Frontrow Technology
← All insights & guides
Guide

Cyber security

Is Microsoft Defender an EDR? It Depends Which Defender You Mean (2026)

The built-in Defender Antivirus is not an EDR, but Defender for Endpoint Plan 2 and Defender for Business are. Which licence includes which, capability by capability, with AUD prices. Checked September 2026.

Graeme Lodge · Last reviewed 12 September 2026 · 9 min read

The Microsoft Defender antivirus built into Windows is not an EDR. Microsoft Defender for Endpoint Plan 2 and Microsoft Defender for Business are genuine EDR products, available standalone or inside Microsoft 365 E5 and Business Premium respectively. Whether your organisation already has EDR depends entirely on which licence it holds.

The question comes up constantly because Microsoft uses the Defender brand across a wide family of security products, and several of them run on the same laptop. This guide separates the family, then shows which Microsoft 365 licence includes genuine endpoint detection and response, with Australian pricing.

Which Defender is which?

Five products account for nearly all the confusion. Here is what each one actually is.

  • Microsoft Defender Antivirus: the free protection built into Windows 10 and 11. Real-time malware scanning with cloud-delivered protection. It is an antivirus, not an EDR.
  • Microsoft Defender for Endpoint Plan 1: a paid endpoint protection platform (EPP). It adds attack surface reduction rules, device control and centralised management on top of the antivirus. Still not an EDR.
  • Microsoft Defender for Endpoint Plan 2: Microsoft's full EDR. Behavioural sensors record activity on every onboarded device, detections are correlated into incidents, and responders get device isolation, live response, automated investigation and advanced hunting with KQL.
  • Microsoft Defender for Business: the same core EDR engine packaged for organisations of up to 300 employees, with simplified onboarding and sensible default policies. It is included in Microsoft 365 Business Premium and also sold standalone.
  • Microsoft Defender XDR: the portal and correlation layer that joins Defender for Endpoint with Defender for Office 365, Defender for Identity and Defender for Cloud Apps, so one incident can span mailbox, identity and device.

So the honest answer to the headline question is a counter-question: which Defender? The free antivirus is not an EDR. Plan 2 and Defender for Business are. Plan 1 sits in between as prevention without the detection and response layer.

What is the difference between antivirus, EDR and XDR?

Antivirus stops known malicious files at the moment they land. It is essential, and the version built into Windows is genuinely good, but it works file by file and makes its decision in the moment.

EDR starts from a different assumption: some attacks will get past prevention. It continuously records what happens on each endpoint, from process launches to network connections, and flags chains of behaviour that look like an intrusion in progress. When something fires, a responder can see the full history and cut the device off from the network while keeping it reachable for investigation.

XDR widens the same idea beyond the endpoint. Microsoft Defender XDR correlates endpoint signals with what is happening in email, identity and cloud apps, so a phishing email and the compromised sign-in that followed it appear as one incident rather than two disconnected alerts.

Which Microsoft 365 licence includes EDR?

This is where budgets are won and lost, because many organisations already pay for EDR without knowing it, and others assume they have it when they do not.

  • Microsoft 365 Business Premium includes Microsoft Defender for Business, a full EDR. AU$32.90 per user per month paid yearly, ex GST, checked September 2026 (the Copilot add-on is priced separately).
  • Microsoft Defender for Business standalone is AU$4.50 per user per month paid yearly, ex GST, checked September 2026. It can sit alongside other Microsoft 365 plans for organisations up to 300 employees.
  • Microsoft 365 E3 includes Defender for Endpoint Plan 1 only. E3 on its own does not give you EDR.
  • Microsoft 365 E5, or E3 plus the Microsoft Defender Suite add-on, includes Defender for Endpoint Plan 2, the full EDR. Defender Suite is the current name for what Microsoft previously sold as Microsoft 365 E5 Security, so older quotes and internal documents may still use the old name.

Microsoft publishes its own comparison, and it is worth reading rather than paraphrasing, because the interesting rows are the ones where Defender for Business sits above Plan 1 and the ones where it does not reach Plan 2.

Microsoft's comparison of Defender for Business against the Defender for Endpoint plans (checked September 2026)
CapabilityDefender for BusinessEndpoint Plan 1Endpoint Plan 2
Next-generation protectionYesYesYes
Attack surface reductionYesYesYes
Centralised management and APIsYesYesYes
Cross-platform (Mac, iOS/iPadOS, Android)YesYesYes
Endpoint detection and responseYes (optimised)NoYes
Automated investigation and remediationYesNoYes
Automatic attack disruptionYesNoYes
Vulnerability management (core capabilities)YesNoYes
Threat analyticsYes (optimised)NoYes
Monthly security summary reportingYesNoYes
Advanced hunting, plus six months of data retentionNoNoYes
Microsoft Threat ExpertsNoNoYes
Simplified firewall and antivirus configuration for WindowsYesNoNo
Server protectionExtra licenceExtra licenceExtra licence

Two rows deserve a second look. The last one is the gap Frontrow finds most often: Windows and Linux server protection is never included, under any of the three, and needs a separate licence. A business still running a file server or a line-of-business application server is the one most likely to have assumed otherwise. And the second-to-last row is the quiet advantage of the small-business product, because the wizard-driven firewall and antivirus configuration exists precisely because a 30-person business has nobody whose job is tuning endpoint policy.

