Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Review

Defender for Endpoint P1 Review: Prevention Without the Investigation

10 min read Updated October 5, 2026 Microsoft Product Reviews

Fix it now

Plan 1 is a prevention product with three manual response actions and nothing behind them. It blocks, hardens and controls, and it lets you run a scan, isolate a device or add an indicator. It does not build a device timeline, hunt across telemetry, remediate on its own or report vulnerabilities. Buy it knowing that.

  1. Buy it if you already hold Microsoft 365 E3, A3 or G3, because Plan 1 is included and switching it on is the cheapest security improvement available to you.
  2. Buy it if your incident response plan is genuinely to reimage the machine and move on.
  3. Buy it if you need central, cross-platform control of antivirus policy, firewall, web content filtering and removable storage without adding an agent to Windows.
  4. Skip it if you have fewer than 300 users. Defender for Business normally costs less and includes detection and response, automated remediation and core vulnerability management that Plan 1 does not have.
  5. Skip it if anyone will ask what an attacker touched after a detection. That answer only exists in Plan 2.
  6. If you plan to run Plan 1 and Plan 2 in the same tenant, read the mixed-licensing section before you order, because assigning user licences is not what makes it work.

Servers are not left out. Microsoft licenses Defender for Endpoint Plan 1 for servers separately, so a Plan 1 estate with Windows Server machines has a documented route rather than a gap.

If that settles it you can stop here. If you want the exact boundary between Plan 1, Defender for Business and Plan 2, the rest sets it out.

Why it happens

The protection stack in Plan 1 is the full one, and it is worth listing because the plan’s reputation understates it. Next-generation antimalware with behaviour-based, heuristic and real-time protection, cloud-delivered protection for new threats, and tamper protection. Attack surface reduction rules. Controlled folder access for ransomware. Device control governing which removable storage may be read or written. Web protection covering both threats and content filtering. Network protection. Network firewall management. Application control on Windows 10 and later. All of it managed centrally from the Defender portal with role-based access control, reporting and APIs, across Windows and Mac, with mobile threat defence for iOS and Android.

Plan 1 also has three manual response actions, which is the detail most comparisons get wrong by omission. You can run an antivirus scan on a device, isolate a device from the network while keeping its connection to Defender for Endpoint alive, and add an indicator to block or allow a file. That is not investigation and it is not automation, but it is enough to contain a machine while you decide what to do, and any review that says Plan 1 cannot respond at all is describing something else.

What is deliberately missing is the layer that runs after containment. There is no endpoint detection and response, so no device timeline reconstructing what ran and in what order, and no automated investigation that quarantines related artefacts on other machines. There is no advanced hunting, so no query across raw telemetry and no custom detection rules. There is no vulnerability management, so no inventory of outdated software or exposed configurations. The practical consequence is narrow and important: when Plan 1 blocks something, you learn that something was blocked on one machine. You do not learn how it arrived, whether the same thing reached three other people, or what to check next.

The attack surface reduction rules are the part of this plan that earns its keep, and they are the part most often left at defaults. They block the technique rather than the file: Office spawning child processes, scripts running downloaded payloads, credential theft against the LSASS process, executables launching from mail clients. An organisation that turned these on properly would be measurably safer than one that bought a more expensive plan and left it alone. That is not a rhetorical point, it is the reason to buy Plan 1 at all.

The awkward comparison nobody makes for you is with Defender for Business. Under 300 users, Defender for Business includes simplified endpoint detection and response, automated investigation and remediation, automatic attack disruption, threat analytics and core vulnerability management, none of which Plan 1 has. If you are under that ceiling, Plan 1 is very likely both more expensive and less capable for your situation. The reason Plan 1 exists is that it is bundled into Microsoft 365 E3, A3 and G3, where an organisation of any size gets a solid prevention layer without paying for E5.

One more correction to the folklore: the claim that Plan 1 runs the same engine as the Defender already in Windows is not something Microsoft publishes, and it is not the point in any case. What Plan 1 adds is central policy at scale, reporting, role-based access, device control, web content filtering and an API. On one machine there is little visible difference. Across two hundred there is all the difference, and that is what you are paying for.

Full reference

What Plan 1 includes

Area In Plan 1
Next-generation protection Behaviour-based, heuristic and real-time antivirus, cloud-delivered protection, tamper protection
Attack surface reduction ASR rules, controlled folder access, network protection, network firewall, application control
Device control Block or allow removable devices and files on removable devices
Web Web threat protection and web content filtering
Response Run antivirus scan, isolate device, add an indicator to block or allow a file
Management Defender portal, role-based access control, reporting, APIs
Platforms Windows and Mac, with mobile threat defence for iOS and Android

