HomeBlogComparison

Microsoft Defender for Office 365 Plan 1 vs Plan 2: What Plan 2 Adds

Pixel-art illustration of a robot holding a tablet and gesturing across an open-plan office of cubicles, with a city skyline outside the windows

Microsoft Defender for Office 365 Plan 1 adds prevention to Microsoft 365 email and collaboration: Safe Links, Safe Attachments, impersonation protection and real-time detections. Plan 2 includes everything in Plan 1 and adds the tools for investigating and cleaning up after a message gets through: Threat Explorer, automated investigation and response, campaign views, attack simulation training and Defender XDR integration. Microsoft lists Plan 1 at $2.00 and Plan 2 at $5.00 per user per month, paid yearly, as of October 2026, and Microsoft 365 Business Premium already includes Plan 1.

Put simply, Plan 1 stops more bad mail and Plan 2 helps someone find and remove what got through. If you would get Plan 2 inside Microsoft's $10 bundle, read our review of the Defender Suite for Business Premium; if phishing simulations are the main reason to upgrade, compare security awareness training platforms first.

What is the difference between Defender for Office 365 Plan 1 and Plan 2?

Microsoft describes a ladder. In its Defender for Office 365 overview, the built-in protection in every cloud mailbox stops broad, volume-based, known attacks; Plan 1 protects email and collaboration from zero-day malware, phishing and business email compromise; Plan 2 adds phishing simulations, post-breach investigation, hunting, response and automation.

Built-in protectionPlan 1Plan 2
What it isFiltering included with every Microsoft 365 cloud mailbox, long known as Exchange Online ProtectionPrevention and detection added on topPlan 1 plus investigation, automation and training
What it coversAnti-malware, anti-spam, spoof protection, quarantine, message trace and zero-hour auto purge for emailImpersonation protection for named users and domains, mailbox intelligence, Safe Attachments for email, SharePoint, OneDrive and Teams, Safe Links in email, Office apps and Teams, and real-time detectionsEverything in Plan 1, plus Threat Explorer, Threat Trackers, campaigns, automated investigation and response, attack simulation training, priority account protection, and incidents and advanced hunting in Defender XDR
Who runs itNobody, day to day; defaults apply until someone changes themAn admin who sets the policies and reviews quarantine and user reportsA security analyst or provider who investigates and responds
Who it fitsEvery tenant has itAny business that pays vendors by email or holds client dataBusinesses with someone to investigate, or that want Microsoft's phishing simulations
Cost driversIncluded$2.00 per user per month, or included in Business Premium and, since July 1, 2026, in Microsoft 365 E3 and Office 365 E3$5.00 per user per month, or included in Microsoft 365 E5, Office 365 E5 and Microsoft's Defender Suites
EffortNone to start, which is the problemSetup work up front, then routine reviewOngoing analyst time; its tools do nothing if nobody opens them

What does Plan 1 add to the built-in protection?

Plan 1 is about prevention and detection. The parts that matter most to a small business:

  • Impersonation protection. Anti-phishing policies that catch lookalikes of the people and domains you name, plus mailbox intelligence, which learns who each user normally writes to. It protects only the people and domains someone adds to the policy.
  • Safe Attachments. Microsoft detonates attachments in a sandbox before delivery, and the same protection can cover files in SharePoint, OneDrive and Teams.
  • Safe Links. Links in email, Office apps and Teams are checked when someone clicks them, not only when the message arrives.
  • Real-time detections. A report of the malware and phishing Defender caught, with an email entity page for each message, so an admin can see what arrived and what happened to it.

What does Plan 2 add?

Plan 2 adds investigation, response and automation:

  • Threat Explorer instead of real-time detections. Microsoft's quick test: if the Defender portal shows Email & collaboration > Explorer, the tenant has Plan 2; if it shows Real-time detections, it has Plan 1.
  • Automated investigation and response. Investigations that start from a suspicious message or a compromised-user alert and recommend cleanup actions.
  • Campaigns and Threat Trackers. Campaign views group related phishing messages so you can see everyone who received them; Threat Trackers follow threat activity over time.
  • Attack simulation training. Microsoft's phishing simulator, which Plan 1 does not include.
  • Priority account protection. Extra protection for the accounts you tag as most targeted, such as owners and finance staff.
  • Defender XDR integration. Email incidents joined with device and identity alerts, with advanced hunting across them. Microsoft's service description lists this integration for Plan 2, not Plan 1.

Do you need Plan 2 if nobody investigates email?

Usually not. Explorer, automated investigation and campaign views are tools for a person working an incident. In a 20-person office where nobody opens the Defender portal, Plan 2 adds cost without adding much at the inbox, because the blocking features, Safe Links, Safe Attachments and impersonation protection, are already in Plan 1. The exceptions are attack simulation training, which an owner or office manager can run, and priority account protection for the few people attackers target most.

