Analyst working across several data screens
Microsoft Defender for Endpoint

Defender for Endpoint P1 vs P2 in 2026. Which users need Plan 2, and what it costs.

What each plan covers, the three routes to Plan 2 and their prices, how to size Plan 2 to your SOC, and the compliance gap Microsoft finds at renewal.

Contact Us Microsoft Advisory
500+Enterprise clients
$2B+Under advisory
PublishedMarch 24, 2026UpdatedSeptember 24, 2026
ContentsKey takeawaysP1 vs P2 capabilitiesRoutes to Plan 2 and pricesWhat a P1 and P2 mix savesWho needs Plan 2The under licensing gapWhat we have seenAnswering the account teamCrowdStrike and SentinelOneWhat to do nextFAQ

Plan 1 is the prevention baseline Microsoft 365 E3 already pays for. Plan 2 is full EDR, usually bought through the E5 Security add on or E5. The licensing question is which users need Plan 2, because the answer prices three different ways.

Key takeaways
  • Plan 1 prevents, Plan 2 investigates. Plan 1 covers antivirus, attack surface reduction, device control and web protection; Plan 2 adds EDR, advanced hunting, vulnerability management and automated investigation.
  • Standalone gap is $2.20. Plan 1 lists at $3 and Plan 2 at $5.20 per user per month, which caps the saving from moving a user down at about 42 percent.
  • The add on is the real negotiation. The E5 Security add on, now sold as Microsoft Defender Suite, lists at $12 on E3 and has the widest gap between list and negotiated price.
  • Security alone does not justify E5. E5 rose from $57 to $60 on July 1, 2026, and the extra over E3 plus the add on buys compliance, voice and analytics you may not deploy.
  • Size Plan 2 to the SOC. A persona mix of Plan 2 where analysts work and Plan 1 elsewhere is supported by Microsoft's own mixed licensing settings.
  • Servers need their own plan. User licenses cover client devices only, so server EDR belongs under Defender for Servers in Defender for Cloud.
  • Build the inventory before Microsoft does. A named list of who uses Plan 2 features closes the under licensing gap and sizes the mix in one exercise.

What is the difference between Defender for Endpoint P1 and P2?

Plan 1 prevents attacks on the device. Plan 2 adds the tools a security operations center needs to detect, investigate and respond once something gets through. Plan 1 is included in Microsoft 365 E3, while Plan 2 comes with Microsoft 365 E5, the E5 Security add on and Windows Enterprise E5.

Plan 1 is a full prevention stack. It covers Microsoft Defender Antivirus with cloud delivered protection, attack surface reduction rules for Office macros and scripts, device control down to USB blocking, application control, SmartScreen web protection, network protection against malicious destinations, the endpoint firewall, and the Defender portal with basic reporting.

Defender for Endpoint Plan 1 and Plan 2 capabilities
CapabilityPlan 1Plan 2
Next generation antivirus, cloud deliveredIncludedIncluded
Attack surface reduction rulesIncludedIncluded
Device control and web protectionIncludedIncluded
Endpoint detection and response, live response, six month retentionNot includedIncluded
Advanced hunting, KQL across the endpoint datasetNot includedIncluded
Threat and vulnerability management dashboard (now the core of Defender Vulnerability Management)Not includedIncluded
Automated investigation and responseNot includedIncluded
Defender Vulnerability Management add on, $2 per user per monthNot availableAvailable on a Plan 2 base
Defender Experts managed hunting eligibilityNot includedPlan 2 base required

For a workforce whose threat model is commodity malware and phishing payloads, the Plan 1 rows do the job. If you run Microsoft 365 E3, you already pay for them.

What Plan 2 gives a security operations team

Plan 2 is what a SOC consumes. It supplies the EDR evidence trail, the hunting surface, the vulnerability dashboard, and the automation that closes routine alerts without analyst time. It also adds threat analytics and sandbox deep analysis of suspicious files.

Defender Experts, Microsoft's managed hunting service, is a separate SKU with its own price, and it requires the Plan 2 base. If you plan to outsource hunting to Microsoft later, the Plan 2 decision comes first.

