Skip to content

Est. 2011ยทMicrosoft Partner 7033487ยทDelivery under 3 minยทSupport 7 days a week

Your vault is empty.

Review

Defender for Endpoint P2 Review: Full EDR, If You Have Someone to Run It

10 min read Updated October 5, 2026 Microsoft Product Reviews

Fix it now

Plan 2 is a full endpoint detection and response platform: correlated incidents, a device timeline, automated investigation and remediation, automatic attack disruption, live response into a running machine, vulnerability management and a query language over raw telemetry. It is genuinely capable, and it is the clearest example in Microsoft’s catalogue of a licence that delivers nothing unattended.

  1. Buy it if a named person or a retained provider will look at alerts on a defined schedule. Write down which one before you sign.
  2. Buy it if you must be able to reconstruct an incident afterwards for a regulator, an insurer or a customer.
  3. Buy it if you are heading for Microsoft 365 E5 or E7 anyway, because Plan 2 is included and buying it separately then is waste.
  4. Skip it if the console will be opened during onboarding and never again. Plan 1 or Defender for Business protects you more honestly for less.
  5. Skip it if you have nobody to tune it. Untuned detection and response produces noise, and noise trains people to ignore alerts.
  6. If you are mixing it with Plan 1, set the subscription settings and device tags before you judge the result, because licences alone do not switch a tenant into mixed mode.

Below 300 users, compare it against Defender for Business first. That product includes simplified endpoint detection and response, automated remediation, automatic attack disruption and core vulnerability management, and the missing hunting layer is rarely the constraint at that size.

If that settles it you can stop here. If you want the response layer described properly and the licensing routes compared, keep reading.

Why it happens

With Plan 2 detections stop being isolated events. Related signals across devices, identities and mailboxes are correlated into an incident with a story attached, and each device carries a timeline showing which processes ran, what they wrote and which connections they opened around the event. From the portal you can isolate a device from the network while leaving your management connection alive, restrict it to approved applications, collect an investigation package, and open a live response session to pull files or run scripts without visiting the machine.

Automated investigation and remediation is the part that pays for itself in a small team. When an alert fires the service examines related artefacts on that device and on others, decides which are malicious, and acts according to the automation level you configured. At full automation it closes a large share of routine alerts without a human. Set to semi-automatic it prepares the remediation and waits for approval. Configuring this properly is the single highest-value hour anybody will spend in the console, and it is routinely left at whatever the default was.

Automatic attack disruption sits alongside it and is a different mechanism worth understanding separately. Rather than raising an alert and waiting, it contains an attack that is already in progress, on the reasoning that a compromised account or device is more usefully cut off in the first minutes than investigated in the first hour. It is one of the capabilities Microsoft now lists across Plan 2 and Defender for Business, and it changes what happens on a night when nobody is watching.

Vulnerability management arrives with the plan: software inventory, missing updates, weak configurations and exposed devices, ranked by how exposed you actually are rather than by raw severity. Threat analytics connects current campaigns to your own estate. Endpoint attack notifications bring Microsoft analysts in when they see something targeted at you. Together with the APIs, that is the reference material a responder needs and Plan 1 does not have.

Advanced hunting is the feature that appears in every comparison table and in very few working weeks. It is a query language over raw telemetry: process creation, network connections, file events, registry writes, sign-ins. You can ask a question the product never anticipated, such as which machines executed a particular binary in the last fortnight, and turn a useful query into a custom detection rule that runs on a schedule. Writing useful queries requires familiarity with the schema and time to build a library. If nobody on your side will do that, you are paying for capability you will benefit from only when an incident forces an outside responder to use it, which is real but much narrower than the sales conversation implies. Raw hunting telemetry is also retained for a shorter window than alerts and incidents, so check the current figure against your own reporting obligations rather than assuming it covers a late discovery.

The decision that actually determines whether this licence is worth anything is not technical. Somebody has to work it: an internal person on a defined rhythm, a rota that covers evenings, or a managed detection service. The fourth option, which is nobody, is the most common outcome and the worst possible use of the money. Decide which of those you are before you sign, and write it down where the next person can find it.

Full reference

Operating models, and the one that fails

Operating model What it means in practice Suits
Internal, working hours A named person triages alerts each morning and after lunch An IT team with moderate risk
Internal, on call A rota covers evenings and weekends Regulated or high-value targets with the headcount
Managed by a provider A security provider or Microsoft’s own managed service watches the tenant Teams without the staff or the hours
Nobody Alerts accumulate unread Nobody, and it is still the most common outcome

If the honest answer is the fourth row, either fix that or buy a cheaper plan and spend the difference on backups and multifactor authentication, which protect you without needing an audience. A managed detection and response service on top of Plan 2 is a more honest purchase than a licence nobody works.

