We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Security
  2. Defender for Endpoint
Microsoft Defender for Endpoint

The endpoint product bundled with Business Premium is better than the one bundled with E3.

That reads like a mistake, and the published comparison table says it plainly. Defender for Business carries detection and response, investigations that run themselves, automatic attack disruption and vulnerability management. Plan 1, which is what arrives with E3, carries none of the four. Worth establishing before anybody signs anything.

Book an endpoint protection reviewSee what each plan gives you
Microsoft Defender for Endpoint plan comparison for US organizations
  • Business beats P1On six separate capabilities
  • Up to 300 usersThe Defender for Business limit
  • P1 is in E3Prevention, not detection
  • Servers extraLicensed separately on every plan
What each plan actually contains

Eight things to establish before choosing a Defender plan.

Endpoint protection gets sold as one concept and delivered as three genuinely different products. The distinction that matters has nothing to do with which tier sounds most impressive. It is whether the thing can only stop an attack, or can also notice, investigate and respond to one that already got through.

The counter-intuitive part, from Microsoft's own table

The small business product carries investigation and remediation that run without a human, automatic attack disruption, detection and response on the endpoint, threat analytics and core vulnerability management. Plan 1 carries none of them. The documentation states it outright: Defender for Business contains everything in Plan 1, some of what is in Plan 2, and several things unique to itself. Which makes the product aimed at small companies the more capable of the two.

What Plan 1 actually is: prevention, done well

Modern antimalware, rules that shrink the attack surface, ransomware mitigation through controlled folder access, control over removable media, web threat protection and content filtering, network protection, a firewall and application control. On top of that, three actions somebody can take by hand: run a scan, isolate a machine, and add an indicator to block or permit a file. It is a genuinely solid preventive product, and it is not detection and response.

What Plan 2 adds that nothing else has

Exactly two things. Retention, meaning thirty days of advanced hunting and six months of data kept, which is what makes it possible to investigate something that began long before anybody noticed. And access to the Microsoft threat expert service. Everything else people associate with Plan 2, detection and response and automated investigation included, is also present in Defender for Business, and that changes the comparison considerably.

The three hundred user ceiling

The small business product is built for companies of up to three hundred people, and that ceiling is the single constraint deciding whether the capable and inexpensive option is open to you at all. For a great many American small and mid-sized businesses it is. For anybody approaching that number, the transition is worth planning deliberately rather than discovering the limit halfway through a year of hiring.

How you get Defender for Business

It comes with Business Premium, and can be bought on its own by any company up to three hundred people, with Business Basic, Business Standard and the entry Office plan given as examples of where that applies. So an American business already on Business Premium has it sitting there, and one on Business Standard can add it without changing plan at all. Neither of those facts is widely understood.

Servers are licensed separately on every plan

The same note appears against all three options: protecting Windows and Linux servers is possible and needs additional licenses. This catches out anybody assuming the licensing bought for their people covers the machines in the rack too. Plan 1 can be licensed separately for servers, and where the server product is also in play through Defender for Cloud there is a documented interaction between them worth reading rather than guessing at.

Deployment through Intune, or without it

Plan 1 is configured centrally through the Defender portal with device management integrated. The small business product is deliberately built to work whether or not you run a device management platform at all, with guided configuration and sensible default policies, and it carries simplified firewall and antivirus configuration for Windows that neither of the other two provides. For a small team with nobody administering devices full time, that difference is entirely practical rather than cosmetic.

Access control changed for new customers

One detail worth carrying into a deployment. Since 16 February 2025, anybody new to Defender for Endpoint gets the unified access control model only, while existing customers keep whatever roles and permissions they already had. If you are onboarding today, your permission model will not match what the older documentation describes, nor what a colleague who set one up three years ago remembers.

The comparison nobody runs

A company on E3 may well have weaker endpoint protection than one on Business Premium.

