Microsoft Defender For Endpoint P1 [New Commerce Experience]
Microsoft Defender for Endpoint Plan 1
Microsoft Defender for Endpoint Plan 1 is the preventive tier of Microsoft's endpoint security platform. It provides next-generation antimalware, attack surface reduction rules, device control, endpoint firewall, network protection and application control, managed centrally and covering Windows, macOS, iOS and Android. What it does not provide matters as much as what it does. Plan 1 has no endpoint detection and response, no automated investigation and remediation, and no threat and vulnerability management. Its response actions are manual only. Buyers who need detection and investigation after a compromise need Plan 2, or Microsoft Defender for Business if the organisation is under 300 users.
What it is
Microsoft Defender for Endpoint Plan 1 is the foundational tier of Defender for Endpoint. It concentrates on stopping threats before they run, rather than on investigating them afterwards.
Who it is for
Organisations that want Microsoft's preventive endpoint controls under central management, and that either handle detection and investigation elsewhere or do not require it. Plan 1 is also the endpoint component included in Microsoft 365 E3.
Key capabilities
- Next-generation antimalware protection
- Attack surface reduction rules
- Device control and endpoint firewall
- Network protection and application control
- Central management through the Microsoft Defender portal
- Coverage across Windows, macOS, iOS and Android
What is not included
This is the part the product name does not tell you. Plan 1 does not include endpoint detection and response, automated investigation and remediation, threat and vulnerability management, advanced hunting, threat intelligence, deep analysis sandboxing, or Microsoft Threat Experts. Microsoft documents every one of these as a Plan 2 capability.
Response in Plan 1 is manual and limited to four actions: run an antivirus scan, isolate a device, stop and quarantine a file, and add an indicator to block or allow a file.
Choosing between the plans
If detection and response after a breach is the requirement, Plan 1 is not the right licence. Organisations of up to 300 users should compare Microsoft Defender for Business, which includes endpoint detection and response and automated investigation at the small business tier. Larger organisations need Plan 2.
Does Defender for Endpoint Plan 1 include endpoint detection and response?
No. Endpoint detection and response is a Plan 2 capability. Plan 1 covers prevention: next-generation protection, attack surface reduction, device control, endpoint firewall, network protection and application control.
Does Plan 1 include automated investigation and remediation?
No. Automated investigation and remediation is in Plan 2. Plan 1 provides manual response actions only: run an antivirus scan, isolate a device, stop and quarantine a file, and add an indicator to block or allow a file.
Does Plan 1 include vulnerability management?
No. Threat and vulnerability management is a Plan 2 capability. It is also present in Microsoft Defender for Business in its core form.
Which is better for a business under 300 users, Plan 1 or Defender for Business?
For most organisations under 300 users, Microsoft Defender for Business covers more ground. It includes everything in Plan 1 and adds endpoint detection and response, automated investigation and remediation and core vulnerability management.
Where does Plan 1 already come included?
Defender for Endpoint Plan 1 is included in Microsoft 365 E3, A3 and G3. It is also sold as a standalone user subscription licence.
- Vendor
- Microsoft
- Category
- Security
- Type
- SaaS
- Billing
- Monthly
- Commitment
- 1-Year
- Available terms
- 1-Year, Monthly
- Unit price
- €2.40 /mo
- SKU
- MST-NCE-131-C100
Term or edition paths Microsoft allows this subscription to move to.
Attachable SKUs from the same category. Check each add-on's prerequisites for base-licence eligibility.
- 1You prepay through ITSailor (Malta) — VAT handled, reverse-charge for valid EU VAT IDs.
- 2We provision through Pax8 wholesale into your Microsoft tenant — no third-party MSP markup.
- 3You keep the tenant. Sovereign by default — every engagement closes with an Exit Kit.
Pax8 wholesale, margin in the price
Microsoft Defender Vulnerability Management Add-on (Education Student Pricing) [New Commerce Experience]
Microsoft Defender Vulnerability Management add-on is available to Defender for Endpoint Plan 2 customers to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.
Microsoft Entra ID P1 (Education Student Pricing) [New Commerce Experience]
Microsoft Entra ID P1 provides single sign-on to thousands of cloud (SaaS) apps and access to web apps you run on-premises. Built for ease of use, Microsoft Entra ID P1 features multi-factor authentication (MFA); access control based on device health, user location, and identity; and holistic security reports, audits,
Microsoft Entra ID P2 (Education Student Pricing) [New Commerce Experience]
Microsoft Entra ID P2 includes all the capabilities of P1 plus advanced identity protection features such as Identity Protection, which helps detect potential vulnerabilities affecting your organization’s identities, and Privileged Identity Management, which helps manage, control, and monitor access within your organiz
Microsoft Defender Vulnerability Management (Education Student Pricing) [New Commerce Experience]
Microsoft Defender Vulnerability Management standalone is a comprehensive vulnerability management solution to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.