Microsoft Defender Plans Pricing
Microsoft Defender is a portfolio of security products with two distinct pricing models. Endpoint / XDR / Identity products (Defender for Endpoint Plan 1/2, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, Defender XDR) are licensed per-user-per-month, often bundled into Microsoft 365 E5 / E5 Security / E5 Mobility + Security. Defender for Cloud (CSPM/CWP) is consumption-priced per resource per hour with Plan 1 (CSPM) free tier and Plan 2 (Defender Plans) per-resource hourly meters. Defender for Business (SMB SKU) is $3/user/month or bundled with M365 Business Premium.
Plans
Core endpoint security — next-gen AV, attack surface reduction, application control, web/network protection, manual response.
- Next-gen antimalware
- Attack surface reduction
- Centralized management
Adds EDR, threat & vulnerability management, automated investigation, Microsoft Threat Experts, sandbox, and advanced hunting.
- EDR with behavioral detection
- Threat & vulnerability management
- Automated investigation & response
- Microsoft Threat Experts
SMB-targeted endpoint protection (≤300 users). Standalone or included with M365 Business Premium.
- SMB-grade endpoint security
- Up to 300 users
- Bundled in M365 Business Premium
Email security — Safe Attachments, Safe Links, anti-phishing.
- Safe Attachments
- Safe Links
- Anti-phishing
Adds Threat Explorer, Threat Trackers, Attack Simulator, and automated investigation/response for email.
- Threat Explorer & hunting
- Attack Simulator
- Automated investigation & response
On-premises Active Directory threat detection.
- AD threat detection
- Lateral movement path analytics
Cloud Access Security Broker; SaaS app discovery and governance.
- SaaS app discovery
- Conditional access app control
- Information protection
Free baseline cloud security posture management for Azure subscriptions. Includes secure-score, recommendations, and asset inventory.
- Secure score
- Asset inventory
- Compliance dashboard (limited)
Premium CSPM with attack-path analysis, agentless vulnerability scanning, data-aware security posture, governance, regulatory compliance.
- Attack path analysis
- Agentless scanning
- Cloud security graph
Server endpoint protection on Azure / AWS / GCP / on-prem (via Arc).
- Microsoft Defender for Endpoint included
- License flexibility (server-by-server)
Adds vulnerability assessment (Qualys/Defender VM), file integrity monitoring, just-in-time VM access, adaptive application controls, network hardening.
- Vulnerability assessment
- File integrity monitoring
- Just-in-time VM access
- Adaptive app controls
Threat detection on Azure Storage (malware scanning, anomalous access).
- Malware scanning on upload
- Anomaly detection
SQL / Cosmos DB / Open-source DBs threat protection.
- SQL injection detection
- Anomaly detection
Kubernetes / container security across AKS, EKS, GKE, on-prem.
- Image vulnerability scanning
- Runtime threat detection
- Kubernetes hardening
Unified XDR portal — included at no extra cost when you license any of the underlying Defender E5 components.
- Cross-domain correlation
- Unified incidents
- Advanced hunting
Microsoft 365 E5 Security add-on bundles Defender for Endpoint P2, Defender for Identity, Defender for Office 365 P2, and Defender for Cloud Apps.
- Defender for Endpoint P2
- Defender for Identity
- Defender for Office 365 P2
- Defender for Cloud Apps
Negotiated rates via EA / MCA / CSP. Often bundled with M365 E5 ELA.
- Volume discount
- M365 E5 ELA bundling
- Dedicated technical account management