Security operations analyst monitoring endpoint threat dashboards
Defender for Endpoint P1 vs P2

Defender for Endpoint. Plan 1 or Plan 2.

A buyer side guide to Microsoft Defender for Endpoint Plan 1 versus Plan 2 in 2026. The feature gap, who needs EDR, the E5 packaging, and how to license each.

Contact Us Microsoft Practice
500+Enterprise clients
$2B+Under advisory
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent

Defender for Endpoint Plan 1 delivers prevention while Plan 2 adds detection, response, and hunting, so the choice turns on whether your team can act on alerts, and most enterprises that justify the product at all need Plan 2.

Key takeaways

  • Plan 1 is prevention only: antivirus, attack surface reduction, web protection.
  • Plan 2 adds EDR, automated investigation, and threat hunting.
  • Plan 2 is included in Microsoft 365 E5 and E5 Security.
  • Plan 1 is available standalone or inside E3.
  • A team that acts on alerts needs Plan 2, not Plan 1.

This guide is for security and procurement leaders sizing Defender for Endpoint in 2026. Read it with the Defender suite guide and the Microsoft Practice page so the security design and the commercial design stay aligned.

What separates Plan 1 from Plan 2?

The split is prevention versus operations. Plan 1 stops known threats, while Plan 2 gives a security team the tools to detect, investigate, and respond.

What does Plan 1 cover?

Plan 1 is the prevention tier. It blocks and contains threats on the device but leaves the investigation and response work outside its scope.

  • Next generation antivirus: core malware prevention.
  • Attack surface reduction: rules that close common vectors.
  • Web and device control: protection and policy enforcement.

What does Plan 2 add?

Plan 2 adds the security operations layer. These are the capabilities a SOC uses every day to find and stop active threats.

  • Endpoint detection and response: the core EDR layer.
  • Automated investigation: auto triage and remediation.
  • Threat hunting: proactive search across endpoints.

How is each plan licensed and packaged?

Packaging decides the cheapest route. Plan 2 rides inside E5, so an E5 estate already owns it, while an E3 estate must add it.

Defender for Endpoint plans compared

Dimension Plan 1 Plan 2
Core functionPreventionPrevention plus EDR
Bundled inMicrosoft 365 E3E5 and E5 Security
Threat huntingNot includedIncluded
Best fitPrevention only needActive SOC or MDR

Where does E5 change the math?

An E5 seat already includes Plan 2. Buying a standalone Plan 2 license for an E5 user is a duplicate, so reconciling entitlements is the first cost check. Microsoft documents the Plan 1 and Plan 2 feature split in detail.

Per user or per device?

Both metrics exist. Per device can be cheaper for shared workstations, while per user fits a knowledge worker estate, so the device profile drives the metric choice.

How do you choose the right plan?

Anchor the choice on response capability. The tools only pay off if someone can use them, so the question is operational before it is commercial.

Can your team act on detections?

If a team investigates and responds, Plan 2 is required to give them EDR and hunting. If endpoints only need prevention, Plan 1 covers it, though that is rare in an enterprise.

  1. Check the SOC: can anyone act on EDR alerts.
  2. Check entitlements: does E5 already include Plan 2.
  3. Pick the metric: per user or per device by estate.

What to do next

  1. Confirm whether your team can act on detection and response alerts.
  2. Reconcile E5 entitlements before buying any standalone Plan 2 seat.
  3. Decide per user or per device by your endpoint profile.
  4. Right size Plan 1 versus Plan 2 by role rather than estate wide.
  5. Compare standalone Plan 2 against an E5 Security step up.
  6. Take the reconciled position into your next EA renewal.

Frequently asked questions

What is the difference between Defender for Endpoint Plan 1 and Plan 2?

Plan 1 covers core endpoint protection such as next generation antivirus, attack surface reduction, and manual response actions. Plan 2 adds endpoint detection and response, automated investigation, threat and vulnerability management, and threat hunting. Plan 2 is the full security operations tier.

Is Defender for Endpoint Plan 2 included in Microsoft 365 E5?

Yes. Defender for Endpoint Plan 2 is included in Microsoft 365 E5 and in the E5 Security add on. Customers on E3 can step up to E5 Security or buy Plan 2 standalone to get the full endpoint capability.

What is included in Defender for Endpoint Plan 1?

Plan 1 includes next generation antivirus, attack surface reduction rules, device control, web protection, and manual response actions on a device. It does not include EDR, automated investigation, or threat hunting, which are Plan 2 features.

Do you need Defender for Endpoint Plan 2?

If you have a security team that acts on alerts, yes. Plan 1 leaves the detection and response gap open, so any organization running a SOC or managed detection service needs the EDR and hunting capabilities in Plan 2.

How is Defender for Endpoint licensed?

Both plans are licensed per user or per device. Plan 1 is available standalone or in Microsoft 365 E3, while Plan 2 comes in E5, E5 Security, or as a standalone per user license. The metric matters for shared device estates.

How do buyers choose between Plan 1 and Plan 2?

Match the plan to whether you can act on detections. If a team investigates and responds, Plan 2 is required. If endpoints only need prevention with no response capability, Plan 1 covers it at lower cost, though most enterprises need Plan 2.

Microsoft EA Renewal Playbook

The full microsoft ea renewal playbook framework from the Microsoft Practice.

Microsoft renewal moves, the EA framework, the M365 SKU framework, the Copilot framework, and the buyer side moves across the full Microsoft estate.

Used across more than five hundred enterprise engagements. Independent. Buyer side. Built for procurement leaders running the next renewal cycle.

No spam. We will only email you about this download. Privacy.
Run the Microsoft 365 license optimizer against your estate in under five minutes.
Open the Tool →
Plan 1
Prevention
Plan 2
EDR and hunting
In E5
Plan 2 bundled
100%
Buyer Side

Buyers who already hold E5 sometimes buy Plan 2 standalone as well. The capability is in the E5 seat, so the standalone line is a duplicate nobody reconciled.

Morten Andersen
Co Founder. Ex IBM, ex Oracle.
Deep Library

More on this topic.

Microsoft Practice →
Laptop showing an endpoint security console
Microsoft
Defender Endpoint P1 vs P2 Licensing
The licensing detail behind the two endpoint plans.
12 min read
Security operations analyst monitoring dashboards
Microsoft
Microsoft Defender Suite 2026
How the Defender products are packaged and licensed in 2026.
14 min read
Analyst comparing licensing options at a desk
Microsoft
Is E5 Security Worth It
Whether the E5 Security add on pays for itself against standalone SKUs.
11 min read
Network security visualization on screens
Microsoft
Microsoft Security Licensing
A buyer side map of the full Microsoft security licensing stack.
15 min read
Modern corporate office building exterior
Microsoft
Microsoft Advisory Practice
How our buyer side Microsoft practice supports your negotiation.
8 min read
Editorial boardroom interior

The advisor your vendors do not want.

500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.

Microsoft brief. Once a week.

One short note on Microsoft security and endpoint licensing, Defender packaging, EA renewals, and the buyer side moves we are running in client engagements.