Microsoft 365 E5 Security
What's included
Curated capability groupings first, then every remaining service plan Microsoft provisions with this SKU — together they're the complete list, nothing is hidden.
| Identity |
|---|
| Risk-Based Conditional Access / Identity Protection Adds Identity Protection risk-based Conditional Access and Privileged Identity Management on top of Entra ID P1. Automatically detect and respond to compromised credentials and risky sign-ins, and build Conditional Access policies that key off Microsoft’s calculated user/sign-in risk score. |
| Privileged Identity Management Adds Identity Protection risk-based Conditional Access and Privileged Identity Management on top of Entra ID P1. Grant admin roles just-in-time (time-bound, approval-gated activation) instead of standing access, with full activation audit history. A core Entra ID P2 entitlement, also obtainable via the standalone Entra ID Governance add-on. |
| Access Reviews Adds Identity Protection risk-based Conditional Access and Privileged Identity Management on top of Entra ID P1. Periodically require an owner or the user themselves to re-certify continued need for group membership, app access, or a role assignment — access that’s no longer needed gets removed automatically. |
| Entitlement Management Adds Identity Protection risk-based Conditional Access and Privileged Identity Management on top of Entra ID P1. Bundle groups, apps, and SharePoint sites into a requestable "access package" with approval workflow and automatic expiration — including for external/guest users. |
| Security |
| Defender for Endpoint Plan 2 Endpoint detection and response, threat and vulnerability management, and attack surface reduction for Windows, macOS, Linux, iOS, and Android devices. Endpoint detection and response: attack surface reduction, behavioral monitoring, and automated investigation/remediation for Windows, macOS, Linux, iOS, and Android devices. |
| Defender for Office 365 Plan 2 Protects email and collaboration content from phishing, malware, and malicious links via Safe Links and Safe Attachments. Protects mail and collaboration content from phishing and malware: Safe Links, Safe Attachments, and anti-phishing at Plan 1; adds automated investigation/response, attack simulation, and threat hunting at Plan 2. |
| Defender for Identity Monitors on-premises Active Directory signals to detect compromised identities and malicious insider actions. Monitors on-premises Active Directory signals (via a lightweight sensor on domain controllers) to detect compromised identities and lateral-movement/privilege-escalation attacks. |
| Defender for Cloud Apps Full Defender for Cloud Apps (all sanctioned SaaS) A cloud access security broker (CASB) that discovers shadow IT and applies access and session controls to third-party cloud apps. A cloud access security broker (CASB): discovers shadow IT, and applies session/access policies across sanctioned SaaS apps. The Office 365-scoped tier only covers Microsoft 365 activity; the full product extends that policy control to third-party cloud apps. |
| Other service plans |
| Microsoft 365 Defender A unified cross-product incident view and automated investigation/response across the Microsoft Defender security products. |
| Office 365 SafeDocs Opens Office files from untrusted sources in a protected cloud-based view before allowing local editing. |