What are Microsoft Defender for Office 365 Plan 1 and Plan 2? Understanding email protection in E3 and E5
About this article
This article was generated using an automated workflow powered by generative AI. It is based on the Microsoft Learn documentation for Defender for Office 365 as of September 17, 2026, and incorporates the E3 changes effective from July 2026.Verification Status: 📘 Confirmed via official Microsoft documentation (physical hardware verification not conducted)
Microsoft Defender for Office 365 builds on the baseline protection of Exchange Online Protection to safeguard email and collaboration tools against phishing, zero-day malware, malicious URLs, and attachments. Plan 1 strengthens prevention and detection, while Plan 2 expands into SOC-focused capabilities such as attack simulation, threat hunting, investigation, and automated response.
Important considerations for E3 in 2026
Current Microsoft service documentation explicitly states that:Defender for Office 365 Plan 1 is included in Office 365 E3 and Microsoft 365 E3 starting July 1, 2026.Older comparison articles may state that MDO P1 is not included in E3, so always verify the date of the information when designing architectures for 2026 and beyond.
Microsoft 365 E5 is documented as including Plan 2.
| Tier | Key Concept |
|---|---|
| Basic Protection | Baseline defense against high-volume and known attacks |
| Plan 1 | Safe Links, Safe Attachments, enhanced anti-phishing, real-time detections, etc. |
| Plan 2 | P1 + Attack Simulation Training, Threat Explorer, AIR, advanced hunting, etc. |
Because features are regularly updated, always consult the latest service descriptions and Product Terms when making licensing decisions.
First Step: Observe detection status without changing settings
Open email-related dashboards, Explorer, or Real-time detections in the Microsoft Defender portal within the scope of your licenses and permissions. Initially, avoid making policy changes or deleting emails, and check the following:
Trends in phishing, malware, and spam
Detections related to Safe Links and Safe Attachments
Target users and messages
Detection timestamps
Determination reasons
What to look at here
Available investigation and response capabilities differ between Plan 1 and Plan 2. Verify not only whether items appear on the screen, but also which service plan is currently assigned to the user.
Change one setting
Narrow down the time filter to a short window, such as the last 24 hours. Verify that the number of results decreases, and understand the relationship between filters and actual data. Do not execute message deletions or remediation right away.
Expanded investigations with Plan 2
Plan 2 expands the scope to post-breach and post-detection investigation and remediation using tools such as Threat Explorer, Automated Investigation and Response (AIR), Attack Simulation Training, and advanced hunting in Defender XDR.
Even when using KQL, start with read-only queries and small result sets. Verify the availability of email-related tables based on your licensing and data deployment status.
For enterprise implementation
The inclusion of P1 in E3 environments from July 2026 onward does not mean existing email security designs can be automatically replaced. Review Safe Links and Safe Attachments policies, target scopes, exceptions, dual-processing setups with existing gateways, user reporting mechanisms, and SOC investigation procedures.
For E5 and P2, operational effectiveness depends less on having many features and more on determining who uses Threat Explorer and AIR, and to what extent automated remediation is permitted. When conducting attack simulations, avoid campaigns that harvest actual credentials, and design them with corporate policies and participant considerations in mind.
Checklist for administrators
Have you accounted for the E3 equals P1 change effective July 1, 2026?
Have you verified differences against E5 and P2 using the latest service descriptions?
Understand the precedence between preset security policies and custom policies.
Define the target scope for Safe Links and Safe Attachments.
Establish user reporting workflows.
Configure permissions for AIR and remediation.
Design coexistence models with third-party email security solutions.
Official and primary sources
Defender for Office 365 service description: https://learn.microsoft.com/en-us/office365/servicedescriptions/office-365-advanced-threat-protection-service-description
Why do I need Defender for Office 365?: https://learn.microsoft.com/en-us/defender-office-365/mdo-about
Under the 2026 E3 licensing model, the assumption that "Defender for Office 365 is only in E5" is no longer reliable. The boundary between Plan 1 and Plan 2 must be evaluated based on both current agreements and operational goals.
