Brand: Microsoft | Category: Network Security
SKU: MICR-CFQ7TTC0LGV0 | Part #: CFQ7TTC0LGV0 | MPN: CFQ7TTC0LGV0
Contact for Pricing — Request a Quote
Microsoft Defender for Endpoint Plan 2 is Microsoft's comprehensive enterprise-grade endpoint detection and response (EDR) and extended detection and response (XDR) platform, delivered as a per-user cloud-native subscription (part number CFQ7TTC0LGV0). It provides deep behavioral-based threat protection across Windows, macOS, Linux, Android, and iOS endpoints, combining real-time antivirus, attack surface reduction rules, next-generation protection, automated investigation and remediation (AIR), and endpoint detection and response capabilities into a single unified agent and portal experience. The platform is built on the Microsoft Defender XDR ecosystem and integrates natively with Microsoft Sentinel, Microsoft Intune, and Entra ID for correlated, cross-domain security signal enrichment.
Plan 2 extends the foundational capabilities of Plan 1 with advanced threat hunting, six months of raw endpoint telemetry retained in Microsoft 365 Defender (now Microsoft Defender portal), Microsoft Threat Experts managed threat hunting service, deception capabilities (honeypot-style decoys), and device discovery for unmanaged assets on the network. The Threat and Vulnerability Management (TVM) module continuously inventories software, configurations, and vulnerabilities across enrolled devices and correlates exposure data against active exploit intelligence to prioritize remediation workflows. Sandbox-based detonation analysis through deep analysis and integration with Microsoft Defender SmartScreen further strengthens zero-day and fileless malware detection.
Targeted at mid-market to large enterprise organizations, Defender for Endpoint P2 is licensed on a per-user basis, allowing each licensed user to protect up to five concurrent devices simultaneously. It is available as a standalone subscription or as a component of Microsoft 365 E5, Microsoft 365 E5 Security, and Microsoft Defender XDR bundles. The solution operates without requiring on-premises infrastructure, leveraging Microsoft's hyperscale cloud for threat intelligence aggregation across billions of signals processed daily through the Microsoft Intelligent Security Graph.
| Manufacturer | Microsoft |
| Manufacturer Part Number | CFQ7TTC0LGV0 |
| Product Name | Microsoft Defender for Endpoint Plan 2 |
| Subscription Model | Per-user, cloud-based SaaS subscription |
| Devices Per Licensed User | Up to 5 concurrent devices |
| Supported Client OS | Windows 10, Windows 11, macOS, Android, iOS/iPadOS |
| Supported Server OS | Windows Server 2012 R2, 2016, 2019, 2022; Linux (RHEL, CentOS, Ubuntu, SLES, Debian, Oracle Linux, Fedora, Amazon Linux 2) |
| Core Capability Tier | Plan 2 (full EDR/XDR feature set, superset of Plan 1) |
| Endpoint Detection and Response (EDR) | Included — behavioral-based, kernel-level telemetry collection with real-time alert generation |
| Next-Generation Protection | Included — cloud-delivered ML antivirus, behavior monitoring, PUA protection |
| Attack Surface Reduction (ASR) | Included — ASR rules, network protection, web content filtering, controlled folder access, exploit protection |
| Automated Investigation and Remediation (AIR) | Included — automated playbook-driven investigation with full or semi-automated remediation |
| Threat and Vulnerability Management (TVM) | Included — real-time software inventory, CVE correlation, security recommendations, remediation tracking |
| Advanced Threat Hunting | Included — KQL-based custom queries across up to 180 days of raw endpoint telemetry |
| Endpoint Telemetry Retention | Up to 180 days |
| Threat Intelligence Integration | Microsoft Intelligent Security Graph; IOC ingestion (file hash, IP, URL, certificate); MITRE ATT&CK framework mapping |
| Managed Threat Hunting Service | Microsoft Threat Experts — targeted attack notifications and on-demand expert consultation included |
| Device Discovery | Included — unmanaged device and network asset discovery via enrolled endpoint sensors |
| Deception Capabilities | Included in P2 — lure-based decoy artifacts to detect lateral movement |
| Management Portal | Microsoft Defender portal (security.microsoft.com) |
| XDR Integration | Native integration with Microsoft Defender XDR (identity, email, cloud apps, endpoints) for unified incident correlation |
| Deployment Method | Agent-based onboarding via Microsoft Intune, Microsoft Endpoint Configuration Manager, Group Policy, local script, or VDI package |
| Licensing Prerequisite | Azure Active Directory (Entra ID) tenant required; available standalone or included in Microsoft 365 E5 / Microsoft 365 E5 Security / Microsoft Defender XDR |
Available from Omnixon Global. Submit an RFQ and our team will confirm configuration and availability for your order.
| Brand | Microsoft |
| Category | Network Security |
| SKU | MICR-CFQ7TTC0LGV0 |
| Part Number | CFQ7TTC0LGV0 |
| Condition | New |
| Manufacturer Part Number | CFQ7TTC0LGV0 |
| Product Name | Microsoft Defender for Endpoint Plan 2 |
| Subscription Model | Per-user, cloud-based SaaS subscription |
| Devices Per Licensed User | Up to 5 concurrent devices |
| Supported Client OS | Windows 10, Windows 11, macOS, Android, iOS/iPadOS |
| Supported Server OS | Windows Server 2012 R2, 2016, 2019, 2022; Linux (RHEL, CentOS, Ubuntu, SLES, Debian, Oracle Linux, Fedora, Amazon Linux 2) |
| Core Capability Tier | Plan 2 (full EDR/XDR feature set, superset of Plan 1) |
| Endpoint Detection and Response (EDR) | Included — behavioral-based, kernel-level telemetry collection with real-time alert generation |
| Next-Generation Protection | Included — cloud-delivered ML antivirus, behavior monitoring, PUA protection |
| Attack Surface Reduction (ASR) | Included — ASR rules, network protection, web content filtering, controlled folder access, exploit protection |
| Automated Investigation and Remediation (AIR) | Included — automated playbook-driven investigation with full or semi-automated remediation |
| Threat and Vulnerability Management (TVM) | Included — real-time software inventory, CVE correlation, security recommendations, remediation tracking |
| Advanced Threat Hunting | Included — KQL-based custom queries across up to 180 days of raw endpoint telemetry |
| Endpoint Telemetry Retention | Up to 180 days |
| Threat Intelligence Integration | Microsoft Intelligent Security Graph; IOC ingestion (file hash, IP, URL, certificate); MITRE ATT&CK framework mapping |
| Managed Threat Hunting Service | Microsoft Threat Experts — targeted attack notifications and on-demand expert consultation included |
| Device Discovery | Included — unmanaged device and network asset discovery via enrolled endpoint sensors |
| Deception Capabilities | Included in P2 — lure-based decoy artifacts to detect lateral movement |
| Management Portal | Microsoft Defender portal (security.microsoft.com) |
| XDR Integration | Native integration with Microsoft Defender XDR (identity, email, cloud apps, endpoints) for unified incident correlation |
| Deployment Method | Agent-based onboarding via Microsoft Intune, Microsoft Endpoint Configuration Manager, Group Policy, local script, or VDI package |
| Licensing Prerequisite | Azure Active Directory (Entra ID) tenant required; available standalone or included in Microsoft 365 E5 / Microsoft 365 E5 Security / Microsoft Defender XDR |