This is genuinely counter-intuitive, it comes straight out of the published comparison table, and it changes what people buy. Worth stating carefully, because on first reading it sounds like somebody made an error.

  • E3 brings Plan 1. Business Premium brings Defender for Business. On the published comparison, Defender for Business carries investigation and remediation that run themselves, automatic attack disruption, detection and response on the endpoint, threat analytics, core vulnerability management, and a monthly security summary. Plan 1 carries none of those six.
  • And it goes further than that. Simplified firewall and antivirus configuration for Windows is listed against Defender for Business and against neither of the enterprise plans. On that one capability the product built for small companies is ahead of the flagship. It is a perfectly reasonable design decision and a genuinely surprising fact if nobody has ever shown you the table.
  • What Plan 2 has and Defender for Business does not is far narrower than anybody assumes. Retention, meaning thirty days of advanced hunting and six months of data kept, and the threat expert service. Retention is the substantive one, because it is what lets you investigate an incident that started well before anyone noticed, and that is very nearly always the situation you find yourself in.
  • What that means in practice for an American company. Under three hundred people, Defender for Business is probably the right answer and there is a fair chance you already hold it. On E3, having assumed you had detection and response, you do not, and the real question becomes whether to add Plan 2 or to accept knowingly that you have prevention and no detection. Both of those are defensible positions. Believing you have detection when you have prevention is not, and it is precisely the assumption a cyber insurance questionnaire will ask you to put in writing and sign.
Ask us which plan you actually hold today
How we advise on this

Four things that make this advice worth having.

We resell Microsoft licensing, which means any recommendation to upgrade puts money in our pocket. That makes it worth setting out plainly how we approach the question.

We check what you hold before recommending a plan

A meaningful share of the companies that come to us about endpoint protection already hold Defender for Business inside Business Premium and have never onboarded a single machine to it. In that situation the recommendation is to deploy rather than to buy, and that is the correct answer despite earning us nothing whatsoever in licensing.

You get told when the plan you hold is weaker than you believe

The E3 case is the one that matters most. Companies on E3 routinely believe they have detection and response on the endpoint, and Plan 1 simply does not contain it. That is no criticism of Plan 1, which is a capable preventive product on its own terms. But the gap between what people believe they hold and what they actually hold is exactly where an incident becomes expensive, and exactly where an insurance questionnaire gets answered incorrectly.

We ask who would respond before recommending detection

Detection and response produces alerts, and an alert nobody answers changes nothing at all. Where there is no one to act on a detection outside office hours, the honest recommendation is usually to strengthen prevention and configuration first, or to buy detection alongside somebody who will respond to it. Selling detection into an empty room is a common pattern and an expensive one.

We deploy it properly rather than switching it on

Every device onboarded, Macs and phones included, the attack surface reduction rules enabled deliberately rather than left on whatever arrived, device control and web filtering configured, servers licensed correctly, and the whole thing tuned so that an alert means something. A deployment producing noise nobody reads is functionally identical to no deployment at all.

Which plan fits which organization

Six US situations and what we would usually recommend.

What we recommend genuinely varies with size, with sector, and with whether anybody is available to respond at two in the morning. In two of the six below, the answer is simply to deploy what you already own.

A business under three hundred users on Business Premium

You already hold Defender for Business, which carries detection and response, investigation that runs itself, attack disruption and core vulnerability management. The work here is deployment and configuration rather than purchasing, and it is very often the highest return security project available to an American small business, precisely because the capability has already been paid for and is sitting idle.

An organization on Microsoft 365 E3

What you hold is Plan 1, which prevents and does not detect, investigate or respond. If you assumed otherwise, that assumption is itself the finding. The decision in front of you is whether to add Plan 2 for detection, retention and expert access, or to accept a purely preventive posture on purpose and spend the money somewhere it does more good. Both are legitimate choices. Arriving at one by accident is not.

