Microsoft Defender for Office 365
Answer: Defender for Office 365 capabilities are divided between Plan 1, Plan 2, and suites that include them; determine whether the requirement is protection, investigation, simulation, hunting, or automated response before selecting a plan.
Administrator playbook
Decide, verify, and document
Use the curated answer as a starting point, then prove the outcome against the target tenant or device.
What it means
- Plan 1 focuses on protection features such as Safe Links and Safe Attachments
- Plan 2 adds advanced investigation, hunting, automation, and training capabilities
- Included rights vary by Microsoft 365 and security suite
What to check next
- Map each required Defender feature to the current service description
- Confirm every protected or benefiting user is licensed
- Check whether the entitlement is standalone or inherited from a suite
Verify success
- Confirm the SKU is assigned to every benefiting user or covered device.
- Confirm the required service plan is enabled, not merely present in the tenant.
- Re-test the exact feature after license propagation and record the result.
Escalate when
- Microsoft documentation and the tenant SKU/service-plan view disagree.
- The feature remains unavailable after assignment and normal propagation.
- A purchase or renewal decision depends on contract-specific product terms.
Copyable admin briefAnswer, next checks, source, and review date
List subscribed SKUs
Get-MgSubscribedSku | Select-Object SkuPartNumber,ConsumedUnits,PrepaidUnitsRead-only. Confirms tenant inventory; it does not prove that a service plan is enabled for a specific user.
Evidence to preserve
- Plans
- Plan 1 and Plan 2
- Workload
- Exchange Online, SharePoint, OneDrive, Teams
- Verify
- Current Defender service description
- Exact feature and workload
- Users or devices benefiting from it
- Assigned SKU and enabled service plans
- Tenant region and purchase channel
