A frontline worker–priced edition combining the Defender and Purview Suites into one add-on — identity, endpoint, email, and cloud app security alongside data classification, DLP, insider risk management, and eDiscovery. Extends near-E5-level security and compliance to shift-based and deskless staff at a reduced cost.
Enterprise-grade endpoint security simplified for SMBs (up to 300 users). Includes next-generation antivirus, endpoint detection and response (EDR), automated investigation and remediation, threat and vulnerability management, and firewall protection across Windows, macOS, iOS, and Android — a streamlined, pre-configured alternative to Defender for Endpoint for businesses without a dedicated security team.
Part of the Microsoft Defender security product family, providing threat protection for the specific workload named.
Part of the Microsoft Defender security product family, providing threat protection for the specific workload named.
Part of the Microsoft Defender security product family, providing threat protection for the specific workload named.
The frontline worker–priced edition of Defender for Endpoint Plan 1, delivering core endpoint protection — next-generation antivirus, attack surface reduction rules, device control, and endpoint firewall — sized and priced for shift-based, deskless staff rather than standard knowledge workers.
The frontline worker–priced edition of Defender for Endpoint Plan 2, adding endpoint detection and response (EDR), automated investigation and remediation, and threat and vulnerability management on top of the F1 core protection tier — sized and priced for shift-based, deskless staff.
Core endpoint protection for devices, including next-generation antivirus, attack surface reduction rules, device control, endpoint firewall, network protection, and application control. The foundational tier of Defender for Endpoint — available standalone or as part of Microsoft 365 E3 — upgradable to Plan 2 for full EDR and automated response capabilities.
Comprehensive endpoint protection, building on Plan 1's core antivirus and attack surface reduction with full endpoint detection and response (EDR), automated investigation and remediation, threat and vulnerability management, threat intelligence, and sandbox analysis. The tier where Defender for Endpoint becomes a true EDR platform — included in Microsoft 365 E5.
A per-node add-on that extends Defender for Endpoint's protection, detection, and response capabilities to Windows and Linux server instances. Requires a combined minimum of 50 eligible Defender for Endpoint licenses (e.g. Windows E5, Microsoft 365 E5) to purchase, and isn't assigned to a specific server — just licensed against the total number of servers being protected.
Monitors on-premises Active Directory signals to detect and investigate advanced identity-based threats — compromised accounts, lateral movement, and privilege escalation. Integrates with Microsoft Defender XDR to correlate identity risk with endpoint, email, and cloud app signals for a fuller picture of an attack.
The frontline worker–priced edition of Microsoft Defender for Identity, monitoring on-premises Active Directory signals to detect and investigate advanced identity-based threats such as compromised accounts and lateral movement — sized and priced for shift-based, deskless staff.

