Defender addons vs E5 math

18 Sept 2026

Defender add-ons vs jumping to E5: the actual math

The E5 conversation always arrives the same way. Someone needs one thing — EDR on the laptops, or PIM for the four Global Admins — and the reseller answers with a quote for the whole tenant. From there the decision feels like a coin flip between "buy the one product" and "upgrade everybody", and whichever way it lands, nobody can show the working afterwards.

The working exists. It is not a price comparison, and the reason it isn't is the part almost every quote leaves out.

TL;DR

Buying the four Defender products separately does not reconstruct the Microsoft Defender Suite. Two of the suite's service plans — Entra ID P2 and Office 365 SafeDocs — are not sold inside any Defender component plan. For any group of users who need PIM, risk-based Conditional Access or Safe Documents, the à la carte column isn't cheaper. It's invalid.

Three ways to buy the same posture

Start from Microsoft 365 E3, which is where most of these conversations begin. E3 already carries Microsoft Entra ID P1 and Defender for Office 365 Plan 1 — Conditional Access, Safe Links, Safe Attachments, impersonation protection. That is a real baseline, and it's worth naming because the upgrade is usually sold as if E3 had nothing.

From there, three routes:

What you want E3 + components E3 + Defender Suite Microsoft 365 E5
EDR on endpoints (Defender for Endpoint P2) buy it included included
Threat Explorer, AIR, attack simulation (MDO P2) buy it included included
Defender for Identity, Defender for Cloud Apps buy them included included
PIM, Identity Protection (Entra ID P2) not sold here included included
Safe Documents (Office 365 SafeDocs) not sold here included included
Lifecycle Workflows, ML-assisted access reviews no no still no

The Defender Suite is the add-on formerly sold as Microsoft 365 E5 Security — Microsoft's own licensing page now carries both names in the same line. It is the middle column, and the middle column is where the interesting rows are.

The two service plans that aren't in the à la carte column

Entra ID P2. The licensing page enumerates every offer that carries it: Microsoft 365 E5, Microsoft 365 E7, Microsoft Defender Suite, the two FLW suites, and Enterprise Mobility + Security E5. No Defender component plan appears on that list. So if the requirement that started the conversation was Privileged Identity Management or risk-based Conditional Access — both P2-only — then buying Defender for Identity does nothing for you. It's a different product with a confusingly adjacent name.

Office 365 SafeDocs. This one is stated outright: Safe Documents is controlled by the SAFEDOCS service plan (bf6f5520-59e3-4f82-974b-7dbbc4fd27c7), it ships in Microsoft 365 A5/E5/G5 and the Microsoft Defender Suite, and — the sentence people miss — it "isn't included in Microsoft Defender for Office 365 Plan 1 or Plan 2". You can buy the most expensive email security plan Microsoft sells and still not have it.

THE LADDER, AND THE BRANCH THAT DOESN'T REJOIN IT Microsoft 365 E3 Entra ID P1 · Defender for Office 365 P1 + Microsoft Defender Suite MDE P2 · MDO P2 · Identity · Cloud Apps + Entra ID P2 · Office 365 SafeDocs sold only in this box and above Microsoft 365 E5 the Suite, plus the non-security half Entra Suite / Microsoft 365 E7 Entra ID Governance — not in E5 THE À LA CARTE PATH Four products, bought separately Defender for Endpoint P2 Defender for Office 365 P2 Defender for Identity · Defender for Cloud Apps Not purchasable on this path Entra ID P2 — PIM, Identity Protection Office 365 SafeDocs

The break-even is a count, not a price

Two reasons this article quotes no per-seat prices. First, nobody pays list — your CSP or EA number is the only one that matters and it's already in your agreement. Second, and more usefully: the price isn't the variable that decides it. The count is.

The arithmetic is per-cohort, not per-tenant. That's the whole trick. Split the headcount into groups by what they genuinely need, then run the comparison inside each group:

  • Everyone with a mailbox — do they need MDO Plan 2, or is Plan 1 (already in E3) sufficient? The difference is Threat Explorer instead of Real-time detections, automated investigation and response, campaign views and attack simulation training. That's a SOC capability. A tenant with no SOC is buying a portal page nobody opens.
  • People carrying a managed endpoint — Defender for Endpoint Plan 2 is per-seat, and rarely needed by every seat in a company with shared kiosks, frontline devices or contractors.
  • Anyone holding a privileged role — this cohort is usually between four and twenty people, and it is the one that needs Entra ID P2. It is also the cohort where the à la carte column doesn't exist.

Sum the per-cohort verdicts and you get a tenant answer that is usually mixed — Suite for forty people, E3 for the rest — rather than the all-or-nothing the quote assumed. The failure mode is pricing 300 seats of E5 against a requirement that belonged to 12 of them.

E5 is not the top of the ladder either

Worth knowing before anyone signs, because it's the reverse of the usual surprise. E5 gives you Entra ID P2, and P2 gives you PIM, Identity Protection and the access-review capabilities that were generally available under P2. It does not give you Microsoft Entra ID Governance — and Lifecycle Workflows, machine-learning-assisted access certifications, access reviews scoped to inactive users and auto-assignment policies all sit behind that licence, which ships in the Entra Suite and Microsoft 365 E7.

So "we went E5 to fix joiner-mover-leaver" is a sentence with a bill attached and no Lifecycle Workflow at the end of it.

Measure the tenant before you price it

Every input above is readable from your own tenant in minutes, and none of it needs a reseller.

1
List what you already own.

The subscribedSku resource returns skuPartNumber, prepaidUnits and consumedUnits per subscription. Done when you have a list of SKUs with a paid-seat number you'd defend in a meeting.

2
Read the service plans, not the SKU names.

Every SKU carries a servicePlans array, and that is where the tier actually lives — SAFEDOCS either appears under a user's licences or it doesn't. Microsoft's product and service plan reference maps every String ID to skuPartNumber and every GUID to skuId. Done when you can answer "who has Plan 2?" without opening a portal.

3
Size the cohorts.

Privileged role holders, endpoint carriers, mailbox holders. Three numbers. Done when each one is a count of people rather than a count of licence rows.

4
Subtract the seats that shouldn't be there.

Upgrading a dormant account costs the same as upgrading a working one. Run the licence waste audit and the dormant account check first — the E5 quote shrinks before you've negotiated anything. Done when the number you're pricing is a number of humans.

None of this is hard data to get; it's just data nobody assembles before the renewal call. GraphPaaS keeps the SKU and service-plan picture per tenant so the four steps are a page rather than a project, which matters most if you're running the same comparison across a dozen customers.

Sources
GraphPaaS

Know which service plans your tenant actually holds before the renewal call decides for you.

See your licence picture →

Newsletter

Get the next article by email

Practical M365 & Azure cost pieces like this one. No spam, unsubscribe anytime.