• Comprehensive endpoint protection, building on Plan 1's core antivirus and attack surface reduction with full endpoint detection and response (EDR), automated investigation and remediation, threat and vulnerability management, threat intelligence, and sandbox analysis. The tier where Defender for Endpoint becomes a true EDR platform — included in Microsoft 365 E5.

  • A per-node add-on that extends Defender for Endpoint's protection, detection, and response capabilities to Windows and Linux server instances. Requires a combined minimum of 50 eligible Defender for Endpoint licenses (e.g. Windows E5, Microsoft 365 E5) to purchase, and isn't assigned to a specific server — just licensed against the total number of servers being protected.

  • Monitors on-premises Active Directory signals to detect and investigate advanced identity-based threats — compromised accounts, lateral movement, and privilege escalation. Integrates with Microsoft Defender XDR to correlate identity risk with endpoint, email, and cloud app signals for a fuller picture of an attack.

  • The frontline worker–priced edition of Microsoft Defender for Identity, monitoring on-premises Active Directory signals to detect and investigate advanced identity-based threats such as compromised accounts and lateral movement — sized and priced for shift-based, deskless staff.

  • A per-device add-on to Microsoft Defender for Endpoint P2 that extends security monitoring to enterprise IoT devices — VoIP phones, printers, cameras, conferencing systems, smart TVs, and other connected devices without built-in security agents. Helps security teams identify and respond to vulnerabilities in devices that traditional endpoint protection doesn't cover.

  • A site-based license securing operational technology (OT) and industrial control system (ICS) environments — for a large facility size tier. Provides agentless network detection and response across a physical site, integrating with Microsoft Defender XDR and Microsoft Sentinel for unified security operations.

  • A site-based license securing operational technology (OT) and industrial control system (ICS) environments — for a medium facility size tier. Provides agentless network detection and response across a physical site, integrating with Microsoft Defender XDR and Microsoft Sentinel for unified security operations.

  • A site-based license securing operational technology (OT) and industrial control system (ICS) environments — for a small facility size tier. Provides agentless network detection and response across a physical site, integrating with Microsoft Defender XDR and Microsoft Sentinel for unified security operations.

  • A site-based license securing operational technology (OT) and industrial control system (ICS) environments — for the largest facility size tier. Provides agentless network detection and response across a physical site (factory, campus, hospital, rig, etc.), integrating with Microsoft Defender XDR and Microsoft Sentinel for unified security operations.

  • A site-based license securing operational technology (OT) and industrial control system (ICS) environments — for the smallest facility size tier. Provides agentless network detection and response across a physical site, integrating with Microsoft Defender XDR and Microsoft Sentinel for unified security operations.

  • Protects email, collaboration tools, and documents against advanced threats such as phishing and business email compromise. Includes Safe Attachments, Safe Links, and anti-phishing policies — the foundational tier of advanced threat protection for Office 365, upgradable to Plan 2 for automated investigation, threat hunting, and attack simulation.

  • Microsoft's advanced threat protection for email, documents, and collaboration tools, building on Plan 1's Safe Attachments, Safe Links, and anti-phishing policies. Adds threat trackers, automated investigation and response, attack simulation training, and real-time reporting — for organisations needing proactive, automated defence against sophisticated phishing and business email compromise attacks.