Defender for Office 365 Licensing Guide

4 min. readlast update: 09.22.2024

Defender for Office 365 Plan 1 (P1) Features:

Plan 1 provides essential security features focused on protecting your organization from email-based threats. The key features include:

1. Safe Attachments: Scans all attachments in emails for malicious content by sandboxing them before they reach a recipient’s inbox. This ensures that harmful attachments are blocked.
   
2. Safe Links: Protects users by scanning URLs in emails and documents for malicious sites at the time of click. If a link is determined to be malicious, users are warned or blocked from accessing the site.

3. Anti-phishing Policies: Provides protection against phishing attacks by detecting spoofed emails and impersonation attempts. This feature helps safeguard users from social engineering attacks that aim to steal sensitive information.

4. Real-time Threat Detection: Offers immediate alerts for suspicious activities, such as malicious content delivered via emails or collaboration tools like Microsoft Teams, SharePoint, and OneDrive.

5. Internal and External Email Protection: Safeguards both inbound and outbound emails, ensuring that threats are detected and mitigated before they can cause damage.

6. Microsoft Teams Safe Links: Extends the Safe Links feature to Microsoft Teams, ensuring links shared within Teams chats are scanned for potential threats.

Defender for Office 365 Plan 2 (P2) Features:

In addition to all the features provided in P1, Plan 2 introduces several advanced threat detection, investigation, and response capabilities, making it suitable for organizations with higher security requirements.

1. Threat Explorer (Advanced Threat Investigation): Allows security teams to investigate and explore threats in real-time across email and collaboration services. It helps to dig deeper into threat details, track delivery, and get insights into how the threat entered the environment.

2. Automated Investigation and Response (AIR): This feature automatically investigates alerts, gathers data, and remediates threats without the need for human intervention. It significantly reduces the time needed to detect and respond to threats, freeing up security teams to focus on more critical issues.

3. Threat Tracker: Offers insights into the evolving threat landscape. Security teams can use Threat Tracker to monitor global cyber threats and understand how they might affect the organization, providing proactive defense capabilities.

4. Attack Simulation Training: A proactive tool that enables organizations to run phishing attack simulations on their employees. It helps improve user awareness and readiness by simulating real-world phishing attacks, providing feedback, and tracking user behavior.

5. Microsoft 365 Defender (XDR Capabilities): Plan 2 provides extended detection and response capabilities that allow security teams to correlate threats across multiple domains (email, endpoints, identity, and apps). This enables holistic threat hunting and incident correlation across an organization’s assets.

6. Advanced Threat Analytics: Plan 2 offers detailed analytics and reporting on advanced threats, giving security teams comprehensive insights into the organization's security posture and incident history.

Feature Comparison Summary:

- Plan 1 is focused on email protection and includes basic features like Safe Attachments, Safe Links, anti-phishing, and real-time threat detection for emails and documents.
- Plan 2 adds advanced threat protection capabilities, such as automated investigation, threat tracking, attack simulation, and in-depth threat analytics for more comprehensive security 

These features make P2 more suitable for organizations with a higher risk profile, whereas P1 provides sufficient protection for businesses that mainly need to secure email communications.

The pricing for Microsoft Defender for Office 365 plans are as follows:

Defender for Office 365 Plan 1 (P1):
- Cost: $2.00 per user/month (based on an annual commitment).
- Focused on email and collaboration protection with core features like Safe Attachments, Safe Links, and anti-phishing.

Defender for Office 365 Plan 2 (P2):
- Cost: $5.00 per user/month (based on an annual commitment).
- Includes all features of P1, plus advanced threat protection tools like Threat Explorer, Automated Investigation and Response (AIR), and Attack Simulation Training.

These plans can be purchased as standalone licenses or as part of Microsoft 365 subscriptions.

Microsoft Defender for Office 365 Plan 1 (P1) is included with the following Microsoft 365 plans:

  1. Microsoft 365 Business Premium:

    • P1 is bundled as part of the Microsoft 365 Business Premium plan, which is designed for small and medium-sized businesses (SMBs).
  2. Microsoft 365 E3:

    • Defender for Office 365 P1 is included in Microsoft 365 E3, providing essential email protection for enterprises.

Microsoft Defender for Office 365 Plan 2 (P2) is included with the following plans:

1. Microsoft 365 E5:
   - P2 is bundled with Microsoft 365 E5, providing advanced threat protection for enterprises.

2. Office 365 E5:
   - Defender for Office 365 P2 is also included in Office 365 E5, offering robust security features for email and collaboration tools.

3. Microsoft 365 E5 Security Add-on:
   - For organizations with Microsoft 365 E3 or Office 365 E3, P2 can be included through the Microsoft 365 E5 Security Add-on.

Was this article helpful?