Contents
Key takeawaysWhat E5 Security includesCalculating the break evenWhat we have seenOverlap with tools you ownCheaper pathsAccount team lines and repliesTiming and contract termsWhat to do nextFAQE5 Security is worth the upgrade when you would otherwise buy three or more of its components standalone. Below that count, targeted standalone licenses usually cost less, so the decision is a pricing exercise more than a feature debate.
- An add on, not a seat. E5 Security, now sold as the Microsoft Defender Suite at $12 per user per month, sits on top of E3 and does not replace it.
- What it bundles. Defender for Endpoint and Defender for Office 365 Plan 2, Entra ID P2, Defender for Cloud Apps and Defender for Identity.
- The break even. The add on pays off when you would buy three or more of those tools separately, weighted by how many users each one covers.
- Watch for double spend. In 20 to 35 percent of the cases we reviewed, the customer already paid for Defender for Endpoint or Entra ID P2 on its own.
- Leave frontline out. Frontline and light users rarely need P2 conditional access and risk policies.
- Secure Score needs work. The score improves only when the features are turned on and tuned.
- Decide at renewal. Price the add on against your actual standalone stack before you commit in the next agreement.
This guide is for security and procurement leaders deciding whether to add Microsoft E5 Security on top of Microsoft 365 E3. It covers what the add on contains, how to price it against tools you already own, and what to agree before signing. Read it alongside our E3 vs E5 vs F3 comparison and the Microsoft Practice page.
What does Microsoft E5 Security include in 2026?
E5 Security is a paid add on that layers Microsoft's premium security stack onto an E3 seat. It does not turn E3 into E5, because you keep E3 and pay extra per user for the security bundle. Microsoft now sells it as the Microsoft Defender Suite, listed at $12 per user per month on an annual commitment.
The prerequisite is Microsoft 365 E3, or Office 365 E3 plus Enterprise Mobility + Security E3. Microsoft lists the contents on its Microsoft 365 security page:
- Defender for Endpoint Plan 2. Endpoint detection and response across managed devices.
- Defender for Office 365 Plan 2. Phishing, attachment and link protection for mail, with investigation and attack simulation tools.
- Entra ID P2. Risk based conditional access and Privileged Identity Management.
- Defender for Cloud Apps. Visibility and control over sanctioned and shadow apps.
- Defender for Identity. Threat detection on your on premises Active Directory domain controllers.
- Defender XDR. The console that correlates alerts across the products above.
What does E3 already give you before the add on?
Microsoft 365 E3 already includes Entra ID P1, Defender for Endpoint Plan 1 and Defender for Office 365 Plan 1. For those three products, the add on buys the step from Plan 1 to Plan 2.
E3 has no Defender for Identity and, beyond basic shadow IT discovery, no Defender for Cloud Apps or Plan 2 automated investigation and hunting. You are paying $12 for these upgrades and additions, so ask which of them your security team would switch on and run.
Is E5 Security the same as buying full E5?
No. Full E5 also bundles Teams Phone for voice, Microsoft Purview for advanced compliance, and Power BI Pro. Microsoft 365 E5 and E7 licenses also carry a monthly Security Copilot allocation of 400 Security Compute Units per 1,000 paid users, capped at 10,000 a month. The Defender Suite on E3 does not include that allocation.
| Option | Price | What you get over E3 |
|---|---|---|
| Microsoft 365 E3 | $39 | Baseline, with the Plan 1 security tiers |
| E3 plus Defender Suite | $51 | The security stack only |
| Microsoft 365 E5 | $60 | Security, Purview compliance, Teams Phone, Power BI Pro, Security Copilot allocation |
| E3 plus Defender Suite plus Purview Suite | $63 | Security and compliance, without voice or Power BI Pro |
If you only want the security tools, the add on is $9 cheaper per user than the jump to a full E5 seat. Once you also need the compliance tools, two $12 suites cost more than E5 itself, and the full seat becomes the cheaper route. The compliance and voice value is what separates the two.
Negotiating Microsoft E5, E7, and Copilot Cowork: The Two-Layer Bill
How do you calculate the E5 Security break even?
The add on usually wins on price when it replaces three or more components you would otherwise license standalone. At one or two, standalone is usually cheaper and cleaner. Then run a second count of how many users each standalone tool would cover, because that can reverse the answer.
| Component | Already in E3 | Standalone use case | Keep standalone if |
|---|---|---|---|
| Defender for Endpoint P2 | Plan 1 | EDR on managed devices | It is your only premium tool |
| Defender for Office 365 P2 | Plan 1 | Mail threat protection | Mail risk is your single driver |
| Entra ID P2 | P1 | Risk based access | Only a small group needs it |
| Defender for Cloud Apps | No | Shadow IT control | You already run a third party CASB |
| Defender for Identity | No | Attack detection on domain controllers | Your identity threat detection already comes from another vendor |
A worked example with list prices
Say you run 2,500 knowledge workers on E3. Your security team wants Defender for Office 365 Plan 2 for everyone and Entra ID P2 for 120 administrators and high risk roles. Microsoft lists Defender for Office 365 Plan 2 at $5 and Entra ID P2 at $10 per user per month.
