Contents
Key takeawaysThe security stackWhat we have seenThe E5 Security add onCost for 5,000 usersWhere buyers overpayChecking your rightsSentinel costWhat Microsoft will sayContract termsWhat to do nextFAQMicrosoft sells the same security protection through E5, the $12 E5 Security add on for E3, and standalone SKUs. In our engagements most buyers paid twice somewhere, and segmenting users by risk usually cost less than uniform E5.
- Four product families. Microsoft security splits across Defender, Entra identity, Purview compliance and the Sentinel SIEM, each sold inside suites, as add ons and standalone.
- The add on sits on E3. The E5 Security add on, now sold as the Microsoft Defender Suite at $12, puts the E5 security stack onto an E3 base.
- Defender is a family. Endpoint, Office 365, Cloud Apps, Identity and Defender for Cloud each carry their own entitlement, and Defender for Cloud is billed through Azure.
- Duplicates are common. Standalone Defender or Entra SKUs duplicated E5 rights on 10 to 25 percent of seats in the engagements we advised.
- Usage decides the path. E3 plus the add on costs $51 at list against $60 for E5, until a seat also needs Purview.
- Sentinel needs its own model. Ingestion and retention drive the Sentinel bill, and the E5 data grant covers only listed Microsoft 365 sources.
- One owner. Security and procurement buying separately is the main source of overlap, so put one person over the whole stack.
What is in the Microsoft security stack?
Microsoft security licensing covers four product families: Defender, Entra, Purview and Sentinel. Each can be licensed inside a Microsoft 365 suite, as an add on, or as a standalone SKU, and that choice of routes is where the overlap and the double payments start.
Microsoft lays out the portfolio in its Microsoft security product comparison and the Defender products in the Microsoft Defender XDR documentation. For licensing purposes the map looks like this:
- Defender. Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Defender for Identity and Defender for Cloud.
- Entra. Identity protection, conditional access and identity governance.
- Purview. Data compliance, information protection, data loss prevention and data governance.
- Sentinel. The cloud SIEM, priced largely on data ingestion and retention and billed through Azure.
How is the Defender family split?
Defender is a family of products, each with its own entitlement. Endpoint protects devices, Office 365 protects mail and collaboration, Cloud Apps governs SaaS use and Defender for Cloud covers server and cloud workloads.
- Microsoft 365 E3. Defender for Endpoint Plan 1, Defender for Office 365 Plan 1, added in Microsoft's July 2026 update and rolling out to tenants through the third quarter, and the discovery part of Defender for Cloud Apps.
- Microsoft 365 E5. Plan 2 of Defender for Endpoint and Defender for Office 365, plus Defender for Identity and the full Defender for Cloud Apps.
Defender for Cloud sits outside every user suite. It is charged per protected resource through your Azure subscription, so no E5 or add on purchase covers it. More detail on the endpoint plans is in our Defender for Endpoint P1 versus P2 guide.
Where does Entra fit?
Entra delivers identity security. Entra ID Plan 1 is included in E3 and E5, and Plan 2 is included in E5, as the Microsoft Entra documentation describes. A separate Entra purchase on those seats, listed at $7 for P1 and $10 for P2 per user per month, duplicates a right you already hold.
Plan 2 brings risk based conditional access, Identity Protection and Privileged Identity Management. The fuller lifecycle features sit in Entra ID Governance at $7, which is also part of the $12 Entra Suite. See our Entra ID pricing guide for the plan by plan split.
Where do Purview and Sentinel sit?
Purview is the compliance side, documented in the Microsoft Purview documentation. E3 includes data loss prevention for email and files. E5 adds Information Protection Plan 2, insider risk, eDiscovery and the wider compliance set, and E3 buyers can add the same through the Microsoft Purview Suite, formerly Microsoft 365 E5 Compliance, at $12.
Sentinel is different in kind. It is a consumption service, so its bill depends on how many gigabytes you send it and how long you keep them, which no seat count can tell you.
Microsoft EA: Where the Leverage Really Is, and the Mistakes That Give It Away
What have we seen in recent Microsoft security licensing negotiations?