A firm that must evidence detection capability

When an insurance application, a SOC 2 audit, a HIPAA risk assessment or a questionnaire from a large customer asks specifically about detection and response on endpoints, Plan 1 does not answer that question and either of the other two does. With several carriers this has moved from something affecting your premium to something you must have before they will write the policy at all, and answering accurately depends on knowing which product you genuinely run.

A business that needs to investigate historical incidents

This is the single clearest argument for Plan 2 over anything else. Thirty days of advanced hunting alongside six months of retained data is what makes it possible to reconstruct an incident that began well before anybody noticed it, and that is the normal case rather than the unusual one. Where your obligations or your risk genuinely require that, no other plan provides it.

An organization growing past three hundred users

The small business product stops at three hundred people, so growth eventually forces a change. Planning that in advance is a great deal easier than running into the ceiling halfway through a year of hiring, and the sensible moment to model the move onto Plan 2, or onto a plan containing it, is before the constraint bites rather than the week after.

A company with servers nobody licensed

Protecting servers needs additional licensing on every plan, and companies routinely assume what they bought for their people covers the machines in the rack. What we usually find is that the servers holding the most valuable data are the least protected devices anywhere in the business, which is the exact inverse of what anyone intended and is straightforward to put right once somebody has noticed it.

Three positions

What we typically find when we open up endpoint protection in an American estate.

The middle column is both the most common and the most misleading, because the company holds a license, sincerely believes it has endpoint protection, and has never onboarded half the machines it owns.
Plan matched to size and need
Right plan, fully deployedYes
Licensed, partly onboardedBy accident
Built-in antivirus onlyNot chosen
All devices onboarded and reporting
Right plan, fully deployedYes
Licensed, partly onboardedSome
Built-in antivirus onlyNot applicable
Macs and mobile devices covered
Right plan, fully deployedYes
Licensed, partly onboardedRarely
Built-in antivirus onlyNo
Servers separately licensed
Right plan, fully deployedYes
Licensed, partly onboardedUsually not
Built-in antivirus onlyNo
Attack surface reduction rules enabled
Right plan, fully deployedYes
Licensed, partly onboardedDefault only
Built-in antivirus onlyNo
Detection and response available
Right plan, fully deployedYes
Licensed, partly onboardedDepends on plan
Built-in antivirus onlyNo
Somebody responds to alerts
Right plan, fully deployedYes
Licensed, partly onboardedSometimes
Built-in antivirus onlyNo alerts exist
Could investigate an incident from three months ago
Right plan, fully deployedIf on Plan 2
Licensed, partly onboardedNo
Built-in antivirus onlyNo
Vulnerability position visible
Right plan, fully deployedYes
Licensed, partly onboardedDepends on plan
Built-in antivirus onlyNo
Passes a cyber insurance EDR question honestly
Right plan, fully deployedYes
Licensed, partly onboardedUnclear
Built-in antivirus onlyNo
Feature
Right plan, fully deployed
Licensed, partly onboarded
Built-in antivirus only
Plan matched to size and need
YesBy accidentNot chosen
All devices onboarded and reporting
YesSomeNot applicable
Macs and mobile devices covered
YesRarelyNo
Servers separately licensed
YesUsually notNo
Attack surface reduction rules enabled
YesDefault onlyNo
Detection and response available
YesDepends on planNo
Somebody responds to alerts
YesSometimesNo alerts exist
Could investigate an incident from three months ago
If on Plan 2NoNo
Vulnerability position visible
YesDepends on planNo
Passes a cyber insurance EDR question honestly
YesUnclearNo
The three products side by side

Defender for Business, Plan 1 and Plan 2.

Reproduced from Microsoft's published comparison. Where Microsoft marks a capability as optimized rather than full, that is preserved, because for a small organization the optimized version is frequently the more usable one.