Why Plan 2 is not simply the better tier

The two plans divide the work between protecting a device and investigating it. A device that no analyst will ever open in the portal gets the same prevention from Plan 1 as from Plan 2. Automated investigation is the one Plan 2 feature that acts without an analyst, and on low risk devices a reimage usually does the same job.

A user whose alerts no one will ever investigate gets nothing from Plan 2 except the invoice.
Watch the briefingResearch briefing · 4:06

Microsoft EA: Where the Leverage Really Is, and the Mistakes That Give It Away

Which Microsoft 365 plans include Defender P2, and what does each route cost?

You can reach Plan 2 three ways: the standalone license, the E5 Security add on on top of E3, or full Microsoft 365 E5. Plan 2 rarely sells standalone in large organizations, and the route you choose sets the price far more than the list rate of Plan 2 itself.

The three routes to Defender for Endpoint Plan 2
RouteList priceWhat you actually payWhen it wins
Standalone Plan 2$5.20 per user per monthClose to list, thin discountingOrganizations outside Microsoft 365 and mixed vendor stacks
E5 Security add on (Microsoft Defender Suite), on E3$12 per user per month$8 to $10 median negotiated, $6 to $8 top quartileE3 customers that want the security suite without full E5
Full Microsoft 365 E5$57, raised to $60 on July 1, 2026Discounted off the E5 rate, but you buy the whole suiteOnly when compliance, voice and analytics workloads justify the rest of E5

Standalone, Plan 1 lists at $3 and Plan 2 at $5.20 per user per month. The EDR delta is $2.20 before any bundling. Windows 10 and Windows 11 Enterprise E5 also include Plan 2, which matters if your Windows licensing sits on a separate agreement.

What the E5 Security add on carries besides Defender for Endpoint

Microsoft now markets the add on as Microsoft Defender Suite. It still lists at $12 per user per month, paid yearly, and requires Microsoft 365 E3, or Office 365 E3 together with Enterprise Mobility and Security E3.

  • Defender for Endpoint Plan 2. The endpoint EDR this page is about.
  • Entra ID P2. Risk based conditional access, identity protection and privileged identity management.
  • Defender for Office 365 Plan 2. Email and collaboration threat hunting and attack simulation.
  • Defender for Cloud Apps. Discovery and control of SaaS usage.
  • Defender for Identity. Detection of attacks against on premises Active Directory.

That bundle makes the add on the real negotiation, and it behaves like one. The spread between $12 list and the top quartile rate is wider than most whole product discounts Microsoft gives.

How the add on compares with full E5 after the July 2026 increase

At list, Microsoft 365 E3 now costs $39 per user per month, so E3 plus the add on comes to $51 against $60 for E5. The account team will present that $9 gap as a small step up. It buys the E5 compliance, voice and analytics workloads, which is only good value if you will deploy them.

Refuse any attempt to turn an E5 Security need into an E5 upgrade. The E3 versus E5 decision should be made on the full suite, never on security alone.

Lock the add on price for the full EA term

Microsoft's default position is that the E5 Security add on reprices at each anniversary. A price hold on the add on, written into the enrollment, is a standard ask that most buyers never make.

That hold is worth more than an extra point of discount, because it protects you from the next list increase as well as the current one.

Free white paper

Defender for Endpoint licensing guide

The persona worksheet, Plan 2 route pricing, server rules and compliance checklist in one download.

Get the white paper →

How much does a Plan 1 and Plan 2 mix save?

In our benchmarks, a mix sized to user personas cut the Defender line 20 to 30 percent against flat Plan 2 coverage, with no loss of security coverage. The saving depends on how many users can move to Plan 1, and the standalone prices set a hard ceiling on it.

A worked example at standalone list prices

Say you license 6,000 users on standalone Defender for Endpoint and your SOC actively investigates 2,000 of them. The table compares flat Plan 2 with a split at the list prices above.

Hypothetical 6,000 user organization, standalone list prices
ScenarioPlan 2 usersPlan 1 usersMonthly costAnnual cost
Flat Plan 26,000 at $5.200$31,200$374,400
Persona mix2,000 at $5.204,000 at $3$22,400$268,800
Difference$8,800$105,600, about 28 percent

Moving every user to Plan 1 would cut the standalone Defender bill by about 42 percent, which is the ceiling. Each user you move saves the same amount each month, so the result tracks the share of users whose devices your SOC does not work.

