The Microsoft Defender Portfolio
What each product actually does — and which license carries it. Every Defender SKU sorted into the three buying motions that customers actually purchase through: user-licensed, resource-metered, and asset-metered.
Nearly every Defender licensing mistake comes from confusing three buckets. The portfolio looks sprawling until you sort it by how it is purchased rather than by what it protects — at which point it collapses into three clean families.
| Family | Buying unit | Where it is billed | What lives here |
|---|---|---|---|
| User-licensed | Per user / month | Microsoft 365 seat | Endpoint P1 · P2, Office 365 P1 · P2, Defender for Identity, Defender for Cloud Apps, Defender XDR |
| Resource-metered | Per resource / hour | Azure subscription | Defender CSPM, Defender for Servers P1 · P2, and every workload plan |
| Asset-metered | Per device or per site | Azure resource / device entitlement | Defender for IoT (OT and Enterprise), Defender EASM |
Five capability domains, three ways of paying. Take the whole spread, or walk straight to the one that matters to you.
Six products, one bundle. Together these form the Microsoft Defender Suite — the add-on that lifts an E3 estate to E5-level Defender coverage without moving the whole seat.
P1, P2 and the add-on stack. Defender for Business is a different route to the same job — not a rung on the ladder.
"Is this Windows-only?" and "who watches it at 2am?" Both have answers, and neither is a new SKU decision.
🌍 Every platform, one license
- Windows client and Windows Server
- macOS
- Linux server distributions
- iOS and Android
- Servers anywhere via Azure Arc
👁️ Defender Experts
- Experts for Hunting — proactive hunting on your data
- Experts for XDR — managed detection and response
- Microsoft analysts triage and respond in your tenant
- Expert consultation from inside the portal
- A separate managed service — not bundled into E5
Plan 1 stops the message. Plan 2 tells you what happened, hunts the rest, and trains the user.
Plan 1 Protect
- Safe Links — time-of-click URL rewriting
- Safe Attachments — detonation sandbox
- Coverage for SharePoint, OneDrive & Teams
- Impersonation-based anti-phishing
- Real-time detections view
Plan 2 Protect + investigate + train
- Threat Explorer & Threat Trackers
- Campaign Views
- Automated Investigation & Response
- Attack Simulation Training
- Priority account protection + XDR integration
Licensing shifted
Older guidance says E3 carries Exchange Online Protection only. If you are paying for standalone P1 alongside E3, that spend can be retired — audit for it.
Business Premium has always carried Plan 1. Plan 2 arrives with E5, A5, G5, F5 Security, or the Defender Suite add-on.
The attacker moves through identity and lands in SaaS. Neither shows up in an EDR console.
🪪 Defender for Identity
- Detects lateral movement across Active Directory
- Surfaces credential abuse and Kerberos attacks
- Flags compromised identities in near real time
- Highlights risky insider actions
- Feeds identity signal directly into XDR incidents
☁️ Defender for Cloud Apps
- Shadow IT discovery across sanctioned & unsanctioned apps
- SaaS security posture management
- Session controls via Conditional Access App Control
- DLP applied consistently across SaaS
- App governance for OAuth consent risk
No separate SKU. It activates when you hold the underlying Plan 2 licenses — and it is where Defender and Sentinel now converge.
A CNAPP spanning Azure, AWS, GCP and on-prem. Billed per resource — it is not in any Microsoft 365 SKU.
📐 CSPM — Posture
- Attack path analysis
- The cloud security graph
- Agentless scanning
- Multicloud posture across Azure, AWS, GCP
A free foundational tier carries Secure Score — Defender CSPM is the paid tier above it.
🛡️ CWPP — Workload protection
- Threat detection delivered per workload type
- You enable only the plans matching the resources you actually run
- Each plan is switched on and billed independently
Workload plans you turn on individually
Plan 1 is essentially Endpoint P2 delivered to servers. Plan 2 is where the cloud-native capability lives.
Plan 1 Entry tier
Endpoint Plan 2 EDR, integrated into Defender for Cloud and delivered to the server estate — Azure, AWS, GCP and on-prem via Arc.
Choose Plan 1 when you need EDR coverage on servers and nothing more — posture, compliance and scanning are handled elsewhere.
Plan 2 Everything in Plan 1, plus
- Agentless machine scanning
- Vulnerability assessment
- Agentless malware scanning
- Regulatory compliance
- File integrity monitoring
- Just-in-time VM access
- OS baseline & update assessment
- Agentless secrets scanning
- Free data ingestion benefit
- Network-layer threat detection
Unmanaged, unmanageable and usually unmonitored — priced by device or by site, not by user.
| Product | How it is licensed | What it covers |
|---|---|---|
| Defender for IoT — OT | Per site or per device | Passive network monitoring for OT and ICS environments. Protocol-aware detection for industrial control systems where you cannot install an agent. |
| Defender for IoT — Enterprise | Entitlement rides on your Defender licensing — confirm device allowance | Unmanaged network devices sitting inside the corporate LAN — printers, cameras, VoIP handsets, building systems. |
| Defender EASM | Azure resource, metered per discovered asset | Continuously discovers and maps your internet-facing attack surface, including shadow assets outside the known estate. |
A complete capability map — grouped by the SKU channel customers actually buy through.
Per user / month · Suite + standalone plans
Per resource / hour · Enable plans individually
Buying unit: per site or per device
The single table most licensing conversations are really asking for.
| Defender product | BusinessPremium | Microsoft365 E3 | Defender Suiteadd-on to E3 | Microsoft365 E5 | Microsoft365 E7 |
|---|---|---|---|---|---|
| Defender for Business | |||||
| Defender for Endpoint P1 | |||||
| Defender for Endpoint P2 | |||||
| Defender for Office 365 P1 | |||||
| Defender for Office 365 P2 | |||||
| Defender for Identity | |||||
| Defender for Cloud Apps | |||||
| Defender XDR | |||||
| Defender for Cloud (Azure) |
- Endpoint P2 supersedes P1 wherever both appear.
- E3 gained Defender for Office 365 P1 on 1 July 2026.
- E7 is a superset of E5 — Defender content stays at E5 level.
Every one of these has shown up in a real licensing conversation.
Defender Antivirus is not Defender for Endpoint
The in-box Windows AV is free and is not an EDR product. Customers conflate these constantly — and then believe they already have coverage they have never bought.
Defender for Cloud is not in E5
"We're E5, so Azure is covered" is wrong. Cloud workload protection is metered separately in Azure, on the subscription — not on the seat.
Office 365 P1 now ships with E3
Standalone P1 purchased alongside E3 became redundant on 1 July 2026. Audit for it — this is money currently being spent twice.
Agent protection moved to Agent 365
AI-agent protection is now per-user licensed regardless of platform. Non-agent AI infrastructure stays pay-as-you-go.
Sovereign cloud parity lags
In GCC High, G5 maps to the P2 tier, but several Cloud and IoT plans are unavailable. Validate per plan before you commit.