Decision guide · 2026-09-14
Microsoft Defender for Business, Endpoint P1 or P2: which should you choose in Belgium?
An operational comparison to align licensing, detection level, response capability and endpoint management, without confusing the tool with a security service.

What is the real choice to make?
The choice is not simply between three licences: it combines a level of prevention, detection capability, operating model and actual estate.
Start with the incidents the organisation needs to be able to prevent, see and handle. Modern antivirus blocks known threats and reduces the attack surface; an EDR retains and correlates more signals in order to investigate suspicious behaviour. Automated investigation can then analyse an alert and propose or execute remediation actions depending on the configuration. If nobody monitors the queue, assesses incidents and decides whether to isolate a machine, purchasing the feature does not by itself create a response capability.
Then map users, workstations, mobiles and servers, operating systems, sites and responsibilities. The GVISION page dedicated to XDR/MDR endpoint protection illustrates the operational step that follows the choice of technology: bringing signals together, handling alerts and organising the response. This article remains a Microsoft comparison and does not assume that the same solution is suitable for every environment.
What do Business, P1 and P2 cover?
Business combines P1 prevention with certain P2 capabilities in an optimised experience; P1 hardens and protects; P2 adds advanced investigation and response.
According to the Microsoft Defender for Business overview, updated on 20 January 2026, Business is designed for organisations with up to 300 users. It is available separately or included with Microsoft 365 Business Premium. It includes next-generation protection, attack surface reduction, optimised EDR, automated investigation and remediation, as well as core vulnerability management capabilities. Its aim is to make an advanced set of capabilities usable with simpler configuration.
La Microsoft Defender service description, updated on 22 May 2026, describes P1 as the prevention foundation: next-generation antimalware, attack surface reduction rules, device control, firewall, network protection and application control. P2 adds EDR, automated investigation and remediation, vulnerability management, threat analytics, deep analysis and Microsoft Threat Experts. P2 is therefore not simply “more blocking”: it provides greater support for investigative work.
How can capabilities be compared without taking shortcuts?
The table shows that no plan wins outright: P1 may be sufficient for a preventive strategy, Business combines simplicity with EDR, while P2 is aimed at advanced operations.
Read each line in the context of licensing and operations. An organisation already equipped with Microsoft 365 Business Premium may have access to Business without a separate purchase for eligible users, but it still needs to deploy, configure, test and monitor the service. An organisation with E3 may have P1 depending on its agreement and can decide whether the risk and response capability justify P2. Commercial names and inclusions may change: check the licensing portal and Microsoft terms at the time of purchase.
Costs are not included in this table because they depend on the programme, country, commitment, discounts, base licences and servers. Instead, compare the total cost: licences, administration, onboarding, alert handling, SIEM/SOC integration, retention, training and incident handling. An advanced feature without a process can cost more than it protects; a minimum licence without sufficient visibility can delay detection.
| Criterion | Defender for Business | Endpoint P1 | Endpoint P2 |
|---|---|---|---|
| Target audience | Organisations with up to 300 users | Organisations with enterprise prevention requirements | Organisations with advanced detection and response operations |
| Next-generation protection | Yes | Yes | Yes |
| Attack surface reduction | Yes | Yes | Yes |
| EDR | Yes, optimised experience | No, no full EDR | Yes, advanced capabilities |
| Automated investigation and remediation | Yes | No | Yes |
| Vulnerability management | Core capabilities | Not indicated as a P1 capability | Advanced capabilities |
| Advanced Hunting | Not indicated in the Microsoft comparison | No | Yes, data and six-month retention according to Microsoft |
| Configuration | Simplified, with possible Intune integration | Managed through enterprise tools | Managed through enterprise tools and the SOC |
| Cross-platform | Windows, macOS, Linux, Android, iOS subject to prerequisites | Same platform, capabilities depending on plan and OS | Same platform, capabilities depending on plan and OS |
| Servers | Additional server licence required | Separate server licence depending on the scenario | Separate server licence depending on the scenario |
| Main limitation | 300-user threshold and simplified experience | No full EDR | More capabilities to operate and govern |
| Best choice according to the need | Eligible team wanting simplified EDR and automation | Microsoft prevention with another detection solution | Organisation requiring advanced investigation, hunting and response |
Target audience
Business: Organisations with up to 300 users
P1: Organisations with enterprise prevention requirements
P2: Organisations with advanced detection and response operations
Next-generation protection
Business: Yes
P1: Yes
P2: Yes
Attack surface reduction
Business: Yes
P1: Yes
P2: Yes
EDR
Business: Yes, optimised experience
P1: No, no full EDR
P2: Yes, advanced capabilities
Automated investigation and remediation
Business: Yes
P1: No
P2: Yes
Vulnerability management
Business: Core capabilities
P1: Not indicated as a P1 capability
P2: Advanced capabilities
Advanced Hunting
Business: Not indicated in the Microsoft comparison
P1: No
P2: Yes, data and six-month retention according to Microsoft
Configuration
Business: Simplified, with possible Intune integration
P1: Managed through enterprise tools
P2: Managed through enterprise tools and the SOC
Cross-platform
Business: Windows, macOS, Linux, Android, iOS subject to prerequisites
P1: Same platform, capabilities depending on plan and OS
P2: Same platform, capabilities depending on plan and OS
Servers
Business: Additional server licence required
P1: Separate server licence depending on the scenario
P2: Separate server licence depending on the scenario
Main limitation
Business: 300-user threshold and simplified experience
P1: No full EDR
P2: More capabilities to operate and govern
Best choice according to the need
Business: Eligible team wanting simplified EDR and automation
P1: Microsoft prevention with another detection solution
P2: Organisation requiring advanced investigation, hunting and response
What does the 300-user limit change?
