The endpoint product bundled with Business Premium is better than the one bundled with E3.
That reads like a mistake, and the published comparison table says it plainly. Defender for Business carries detection and response, investigations that run themselves, automatic attack disruption and vulnerability management. Plan 1, which is what arrives with E3, carries none of the four. Worth establishing before anybody signs anything.

- Business beats P1On six separate capabilities
- Up to 300 usersThe Defender for Business limit
- P1 is in E3Prevention, not detection
- Servers extraLicensed separately on every plan
Eight things to establish before choosing a Defender plan.
The counter-intuitive part, from Microsoft's own table
The small business product carries investigation and remediation that run without a human, automatic attack disruption, detection and response on the endpoint, threat analytics and core vulnerability management. Plan 1 carries none of them. The documentation states it outright: Defender for Business contains everything in Plan 1, some of what is in Plan 2, and several things unique to itself. Which makes the product aimed at small companies the more capable of the two.
What Plan 1 actually is: prevention, done well
Modern antimalware, rules that shrink the attack surface, ransomware mitigation through controlled folder access, control over removable media, web threat protection and content filtering, network protection, a firewall and application control. On top of that, three actions somebody can take by hand: run a scan, isolate a machine, and add an indicator to block or permit a file. It is a genuinely solid preventive product, and it is not detection and response.
What Plan 2 adds that nothing else has
Exactly two things. Retention, meaning thirty days of advanced hunting and six months of data kept, which is what makes it possible to investigate something that began long before anybody noticed. And access to the Microsoft threat expert service. Everything else people associate with Plan 2, detection and response and automated investigation included, is also present in Defender for Business, and that changes the comparison considerably.
The three hundred user ceiling
The small business product is built for companies of up to three hundred people, and that ceiling is the single constraint deciding whether the capable and inexpensive option is open to you at all. For a great many American small and mid-sized businesses it is. For anybody approaching that number, the transition is worth planning deliberately rather than discovering the limit halfway through a year of hiring.
How you get Defender for Business
It comes with Business Premium, and can be bought on its own by any company up to three hundred people, with Business Basic, Business Standard and the entry Office plan given as examples of where that applies. So an American business already on Business Premium has it sitting there, and one on Business Standard can add it without changing plan at all. Neither of those facts is widely understood.
Servers are licensed separately on every plan
The same note appears against all three options: protecting Windows and Linux servers is possible and needs additional licenses. This catches out anybody assuming the licensing bought for their people covers the machines in the rack too. Plan 1 can be licensed separately for servers, and where the server product is also in play through Defender for Cloud there is a documented interaction between them worth reading rather than guessing at.
Deployment through Intune, or without it
Plan 1 is configured centrally through the Defender portal with device management integrated. The small business product is deliberately built to work whether or not you run a device management platform at all, with guided configuration and sensible default policies, and it carries simplified firewall and antivirus configuration for Windows that neither of the other two provides. For a small team with nobody administering devices full time, that difference is entirely practical rather than cosmetic.
Access control changed for new customers
One detail worth carrying into a deployment. Since 16 February 2025, anybody new to Defender for Endpoint gets the unified access control model only, while existing customers keep whatever roles and permissions they already had. If you are onboarding today, your permission model will not match what the older documentation describes, nor what a colleague who set one up three years ago remembers.
A company on E3 may well have weaker endpoint protection than one on Business Premium.
This is genuinely counter-intuitive, it comes straight out of the published comparison table, and it changes what people buy. Worth stating carefully, because on first reading it sounds like somebody made an error.
- E3 brings Plan 1. Business Premium brings Defender for Business. On the published comparison, Defender for Business carries investigation and remediation that run themselves, automatic attack disruption, detection and response on the endpoint, threat analytics, core vulnerability management, and a monthly security summary. Plan 1 carries none of those six.
- And it goes further than that. Simplified firewall and antivirus configuration for Windows is listed against Defender for Business and against neither of the enterprise plans. On that one capability the product built for small companies is ahead of the flagship. It is a perfectly reasonable design decision and a genuinely surprising fact if nobody has ever shown you the table.
- What Plan 2 has and Defender for Business does not is far narrower than anybody assumes. Retention, meaning thirty days of advanced hunting and six months of data kept, and the threat expert service. Retention is the substantive one, because it is what lets you investigate an incident that started well before anyone noticed, and that is very nearly always the situation you find yourself in.
- What that means in practice for an American company. Under three hundred people, Defender for Business is probably the right answer and there is a fair chance you already hold it. On E3, having assumed you had detection and response, you do not, and the real question becomes whether to add Plan 2 or to accept knowingly that you have prevention and no detection. Both of those are defensible positions. Believing you have detection when you have prevention is not, and it is precisely the assumption a cyber insurance questionnaire will ask you to put in writing and sign.
Four things that make this advice worth having.
We check what you hold before recommending a plan
A meaningful share of the companies that come to us about endpoint protection already hold Defender for Business inside Business Premium and have never onboarded a single machine to it. In that situation the recommendation is to deploy rather than to buy, and that is the correct answer despite earning us nothing whatsoever in licensing.
