
Microsoft Defender for Endpoint P2 Annual Subscription (12 Months)
PRODUCT DESCRIPTION
Microsoft Defender for Endpoint Plan 2 Annual Subscription (CFQ7TTC0LGV0:0001) - Local Support
Everything in Plan 1, Plus Detection, Response and Vulnerability Management
Plan 2 is the full Defender for Endpoint platform: Microsoft describes the product as one "designed to help organizations prevent, detect, investigate, and respond to advanced threats on their endpoints", and Plan 2 is the plan that delivers all four verbs. It includes every Plan 1 capability and adds the detection and response layer that a security operations team, a managed detection and response provider or an auditor will expect to see.
What Plan 2 Adds Over Plan 1
Microsoft's sources agree on the core additions: endpoint detection and response, automated investigation and remediation, threat and vulnerability management, threat analytics and Microsoft Threat Experts. The surviving comparison table also shows automatic attack disruption, monthly security summary reporting and the retention line "30 days advanced hunting; six months of data retention" as Plan 2 only. The Defender service description separately names sandbox, or deep analysis, as a Plan 2 differentiator.
Six Months of Retention and Thirty Days of Advanced Hunting
Retention is often the deciding factor. Microsoft's retention statement for the product is that data "is retained for 180 days, visible across the portal", and that in the advanced hunting investigation experience "it's accessible via a query for 30 days". If your incident response process or your regulator expects you to be able to hunt back across historical endpoint telemetry, this is the plan that gives you it.
Servers Are Still Not Included
The same warning applies to Plan 2 as to Plan 1, and Microsoft's wording covers both: "Defender for Endpoint Plan 1 and Plan 2 do not include server licenses." Server coverage comes from Microsoft Defender for Servers Plan 1 or Plan 2 through Defender for Cloud, from Microsoft Defender for Endpoint Server, or from Microsoft Defender for Business servers. Count your servers separately and ask us to quote them.
Defender for Endpoint Plan 2 Annual Subscription Datasheet — Licensing and Specifications
Licensing
| Licensed by | Per user, as a user subscription licence |
| Included in | Microsoft 365 E5, A5 and G5, which include Windows 10 and 11 Enterprise E5; Windows 11 Enterprise E5 and A5; Windows 10 Enterprise E5 and A5; Microsoft 365 E5 Security; the Microsoft Defender Suite and its EDU, GOV and FLW variants; and Microsoft Defender + Purview Suite FLW. Also available standalone |
| Server coverage | Not included. Microsoft: "Defender for Endpoint Plan 1 and Plan 2 do not include server licenses" |
| Minimum purchase | Not published by Microsoft |
| Term | Twelve months as sold by SourceIT |
What Plan 2 Adds Over Plan 1
| Endpoint detection and response | Plan 2 only |
| Automated investigation and remediation | Plan 2 only |
| Automatic attack disruption | Plan 2 only, per the surviving comparison table |
| Threat and vulnerability management | Plan 2 only |
| Threat analytics | Plan 2 only |
| Microsoft Threat Experts | Plan 2 only |
| Sandbox and deep analysis | Named as a Plan 2 differentiator by the Defender service description; absent from the comparison table |
| Monthly security summary reporting | Plan 2 only, per the surviving comparison table |
| Data retention | "30 days advanced hunting; six months of data retention", Plan 2 only |
| Everything in Plan 1 | Included — next-generation protection, attack surface reduction, device control, web and network protection, firewall, application control, manual response actions and central management |
Where Microsoft's Own Sources Disagree
| The withdrawn comparison page | Microsoft has withdrawn its dedicated Plan 1 and Plan 2 comparison page. It is not linked here |
| Row lists differ | The Defender service description, the Plan 1 overview and the Defender for Business comparison table each carry a different row list. The additions named above are those the sources support between them |
| Vulnerability management naming | The comparison table calls it "Vulnerability management (core capabilities)"; the service description calls the same thing "threat and vulnerability management" |
Data Residency and Retention
| Where the data sits | The two Microsoft pages disagree. The data storage and privacy page says Defender for Endpoint "operates in the Microsoft Azure data centers in the European Union, the United Kingdom, the United States, Australia, Switzerland, India, or the United Arab Emirates". The minimum requirements page offers only "European Union datacenter, United Kingdom datacenter, United States datacenter" |
| Singapore | Not listed on either page. A Singapore tenant will be stored outside Singapore |
| Changing it later | "Data storage location cannot be changed after initial setup" |
| Retention | Microsoft publishes 180 days of retention for the product, and 30 days in the advanced hunting investigation experience. The comparison table marks six months of retention with 30 days of advanced hunting as Plan 2 only, so a Plan 1 subscription should not be sized on these figures |
What Microsoft Does Not Publish for This Product
The following are commonly asked about but are not stated on any current official Microsoft source for this product, so SourceIT does not quote them: a minimum seat count, any Singapore data residency option, a current single-page Plan 1 and Plan 2 comparison and a mapping between the commerce SKU identifier and this product. We would rather leave a field blank than print a figure we cannot substantiate.
