Microsoft Defender for Office 365 (Plan 1) [New Commerce Experience]
Microsoft Defender for Office 365 (Plan 1)
Microsoft Defender for Office 365 Plan 1 is the protection layer above the filtering every Microsoft 365 mailbox already has. It adds Safe Attachments, Safe Links, anti-phishing policies with impersonation protection and configurable phishing thresholds, Safe Attachments for SharePoint, OneDrive and Microsoft Teams, and real-time detections for investigation. It is included in Microsoft 365 Business Premium and, since 1 July 2026, in Office 365 E3 and Microsoft 365 E3. Before buying it standalone, check whether one of those already covers the tenant. The step above it, Plan 2, is where attack simulation training, Threat Explorer and automated investigation live.
What it is
Microsoft Defender for Office 365 Plan 1 is Microsoft's advanced email and collaboration security tier. It sits above the anti-malware and anti-spam filtering that is built into every Microsoft 365 organisation with cloud mailboxes.
Who it is for
Organisations that need protection against targeted phishing and malicious attachments and links, rather than only bulk spam and known malware, and whose current plan does not already include it.
Key capabilities
- Safe Attachments, detonating attachments before delivery, including for SharePoint, OneDrive and Microsoft Teams
- Safe Links, rewriting and checking URLs at click time
- Anti-phishing policies with impersonation protection and configurable phishing confidence thresholds
- Tenant Allow and Block list for Teams
- User-reported Teams items
- Real-time detections for investigating what reached whom
- The email entity page and the Teams message entity panel
- User tags, including priority accounts
- Zero-hour auto purge for Teams
Check whether you already have it
Plan 1 is included in Microsoft 365 Business Premium, and since 1 July 2026 it is also included in Office 365 E3 and Microsoft 365 E3. If the tenant is on one of those, the standalone licence adds nothing.
What is not included
Plan 2 adds attack simulation training, priority account protection, Threat Explorer, threat trackers, automated investigation and response, advanced hunting in Microsoft Defender XDR, incident and alert investigation, and the ability to remove users from Teams chats. Plan 1 gives protection and real-time detections; Plan 2 gives the hunting and automation on top.
A useful way to tell the plans apart
In the Microsoft Defender portal, Email and collaboration then Real-time detections indicates Plan 1. Threat Explorer in its place indicates Plan 2.
Do I already have Defender for Office 365 Plan 1?
You do if the tenant is on Microsoft 365 Business Premium, or on Office 365 E3 or Microsoft 365 E3, which have included it since 1 July 2026. The standalone licence is for plans that do not carry it.
What does this add over the built-in filtering?
Every Microsoft 365 organisation with cloud mailboxes already has anti-malware, anti-spam and anti-spoofing. Plan 1 adds Safe Attachments, Safe Links, impersonation protection in anti-phishing policies, and real-time detections.
What does Plan 2 add over Plan 1?
Attack simulation training, priority account protection, Threat Explorer, threat trackers, automated investigation and response, advanced hunting in Microsoft Defender XDR, and the ability to remove users from Teams chats.
How can I tell which plan a tenant is on?
In the Microsoft Defender portal, look under Email and collaboration. Real-time detections indicates Plan 1. Threat Explorer in its place indicates Plan 2.
Does Plan 1 protect files as well as email?
Yes. Safe Attachments covers SharePoint, OneDrive and Microsoft Teams, so files shared through those services are scanned as well as email attachments.
- Vendor
- Microsoft
- Category
- Security
- Type
- SaaS
- Billing
- Monthly
- Commitment
- 1-Year
- Available terms
- Monthly, 1-Year
- Unit price
- €1.69 /mo
- SKU
- MST-NCE-134-C100
Term or edition paths Microsoft allows this subscription to move to.
Optional attachments that extend this base licence.
Attachable SKUs from the same category. Check each add-on's prerequisites for base-licence eligibility.
- 1You prepay through ITSailor (Malta) — VAT handled, reverse-charge for valid EU VAT IDs.
- 2We provision through Pax8 wholesale into your Microsoft tenant — no third-party MSP markup.
- 3You keep the tenant. Sovereign by default — every engagement closes with an Exit Kit.
Pax8 wholesale, margin in the price
Microsoft Defender Vulnerability Management Add-on (Education Student Pricing) [New Commerce Experience]
Microsoft Defender Vulnerability Management add-on is available to Defender for Endpoint Plan 2 customers to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.
Microsoft Entra ID P1 (Education Student Pricing) [New Commerce Experience]
Microsoft Entra ID P1 provides single sign-on to thousands of cloud (SaaS) apps and access to web apps you run on-premises. Built for ease of use, Microsoft Entra ID P1 features multi-factor authentication (MFA); access control based on device health, user location, and identity; and holistic security reports, audits,
Microsoft Entra ID P2 (Education Student Pricing) [New Commerce Experience]
Microsoft Entra ID P2 includes all the capabilities of P1 plus advanced identity protection features such as Identity Protection, which helps detect potential vulnerabilities affecting your organization’s identities, and Privileged Identity Management, which helps manage, control, and monitor access within your organiz
Microsoft Defender Vulnerability Management (Education Student Pricing) [New Commerce Experience]
Microsoft Defender Vulnerability Management standalone is a comprehensive vulnerability management solution to access continuous asset visibility, in-depth vulnerability assessments, and risk-based prioritization to help teams address critical vulnerabilities and misconfigurations.