Microsoft Defender for Endpoint P2 (per-user subscription)

Microsoft Defender for Endpoint P2 (per-user subscription)

Brand: Microsoft | Category: Network Security

SKU: MICR-CFQ7TTC0LGV0 | Part #: CFQ7TTC0LGV0 | MPN: CFQ7TTC0LGV0

Contact for Pricing — Request a Quote

Request a Quote Contact Us

About the Microsoft Defender for Endpoint P2 (per-user subscription)

Microsoft Defender for Endpoint Plan 2 is Microsoft's comprehensive enterprise-grade endpoint detection and response (EDR) and extended detection and response (XDR) platform, delivered as a per-user cloud-native subscription (part number CFQ7TTC0LGV0). It provides deep behavioral-based threat protection across Windows, macOS, Linux, Android, and iOS endpoints, combining real-time antivirus, attack surface reduction rules, next-generation protection, automated investigation and remediation (AIR), and endpoint detection and response capabilities into a single unified agent and portal experience. The platform is built on the Microsoft Defender XDR ecosystem and integrates natively with Microsoft Sentinel, Microsoft Intune, and Entra ID for correlated, cross-domain security signal enrichment.

Plan 2 extends the foundational capabilities of Plan 1 with advanced threat hunting, six months of raw endpoint telemetry retained in Microsoft 365 Defender (now Microsoft Defender portal), Microsoft Threat Experts managed threat hunting service, deception capabilities (honeypot-style decoys), and device discovery for unmanaged assets on the network. The Threat and Vulnerability Management (TVM) module continuously inventories software, configurations, and vulnerabilities across enrolled devices and correlates exposure data against active exploit intelligence to prioritize remediation workflows. Sandbox-based detonation analysis through deep analysis and integration with Microsoft Defender SmartScreen further strengthens zero-day and fileless malware detection.

Targeted at mid-market to large enterprise organizations, Defender for Endpoint P2 is licensed on a per-user basis, allowing each licensed user to protect up to five concurrent devices simultaneously. It is available as a standalone subscription or as a component of Microsoft 365 E5, Microsoft 365 E5 Security, and Microsoft Defender XDR bundles. The solution operates without requiring on-premises infrastructure, leveraging Microsoft's hyperscale cloud for threat intelligence aggregation across billions of signals processed daily through the Microsoft Intelligent Security Graph.

Ideal for

  • Enterprise SOC teams leveraging the 180-day endpoint telemetry retention and advanced hunting (KQL-based queries) to conduct proactive threat hunts across the full device fleet without deploying separate SIEM storage
  • Automated incident response workflows using AIR playbooks to isolate compromised endpoints, collect forensic evidence, and remediate malicious artifacts with minimal analyst intervention during active ransomware or credential-theft campaigns
  • Continuous vulnerability and misconfiguration management using Threat and Vulnerability Management to correlate CVE exposure against real-world exploit activity and generate prioritized remediation tickets integrated with ServiceNow or Jira
  • Cross-platform endpoint protection for heterogeneous environments spanning Windows Server, Windows 10/11 clients, macOS, Linux distributions, and mobile (Android/iOS) under a single management plane in the Microsoft Defender portal
  • Network device and unmanaged asset discovery enabling security teams to identify rogue or unmanaged endpoints, IoT devices, and network appliances visible from enrolled devices, then onboard or isolate them to reduce attack surface
  • Microsoft Threat Experts on-demand engagement allowing enterprise security teams to request targeted attack notifications and direct analyst consultation for critical incidents without maintaining a full in-house threat intelligence capability