Overlapping purchases were the norm. Across roughly 25 to 35 Microsoft security licensing engagements I advised in 2024 and 2025, three findings came up again and again:
- Duplicate rights. Standalone Defender or Entra SKUs duplicated rights already in E5 on 10 to 25 percent of seats.
- Unused E5 security. Organizations on full E5 used only a fraction of its security stack, so E3 with the E5 Security add on would have cost less.
- Late Sentinel surprises. Sentinel ingestion was modeled separately, after the security SKUs were fixed, and the cost surprised the buyer once the logs started flowing.
The common cause was organizational. Security teams bought tools against threats, procurement bought suites against a renewal date, and no one compared the two lists seat by seat.
Microsoft EA Renewal Guide
How to set the E3, E5 and add on mix and the contract terms for your next Microsoft renewal.
Get the white paper →How does the E5 Security add on work?
The E5 Security add on puts the E5 security capabilities on top of an E3 base. Microsoft now sells it as the Microsoft Defender Suite, previously Microsoft 365 E5 Security, at $12 per user per month, and it requires Microsoft 365 E3 or Office 365 E3 with Enterprise Mobility + Security E3.
It contains Defender XDR, Defender for Endpoint Plan 2, Defender for Identity, Defender for Office 365 Plan 2, Defender for Cloud Apps and Entra ID Plan 2. That is the security core of E5, sold without the rest of the suite. The three routes to the same protection compare like this at current list prices:
| Path | What you buy | List per user per month | Best when |
|---|---|---|---|
| Full E5 | E5 suite for all seats | $60 | Most E5 capabilities are used, including compliance, voice and analytics |
| E3 plus E5 Security | E3 base plus the Defender Suite | $39 plus $12, so $51 | You want E5 security and not the rest of E5 |
| E3 plus standalone | E3 plus individual SKUs such as Entra ID P2 at $10 | $39 plus each SKU | Only a few seats or one capability need more |
When is the add on cheaper than full E5?
It is cheaper when users need the E5 security stack but not the E5 analytics, voice and compliance extras. At list, the add on route saves $9 per user per month against E5. Once a seat also needs the Purview Suite, the sum becomes $63 and full E5 at $60 is the cheaper choice.
What the add on leaves out
The compliance, Teams Phone and Power BI Pro parts of E5 are not in the add on. Nor is Security Copilot, because Microsoft's allocation of 400 Security Compute Units per 1,000 users a month, capped at 10,000 per tenant, applies to E5 and E7 licenses only.
What does each option cost for 5,000 users?
For a hypothetical 5,000 user organization on E3 today, segmenting by risk costs about $1 million a year less than moving everyone to E5. The table uses list prices and assumes 1,500 users are high risk: administrators, executives, finance staff and anyone with privileged access.
| Option | Calculation | Annual list cost | Change against all E3 |
|---|---|---|---|
| All users on E3 | 5,000 × $39 × 12 | $2,340,000 | Baseline |
| All users on E5 | 5,000 × $60 × 12 | $3,600,000 | +$1,260,000 |
| All users on E3 plus E5 Security | 5,000 × $51 × 12 | $3,060,000 | +$720,000 |
| Segmented: 1,500 on E3 plus E5 Security, 3,500 on E3 | $918,000 + $1,638,000 | $2,556,000 | +$216,000 |
The segmented option costs $1,044,000 a year less than uniform E5 and $504,000 less than giving every user the add on. Discounts will move each line. The ranking only changes if Microsoft discounts E5 far more deeply than E3 and the add on, so compare the net unit prices side by side.
Two checks come before you take that saving. The low risk users still need adequate protection on E3, and some Defender services cannot be split by user, which the section on license rules below covers.
Where do buyers overpay on Microsoft security?
Overpayment shows up in five recurring places. Most of it comes from standalone SKUs on seats whose suite already grants the right, and from full E5 bought for security alone:
- Standalone on E5. A separate Defender or Entra SKU on an E5 seat is a duplicate. Say 300 of 2,000 E5 users also carry Entra ID P2 at $10: that is $36,000 a year at list for a right already paid for.