Capability

Next-generation protection

Defender for Business
Yes
Plan 1
Yes
Plan 2
Yes

Capability

Attack surface reduction

Defender for Business
Yes
Plan 1
Yes
Plan 2
Yes

Capability

Centralized management

Defender for Business
Yes
Plan 1
Yes
Plan 2
Yes

Capability

Cross-platform, Mac, iOS, iPadOS, Android

Defender for Business
Yes
Plan 1
Yes
Plan 2
Yes

Capability

APIs

Defender for Business
Yes
Plan 1
Yes
Plan 2
Yes

Capability

Endpoint detection and response

Defender for Business
Yes, optimized
Plan 1
No
Plan 2
Yes

Capability

Automated investigation and remediation

Defender for Business
Yes
Plan 1
No
Plan 2
Yes

Capability

Automatic attack disruption

Defender for Business
Yes
Plan 1
No
Plan 2
Yes

Capability

Threat analytics

Defender for Business
Yes, optimized
Plan 1
No
Plan 2
Yes

Capability

Vulnerability management, core capabilities

Defender for Business
Yes
Plan 1
No
Plan 2
Yes

Capability

Monthly security summary reporting

Defender for Business
Yes
Plan 1
No
Plan 2
Yes

Capability

Simplified firewall and antivirus configuration

Defender for Business
Yes
Plan 1
No
Plan 2
No

Capability

Data retention, 30-day hunting and six months data

Defender for Business
No
Plan 1
No
Plan 2
Yes

Capability

Microsoft Threat Experts

Defender for Business
No
Plan 1
No
Plan 2
Yes

Capability

Windows and Linux server protection

Defender for Business
Extra licenses
Plan 1
Extra licenses
Plan 2
Extra licenses
CapabilityDefender for BusinessPlan 1Plan 2
Next-generation protectionYesYesYes
Attack surface reductionYesYesYes
Centralized managementYesYesYes
Cross-platform, Mac, iOS, iPadOS, AndroidYesYesYes
APIsYesYesYes
Endpoint detection and responseYes, optimizedNoYes
Automated investigation and remediationYesNoYes
Automatic attack disruptionYesNoYes
Threat analyticsYes, optimizedNoYes
Vulnerability management, core capabilitiesYesNoYes
Monthly security summary reportingYesNoYes
Simplified firewall and antivirus configurationYesNoNo
Data retention, 30-day hunting and six months dataNoNoYes
Microsoft Threat ExpertsNoNoYes
Windows and Linux server protectionExtra licensesExtra licensesExtra licenses
How an engagement runs

Five steps, and the first one frequently makes everything after it cheaper.

One to three weeks as a rule, depending how large the estate is. The licensing question gets settled before anything else, because the answer regularly changes the shape of the deployment and occasionally removes the need to buy anything at all.
  1. 1

    Establish which product you actually hold

    Which plans your people are actually on, whether you sit under the three hundred user threshold, and therefore which of the three products you hold, if any. This surprises people in both directions with some regularity, and it is the necessary foundation for every decision that follows.

  2. 2

    Reconcile onboarded devices against real devices

    How many machines report into the portal set against how many the business genuinely uses, counting Macs, phones and servers. That gap is almost always substantial, and a device that was never onboarded is entirely unprotected no matter what you are paying for. Servers make up the largest part of it more often than not.

  3. 3

    Decide the plan honestly against who would respond

    Whether prevention alone is enough for you, whether anybody would act on a detection, and whether being able to investigate history matters enough to justify the Plan 2 retention specifically. If nobody would answer an alert overnight, you hear that said out loud, and the conversation turns to pairing detection with somebody who responds rather than selling a capability into an empty room.

  4. 4

    Deploy and configure, not just enable

    Every machine onboarded, the attack surface reduction rules turned on deliberately rather than left as found, control over removable media configured, web content filtering set up alongside the threat protection, servers licensed correctly, and the detections tuned until an alert is credible enough that somebody actually opens it.

  5. 5

    Establish the operating rhythm

    Who reads the alerts and how quickly, where the vulnerability findings actually go, whether the monthly summary lands in front of a human, and a fixed date to re-check device coverage as the estate shifts underneath you. A deployment with no rhythm attached becomes an unread console inside twelve months.