Technical specifications

ManufacturerMicrosoft
Manufacturer Part NumberCFQ7TTC0LGV0
Product NameMicrosoft Defender for Endpoint Plan 2
Subscription ModelPer-user, cloud-based SaaS subscription
Devices Per Licensed UserUp to 5 concurrent devices
Supported Client OSWindows 10, Windows 11, macOS, Android, iOS/iPadOS
Supported Server OSWindows Server 2012 R2, 2016, 2019, 2022; Linux (RHEL, CentOS, Ubuntu, SLES, Debian, Oracle Linux, Fedora, Amazon Linux 2)
Core Capability TierPlan 2 (full EDR/XDR feature set, superset of Plan 1)
Endpoint Detection and Response (EDR)Included — behavioral-based, kernel-level telemetry collection with real-time alert generation
Next-Generation ProtectionIncluded — cloud-delivered ML antivirus, behavior monitoring, PUA protection
Attack Surface Reduction (ASR)Included — ASR rules, network protection, web content filtering, controlled folder access, exploit protection
Automated Investigation and Remediation (AIR)Included — automated playbook-driven investigation with full or semi-automated remediation
Threat and Vulnerability Management (TVM)Included — real-time software inventory, CVE correlation, security recommendations, remediation tracking
Advanced Threat HuntingIncluded — KQL-based custom queries across up to 180 days of raw endpoint telemetry
Endpoint Telemetry RetentionUp to 180 days
Threat Intelligence IntegrationMicrosoft Intelligent Security Graph; IOC ingestion (file hash, IP, URL, certificate); MITRE ATT&CK framework mapping
Managed Threat Hunting ServiceMicrosoft Threat Experts — targeted attack notifications and on-demand expert consultation included
Device DiscoveryIncluded — unmanaged device and network asset discovery via enrolled endpoint sensors
Deception CapabilitiesIncluded in P2 — lure-based decoy artifacts to detect lateral movement
Management PortalMicrosoft Defender portal (security.microsoft.com)
XDR IntegrationNative integration with Microsoft Defender XDR (identity, email, cloud apps, endpoints) for unified incident correlation
Deployment MethodAgent-based onboarding via Microsoft Intune, Microsoft Endpoint Configuration Manager, Group Policy, local script, or VDI package
Licensing PrerequisiteAzure Active Directory (Entra ID) tenant required; available standalone or included in Microsoft 365 E5 / Microsoft 365 E5 Security / Microsoft Defender XDR

Available from Omnixon Global. Submit an RFQ and our team will confirm configuration and availability for your order.

Technical Specifications

BrandMicrosoft
CategoryNetwork Security
SKUMICR-CFQ7TTC0LGV0
Part NumberCFQ7TTC0LGV0
ConditionNew
Manufacturer Part NumberCFQ7TTC0LGV0
Product NameMicrosoft Defender for Endpoint Plan 2
Subscription ModelPer-user, cloud-based SaaS subscription
Devices Per Licensed UserUp to 5 concurrent devices
Supported Client OSWindows 10, Windows 11, macOS, Android, iOS/iPadOS
Supported Server OSWindows Server 2012 R2, 2016, 2019, 2022; Linux (RHEL, CentOS, Ubuntu, SLES, Debian, Oracle Linux, Fedora, Amazon Linux 2)
Core Capability TierPlan 2 (full EDR/XDR feature set, superset of Plan 1)
Endpoint Detection and Response (EDR)Included — behavioral-based, kernel-level telemetry collection with real-time alert generation
Next-Generation ProtectionIncluded — cloud-delivered ML antivirus, behavior monitoring, PUA protection
Attack Surface Reduction (ASR)Included — ASR rules, network protection, web content filtering, controlled folder access, exploit protection
Automated Investigation and Remediation (AIR)Included — automated playbook-driven investigation with full or semi-automated remediation
Threat and Vulnerability Management (TVM)Included — real-time software inventory, CVE correlation, security recommendations, remediation tracking
Advanced Threat HuntingIncluded — KQL-based custom queries across up to 180 days of raw endpoint telemetry
Endpoint Telemetry RetentionUp to 180 days
Threat Intelligence IntegrationMicrosoft Intelligent Security Graph; IOC ingestion (file hash, IP, URL, certificate); MITRE ATT&CK framework mapping
Managed Threat Hunting ServiceMicrosoft Threat Experts — targeted attack notifications and on-demand expert consultation included
Device DiscoveryIncluded — unmanaged device and network asset discovery via enrolled endpoint sensors
Deception CapabilitiesIncluded in P2 — lure-based decoy artifacts to detect lateral movement
Management PortalMicrosoft Defender portal (security.microsoft.com)
XDR IntegrationNative integration with Microsoft Defender XDR (identity, email, cloud apps, endpoints) for unified incident correlation
Deployment MethodAgent-based onboarding via Microsoft Intune, Microsoft Endpoint Configuration Manager, Group Policy, local script, or VDI package
Licensing PrerequisiteAzure Active Directory (Entra ID) tenant required; available standalone or included in Microsoft 365 E5 / Microsoft 365 E5 Security / Microsoft Defender XDR