Lifecycle, End of Support and Entitlement
SourceIT sells this as a twelve-month subscription with a GST invoice in Singapore. The subscription is a right to use the service for the term, not a perpetual licence: when the term ends the entitlement ends unless it is renewed.
Microsoft's lifecycle page places Defender for Endpoint under the Component Lifecycle Policy with a start date of 2 August 2016 and an end date shown as "See Note". No retirement date is published. Former names customers still search for are Windows Defender Advanced Threat Protection and Microsoft Defender Advanced Threat Protection.
Talk to our team before the renewal date rather than after it. Seat counts, mid-term changes and co-terming with the rest of your Microsoft estate are all easier to arrange in advance, and we can quote the alternatives if a bundle would work out better for you.
Published Lifecycle Dates
| Lifecycle policy | Component Lifecycle Policy per Microsoft's lifecycle page |
| Start date | 2 August 2016 |
| End date | "See Note" — no retirement date is published |
| Former names | Windows Defender Advanced Threat Protection, then Microsoft Defender Advanced Threat Protection. Microsoft's lifecycle note reads: "Windows Defender Advanced Threat Protection is now called Microsoft Defender for Endpoint" |
Support and Entitlement Position
This is a software subscription, not hardware. It carries no hardware warranty, and any warranty term you see on a hardware listing does not apply here. What you are buying is a twelve-month right to use the service, together with SourceIT's local support in Singapore. Microsoft's own condition is that technical and billing support for a subscription bought through a partner runs through that partner, so for this subscription that means us: raise the ticket with SourceIT and we escalate to Microsoft where it needs to go. Renewal, seat changes and co-terming are handled on your SourceIT account. Ask our team for the current entitlement position in writing with your quotation.
Compatibility, Deployment and System Requirements
Check what you already own before you buy this. Several Microsoft 365 and Enterprise Mobility + Security bundles already include this service, and a tenant that buys it separately can end up paying twice for the same entitlement. Send us your current subscription list and we will check your existing entitlements before we quote.
Neither plan includes server licences. Microsoft states it directly: "Defender for Endpoint Plan 1 and Plan 2 do not include server licenses." Servers are covered by Microsoft Defender for Servers Plan 1 or Plan 2 through Defender for Cloud, by Microsoft Defender for Endpoint Server, or by Microsoft Defender for Business servers. This is the most expensive assumption a buyer makes on this product, so count your servers separately and ask us to quote them.
Microsoft's published hardware floor is modest — "Cores: 2 minimum, 4 preferred; Memory: 1 GB minimum, 4 GB preferred" — and "IPv4 must be enabled". Onboarded devices must be excluded from any group policy that disables Microsoft Defender Antivirus, and security intelligence updates must be configured on every onboarded device; where Defender Antivirus is not the active antivirus product it runs in passive mode.
Microsoft does not name Microsoft Entra ID or Microsoft Intune as a hard prerequisite on its minimum requirements page, so this page does not claim one. Intune is one of several supported onboarding routes rather than a requirement.
