Contents
Key takeawaysHow threat protection is licensedBundle or standalonePlan 1 or Plan 2Why seats follow the org chartFinding seats without alertsWhere Sentinel fitsWhat our reviews showedAccount team lines and repliesWhat to do nextFAQLicense Defender by exposure tier. Buy the E5 Security add on for groups that need three or more Defender products, standalone plans on E3 below that, and keep Sentinel on its own consumption budget.
- Two ways to buy. Defender plans are sold per user on their own, or bundled in E5 and the E5 Security add on, now the Microsoft Defender Suite at $12 on top of E3.
- The three plus rule. The suite beats standalone plans when a user group needs three or more Defender products; below that, standalone on E3 costs less.
- Tier by exposure. Apply the rule to each tier, because domain admins, finance approvers and frontline staff face different threats.
- Plan 2 where Defender is justified. Groups that need Defender at all usually need the investigation and response depth that only Plan 2 carries.
- Check what you already own. E3 includes Defender for Endpoint Plan 1 and, since July 1, 2026, Defender for Office 365 Plan 1, so standalone Plan 1 purchases for E3 users are duplicates.
- Sentinel is a separate bill. It meters gigabytes of ingestion and analytics, so budget and negotiate it apart from the Defender seats.
How does Microsoft license threat protection in 2026?
Microsoft sells threat protection through the Defender family, as standalone plans per user or bundled into Microsoft 365 E5 and the E5 Security add on. Microsoft Sentinel, the cloud SIEM, sits outside that model and bills by the gigabyte.
| Product | How it licenses | What it means for your budget |
|---|---|---|
| Defender standalone plans | Per user, per product | An E3 customer can add only the pieces each user group needs |
| E5 Security, now sold as the Microsoft Defender Suite | $12 per user per month on top of E3, bundling four Defender products | Most of the E5 security value without the full E5 price jump |
| Microsoft 365 E5 | The full suite at $60 per user per month, security included | Justified by the whole suite, never by security alone |
| Defender Plan 1 and Plan 2 | Same products, different response depth | Teams that justify Defender at all usually need Plan 2 |
| Microsoft Sentinel | Consumption: ingestion and analytics per gigabyte | Budgeted apart from seats and controlled by data routing |
| Capabilities inside existing seats | Already paid for | The most common double purchase in security licensing |
What does E3 already include?
Microsoft 365 E3, listed at $39 per user per month since July 1, 2026, carries Defender for Endpoint Plan 1, Defender for Office 365 Plan 1 and Entra ID P1. Defender for Office 365 Plan 1 came into E3 with that price change. Any standalone Plan 1 bought for E3 users is now a duplicate.
So on E3 you never price Defender from zero. You price the step from Plan 1 to Plan 2, plus what E3 lacks: Defender for Identity, the full Defender for Cloud Apps and Entra ID P2.
How does the Defender Suite compare with full E5?
The Defender Suite, as E5 Security is now sold, costs $12 per user per month on top of Microsoft 365 E3 (or Office 365 E3 with EMS E3). It carries the four Defender products (Endpoint Plan 2, Office 365 Plan 2, Identity, Cloud Apps) plus Entra ID P2 and the Defender XDR portal.
E3 plus the suite comes to $51 a month. Full E5 at $60 adds Purview compliance, Power BI Pro, Teams Phone and Security Copilot for the extra $9, so buy it for those workloads. Our E5 Security upgrade analysis and Defender Suite guide go further.
5 Tips for Your Microsoft Negotiation
When does E5 Security beat buying Defender products separately?
The bundle wins when a user needs three or more Defender products you would otherwise buy separately. Below three, standalone plans on top of E3 cost less. Do the count for each group of users with similar exposure, because the answer for your SOC analysts differs from the answer for your warehouse staff.
- Three or more products justified. Buy the Defender Suite for that tier.
- One or two products justified. Buy standalone plans on top of E3 for that tier.
- Count Entra ID P2 as well. It lists at $10 a month on its own, so a tier that needs Privileged Identity Management plus one Defender product is already past the $12 suite price.
Which Microsoft rules limit how far you can tier?
Not every Defender product splits cleanly by user. These rules decide which products can follow a tier and which follow the whole tenant.
- Defender for Endpoint. Licensed per user, with up to five concurrent onboarded devices each. Plan 1 and Plan 2 can run side by side: you tag devices "License MDE P1", or set a dynamic rule, so each device gets the capabilities its user paid for.
- Defender for Office 365. Every user who accesses a protected mailbox needs a license, and so does every protected shared mailbox. If Safe Attachments is on for SharePoint, OneDrive or Teams, every user of those services needs one. Policies can be scoped to licensed users.
- Defender for Cloud Apps. A tenant level service, switched on for everyone by default, which you can scope to licensed users.
- Defender for Identity. Licensed per user but delivered at tenant level, and Microsoft lists it among services that cannot limit the benefit to specific users. In practice you price it for everyone the sensors watch, or not at all.
What does tiering look like for a 4,000 user E3 company?
Say you run 4,000 users on Microsoft 365 E3, and the renewal proposal puts the Defender Suite on every seat. Your alert history sorts the users into three exposure tiers. The table prices both options at list.
| Tier | Users | What they get | Annual cost at list |
|---|---|---|---|
| Tier A: admins, finance approvers, executives | 400 | Defender Suite at $12 | $57,600 |
| Tier B: office staff with mailbox and SaaS exposure | 2,400 | Defender for Office 365 Plan 2 at $5 | $144,000 |
| Tier C: low exposure users with no privileged access | 1,200 | E3 baseline only (Plan 1 protection) | No added cost |
| Tiered total | 4,000 | Mixed | $201,600 |
| Uniform proposal | 4,000 | Defender Suite on every seat at $12 | $576,000 |
The tiered design costs $374,400 a year less, unless you run Defender for Identity. Under the tenant rule, that means licensing the 3,600 users in tiers B and C too. Spread over 3,600 users and 12 months, Identity would have to cost more than about $8.67 per user per month before the uniform suite came out cheaper.
Microsoft no longer publishes standalone prices for Defender for Endpoint Plan 2, Defender for Identity or Defender for Cloud Apps, so take those from your reseller quote before you fix the tiers.
Microsoft Security Licensing, Unbundled
The Defender product map, the bundle comparison and the tiering model in one white paper.
Get the white paper →Which user groups need Defender Plan 2 instead of Plan 1?
If a group of users justifies Defender at all, it usually needs Plan 2. Plan 1 prevents and blocks. Plan 2 adds the investigation and response depth that a security operations team works with every day, so the Plan 1 saving tends to reopen the bundle question.
What does Plan 2 add over Plan 1?
- Defender for Endpoint Plan 2. Endpoint detection and response, automated investigation and remediation, advanced hunting and threat analytics. Plan 1 stops at next generation antivirus, attack surface reduction rules, device control and manual response actions. Our Plan 1 and Plan 2 comparison covers the detail.
- Defender for Office 365 Plan 2. Threat Explorer, automated investigation and response, and attack simulation training, on top of the Safe Links, Safe Attachments and phishing protection in Plan 1.
Why we advise against moving users down to Plan 1 to save money
A common recommendation is to shift part of the population from Plan 2 to Plan 1 and bank the difference. We think that cuts in the wrong place. If a user needs Plan 2 depth, the downgrade removes what your SOC uses; if not, take the product off that tier and keep the E3 baseline.
The Plan 1 compromise also muddles the three plus count. A tier with three products at Plan 1 still has three products, and you are back to pricing the suite. Hold the Plan 2 line where Defender is justified, and remove the deployment where it is not.
Why does security licensing follow the org chart instead of the threat?
Because security is bought once for everyone and then renewed without review, which no other Microsoft workload gets away with. Unused Visio seats get culled, Power BI Pro gets tiered, and the E5 mix gets audited at a large renewal. Security deploys uniformly, renews automatically and only grows, since no one wants to have removed protection before the breach.
