Defender Portfolio
Microsoft Industry Solutions · Security Portfolio Briefing

The Microsoft Defender Portfolio

What each product actually does — and which license carries it. Every Defender SKU sorted into the three buying motions that customers actually purchase through: user-licensed, resource-metered, and asset-metered.

3
Buying Motions
20+
Products & Plans
5
Capability Domains
10
Workload Plans
5
Costly Mistakes
01
User-licensed
Per user / per month
Rides on Microsoft 365 SKUs. Endpoint, Office 365, Identity, Cloud Apps and XDR all sit here.
Bought with M365 seats
02
Resource-metered
Per resource / per hour
Defender for Cloud and its workload plans. Billed on the Azure subscription — never on an M365 seat.
Bought in Azure
03
Asset-metered
Per device or per site
Defender for IoT for OT and unmanaged network devices, plus external attack surface assets.
Bought per asset
01🧭
The Mental Model
Three families · Three ways of paying

Nearly every Defender licensing mistake comes from confusing three buckets. The portfolio looks sprawling until you sort it by how it is purchased rather than by what it protects — at which point it collapses into three clean families.

FamilyBuying unitWhere it is billedWhat lives here
User-licensed Per user / month Microsoft 365 seat Endpoint P1 · P2, Office 365 P1 · P2, Defender for Identity, Defender for Cloud Apps, Defender XDR
Resource-metered Per resource / hour Azure subscription Defender CSPM, Defender for Servers P1 · P2, and every workload plan
Asset-metered Per device or per site Azure resource / device entitlement Defender for IoT (OT and Enterprise), Defender EASM
🧠
The one question that resolves most confusion: "Is this bought on a seat, on an Azure meter, or per asset?" Answer that first, and the rest of the conversation — entitlement, true-up, renewal, ownership — follows from it. Two products that protect adjacent things are frequently in different families.
⚠️
Licensing terms move. Inclusions, plan names and regional availability change on Microsoft's schedule, not yours. Treat this page as a briefing map — validate current entitlement against the Microsoft licensing terms and your own agreement before you commit to a design or a purchase.
02🗂️
The Full Menu
Every Defender product, on one table

Five capability domains, three ways of paying. Take the whole spread, or walk straight to the one that matters to you.

Endpoint & Device
Defender for Business User
AV, EDR and ASR simplified for organisations up to 300 seats.
Defender for Endpoint P1 User
Next-gen AV, attack surface reduction, web and device control.
Defender for Endpoint P2 User
Everything in P1 plus EDR, auto-remediation and advanced hunting.
Vulnerability Management Add-on
Security baselines, firmware and certificate assessment.
Email & Collaboration
Defender for Office 365 P1 User
Safe Links and Safe Attachments across SharePoint, OneDrive and Teams, plus impersonation anti-phishing. Included natively in E3.
Defender for Office 365 P2 User
Threat Explorer, campaign views, automated investigation and response, attack simulation training, priority accounts.
Not the same as Endpoint
Office 365 protects the message and the inbox. Endpoint protects the machine. Bought independently.
Identity & SaaS
Defender for Identity User
Identity infrastructure detection: lateral movement, credential abuse, Kerberos attacks, insider activity.
Defender for Cloud Apps User
CASB — shadow IT discovery, SaaS posture, session controls, DLP and OAuth app governance.
Defender XDR No SKU
Activates on the underlying Plan 2 licenses and unifies Defender and Sentinel signal in one portal.
Cloud & Workloads
Defender CSPM Azure
Attack paths, the cloud security graph and agentless posture across Azure, AWS, GCP and on-prem.
Defender for Servers P1 · P2 Azure
P1 is Endpoint P2 delivered to servers. P2 adds agentless scanning, FIM, JIT access and compliance.
Workload plans Azure
Storage · SQL · Containers · App Service · Key Vault · DNS · Resource Manager · OSS DBs · APIs · AI services.
Device, OT & Exposure
Defender for IoT — OT Asset
Passive, protocol-aware monitoring for industrial control environments where no agent can run.
Defender for IoT — Enterprise Asset
Unmanaged devices on the corporate LAN: printers, cameras, VoIP handsets, building systems.
Defender EASM Asset
Maps your internet-facing and shadow assets from the outside in. Metered per discovered asset.
🍽️
On every plate: Microsoft Defender Antivirus is built into Windows — it is free, and it is not Defender for Endpoint or an EDR SKU.
03👤
What You Get on a Microsoft 365 Seat
Family 01 · User-licensed

Six products, one bundle. Together these form the Microsoft Defender Suite — the add-on that lifts an E3 estate to E5-level Defender coverage without moving the whole seat.