Platform Support and Deployment
| Windows client | Windows 10 and 11 Enterprise, IoT Enterprise, Education, Pro and Pro Education, including Windows on Arm; Windows Enterprise LTSC 2016 and later; Windows Enterprise multi-session; Windows 7 SP1 Pro and Enterprise via the Defender deployment tool; Windows 8.1 Pro and Enterprise via Log Analytics |
| Windows Server | 2012 R2 and later including Core; Semi-Annual Channel 1803 and later; 2008 R2 SP1 via the Defender deployment tool. Server coverage requires separate licences |
| Virtual | Windows 365 Cloud PCs; Azure Virtual Desktop; Azure Local nodes on Azure Stack HCI OS 23H2 and later |
| Other platforms | macOS, Linux, Windows Subsystem for Linux, Android and iOS |
| Hardware floor | "Cores: 2 minimum, 4 preferred; Memory: 1 GB minimum, 4 GB preferred". IPv4 must be enabled |
| Onboarding routes | Defender deployment tool, Intune or MDM, Configuration Manager, local script for up to 10 devices, Group Policy, non-persistent VDI, Azure Virtual Desktop, SCEP; JAMF Pro for macOS; installer script, Ansible, Chef, Puppet or Saltstack for Linux |
Official Microsoft Sources & Downloads
- Microsoft Defender for Endpoint overview (Microsoft Learn)
- Overview of Defender for Endpoint Plan 1 (Microsoft Learn)
- Defender for Endpoint minimum requirements (Microsoft Learn)
- Defender for Endpoint deployment strategy (Microsoft Learn)
- Defender for Endpoint data storage and privacy (Microsoft Learn)
- What is Microsoft Defender for Business, with the Plan 1 and Plan 2 table (Microsoft Learn)
- Microsoft Defender service description (Microsoft Learn)
- Microsoft Defender for Endpoint lifecycle (Microsoft Learn)
- Microsoft security product renaming announcement, 22 September 2020
- Modern Lifecycle Policy (Microsoft Learn)
Where a figure appears on this page it is quoted from one of these Microsoft pages; where Microsoft publishes nothing, this page says so rather than filling the gap. Supplied by SourceIT in Singapore with a GST invoice and local support. For a written quotation, current stock position or delivery lead time, contact our team.
Frequently Asked Questions — Defender for Endpoint Plan 2 Annual Subscription
We have Microsoft 365 E5. Do we need to buy this?
No. Microsoft lists Defender for Endpoint Plan 2 as included in Microsoft 365 E5, A5 and G5, in Windows 10 and 11 Enterprise E5 and A5, in Microsoft 365 E5 Security and in the Microsoft Defender Suite. Send us your subscription list and we will check it before quoting rather than sell you an entitlement you already hold.
Is Plan 2 worth it over Plan 1?
It depends on whether anyone will use the detection and response layer. Plan 2 adds endpoint detection and response, automated investigation and remediation, threat and vulnerability management, threat analytics, Microsoft Threat Experts and six months of retention with thirty days of advanced hunting. If you have a security operations function, a managed detection and response provider, or a regulator who expects historical endpoint telemetry, Plan 2 is the one. If nobody will look at the telemetry, Plan 1 buys the protection without the platform.
Does this cover our servers?
No. Microsoft's wording covers both plans: "Defender for Endpoint Plan 1 and Plan 2 do not include server licenses." Servers need Microsoft Defender for Servers Plan 1 or Plan 2 through Defender for Cloud, Microsoft Defender for Endpoint Server, or Microsoft Defender for Business servers.
How far back can we hunt?
Microsoft publishes 180 days of retention visible across the portal, with 30 days queryable in the advanced hunting investigation experience. The comparison table expresses the same entitlement as "30 days advanced hunting; six months of data retention" and marks it Plan 2 only.
Where is the data stored, and can we choose Singapore?
Not Singapore. Microsoft's two current pages give different region lists — one names the European Union, United Kingdom, United States, Australia, Switzerland, India and the United Arab Emirates; the other offers only European Union, United Kingdom and United States at onboarding. Singapore appears on neither, and Microsoft states that the storage location cannot be changed after initial setup.
