Skip to content
Microsoft logo
Microsoft

Microsoft Defender for Office 365 (Plan 2) [New Commerce Experience]

SecuritySaaSMonthly1-Year
SKU MST-NCE-135-C100

Microsoft Defender for Office 365 (Plan 2)

Microsoft Defender for Office 365 Plan 2 contains everything in Plan 1 and adds the investigation and automation layer. That means attack simulation training for running controlled phishing exercises against your own staff, priority account protection, Threat Explorer and threat trackers in place of Plan 1's real-time detections, automated investigation and response, advanced hunting across Microsoft Defender XDR, incident and alert investigation, and the ability to remove users from Teams chats. It is included in Microsoft 365 E5, A5 and GCC G5. The standalone licence is for organisations on E3 or Business Premium that need the hunting and automation without moving the whole tenant to E5.

What it is

Microsoft Defender for Office 365 Plan 2 is the full email and collaboration security tier. Plan 1 protects and detects; Plan 2 adds the tooling to hunt, investigate and automate the response.

Who it is for

Organisations with someone who will act on the findings: a security team, or a provider running detection and response on their behalf. Also organisations that need to run phishing simulations against their own staff as part of an awareness programme.

Key capabilities

  • Everything in Microsoft Defender for Office 365 Plan 1
  • Attack simulation training, running controlled phishing simulations against your own users
  • Priority account protection for the identities most likely to be targeted
  • Threat Explorer and threat trackers, in place of Plan 1's real-time detections
  • Automated investigation and response
  • Advanced hunting in Microsoft Defender XDR, including hunting across Teams messages
  • Incident and alert investigation in Microsoft Defender XDR
  • Removing users from Teams chats as a response action

Check whether you already have it

Plan 2 is included in Microsoft 365 E5, A5 and GCC G5. The standalone licence is the route for tenants on Microsoft 365 E3 or Business Premium that want this capability without moving every user to E5. Compare the two before deciding, because on a large tenant the arithmetic can go either way.

The honest test before buying

Threat Explorer, advanced hunting and automated investigation all produce work. They assume a responder who will look. An organisation with nobody in that role gets more value from Plan 1 plus a managed service than from Plan 2 unattended.

A useful way to tell the plans apart

In the Microsoft Defender portal, under Email and collaboration, Threat Explorer indicates Plan 2. Real-time detections in its place indicates Plan 1.

Features
Everything in Defender for Office 365 Plan 1
Attack simulation training for controlled phishing exercises
Priority account protection
Threat Explorer and threat trackers
Automated investigation and response
Advanced hunting across Microsoft Defender XDR
Removing users from Teams chats as a response action
Use cases
Hunting across mail and Teams data after a suspected compromise
Running controlled phishing simulations as part of staff awareness
Automating first-line triage of email security alerts
Adding Plan 2 capability to an E3 tenant without a full E5 move
FAQ
What does Plan 2 add over Plan 1?

Attack simulation training, priority account protection, Threat Explorer and threat trackers, automated investigation and response, advanced hunting in Microsoft Defender XDR including Teams messages, and removing users from Teams chats.

Which plans already include Plan 2?

Microsoft 365 E5, A5 and GCC G5. Tenants on Microsoft 365 E3 or Business Premium can add the standalone licence instead of moving every user to E5.

Can I run phishing simulations with Plan 1?

No. Attack simulation training is a Plan 2 capability. Plan 1 provides protection and real-time detections but not simulation.

Is Plan 2 worth it without a security team?

Its value is in hunting and investigation, which assume someone will look. Without a responder in house or a provider acting for you, Plan 1 combined with a managed service usually delivers more than Plan 2 left unattended.

How can I tell which plan a tenant has?

In the Microsoft Defender portal under Email and collaboration, Threat Explorer indicates Plan 2 and Real-time detections indicates Plan 1.

