Editorial photograph of a security operations team reviewing Microsoft Defender licensing coverage
Microsoft / Security Licensing

Microsoft security licensing. The 2026 framework.

Microsoft security is sold as suites, add ons, and standalone SKUs that overlap in confusing ways. The E5 Security add on, the Defender family, Entra, and Purview can each be bought more than once. This is the buyer side map.

Contact Us Microsoft Practice
500+Enterprise clients
$2B+Under advisory
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent

Microsoft security spans Defender, Entra, Purview, and Sentinel, sold as suites, add ons, and standalone SKUs. The same protection can be assembled several ways at very different prices. This guide maps the stack and shows where buyers pay twice.

Key takeaways

  • Microsoft security splits across Defender, Entra identity, Purview compliance, and Sentinel.
  • The E5 Security add on layers the E5 security stack onto an E3 base.
  • Defender itself is a family: Endpoint, Office 365, Cloud Apps, and for Cloud.
  • Standalone security SKUs frequently duplicate rights already inside E5 or the add on.
  • The cheapest path depends on how many E5 capabilities you actually use.
  • Security and procurement often buy the stack separately, which creates overlap.

What is in the Microsoft security stack?

Four pillars cover most of it. Each can be licensed inside a suite or bought alone, which is where the confusion and the overlap begin.

Microsoft documents the portfolio in its Microsoft security product comparison and the Defender family in the Microsoft Defender XDR documentation.

  • Defender: Endpoint, Office 365, Cloud Apps, and Defender for Cloud.
  • Entra: identity protection, conditional access, and identity governance.
  • Purview: data compliance, information protection, and data loss prevention.
  • Sentinel: cloud SIEM, priced largely on data ingestion.

How is the Defender family split?

Defender is not one product. Endpoint protects devices, Office 365 protects mail and collaboration, Cloud Apps governs SaaS, and Defender for Cloud covers workloads. Each has its own entitlement.

Where does Entra fit?

Entra delivers identity security. Plan 1 is in E3 and E5, and Plan 2 is in E5. Buying Entra separately on those seats duplicates a right you already hold, per the Microsoft Entra documentation.

How does the E5 Security add on work?

The E5 Security add on layers the E5 security capabilities onto an E3 base. It is the lever for buyers who want E5 grade security without paying for the full E5 suite.

Three ways to reach the same security posture

PathWhat you buyBest when
Full E5E5 suite for all seatsMost E5 capabilities are used
E3 plus E5 SecurityE3 base plus security add onYou want E5 security, not all of E5
E3 plus standaloneE3 plus individual security SKUsOnly a few seats need extra

The compliance pieces sit in Purview, documented in the Microsoft Purview documentation.

When is the add on cheaper than full E5?

When your users need the E5 security stack but not the E5 analytics, voice, and compliance extras. The add on isolates the security value and leaves the rest unpaid.

Where do buyers overpay on Microsoft security?

Overlap appears when standalone SKUs sit on seats whose suite already grants the right. It also appears when full E5 is bought for security alone.

  • Standalone on E5: a separate Defender or Entra SKU on an E5 seat is a duplicate.
  • Full E5 for security: paying for all of E5 when only security is needed.
  • Uniform licensing: one SKU for everyone ignores that risk is not uniform.
  • Unmodeled Sentinel: ingestion cost treated as an afterthought.

Where the common advice on Microsoft security licensing is wrong

The common advice is to standardize the whole organization on E5 because security should not be rationed and uniform licensing is simpler. We disagree. In the engagements we advised, uniform E5 meant paying full suite price for a security stack that many users barely touched, while the E3 plus E5 Security add on reached the same protection for less. The buyer side move is to segment the population by risk, license the high risk seats to the security they need, and use the E5 Security add on rather than full E5 where the analytics and voice extras are not used. Security is not rationed by this. Spend is.