What you need a different plan for

What you need Where it lives
Central antivirus, firewall and ASR policy Plan 1, Defender for Business or Plan 2
Device control over removable storage Plan 1, Defender for Business or Plan 2
Alerts, incidents and a device timeline Defender for Business, simplified, or Plan 2
Automated investigation and remediation Defender for Business or Plan 2
Automatic attack disruption Defender for Business or Plan 2
Vulnerability and software inventory Defender for Business, core capabilities, or Plan 2
Advanced hunting and custom detections Plan 2 only

Running Plan 1 and Plan 2 in the same tenant

This is supported, and it is a sensible way to spend less by giving Plan 2 to the accounts and machines that would matter most in an incident. It is also not what most people assume it is. Microsoft states plainly that assigning user licences in the Microsoft 365 admin centre does not put your tenant into mixed mode. The mechanism is a tenant setting plus device tagging:

  1. Hold active licences for both plans.
  2. In the Defender portal, go to Settings, then Endpoints, then Licenses, and choose to manage subscription settings for Plan 1 and Plan 2.
  3. Tag the client devices that should receive Plan 1 capabilities with the tag License MDE P1, either manually or through a dynamic rule based on device name, domain, operating system platform or existing tags.
  4. Allow up to three hours for tags to apply. Nothing changes until devices are tagged.
  5. Remember that mixed mode applies to client endpoints only. Tagging a server does not change its subscription state.

Defender for Business is not supported in mixed-licence scenarios, and devices tagged through the registry key method do not receive the downgraded functionality. Use a dynamic rule rather than manual tagging if the registry route is how your estate is managed.

Getting the most out of it without spending more

  • Turn on tamper protection first. It is what keeps everything else switched on.
  • Enable attack surface reduction rules in audit mode, read the results for a fortnight, then enforce the ones that produced no legitimate blocks.
  • Configure device control for removable storage. The unmanaged USB stick is still a live route.
  • Use web content filtering, which is in Plan 1 and is one of the few controls that reduces user-driven risk without an agent.
  • Remove local administrator rights. It costs nothing and reduces more risk than most upgrades.

Servers

Plan 1 can be licensed separately for servers, which is the detail that changes the answer for a lot of small estates. That is a different route from Defender for Servers, which is licensed through Defender for Cloud on an Azure subscription and belongs to a different conversation about cloud workload protection. If your entire reason for looking at Plan 1 is server coverage, get both quoted, because the right answer depends on whether the machines are in Azure and whether anyone will use the cloud posture features.

When a licence is the actual fix

Microsoft Defender for Endpoint Plan 1 is the right licence in one specific situation: an organisation too large for Defender for Business that wants centrally managed prevention without paying for the full detection and response stack. If you already hold Microsoft 365 E3, A3 or G3 you own it, and the only work left is enabling it, which costs nothing. Arco can supply Plan 1 as a standalone subscription, and separately for servers where you need it, but we will tell you first whether Defender for Business is the cheaper and stronger answer for your headcount, and whether the step to E5 changes the arithmetic once you count Entra ID and Intune alongside it. If you intend to mix Plan 1 and Plan 2, ask us to walk through the subscription settings and device tagging first, because the licences alone do not produce the result.

Questions people ask about this

Can Plan 1 do anything when it detects something?

Yes, three things: run an antivirus scan on the device, isolate the device from the network while keeping its connection to Defender for Endpoint, and add an indicator to block or allow a file. What it cannot do is tell you what happened, reconstruct a timeline, remediate related artefacts elsewhere, or let you query the telemetry afterwards.

Can I mix Plan 1 and Plan 2 in one tenant?

Yes, but not by licensing alone. Microsoft states that assigning user licences in the admin centre does not put a tenant into mixed mode. You set subscription settings in the Defender portal and then tag client devices with License MDE P1, manually or by dynamic rule, and allow up to three hours for tags to apply. Mixed mode covers client endpoints only, and Defender for Business is not supported in it.

Does Plan 1 include vulnerability management?

No. Defender Vulnerability Management comes with Plan 2 or as an add-on. This is one of the most common misunderstandings about the plan, and it is worth checking against Defender for Business, which includes core vulnerability management and is available to organisations of up to 300 users.

Is Plan 1 the same as the Defender already in Windows?

Not in any way that matters, and Microsoft does not publish an engine comparison, so treat claims either way with suspicion. What Plan 1 adds is central policy at scale, role-based access control, reporting, device control, web content filtering and an API. On one machine there is little visible difference. Across two hundred, that is the whole product.

What is the cheapest honest way to improve endpoint security?

Turn on the attack surface reduction rules you already own, enable tamper protection, and remove local administrator rights. All three cost nothing and reduce more risk than most upgrades do.

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Review Microsoft 365 Business Standard Review: The Default SMB Licence in 2026 Review Microsoft 365 Business Premium Review: Security Worth the Step Up? Review Remote Desktop Services CAL Review: The Licence Everyone Forgets to Buy Review Planner and Project Plan 3 Review 2026: The Manager’s Working Licence
โ† Back to Knowledge Base