| Scenario | Calculation | Annual cost |
|---|---|---|
| Scenario A: two tools, P2 scoped to 120 users | 2,500 x $5 x 12, plus 120 x $10 x 12 | $150,000 + $14,400 = $164,400 |
| Defender Suite for all 2,500 | 2,500 x $12 x 12 | $360,000 |
| Scenario B: same two tools, P2 for all 2,500 | 2,500 x $5 x 12, plus 2,500 x $10 x 12 | $150,000 + $300,000 = $450,000 |
In scenario A, standalone saves $195,600 a year, which is the typical one or two tool result. In scenario B the same two tools cost $90,000 more than the suite, because Entra ID P2 alone is $10 of the $12. So treat the component count as a first filter and let the user count per component settle the close cases.
Two more adjustments belong in the model. Price against your negotiated rates, since EA discounts on the suite and on standalone lines rarely match. And ask Microsoft to price any standalone Plan 2 net of the Plan 1 you already own through E3, because list pricing gives you no credit for it.
Does E5 Security raise your Secure Score?
It can, but only after configuration. The score counts completed recommended actions, so it rises when policies are enabled and tuned. Newly licensed products can add actions to the total before they add any points. Microsoft explains the scoring on its Secure Score documentation.
Microsoft EA renewal guide
Where security add ons fit in your EA renewal, and the contract terms to ask for before you sign.
Get the white paper →What have we seen in recent E5 Security decisions?
Between 2024 and 2025, Morten Andersen reviewed roughly 30 to 40 Microsoft environments where the E5 Security add on was on the table, 35 of them recorded in our engagement file. The decision almost never turned on features. It turned on how much of the bundle the customer already owned standalone.
- Existing standalone licenses. In 20 to 35 percent of cases the customer already paid for Defender for Endpoint or Entra ID P2 on its own.
- Low enablement. Enabled feature coverage sat at 40 to 60 percent of what the add on licensed.
- Frontline inflation. Frontline seats were given P2 policies they never triggered, which raised the upgrade count and the quote.
E5 Security is a procurement bundle before it is a feature upgrade, and you should price it like one.
Where does E5 Security overlap with tools you already pay for?
Overlap is the most common reason the upgrade looks worse than the account team's slides. Many customers already buy one or two components standalone, then pay for them again inside the add on. That is double spend, with no new protection behind it.
- Standalone Defender for Endpoint. Bought for one device class, such as servers or a high risk group, then duplicated in the add on.
- Third party CASB. Overlaps Defender for Cloud Apps and may be redundant.
- Standalone Entra ID P2. Already licensed for admins, then licensed again for all.
- A third party EDR agent. If CrowdStrike or SentinelOne stays on your endpoints, Defender for Endpoint P2 is paid for and idle. Our EDR comparison covers that choice.
Why we push back on the consolidation pitch
The standard Microsoft account team pitch is that E5 Security is a clear upgrade because it consolidates your stack and lifts Secure Score. We disagree. In roughly 1 in 3 environments we reviewed, the customer already paid for at least one bundle component standalone, so the add on duplicated spend rather than replacing it.
Features were also only partly enabled, so the Secure Score story did not hold at the license level. Count actual standalone replacements first, then exclude frontline seats, and only then price the add on. Bundles reward customers who consolidate and retire tools, and they penalize customers who simply add another layer.
Which licensing rules make a partial rollout harder than it looks?
Several of the products are tenant level services, and Microsoft's licensing terms require a license for every user who benefits. Scoping the add on to a subset of users can leave you out of compliance.
- Defender for Office 365. Every user who accesses a protected mailbox needs a license, as do protected shared mailboxes. With Safe Attachments on for SharePoint, OneDrive or Teams, every user of those services needs one, and the same applies to Safe Links in Office apps and Teams.
- Defender for Identity. Microsoft states it cannot currently limit its benefits to specific users, so plan to license every user whose accounts it protects.
- Defender for Cloud Apps. It is on for the whole tenant by default. Admins can scope it to licensed users with its scoped deployment settings.
What are the cheaper paths to the same protection?
If your break even count is one or two, you have cheaper options than the full add on. Buy the components you need standalone, scope P2 to the groups that use it, and leave frontline seats out entirely.
- Targeted standalone. License only the one or two tools that close your real gaps.
- Group scoped P2. Apply Entra ID P2 to admins and high risk roles only. Microsoft documents group based assignment in its Entra ID group licensing guide.
- Frontline carve out. Keep F SKU staff on their existing security baseline.
How should frontline seats be treated?
Leave them out of the E3 add on count, since risk based conditional access and privileged identity management rarely apply to staff who work in a browser on a shared device.
The Defender Suite requires E3, so it cannot attach to F1 or F3 users at all. Microsoft sells a separate F5 Security add on for those plans, and it deserves the same scoping test before you buy it. See our F3 vs E3 comparison for where that line falls.
What will the Microsoft account team say, and how should you answer?
