HomeMicrosoft HubThreat Protection Licensing
Microsoft  |  Security Licensing Buyer Guide 2026

More than a third of E5 Security seats never produced an alert worth responding to

Security licensing is the one part of the Microsoft estate bought on fear and renewed on inertia. The alert log is the usage report nobody reads: in our reviews, over a third of E5 Security seats sat on users who never generated a Defender alert worth a response.

Prepared by Redress Compliance · August 14, 2026 · Microsoft advisory. Security licensing reviews across E3 and E5 estates, 2024 to 2026.

Executive summary

More than a third of E5 Security seats sat on users who never generated a Defender alert worth a response. That is the signature of security licensed by org chart rather than by threat model, and it is the largest recoverable line in the security budget.

The structure is simple once separated: the Defender family sells standalone per user or bundled into E5 and E5 Security, and E5 Security is the E3 add on carrying Defender for Endpoint Plan 2, Defender for Office 365 Plan 2, Defender for Identity, and Defender for Cloud Apps.

The bundle math has one rule. E5 or E5 Security makes sense when you would otherwise buy three or more Defender products separately for the same user. Below that line, standalone wins.

Plan 2 is the real product. Most security teams that justify Defender at all need Plan 2 depth, so the Plan 1 saving usually reopens the bundle question instead of settling it.

Sentinel is a different bill entirely: consumption by ingestion, not per user, budgeted apart from the seats and controlled through architecture. Pairing them in one budget line is how both get overbought.

1 in 3+
E5 Security seats on users with no Defender alert worth a response.
4
Defender products bundled in E5 Security: Endpoint P2, Office 365 P2, Identity, Cloud Apps.
3+
Standalone products at which the bundle starts beating separate purchases.
2 meters
Defender per user, Sentinel per gigabyte: two bills, two disciplines.
1.

The stack, separated

ProductHow it licensesBuyer note
Defender standalone plansPer user, per productAn E3 estate can add only the pieces each user tier needs
E5 SecurityE3 add on bundling four Defender productsMost of the E5 security value without the full E5 price jump
Microsoft 365 E5The full suite, security includedJustified by the whole suite, never by security alone
Defender Plan 1 vs Plan 2Response depth differsTeams that justify Defender at all usually need Plan 2
Microsoft SentinelConsumption: ingestion and analytics per gigabyteBudgeted apart from seats; controlled by routing, not licensing
Capabilities inside existing seatsAlready paid forThe most common double purchase in the security estate

The three plus rule does the SKU work. Count the Defender products a user tier genuinely needs: at three or more, E5 Security earns its price; below three, standalone plans on E3 price better. The rule only works per tier, not per company, which is exactly why the uniform rollout fails it: the SOC needs the stack, the frontline workforce rarely does, and one SKU for both means someone is subsidizing someone.

2.

The moves that right size the estate

Free white paper

Microsoft security licensing, unbundled

The Defender product map, the E5 versus E5 Security versus standalone math, the alert log method, and the tiering model for the security estate.

Get the white paper →
3.

Security follows the org chart, threats do not

Every other Microsoft workload gets right sized eventually. Unused Visio seats get culled, Power BI Pro gets tiered, even the E5 mix gets audited when the renewal is large enough. Security is the exception: it deploys uniformly, renews automatically, and grows monotonically, because nobody wants to be the person who removed protection before the breach.

That asymmetry is priced in. The uniform rollout, E5 Security for everyone on E3, is administratively effortless and analytically indefensible, because threat exposure is the least uniform property in the company. A domain admin, a finance approver, and a frontline kiosk account do not face the same adversary, and licensing them identically means the kiosk is paying for the admin's threat model.

The alert log is where the truth sits, and it is the usage report nobody reads. A third or more of E5 Security seats producing no alert worth a response is not evidence the product failed. It is evidence the seat was assigned to a user whose exposure never required it, and unlike most licensing questions, this one has telemetry: the SOC's own console will tell you which seats earn their keep.

The economics compound quietly. The unnecessary bundle seat costs more than the standalone piece the user actually needed, the renewal carries the whole population forward as a block, and the capabilities already inside existing seats get bought again standalone by a different budget holder who never saw the entitlement map. Three small leaks, one direction.

The counter is to treat security licensing exactly like the security program treats everything else: by risk tier. Map exposure, apply the three plus rule per tier, hold Plan 2 where Defender is justified, and let the alert log arbitrate annually. Nothing about this weakens the security posture. It funds it, by moving spend from seats that never alert to the controls that do.

The consumption side of this estate, the Sentinel meter and the ingestion tuning that cut it 25 to 45 percent, has its own analysis in the Sentinel pricing brief. The wider position sits in the Microsoft practice.

