Compare Microsoft Defender for Endpoint plans

Microsoft Defender for Endpoint is an enterprise endpoint security platform designed to help enterprise networks prevent, detect, investigate, and respond to advanced threats. Defender for Endpoint provides advanced threat protection that includes antivirus, antimalware, ransomware mitigation, and more, together with centralized management and reporting. You can choose from the following options for Microsoft Defender for Endpoint:

You can use this article to help clarify what protection is provided by the different features available in Defender for Endpoint Plan 1, Defender for Endpoint Plan 2 and the Defender Vulnerability Management add-on.

Defender for Endpoint Plan 1 Defender for Endpoint Plan 2 Defender Vulnerability Management add-on
Next-generation protection
(includes antimalware and antivirus)

Attack surface reduction

Manual response actions

Centralized management

Security reports

APIs

Defender for Endpoint Plan 1 capabilities, plus:

Device discovery

Device inventory

Core Defender Vulnerability Management capabilities

Threat Analytics

Automated investigation and response

Advanced hunting

Endpoint detection and response

Microsoft Threat Experts

Additional Defender Vulnerability Management for Defender for Endpoint Plan 2:

Security baselines assessment

Block vulnerable applications

Browser extensions

Digital certificate assessment

Network share analysis

Support for Windows 10, iOS, Android OS, and macOS devices Support for Windows (client and server) and non-Windows platforms
(macOS, iOS, Android, and Linux)
Support for Windows (client and server) and non-Windows platforms
(macOS, iOS, Android, and Linux)
To try Defender for Endpoint Plan 1, visit https://aka.ms/mdep1trial To try Defender for Endpoint Plan 2, visit https://aka.ms/MDEp2OpenTrial To try Microsoft Defender Vulnerability Management add-on, visit https://aka.ms/AddonPreviewTrial. For more information, see Get Defender Vulnerability Management.

Next steps

See also