💻Endpoint P1
Next-gen AV, attack surface reduction, web & network protection, device control, manual response.
🛡️Endpoint P2
Everything in P1 plus full EDR, automated investigation & remediation, advanced hunting, sandboxing.
✉️Office 365 P1
Safe Links, Safe Attachments across SharePoint / OneDrive / Teams, impersonation anti-phishing.
🔍Office 365 P2
Threat Explorer, campaign views, attack simulation training, priority account protection.
🪪Defender for Identity
On-prem Active Directory threat detection: lateral movement, credential abuse, insider actions.
☁️Defender for Cloud Apps
CASB — shadow IT discovery, SaaS posture, session controls, DLP across sanctioned apps.
The practical shape of this family: it is bought and renewed by whoever owns the Microsoft 365 agreement — not by the Azure subscription owner. If your security team's budget sits on the Azure side, this is the family they cannot buy themselves.
04💻
The Endpoint Ladder
Pick a rung, not a product

P1, P2 and the add-on stack. Defender for Business is a different route to the same job — not a rung on the ladder.

Increasing capability
SMB Track
Defender for Business
Simplified AV, EDR and ASR tuned for organisations up to 300 employees.
Prevention
Endpoint Plan 1
Next-gen AV, ASR rules, web and network protection, device control, manual response.
Prevention + EDR
Endpoint Plan 2
Adds EDR, device discovery, automated investigation and remediation, advanced hunting, threat analytics.
Add-on
Vulnerability Mgmt
Browser extension, firmware and certificate assessment, security baselines, blocking of vulnerable apps.
🪜
Defender for Business and Endpoint P1/P2 are alternatives, not cumulative purchases. The ladder itself is strictly cumulative — each tier is a superset of the one below — but the SMB track sits beside it, not underneath it.
05🌐
Coverage & Delivery
Two questions every room asks

"Is this Windows-only?" and "who watches it at 2am?" Both have answers, and neither is a new SKU decision.

🌍 Every platform, one license
Endpoint P1 and P2 cover the whole estate
  • Windows client and Windows Server
  • macOS
  • Linux server distributions
  • iOS and Android
  • Servers anywhere via Azure Arc
👁️ Defender Experts
Microsoft runs it when you cannot
  • Experts for Hunting — proactive hunting on your data
  • Experts for XDR — managed detection and response
  • Microsoft analysts triage and respond in your tenant
  • Expert consultation from inside the portal
  • A separate managed service — not bundled into E5
💬
The short answers: platform coverage costs nothing extra — it is the same endpoint license. Defender Experts is bought separately, as a service.
06✉️
Defender for Office 365
Where the line falls between P1 and P2

Plan 1 stops the message. Plan 2 tells you what happened, hunts the rest, and trains the user.

Plan 1 Protect
Stop it at the door
  • Safe Links — time-of-click URL rewriting
  • Safe Attachments — detonation sandbox
  • Coverage for SharePoint, OneDrive & Teams
  • Impersonation-based anti-phishing
  • Real-time detections view
Plan 2 Protect + investigate + train
Everything in Plan 1, plus
  • Threat Explorer & Threat Trackers
  • Campaign Views
  • Automated Investigation & Response
  • Attack Simulation Training
  • Priority account protection + XDR integration

Licensing shifted

💰
Since 1 July 2026, Defender for Office 365 P1 is included natively in Office 365 E3 and Microsoft 365 E3.

Older guidance says E3 carries Exchange Online Protection only. If you are paying for standalone P1 alongside E3, that spend can be retired — audit for it.