Straight answers

What organizations ask about Defender for Endpoint.

On the published comparison, yes, across six separate capabilities. The small business product carries detection and response on the endpoint, investigation and remediation that run without a human, automatic attack disruption, threat analytics, core vulnerability management and a monthly security summary. Plan 1 carries none of the six. The documentation describes Defender for Business as containing everything in Plan 1, some of what is in Plan 2, and several things unique to itself. It also carries simplified firewall and antivirus configuration for Windows, which neither enterprise plan provides at all.

Because the small business product stops at three hundred people and Plan 1 does not. Past that threshold Defender for Business is simply unavailable, so the comparison becomes Plan 1 against Plan 2 and nothing else. Plan 1 is also what arrives inside E3, which means a great many companies hold it without having chosen it at any point. It is a capable preventive product. The mistake is assuming it does anything beyond prevent.

Two things on the comparison, and only two. Retention, meaning thirty days of advanced hunting and six months of data kept, and access to the threat expert service. For most companies retention is the substantive one. It is what makes it possible to investigate an incident that began before anybody noticed, which is the normal situation rather than the unusual one, and no other plan offers it.

No. E3 brings Plan 1, and detection and response is not part of Plan 1. What you get is modern antivirus, attack surface reduction, device control, web and network protection, a firewall, application control, and three actions somebody can take by hand: run a scan, isolate a machine, and block or permit a file by indicator. That is meaningful prevention. It is not detection and response, and companies assuming otherwise usually find out while completing a cyber insurance application that asks the question in so many words.

Yes, on all three. The same note appears against every option: protecting Windows and Linux servers is available and needs additional licenses. It catches out anybody assuming that what they bought for their staff covers the whole estate, and the practical result is that the machines holding the most valuable data end up the least protected in the building. Where the server product is also running through Defender for Cloud, there is a documented interaction between the two licenses worth checking rather than guessing at.

Yes, and that is exactly what it was built for. It works whether you already run a device management platform or have only just arrived in the Microsoft cloud, with guided configuration and sensible default policies. It also carries simplified firewall and antivirus configuration for Windows, which is precisely the capability making it usable with no device management platform at all. For a small American business with nobody doing IT full time, that difference is entirely practical.

Yes. Support for Mac, iPhone, iPad and Android is listed against all three products. The gap we actually find in practice is never licensing, it is onboarding. Windows machines get onboarded during a project and the Macs and phones are quietly left behind, so the estate is half covered while the console looks entirely healthy. Reconciling what is onboarded against what genuinely exists is among the first things we do.

They target software behaving in ways that legitimate software rarely does, which happens to describe most of what an attacker needs to do. They come with every tier including Plan 1, and in most estates we look at they are either switched off entirely or sitting on whatever the default was. Enabling them deliberately, after running in audit mode long enough to know what would break, is among the highest value configuration changes available anywhere, and it costs nothing beyond the license already in your hand.

The small business product stops at three hundred people, so past that number the comparison is Plan 1 against Plan 2 and nothing else. This transition goes far better planned than discovered, so anybody approaching the ceiling should model it now. The question that actually matters is whether you have been relying on capabilities present in Defender for Business and in Plan 2 but absent from Plan 1. Where you have, Plan 2 is the like-for-like move and Plan 1 is a downgrade wearing a different name.

For most American companies already inside Microsoft licensing, this is genuinely competitive, and it carries the significant advantage of putting endpoint signals in the same console as identity and email. The honest caveats are three. The capability depends enormously on which plan you hold. Servers need licensing of their own. And a product from another vendor with a managed response service attached will comfortably beat a Defender deployment nobody watches. The product is rarely what decides the outcome. The deployment and the response arrangement almost always are.

