
Microsoft Defender for Endpoint P1 Annual Subscription (12 Months)
PRODUCT DESCRIPTION
Microsoft Defender for Endpoint Plan 1 Annual Subscription (CFQ7TTC0J1GB:0003) - Local Support
Preventive Endpoint Protection, Without the Detection and Response Layer
Microsoft describes Defender for Endpoint as "an enterprise endpoint security platform designed to help organizations prevent, detect, investigate, and respond to advanced threats on their endpoints". Plan 1 is the preventive half of that sentence. It is the right plan when you want strong, centrally managed protection across Windows, macOS, Linux, Android and iOS, and you are not yet running a security operations function that would use detection and response tooling.
What Plan 1 Includes
Microsoft's Plan 1 overview lists next-generation protection described as "industry-leading, robust antimalware and antivirus protection"; "Manual response actions - such as sending a file to quarantine"; and an attack surface reduction set comprising attack surface reduction rules, ransomware mitigation through controlled folder access, device control, web protection, network protection, network firewall and application control. It adds centralised configuration and management through the Microsoft Defender portal with Intune integration, role-based access control, reporting and APIs. Application control is available on Windows 10 or later.
What Plan 1 Does Not Include
This is the part worth reading twice. Across Microsoft's surviving comparison sources, the capabilities that are Plan 2 only are endpoint detection and response, automated investigation and remediation, threat and vulnerability management, threat analytics, Microsoft Threat Experts, and the six-month data retention with thirty days of advanced hunting. If a security operations team, a managed detection and response provider or an auditor is expecting to see EDR telemetry, Plan 1 will not give it to them. Ask us to price Plan 2 alongside this.
Servers Are Not Included in Either Plan
Microsoft states it plainly: "Defender for Endpoint Plan 1 and Plan 2 do not include server licenses." Server coverage comes from Microsoft Defender for Servers Plan 1 or Plan 2 through Defender for Cloud, from Microsoft Defender for Endpoint Server, or from Microsoft Defender for Business servers. Count your servers separately when you size this and we will quote them properly.
Defender for Endpoint Plan 1 Annual Subscription Datasheet — Licensing and Specifications
Licensing
| Licensed by | Per user, as a user subscription licence |
| Included in | Microsoft 365 E3, A3 and G3, and available as a standalone user subscription licence |
| Server coverage | Not included. Microsoft: "Defender for Endpoint Plan 1 and Plan 2 do not include server licenses" |
| Minimum purchase | Not published by Microsoft |
| Term | Twelve months as sold by SourceIT |
Capabilities Microsoft Lists in Plan 1
| Next-generation protection | Included — "industry-leading, robust antimalware and antivirus protection" |
| Attack surface reduction | Included — attack surface reduction rules, ransomware mitigation through controlled folder access, device control, web protection, network protection, network firewall and application control |
| Manual response actions | Included — "such as sending a file to quarantine" |
| Central management | Included — Microsoft Defender portal, Intune integration, role-based access control, reporting and APIs |
| Cross-platform | Included — macOS, iOS, iPadOS and Android |
| Endpoint detection and response | Plan 2 only |
| Automated investigation and remediation | Plan 2 only |
| Vulnerability management | Plan 2 only |
| Threat analytics and Microsoft Threat Experts | Plan 2 only |
| Data retention | Plan 2 only for six months of retention with 30 days of advanced hunting |
Where Microsoft's Own Sources Disagree
| Web protection, controlled folder access and manual response | The Plan 1 overview page includes all three in Plan 1. The Defender service description's Plan 1 list omits them. Both are current Microsoft pages |
| Sandbox and advanced hunting | The service description names sandbox, or deep analysis, as a Plan 2 differentiator. The surviving comparison table has no sandbox row and reaches advanced hunting only through its retention row |
| Attack disruption and monthly reporting | The comparison table adds automatic attack disruption and monthly security summary reporting as Plan 2 items; the service description does not mention either |
| The page that used to settle it | Microsoft has withdrawn its dedicated Plan 1 and Plan 2 comparison page, so it is not linked from this listing |
Data Residency and Retention
| Where the data sits | The two Microsoft pages disagree. The data storage and privacy page says Defender for Endpoint "operates in the Microsoft Azure data centers in the European Union, the United Kingdom, the United States, Australia, Switzerland, India, or the United Arab Emirates". The minimum requirements page offers only "European Union datacenter, United Kingdom datacenter, United States datacenter" |
| Singapore | Not listed on either page. A Singapore tenant will be stored outside Singapore |
| Changing it later | "Data storage location cannot be changed after initial setup" |
| Retention | Microsoft publishes 180 days of retention for the product, and 30 days in the advanced hunting investigation experience. The comparison table marks six months of retention with 30 days of advanced hunting as Plan 2 only, so a Plan 1 subscription should not be sized on these figures |
What Microsoft Does Not Publish for This Product
The following are commonly asked about but are not stated on any current official Microsoft source for this product, so SourceIT does not quote them: a minimum seat count, any Singapore data residency option, a current single-page Plan 1 and Plan 2 comparison and a mapping between the commerce SKU identifier and this product. We would rather leave a field blank than print a figure we cannot substantiate.
