This post has been updated and refreshed on June 4th, 2026
Key Takeaways
- E5 adds meaningful security capabilities that E3 does not include: Defender for Endpoint Plan 2, Identity, and Cloud Apps, risk-based Conditional Access, and one-year audit log retention.
- E7, generally available as of May 1, 2026, bundles E5 with Microsoft 365 Copilot, Agent 365, and the full Microsoft Entra Suite, representing roughly 15% savings over buying those components separately and introducing a governance layer specifically designed for AI agents.
- The upgrade to E5 or E7 is worth it if the features you are paying for address threats targeting your environment. Many organizations upgrade without that clarity and underuse what they paid for.
- Before committing to any tier change, audit what you are already licensed for and what is actively configured. Closing configuration gaps in your current stack often reduces risk.
Microsoft's licensing structure for enterprise security has changed more in the past six months than it did in the previous decade. E7, branded the Frontier Suite, became generally available on May 1, 2026, and represents the first new enterprise tier since E5 launched in 2015. Furthermore, the bundling logic around Copilot for Security has shifted considerably.
Are you interested in upgrading? The decision is no longer just E3 versus E5. For many security leaders, the question is now whether E7's agent governance and expanded identity capabilities are right for their environment.
This guide breaks down what each tier actually includes from a security perspective, puts the three tiers side by side, and provides a practical framework for deciding which path fits your environment.
What E3, E5, and E7 Each Include: A Security Feature Breakdown

The security capabilities across the three tiers build on each other incrementally, so it helps to understand what each layer adds before trying to evaluate them comparatively.
E3 is the productivity and baseline security foundation. It includes Defender for Office 365 Plan 1, covering Safe Attachments, Safe Links, and basic anti-phishing. On the endpoint side, Defender for Endpoint Plan 1 covers attack surface reduction and antivirus. Identity gets Entra ID Plan 1, which provides Conditional Access and baseline MFA enforcement. Audit logs are retained for 180 days. E3 is a capable starting point, but it leaves meaningful gaps in endpoint detection, identity risk management, and cloud app visibility.
E5 closes most of those gaps. Defender for Office 365 advances to Plan 2, adding Threat Explorer, automated investigation and response, and Attack Simulation Training. Defender for Endpoint moves to Plan 2, adding full EDR, behavioral AI-based detection, and proactive threat hunting. Identity gets Entra ID Plan 2, replacing static Conditional Access policies with risk-based ones that respond dynamically to threat signals, and adding Privileged Identity Management and access reviews. Defender for Identity and Defender for Cloud Apps, both absent in E3, are included. Audit log retention extends to one year. For organizations facing credential-based attacks, limited endpoint visibility, or unsanctioned SaaS usage, E5 addresses all three.
E7 does not significantly expand the security stack beyond E5. The Defender suite, Purview, and Intune capabilities that define E5's security posture carry over unchanged. What E7 adds is built around two distinct needs that E5 was not designed for: governing AI agents and extending identity infrastructure beyond what Entra ID Plan 2 covers.
The full Microsoft Entra Suite in E7 goes further than Plan 2 by adding Internet Access, Private Access, ID Governance, and verified credentials. This applies a Zero Trust framework not just to users, but to apps, data, and AI agents as your AI footprint expands. For organizations actively replacing legacy VPN with Zero Trust Network Access or rolling out lifecycle governance workflows, the Entra Suite consolidates capabilities that would otherwise require separate procurement.
Agent 365 is the component that most distinguishes E7. It is a governance and security control plane, not a tool for building or running AI agents. It gives IT and security administrators visibility over the agents operating across the organization through Entra, Purview, and Defender, enforcing policy over agents the same way existing tools enforce policy over human users. As autonomous agents proliferate in enterprise environments, they access data, invoke tools, and operate at machine speed. Without a governance layer, that activity is invisible to the controls your security team depends on.
Microsoft 365 Copilot is also included natively in E7, where it requires a separate add-on purchase at E3 or E5. Work IQ, the intelligence layer underpinning Copilot in E7, uses signals across email, meetings, documents, and collaboration to ground AI outputs in organizational context.