That reluctance is priced into the proposal. E5 Security for everyone on E3 is easy to administer and hard to justify, because threat exposure is the least uniform property in a company. A domain admin, a finance approver and a kiosk account face different adversaries, yet a uniform rollout bills them the same. The cost builds up in three places:
- The bundle seat. An unnecessary suite seat costs more than the one standalone product the user needed.
- The renewal block. The renewal carries the whole population forward as one quantity, so the overbuy repeats every term.
- The second purchase. A different budget holder buys a capability standalone that already sits inside existing seats, because they never saw the entitlement map.
The fix is to license security the way your security program already manages everything else, by risk tier. Protection does not get weaker. Spend shifts from seats that never alert to the controls that do.
How do you find security seats that never produced an alert?
Lay twelve months of Defender alerts, grouped by user, against the license assignment for the same users. Users who hold a suite seat but appear in no alert your analysts worked are the candidates for a lower tier. Few licensing questions come with their own telemetry, and your SOC's console already holds this one.
Where does the data live?
- Alerts by user. The Defender portal keeps incidents and alerts for 180 days, and advanced hunting reaches back 30 days. For a full year, connect Defender XDR alerts to Sentinel or export them through the Microsoft Graph security API each quarter. Within the 30 day window, the AlertInfo and AlertEvidence tables give the user behind each alert.
- Alerts worth a response. Count alerts your analysts classified as true positive, or incidents that were assigned and worked. Informational and false positive alerts do not count.
- License assignment. Export it from the Microsoft 365 admin center, or pull it per user with Get-MgUserLicenseDetail in Microsoft Graph PowerShell.
- Endpoint license use. Settings, Endpoints, Licenses in the Defender portal shows assigned Defender for Endpoint licenses, based on users seen on onboarded devices.
- The entitlement map. List the Defender capabilities inside each seat type you own (E3, E5, the suite, Windows Enterprise E5, standalone plans) before anyone approves a new purchase.
How should you read an empty alert history?
An empty history does not mean the user was unprotected or that the product failed. Phishing blocked and malware stopped at the Plan 1 layer often never become alerts an analyst works. What it does show is that the Plan 2 investigation and response layer did no work at that desk for a year.
That is the question the licensing decision turns on. Use the result to place users in tiers, and repeat the comparison every year before renewal so users move between tiers in both directions as their roles change.
Where does Microsoft Sentinel fit in the threat protection budget?
Sentinel belongs on its own budget line. It bills on consumption for data ingestion and analytics per gigabyte, while Defender bills per user. The two are managed in different ways, and when they share one budget line, both tend to get overbought.
Architecture controls the Sentinel bill: which sources you connect, which tables go to the analytics tier and which go to cheaper storage. The ingestion tuning covered in our Sentinel pricing brief cut the meter by 25 to 45 percent, and the Sentinel optimization guide covers the routing work.
- Where seats touch the meter. E5 and E5 Security users bring a data grant of up to 5 MB per user per day for named Microsoft data types.
- What is free regardless. Alerts from Defender products ingest at no charge for every Sentinel customer, which is why streaming them for the alert review costs little.
What have our security licensing reviews shown from 2024 to 2026?
Across the E3 and E5 customers we reviewed from 2024 to 2026, wherever security was rolled out uniformly, more than a third of E5 Security seats sat on users who never generated a Defender alert worth a response. That is the largest recoverable line in the security budget.
The cause is licensing by org chart rather than by threat model. Three patterns recurred:
- Uniform rollouts. E5 Security on every E3 seat, covering populations with very different exposure.
- Duplicate standalone buys. Defender plans purchased separately for users whose E5 seats already contained them.
- Sentinel inside the seat discussion. The per gigabyte meter was budgeted and negotiated alongside per user seats, where it does not belong.
A seat whose user generated no Defender alert worth a response in a year is a seat licensed to a threat that did not materialize at that desk.
What will the Microsoft account team say, and how should you answer?
Expect the renewal proposal to price the Defender Suite on every E3 seat. These are the lines we hear most, with replies that hold up.
- "The suite for everyone is simpler and cheaper per product." Only for users who need three or more products. Show the per tier count and ask for a quote on tiered quantities.