The 300-user limit is a positioning condition for Defender for Business; beyond this threshold, Microsoft directs organisations towards the enterprise P1 or P2 offerings.
La Microsoft Defender for Business FAQ, updated on 7 August 2026, confirms that the offering is intended for up to 300 users and recommends the enterprise offerings beyond that threshold. Do not count devices alone: document the identities to which the licence must be assigned, external workers, prohibited shared accounts, subsidiaries and planned growth. An organisation with 285 people acquiring another company should not build an architecture that cannot scale.
Be careful with mixed environments. Microsoft states that a tenant simultaneously holding Defender for Business and Defender for Endpoint P2 licences uses the Business experience by default. To switch to P2, all relevant users must be licensed and Microsoft Support must be contacted. This behaviour makes a partial transition more complex than simply adding licences. Therefore, validate coexistence, usage rights and the actual experience before signing or migrating.
Who should handle the alerts?
An EDR licence does not replace the roles, working hours or decisions required to assess and contain an incident.
Define a console owner, a deputy and an escalation chain. Specify what is reviewed each day, alert priorities, the time allowed for assessment, the conditions for isolating a workstation and how to contact the business owner. A school, hospital, public authority or industrial group will not always accept the same automated action. The security team must understand the consequences of isolation, quarantine or blocking on business operations.
P2 provides more material for investigation, but it still needs to be interpreted. Business simplifies certain views and automations, which helps a small team without removing the need for governance. P1 may be appropriate when another tool or service provides detection and response. Therefore, also compare the internal SOC, service provider, coverage hours, evidence collection, notifications and exercises. The decision concerns a socio-technical system, not a box in a table.
How should workstations, mobiles and servers be handled?
Inventory every operating system and server: cross-platform coverage exists, but onboarding, capabilities and licensing are not identical.
Microsoft presents Defender for Endpoint as a platform covering Windows, macOS, Linux, Android and iOS in its documentation updated on 28 July 2026. This scope does not mean that every capability is identical everywhere. Check supported versions, prerequisites, agent, passive or active mode, application exclusions, connectivity and how each device type appears in the portal. Include off-site and rarely connected workstations in the test.
Servers require separate attention. Microsoft specifies that their protection requires an additional server licence or an appropriate Defender for Servers offering, depending on the architecture. Inventory physical hosts, virtual machines, legacy systems and third-party-managed servers. Do not blindly apply a workstation policy to a production server. Have exclusions, maintenance windows, performance and rollback procedures validated by the application owner.
What role does Microsoft Intune play?
Intune facilitates endpoint onboarding and policies, but compliance, security configuration and incident response must be kept separate.
La Defender for Business configuration procedure describes a wizard, roles, notifications, Windows onboarding and integration with Intune. The FAQ also specifies that custom ASR rules require Intune. In a Microsoft 365 estate, endpoint management with Microsoft Intune can therefore serve as a deployment and control layer. However, verify which authority manages each setting to avoid two conflicting policies.
Build a clear hierarchy: pilot groups, baseline policies, temporary exceptions, owners and expiry dates. Do not turn an application exception into a general exclusion. Test attack surface reduction rules in audit mode where an observation mode exists, then measure the affected applications before activation. Finally, verify that devices are actually onboarded, active, up to date and assigned to the correct group; assigning a policy does not prove that it has been applied.
What data and GDPR rules should be considered?
Collect the signals required for security, limit access and document purpose, retention and employee monitoring.
