A device and identity management bundle combining Entra ID P1 (SSO, MFA, Conditional Access), Microsoft Intune (mobile device and app management), and Azure Information Protection P1 (document encryption and rights management). The foundational security layer included in Microsoft 365 E3, giving organisations control over how corporate data is accessed and shared across devices.
Builds on EMS E3 with advanced identity and threat protection: Entra ID P2 (risk-based Conditional Access, Identity Protection, Privileged Identity Management), Azure Information Protection P2, and Microsoft Defender for Cloud Apps. The more comprehensive security tier included in Microsoft 365 E5, adding proactive, automated threat detection and governance on top of E3's baseline controls.
Upgrades an existing Microsoft Entra ID P2 subscription to the full Entra Suite. Adds Entra ID Governance, Private Access (ZTNA/VPN replacement), Internet Access (secure web gateway), premium Verified ID features (including Face Check), and advanced Identity Protection — a complete cloud-based solution for securing workforce access across cloud and on-premises resources.
An Intune Suite add-on that lets you create, configure, and manage your own certification authorities (CAs) and certificates entirely in the cloud — no on-premises servers, connectors, or hardware required. Automates certificate issuance, delivery, and revocation for Intune-managed Windows, iOS, macOS, and Android devices, enabling certificate-based authentication in minutes rather than weeks.
A frontline worker–priced edition of Microsoft Cloud PKI, letting IT create, configure, and manage certification authorities and certificates entirely in the cloud for Intune-managed devices — no on-premises infrastructure required — extended to shift-based and deskless staff at a reduced cost compared to the standard Intune Suite offering.
A frontline worker–priced edition combining the Defender and Purview Suites into one add-on — identity, endpoint, email, and cloud app security alongside data classification, DLP, insider risk management, and eDiscovery. Extends near-E5-level security and compliance to shift-based and deskless staff at a reduced cost.
Enterprise-grade endpoint security simplified for SMBs (up to 300 users). Includes next-generation antivirus, endpoint detection and response (EDR), automated investigation and remediation, threat and vulnerability management, and firewall protection across Windows, macOS, iOS, and Android — a streamlined, pre-configured alternative to Defender for Endpoint for businesses without a dedicated security team.
Part of the Microsoft Defender security product family, providing threat protection for the specific workload named.
Part of the Microsoft Defender security product family, providing threat protection for the specific workload named.
Part of the Microsoft Defender security product family, providing threat protection for the specific workload named.
The frontline worker–priced edition of Defender for Endpoint Plan 1, delivering core endpoint protection — next-generation antivirus, attack surface reduction rules, device control, and endpoint firewall — sized and priced for shift-based, deskless staff rather than standard knowledge workers.
The frontline worker–priced edition of Defender for Endpoint Plan 2, adding endpoint detection and response (EDR), automated investigation and remediation, and threat and vulnerability management on top of the F1 core protection tier — sized and priced for shift-based, deskless staff.

