More than a third of E5 Security seats never produced an alert worth responding to
Security licensing is the one part of the Microsoft estate bought on fear and renewed on inertia. The alert log is the usage report nobody reads: in our reviews, over a third of E5 Security seats sat on users who never generated a Defender alert worth a response.
Prepared by Redress Compliance · August 14, 2026 · Microsoft advisory. Security licensing reviews across E3 and E5 estates, 2024 to 2026.
Executive summary
More than a third of E5 Security seats sat on users who never generated a Defender alert worth a response. That is the signature of security licensed by org chart rather than by threat model, and it is the largest recoverable line in the security budget.
The structure is simple once separated: the Defender family sells standalone per user or bundled into E5 and E5 Security, and E5 Security is the E3 add on carrying Defender for Endpoint Plan 2, Defender for Office 365 Plan 2, Defender for Identity, and Defender for Cloud Apps.
The bundle math has one rule. E5 or E5 Security makes sense when you would otherwise buy three or more Defender products separately for the same user. Below that line, standalone wins.
Plan 2 is the real product. Most security teams that justify Defender at all need Plan 2 depth, so the Plan 1 saving usually reopens the bundle question instead of settling it.
Sentinel is a different bill entirely: consumption by ingestion, not per user, budgeted apart from the seats and controlled through architecture. Pairing them in one budget line is how both get overbought.
The stack, separated
| Product | How it licenses | Buyer note |
|---|---|---|
| Defender standalone plans | Per user, per product | An E3 estate can add only the pieces each user tier needs |
| E5 Security | E3 add on bundling four Defender products | Most of the E5 security value without the full E5 price jump |
| Microsoft 365 E5 | The full suite, security included | Justified by the whole suite, never by security alone |
| Defender Plan 1 vs Plan 2 | Response depth differs | Teams that justify Defender at all usually need Plan 2 |
| Microsoft Sentinel | Consumption: ingestion and analytics per gigabyte | Budgeted apart from seats; controlled by routing, not licensing |
| Capabilities inside existing seats | Already paid for | The most common double purchase in the security estate |
The three plus rule does the SKU work. Count the Defender products a user tier genuinely needs: at three or more, E5 Security earns its price; below three, standalone plans on E3 price better. The rule only works per tier, not per company, which is exactly why the uniform rollout fails it: the SOC needs the stack, the frontline workforce rarely does, and one SKU for both means someone is subsidizing someone.
The moves that right size the estate
- Read the alert log against the license assignment. A seat whose user generated no actionable Defender alert in a year is a seat licensed to a threat that did not materialize at that desk.
- Map users to Defender products by exposure tier, not by department, and apply the three plus rule per tier.
- Check what already sits inside existing seats before buying anything standalone, because capabilities inside an E5 seat are the most common double purchase.
- Hold the Plan 2 line where Defender is justified at all, and question the deployment rather than the plan level where it is not.
- Budget Sentinel separately and control it through ingestion routing, since its meter reads gigabytes, not users, and no seat decision moves it.
Microsoft security licensing, unbundled
The Defender product map, the E5 versus E5 Security versus standalone math, the alert log method, and the tiering model for the security estate.
Get the white paper →Security follows the org chart, threats do not
Every other Microsoft workload gets right sized eventually. Unused Visio seats get culled, Power BI Pro gets tiered, even the E5 mix gets audited when the renewal is large enough. Security is the exception: it deploys uniformly, renews automatically, and grows monotonically, because nobody wants to be the person who removed protection before the breach.
That asymmetry is priced in. The uniform rollout, E5 Security for everyone on E3, is administratively effortless and analytically indefensible, because threat exposure is the least uniform property in the company. A domain admin, a finance approver, and a frontline kiosk account do not face the same adversary, and licensing them identically means the kiosk is paying for the admin's threat model.
The alert log is where the truth sits, and it is the usage report nobody reads. A third or more of E5 Security seats producing no alert worth a response is not evidence the product failed. It is evidence the seat was assigned to a user whose exposure never required it, and unlike most licensing questions, this one has telemetry: the SOC's own console will tell you which seats earn their keep.