Lifecycle, End of Support and Entitlement
SourceIT sells this as a twelve-month subscription with a GST invoice in Singapore. The subscription is a right to use the service for the term, not a perpetual licence: when the term ends the entitlement ends unless it is renewed.
Microsoft's lifecycle page places Defender for Endpoint under the Component Lifecycle Policy with a start date of 2 August 2016 and an end date shown as "See Note". No retirement date is published. The product has been renamed twice: Microsoft's lifecycle note reads "Windows Defender Advanced Threat Protection is now called Microsoft Defender for Endpoint", and Microsoft's 2020 announcement confirms "Microsoft Defender for Endpoint (previously Microsoft Defender Advanced Threat Protection)".
Talk to our team before the renewal date rather than after it. Seat counts, mid-term changes and co-terming with the rest of your Microsoft estate are all easier to arrange in advance, and we can quote the alternatives if a bundle would work out better for you.
Published Lifecycle Dates
| Lifecycle policy | Component Lifecycle Policy per Microsoft's lifecycle page |
| Start date | 2 August 2016 |
| End date | "See Note" — no retirement date is published |
| Former names | Windows Defender Advanced Threat Protection, then Microsoft Defender Advanced Threat Protection. Microsoft's lifecycle note reads: "Windows Defender Advanced Threat Protection is now called Microsoft Defender for Endpoint" |
Support and Entitlement Position
This is a software subscription, not hardware. It carries no hardware warranty, and any warranty term you see on a hardware listing does not apply here. What you are buying is a twelve-month right to use the service, together with SourceIT's local support in Singapore. Microsoft's own condition is that technical and billing support for a subscription bought through a partner runs through that partner, so for this subscription that means us: raise the ticket with SourceIT and we escalate to Microsoft where it needs to go. Renewal, seat changes and co-terming are handled on your SourceIT account. Ask our team for the current entitlement position in writing with your quotation.
Compatibility, Deployment and System Requirements
Check what you already own before you buy this. Several Microsoft 365 and Enterprise Mobility + Security bundles already include this service, and a tenant that buys it separately can end up paying twice for the same entitlement. Send us your current subscription list and we will check your existing entitlements before we quote.
Neither plan includes server licences. Microsoft states it directly: "Defender for Endpoint Plan 1 and Plan 2 do not include server licenses." Servers are covered by Microsoft Defender for Servers Plan 1 or Plan 2 through Defender for Cloud, by Microsoft Defender for Endpoint Server, or by Microsoft Defender for Business servers. This is the most expensive assumption a buyer makes on this product, so count your servers separately and ask us to quote them.
Microsoft's published hardware floor is modest — "Cores: 2 minimum, 4 preferred; Memory: 1 GB minimum, 4 GB preferred" — and "IPv4 must be enabled". Onboarded devices must be excluded from any group policy that disables Microsoft Defender Antivirus, and security intelligence updates must be configured on every onboarded device; where Defender Antivirus is not the active antivirus product it runs in passive mode.
Microsoft does not name Microsoft Entra ID or Microsoft Intune as a hard prerequisite on its minimum requirements page, so this page does not claim one. Intune is one of several supported onboarding routes rather than a requirement.