Licensing routes

Route What it carries Worth it when
Standalone Defender for Endpoint Plan 2 Plan 2 only You want endpoint coverage and nothing else changes
Microsoft 365 E5 Plan 2 plus the wider security, compliance and analytics stack You would buy several of those components anyway
Microsoft 365 E5 Security, which Microsoft documentation now also calls Microsoft Defender Suite Plan 2 plus the other Defender workloads and Entra ID P2 You are on E3 and want the security half without the rest of E5
Microsoft 365 E7 Everything in E5 plus Microsoft Copilot, the Microsoft Entra Suite and Agent 365 You were already pricing E5 plus Copilot seats
Windows 11 or Windows 10 Enterprise E5, Microsoft 365 A5 or G5 Plan 2 Your estate is licensed that way already

The add-on that used to be quoted as Microsoft 365 E5 Security now appears in some Microsoft documentation as Microsoft Defender Suite. Both names are still in circulation, so match the entitlement list rather than the label on the quote.

Mixing Plan 1 and Plan 2 properly

  1. Hold active licences for both plans.
  2. In the Defender portal, open Settings, then Endpoints, then Licenses, and choose to manage subscription settings for Plan 1 and Plan 2.
  3. Tag the client devices that should get the Plan 1 experience with License MDE P1, manually or by a dynamic rule.
  4. Allow up to three hours for tags to apply. Assigning user licences in the admin centre does not put the tenant into mixed mode on its own.
  5. Remember that mixed mode applies to client endpoints only, and that Defender for Business is not supported in it.

The first month, in order

  1. Onboard, confirm telemetry is arriving, and leave the automation level alone until you can see normal.
  2. Configure automated investigation and remediation deliberately rather than accepting the default.
  3. Turn on attack surface reduction rules in audit mode, then enforce.
  4. Set up device groups that reflect how you would actually respond, not how the org chart looks.
  5. Agree the triage rhythm with the named owner and put it in a calendar. This is the step that decides whether any of the rest matters.

What it does not replace

  • A SIEM. Plan 2 covers endpoints, identity and Microsoft cloud services well. Firewalls, network devices, line-of-business applications and non-Microsoft services still need somewhere to send their logs.
  • Server workload protection in Azure, which is a Defender for Cloud conversation rather than a per-user licence.
  • Backups. Detection and response reduces the chance of a bad week; it does not replace the ability to restore.
  • A person. This is the whole point of the article.

When a licence is the actual fix

Microsoft Defender for Endpoint Plan 2 is the right purchase when somebody will work it. If you have an internal owner, a retained security provider, or a compliance obligation to account for incidents, it is a strong platform and the automated investigation alone reduces real workload. Arco can supply Plan 2 per user, but ask us to compare four routes first: standalone Plan 2, the E5 Security add-on that Microsoft documentation now also calls the Microsoft Defender Suite, full Microsoft 365 E5, and Microsoft 365 E7 if Copilot and the Entra Suite were already on your list. Mixing plans is allowed, so covering administrators and finance with Plan 2 while the rest of the estate runs Plan 1 is a legitimate way to spend less, provided somebody configures the subscription settings and device tags that actually make mixed mode work.

Questions people ask about this

Can we buy Plan 2 for some users and Plan 1 for others?

Yes, and it is a sensible pattern, but it is not automatic. You set the tenant subscription settings in the Defender portal and tag client devices with License MDE P1, by hand or with a dynamic rule, and allow up to three hours. Microsoft states that assigning user licences in the admin centre does not put a tenant into mixed mode, and mixed mode covers client endpoints only.

How long is the hunting data kept?

Raw telemetry for advanced hunting is retained for a shorter window than alerts and incidents. The figure has changed over the product’s life, so check the current retention against your own reporting obligations rather than trusting a number in an article. If you need a longer evidential record, forward the data to a SIEM such as Microsoft Sentinel and pay for storage there.

Does Plan 2 replace a SIEM?

Not entirely. It covers endpoints, identity and Microsoft cloud services well. Firewalls, network devices, line-of-business applications and non-Microsoft services still need somewhere to send their logs, which is where Sentinel or another SIEM comes in.

Is it worth it for fewer than fifty devices?

Usually not on its own. Below 300 users, Defender for Business gives you simplified detection and response, automated remediation, automatic attack disruption and core vulnerability management for less, and the missing hunting layer is rarely the constraint at that size. Note that Defender for Business and Plan 2 cannot be mixed in one tenant.

We are pricing Microsoft 365 E5. Does E7 change the decision?

It might. Microsoft 365 E7 became generally available on 1 May 2026 and is a strict superset of E5, adding Microsoft Copilot, the Microsoft Entra Suite and Agent 365. If you were going to buy E5 and then add Copilot seats for most staff, price E7 against that combination before committing to either.

Was this article helpful?

Your feedback helps us improve our documentation.

Related articles

Review Planner and Project Plan 3 Review 2026: The Manager’s Working Licence Review Azure Virtual Desktop Review: Flexible, Powerful and Harder to Budget Review Windows 11 Home Review 2026: Enough for Most People, Until It Isn’t Review Exchange Server SE Standard Review: On-Prem Mail After the 2019 Era
โ† Back to Knowledge Base