Business Premium has always carried Plan 1. Plan 2 arrives with E5, A5, G5, F5 Security, or the Defender Suite add-on.

07🪪
Identity & SaaS
The two blind spots endpoint tooling misses

The attacker moves through identity and lands in SaaS. Neither shows up in an EDR console.

🪪 Defender for Identity
Signal source: identity infrastructure sensors
  • Detects lateral movement across Active Directory
  • Surfaces credential abuse and Kerberos attacks
  • Flags compromised identities in near real time
  • Highlights risky insider actions
  • Feeds identity signal directly into XDR incidents
☁️ Defender for Cloud Apps
Signal source: proxy, API connectors, logs
  • Shadow IT discovery across sanctioned & unsanctioned apps
  • SaaS security posture management
  • Session controls via Conditional Access App Control
  • DLP applied consistently across SaaS
  • App governance for OAuth consent risk
🛒
How you buy both: included in Microsoft 365 E5, or in the Defender Suite add-on to E3. Neither is sold on an Azure meter.
08🔗
Defender XDR — The Connective Tissue
Not a purchase, but the payoff

No separate SKU. It activates when you hold the underlying Plan 2 licenses — and it is where Defender and Sentinel now converge.

EndpointDevice signal
EmailMessage signal
IdentityDirectory signal
SaaSApp signal
Defender XDR
Unified portal · Defender + Sentinel
Correlated incidentsAlerts from every signal domain collapse into one attack story.
Automatic attack disruptionContains compromised assets in flight, before the analyst reads the alert.
Single hunting surfaceOne KQL schema across endpoint, identity, email, SaaS and Sentinel.
🎯
One incident queue. Defender and Sentinel now sit behind a single portal and data lake. The commercial point is that XDR is what the Plan 2 licenses were for — a customer holding P2 across domains and still triaging in four consoles is paying for a capability they have not switched on.
09☁️
Defender for Cloud
Family 02 · Resource-metered · The Azure side of the house

A CNAPP spanning Azure, AWS, GCP and on-prem. Billed per resource — it is not in any Microsoft 365 SKU.

📐 CSPM — Posture
Know what is exposed
  • Attack path analysis
  • The cloud security graph
  • Agentless scanning
  • Multicloud posture across Azure, AWS, GCP

A free foundational tier carries Secure Score — Defender CSPM is the paid tier above it.

🛡️ CWPP — Workload protection
Detect what is happening
  • Threat detection delivered per workload type
  • You enable only the plans matching the resources you actually run
  • Each plan is switched on and billed independently

Workload plans you turn on individually

ServersStorageSQL ContainersApp ServiceKey Vault DNSResource ManagerOpen-source DBs APIs
🔭
Also in this family: Defender EASM, which maps your internet-facing and shadow assets from the outside in — metered by discovered asset rather than by resource-hour.
10🖥️
Defender for Servers
Plan 1 versus Plan 2

Plan 1 is essentially Endpoint P2 delivered to servers. Plan 2 is where the cloud-native capability lives.

Plan 1 Entry tier
EDR on servers, and nothing more

Endpoint Plan 2 EDR, integrated into Defender for Cloud and delivered to the server estate — Azure, AWS, GCP and on-prem via Arc.

Choose Plan 1 when you need EDR coverage on servers and nothing more — posture, compliance and scanning are handled elsewhere.

Plan 2 Everything in Plan 1, plus
The cloud-native capability
  • Agentless machine scanning
  • Vulnerability assessment
  • Agentless malware scanning
  • Regulatory compliance
  • File integrity monitoring
  • Just-in-time VM access
  • OS baseline & update assessment
  • Agentless secrets scanning
  • Free data ingestion benefit
  • Network-layer threat detection
🔁
The overlap that surprises people: Servers Plan 1 delivers Endpoint Plan 2 capability, but it is bought on an Azure meter — not on an M365 seat. Two different families can put the same EDR on the same machine. Decide deliberately which one owns your servers.
11🏭
The Estate Nobody Has an Agent On
Family 03 · Asset-metered · Device, OT & exposure

Unmanaged, unmanageable and usually unmonitored — priced by device or by site, not by user.