- Full E5 for security. Paying for all of E5 when only the security stack is used.
- Uniform licensing. One SKU for everyone ignores that risk differs by role.
- Unmodeled Sentinel. Ingestion cost treated as an afterthought once the seat mix is signed.
- Duplicate tools outside Microsoft. A third party endpoint or email security product renewed alongside Defender Plan 2 rights that were bought to replace it.
Why we do not put every user on E5 by default
The usual advice is to standardize the whole organization on E5, because security should not be rationed and one SKU is simpler to run. We disagree with it as a default.
In the engagements we advised, uniform E5 meant paying the full suite price for a security stack that many users barely touched. E3 with the E5 Security add on gave the users who needed it the same protection for less.
Buy E5 security for the people attackers target, and stop paying suite price for features your users never open.
The better course is to segment the population by risk, license the high risk seats to the security they need, and use the add on instead of full E5 where the analytics and voice extras go unused. High risk users keep full E5 security.
Where segmenting meets Microsoft's license rules
Some services can be scoped to licensed users and some cannot. Defender for Cloud Apps supports scoped deployment to licensed users, and Entra ID P2 features such as risk based policies are assigned per user. Microsoft's service description says Defender for Identity is enabled for the whole tenant and cannot yet limit its benefit to specific users.
Defender for Office 365 has the widest rule. Microsoft's service description requires a license for each of these:
- every user who accesses a protected mailbox, and every protected shared mailbox
- every Teams, SharePoint or OneDrive user once Safe Attachments is on for those services
- every Office app or Teams user covered by Safe Links
Size those services against the whole affected population before you count the segmented saving.
How do you check which security rights you already own?
Start from the tenant. It shows which licenses are assigned to which users, and that is the only reliable way to find duplicates. These sources cover most of it:
- Microsoft 365 admin center. Billing, then Licenses, lists every SKU with purchased and assigned counts.
- Microsoft Graph PowerShell. Get-MgSubscribedSku returns every subscribed SKU and its service plans, which you can join to user assignments to find E5 users who also hold standalone Entra or Defender SKUs.
- Defender portal device inventory. The count of onboarded devices shows whether Defender for Endpoint is deployed as widely as it is licensed.
- Sentinel Usage table. A KQL query on Usage with IsBillable set to true, or the Workspace Usage Report workbook, shows billable gigabytes by data type.
How do you control Microsoft Sentinel cost?
Sentinel is priced on data ingestion and retention, so cost follows what you ingest and how long you keep it. Model the volume before you commit, and before the security SKUs are locked, because the seat mix changes what is free. Detail on the meters is in our Sentinel pricing guide.
What Microsoft gives you at no charge
- Free sources. Azure Activity logs, Office 365 audit logs and alerts from the Defender products ingest free. Raw Defender and Entra logs do not.
- The Microsoft 365 grant. E5, E7 and E5 Security licenses earn up to 5 MB per user per day of listed Microsoft 365 data, such as Entra sign in logs and advanced hunting data. For 5,000 licensed users that is roughly 25 GB a day.
- Retention. The first 90 days of data in the analytics tier are retained at no extra charge. Longer retention is billed, and the data lake tier is the lower cost place for it.
Commitment tiers start at 100 GB a day and can only be lowered every 31 days. Firewall, proxy and server logs tend to be the largest feeds, and none of them count toward the grant.
What will the Microsoft account team say, and how should you answer?
Expect a small set of arguments for full E5, and prepare a precise answer to each. The replies below are the ones we use:
- "E5 is only a few dollars more than E3 plus the add on." That $9 gap applies only to users who need the add on. Your low risk users would stay on plain E3, where the gap to E5 is $21 per user per month at list, so ask them to price full E5 against that mix.
- "Security Copilot is now included with E5." Ask how many compute units your team used last quarter. Value the allocation at that use, not at the list price of the full grant.
- "Segmenting will leave you out of compliance." Ask them to name the service description clause for each product. The concern is valid for Defender for Identity and wide for Defender for Office 365. It does not apply to per user services such as Entra ID P2.