Is Microsoft Defender EDR free?

The antivirus is free with Windows. EDR is not. The cheapest route to genuine Microsoft EDR is Defender for Business standalone at AU$4.50 per user per month ex GST, checked September 2026, which is modest against the cost of a single incident response engagement.

The more common situation Frontrow encounters is a business already paying for Microsoft 365 Business Premium that has never onboarded its devices to Defender for Business. The EDR licence is being paid for every month while the capability sits switched off. Onboarding devices is configuration work, not a purchase.

Is Microsoft Defender a good EDR?

On the independent evidence, yes. Gartner named Microsoft a Leader in its 2026 Magic Quadrant for Endpoint Protection, announced 29 May 2026, continuing a multi-year run in the Leader quadrant.

MITRE's ATT&CK Evaluations put participating vendors through the same emulated attacks and publish raw results rather than rankings. In the 2024 Enterprise round, which emulated ransomware operators and a North Korean state-sponsored actor, Microsoft reported 100 per cent technique-level detection on the Linux and macOS scenarios with zero false positives. The full results are on the MITRE evaluations site for anyone who wants to compare vendors directly.

Third-party EDR platforms are also credible, and some are excellent. The practical case for Defender in a Microsoft-centred business is signal quality: it already sees your Microsoft Entra ID sign-ins and your Exchange Online mail flow, and correlates them with endpoint activity without any integration work.

Where does EDR fit in the Essential Eight?

EDR is not one of the Essential Eight. The eight strategies are preventive and recovery controls such as application control, patching, multi-factor authentication and regular backups. An organisation could run the best EDR in the world and still sit at Maturity Level Zero.

Detection still matters to the ACSC. ASD's broader Strategies to Mitigate Cyber Security Incidents, the publication the Essential Eight was drawn from, recommends EDR software for detecting compromises and supporting incident response. The sensible reading for an Australian business: treat the Essential Eight as the prevention baseline and EDR as the answer for when prevention is not enough.

Who watches the alerts?

An EDR nobody monitors is a smoke alarm in an empty building. Automated investigation in Defender for Business can resolve routine detections on its own, but genuine incidents still queue in the portal waiting for a human decision. The detections that precede ransomware deployment often arrive days before the encryption does, and they only help if someone reads them that day.

The real question for a small business is less which EDR to buy than who checks the portal. Some allocate it to internal IT as a daily habit. Others have their Microsoft partner watch it as part of a managed service, the arrangement Frontrow runs for its Australian SMB clients. Either model works; having no model is the failure state.

Common questions

Frequently asked

Is the free Microsoft Defender in Windows an EDR?
No. Microsoft Defender Antivirus, built into Windows 10 and 11, is an antivirus. It blocks malware on the device but does not record endpoint telemetry, correlate incidents or give responders investigation and isolation tools. EDR requires a paid licence such as Microsoft Defender for Business or Defender for Endpoint Plan 2.
Is Microsoft Defender for Endpoint an EDR or an XDR?
Defender for Endpoint Plan 2 is an EDR: it detects and responds to threats on endpoints. Microsoft Defender XDR is the wider suite that correlates those endpoint signals with email, identity and cloud app telemetry from the other Defender products. Plan 2 is the endpoint component inside that suite.
Does Microsoft 365 Business Premium include EDR?
Yes. Business Premium includes Microsoft Defender for Business, a genuine EDR with behavioural detection, automated investigation and response, and vulnerability management, for organisations of up to 300 employees. Devices must be onboarded to it before anything is protected, and many tenants never complete that step.
How much does Microsoft Defender EDR cost in Australia?
Defender for Business standalone is AU$4.50 per user per month ex GST paid yearly, checked September 2026 against Microsoft's Australian pricing. It is also included in Microsoft 365 Business Premium at AU$32.90 per user per month ex GST (Copilot add-on priced separately). Larger organisations get Defender for Endpoint Plan 2 through Microsoft 365 E5 or the Microsoft Defender Suite add-on, which Microsoft previously sold as Microsoft 365 E5 Security.
Is Defender for Business as good as Defender for Endpoint Plan 2?
It runs the same core detection engine and includes automated investigation and response. The differences: Defender for Business is capped at 300 employees, keeps a shorter investigation history and leaves out advanced hunting with KQL. Most small businesses find those trade-offs acceptable; security teams that hunt threats proactively want Plan 2.

The matched next step

Find out where your own tenant would have failed

Most incidents start with a control Frontrow checks in week one: MFA coverage, legacy authentication, admin sprawl, unpatched servers. A security baseline review scores your Microsoft 365 tenant against the Essential Eight and hands you a prioritised fix list — whether or not Frontrow does the fixing.

Want Frontrow to run this with your team?

A 30-minute call with a senior consultant. No deck. Frontrow walks through your tenant, your priorities and the next sensible move.