Expect the add on to arrive inside a renewal proposal with a consolidation story attached. These are the lines we hear most often, with the reply that keeps the discussion on your numbers.
- "The suite is cheaper than buying the parts." Ask which parts. Show your own count of tools you would actually buy, and the user count for each.
- "It will lift your Secure Score." Ask for the recommended actions the suite would close in your tenant, then compare them with what your team can deploy this year.
- "Every user needs the same protection." Point to your frontline and shared seats, and to the admin group that is the real Entra ID P2 population.
- "This discount is only available if you sign this quarter." Tie the decision to your renewal date and ask for the same unit price to be held in the new agreement.
When should you make the E5 Security decision?
Make it at renewal, not mid term. The add on count and your standalone stack are the evidence you bring to the next agreement, while a mid term purchase fixes the spend without a contract event to trade against. Microsoft summarizes its enterprise pricing on its plans and pricing page.
Which contract terms should you ask for?
- A unit price hold for the full term. Put the add on and its unit price in the signed enrollment for all three years, so a later order does not pick up whatever the price list says at that point.
- A ramp. Start with the users your team will onboard in year one and add the rest later at the same price.
- A reduction right at anniversary. If adoption stalls, you can cut the add on quantity instead of paying for shelfware. Our E5 shelfware guide shows what unused seats cost.
- Credit on a later step to E5. If you may need Purview within the term, agree now that add on payments count toward the full E5 seat.
- Standalone retirement dates. Align the end of any standalone Defender, Entra or CASB subscription with the add on start, so you do not pay for both.
How can you check what you actually use?
Start with the data Microsoft already gives you. It shows which licenses are assigned and which features are switched on.
- Microsoft 365 admin center, Billing, Licenses. Assigned versus purchased counts for every SKU, including standalone security lines.
- Secure Score in the Defender portal. Recommended actions by product, showing which ones are completed.
- Defender portal device inventory. Onboarded devices, which reveals whether Defender for Endpoint or another EDR agent is really running.
- Entra admin center, Identity Protection. Risky users and sign ins, which shows whether P2 risk policies ever fire.
- Defender for Cloud Apps, Cloud Discovery. Whether shadow IT reports are being used or duplicated by another CASB.
What to do next
- Inventory. List every security tool you license today, standalone and inside E3.
- Map. Match each Defender Suite component to a tool you already pay for or would buy.
- Count. Tally the standalone tools the add on would replace. Three or more points to buying the add on.
- Scope P2. Confirm which user groups actually need Entra ID P2 risk policies.
- Exclude frontline. Take frontline and shared seats out of the upgrade count.
- Model. Price the add on against your real standalone stack using your negotiated rates.
- Renew. Bring the count, the model and the contract terms above into the renewal discussion.
Frequently asked questions
Is Microsoft E5 Security worth the upgrade?
It is worth it when you would otherwise license three or more of its components standalone and plan to deploy them. Below that count, buying the individual tools you need is cheaper and avoids paying for features you will not enable. Check the user count too, since Entra ID P2 for everyone can tip a two tool case toward the suite.
What is the difference between E5 Security and full E5?
E5 Security adds only the security products to an E3 seat, for $51 a user in total at list. Full E5 at $60 also brings Purview compliance, Teams Phone, Power BI Pro and a Security Copilot allocation. If you would need the Purview Suite as well, full E5 costs less than the two add ons together.
What does the E5 Security add on include?
Defender for Endpoint Plan 2, Defender for Office 365 Plan 2, Entra ID P2, Defender for Cloud Apps and Defender for Identity, tied together in Defender XDR. It grants the licenses for these tools but does not configure or enable them for you.
Does E5 Security improve Secure Score automatically?
No. Buying the add on changes nothing in the score until someone completes the recommended actions, such as onboarding devices to Defender for Endpoint or turning on risk based sign in policies. Licensing the bundle without that work buys capability on paper and no measurable risk reduction.
Do frontline workers need E5 Security?
Most do not. Staff on shared devices who work mainly in a browser rarely trigger risk based access or privileged identity controls. Users on F1 or F3 cannot take the E3 based Defender Suite at all, and Microsoft sells them a separate F5 Security add on, so scope any upgrade to the roles that need it.
How do you avoid paying twice for security tools?
Before you price the add on, pull every standalone security subscription from the admin center and your reseller invoices, and map each one to a suite component. Where the suite duplicates a tool, set the standalone end date to match the add on start date so you are never billed for both.
Can you buy only part of the E5 Security stack?
Yes. Defender for Office 365 Plan 2 lists at $5 and Entra ID P2 at $10 per user per month, so you can license only the tool that closes your gap. Defender for Endpoint Plan 2, Defender for Identity and Defender for Cloud Apps are also sold standalone, so ask your reseller to quote them next to the suite.
When should you decide on the E5 Security upgrade?
Decide at your Enterprise Agreement renewal. That is when a new price, a ramp and reduction rights can be agreed together, and when Microsoft has most reason to concede them. An upgrade signed mid term tends to inherit the terms of the current agreement.