You get told when the plan you hold is weaker than you believe
The E3 case is the one that matters most. Companies on E3 routinely believe they have detection and response on the endpoint, and Plan 1 simply does not contain it. That is no criticism of Plan 1, which is a capable preventive product on its own terms. But the gap between what people believe they hold and what they actually hold is exactly where an incident becomes expensive, and exactly where an insurance questionnaire gets answered incorrectly.
We ask who would respond before recommending detection
Detection and response produces alerts, and an alert nobody answers changes nothing at all. Where there is no one to act on a detection outside office hours, the honest recommendation is usually to strengthen prevention and configuration first, or to buy detection alongside somebody who will respond to it. Selling detection into an empty room is a common pattern and an expensive one.
We deploy it properly rather than switching it on
Every device onboarded, Macs and phones included, the attack surface reduction rules enabled deliberately rather than left on whatever arrived, device control and web filtering configured, servers licensed correctly, and the whole thing tuned so that an alert means something. A deployment producing noise nobody reads is functionally identical to no deployment at all.
Six US situations and what we would usually recommend.
A business under three hundred users on Business Premium
You already hold Defender for Business, which carries detection and response, investigation that runs itself, attack disruption and core vulnerability management. The work here is deployment and configuration rather than purchasing, and it is very often the highest return security project available to an American small business, precisely because the capability has already been paid for and is sitting idle.
An organization on Microsoft 365 E3
What you hold is Plan 1, which prevents and does not detect, investigate or respond. If you assumed otherwise, that assumption is itself the finding. The decision in front of you is whether to add Plan 2 for detection, retention and expert access, or to accept a purely preventive posture on purpose and spend the money somewhere it does more good. Both are legitimate choices. Arriving at one by accident is not.
A firm that must evidence detection capability
When an insurance application, a SOC 2 audit, a HIPAA risk assessment or a questionnaire from a large customer asks specifically about detection and response on endpoints, Plan 1 does not answer that question and either of the other two does. With several carriers this has moved from something affecting your premium to something you must have before they will write the policy at all, and answering accurately depends on knowing which product you genuinely run.
A business that needs to investigate historical incidents
This is the single clearest argument for Plan 2 over anything else. Thirty days of advanced hunting alongside six months of retained data is what makes it possible to reconstruct an incident that began well before anybody noticed it, and that is the normal case rather than the unusual one. Where your obligations or your risk genuinely require that, no other plan provides it.
An organization growing past three hundred users
The small business product stops at three hundred people, so growth eventually forces a change. Planning that in advance is a great deal easier than running into the ceiling halfway through a year of hiring, and the sensible moment to model the move onto Plan 2, or onto a plan containing it, is before the constraint bites rather than the week after.
A company with servers nobody licensed
Protecting servers needs additional licensing on every plan, and companies routinely assume what they bought for their people covers the machines in the rack. What we usually find is that the servers holding the most valuable data are the least protected devices anywhere in the business, which is the exact inverse of what anyone intended and is straightforward to put right once somebody has noticed it.
What we typically find when we open up endpoint protection in an American estate.
| Feature | Right plan, fully deployed | Licensed, partly onboarded | Built-in antivirus only |
|---|---|---|---|
Plan matched to size and need | Yes | By accident | Not chosen |
All devices onboarded and reporting | Yes | Some | Not applicable |
Macs and mobile devices covered | Yes | Rarely | No |
Servers separately licensed | Yes | Usually not | No |
Attack surface reduction rules enabled | Yes | Default only | No |
Detection and response available | Yes | Depends on plan | No |
Somebody responds to alerts | Yes | Sometimes | No alerts exist |
Could investigate an incident from three months ago | If on Plan 2 | No | No |
Vulnerability position visible | Yes | Depends on plan | No |
Passes a cyber insurance EDR question honestly | Yes | Unclear | No |
Defender for Business, Plan 1 and Plan 2.
Capability
Next-generation protection
- Defender for Business
- Yes
- Plan 1
- Yes
- Plan 2
- Yes
Capability
Attack surface reduction
- Defender for Business
- Yes
- Plan 1
- Yes
- Plan 2
- Yes
Capability
Centralized management
- Defender for Business
- Yes
- Plan 1
- Yes
- Plan 2
- Yes
Capability
Cross-platform, Mac, iOS, iPadOS, Android
- Defender for Business
- Yes
- Plan 1
- Yes
- Plan 2
- Yes
Capability
APIs
- Defender for Business
- Yes
- Plan 1
- Yes
- Plan 2
- Yes
Capability
Endpoint detection and response
- Defender for Business
- Yes, optimized
- Plan 1
- No
- Plan 2
- Yes
Capability
Automated investigation and remediation
- Defender for Business
- Yes
- Plan 1
- No
- Plan 2
- Yes
Capability
Automatic attack disruption
- Defender for Business
- Yes
- Plan 1
- No
- Plan 2
- Yes
Capability
Threat analytics
- Defender for Business
- Yes, optimized
- Plan 1
- No
- Plan 2
- Yes
Capability
Vulnerability management, core capabilities
- Defender for Business
- Yes
- Plan 1
- No
- Plan 2
- Yes
Capability
Monthly security summary reporting
- Defender for Business
- Yes
- Plan 1
- No
- Plan 2
- Yes
Capability
Simplified firewall and antivirus configuration
- Defender for Business
- Yes
- Plan 1
- No
- Plan 2
- No
Capability
Data retention, 30-day hunting and six months data
- Defender for Business
- No
- Plan 1
- No
- Plan 2
- Yes
Capability
Microsoft Threat Experts
- Defender for Business
- No
- Plan 1
- No
- Plan 2
- Yes
Capability
Windows and Linux server protection
- Defender for Business
- Extra licenses
- Plan 1
- Extra licenses
- Plan 2
- Extra licenses
Five steps, and the first one frequently makes everything after it cheaper.