How the calculation changes on an E3 base

On Microsoft 365 E3, Plan 1 is already paid for, so the question becomes which users get the add on. Removing the add on from a user also removes Entra ID P2, Defender for Office 365 Plan 2, Defender for Cloud Apps and Defender for Identity for that user.

Before you size the add on to the SOC's populations, check which of those four products each group needs. A group that needs Entra ID P2 for risk based access policies may still be cheaper on the add on than on separate licenses.

Which users need Defender for Endpoint Plan 2?

Plan 2 belongs on users whose devices an analyst will hunt across, or whose alerts someone will investigate beyond the automated verdict. Make that call population by population, with the SOC in the room.

  • Plan 2 populations. Privileged accounts and admins, developers and build infrastructure users, executives and their staff, high risk roles handling money or sensitive data, and every device the SOC's detection engineering actually covers.
  • Plan 1 populations. Frontline and task workers on managed devices, kiosk and shared device users, and groups whose incident path is reimage rather than investigate. These users usually sit on E3 or F3 already.
  • Servers. Licensed separately, per server, and covered in the next section.

The same persona worksheet drives the neighboring decisions. Intune Plan 1 versus Plan 2 follows the identical logic on the management side, and the Microsoft 365 licensing pillar places both inside the full suite architecture.

How Defender for Endpoint licensing works for servers

Server endpoint protection is licensed through Defender for Servers under Microsoft Defender for Cloud, per server, outside the user SKUs. A user license covers up to five concurrent client devices, but it does not cover Windows Server or Linux server operating systems.

Defender for Servers comes in two plans, summarized below. Microsoft recommends onboarding on premises servers through Azure Arc so they receive the full feature set.

Defender for Servers plans
PlanWhat it addsFits
Defender for Servers Plan 1Defender for Endpoint EDR on the serverServers that need the same EDR as your Plan 2 clients
Defender for Servers Plan 2Plan 1 plus agentless scanning, file integrity monitoring, premium vulnerability management, just in time machine accessServers that also need integrity monitoring, vulnerability assessment and access controls

Server EDR switched on with no server plan behind it is the same compliance gap as the desktop one, with a bigger invoice attached. Check it before you check anything else on the server side.

Why we would not put Plan 2 on every user

The usual advice from resellers and account teams is to standardize on Plan 2, or on E5, for everyone, because a single tier is simpler to run and gives the SOC full signal. We disagree, because the Plan 2 premium buys investigation tools, and a device the SOC does not investigate gets no return from them.

Flat coverage pays the premium on thousands of devices that no analyst will open. The better course is Plan 2 on the populations your detection engineering covers, Plan 1 everywhere else, with the split reviewed each year against the SOC's own coverage list.

Rack mounted server hardware with green status lights
User licenses stop at the client device. Every server operating system environment, physical or virtual, needs its own Defender for Servers coverage.

Can Microsoft see Plan 2 features used on Plan 1 licenses?

Yes. By default, advanced hunting, the vulnerability dashboard and automated investigation run across the tenant, and they do not check per user licensing before they run. Consumption is visible to Microsoft, and its audit and true up process treats Plan 2 use by Plan 1 users as under licensing.

The finding usually lands at the worst moment, inside an EA renewal. There it becomes pressure toward the E5 conversation you were trying to avoid. The EA guide covers where such a finding lands in the agreement mechanics.

How to check your own position before Microsoft does

The defense is a named user inventory of who consumes Plan 2 features, reconciled against entitlements. These are the places to build it from.