- "E7 bundles everything at $99." Price its parts against your adoption plan. Copilot, Agent 365 and the Entra Suite are worth the bundle only if you would buy them anyway, as our E7 guide sets out.
What should you ask for in the contract?
Ask for terms that keep the segmented design cheap for the whole agreement. These carry the most weight:
- Price hold on add ons. Fix the Defender Suite and Purview Suite unit prices for the term, so the add on route keeps its gap to E5.
- Step up at the difference. Move add on seats to full E5 mid term by paying only the price difference.
- Anniversary reductions. Ask for the right to lower add on counts at each anniversary as roles change.
- Written license scope. Get Microsoft's written position on how many users must be licensed for Defender for Identity and Defender for Office 365 in your design.
- Sentinel treatment. Ask whether Sentinel consumption counts toward any Azure commitment you hold.
Who should own security licensing?
Give one person ownership across security and procurement. When the two teams buy separately, overlap is almost guaranteed. Engage independent Microsoft advisory to reconcile the two views before the order is placed.
What to do next
- Inventory. List every Microsoft security SKU assigned across the tenant, plus third party security contracts.
- Net duplicates. Net each standalone SKU against the suite on the same seat, and plan to drop the duplicates at the next anniversary.
- Segment. Group users by security risk, starting from privileged roles and high value data access.
- Compare paths. Price full E5, E3 plus E5 Security, and E3 plus standalone for each segment, including the Purview crossover at $63.
- Model Sentinel. Estimate ingestion and retention separately, net of free sources and the per user grant.
- Assign an owner. Make one person accountable across security and procurement for licensing.
- Reconcile before renewal. Review the stack with independent Microsoft advisory six months before signature, while there is time to change the mix.
Want a second opinion on your Microsoft licensing? Our Microsoft licensing consultants work only for buyers, with no reseller margin.
Frequently asked questions
What does the Microsoft E5 Security add on include?
It adds Defender XDR, Defender for Endpoint Plan 2, Defender for Office 365 Plan 2, Defender for Identity, Defender for Cloud Apps and Entra ID Plan 2 to an E3 license. Microsoft has renamed it the Microsoft Defender Suite, and buyers get E5 grade security without paying for the whole E5 suite.
Is Defender one product or several?
Several. Defender for Endpoint, Defender for Office 365, Defender for Cloud Apps, Defender for Identity and Defender for Cloud are licensed separately, even though they share the Defender XDR portal. Check each one on its own when you look for gaps or duplicates.
Is Entra ID already in my suite?
Yes, in part. Microsoft 365 E3 includes Entra ID Plan 1 and E5 includes Plan 2, so a standalone Entra ID purchase for those users is a duplicate. Entra ID Governance and the Entra Suite are not in either suite and are bought as add ons.
When is E3 plus E5 Security cheaper than E5?
Whenever a user needs the security stack but not the E5 compliance, voice and analytics extras. The balance tips back to E5 when a user needs both the security and the compliance add ons, and E5 also carries the Security Copilot allocation that the add on route does not.
What is Microsoft Purview?
Purview is Microsoft's compliance and data security family, covering information protection, data loss prevention, insider risk, eDiscovery, audit and data governance. E5 includes the full set, E3 includes basic data loss prevention, and the Purview Suite adds the E5 level to an E3 user for $12.
How is Microsoft Sentinel priced?
Sentinel bills through your Azure subscription for the data you ingest and keep, either pay as you go per gigabyte or through daily commitment tiers. Some Microsoft sources are free, and E5 or E5 Security users earn a daily data grant, so net those out before you size a tier.
Where do buyers most often overpay on security?
Most often on standalone Entra or Defender SKUs left on users who later moved to E5, and on full E5 bought only for its security features. A third source is a third party security product renewed after Defender rights were bought to replace it.
Should everyone get the same security license?
Rarely. Administrators, executives and users with access to sensitive data face more attacks than the average employee. Licensing those groups fully and the rest to a lower base usually costs less than uniform E5, provided tenant wide services such as Defender for Identity are sized correctly.