Microsoft Defender for Endpoint
Architecture and deployment

Defender Endpoint Plan 1

In brief

The page adds licensing details for standalone, Microsoft 365 E3, and server deployments, and updates links for Windows Firewall and Application Control documentation.

What Defender admins need to know

Review the licensing guidance when planning server deployments or evaluating eligibility for a Defender for Servers discount. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

ms.service: defender-endpoint ms.subservice: onboard ms.localizationpriority: medium ms.date: 05/02/202507/28/2026 appliesto:

  • Microsoft Defender for Endpoint Plan 1 ms.reviewer: shlomiakirav
  • Safeguard sensitive data and intellectual property
  • Extend your security investment

To learn more, see Windows Defender Firewall with advanced securityWindows Defender Firewall with advanced security.

Application control

Application control protects your Windows endpoints by running only trusted applications and code in the system core (kernel). Your security team can define application control rules that consider an application's attributes, such as its codesigning certificates, reputation, launching process, and more. Application control is available in Windows 10 or later.

To learn more, see Application control for WindowsApplication control for Windows.

Centralized management

To learn more, see Defender for Endpoint APIs.

Licensing

Defender for Endpoint Plan 1 is available as a standalone subscription or as part of Microsoft 365 E3. For server deployments, you can license Defender for Endpoint Plan 1 for servers separately.

If you're also using Microsoft Defender for Servers as part of Defender for Cloud, check if you're eligible for a licensing discount when you have both Defender for Endpoint and Defender for Servers.

Next steps