  1. The license usage report. In the Defender portal, go to Settings, Endpoints, Licenses. It shows available and assigned licenses, calculated from the users detected on onboarded devices, and can lag active usage by up to one day.
  2. Mixed licensing settings. On the same page, Manage subscription settings is where you run Plan 1 and Plan 2 in one tenant. Devices tagged License MDE P1, manually or by dynamic rule, get Plan 1 capability, and new tags apply within about 3 hours.
  3. Assigned licenses. The Microsoft 365 admin center, under Billing and Licenses, shows which users hold E3, E5, the add on or standalone plans.
  4. Device inventory. The DeviceInfo table in advanced hunting lists onboarded devices by operating system, which separates servers from clients.
  5. Analyst activity. The History tab of the Action center lists response and remediation actions by device, such as isolation, antivirus scans and quarantined files, so you can see which devices analysts have actually worked in the past 90 days.

Mixed licensing settings apply to client devices only. Windows Server and Linux servers still need Defender for Servers, whatever tags you set.

The list most organizations cannot produce

Not one of the 35 to 45 security environments we benchmarked could produce that named user list on day one. Every misalignment we found, paid but unused Plan 2 and used but unpaid Plan 2, followed from the missing inventory.

Building it takes days. Once you have it, the renewal becomes a pricing discussion rather than a defensive one.

What have we seen in recent Defender for Endpoint negotiations?

Most organizations we review overpay in one direction and under license in the other, usually at the same time. The patterns below come from the security environments we benchmarked.

  • Plan 2 in use without Plan 2 licenses. At first review, 55 to 65 percent were running Plan 2 features on users licensed only for Plan 1. That is an unpriced compliance gap waiting for an audit.
  • Flat coverage at the same time. Alongside that gap, flat Plan 2 coverage often paid the EDR premium for thousands of users whose devices no analyst would ever hunt across.
  • Servers left out. In 1 environment out of 3, server EDR was running with no Defender for Servers plan behind it.

What the persona mix did to the bill

Where clients moved to a persona aligned mix, the Defender line fell by the amounts shown in the savings section, and security coverage stayed where it was. The inventory work that found the compliance gap was the same work that sized the mix, so one exercise fixed both problems.

What will the Microsoft account team say, and how should you answer?

Expect the conversation to move toward E5 and toward full coverage. These are the lines we hear most often, with the replies that hold up.

  • "E5 is only $9 more than E3 plus the Defender Suite, so move everyone up." Ask for E5 priced against the compliance, voice and analytics workloads you will deploy in the term. If those workloads are not planned, ask for the add on quote on its own line.
  • "The add on reprices at each anniversary." Reply that you will sign only with a price hold written into the enrollment for the full term.
  • "Plan 2 features are on across your tenant, so every user needs Plan 2." Point to Microsoft's own mixed licensing settings and the License MDE P1 tag, and show your reconciled inventory.
  • "The discount depends on committing the whole organization to the suite." Commit the populations you have sized, and ask for the right to add users at the same unit price during the term.

Contract wording to ask for

  1. A price hold on the add on for the EA term. Without it, the anniversary repricing erodes the discount you negotiated.
  2. Additions at the signed unit price. Growth in the Plan 2 population should not reopen the price.
  3. A reduction right at anniversary for the add on. If the SOC's coverage shrinks, the license count should be able to follow.
  4. Written acceptance of mixed licensing. A clause or letter confirming that devices tagged for Plan 1 under Microsoft's documented settings are licensed correctly.
  5. A clear server definition. Confirmation that servers are covered by Defender for Servers billing and are never counted against user licenses.

How do CrowdStrike and SentinelOne change the Defender negotiation?

A credible alternative in the file changes the price even if you stay with Microsoft. Defender for Endpoint competes with CrowdStrike Falcon and SentinelOne, and the E5 Security discount, the add on price hold and the Defender Experts rate all respond when Microsoft believes you might switch.

The CrowdStrike versus SentinelOne versus Defender comparison covers the capability and pricing detail. Our commercial reading comes down to two points.

  • Where Defender is hard to beat. When Plan 2 rides inside an add on you were negotiating anyway.
  • Where it is weakest. Standalone, against per endpoint EDR pricing.

That is why Microsoft prices the routes the way it does. It is also why most of the recoverable money sits in the persona mix and the add on price.