Platform Support and Deployment
| Windows client | Windows 10 and 11 Enterprise, IoT Enterprise, Education, Pro and Pro Education, including Windows on Arm; Windows Enterprise LTSC 2016 and later; Windows Enterprise multi-session; Windows 7 SP1 Pro and Enterprise via the Defender deployment tool; Windows 8.1 Pro and Enterprise via Log Analytics |
| Windows Server | 2012 R2 and later including Core; Semi-Annual Channel 1803 and later; 2008 R2 SP1 via the Defender deployment tool. Server coverage requires separate licences |
| Virtual | Windows 365 Cloud PCs; Azure Virtual Desktop; Azure Local nodes on Azure Stack HCI OS 23H2 and later |
| Other platforms | macOS, Linux, Windows Subsystem for Linux, Android and iOS |
| Hardware floor | "Cores: 2 minimum, 4 preferred; Memory: 1 GB minimum, 4 GB preferred". IPv4 must be enabled |
| Onboarding routes | Defender deployment tool, Intune or MDM, Configuration Manager, local script for up to 10 devices, Group Policy, non-persistent VDI, Azure Virtual Desktop, SCEP; JAMF Pro for macOS; installer script, Ansible, Chef, Puppet or Saltstack for Linux |
Official Microsoft Sources & Downloads
- Microsoft Defender for Endpoint overview (Microsoft Learn)
- Overview of Defender for Endpoint Plan 1 (Microsoft Learn)
- Defender for Endpoint minimum requirements (Microsoft Learn)
- Defender for Endpoint deployment strategy (Microsoft Learn)
- Defender for Endpoint data storage and privacy (Microsoft Learn)
- What is Microsoft Defender for Business, with the Plan 1 and Plan 2 table (Microsoft Learn)
- Microsoft Defender service description (Microsoft Learn)
- Microsoft Defender for Endpoint lifecycle (Microsoft Learn)
- Microsoft security product renaming announcement, 22 September 2020
- Modern Lifecycle Policy (Microsoft Learn)
Where a figure appears on this page it is quoted from one of these Microsoft pages; where Microsoft publishes nothing, this page says so rather than filling the gap. Supplied by SourceIT in Singapore with a GST invoice and local support. For a written quotation, current stock position or delivery lead time, contact our team.
Frequently Asked Questions — Defender for Endpoint Plan 1 Annual Subscription
What is the actual difference between Plan 1 and Plan 2?
Across Microsoft's surviving sources the capabilities that are Plan 2 only are endpoint detection and response, automated investigation and remediation, threat and vulnerability management, threat analytics, Microsoft Threat Experts, and six months of data retention with thirty days of advanced hunting. Plan 1 is the preventive stack: next-generation antivirus, attack surface reduction, device control, web and network protection, firewall, application control and manual response actions. Note that Microsoft's three current sources do not carry identical row lists and the page that used to reconcile them has been withdrawn.
Does this cover our servers?
No. Microsoft states: "Defender for Endpoint Plan 1 and Plan 2 do not include server licenses." Servers need Microsoft Defender for Servers Plan 1 or Plan 2 through Defender for Cloud, Microsoft Defender for Endpoint Server, or Microsoft Defender for Business servers. Tell us your server count and we will quote it separately.
We have Microsoft 365 E3. Do we already have this?
Yes. Microsoft lists Defender for Endpoint Plan 1 as included in Microsoft 365 E3, A3 and G3. If your users are on E3 you already hold this entitlement, and the useful conversation is whether Plan 2 is worth adding rather than whether to buy Plan 1 again.
Which operating systems does it support?
Microsoft lists Windows 10 and 11 in Enterprise, IoT Enterprise, Education, Pro and Pro Education editions including Windows on Arm, Windows Enterprise LTSC 2016 and later, Windows Enterprise multi-session, Windows 7 SP1 and 8.1 through specific routes, Windows Server 2012 R2 and later, Windows 365 Cloud PCs, Azure Virtual Desktop, macOS, Linux, Windows Subsystem for Linux, Android and iOS. Server coverage still needs its own licence.
Where is the data stored, and can we choose Singapore?
Not Singapore. Microsoft's two current pages give different region lists — one names the European Union, United Kingdom, United States, Australia, Switzerland, India and the United Arab Emirates; the other offers only European Union, United Kingdom and United States at onboarding. Singapore appears on neither. Microsoft also states that "Data storage location cannot be changed after initial setup", so this is a decision to get right the first time.