Editorial photograph of a security and procurement team mapping Microsoft Defender coverage by risk tier
Risk is not uniform across an organization, so security licensing should not be either. The E5 Security add on lets buyers fund protection without buying the full E5 suite for every seat.
25 to 35
Security engagements advised
10 to 25%
Seats with duplicate security SKUs
3
Paths to the same posture

Source: Redress Compliance advisory engagement file, 2024 to 2025.

What buyer side moves clean up the security stack?

The waste comes from buying the stack in pieces without a map. The controls put one owner over the whole picture.

  • Map the stack: list every security SKU against the suite on each seat.
  • Segment by risk: license high risk seats fully, others to a base.
  • Prefer the add on: use E5 Security on E3 where full E5 is not needed.
  • Model Sentinel: size ingestion cost before fixing the SKU mix.

Who should own security licensing?

A single owner across security and procurement. When the two buy separately, overlap is almost guaranteed. Engage independent Microsoft advisory to reconcile the two views.

How do you control Sentinel cost?

Sentinel is priced on data ingestion, so the lever is what you ingest and how long you retain it. Model the volume before committing, not after the security SKUs are locked.

What should a buyer do next?

Work the estate in this order. Each step is one decision a procurement or licensing lead can own.

  1. Inventory every Microsoft security SKU assigned across the estate.
  2. Net each standalone SKU against the suite on the same seat.
  3. Segment the user population by security risk.
  4. Compare full E5, E3 plus E5 Security, and E3 plus standalone for each segment.
  5. Model Sentinel ingestion and retention cost separately.
  6. Assign one owner across security and procurement for licensing.
  7. Reconcile the stack with independent Microsoft advisory before renewal.

Frequently asked questions

What does the Microsoft E5 Security add on include?

The E5 Security add on layers the E5 security capabilities, including Defender and identity protection, onto an E3 base. It lets buyers reach E5 grade security without the full E5 suite.

Is Defender one product or several?

Several. The Defender family includes Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, and Defender for Cloud, each with its own entitlement.

Is Entra ID already in my suite?

Entra ID Plan 1 is included in E3 and E5, and Plan 2 is included in E5. A standalone Entra SKU on those seats duplicates a right you already hold.

When is E3 plus E5 Security cheaper than E5?

When users need the E5 security stack but not the E5 analytics, voice, and compliance extras. The add on isolates the security value at a lower price.

What is Microsoft Purview?

Purview is the Microsoft compliance stack, covering information protection, data loss prevention, and data governance. It is included in E5 and parts can be bought separately.

How is Microsoft Sentinel priced?

Sentinel is a cloud SIEM priced largely on data ingestion and retention. Its cost should be modeled separately from the security SKUs to avoid surprises.

Where do buyers most often overpay on security?

On standalone SKUs that duplicate suite entitlements, and on full E5 bought for seats that only need the security stack rather than the whole suite.

Should everyone get the same security license?

Rarely. Risk is not uniform, so segmenting the population and licensing high risk seats more fully is usually cheaper than uniform E5 for all.

Run the Microsoft 365 license optimizer against your estate in under five minutes.
Open the Tool →
E5 Security
Add On To E3
Defender
Endpoint, O365, Cloud
Purview
Compliance Stack
100%
Buyer Side
5 min
Optimizer Run

Microsoft security licensing is a stack that can be assembled three different ways for the same outcome. The cheapest path is rarely the one the security team and the account team arrive at separately.

Fredrik Filipsson
Co Founder and Group CEO, Redress Compliance
Deep Library

More on the Microsoft estate.

Microsoft Practice →
Microsoft E3 versus E5 decision
Microsoft
M365 E3 versus E5
The decision that drives the security add on.
9 min read
Microsoft 365 duplicate add ons
Microsoft
M365 duplicate add ons
The duplicate spend inside the security stack.
8 min read
Microsoft advisory practice
Microsoft
Microsoft advisory
Independent buyer side Microsoft licensing advisory.
6 min read
Editorial photograph of a corporate boardroom set for a contract review

The advisor your vendors do not want.

500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay Microsoft for the next three years.

The buyer side Microsoft brief.

Renewal levers, SKU changes, and audit posture. One email when it matters. No noise.