Watch the briefing · 3:585 Tips for Your Microsoft NegotiationNever pick from the Multiple Equivalent Offers menu, right size before pricing, and split the stack so one workload never subsidizes another's optics.
Try Vera AI · free 30 day trial
Vera maps your security seat assignment against the alert telemetry, prices the standalone versus bundle paths per tier, and benchmarks your E5 Security position.
  • Percentile standing for your exact deal size and industry, from real closed transactions
  • Scenario simulation before the call: test alternative terms and see the financial impact of each
  • A negotiation playbook, talking points, and a two page executive brief on day one
Start the free Vera AI trial →30 days free · no credit card · cancel anytime
4.

What the security licensing reviews showed, 2024 to 2026

Across the E3 and E5 estates we reviewed, the same picture repeated wherever security had been rolled out uniformly:

1 in 3+
Seats without actionable alerts

E5 Security seats on users who never generated a Defender alert worth a response, the recoverable core of the security budget.

3+
The bundle threshold

The standalone product count at which E5 Security starts earning its price, applied per exposure tier rather than per company.

Three patterns recurred. Uniform E5 Security rollouts covering populations with radically different exposure. Standalone Defender purchases duplicating capabilities already inside existing E5 seats. And Sentinel budgeted as part of the seat conversation, where its per gigabyte meter belongs to a different discipline entirely.

The buyer side move is to let the alert log arbitrate. The wider library sits in the Microsoft practice.

5.

Your first five moves

  1. Pull twelve months of Defender alert data by user and lay it against the license assignment, because the gap between them is the finding.
  2. Tier the population by exposure, and apply the three plus rule per tier: bundle where three or more Defender products are justified, standalone below.
  3. Build the entitlement map of what already sits inside each seat type before approving any standalone security purchase.
  4. Keep Plan 2 where Defender is justified, and remove the deployment rather than downgrade the plan where it is not.
  5. Move Sentinel to its own budget line governed by ingestion architecture, and take the seat conversation and the meter conversation separately. The Microsoft practice runs both with you.
6.

Frequently asked questions

How is Microsoft threat protection licensed in 2026?

Mainly through the Defender family, sold either as standalone plans per user or bundled into the Microsoft 365 E5 and E5 Security suites. You can buy a single Defender product or take the whole stack inside a larger M365 SKU.

What is in E5 Security?

E5 Security is an add on for E3 customers that bundles Defender for Endpoint Plan 2, Defender for Office 365 Plan 2, Defender for Identity, and Defender for Cloud Apps. It delivers most of the E5 security value without the full E5 price jump.

When does E5 or E5 Security beat standalone Defender?

When you would otherwise buy three or more Defender products separately for the same user. Below that line, an E3 estate adding only the pieces each user tier needs prices better than the bundle.

Do you need Defender Plan 1 or Plan 2?

Most security teams that justify Defender at all need Plan 2, which carries the investigation and response depth the operations program actually uses. Buying Plan 1 to save money usually re opens the standalone versus bundle question rather than settling it.

Where does Microsoft Sentinel fit in the threat protection cost model?

Sentinel is the cloud SIEM and is licensed separately by data ingestion and analytics, not per user. It pairs with Defender but its cost model is consumption based, so it is budgeted apart from the Defender seat licenses and controlled through ingestion architecture.

How do you find over licensed security seats?

Read the alert log against the license assignment. In our reviews more than a third of E5 Security seats sat on users who never generated a Defender alert worth a response, which is the signature of security licensed by org chart rather than by threat model.

How do you avoid double paying for Microsoft security capabilities?

Map which users need each Defender product before renewing, and check what already sits inside their existing seats. Capabilities already included in an E5 seat are commonly bought again standalone, and the map is what prevents it.

Watch the briefingResearch briefing · 3:58

5 Tips for Your Microsoft Negotiation

Never pick from the Multiple Equivalent Offers menu, right-size before pricing, split the stack so Azure never subsidizes M365 optics, bring a calendar and a credible partial no, and convert the relationship into contract language.

© 2026 Redress Compliance · Independent, buyer sideredresscompliance.com
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent
Microsoft White Paper

The full Microsoft security licensing, unbundled white paper.

The Defender product map, the E5 versus E5 Security versus standalone math, the alert log method, and the tiering model for the security estate.

Gated with a work email on the download page. No sales follow up you did not ask for.

Get the White Paper →
Independent, buyer side. We never share your details with vendors.
Put your own numbers on this with the Microsoft licence optimisation calculator.
Open the Calculator → Microsoft Practice →
Editorial boardroom interior

The advisor your vendors do not want.

500+ enterprise clients. 11 vendor practices. Industry recognized. One conversation can change what you pay for the next three years.

Stay ahead of Microsoft pricing and contract moves.

One buyer side briefing a week. Renewal signals, discount bands, and the levers that work. No vendor spin.