ProductHow it is licensedWhat it covers
Defender for IoT — OT Per site or per device Passive network monitoring for OT and ICS environments. Protocol-aware detection for industrial control systems where you cannot install an agent.
Defender for IoT — Enterprise Entitlement rides on your Defender licensing — confirm device allowance Unmanaged network devices sitting inside the corporate LAN — printers, cameras, VoIP handsets, building systems.
Defender EASM Azure resource, metered per discovered asset Continuously discovers and maps your internet-facing attack surface, including shadow assets outside the known estate.
🏭
Why this family exists at all: the buying unit follows the thing being protected. You cannot put a user license on a turbine controller or a badge reader, so the meter moves to the asset. That also means the budget usually sits with a different team — often OT engineering rather than IT security.
12🗺️
Portfolio Overview
Every product fits one of three buying motions

A complete capability map — grouped by the SKU channel customers actually buy through.

M365 SKUs · User-licensed

Per user / month · Suite + standalone plans

Endpoint + Device
Defender for Business · Endpoint P1 · P2 · Vulnerability Management
Email + Collaboration
Office 365 P1 · P2
Identity + SaaS
Defender for Identity · Defender for Cloud Apps
Unified SecOps
Defender XDR — activates on qualifying underlying Plan 2 licenses
Azure SKUs · Defender for Cloud

Per resource / hour · Enable plans individually

Posture
Defender CSPM
Workload protection plans
Servers P1 · P2 · Storage · SQL · Containers · App Service · Key Vault · DNS · Resource Manager · Open-source DBs · APIs
Exposure
Defender EASM — metered by discovered asset
Device / Site · Asset-metered

Buying unit: per site or per device

OT + Industrial Control
Defender for IoT — OT
Enterprise Network
Defender for IoT — Enterprise
🧱
Foundation: Microsoft Defender Antivirus is built into Windows — it is not a Defender for Endpoint or EDR SKU.
13🧾
Which Bundle Carries Which Product
Putting it together

The single table most licensing conversations are really asking for.

Defender product BusinessPremium Microsoft365 E3 Defender Suiteadd-on to E3 Microsoft365 E5 Microsoft365 E7
Defender for Business
Defender for Endpoint P1
Defender for Endpoint P2
Defender for Office 365 P1
Defender for Office 365 P2
Defender for Identity
Defender for Cloud Apps
Defender XDR
Defender for Cloud (Azure)
Included Not included — buy separately
📌
Three footnotes that carry the table:
  • Endpoint P2 supersedes P1 wherever both appear.
  • E3 gained Defender for Office 365 P1 on 1 July 2026.
  • E7 is a superset of E5 — Defender content stays at E5 level.
🔍
Verify before you commit. This matrix reflects the portfolio as reviewed in August 2026. Bundle inclusions are the most volatile part of the whole portfolio — confirm against current Microsoft licensing terms and the customer's own agreement before it becomes a commercial commitment.
14⚠️
Field Notes
Five things that cost customers money

Every one of these has shown up in a real licensing conversation.

1
Defender Antivirus is not Defender for Endpoint

The in-box Windows AV is free and is not an EDR product. Customers conflate these constantly — and then believe they already have coverage they have never bought.

2
Defender for Cloud is not in E5

"We're E5, so Azure is covered" is wrong. Cloud workload protection is metered separately in Azure, on the subscription — not on the seat.

3
Office 365 P1 now ships with E3

Standalone P1 purchased alongside E3 became redundant on 1 July 2026. Audit for it — this is money currently being spent twice.

4
Agent protection moved to Agent 365

AI-agent protection is now per-user licensed regardless of platform. Non-agent AI infrastructure stays pay-as-you-go.

5
Sovereign cloud parity lags

In GCC High, G5 maps to the P2 tier, but several Cloud and IoT plans are unavailable. Validate per plan before you commit.

🛑
The one habit that prevents all five: validate current plan availability in your target cloud, and current entitlement in the customer's own agreement, before committing to a design. Portfolio maps age; licensing terms move underneath them.