An EDR processes technical information relating to devices, processes, files, connections and sometimes users. TheArticle 5 of the GDPR requires, among other things, purpose limitation, data minimisation, accuracy, storage limitation and security. Involve IT, security, the DPO, HR and employee consultation where applicable. Document the purposes, data categories, recipients, retention period, transfers, access rights and rules of use during an investigation.
According to the Microsoft table, P2 provides Advanced Hunting data and six-month retention for this capability; the comparison does not attribute this retention to Business. Do not choose a retention period simply because it is available. Link it to investigation scenarios, obligations, the SIEM and the budget. Restrict access to search capabilities, log administrative actions and keep cybersecurity separate from general productivity monitoring.
How can you conduct a useful pilot?
A pilot must demonstrate onboarding, prevention, alert generation, escalation and recovery on representative devices.
Start with a reliable inventory and a limited group covering several profiles: office, remote working, a workstation with a business application, Mac or Linux if present, a mobile device and a separate test server. Capture the initial state, existing antivirus solutions, exclusions and network dependencies. Configure roles, notifications and groups before onboarding. Use benign tests documented by Microsoft or your internal procedure; never simulate an attack in production without authorisation.
Then measure coverage, sensor health, false positives, assessment time and impact on applications. Handle an alert end-to-end: receipt, enrichment, decision, communication, remediation and closure. The following illustration reminds us that the pilot must combine tools and people. Expand in rings, with a stop criterion and a rollback procedure. Keep a log of exceptions and a formal decision on the selected licence.


Which Belgian scenarios help clarify the decision?
Size determines eligibility, but criticality, estate, working hours and response capability determine the level that is actually useful.
A 120-person services company already using Microsoft 365 Business Premium may favour Defender for Business, then invest in onboarding, policies and monitoring. A 70-person association with limited IT may make the same choice but entrust assessment to a partner. A 450-user company using E3 may retain P1 if another solution provides EDR, or evaluate P2 to consolidate investigations. In every case, the inventory of existing licences comes before price comparison.
A multi-site group with 24/7 production will need to test isolation and exclusions on industrial workstations. A healthcare organisation will prioritise continuity, traceability and separation of roles. A public authority may need to integrate procurement procedures, delegations and on-call schedules. An international company will check tenant governance, regions and the SOC. These examples do not prescribe a licence: they show why the operating context can overturn a choice based solely on the number of users.
What mistakes should be avoided?
The most costly mistakes are choosing based on price alone, forgetting servers, mixing licences without testing and leaving alerts without an owner.
Also avoid confusing a device enrolled in Intune with a device correctly onboarded in Defender, activating all ASR rules on the same day, keeping exclusions without an expiry date or assuming that all capabilities are identical across every OS. Do not duplicate policies across multiple consoles without defining the authority. Do not treat a green dashboard as proof of security: check sensors, events, notifications and response actions.
Finally, do not present P2 as automatically superior. If nobody conducts investigations, the capability remains underused; if the risk requires visibility that P1 does not provide, the apparent saving is misleading. Document the assumptions, test a representative sample and reassess after an acquisition, licence migration or SOC change. The best choice is the one the organisation can maintain, monitor and mobilise during an incident.
Frequently asked questions
Does Defender for Business include EDR?
Yes. Microsoft specifies optimised EDR, as well as automated investigation and remediation. P1 does not provide full EDR; P2 provides advanced capabilities.
Is Business limited to 300 devices?
Microsoft positions the offering for organisations with up to 300 users. Devices and servers must nevertheless be inventoried and licensed according to the applicable terms.
Can Business and P2 be mixed in the same tenant?
The Microsoft FAQ states that a mixed environment uses the Business experience by default. A transition to P2 must therefore be planned and validated with the appropriate licences and Microsoft Support.
Are servers included?
Not by default. Microsoft provides for an additional server licence or a Defender for Servers offering depending on the scenario. Check each system and environment.
Is Intune mandatory?
Not for all capabilities, but it facilitates deployment and enables, among other things, custom ASR policies in the documented scenarios.
Does P2 replace a SOC or MDR?
No. P2 provides more data and automation; an organisation or service provider must still monitor, assess, make decisions and respond.
How should you choose between P1 and P2?
Start with incident scenarios, the need for EDR and investigation, existing licences, the estate, response capability and a representative pilot.
Conclusion
Defender for Business, P1 and P2 address different models. Business brings advanced capabilities together in an experience designed for eligible organisations; P1 provides a preventive foundation; P2 supports deeper investigation and response. A sound decision-making process links the licences already held, actual devices, risks and responsibility for alerts.
GVISION can help a Belgian organisation inventory its estate, clarify the operating model and test deployment without turning the comparison into a universal promise. To move from the table to a verifiable scope, you can define your choice and pilot.



