The short answer. Defender for Business is not the cheap version of Defender for Endpoint. It sits between Plan 1 and Plan 2. It includes endpoint detection and response and automated investigation and remediation, both of which Plan 1 lacks entirely. What it does not have is the enterprise hunting and analytics layer that Plan 2 adds.
That surprises most people, and it is the single most useful thing to know before you buy.
What each plan includes
| Capability | Defender for Business | Endpoint Plan 1 | Endpoint Plan 2 |
|---|---|---|---|
| Next-generation anti-malware | Yes | Yes | Yes |
| Attack surface reduction rules | Yes | Yes | Yes |
| Device control, firewall, network protection | Yes | Yes | Yes |
| Endpoint detection and response (EDR) | Yes | No | Yes |
| Automated investigation and remediation | Yes | No | Yes |
| Threat and vulnerability management | Partial | No | Yes |
| Threat analytics | No | No | Yes |
| Sandbox / deep analysis | No | No | Yes |
| Microsoft Threat Experts | No | No | Yes |
| User limit | 300 | None | None |
Source: Microsoft Learn, Defender for Business FAQ and the Microsoft Defender service description. Licensing changes; verify against Microsoft before purchase.
Plan 1 vs Plan 2: prevention versus detection
The cleanest way to hold the difference in your head is that Plan 1 is preventive and Plan 2 is investigative.
What Plan 1 gives you
Next-generation anti-malware, attack surface reduction rules, device control, endpoint firewall, network protection and application control. Real controls that stop real attacks. What it does not give you is the ability to see what happened after something got through, or to have the platform respond on its own.
What Plan 2 adds
Endpoint detection and response, automated investigation and remediation, threat and vulnerability management, threat analytics, sandbox deep analysis, and access to Microsoft Threat Experts. This is the tier that assumes you have someone who will actually use a hunting console.
- Defender for Business has EDR and automated remediation. Plan 1 does not.
- Plan 2 is the only tier with advanced hunting, threat analytics and Microsoft Threat Experts.
- Defender for Business caps at 300 users and is included in Microsoft 365 Business Premium.
- Servers are licensed separately under every plan. Budget for them.
Which one fits you
- Under 300 users, no dedicated security staff. Defender for Business, almost always. You likely already own it through Business Premium.
- Over 300 users, or growing through it. Plan 2. Plan the move before you hit the cap, because Microsoft requires the enterprise plan across all users at renewal rather than a partial upgrade.
- Plan 1 only. A narrow fit. It generally makes sense when endpoint detection is already delivered by another platform and you want Microsoft's preventive controls alongside it.
- Regulated environment. If you are subject to CMMC, HIPAA or CJIS, the question is not only which licence but whether you can evidence the controls operating. That usually points to Plan 2 or Defender for Business with a managed detection layer over the top.
The part licensing does not solve
Every one of these plans generates alerts. None of them answers the alert at two in the morning. The most common failure we see is not the wrong licence, it is the right licence with nobody watching the console.
Buying EDR without someone to act on it is buying a smoke alarm for an empty house. The detection works perfectly. Nobody is home.
If that describes your situation, the gap is monitoring rather than tooling. That is what Navigate managed SOC and our endpoint detection and response service exist to cover.
A note on servers and device counts
Each Defender for Business user licence covers up to five client devices, meaning Windows, Mac, Android and iOS. Servers are licensed separately under all three plans. Server licensing is the line item most often missed when organisations budget endpoint security, and it is usually discovered after the purchase order.
Frequently asked questions
What is the difference between Defender for Business and Defender for Endpoint?
Defender for Business is built for organisations up to 300 users and includes endpoint detection and response plus automated investigation and remediation. Defender for Endpoint Plan 1 includes neither. Plan 2 includes both and adds threat and vulnerability management, threat analytics, sandbox analysis and Microsoft Threat Experts. Defender for Business sits between the two plans rather than below both.
What is the difference between Defender for Endpoint Plan 1 and Plan 2?
Plan 1 covers preventive controls: next-generation anti-malware, attack surface reduction rules, device control, endpoint firewall, network protection and application control. Plan 2 includes all of that and adds endpoint detection and response, automated investigation and remediation, threat and vulnerability management, threat analytics, sandbox deep analysis and Microsoft Threat Experts.
Is Defender for Business included in Microsoft 365 Business Premium?
Yes, and it is also sold standalone. Many organisations already own it through Business Premium without having deployed or configured it, which is worth checking before any new purchase.
What happens if we exceed 300 users on Defender for Business?
Microsoft directs organisations past that limit to an enterprise plan such as Defender for Endpoint Plan 2, Microsoft 365 E3 or E5, licensed across all users at renewal. Plan the transition before you reach the cap rather than after.
Does Defender for Business cover servers?
Not under the base user licence. Each licence covers up to five client devices. Servers require separate licensing under every Defender plan.
Keep exploring
- Endpoint detection and response
- Navigate managed SOC
- The different types of cybersecurity
- Navigate Security
Ready for a clear path forward?
Start with a Navigate Clarity Conversation. A free 30 minute review of where you stand and what to do first.
Start with a Clarity Conversation