- 1
Establish which product you actually hold
Which plans your people are actually on, whether you sit under the three hundred user threshold, and therefore which of the three products you hold, if any. This surprises people in both directions with some regularity, and it is the necessary foundation for every decision that follows.
- 2
Reconcile onboarded devices against real devices
How many machines report into the portal set against how many the business genuinely uses, counting Macs, phones and servers. That gap is almost always substantial, and a device that was never onboarded is entirely unprotected no matter what you are paying for. Servers make up the largest part of it more often than not.
- 3
Decide the plan honestly against who would respond
Whether prevention alone is enough for you, whether anybody would act on a detection, and whether being able to investigate history matters enough to justify the Plan 2 retention specifically. If nobody would answer an alert overnight, you hear that said out loud, and the conversation turns to pairing detection with somebody who responds rather than selling a capability into an empty room.
- 4
Deploy and configure, not just enable
Every machine onboarded, the attack surface reduction rules turned on deliberately rather than left as found, control over removable media configured, web content filtering set up alongside the threat protection, servers licensed correctly, and the detections tuned until an alert is credible enough that somebody actually opens it.
- 5
Establish the operating rhythm
Who reads the alerts and how quickly, where the vulnerability findings actually go, whether the monthly summary lands in front of a human, and a fixed date to re-check device coverage as the estate shifts underneath you. A deployment with no rhythm attached becomes an unread console inside twelve months.
What organizations ask about Defender for Endpoint.
Fifteen questions before you buy or upgrade anything.
What you already have
- Which Microsoft 365 plan do your users hold?Business Premium brings Defender for Business. E3 brings Plan 1.
- Are you under three hundred users?The three hundred user ceiling, which decides which options are open to you.
- Is Defender actually onboarded, or just licensed?A license with no devices onboarded protects nothing.
- How many devices are reporting in the Defender portal?Compare that number to your actual device count.
- Are Macs and mobile devices onboarded too?Cross-platform support exists on all three plans.
Would you use what you are buying
- Do you need detection, or is prevention enough?Plan 1 prevents. It does not detect and respond.
- Would anybody act on an EDR alert at 2am?Detection with no responder changes very little.
- Would you ever need to investigate something that started months back?That is what the Plan 2 retention argument rests on, and it is a genuine one.
- Are attack surface reduction rules actually enabled?Included at every tier and frequently left off.
- Is anyone reading the monthly security summary?Available in Defender for Business and Plan 2.
The parts people forget
- Are your servers licensed?Extra licenses on every plan. Not covered by user licensing.
- Is the server product also in play through Defender for Cloud?There is a documented licensing interaction worth checking.
- Is web content filtering configured, or only threat protection?Two separate things, both in Plan 1 and above.
- Is device control set for removable media?Included, and rarely configured.
- Are you a new customer subject to Unified RBAC?Applies to customers onboarded from February 16, 2025.
The pages around this one.
Microsoft Defender
The wider Defender range spanning endpoints, identity, email and cloud, and how those pieces fit the estate you actually run.
Microsoft Defender XDR
The correlation layer that joins endpoint signals with identity, email and cloud into one incident.
Cybersecurity audit and compliance
A complete posture review, including the question of whether the security capabilities you pay for every month have ever been deployed.
Find out which Defender product you already have.
Business Premium means Defender for Business, which is more capable than most people expect. E3 means Plan 1, which is less capable than most people assume. Then count how many devices are actually onboarded. Those two answers usually decide whether this is a purchase or a deployment.
Related Services
Explore more solutions that work great with this service
Microsoft Defender XDR Services
One incident queue across endpoint, email and identity
Learn moreMicrosoft Defender Vulnerability Management Services
Defender Vulnerability Management deployment for US organizations:
Learn moreMobile Threat Defense with Intune
Mobile Threat Defense integration for US organizations: selecting one
Learn moreMicrosoft Defender
Advanced endpoint and email threat protection
Learn moreEndpoint Security
Endpoint security for US businesses using Microsoft Defender for
Learn moreMicrosoft Security Services
The Microsoft security stack deployed and managed end to end
Learn more