Microsoft certification badges banner
Headshot of Michael Korting

Blog

Microsoft 365 • Security • Compliance

Microsoft Defender for Office 365: Understanding Plan 1 vs. Plan 2 Licensing

Where Plan 1 is enough, where Plan 2 adds real value, and what E3 customers should prioritize after the July 2026 licensing change.

Introduction

Email is still one of the easiest ways for attackers to get into an organization. Phishing, business email compromise, malicious attachments, credential theft, and impersonation attacks continue to evolve faster than traditional spam filtering can keep up.

Microsoft Defender for Office 365 adds advanced protection on top of Exchange Online Protection, including Safe Links, Safe Attachments, anti-phishing controls, investigation tools, automation, and reporting. In Microsoft 365 tenant assessments, the licensing question comes up constantly:

Key question: Do we need Defender for Office 365 Plan 2, or is Plan 1 sufficient?

The answer is no longer just a feature comparison. It now depends on licensing, operational maturity, security staffing, compliance needs, and how much investigation capability the organization truly needs.

Important July 2026 licensing update: Effective July 1, 2026, Defender for Office 365 Plan 1 is included with both Microsoft 365 E3 and Office 365 E3. For many E3 customers, the conversation has shifted from buying Plan 1 to making sure the newly included protections are actually enabled, tuned, and monitored. Plan 2 remains the advanced investigation, automation, hunting, and simulation tier.

What Is Defender for Office 365?

Microsoft Defender for Office 365 builds on Exchange Online Protection, the native email hygiene service included with Exchange Online.

Exchange Online Protection provides:

  • Anti-spam filtering
  • Anti-malware protection
  • Connection filtering
  • Transport rules
  • Basic spoof detection
  • Mail flow protection

Defender for Office 365 adds protection layers needed for more modern email threats, including Safe Attachments, Safe Links, anti-phishing protection, impersonation detection, real-time detonation analysis, Threat Explorer, automated investigation and response, and Attack Simulation Training.

The Defender platform also aligns closely with Secure Score recommendations and Microsoft security baselines. In practical assessments, the biggest gains often come from enabling Safe Attachments, Safe Links, anti-phishing policies, impersonation protection, and foundational authentication controls such as SPF, DKIM, and DMARC.

Defender for Office 365 Plan 1

Plan 1 is the preventative protection tier. It is aimed at organizations that need strong phishing, malware, URL, attachment, and impersonation controls but do not need full threat hunting, automated investigation, or attack simulation capabilities. Since the July 2026 licensing changes, Plan 1 is now part of Microsoft 365 E3 and Office 365 E3, making deployment and configuration the real priority for many E3 tenants.

Safe Attachments

Safe Attachments detonates suspicious files in a secure environment before users interact with them. Suspicious files can be blocked, quarantined, replaced, or monitored. For most tenants, Safe Attachments should be more than licensed; it should be enforced. Block mode and appropriate quarantine settings can prevent malicious files from ever reaching end users.

Safe Links

Safe Links protects users when they click URLs in email and supported Office content. URLs are checked in real time, malicious sites can be blocked, and users can receive warning messages before proceeding. This is especially useful against phishing sites that appear after the original message is delivered.

Anti-Phishing Protection

Plan 1 includes user and domain impersonation detection, mailbox intelligence, spoof intelligence, and phishing safety tips. High-value targets such as executives, finance, HR, administrators, and help desk teams should be protected explicitly.

Preset Security Policies

Preset security policies are one of the fastest ways to raise the baseline. Standard should generally be treated as the minimum modern baseline. Strict provides more aggressive filtering and phishing controls for organizations that can support stronger enforcement.

Defender for Office 365 Plan 2

Plan 2 includes Plan 1 and adds the tools security teams need to investigate, respond, hunt, train, and report at a deeper level. This is where Defender for Office 365 becomes less about prevention alone and more about security operations.

Threat Explorer

Threat Explorer gives analysts deeper visibility into email-borne threats across the tenant. Security teams can search messages, analyze phishing campaigns, investigate malware detections, review delivery actions, and track impacted users.

Automated Investigation and Response

Automated investigation and response can investigate suspicious activity, examine related indicators, identify compromised content, and recommend remediation actions. For lean security teams, this automation can reduce the manual work required to triage routine incidents.

Attack Simulation Training

Attack Simulation Training is one of the strongest Plan 2 differentiators because it brings phishing simulation and user training directly into the Microsoft Defender portal. If Defender for Office 365 Plan 2 is already licensed, Attack Simulation Training should be evaluated before renewing or expanding a separate phishing simulation subscription.

