Yes. Microsoft 365 E3 and A3 include Microsoft Defender for Endpoint Plan 1 (P1). Microsoft announced the change on January 13, 2022, and made it effective January 14, 2022. Current Microsoft licensing documentation still lists P1 with Microsoft 365 E3, A3 and G3, so “now include” describes a 2022 change—not a new 2026 announcement.
The entitlement gives you foundational endpoint protection. It does not automatically onboard devices, configure policies, provide endpoint detection and response (EDR), or license your servers.
What Microsoft 365 E3/A3 actually includes
Microsoft lists Defender for Endpoint Plan 1 as an included entitlement for Microsoft 365 E3, A3 and G3. The original announcement is available from Microsoft, while the current service description is maintained in Microsoft’s licensing documentation.
A3 is the education edition. It qualifies for P1, but that does not make every commercial E3 and education A3 licensing right identical. Your agreement, purchasing channel and user types still matter for other services.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
P1 capabilities
Microsoft describes P1 as the foundational endpoint-protection tier. Its documented capabilities include:
- Next-generation anti-malware.
- Attack-surface-reduction controls.
- Device control, including controls such as USB restrictions.
- Endpoint firewall and network protection.
- Web control, including category-based URL blocking.
- Application control.
- Device-based conditional access.
- APIs, SIEM connectivity and custom threat intelligence.
These are broader than Microsoft Defender Antivirus alone. The current Defender for Endpoint product page describes the plan boundaries and feature set.
What “included” does—and does not—mean
An E3 or A3 subscription creates a licensing entitlement; it is not proof that a device is protected. Deployment is a separate operational process.
Rank #2
- Entitlement: The qualifying user has rights to use P1.
- Activation: Administrators may need to configure Defender settings and permissions.
- Onboarding: Supported computers and mobile devices must be connected to the Defender service.
- Policy: Firewall rules, exclusions, web controls and attack-surface-reduction settings must be selected and deployed.
- Operations: Someone must review device health, alerts, incidents and policy status.
Use Microsoft’s current Plan 1 setup and configuration guide for the onboarding methods and prerequisites. Portal navigation changes, so treat older screenshots and menu paths as potentially stale.
Plan 1 versus Plan 2
P1 is a baseline prevention and hardening tier. Plan 2 (P2) includes P1 and adds the deeper detection, response and exposure capabilities used by organizations with more demanding security operations.
| Capability area | Defender for Endpoint P1 | Defender for Endpoint P2 |
|---|---|---|
| Anti-malware, attack-surface reduction, device control | Included | Included |
| Endpoint firewall, network protection, web and application control | Included | Included |
| Endpoint detection and response (EDR) | Not a P1 entitlement | Included |
| Automated investigation and remediation | Not a P1 entitlement | Included |
| Automatic attack disruption | Not a P1 headline capability | Included |
| Exposure and vulnerability management | Limited or not part of the P1 entitlement | Advanced capabilities associated with P2 |
| Threat hunting and advanced threat intelligence | Not the core P1 tier | P2-oriented capabilities |
| Deception and sandbox/deep analysis | Not included as P1 features | Included or associated with P2 capabilities |
Microsoft’s current comparison places EDR, automated investigation and remediation, automatic attack disruption, exposure management, threat intelligence and related advanced functions in the higher tier. Do not describe P1 as “EDR included.”
Who and what is covered?
User assignment matters
The entitlement is generally user-based. Check which people hold E3, A3 or G3 and whether everyone using a protected endpoint is appropriately licensed. Shared devices, kiosks, contractors, temporary workers and frontline users can require separate licensing analysis. One user subscription does not automatically license unrelated users or every device in the tenant.
Servers require a separate licensing path
Do not treat the E3/A3 P1 entitlement as a server license. Microsoft’s P1 setup documentation says server onboarding requires an additional option, such as Defender for Servers Plan 1 or Plan 2 through Defender for Cloud, Microsoft Defender for Endpoint Server, or Defender for Business servers where eligible. Review the server requirement in the official setup guide before onboarding production servers.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Supported platforms
The current P1 setup documentation lists these client platforms:
- Windows 11.
