Microsoft's advanced threat protection for email, documents, and collaboration tools, building on Plan 1's Safe Attachments, Safe Links, and anti-phishing policies. Adds threat trackers, automated investigation and response, attack simulation training, and real-time reporting — for organisations needing proactive, automated defence against sophisticated phishing and business email compromise attacks.
The frontline worker–priced equivalent of Defender for Office 365 Plan 1, protecting email and collaboration tools against advanced threats such as phishing and business email compromise. Includes Safe Attachments, Safe Links, and anti-phishing policies — a cost-effective baseline of threat protection for shift-based, deskless staff.
The frontline worker–priced equivalent of Defender for Office 365 Plan 2, protecting email, documents, and collaboration tools against advanced threats like phishing and business email compromise. Adds threat hunting, automation, attack simulation training, and cross-domain XDR capabilities on top of the F1 tier — sized and priced for shift-based, deskless staff.
Bundles Microsoft's E5-level security stack — Entra ID P2, Defender for Identity, Defender for Endpoint Plan 2, Defender for Office 365 Plan 2, and Defender for Cloud Apps — into a single add-on. Gives comprehensive identity, endpoint, email, and cloud app protection at a lower combined cost than licensing each component separately.
Bundles Microsoft's E5-level security stack — Entra ID P2, Defender for Identity, Defender for Endpoint Plan 2, Defender for Office 365 Plan 2, and Defender for Cloud Apps — into a single add-on, purchased on a 3-year term. Gives comprehensive identity, endpoint, email, and cloud app protection at a lower combined cost than licensing each component separately.
A frontline worker–priced edition of the Defender Suite (formerly the E5 Security add-on), bundling Entra ID P2, Defender for Identity, Defender for Endpoint Plan 2, Defender for Office 365 Plan 2, and Defender for Cloud Apps — extending enterprise-grade identity, device, email, and cloud app protection to shift-based and deskless staff at a reduced cost.
Full vulnerability management capabilities for any EDR solution — not just Defender for Endpoint. Includes device discovery and inventory, risk-based vulnerability assessment, configuration and security baseline assessment, and remediation tracking. Suited to organisations that need comprehensive vulnerability management but don't already have Defender for Endpoint Plan 2 as the underlying EDR
An add-on for Defender for Endpoint Plan 2 customers, extending core vulnerability management with premium capabilities: security baseline assessment, blocking known vulnerable applications, browser extension inventory, digital certificate assessment, and network share analysis. Gives security teams deeper, more proactive visibility into an organisation's attack surface beyond the core Plan 2 vulnerability tools.
Part of the Microsoft Defender security product family, providing threat protection for the specific workload named.
A frontline worker–priced edition of Microsoft Defender Vulnerability Management, giving continuous asset discovery, risk-based vulnerability assessment, and prioritised remediation guidance across devices — extended to shift-based and deskless staff at a reduced cost compared to the standard offering.
The frontline worker edition of Microsoft Entra ID, providing core identity and access management — single sign-on, Conditional Access, and multi-factor authentication — sized and priced for shift-based, deskless staff rather than standard knowledge workers.
Microsoft's foundational identity and access management tier, providing Conditional Access, multi-factor authentication, self-service password reset, and hybrid identity integration with on-premises Active Directory. The baseline security layer for controlling how users and devices access company resources — included in Microsoft 365 Business Premium and E3.

