Skip to content
Microsoft logo
Microsoft

Microsoft Defender For Endpoint P1 [New Commerce Experience]

SecuritySaaSMonthly1-Year
SKU MST-NCE-131-C100

Microsoft Defender for Endpoint Plan 1

Microsoft Defender for Endpoint Plan 1 is the preventive tier of Microsoft's endpoint security platform. It provides next-generation antimalware, attack surface reduction rules, device control, endpoint firewall, network protection and application control, managed centrally and covering Windows, macOS, iOS and Android. What it does not provide matters as much as what it does. Plan 1 has no endpoint detection and response, no automated investigation and remediation, and no threat and vulnerability management. Its response actions are manual only. Buyers who need detection and investigation after a compromise need Plan 2, or Microsoft Defender for Business if the organisation is under 300 users.

What it is

Microsoft Defender for Endpoint Plan 1 is the foundational tier of Defender for Endpoint. It concentrates on stopping threats before they run, rather than on investigating them afterwards.

Who it is for

Organisations that want Microsoft's preventive endpoint controls under central management, and that either handle detection and investigation elsewhere or do not require it. Plan 1 is also the endpoint component included in Microsoft 365 E3.

Key capabilities

  • Next-generation antimalware protection
  • Attack surface reduction rules
  • Device control and endpoint firewall
  • Network protection and application control
  • Central management through the Microsoft Defender portal
  • Coverage across Windows, macOS, iOS and Android

What is not included

This is the part the product name does not tell you. Plan 1 does not include endpoint detection and response, automated investigation and remediation, threat and vulnerability management, advanced hunting, threat intelligence, deep analysis sandboxing, or Microsoft Threat Experts. Microsoft documents every one of these as a Plan 2 capability.

Response in Plan 1 is manual and limited to four actions: run an antivirus scan, isolate a device, stop and quarantine a file, and add an indicator to block or allow a file.

Choosing between the plans

If detection and response after a breach is the requirement, Plan 1 is not the right licence. Organisations of up to 300 users should compare Microsoft Defender for Business, which includes endpoint detection and response and automated investigation at the small business tier. Larger organisations need Plan 2.

Features
Next-generation antimalware protection
Attack surface reduction rules
Device control and endpoint firewall
Network protection and application control
Central management in the Microsoft Defender portal
Manual response actions only
No endpoint detection and response in this plan
Use cases
Applying Microsoft preventive endpoint controls across a mixed device estate
Standardising antimalware and attack surface reduction under central management
Adding endpoint prevention where detection and investigation are handled by another product
Establishing the endpoint baseline that comes with Microsoft 365 E3
FAQ
Does Defender for Endpoint Plan 1 include endpoint detection and response?

No. Endpoint detection and response is a Plan 2 capability. Plan 1 covers prevention: next-generation protection, attack surface reduction, device control, endpoint firewall, network protection and application control.

Does Plan 1 include automated investigation and remediation?

No. Automated investigation and remediation is in Plan 2. Plan 1 provides manual response actions only: run an antivirus scan, isolate a device, stop and quarantine a file, and add an indicator to block or allow a file.

Does Plan 1 include vulnerability management?

No. Threat and vulnerability management is a Plan 2 capability. It is also present in Microsoft Defender for Business in its core form.

Which is better for a business under 300 users, Plan 1 or Defender for Business?

For most organisations under 300 users, Microsoft Defender for Business covers more ground. It includes everything in Plan 1 and adds endpoint detection and response, automated investigation and remediation and core vulnerability management.

Where does Plan 1 already come included?

Defender for Endpoint Plan 1 is included in Microsoft 365 E3, A3 and G3. It is also sold as a standalone user subscription licence.

Plan details
Vendor
Microsoft
Category
Security
Type
SaaS
Billing
Monthly
Commitment
1-Year
Available terms
1-Year, Monthly
Unit price
€2.40 /mo
SKU
MST-NCE-131-C100
Conversions & upgrades

Term or edition paths Microsoft allows this subscription to move to.

How buying works
  1. 1You prepay through ITSailor (Malta) — VAT handled, reverse-charge for valid EU VAT IDs.
  2. 2We provision through Pax8 wholesale into your Microsoft tenant — no third-party MSP markup.
  3. 3You keep the tenant. Sovereign by default — every engagement closes with an Exit Kit.
Microsoft NCE termsNew Commerce Experience applies: within 7 days of activation you may cancel or reduce seats (pro-rated). After day 7 the subscription is committed for the term. We mirror this verbatim — no surprises.
Your price
Term
Billing cycle
€2.70/mo
Pax8 suggested retail €2.731% off Pax8 suggested retail
Quantity
1
Ask a question

Pax8 wholesale, margin in the price

More in Security
Add-on
Microsoft

Microsoft Defender Vulnerability Management Add-on (Education Student Pricing) [New Commerce Experience]

Microsoft Defender Vulnerability Management add-on is available to Defender for Endpoint Plan 2 customers to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.

€0.28/mo
SecurityEDU
SaaS
Microsoft

Microsoft Entra ID P1 (Education Student Pricing) [New Commerce Experience]

Microsoft Entra ID P1 provides single sign-on to thousands of cloud (SaaS) apps and access to web apps you run on-premises. Built for ease of use, Microsoft Entra ID P1 features multi-factor authentication (MFA); access control based on device health, user location, and identity; and holistic security reports, audits,

€0.28/mo
SecurityEDU
SaaS
Microsoft

Microsoft Entra ID P2 (Education Student Pricing) [New Commerce Experience]

Microsoft Entra ID P2 includes all the capabilities of P1 plus advanced identity protection features such as Identity Protection, which helps detect potential vulnerabilities affecting your organization’s identities, and Privileged Identity Management, which helps manage, control, and monitor access within your organiz

€0.42/mo
SecurityEDU
SaaS
Microsoft

Microsoft Defender Vulnerability Management (Education Student Pricing) [New Commerce Experience]

Microsoft Defender Vulnerability Management standalone is a comprehensive vulnerability management solution to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.

€0.42/mo
SecurityEDU