The economics compound quietly. The unnecessary bundle seat costs more than the standalone piece the user actually needed, the renewal carries the whole population forward as a block, and the capabilities already inside existing seats get bought again standalone by a different budget holder who never saw the entitlement map. Three small leaks, one direction.
The counter is to treat security licensing exactly like the security program treats everything else: by risk tier. Map exposure, apply the three plus rule per tier, hold Plan 2 where Defender is justified, and let the alert log arbitrate annually. Nothing about this weakens the security posture. It funds it, by moving spend from seats that never alert to the controls that do.
The consumption side of this estate, the Sentinel meter and the ingestion tuning that cut it 25 to 45 percent, has its own analysis in the Sentinel pricing brief. The wider position sits in the Microsoft practice.
Watch the briefing · 3:585 Tips for Your Microsoft NegotiationNever pick from the Multiple Equivalent Offers menu, right size before pricing, and split the stack so one workload never subsidizes another's optics.
- Percentile standing for your exact deal size and industry, from real closed transactions
- Scenario simulation before the call: test alternative terms and see the financial impact of each
- A negotiation playbook, talking points, and a two page executive brief on day one
What the security licensing reviews showed, 2024 to 2026
Across the E3 and E5 estates we reviewed, the same picture repeated wherever security had been rolled out uniformly:
E5 Security seats on users who never generated a Defender alert worth a response, the recoverable core of the security budget.
The standalone product count at which E5 Security starts earning its price, applied per exposure tier rather than per company.
Three patterns recurred. Uniform E5 Security rollouts covering populations with radically different exposure. Standalone Defender purchases duplicating capabilities already inside existing E5 seats. And Sentinel budgeted as part of the seat conversation, where its per gigabyte meter belongs to a different discipline entirely.
The buyer side move is to let the alert log arbitrate. The wider library sits in the Microsoft practice.
Your first five moves
- Pull twelve months of Defender alert data by user and lay it against the license assignment, because the gap between them is the finding.
- Tier the population by exposure, and apply the three plus rule per tier: bundle where three or more Defender products are justified, standalone below.
- Build the entitlement map of what already sits inside each seat type before approving any standalone security purchase.
- Keep Plan 2 where Defender is justified, and remove the deployment rather than downgrade the plan where it is not.
- Move Sentinel to its own budget line governed by ingestion architecture, and take the seat conversation and the meter conversation separately. The Microsoft practice runs both with you.
Frequently asked questions
How is Microsoft threat protection licensed in 2026?
Mainly through the Defender family, sold either as standalone plans per user or bundled into the Microsoft 365 E5 and E5 Security suites. You can buy a single Defender product or take the whole stack inside a larger M365 SKU.
What is in E5 Security?
E5 Security is an add on for E3 customers that bundles Defender for Endpoint Plan 2, Defender for Office 365 Plan 2, Defender for Identity, and Defender for Cloud Apps. It delivers most of the E5 security value without the full E5 price jump.
When does E5 or E5 Security beat standalone Defender?
When you would otherwise buy three or more Defender products separately for the same user. Below that line, an E3 estate adding only the pieces each user tier needs prices better than the bundle.
Do you need Defender Plan 1 or Plan 2?
Most security teams that justify Defender at all need Plan 2, which carries the investigation and response depth the operations program actually uses. Buying Plan 1 to save money usually re opens the standalone versus bundle question rather than settling it.
Where does Microsoft Sentinel fit in the threat protection cost model?
Sentinel is the cloud SIEM and is licensed separately by data ingestion and analytics, not per user. It pairs with Defender but its cost model is consumption based, so it is budgeted apart from the Defender seat licenses and controlled through ingestion architecture.
How do you find over licensed security seats?
Read the alert log against the license assignment. In our reviews more than a third of E5 Security seats sat on users who never generated a Defender alert worth a response, which is the signature of security licensed by org chart rather than by threat model.
How do you avoid double paying for Microsoft security capabilities?
Map which users need each Defender product before renewing, and check what already sits inside their existing seats. Capabilities already included in an E5 seat are commonly bought again standalone, and the map is what prevents it.
5 Tips for Your Microsoft Negotiation
Never pick from the Multiple Equivalent Offers menu, right-size before pricing, split the stack so Azure never subsidizes M365 optics, bring a calendar and a credible partial no, and convert the relationship into contract language.