Defend continuously with Project Perception
Bring security data, tools, and workflows together in an agentic system that helps your team find, investigate, and respond to risk at machine speed.
Secure from end to end
Safeguard your AI, clouds, apps, data, devices, and identities.
Get powerful protection with security agents that defend with speed, scale, and intelligence.
Drive innovation by strengthening AI environments with security and governance across your apps, agents, platforms, and clouds.
Multiply your teams’ productivity and accuracy with agents that use unified graph analytics and 100 trillion daily signals to surface threats early and guide precise responses.
Simplify your security operations with seamless end-to-end protection that cuts costs and increases productivity.1
Comprehensive, cost-effective security
Built to support your Zero Trust strategy.
Empower teams to manage and protect at the speed and scale of AI.
Detect and respond to attacks against your devices, identities, apps, email, and clouds with leading extended detection and response (XDR) products.
Run a faster, leaner SOC with a cloud-native SIEM built for AI. Detect threats across your entire environment, investigate incidents in minutes, and cut SIEM costs with a built-in data lake, without adding tools or analysts.
An AI-ready platform that delivers industry-leading security information, unified data lake, enriched graph-powered visibility, and a collection of intelligent reasoning tools.
Verify every identity and access request across your clouds, platforms, and devices with a collection of identity and access products.
Safeguard data wherever it lives with a collection of unified information protection, governance, and compliance products.
Strengthen device security and enable seamless hybrid work experiences with endpoint management products.
Outpace cyberattackers with the speed and scale of industry-leading generative AI.
Gain visibility and disrupt attacks across your multicloud, multiplatform environment with unified SecOps in Defender.
Foster AI innovation and safeguard data with a solution that unifies data security and governance.
Securely connect all of your users, apps, and devices with a complete identity solution.
Safeguard all of your apps and resources with complete visibility and comprehensive protection across workloads.
Prevent, investigate, and remediate risks across your organization with adaptive solutions.
Comprehensive expert-led services to help defend against threats, build cyber resilience, and modernize security operations.
Stop attackers with always-on, AI-accelerated managed extended detection and response that’s expert-led and natively integrated in Microsoft Defender.
Stay ahead of emerging cyberthreats with around-the clock, AI-powered threat hunting across endpoints, identities, emails, cloud apps, and cloud workloads.
Your first call before, during, and after a cybersecurity incident.
What is Project Perception and how do its agents divide the work?
A coordinated system of security agents, newly announced in Microsoft’s July 2026 security roundup. They work as a team rather than as separate tools.
The division is by job. Red goes looking for weaknesses, blue investigates what turns up, green hardens it. The loops run continuously rather than as one pass.
How Microsoft states it
Project Perception, newly announced, is a coordinated system of specialized agents, cybersecurity-focused models, and enterprise-wide signals that transform how security operates. These multi-agent autonomous workflows work as a team to operate in continuous loops to execute end-to-end security workflows.
The agents work as a team
Governing the agents themselves is a separate job. That sits in Agent 365, further down this page. The wider picture of using AI safely is on Microsoft AI.
How do Microsoft 365 E3, E5 and E7 differ on security?
All three plans carry Entra ID, Intune Plan 1, Defender for Endpoint, Defender for Office 365 plus Purview. What moves is the plan level. E3 is the foundation you bolt suites onto, E5 folds those suites in, E7 takes the same controls out to the agents.
The split matters most on identity. E3 gets Microsoft Entra ID (P1). E5 and E7 get Microsoft Entra ID (P2) capabilities, which is where risk detection lives. E7 is the only one of the three that ships the Microsoft Entra Suite in the box.
| Identity and access | Microsoft Entra ID (P1) on E3. Microsoft Entra ID (P2) capabilities on E5 and E7, plus the Microsoft Entra Suite on E7. |
|---|---|
| Endpoint security | Microsoft Defender for Endpoint (P1) on E3, (P2) on E5 and E7. |
| Email and collaboration | Microsoft Defender for Office 365 (P1) on E3, (P2) on E5 and E7. |
| First appears on E5 | Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Microsoft Defender for IoT, Microsoft Purview Insider Risk Management, Microsoft Purview Communication Compliance. |
| First appears on E7 | Agent 365, Microsoft Entra Suite, Azure Virtual Desktop. |
The Intune advanced endpoint management capabilities moved between plans on July 1, 2026, so they sit in the FAQ rather than this table.
How Microsoft puts the E7 case
Microsoft 365 E7 extends the security value of Microsoft 365 E5 by protecting and governing AI agents at scale. While Microsoft 365 E5 secures identities, endpoints, and data for the human workforce, Microsoft 365 E7 adds advanced identity governance and security controls for Copilot and AI agents. This gives organizations the visibility, control, and guardrails needed as AI becomes embedded across work, ensuring AI can be used confidently without introducing new security or compliance risks.