The answer changes when someone is watching. An internal analyst or a managed security provider uses Explorer to find every copy of a phishing message, see who clicked and remove it, and Plan 2's Defender XDR integration lets that person connect the email to the sign-in and the device activity that followed.

Which fits a small team?

Illustrative situations, not client stories:

  • A 15-person firm on Business Premium with no IT staff. Plan 1, configured properly: impersonation protection for the owner, finance staff and key vendors, Microsoft's preset security policies for Safe Links and Safe Attachments, and someone reviewing quarantine.
  • A 40-person firm with a security provider watching alerts. Plan 2, for example through the Defender Suite for Business Premium, so the provider can investigate with Explorer and automated investigation.
  • A company on Business Standard. Plan 1 on its own adds the core protections for $2.00 per user per month; compare that with moving to Business Premium, which includes it.
  • A firm whose insurer asks for phishing simulation results. Plan 2's attack simulation training, or a third-party training platform on top of Plan 1.
  • A firm on Microsoft 365 E3. Since July 1, 2026, E3 includes Plan 1; check that its policies are actually turned on.

What do Plan 1 and Plan 2 cost?

Microsoft's Defender for Office 365 page lists Plan 1 at $2.00 and Plan 2 at $5.00 per user per month, paid yearly, as of October 2026. Plan 1 is included in Business Premium and, according to Microsoft's service description, in Microsoft 365 E3 and Office 365 E3 from July 1, 2026. Plan 2 is included in Microsoft 365 E5 and Office 365 E5 and in Microsoft's Defender Suites: $10.00 per user per month as an add-on to Business Premium, or $12.00 for Microsoft 365 E3 customers.

Three things move the real number:

  • Who must be licensed. Microsoft's licensing terms require a license for any user who accesses a mailbox that benefits from Defender for Office 365, for shared mailboxes that benefit, for everyone using SharePoint, OneDrive or Teams when Safe Attachments covers them, and for anyone using Microsoft 365 apps or Teams when Safe Links is on. Policies can be scoped to licensed users, but Plan 2 for three people does not cover the office.
  • What you already own. Business Premium, E3 and E5 tenants already hold a plan, so the first job is configuring it.
  • Who does the work. Plan 2's value is analyst time. Without it, the extra $3.00 per user buys tools nobody opens.

Microsoft also offers a 90-day trial of Plan 2 from the trials hub in the Defender portal, a fair test of whether anyone will use Explorer before you pay for it.

How does NetSys handle Defender for Office 365?

Our email security services start with what the tenant already pays for. A Business Premium tenant can run for years with Plan 1 at its defaults and impersonation protection covering no one, so we read how mail flows, set impersonation protection for the owners, finance staff and key vendors whose names can move money, and run new policies in report-only mode where the product offers one before enforcing them. NetSys engineers review quarantine, read every message staff report with the Outlook button and remove confirmed phishing from every inbox. Where a third-party gateway earns its place, we add Barracuda in front of Defender. Inside a managed agreement the work sits in the per-user fee; on its own, it is quoted after a review.

Book a call with a NetSys engineer to find out which Defender for Office 365 plan your tenant has and whether its policies are on.

Frequently asked questions

Does Business Premium include Defender for Office 365 Plan 2?

No. Business Premium includes Plan 1. Plan 2 comes as a $5.00 per user add-on or inside the $10.00 Defender Suite for Business Premium, which also adds Defender for Endpoint Plan 2 and Entra ID P2 (list prices as of October 2026, paid yearly).

Is attack simulation training included in Plan 1?

No. Microsoft's feature table lists attack simulation training for Plan 2 and the Defender Suites, not for Plan 1. With Plan 1 you would add a third-party training platform or upgrade.

How can I tell which plan my tenant has?

Open the Microsoft Defender portal and look under Email & collaboration. Microsoft says Explorer appears with Plan 2 and Real-time detections with Plan 1. The licenses page in the Microsoft 365 admin center shows the subscriptions themselves.

What affects cost, implementation and support?

Cost depends on how many users and shared mailboxes need licenses and whether your Microsoft 365 plan already includes a Defender plan. Implementation means setting anti-phishing, Safe Links and Safe Attachments policies, starting from Microsoft's preset security policies, and testing them against your real mail flow. Support is the ongoing part: quarantine review, user reports and, with Plan 2, someone working the investigations.

Is Plan 2 worth it for a small business?

It is when someone will use the investigation tools or you want Microsoft's phishing simulations. If neither is true, configure Plan 1 thoroughly and put the difference toward monitoring or training.

Email Security

Discuss email security for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.