Microsoft Defender for Office 365 (Plan 2) [New Commerce Experience]
Microsoft Defender for Office 365 (Plan 2)
Microsoft Defender for Office 365 Plan 2 contains everything in Plan 1 and adds the investigation and automation layer. That means attack simulation training for running controlled phishing exercises against your own staff, priority account protection, Threat Explorer and threat trackers in place of Plan 1's real-time detections, automated investigation and response, advanced hunting across Microsoft Defender XDR, incident and alert investigation, and the ability to remove users from Teams chats. It is included in Microsoft 365 E5, A5 and GCC G5. The standalone licence is for organisations on E3 or Business Premium that need the hunting and automation without moving the whole tenant to E5.
What it is
Microsoft Defender for Office 365 Plan 2 is the full email and collaboration security tier. Plan 1 protects and detects; Plan 2 adds the tooling to hunt, investigate and automate the response.
Who it is for
Organisations with someone who will act on the findings: a security team, or a provider running detection and response on their behalf. Also organisations that need to run phishing simulations against their own staff as part of an awareness programme.
Key capabilities
- Everything in Microsoft Defender for Office 365 Plan 1
- Attack simulation training, running controlled phishing simulations against your own users
- Priority account protection for the identities most likely to be targeted
- Threat Explorer and threat trackers, in place of Plan 1's real-time detections
- Automated investigation and response
- Advanced hunting in Microsoft Defender XDR, including hunting across Teams messages
- Incident and alert investigation in Microsoft Defender XDR
- Removing users from Teams chats as a response action
Check whether you already have it
Plan 2 is included in Microsoft 365 E5, A5 and GCC G5. The standalone licence is the route for tenants on Microsoft 365 E3 or Business Premium that want this capability without moving every user to E5. Compare the two before deciding, because on a large tenant the arithmetic can go either way.
The honest test before buying
Threat Explorer, advanced hunting and automated investigation all produce work. They assume a responder who will look. An organisation with nobody in that role gets more value from Plan 1 plus a managed service than from Plan 2 unattended.
A useful way to tell the plans apart
In the Microsoft Defender portal, under Email and collaboration, Threat Explorer indicates Plan 2. Real-time detections in its place indicates Plan 1.
What does Plan 2 add over Plan 1?
Attack simulation training, priority account protection, Threat Explorer and threat trackers, automated investigation and response, advanced hunting in Microsoft Defender XDR including Teams messages, and removing users from Teams chats.
Which plans already include Plan 2?
Microsoft 365 E5, A5 and GCC G5. Tenants on Microsoft 365 E3 or Business Premium can add the standalone licence instead of moving every user to E5.
Can I run phishing simulations with Plan 1?
No. Attack simulation training is a Plan 2 capability. Plan 1 provides protection and real-time detections but not simulation.
Is Plan 2 worth it without a security team?
Its value is in hunting and investigation, which assume someone will look. Without a responder in house or a provider acting for you, Plan 1 combined with a managed service usually delivers more than Plan 2 left unattended.
How can I tell which plan a tenant has?
In the Microsoft Defender portal under Email and collaboration, Threat Explorer indicates Plan 2 and Real-time detections indicates Plan 1.
- Vendor
- Microsoft
- Category
- Security
- Type
- SaaS
- Billing
- Monthly
- Commitment
- 1-Year
- Available terms
- 1-Year, Monthly
- Unit price
- €4.10 /mo
- SKU
- MST-NCE-135-C100
Term or edition paths Microsoft allows this subscription to move to.
Optional attachments that extend this base licence.
Attachable SKUs from the same category. Check each add-on's prerequisites for base-licence eligibility.
- 1You prepay through ITSailor (Malta) — VAT handled, reverse-charge for valid EU VAT IDs.
- 2We provision through Pax8 wholesale into your Microsoft tenant — no third-party MSP markup.
- 3You keep the tenant. Sovereign by default — every engagement closes with an Exit Kit.
Pax8 wholesale, margin in the price
Microsoft Defender Vulnerability Management Add-on (Education Student Pricing) [New Commerce Experience]
Microsoft Defender Vulnerability Management add-on is available to Defender for Endpoint Plan 2 customers to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.
Microsoft Entra ID P1 (Education Student Pricing) [New Commerce Experience]
Microsoft Entra ID P1 provides single sign-on to thousands of cloud (SaaS) apps and access to web apps you run on-premises. Built for ease of use, Microsoft Entra ID P1 features multi-factor authentication (MFA); access control based on device health, user location, and identity; and holistic security reports, audits,
Microsoft Entra ID P2 (Education Student Pricing) [New Commerce Experience]
Microsoft Entra ID P2 includes all the capabilities of P1 plus advanced identity protection features such as Identity Protection, which helps detect potential vulnerabilities affecting your organization’s identities, and Privileged Identity Management, which helps manage, control, and monitor access within your organiz
Microsoft Defender Vulnerability Management (Education Student Pricing) [New Commerce Experience]
Microsoft Defender Vulnerability Management standalone is a comprehensive vulnerability management solution to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.