Microsoft Defender for Endpoint: A Complete Guide for IT Teams
Microsoft Defender for Endpoint is Microsoft’s enterprise endpoint protection platform, split into Plan 1, prevention-focused, and Plan 2, which adds full EDR, bundled differently across Microsoft 365 licence tiers. If you have assumed your organization’s licence already includes genuine EDR capability, that assumption is worth checking directly before an incident forces the question.
What Is Microsoft Defender for Endpoint?
Microsoft Defender for Endpoint is Microsoft’s enterprise endpoint security platform, combining next-generation antivirus, attack surface reduction and, at its higher tier, full endpoint detection and response. It integrates directly with the broader Microsoft security ecosystem, Defender for Office 365, Defender for Identity, and Defender XDR.
The platform splits into two distinct plans with a genuinely significant capability gap between them, not simply a price difference, making understanding that gap essential before assuming either tier covers what your organization actually needs.
Plan 1 vs Plan 2: The Real Feature Gap
| Capability | Plan 1 | Plan 2 |
| Next-gen antivirus | Yes | Yes |
| Attack surface reduction | Yes | Yes |
| Full EDR | No | Yes |
| Automated investigation | No | Yes |
| Advanced hunting | No | Yes |
Plan 1 covers next-generation antivirus with cloud-delivered protection and attack surface reduction rules, genuine endpoint hardening and prevention capability. Plan 2 adds what Plan 1 structurally lacks entirely: full endpoint detection and response, automated investigation and remediation, advanced hunting queries and threat analytics.
This is the single most important fact worth stating plainly. Plan 1 does not include EDR at all. Organizations assuming Plan 1 provides detection and response capability, simply at a lighter tier than Plan 2, are working from a mistaken assumption. Plan 2 specifically unlocks EDR, not an enhanced version of something Plan 1 already partially provides.
Which Microsoft 365 Licence Includes Each Plan?
Plan 1 comes included with Microsoft 365 E3. Plan 2 comes included with Microsoft 365 E5, and separately with Windows Enterprise E5 and A5 licensing. Both plans are also available as standalone licences outside any bundled Microsoft 365 tier, priced at $3 per user monthly for Plan 1 and $5.20 per user monthly for Plan 2 at list.
A genuinely current update matters directly here. Following a Microsoft 365 packaging change rolling out through July and August 2026, Defender for Office 365 Plan 1 was added to Microsoft 365 E3, previously requiring a separate add-on or a full E5 upgrade. This improves E3’s baseline security capability meaningfully, though it does not change Defender for Endpoint’s own P1/P2 split, E3 still lacks full endpoint EDR regardless of this specific email security addition.
What Does This Cost, and Where Does Plan 2 Get Over-Bought?
Real benchmark data across roughly 35 to 45 Microsoft security estates studied between 2024 and 2025 identified a consistent, costly pattern: applying Plan 2 uniformly to every single user, rather than aligning licence tier to genuine role-based need, was the single largest waste pattern found.
Persona-aligned licensing, giving Plan 2 specifically to users whose roles genuinely warrant full EDR monitoring, and Plan 1 to lower-risk roles, cut the Defender licensing line by 20 to 30 percent compared to a flat, uniform Plan 2 deployment across an entire estate. A separate, equally telling finding cuts the other direction: roughly 55 to 65 percent of estates reviewed were running Plan 2-tier features on users only licensed for Plan 1, a genuine compliance gap in the opposite direction, using capability the organization was not actually paying for. Both patterns point to the same underlying fix: a genuine, role-based licensing audit, not simply defaulting every user to the highest available tier or assuming licence assignment automatically matches actual feature usage.
Are You Double-Paying for Server Protection?
Here is a more precise, honestly current finding worth stating directly rather than the simpler “double-paying” framing often assumed. The same benchmark research found server protection enabled without corresponding Defender for Servers licensing on roughly one in three estates reviewed, a genuine compliance and coverage gap, not primarily a double-payment problem.
Server workloads require separate licensing through Defender for Servers regardless of which Defender for Endpoint plan covers your standard user devices, priced per server rather than per user, typically around $15 per server monthly. The genuine risk many organizations face is not paying twice for the same server coverage, but assuming server protection is already included within their existing E3 or E5 endpoint licensing when it structurally is not, leaving servers running with a false sense of coverage that a licensing audit specifically needs to catch.