The value is not just licensing consolidation. Attack Simulation Training is connected to the Microsoft security ecosystem that already handles email protection, detections, reporting, user risk context, and remediation workflows.

Important consideration: This does not automatically mean every organization should replace its current awareness platform. Mature third-party tools may include broader awareness content, policy training, compliance workflows, or reporting features that still matter. Evaluate functional requirements before consolidating.

Microsoft also supports training campaigns, simulation automations, payload libraries, and payload automations. Organizations can run one-time simulations, assign training, automate recurring exercises, and use payloads based on real-world attack patterns observed in the tenant.

Campaign Views

Campaign analysis groups related messages so security teams can investigate the broader attack, not just individual emails. Security teams can review attack origin, delivery patterns, impersonated users, and impacted recipients.

Threat Trackers

Threat Trackers provide intelligence about emerging attack campaigns, active phishing trends, industry-wide threats, and Microsoft threat research.

Side-by-Side Comparison

Microsoft Defender for Office 365 Plan 1 and Plan 2 capabilities
FeaturePlan 1Plan 2
Safe AttachmentsYesYes
Safe LinksYesYes
Anti-Phishing ProtectionYesYes
Impersonation ProtectionYesYes
Preset Security PoliciesYesYes
Threat ExplorerNoYes
Campaign ViewsNoYes
Attack Simulation TrainingNoYes
Automated Investigation and ResponseNoYes
Threat TrackersNoYes
Advanced Hunting CapabilitiesNoYes

Which License Is Right for Your Organization?

Plan 1 Is Often Sufficient When:

  • The organization is small to mid-sized
  • Security operations are outsourced
  • Compliance requirements are moderate
  • Security staffing is limited
  • Budget constraints are significant

Plan 1 is a major step up from EOP-only protection, especially now that it is included with E3 suites. For E3 customers, the immediate priority should be validation: confirm Plan 1 entitlement, enable the core policies, review quarantine behavior, protect high-value users, and monitor detections.

Plan 2 Is Recommended When:

  • Regulatory requirements are strict
  • Security incidents must be investigated rapidly
  • A dedicated security team exists
  • Threat hunting is required
  • Security automation is a priority
  • Executive impersonation attacks are a common concern
  • The organization is evaluating consolidation of a separate phishing simulation or awareness platform

Do Not Forget Email Authentication

Licensing matters, but it does not replace proper email authentication. Three technologies should be deployed together:

  • SPF: validates authorized mail servers.
  • DKIM: digitally signs messages to verify authenticity.
  • DMARC: tells receiving systems how to handle authentication failures.
Deployment reminder: A tenant can have the right Defender license and still be exposed if authentication is incomplete.

Lessons Learned from Real-World Deployments

  • Standard security presets are frequently disabled or partially configured.
  • Safe Links and Safe Attachments are often licensed but not deployed.
  • Executive impersonation protection is commonly overlooked.
  • SPF, DKIM, and DMARC are frequently incomplete.
  • Organizations purchase Plan 2 but never use Attack Simulation Training, even while paying separately for third-party phishing simulation tools.
  • Security awareness programs are often disconnected from the email security telemetry used by the operations team.

The biggest security gains often come from fully deploying and operationalizing what the organization already owns.

Final Thoughts

Defender for Office 365 is now a core part of the Microsoft 365 security conversation, especially for E3 customers. After the July 2026 licensing update, many Microsoft 365 E3 and Office 365 E3 tenants now have Plan 1 protections included. That makes configuration the key question: are Safe Links, Safe Attachments, anti-phishing policies, impersonation protection, and authentication controls actually deployed and monitored?

Plan 2 is still the right conversation for organizations that need deeper investigations, automated response, attack simulation, and stronger security operations workflows. It is also worth a serious look when an organization already owns or is considering a standalone phishing simulation platform.

The license matters, but the outcome depends on execution. Security improves when the capabilities are enabled, tuned, reviewed, and used.

Licensing disclaimer: Microsoft licensing, product names, packaging, and features change regularly. As of the July 2026 Microsoft 365 pricing and packaging updates, Defender for Office 365 Plan 1 is included with Microsoft 365 E3 and Office 365 E3 following a suite price increase that also included other Microsoft 365 additions. Always confirm current entitlement, feature availability, and purchasing guidance with Microsoft licensing documentation or your licensing provider before making decisions.

References

Core Microsoft Defender for Office 365 Resources

Policy Configuration

Attack Simulation Training

Email Authentication and Security