Plan detail sits on the individual pages: Microsoft 365 E3, Microsoft 365 E5 and Microsoft 365 E7. The endpoint side is the part that moved most recently, so start with Microsoft Intune advanced capabilities and licensing. Ask for a quote to see two tiers costed side by side.
What is Microsoft Agent 365 and which admins run it?
The control plane for agents. Microsoft 365 E7 is the enterprise plan that includes it.
It does not invent a new admin surface. Agent work lands on roles the tenant already has, which is the part worth checking before anyone plans a rollout.
How Microsoft states it
Agent 365 is the control plane to observe, secure, and govern AI agents, enabling organizations to extend their existing infrastructure for users to agents with purpose-built capabilities tailored for agent needs.
Agent 365 aligns agent administration to four core responsibilities
The plan that carries it is Microsoft 365 E7, on top of everything in E5.
What does the Microsoft Entra Suite add?
Network access controls alongside the identity ones. Microsoft 365 E7 includes it. On E3 or E5 it is an add-on.
Check the prerequisite first. Microsoft Entra Suite requires Microsoft Entra ID P1 or a plan that includes Microsoft Entra ID P1. Special pricing is available for Microsoft Entra ID P2 and Microsoft 365 E5 customers.
How Microsoft states it
The Microsoft Entra Suite is designed to deliver unified Zero Trust user access, enabling your employees to securely access any cloud and on-premises application with least privilege access, across public and private networks inside and outside your corporate perimeter. With a unique combination of deeply integrated Secure Access Service Edge (SASE), identity governance, identity protection and verification products, the Microsoft Entra Suite helps security teams accelerate their Zero Trust security strategy by unifying identity and network access controls.
What is in it
On the plan side it is bundled into Microsoft 365 E7. Ask for a quote if you want it priced against an E5 tenant.
Do Microsoft 365 E5 and E7 include Security Copilot capacity?
Yes. Both plans come with monthly Security Compute Units at no extra cost, sized against paid user licenses. Worth knowing before anyone buys capacity separately.
| Plans | Microsoft 365 E5 and Microsoft 365 E7 |
|---|---|
| Monthly entitlement | 400 Security Compute Units (SCUs) for every 1,000 paid user licenses at no additional cost each month |
| Monthly ceiling | up to 10,000 SCUs per month |
What the capacity is for
Detect, investigate, and respond faster in Microsoft Defender, Entra, Intune, and Purview with agentic AI in Security Copilot.
Plan pages: Microsoft 365 E5 and Microsoft 365 E7. Ask for a quote if you are sizing SCUs against a real headcount.
What does the Data Security Triage Agent do?
It reads the signals behind a data-risk incident and pushes the ones worth a human to the front. Its advanced AI reasoning layer is generally available.
It works inside Microsoft Purview Insider Risk Management. The analysis runs in multiple steps across user, device plus data activity before anything reaches an analyst, so what lands in the queue is the set most likely to need investigating.
How Microsoft states it
The Data Security Triage Agent includes an advanced AI reasoning layer, now generally available, that performs deeper, multi-step analysis across user, device, and data activity signals to surface the incidents most likely to require investigation while reducing noise.
What an analyst can do with it
On the licensing side, Microsoft Purview Insider Risk Management first appears on Microsoft 365 E5 in the plan table above. Ask for a quote if you want it costed against your tenant.
A recognized security leader
A Leader in five Gartner® Magic Quadrant™ reports.2
A Leader in two Forrester Wave™ categories.3
A Leader in four IDC MarketScape reports.4
1. New Technology: The Projected Total Economic Impact™ Of Microsoft Security Copilot, A Forrester New Technology Projected Total Economic Impact Study. Commissioned by Microsoft, November 2024.
2. GARTNER is a registered trademark and service mark of Gartner, Inc. and/or its affiliates in the U.S. and internationally, and MAGIC QUADRANT is a registered trademark of Gartner, Inc. and/or its affiliates and are used herein with permission. All rights reserved. Gartner does not endorse any vendor, product or service depicted in its research publications and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner research publications consist of the opinions of Gartner’s Research & Advisory organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this research, including any warranties of merchantability or fitness for a particular purpose. Gartner, Magic Quadrant for Endpoint Protection Platforms, Evgeny Mirolyubov, Franz Hinner, Deepak Mishra, 14 July 2025. Gartner, Magic Quadrant for Access Management, Brian Guthrie, Nathan Harris, Yemi Davies, Steve Wessels, Published 11 November 2025. Gartner, Magic Quadrant for Security Information and Event Management, By Andrew Davies, Eric Ahlm, Angel Berrios, Darren Livingstone, 8 October 2025. Gartner, Magic Quadrant for CPS Protection Platforms, By Katell Thielemann, Wam Voster, Ruggero Contu, 12 February 2025.
