Licensing

MDE P1 vs P2.

Compare Defender for Endpoint Plan 1 and Plan 2 by capability, with links back to related tables, APIs, and capability records.

P2 Adds or Upgrades

MDE P1 vs P2

CapabilityMDE P1MDE P2TablesAPIs
Attack Surface Reduction

Prevention

Included

Included as a foundational Defender for Endpoint Plan 1 capability.

Included

Included with Defender for Endpoint capabilities for reducing attack surface.

DeviceEventsMicrosoft Defender for Endpoint APIs
Endpoint Detection and Response

Detection and response

Limited

Included with limited manual response actions compared with Plan 2.

Included

Full EDR investigation and response capability.

DeviceEvents, DeviceProcessEvents, DeviceNetworkEvents, DeviceFileEventsMicrosoft Defender for Endpoint APIs, Microsoft Graph Security API
Automated Investigation and Response

Detection and response

Not included

Plan 2 capability.

Included

Automated investigation and remediation capabilities are included in Plan 2.

DeviceEventsMicrosoft Defender for Endpoint APIs, Microsoft Graph Security API
Advanced Hunting

Investigation

Not included

Plan 2 capability.

Included

Advanced hunting over supported Defender XDR data is included.

DeviceProcessEvents, DeviceEvents, DeviceFileEvents, DeviceNetworkEvents, DeviceRegistryEvents, DeviceLogonEvents, DeviceImageLoadEvents, DeviceInfo, ThreatIntelIndicators, ThreatIntelObjectsMicrosoft Graph Security API, Microsoft Defender for Endpoint APIs, Legacy Microsoft Defender XDR APIs
Threat and Vulnerability Management

Exposure management

Not included

Use Plan 2 for the core vulnerability management workflow in this reference slice.

Included

Core vulnerability management capabilities are included through Defender for Endpoint Plan 2.

DeviceInfoMicrosoft Defender for Endpoint APIs