Is the E5 Security Step-Up Worth It for Your Organisation?
For organizations already on E3 with roughly 300 to 2,000 seats, the E5 Security add-on, priced around $12 per user monthly, typically delivers better value than purchasing standalone Plan 2 alone, since the same bundle also includes Defender for Office 365 Plan 2, Defender for Identity and Cloud App Security together.
Organizations exceeding 2,000 seats with a genuinely functioning security operations capability more commonly need the full XDR suite outright, where unified alert correlation across every Microsoft security signal has been found by Gartner’s own 2024 Market Guide for XDR to reduce mean time to respond by an average of 48 percent compared to operating siloed, disconnected security tools. Run the specific bundle math directly against your own reseller quote before committing to standalone SKUs, since assembling equivalent coverage piece by piece frequently costs more than the E5 Security bundle covering the same ground in one purchase.
A Practical Audit Process for Your Own Tenant
Start by exporting your current licence assignment list directly from the Microsoft 365 admin center, confirming exactly which users hold Plan 1 versus Plan 2 today. Cross-reference actual feature usage against that assignment, identifying users running Plan 2-tier capability without corresponding licensing, and users licensed for Plan 2 who genuinely never use EDR-specific features at all.
Confirm server workloads separately, verifying Defender for Servers licensing exists everywhere server-level protection is actually enabled. Cyber Security Solutions Ltd runs exactly this audit process for clients directly, since the specific mismatches this benchmark data identifies, flat over-licensing in one direction, unlicensed feature usage in the other, both represent real, fixable cost and compliance exposure most organizations have never formally reviewed.
What About Smaller Organisations on Business Premium?
Microsoft 365 Business Premium does not include Defender for Endpoint at all. It includes Defender for Business instead, a genuinely solid, SMB-focused EDR and antivirus product, though with a meaningfully smaller feature set than either Enterprise-tier plan, particularly around the broader XDR capability enterprise organizations often need.
This distinction matters directly for smaller organizations evaluating whether their current licensing already covers genuine EDR capability. Business Premium customers do have real endpoint detection and response through Defender for Business specifically, just not through the Defender for Endpoint product line this guide has developed throughout.
Where Does This Sit Against UK Cyber Essentials?
NCSC’s Cyber Essentials scheme satisfies its malware protection requirement through baseline anti-malware software, application allow-listing, or sandboxing, meaning Plan 1’s next-generation antivirus alone genuinely meets this specific minimum requirement. Full EDR through Plan 2 is not currently mandated at any Cyber Essentials tier.
This means the Plan 1 versus Plan 2 decision should reflect genuine organizational risk, not compliance requirements alone, since Cyber Essentials certification does not depend on which specific Defender for Endpoint tier your organization runs.
Conclusion
Understanding the real gap between Plan 1 and Plan 2, and confirming your own licence assignment actually matches genuine usage, is worth far more than assuming your current Microsoft 365 tier already covers what your organization needs. Start with a direct export of your current licence assignments before your next renewal conversation.
FAQs
Plan 1 covers next-generation antivirus and attack surface reduction, prevention capability only. Plan 2 adds full endpoint detection and response, automated investigation and advanced hunting. Plan 1 does not include EDR at all, it is not a lighter version of Plan 2.
Microsoft 365 E5 includes Plan 2, alongside Windows Enterprise E5 and A5 licensing. Microsoft 365 E3 includes only Plan 1. Both plans are also available as standalone licences at $3 and $5.20 per user monthly respectively.
Benchmark research found applying Plan 2 uniformly to every user, rather than aligning tier to genuine role-based need, was the single largest waste pattern, with persona-aligned licensing cutting costs 20 to 30 percent against a flat Plan 2 deployment.
No. Servers require separate licensing through Defender for Servers, priced per server rather than per user. Research found roughly one in three estates had server protection enabled without this corresponding licence, a genuine compliance gap.
Often yes, for organizations with roughly 300 to 2,000 seats already on E3, since the bundle also includes Defender for Office 365 Plan 2, Defender for Identity and Cloud App Security together, typically beating the cost of assembling equivalent coverage separately.
No. Business Premium includes Defender for Business instead, a genuinely capable SMB-focused EDR and antivirus product, though with a smaller feature set than either Enterprise-tier Defender for Endpoint plan, particularly around broader XDR capability.
