Microsoft 365 Security and Compliance for Firstline Workers
What's included
Curated capability groupings first, then every remaining service plan Microsoft provisions with this SKU — together they're the complete list, nothing is hidden.
| Security |
|---|
| Defender for Endpoint Plan 2 Endpoint detection and response, threat and vulnerability management, and attack surface reduction for Windows, macOS, Linux, iOS, and Android devices. Endpoint detection and response: attack surface reduction, behavioral monitoring, and automated investigation/remediation for Windows, macOS, Linux, iOS, and Android devices. |
| Defender for Office 365 Plan 2 Protects email and collaboration content from phishing, malware, and malicious links via Safe Links and Safe Attachments. Protects mail and collaboration content from phishing and malware: Safe Links, Safe Attachments, and anti-phishing at Plan 1; adds automated investigation/response, attack simulation, and threat hunting at Plan 2. |
| Defender for Identity Monitors on-premises Active Directory signals to detect compromised identities and malicious insider actions. Monitors on-premises Active Directory signals (via a lightweight sensor on domain controllers) to detect compromised identities and lateral-movement/privilege-escalation attacks. |
| Defender for Cloud Apps Full Defender for Cloud Apps (all sanctioned SaaS) A cloud access security broker (CASB) that discovers shadow IT and applies access and session controls to third-party cloud apps. A cloud access security broker (CASB): discovers shadow IT, and applies session/access policies across sanctioned SaaS apps. The Office 365-scoped tier only covers Microsoft 365 activity; the full product extends that policy control to third-party cloud apps. |
| Compliance |
| eDiscovery Premium Advanced eDiscovery search, review, and analysis tools, including machine-learning-assisted review, for legal and compliance investigations. Search, hold, and export content across mailboxes, SharePoint, OneDrive, and Teams for a legal or investigative matter. Standard covers search/export; Premium adds review sets, custodian management, and analytics (near-duplicate detection, email threading, predictive coding). |
| Sensitivity Labels Automatic labeling Adds automatic and recommended sensitivity labeling on top of Information Protection for Office 365 Standard's manual labeling. Classify and protect content (encryption, watermarking, access restriction) by applying labels users pick or that get applied for them. Manual, user-applied labeling is the base tier; automatic labeling (content is scanned and labeled without user action) needs the higher tier. |
| Data Loss Prevention |
| Audit Premium Extends Microsoft Purview Audit with a longer retention window and additional high-value audit log events for forensic investigations. A searchable log of user and admin activity across Microsoft 365. Standard covers 180 days of retention and core events; Premium extends retention to a year (with add-ons to 10 years), adds high-value crucial events (mailbox access, mail-forwarding-rule changes), and higher log bandwidth for faster forensic investigation. |
| Purview Information Protection (analytics) Premium Reporting on sensitivity-label usage and information-protection activity across the tenant. Visibility into where labeled/sensitive content actually lives and how it moves (Content Explorer, Activity Explorer) — distinct from Sensitivity Labels itself, which covers creating and applying the labels; this is the reporting/analytics layer on top. |
| Communication Compliance Scans internal and external communications for policy violations such as harassment, regulatory breaches, or sensitive-data sharing. Scans internal and external communications (Teams, Exchange, third-party connectors) for policy violations — harassment, regulatory/insider-trading language, sensitive-data sharing — and routes matches to reviewers. |
| Customer Key Lets an organization supply and control its own encryption keys for Microsoft 365 data at rest. Supply and control your own encryption keys for Microsoft 365’s at-rest data encryption layer, so Microsoft can’t access your content without your key. |
| Customer Lockbox Requires explicit customer approval before a Microsoft engineer can access content to resolve a support request. |
| Productivity |
| Exchange Online Archiving |
| Other service plans |
| Azure Information Protection Premium P2 Adds automatic sensitivity-labeling recommendations and unified labeling management on top of Azure Information Protection Premium P1. |
| Data Classification in Microsoft 365 Automatically identifies and classifies sensitive content (such as credit card or ID numbers) across Microsoft 365 for use in protection and compliance policies. |
| Information Barriers Restricts communication and collaboration between specified groups of users — for example, to prevent conflicts of interest. |
| Microsoft 365 Defender A unified cross-product incident view and automated investigation/response across the Microsoft Defender security products. |
| Microsoft Communications DLP Applies data loss prevention policies to Microsoft Teams chats and channel messages. |
| Microsoft Endpoint DLP Extends data loss prevention policies to monitor and restrict sensitive-content actions on Windows endpoint devices. |
| Microsoft ML-Based Classification Trainable classifiers that use machine learning to identify sensitive or regulated content types beyond pattern-based detection. |
| Office 365 Privileged Access Management Requires just-in-time approval for administrators to perform specific high-risk Exchange Online tasks. |
| Premium Encryption in Office 365 Applies more granular, condition-based encryption rules to Outlook email beyond standard Office 365 Message Encryption. |