What to do next

  1. Build the named user list of actual Plan 2 consumption. Record who has opened advanced hunting, the vulnerability dashboard or live response in the past 90 days. This list settles both the overspend and the compliance gap.
  2. Define the personas and assign plans per population. Plan 2 where the SOC works, Plan 1 where prevention is the job, then configure mixed licensing tags to match.
  3. License servers as servers. Move server EDR onto Defender for Servers under Defender for Cloud and out of the user SKU count.
  4. Negotiate the E5 Security add on as its own line. Treat $12 list as an opening number, ask for a price hold for the term, and aim for the top quartile rate.
  5. Refuse the E5 reframe until the whole suite pays for itself. Security alone never justifies full E5. Run the Microsoft 365 license optimizer against your tenant first.
  6. Bring in help before the renewal clock starts. The Microsoft practice can review the inventory, the quote and the contract wording for the renewal itself.
When to bring in help

Want a second opinion on your Microsoft licensing? Our Microsoft licensing consultants work only for buyers, with no reseller margin.

Frequently asked questions

What is the difference between Defender for Endpoint Plan 1 and Plan 2?

Plan 1 protects the device; Plan 2 equips a SOC to investigate it. Plan 1 blocks threats with antivirus, attack surface reduction, device control and web protection. Plan 2 adds EDR with live response and six month retention, advanced hunting in KQL, threat and vulnerability management, automated investigation, and eligibility for Defender Experts.

Is Defender for Endpoint included in Microsoft 365 E3 or E5?

E3 includes Plan 1, and E5 includes Plan 2. E3 customers can also get Plan 2 through the E5 Security add on without moving to E5. Most enterprises reach Plan 2 through one of those bundles, since the standalone Plan 2 license sees little discounting.

What does the E5 Security add on cost in 2026?

It lists at $12 per user per month on an E3 base and includes Defender for Endpoint Plan 2, Entra ID P2, Defender for Office 365 Plan 2, Defender for Cloud Apps and Defender for Identity. Median negotiated rates run $8 to $10, top quartile buyers sign $6 to $8, and you should ask to lock the price for the full EA term.

Do all users need Plan 2?

No, and flat Plan 2 coverage is the most common overspend we see. Privileged users, developers, executives and high risk roles justify it because a SOC investigates their devices. Frontline, kiosk and shared device users rarely do, and in our benchmarks the persona mix cut the Defender line 20 to 30 percent.

How are servers licensed for Defender for Endpoint?

Servers need Defender for Servers, bought through Microsoft Defender for Cloud and counted per server. A user license covers up to five client devices and no server operating systems. Server EDR switched on without a server plan is a common true up finding, and we saw it in roughly 1 environment in 3.

Can Microsoft detect Plan 2 features used on Plan 1 licenses?

Yes. Features such as advanced hunting and the vulnerability dashboard work at tenant level, so Microsoft can see the consumption, and 55 to 65 percent of the organizations we benchmarked had this gap at first review. It tends to surface during renewal. A named user reconciliation closes it on your own terms.

Can I run Defender for Endpoint P1 and P2 in the same tenant?

Yes. Microsoft supports mixed licensing through Settings, Endpoints, Licenses in the Defender portal. Devices tagged License MDE P1 receive Plan 1 capability and the rest receive Plan 2, so your technical configuration can match what you have bought. The setting applies to client devices only, not servers.

Newsletter
Licensing news that changes what you pay

One email a week on vendor price moves, audit activity and what worked in recent renewals.

Subscribe
Vendor Shield
An advisor on call for every vendor conversation

Always on advisory for renewals, audits and contract questions across your software vendors.

Explore Vendor Shield
Advisory White Paper

Get the Defender for Endpoint licensing guide.

The persona worksheet, route pricing for Plan 2, the server rules and a compliance checklist, built for the CISO and procurement to use together.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
We never share your details with vendors.

Read next

The rest of the E5 security add on

What the 12 dollar add on carries beyond Defender, and which parts you already pay for.

E3, E5, and F3 compared

The plan mix decides more of the bill than the security line does.

The Software Assurance premium

Estates exercised 2 to 4 benefits of the dozen they paid 25 to 29 percent a year for.

Microsoft licensing news, once a week.

Price changes, audit activity and what worked in recent renewals. No vendor spin.