- "Defender for Identity covers the whole tenant anyway, so take the suite." Identity is tenant wide, but it is one product. Price it alone for everyone and buy the suite only for tiers that need the rest.
- "E5 is only $9 more than E3 plus the suite." That $9 per user per month pays for Purview, Power BI Pro, Teams Phone and Security Copilot. Take E5 only where those are in use.
- "Add a Sentinel commitment to this deal for a better overall discount." Size Sentinel from 30 days of billed ingestion and keep it out of the seat negotiation.
Which contract terms should you ask for?
- Separate lines per SKU. The suite, each standalone plan and E5 as separate quantities, so a change in one tier does not reprice the others.
- A price hold for the term. Cover the suite and every standalone Defender plan, so you can move users between tiers at the price you signed.
- A reduction right at each anniversary. Ask for it in writing, because the annual alert review will move users down as well as up.
- A conversion right. Permission to convert suite quantities into standalone Defender for Office 365 Plan 2 during the term when a tier's needs shrink.
What to do next
- Twelve months before renewal. Export the 180 days of alerts the Defender portal already holds, then keep collecting by user so you have a full year by the six month mark.
- Nine months before. Build the entitlement map of what already sits inside each seat type, and stop any standalone security purchase that duplicates it.
- Six months before. Lay the year of alerts against the license assignment, tier the population by exposure, and apply the three plus rule per tier.
- At the same review. Keep Plan 2 where Defender is justified, and take the product off tiers where it is not instead of downgrading the plan.
- Three months before. Get reseller quotes for the standalone plans Microsoft no longer lists, rerun the worked example with your numbers, and put tiered quantities and contract terms to the account team.
- Every budget cycle. Keep Sentinel on its own line, governed by ingestion architecture, and hold the seat and meter negotiations apart. Our Microsoft advisory team runs both with you, and the Microsoft knowledge hub holds the wider library.
Frequently asked questions
How is Microsoft threat protection licensed in 2026?
Through the Defender family, sold as standalone per user plans or inside Microsoft 365 E5 and the E5 Security add on. E3 already carries the Plan 1 tiers of Defender for Endpoint and Defender for Office 365, so most decisions concern Plan 2 and the products E3 lacks.
What is in E5 Security?
The E3 add on bundles Defender for Endpoint Plan 2, Defender for Office 365 Plan 2, Defender for Identity and Defender for Cloud Apps, plus Entra ID P2. It delivers most of the E5 security value for $12 a month, against a $21 gap between E3 and E5 at list.
Is Microsoft 365 E5 Security the same as the Microsoft Defender Suite?
Yes. Microsoft now sells the former E5 Security add on as the Microsoft Defender Suite at $12 per user per month, still requiring Microsoft 365 E3 or Office 365 E3 with EMS E3. Older agreements and some quotes keep the old name.
When does E5 or E5 Security beat standalone Defender?
When a user group would otherwise buy three or more Defender products separately, with Entra ID P2 counted as one of them. Full E5 beats E3 plus the suite only for groups that also use its compliance, analytics and voice workloads. For one or two products, standalone plans on E3 cost less.
Do you need Defender Plan 1 or Plan 2?
Most security teams that justify Defender at all need Plan 2, where detection and response, automated investigation and hunting sit. Defender for Endpoint allows mixed plans in one tenant, with devices tagged for Plan 1. Buying Plan 1 to save money usually reopens the bundle question.
Where does Microsoft Sentinel fit in the threat protection cost model?
Sentinel is the cloud SIEM, billed per gigabyte ingested and analyzed. It pairs with Defender, but budget it apart from the seats and control it through ingestion architecture. E5 users bring a small free allowance for certain Microsoft log types.
How do you find over licensed security seats?
Match a year of Defender alerts your analysts worked, grouped by user, against the license list. Suite seats with no worked alert go to review. Because the portal keeps alerts only 180 days, start exporting at least a year before renewal.
How do you avoid double paying for Microsoft security capabilities?
Map which users need each Defender product before renewing, and list what their existing seats contain, including Windows Enterprise E5. Capabilities inside an E5 seat are often bought again standalone by another budget holder, so share the map with every team that buys security tools.