This is the antivirus, so nothing separate is needed, and running two real-time engines on one machine causes problems rather than doubling anything. What genuinely is worth checking is whether the antivirus is running in active mode or has quietly dropped into passive mode, which happens when another product is installed and takes precedence over it. Estates that migrated across and never removed the old agent are a finding we make repeatedly.

For an American company running up to a few hundred devices, one to three weeks. Onboarding moves quickly where machines are already managed and slowly where they are not, and Macs and phones invariably take longer than anybody budgeted because nobody planned for them at all. The stage that genuinely consumes time is tuning the attack surface reduction rules, which should run in audit mode first so you find out what would break before anything actually gets blocked. Commercially each engagement is scoped on its own, by device count, by platform mix and by whether servers are included. What costs nothing in the first conversation is establishing which product your existing licensing already gives you and how many devices are genuinely onboarded. For a meaningful number of companies those two answers together reveal that the capability was bought years ago and has been sitting idle ever since.
Work out where you stand

Fifteen questions before you buy or upgrade anything.

The first block establishes what you already own, which quite often ends the conversation there. The second tests whether the capability would ever actually get used. The third covers the parts of the estate everybody forgets to license until something goes wrong on one of them.

What you already have

  • Which Microsoft 365 plan do your users hold?
    Business Premium brings Defender for Business. E3 brings Plan 1.
  • Are you under three hundred users?
    The three hundred user ceiling, which decides which options are open to you.
  • Is Defender actually onboarded, or just licensed?
    A license with no devices onboarded protects nothing.
  • How many devices are reporting in the Defender portal?
    Compare that number to your actual device count.
  • Are Macs and mobile devices onboarded too?
    Cross-platform support exists on all three plans.

Would you use what you are buying

  • Do you need detection, or is prevention enough?
    Plan 1 prevents. It does not detect and respond.
  • Would anybody act on an EDR alert at 2am?
    Detection with no responder changes very little.
  • Would you ever need to investigate something that started months back?
    That is what the Plan 2 retention argument rests on, and it is a genuine one.
  • Are attack surface reduction rules actually enabled?
    Included at every tier and frequently left off.
  • Is anyone reading the monthly security summary?
    Available in Defender for Business and Plan 2.

The parts people forget

  • Are your servers licensed?
    Extra licenses on every plan. Not covered by user licensing.
  • Is the server product also in play through Defender for Cloud?
    There is a documented licensing interaction worth checking.
  • Is web content filtering configured, or only threat protection?
    Two separate things, both in Plan 1 and above.
  • Is device control set for removable media?
    Included, and rarely configured.
  • Are you a new customer subject to Unified RBAC?
    Applies to customers onboarded from February 16, 2025.
Related reading

The pages around this one.

Microsoft Defender

The wider Defender range spanning endpoints, identity, email and cloud, and how those pieces fit the estate you actually run.

Learn more

Microsoft Defender XDR

The correlation layer that joins endpoint signals with identity, email and cloud into one incident.

Learn more

Cybersecurity audit and compliance

A complete posture review, including the question of whether the security capabilities you pay for every month have ever been deployed.

Learn more
Next step

Find out which Defender product you already have.

Business Premium means Defender for Business, which is more capable than most people expect. E3 means Plan 1, which is less capable than most people assume. Then count how many devices are actually onboarded. Those two answers usually decide whether this is a purchase or a deployment.

Book an endpoint protection reviewSee the Microsoft security stack

Related Services

Explore more solutions that work great with this service

Microsoft Defender XDR Services

One incident queue across endpoint, email and identity

Learn more

Microsoft Defender Vulnerability Management Services

Defender Vulnerability Management deployment for US organizations:

Learn more

Mobile Threat Defense with Intune

Mobile Threat Defense integration for US organizations: selecting one

Learn more

Microsoft Defender

Advanced endpoint and email threat protection

Learn more

Endpoint Security

Endpoint security for US businesses using Microsoft Defender for

Learn more

Microsoft Security Services

The Microsoft security stack deployed and managed end to end

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA