HomeMicrosoft HubDefender for Endpoint P1 vs P2
Microsoft  |  Security Licensing Buyer Guide 2026

Defender for Endpoint P1 vs P2, the real gap

Plan 1 is the antivirus baseline your E3 estate already pays for. Plan 2 is the full EDR product Microsoft would rather sell you through E5. The licensing question is not which plan is better, it is which users need the difference, because the answer prices three different ways.

Prepared by Redress Compliance · August 6, 2026 · Microsoft security licensing advisory. Based on 35 to 45 security estate benchmarks 2024 to 2026.

Executive summary

The plans split cleanly. Plan 1 is prevention: next generation antivirus, attack surface reduction, device control, and web protection, and it is already included in Microsoft 365 E3. Plan 2 is detection and response: full EDR with live response and six month retention, advanced hunting in KQL.

Threat and vulnerability management, and automated investigation, included in Microsoft 365 E5 and the E5 Security add on.

The money question is the route to Plan 2, because the same capability prices three ways: standalone at $5.20 per user per month against Plan 1 at $3, the E5 Security add on at $12 list on an E3 base, where negotiated rates run $8 to $10 at median and $6 to $8 at top quartile.

Or full Microsoft 365 E5, which rises from $57 to $60 per user per month on July 1, 2026 and carries far more than security.

The estates overpay in one direction and under license in the other, usually at the same time.

Across the security estates we benchmarked, 55 to 65 percent were running Plan 2 features on users licensed for Plan 1 at first review.

An audit finding waiting to be monetized, while flat Plan 2 coverage across the whole estate paid the EDR premium for thousands of users whose devices no analyst will ever hunt across.

The defensible position is a persona mix: Plan 2 where the SOC actually works, Plan 1 where prevention is the job, servers licensed through Defender for Servers rather than user SKUs.

In our benchmarks the persona aligned mix cut the Defender line 20 to 30 percent against a flat Plan 2 estate, with no change in security posture.

$3 vs $5.20
Plan 1 versus Plan 2 standalone list, per user per month. The EDR delta is $2.20 before bundling.
$12 to $8
E5 Security add on: list versus the median negotiated rate on an E3 base. Top quartile signs $6 to $8.
55 to 65%
Estates running Plan 2 features on Plan 1 licensed users at first review, an unpriced compliance gap.
20 to 30%
Defender line reduction from a persona aligned P1 and P2 mix versus flat Plan 2 coverage.
1.

What each plan actually covers

Plan 1 is the prevention stack: Microsoft Defender Antivirus with cloud delivered protection, attack surface reduction rules across Office macros and scripts, device control down to USB blocking and application control, SmartScreen web protection, network protection against malicious destinations.

And the Defender portal with basic reporting.

For a workforce whose threat model is commodity malware and phishing payloads, this is the job, and E3 estates already pay for it.

CapabilityPlan 1Plan 2
Next generation antivirus, cloud deliveredIncludedIncluded
Attack surface reduction rulesIncludedIncluded
Device control and web protectionIncludedIncluded
Endpoint detection and response, live response, six month retentionNot includedIncluded
Advanced hunting, KQL across the endpoint datasetNot includedIncluded
Threat and vulnerability management dashboardNot includedIncluded
Automated investigation and responseNot includedIncluded
Defender Experts managed hunting eligibilityNot includedPlan 2 base required

Plan 2 is what a SOC consumes: the EDR evidence trail, the hunting surface, the vulnerability dashboard, and the automation that closes routine alerts without analyst time. Defender Experts, Microsoft's managed hunting service, is a separate SKU that requires the Plan 2 base.

The plans are a capability split, not a good better tier: a user whose alerts nobody will ever investigate gets nothing from Plan 2 except the invoice.

2.

The three routes to Plan 2, and what each really costs

Plan 2 rarely sells standalone. Most enterprises reach it through a bundle, and the route decides the price:

RouteList priceWhat you actually payWhen it wins
Standalone Plan 2$5.20 per user per monthClose to list, thin discountingNon Microsoft 365 estates and mixed vendor stacks
E5 Security add on, on E3$12 per user per month$8 to $10 median negotiated, $6 to $8 top quartileE3 estates that want the security suite without full E5
Full Microsoft 365 E5$57, rising to $60 on July 1, 2026Discounted off the E5 rate, but you buy the whole suiteOnly when compliance, voice, and analytics workloads justify the rest of E5

The add on carries four other products alongside Defender for Endpoint Plan 2: Entra ID P2, Defender for Office 365 Plan 2, Defender for Cloud Apps, and Defender for Identity.

That makes the E5 Security conversation the real negotiation, and it behaves like one: the gap between $12 list and the $6 to $8 top quartile is wider than most whole product discounts.

The trap to refuse is the account team reframing an E5 Security need as an E5 upgrade, because the E3 versus E5 decision should be made on the full suite, never on security alone.

Lock the add on price for the full EA term. Microsoft's default position is that the E5 Security add on reprices at each anniversary.

A price hold on the add on, written into the enrollment, is a standard ask that most buyers never make, and it is worth more than an extra point of discount, especially across the July 2026 list increase.

Free white paper

The Defender for Endpoint licensing playbook

The persona model worksheet, the three route price math, the server licensing rules, and the compliance gap checklist from 35 plus security estate benchmarks.

Get the white paper →
3.

The persona mix, sizing Plan 2 to the SOC

The unit of decision is the user persona, not the company. A defensible mix comes from one question asked honestly per population: will an analyst ever hunt across this device's telemetry, or investigate its alerts beyond the automated verdict?

In our benchmarks the persona aligned mix cut the Defender line 20 to 30 percent against flat Plan 2 coverage.

The same persona worksheet drives the neighboring decisions: Intune Plan 1 versus Plan 2 follows the identical logic on the management side, and the Microsoft 365 licensing pillar places both inside the full suite architecture.

Try Vera AI · free 30 day trial
See the percentile your E5 Security rate sits at before you renew.
  • Percentile standing for your exact deal size and industry, from real closed transactions
  • Scenario simulation before the call: test alternative terms and see the financial impact of each
  • A negotiation playbook, talking points, and a two page executive brief on day one
Start the free Vera AI trial →30 days free · no credit card · cancel anytime
4.

The compliance gap running the other way

The overspend has a mirror image. Plan 2 features are tenant wide switches in places: advanced hunting, the vulnerability dashboard, and automated investigation do not check per user licensing before they run.

Across the estates we benchmarked, 55 to 65 percent were consuming Plan 2 capabilities on users licensed only for Plan 1 at first review.

Microsoft's audit and true up machinery treats that as under licensing, and the finding usually lands at the worst moment: inside an EA renewal, where it becomes leverage for the E5 conversation you were trying to avoid.

The defense is the same list the persona mix needs anyway: a named user inventory of who consumes Plan 2 features, reconciled against entitlements, before Microsoft builds it for you.

Not one of the 35 to 45 estates we benchmarked could produce that list on day one. Every misalignment in both directions, paid but unused Plan 2 and used but unpaid Plan 2, follows from that missing inventory.

Building it takes days, and it converts the renewal from a defensive conversation into a pricing one. The EA guide covers where the finding lands in the agreement mechanics.

5.

The competitive frame, and why it matters even if you stay

Defender for Endpoint competes with CrowdStrike Falcon and SentinelOne, and the comparison matters commercially even for committed Microsoft estates: the E5 Security discount, the add on price hold, and the Defender Experts rate all move when a credible alternative sits in the file.

The CrowdStrike versus SentinelOne versus Defender comparison covers the capability and pricing detail.

The honest buyer side reading: Defender's economics are hard to beat when Plan 2 rides inside an add on you were negotiating anyway, and weakest standalone against per endpoint EDR pricing.

Which is precisely why Microsoft prices the routes the way it does, and why the persona mix, not the vendor choice, is where most of the recoverable money sits.

6.

Your first five moves

  1. Build the named user list of actual Plan 2 consumption. Who has opened advanced hunting, the vulnerability dashboard, or live response in ninety days. This list settles both the overspend and the compliance gap.
  2. Define the personas and assign plans per population, not per company. Plan 2 where the SOC works, Plan 1 where prevention is the job.
  3. License servers as servers. Move server EDR onto Defender for Servers under Defender for Cloud and out of the user SKU math.
  4. Negotiate the E5 Security add on as its own line with a price hold for the term. $12 list is a starting position; the market clears at $8 to $10 and top quartile buyers sign $6 to $8.
  5. Refuse the E5 reframe until the suite math works. Security alone never justifies full E5. Run the Microsoft 365 license optimizer against the estate, and bring the Microsoft practice in for the renewal itself.
7.

Frequently asked questions

What is the difference between Defender for Endpoint Plan 1 and Plan 2?

Plan 1 is prevention: next generation antivirus, attack surface reduction, device control, and web protection.

Plan 2 adds detection and response: full EDR with live response and six month retention, advanced hunting in KQL, threat and vulnerability management, automated investigation, and eligibility for Defender Experts. Plan 1 protects the device; Plan 2 equips a SOC to investigate it.

Is Defender for Endpoint included in Microsoft 365 E3 or E5?

Plan 1 is included in Microsoft 365 E3. Plan 2 is included in Microsoft 365 E5 and in the E5 Security add on for E3. Standalone, Plan 1 lists at $3 and Plan 2 at $5.20 per user per month. Most enterprises reach Plan 2 through E5 or the add on rather than standalone.

What does the E5 Security add on cost in 2026?

List is $12 per user per month on an E3 base, covering Defender for Endpoint Plan 2 plus Entra ID P2, Defender for Office 365 Plan 2, Defender for Cloud Apps, and Defender for Identity.

Negotiated rates run $8 to $10 at median and $6 to $8 at top quartile, and the add on price can and should be locked for the full EA term.

Do all users need Plan 2?

No, and flat Plan 2 coverage is the most common overspend. Plan 2 belongs on populations a SOC actually investigates: privileged users, developers, executives, and high risk roles. Prevention only populations do the job on Plan 1.

In our benchmarks the persona aligned mix cut the Defender line 20 to 30 percent with no posture change.

How are servers licensed for Defender for Endpoint?

Through Defender for Servers under Microsoft Defender for Cloud, priced per server, not through user SKUs. User licenses cover up to five client devices each but do not cover server operating systems.

In roughly 1 estate in 3 we found server EDR enabled without a server plan behind it, which is an audit finding at true up.

Can Microsoft detect Plan 2 features used on Plan 1 licenses?

Yes. Plan 2 capabilities like advanced hunting and the vulnerability dashboard are tenant level, and consumption is visible to Microsoft.

Fifty five to 65 percent of the estates we benchmarked ran Plan 2 features on Plan 1 users at first review, and the finding typically surfaces as renewal leverage. A named user reconciliation closes the gap on your terms.

© 2026 Redress Compliance · Independent, buyer sideredresscompliance.com
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent
Microsoft Security Licensing White Paper

The full Defender for Endpoint licensing playbook from the Microsoft practice.

The persona worksheet, the three route price math, the server rules, and the compliance checklist from 35 plus security estate benchmarks. Built for CISO and procurement together.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
Independent, buyer side. We never share your details with vendors.
Rightsize E3, E5, and the security add ons with the Microsoft 365 license optimizer.
Open the Tool → Microsoft Advisory →
Editorial boardroom interior

The advisor your vendors do not want.

500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.

Stay ahead of Microsoft pricing and contract moves.

One buyer side briefing a week. Renewal signals, discount bands, and the levers that work. No vendor spin.