The top Defender for Endpoint licence, part of Microsoft 365 E5. On top of everything in Plan 1 it brings endpoint detection and response, automatic investigation and remediation, vulnerability management, threat analytics and in-depth file analysis.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Defender for Endpoint Plan 2 in context, with comparison tables and the common traps.
Terms in this definition
- Licence
What entitles one particular user to the services a subscription offers. Each product licence is made up of several service plans (one per app or service), and before giving it to someone an admin has to record that user's usage location.
- E5
Top-tier Microsoft 365 licensing bundle that includes Entra ID P2 together with ID Governance capabilities.
- EDR
Defender for Endpoint's endpoint detection and response, which uses behaviour to detect and react to post-breach activity and continues even when Defender Antivirus is passive.
- remediation
Applying updates through vSphere Lifecycle Manager, entering maintenance mode where needed, so that every cluster and host ends up compliant with its image or baselines. Readiness can first be confirmed by a pre-check that changes nothing.
- Threat analytics
Analysis written by Microsoft's security researchers about current attackers and campaigns, indicating whether a given threat is affecting your own organisation. These reports now appear in Intel explorer in the Microsoft Defender portal.
Related terms
- Microsoft Defender for Business
Aimed at firms with 300 users or fewer, this device security product combines next-generation antivirus with endpoint detection and response, and is easier to set up than the enterprise Defender for Endpoint Plan 2.
- Microsoft Defender for Servers
Covers Arc-enabled servers and Azure VMs in Defender for Cloud. Plan 1 brings integration with Defender for Endpoint; Plan 2 goes further with agentless scanning, file integrity monitoring and alerts from Defender for DNS.