Defender addons vs E5 math
18 Sept 2026
Defender add-ons vs jumping to E5: the actual math
The E5 conversation always arrives the same way. Someone needs one thing — EDR on the laptops, or PIM for the four Global Admins — and the reseller answers with a quote for the whole tenant. From there the decision feels like a coin flip between "buy the one product" and "upgrade everybody", and whichever way it lands, nobody can show the working afterwards.
The working exists. It is not a price comparison, and the reason it isn't is the part almost every quote leaves out.
Buying the four Defender products separately does not reconstruct the Microsoft Defender Suite. Two of the suite's service plans — Entra ID P2 and Office 365 SafeDocs — are not sold inside any Defender component plan. For any group of users who need PIM, risk-based Conditional Access or Safe Documents, the à la carte column isn't cheaper. It's invalid.
Three ways to buy the same posture
Start from Microsoft 365 E3, which is where most of these conversations begin. E3 already carries Microsoft Entra ID P1 and Defender for Office 365 Plan 1 — Conditional Access, Safe Links, Safe Attachments, impersonation protection. That is a real baseline, and it's worth naming because the upgrade is usually sold as if E3 had nothing.
From there, three routes:
| What you want | E3 + components | E3 + Defender Suite | Microsoft 365 E5 |
|---|---|---|---|
| EDR on endpoints (Defender for Endpoint P2) | buy it | included | included |
| Threat Explorer, AIR, attack simulation (MDO P2) | buy it | included | included |
| Defender for Identity, Defender for Cloud Apps | buy them | included | included |
| PIM, Identity Protection (Entra ID P2) | not sold here | included | included |
| Safe Documents (Office 365 SafeDocs) | not sold here | included | included |
| Lifecycle Workflows, ML-assisted access reviews | no | no | still no |
The Defender Suite is the add-on formerly sold as Microsoft 365 E5 Security — Microsoft's own licensing page now carries both names in the same line. It is the middle column, and the middle column is where the interesting rows are.
The two service plans that aren't in the à la carte column
Entra ID P2. The licensing page enumerates every offer that carries it: Microsoft 365 E5, Microsoft 365 E7, Microsoft Defender Suite, the two FLW suites, and Enterprise Mobility + Security E5. No Defender component plan appears on that list. So if the requirement that started the conversation was Privileged Identity Management or risk-based Conditional Access — both P2-only — then buying Defender for Identity does nothing for you. It's a different product with a confusingly adjacent name.
Office 365 SafeDocs. This one is stated outright:
Safe Documents is controlled by the SAFEDOCS service plan
(bf6f5520-59e3-4f82-974b-7dbbc4fd27c7), it ships in Microsoft 365
A5/E5/G5 and the Microsoft Defender Suite, and — the sentence people miss — it
"isn't
included in Microsoft Defender for Office 365 Plan 1 or Plan 2". You can
buy the most expensive email security plan Microsoft sells and still not have
it.
The break-even is a count, not a price
Two reasons this article quotes no per-seat prices. First, nobody pays list — your CSP or EA number is the only one that matters and it's already in your agreement. Second, and more usefully: the price isn't the variable that decides it. The count is.
The arithmetic is per-cohort, not per-tenant. That's the whole trick. Split the headcount into groups by what they genuinely need, then run the comparison inside each group:
- Everyone with a mailbox — do they need MDO Plan 2, or is Plan 1 (already in E3) sufficient? The difference is Threat Explorer instead of Real-time detections, automated investigation and response, campaign views and attack simulation training. That's a SOC capability. A tenant with no SOC is buying a portal page nobody opens.
- People carrying a managed endpoint — Defender for Endpoint Plan 2 is per-seat, and rarely needed by every seat in a company with shared kiosks, frontline devices or contractors.
- Anyone holding a privileged role — this cohort is usually between four and twenty people, and it is the one that needs Entra ID P2. It is also the cohort where the à la carte column doesn't exist.
Sum the per-cohort verdicts and you get a tenant answer that is usually mixed — Suite for forty people, E3 for the rest — rather than the all-or-nothing the quote assumed. The failure mode is pricing 300 seats of E5 against a requirement that belonged to 12 of them.
E5 is not the top of the ladder either
Worth knowing before anyone signs, because it's the reverse of the usual surprise. E5 gives you Entra ID P2, and P2 gives you PIM, Identity Protection and the access-review capabilities that were generally available under P2. It does not give you Microsoft Entra ID Governance — and Lifecycle Workflows, machine-learning-assisted access certifications, access reviews scoped to inactive users and auto-assignment policies all sit behind that licence, which ships in the Entra Suite and Microsoft 365 E7.
So "we went E5 to fix joiner-mover-leaver" is a sentence with a bill attached and no Lifecycle Workflow at the end of it.
Measure the tenant before you price it
Every input above is readable from your own tenant in minutes, and none of it needs a reseller.
The subscribedSku resource returns skuPartNumber, prepaidUnits and consumedUnits per subscription. Done when you have a list of SKUs with a paid-seat number you'd defend in a meeting.
Every SKU carries a servicePlans array, and that is where the tier actually lives — SAFEDOCS either appears under a user's licences or it doesn't. Microsoft's product and service plan reference maps every String ID to skuPartNumber and every GUID to skuId. Done when you can answer "who has Plan 2?" without opening a portal.
Privileged role holders, endpoint carriers, mailbox holders. Three numbers. Done when each one is a count of people rather than a count of licence rows.
Upgrading a dormant account costs the same as upgrading a working one. Run the licence waste audit and the dormant account check first — the E5 quote shrinks before you've negotiated anything. Done when the number you're pricing is a number of humans.
None of this is hard data to get; it's just data nobody assembles before the renewal call. GraphPaaS keeps the SKU and service-plan picture per tenant so the four steps are a page rather than a project, which matters most if you're running the same comparison across a dozen customers.
- Microsoft Entra licensing — which offers carry Entra ID P1 vs P2, that the Defender Suite is the former Microsoft 365 E5 Security, and that PIM, Identity Protection and Lifecycle Workflows sit on different rungs.
- Safe Documents in Microsoft 365 A5/E5/G5 or Microsoft Defender Suite — the SAFEDOCS service plan, which products carry it, and the explicit exclusion from Defender for Office 365 Plan 1 and Plan 2.
- Why do I need Microsoft Defender for Office 365? — the Plan 1 vs Plan 2 cheat sheet, and which bundles include which plan.
- Microsoft Defender for Endpoint — that Microsoft 365 E5 and E5 Security both include Defender for Endpoint Plan 2.
- subscribedSku resource type — the properties behind step 1: skuPartNumber, prepaidUnits, consumedUnits, servicePlans.
- Product names and service plan identifiers for licensing — the String ID to skuPartNumber and GUID to skuId mapping used in step 2.
Know which service plans your tenant actually holds before the renewal call decides for you.
See your licence picture →