3. Forrester, Forrester Wave, and The Total Economic Impact™ are trademarks of Forrester Research, Inc.
4. IDC MarketScape: Worldwide Unified Endpoint Management Software 2024 Vendor Assessment, doc #US51234224, April 2024. IDC MarketShare: Worldwide Modern Endpoint Security Market Shares, 2024, doc #US53349725e, May 2025.
Frequently asked questions
Microsoft 365 E3 includes Microsoft Entra ID P1, which provides core identity and access management capabilities such as single sign-on, multifactor authentication, Conditional Access, and more.
Microsoft 365 E5 includes Microsoft Entra ID P2, which offers comprehensive identity protection and risk detection, adaptive risk-based access controls, and privileged access for critical resources.
As of July 1, 2026, the capabilities of the Microsoft Intune Suite are included in Microsoft 365 E5, with select capabilities also available in Microsoft 365 E3, bringing advanced endpoint management to more organizations without added cost.
Microsoft’s packaging table lists Intune Remote Help, Intune Advanced Analytics and Intune Plan 2 among the Microsoft 365 E3 feature additions. For Microsoft 365 E5 it lists, in addition to the Microsoft 365 E3 additions: Microsoft Security Copilot, Intune Endpoint Privilege Management, Microsoft Cloud PKI, Intune Enterprise Application Management.
Both Intune Plan 2 and advanced endpoint management add-ons listed require Intune Plan 1 or a plan that includes Intune Plan 1 such as Microsoft 365 E3, Microsoft 365 E5, Microsoft 365 E7, and Microsoft Business Premium.
Configure devices: push settings, restrictions, and platform templates to devices with configuration profiles and the settings catalog.
Protect apps and data: safeguard corporate data with app protection policies, conditional launch rules, and mobile application management for managed and unmanaged devices.
Monitor and troubleshoot: track device health, compliance trends, and app deployment status with built-in reports and Endpoint Analytics.
Develop and automate: use Microsoft Graph APIs, PowerShell, and the Intune Data Warehouse to automate management tasks and build custom integrations. The tools Microsoft documents for this are Device query, Microsoft Graph for Intune, Graph Explorer and Microsoft Graph PowerShell.
Services that integrate with Intune include Configuration Manager and co-management, Microsoft Entra ID, Microsoft Defender for Endpoint, Windows Autopatch plus Windows 365.
Microsoft 365 E3 and E5 licenses include management and protection for up to 15 devices enrolled in Microsoft Intune.
Microsoft Defender for Endpoint licenses include protection for up to 5 devices per user license. This does not include servers, which must be licensed separately.
Tenant governance helps organizations discover, manage, and govern tenants across their environment with centralized policies and cross-tenant delegated administration.
Microsoft Entra ID is making passkeys the default authentication experience, which helps reduce reliance on SMS and voice, strengthens phishing-resistant security, and makes for an easier transition away from Microsoft-provided telecom delivery, which will retire in 2027.
Through new interconnected Entra and Defender experiences, identity and access management and SOC teams share user experience, RBAC, and agentic workflows that eliminate product seams so identity and security operations can work together.
Microsoft Defender for Office 365 provides comprehensive protection against email-based threats, as well as security for your collaboration tools including Microsoft Teams, SharePoint, and OneDrive.
Microsoft Purview now integrates with Microsoft Entra Internet Access to extend data security to the network layer, enabling real-time protection of sensitive data shared with unmanaged cloud and AI apps over the network.
For example, when an employee attempts to upload sensitive customer data or proprietary information, including text and files, into shadow AI apps, sharing is detected and blocked before the data is leaked from the organization.
A new Microsoft Purview Data Loss Prevention (DLP) for Microsoft 365 Copilot protection, available in preview, now gives data security teams greater control over how Copilot leverages email content, given external sources can introduce sensitive, third-party, or unvetted information that organizations may not want to rely on.
Now admins can exclude emails from external senders from being referenced, summarized, or used as grounding data for Copilot.
Cloud Security Posture Management extends coverage to serverless containers, giving teams visibility and continuous posture assessment across containerized workloads running on Azure Container Apps, Azure Container Instances, and Amazon Web Services Elastic Container Service (AWS ECS) on Fargate.
Ask us for a quote if you want any of it costed against your tenant.
What we do alongside the licence
SoftSolutionWorks.com is backed by BlueAlly, an authorized Microsoft reseller. As well as supplying the licences, we can help you choose the plan, deploy it, and finance it.