- Windows 10 version 1709 or later.
- macOS.
- iOS.
- Android.
It also lists server support for Windows Server 2025, 2022, 2019, version 1803 and later, Windows Server 2016 and 2012 R2 with the modern unified solution, Azure Stack HCI OS version 23H2 and later, and Linux. Platform support and onboarding methods can change, and server support does not remove the separate server-license requirement.
Where administrators manage Defender
Defender is managed through Microsoft’s unified Defender portal and related security services. The 2022 announcement explained that the portal experience exposes pages and capabilities according to the customer’s license. Current terminology and navigation should be checked against Microsoft’s Defender documentation rather than copied from an old portal screenshot.
How to verify your entitlement and deployment
- Confirm that the tenant owns Microsoft 365 E3, A3 or G3.
- Check active subscriptions and user assignments in the Microsoft 365 admin center.
- Open the Defender portal and review available endpoint settings, onboarding options, device inventory and any licensing notices.
- Verify that the users operating protected endpoints hold the qualifying license.
- Onboard a controlled test-device group using the current Microsoft setup guide.
- Confirm that test devices appear healthy and report to the portal.
- Review which controls are available under the tenant’s actual license before designing production policies.
- Stop and verify separate server licensing before onboarding servers.
Exact menu names vary by tenant and Microsoft updates the portal frequently, so use the current documentation for the final click path.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
Should you stay with P1 or buy something else?
Keep the included P1 entitlement when
- You need baseline anti-malware and endpoint hardening.
- Firewall, network, web, application and device controls meet your requirements.
- You already own E3 or A3 and do not need a full SOC or EDR feature set.
- Your scope is supported client endpoints and separately licensed servers.
Evaluate Plan 2 when
You need EDR, automated investigation and remediation, advanced threat hunting, automatic attack disruption, or richer exposure and vulnerability management. P2 is aimed at organizations with incident-response processes and staff able to use deeper endpoint telemetry.
Evaluate the Microsoft Defender Suite when
Microsoft presents the Defender Suite as an add-on for Microsoft 365 E3, or for Office 365 E3 combined with Enterprise Mobility + Security E3. Its scope spans endpoint, email and collaboration, identity, SaaS, XDR, data security, compliance and governance. Microsoft’s U.S. pricing page displayed $12 per user per month, paid yearly on August 18, 2026. That is a public U.S. list-price signal, not a guaranteed education, nonprofit, government, reseller or negotiated-contract price. See Microsoft’s pricing page.
Evaluate Microsoft 365 E5 when
E5 bundles advanced security with broader identity, compliance, analytics and productivity rights. The same U.S. pricing page displayed $60 per user per month with Teams and $51.45 without Teams, paid yearly, on August 18, 2026. E5 can be excessive if endpoint protection is your only requirement.
Consider Defender for Business for eligible smaller organizations
Microsoft lists Defender for Business at $3 per user per month, paid yearly, for organizations of up to 300 users and up to five devices per user. It includes EDR, automatic attack disruption, automated investigation and remediation, vulnerability management and simplified onboarding. Eligibility, scale, server needs and compliance requirements differ from an E3/A3 deployment; review the official product page.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsCommon licensing mistakes
- “We own E3, so every device is protected.” Ownership does not onboard devices or configure policies.
- “P1 is just Defender Antivirus.” P1 also covers controls such as device, network, web, application and attack-surface reduction.
- “P1 includes EDR.” Microsoft places EDR in P2.
- “Servers are covered automatically.” Server licensing is separate.
- “A3 and E3 are identical.” They both qualify for P1, but other rights and purchasing terms can differ.
- “P1 and P2 are just portal labels.” The license changes the capabilities available in the portal.
The Bottom Line
Microsoft 365 E3 and A3 include Defender for Endpoint Plan 1, an entitlement that has been in effect since January 14, 2022. Treat it as foundational client-endpoint protection: assign the right users, onboard and configure devices, license servers separately, and move to P2, Defender Suite, E5 or Defender for Business only when your detection, response, scale or broader security requirements justify it.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




