Microsoft Just Made Advanced Security Easier to Attach to E3 — Here's the Add-On Play
Microsoft's August 2026 CSP change lets M365 E3 customers buy Entra ID P2, Defender for Endpoint P2, and Defender for Office 365 P2 as standalone add-ons. Here's what that means for your security posture and your budget.
For years, the answer to "how do we get proper enterprise security on Microsoft 365?" came with a catch. If you were on E3 and wanted the good stuff — risk-based conditional access, endpoint detection that actually catches things, anti-phishing that reads intent rather than just keywords — the standard advice was to jump the whole business up to E5. That meant re-licensing every user, often paying for a stack of features you'd never touch, just to reach three or four you genuinely needed.
That catch has now gone.
Microsoft's August 2026 CSP announcement makes three of the most valuable E5 security components available as discrete add-ons for M365 E3 customers: Entra ID P2, Defender for Endpoint Plan 2, and Defender for Office 365 Plan 2. Crucially, the pricing is now consistent across CSP and Enterprise Agreement, so the days of the same SKU costing wildly different amounts depending on how you bought it are over too.
If you run IT for a UK SME sitting on E3, this is the most useful licensing change in a while. Let me walk through what you can now get, what it costs, and how to decide whether it's worth it.
What actually changed
Before this, the security add-on menu for E3 was patchy. You could bolt on a few things, but the crown-jewel security features were effectively locked behind E5. The upgrade from E3 to E5 is roughly £15–£18 per user per month depending on your agreement — a serious jump when you multiply it across 80 people.
Now you can pick the three security workloads independently:
- Entra ID P2 — the identity layer. This is where you get risk-based conditional access, identity protection that flags suspicious sign-ins in real time, privileged identity management (just-in-time admin access), and access reviews.
- Defender for Endpoint P2 — the endpoint layer. Full endpoint detection and response (EDR), automated investigation and remediation, threat and vulnerability management, and six months of raw hunting data rather than the thinner telemetry you get lower down.
- Defender for Office 365 P2 — the email and collaboration layer. Everything in P1 (Safe Links, Safe Attachments, anti-phishing) plus Threat Explorer, automated investigation, attack simulation training, and campaign views.
Buy all three and you've reconstructed the security heart of E5 without paying for Power BI Pro, advanced compliance, analytics, or the phone-system pieces you may not want.
What it costs — and the honest maths
Approximate CSP monthly per-user pricing at the time of writing:
- Entra ID P2: around £7
- Defender for Endpoint P2: around £4.50
- Defender for Office 365 P2: around £4
All three together lands near £15.50 per user, per month — which, on paper, is close to the E5 upgrade cost.
So why bother? Two reasons.
First, you rarely need all three for everyone. Most SMEs don't want identical security across the whole workforce. A 60-person firm might give Entra ID P2 to all users (identity is universal), Defender for Endpoint P2 to the 60 who have company devices, but Defender for Office 365 P2 only to the 25 in finance, sales, and leadership — the people who get targeted by invoice fraud and phishing. Mix and match, and the real bill sits well below a blanket E5 upgrade.
Second, you can phase it. Start with the identity add-on this quarter, add endpoint next quarter after you've cleaned up device management, layer in email protection later. The E5 route forced an all-or-nothing decision. This doesn't.
Here's a worked example. A 50-user business:
- E5 upgrade for all 50: ~£16/user = £800/month
- Add-on approach: Entra ID P2 for all 50 (£350) + Endpoint P2 for 45 devices (£202) + Office 365 P2 for 20 high-risk users (£80) = £632/month
That's roughly £2,000 a year saved, with security aimed at where the risk actually is rather than spread thin for the sake of a tidy licence count.
Why this matters beyond the price
The cost saving is nice. The bigger win is that E3 customers now have a realistic path to enterprise-grade defence without a disruptive migration.
We see the same gaps repeatedly in SMEs on plain E3. Conditional access exists but can't respond to risk — it can block by location or device, but it can't say "this login looks like the user's credentials were stolen, so challenge or block it." That real-time risk signal is an Entra ID P2 feature, and it's one of the single most effective controls against account takeover.
Endpoint protection is another. E3 includes Defender Antivirus, which is genuinely decent, but it's not EDR. When something does get through, plain E3 gives you very little ability to investigate — no timeline of what the attacker touched, no automated containment, no threat hunting. Defender for Endpoint P2 turns "we think something happened" into "here's exactly what happened, when, and it's already been isolated."
And email. Business email compromise remains the most expensive threat facing UK SMEs — the sort where a spoofed supplier email reroutes a £40,000 payment. Defender for Office 365 P2's attack simulation lets you test your own staff and see who clicks, while the investigation tools help you trace a phishing campaign across every mailbox it touched.
A buyer's decision guide
If you're weighing this up, work through it in this order.
1. Start with identity. If you're going to buy one add-on, make it Entra ID P2. Compromised credentials are behind the majority of breaches, and risk-based conditional access is the highest-leverage control you can add. Apply it to everyone.
2. Then endpoint — if you manage the devices. Defender for Endpoint P2 only pays off if your machines are enrolled and you (or your provider) will actually watch the alerts. EDR you don't monitor is a false sense of security. If nobody's looking at the console, buy it alongside a managed detection service.
3. Then email — targeted at risk. Roll Defender for Office 365 P2 out to finance, procurement, executives, and anyone who handles invoices or payment details first. Expand from there if the budget allows.
4. Compare against the full E5 number. Do the maths for your headcount. If your all-three-for-everyone total genuinely approaches E5, and you'd use the extra compliance and analytics features, E5 may still be the better buy. For most SMEs, it won't be.
Where we come in
Licensing is the easy part. The value only lands once these tools are configured properly, tuned to cut out noise, and monitored by someone who'll act when an alert fires. A Defender for Endpoint console nobody reads protects nobody.
At Cloudworks we help Nottingham and East Midlands SMEs pick the right mix, deploy it in phases that don't disrupt the business, and run the ongoing monitoring so the security you're paying for is doing its job. If you're on E3 and have wondered whether E5 was worth the leap, this change means the answer is now: probably not — and here's what to buy instead.
Book a licensing review and we'll map your headcount against real risk, then price the exact add-on stack that fits.