Plan details
Vendor
Microsoft
Category
Security
Type
SaaS
Billing
Monthly
Commitment
1-Year
Available terms
1-Year, Monthly
Unit price
€4.10 /mo
SKU
MST-NCE-135-C100
Conversions & upgrades

Term or edition paths Microsoft allows this subscription to move to.

UpgradesTo
Microsoft 365 Business Premium (Nonprofit Staff Pricing) [New Commerce Experience]
UpgradesTo
Microsoft 365 Business Premium Donation (Non-Profit Pricing) [New Commerce Experience]
UpgradesTo
Microsoft 365 Business Standard (Non-Profit Pricing) [New Commerce Experience]
UpgradesTo
Office 365 E3 (no Teams) Custom [New Commerce Experience]
UpgradesTo
Microsoft 365 E3 (no Teams) Custom [New Commerce Experience]
UpgradesTo
Microsoft 365 F3 EEA (no Teams) [New Commerce Experience]
UpgradesTo
Exchange Online (Plan 1) - AxeandSawOnly1
UpgradesTo
Teams Essentials and Teams Phone with pay-as-you-go calling (country zone 1 - US) [New Commerce Experience]
UpgradesTo
Teams Essentials and Teams Phone with pay-as-you-go calling (country zone 1) [New Commerce Experience]
UpgradesTo
Teams Essentials and Teams Phone with international calling [New Commerce Experience]
UpgradesTo
Microsoft Teams Essentials with Phone [New Commerce Experience]
UpgradesTo
Microsoft 365 Business Premium and Microsoft 365 Copilot Business [New Commerce Experience]
UpgradesTo
Microsoft 365 Business Basic (No Teams) and Microsoft 365 Copilot Business [New Commerce Experience]
Add-ons

Optional attachments that extend this base licence.

IsAddOnFor
Teams Essentials and Teams Phone with international calling [New Commerce Experience]
IsAddOnFor
Teams Essentials and Teams Phone with pay-as-you-go calling (country zone 1 - US) [New Commerce Experience]
How buying works
  1. 1You prepay through ITSailor (Malta) — VAT handled, reverse-charge for valid EU VAT IDs.
  2. 2We provision through Pax8 wholesale into your Microsoft tenant — no third-party MSP markup.
  3. 3You keep the tenant. Sovereign by default — every engagement closes with an Exit Kit.
Microsoft NCE termsNew Commerce Experience applies: within 7 days of activation you may cancel or reduce seats (pro-rated). After day 7 the subscription is committed for the term. We mirror this verbatim — no surprises.
Your price
Term
Billing cycle
€4.40/mo
Pax8 suggested retail €4.522% off Pax8 suggested retail
Quantity
1
Ask a question

Pax8 wholesale, margin in the price

More in Security
Add-on
Microsoft

Microsoft Defender Vulnerability Management Add-on (Education Student Pricing) [New Commerce Experience]

Microsoft Defender Vulnerability Management add-on is available to Defender for Endpoint Plan 2 customers to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.

€0.28/mo
SecurityEDU
SaaS
Microsoft

Microsoft Entra ID P1 (Education Student Pricing) [New Commerce Experience]

Microsoft Entra ID P1 provides single sign-on to thousands of cloud (SaaS) apps and access to web apps you run on-premises. Built for ease of use, Microsoft Entra ID P1 features multi-factor authentication (MFA); access control based on device health, user location, and identity; and holistic security reports, audits,

€0.28/mo
SecurityEDU
SaaS
Microsoft

Microsoft Entra ID P2 (Education Student Pricing) [New Commerce Experience]

Microsoft Entra ID P2 includes all the capabilities of P1 plus advanced identity protection features such as Identity Protection, which helps detect potential vulnerabilities affecting your organization’s identities, and Privileged Identity Management, which helps manage, control, and monitor access within your organiz

€0.42/mo
SecurityEDU
SaaS
Microsoft

Microsoft Defender Vulnerability Management (Education Student Pricing) [New Commerce Experience]

Microsoft Defender Vulnerability Management standalone is a comprehensive vulnerability management solution to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.

€0.42/mo
SecurityEDU