something Enterprise endpoint licensing assumes on your behalf.
  • Identity mostly survives. Entra ID P1 sits in both Business Premium and E3, so conditional access carries over. Risk based conditional access needs Entra ID P2, which arrives with E5 or the E5 Security add-on.
  • Web filtering is not like for like. Defender for Business supports 1 uniform web content filtering policy for the whole organization. If your rules were built around that single policy, they need rewriting rather than porting.
  • Changing the Defender experience needs a support request. No admin toggle switches the tenant to the Plan 2 experience. A Microsoft Support case does.

None of these are secret. All of them are documented. They are just scattered across 4 or 5 different Microsoft pages that nobody reads while a headcount problem is on fire.

Not sure how many Business family seats you have actually provisioned?

Provisioned licenses and employees are rarely the same number once you count contractors, shared mailboxes and service accounts. We will pull the report and tell you how much room is left.

Book a San Antonio tenant review

Two Microsoft dates San Antonio companies are walking into

Three IT professionals planning the sequence of a Microsoft 365 Business Premium to Enterprise migration in a meeting room

Exchange Web Services is being switched off

Support ends in stages. Microsoft starts disabling EWS globally in October 2026 and fully disables it in April 2027. This applies to Exchange Online only. Exchange Server on premises is untouched.

That hits mid-market harder than small business, because mid-market is where the line of business applications live. Document management that files email against a matter or a job number. A CRM connector that logs correspondence. An archiving or backup tool bought in 2019. A scanner that pushes into a shared mailbox through a service account nobody has looked at since. Any of those can be sitting on EWS, and plenty of vendors have not told their customers yet.

Microsoft’s Exchange team has published an allow list process that lets a tenant opt out of the automatic October change and keep named applications running into 2027. The window to configure it closes at the end of August 2026. Before you decide whether you need it, run the EWS usage report in the Microsoft 365 admin center and find out what is actually calling the API. Most companies are surprised by at least 1 entry on that report.

The July 2026 price increase has already landed

Microsoft announced the change in December 2025 and it took effect on July 1, 2026. Microsoft 365 E3 went from $36 to $39 per user per month and E5 went from $57 to $60, on an annual term billed monthly, per licensing analysts at SAMexpert.

Existing customers keep their current rate until the first renewal after that date. For a company planning a Business Premium to Enterprise move, that turns the renewal date into a real variable rather than an administrative detail. A 400 seat company timing the move badly can pay the increase a full term earlier than it needed to. Model the date before you pick the target SKU, not after.

The 90 day sequence we run before a company hits the wall

Order matters more than the individual steps here, because 2 of these decisions are expensive to reverse and the rest are not.

WhenWhat to doWhy it sits here in the order
90 days outPull the license report and count provisioned Business family seats, not employeesContractors, shared mailboxes and old service accounts move the real number, usually upward
75 days outDecide the endpoint stack before you decide the license familyThe endpoint answer changes which SKU is correct. Doing it second means buying twice
60 days outRun the EWS usage report and list every application that touches a mailboxVendor remediation takes months and none of that timeline is under your control
45 days outModel your renewal date against the July 2026 pricingRenewal timing can be worth more than any discount you negotiate on the SKU
30 days outRebuild security baselines in Intune and test them on a pilot ringThe preconfigured Defender for Business policies do not follow you across
CutoverMove in waves by department and verify device onboarding after each waveA silent onboarding failure looks exactly like a quiet week
30 days afterRe-verify that every device reports into the new portal and reconcile against the asset listThis is where the gaps actually surface, not during the migration itself

There is nothing exotic in that table. It is sequenced so the expensive decisions happen before the irreversible ones. Uprite has been doing this work in Texas for more than 25 years, we hold SOC 2 Type 1, and we stand behind projects with a 120 day satisfaction guarantee, which in practice means we would rather spend an hour on a license report than a weekend on a rollback. If you want the tenant side of the work written down first, our Microsoft 365 migration checklist covers the mechanics, and the 8 Microsoft 365 security settings most Texas companies miss is the shorter list worth fixing before you touch licensing at all.

An honest take on when E5 is the wrong answer

Finance leader working through Microsoft 365 E3 and E5 per user license costs with a calculator and renewal paperwork

E5 is the tidy answer. Defender for Endpoint Plan 2, Entra ID P2, Defender for Office 365 Plan 2, the Purview tooling, and the argument ends. At $60 per user per month it also close to doubles the license line for a company coming off Business Premium.

I will push back on my own advice here. We have recommended E5 to companies that did not need it, and the tell was the same every time. Nobody was going to operate it. Plan 2 EDR with no one watching the alerts produces roughly the same security outcome as Plan 1, with better reporting and a much larger invoice. Buying capability you will not staff is not a security decision, it is an accounting one.

For a lot of San Antonio companies in the 300 to 800 seat range, E3 plus the E5 Security add-on is the better shape. You pick up endpoint, identity and email coverage in 1 motion without paying for compliance tooling that will sit unconfigured. Buying Defender for Endpoint Plan 2 standalone alongside E3 also works and is sometimes cheaper. What does not work is E3 on its own with a hope that prevention holds, which is where a surprising number of companies land by accident. If you want the pricing conversation in isolation, the San Antonio IT buyers guide covers how the all in number tends to differ from the quoted per user rate.

Copilot is a separate line and a separate conversation. Microsoft 365 Copilot is not included in E3 or E5. Both qualify as a base subscription, and the Copilot license is assigned as an add-on on top. Microsoft has since introduced a higher tier, Microsoft 365 E7, which bundles E5 with Copilot and the Entra Suite. If a reseller told you that moving to E5 was how you get Copilot, that quote needs a second look, and our Microsoft Copilot deployment team can sanity check it before you sign.

One more thing worth saying plainly, since San Antonio raises it more than other Texas metros. Growing past 300 users has nothing to do with whether you belong in a government cloud. Those are 2 unrelated decisions that get merged in the same meeting more often than they should. If defense contracting is in scope, the cloud placement question is covered properly on our Microsoft 365 services in San Antonio page, and the certification side sits with CMMC compliance in San Antonio.

San Antonio Microsoft 365 questions we get asked most

Can we stay on Business Premium after we pass 300 employees?

Assume not. Microsoft reserves the right to enforce a 300 license tenant limit across the entire Business family, so treat 300 as a hard ceiling rather than a soft one. The cap counts provisioned licenses rather than headcount, which means contractors, shared mailboxes and licensed service accounts all consume it. Most companies discover the limit on the morning a new hire needs a mailbox, which is the worst possible moment to start reading licensing documentation.

Does moving from Business Premium to E3 reduce our security?

Yes, at the endpoint. Business Premium includes Defender for Business, which carries endpoint detection and response plus automated investigation and remediation. Microsoft 365 E3 includes Defender for Endpoint Plan 1, which carries neither of those. Almost everything else in the move is a step up, including larger mailboxes, unlimited archiving, litigation hold, eDiscovery, and the Windows Enterprise rights that come attached. The endpoint is the single place where the arrow points down, and it happens to be the place that decides how a Tuesday morning ransomware attempt actually ends.

Can we run Business Premium and E3 licenses in the same tenant?

Commercially yes, and Microsoft states it plainly, since Enterprise, Business and standalone plans can be combined within a single account. The security stack is where it falls apart, because Defender for Business does not support mixed licensing.

How much did Microsoft 365 pricing change in 2026?

Microsoft 365 E3 moved from $36 to $39 per user per month and E5 moved from $57 to $60, effective July 1, 2026, on an annual term with monthly billing. Existing customers hold their current rate until the first renewal after that date. That makes renewal timing part of the migration plan rather than a finance task to sort out afterwards.

What breaks when Exchange Web Services is retired?

Anything that reads or writes a mailbox over EWS stops working. In practice that means document management connectors, CRM email logging, older backup and archiving tools, and scan to email workflows built on service accounts. Microsoft begins disabling EWS in October 2026 and completes it in April 2027, and the allow list that defers the first date has to be configured by the end of August 2026.

Do we need GCC or GCC High if we do work with Joint Base San Antonio?

Usually not, and over buying it does real damage. Most San Antonio contractors meet their obligations in the commercial cloud with the right controls applied. Moving to GCC High means a brand new tenant, a full migration rather than a conversion, and the loss of features including PSTN calling and Viva Engage. It is a determination worth writing down before anybody quotes you a migration.

Where to start if 300 is close

Start with the license report, not the quote. Count what is provisioned, subtract what is genuinely dormant, and see how many months of hiring you actually have left. Then decide the endpoint question. Everything else on this page follows from those 2 answers, and both of them are cheaper to get right in a spreadsheet than in a migration window. If your internal team would rather run the project with help than hand it over, co-managed IT in San Antonio is usually the right shape for a company this size, and San Antonio IT support covers the day to day side once the dust settles.

Cross the 300 line on purpose, not by accident

We will pull your license report, map the endpoint stack you have today against the one your target SKU actually gives you, and hand you the list of applications still calling EWS. No obligation, and you keep the findings either way.

Talk to Uprite about your tenant

About Author

Learn More