At a Glance: E3, E5, E7
How to Decide: E3, E5, or E7

The right tier depends on which threats are actually hitting your organization, which controls are actively protecting it, and where the gaps between those two things are largest. Working through the following questions tends to surface the answer more cleanly than evaluating feature lists in isolation.
If you are on E3 and evaluating a move to E5, the case is clearest when credential-based attacks are a demonstrated pattern, when endpoint visibility gaps have contributed to incidents or near-misses, or when SaaS sprawl is creating blind spots your current stack cannot see into. Identity remains one of the most targeted attack surfaces in enterprise environments, and the gap between Entra ID Plan 1 and Plan 2 is substantial enough that organizations dealing with account compromise should treat it as a priority. For organizations that need E5's security capabilities but not its compliance, voice, or analytics features, the E5 Security add-on for E3 customers is a more targeted procurement path that avoids a full license upgrade across all users.
If you are on E5 and evaluating a move to E7, the case is strongest when three things are true at once: Copilot is already deployed or clearly on the near-term roadmap, AI agents are being used at meaningful scale and require governance, and Zero Trust network access or ID Governance are active priorities. If Copilot is already a separate line item, E7's bundled pricing simplifies the renewal math and may actually represent savings depending on how Entra Suite components were being procured. If only one of those conditions applies, building toward E7 incrementally through targeted add-ons is usually the more defensible path.
The Risk That Follows You Across Every Tier: Configuration Drift
Whatever tier your organization is on or is moving toward, licensed capability and active protection are not the same thing. This distinction matters as much at E7 as it does at E3.
Research from Reach shows that the gap between what organizations have licensed and what is actually configured and working is one of the most consistent patterns across mature security stacks. Among 250 cybersecurity professionals surveyed, 97% reported their organization had either a confirmed breach or a near miss in the past year because of a security tool misconfiguration. The average organization is running 35 different cybersecurity tools, and popular security products are updated approximately 20 times per year, meaning a typical enterprise deals with roughly 700 new features or updates across its stack annually. Controls drift. Policies get changed by a cross-functional team. Exceptions get made and forgotten. A product update ships and a setting changes with it. No alarm goes off.
This is not a reason to stay on a lower tier. It is a reason to treat configuration and exposure management as a prerequisite for every upgrade decision rather than something to address after the contract is signed. Copilot for Security and Agent 365 are only as useful as the telemetry feeding them. If your Defender deployment has coverage gaps or policy drift, those gaps limit what any governance layer above them can surface. Addressing misconfiguration issues before expanding your licensing footprint is consistently the higher-leverage move.
How Reach Helps You Make This Decision With Confidence
The E3, E5, and E7 decision has real consequences for security posture and for budget, and the arrival of E7 does have added cost and governance considerations that makes getting it right more important than before. The organizations that get it right are not the ones with the most thorough feature-list analysis. They are the ones who know, with specificity, which threats are targeting their environment and which controls are actually protecting it.
Reach helps security teams answer the upgrade question with data. By ingesting telemetry from your environment, Reach assesses current control coverage and configuration status, surfaces where specific capabilities like Threat Explorer, risk-based Conditional Access, or Agent 365 governance would apply to the exposures you are already facing, and makes the case for or against each tier change visible before any budget is committed. Learn more at this webpage.
FAQs: Microsoft E3 vs. E5 vs. E7 for Security
I'm on E3 and trying to decide between jumping to E5 or going straight to E7. How should I think about this? Almost every organization on E3 that is seriously evaluating security improvements should land on E5 first. The security additions in E5 over E3 are substantial and address threat categories that are actively targeting most enterprise environments. E7's additions over E5 are meaningful but you should consider if they address your environment’s specific use cases, most notably agent governance and expanded identity infrastructure. If your organization is not yet actively deploying AI agents at scale or doesn't have near-term Zero Trust network access requirements, you may want to consider E5's capabilities first. Or perhaps, get E5 configured and working before considering E7.
What is Agent 365, and why does it matter for security? Agent 365 is a governance and security control plane for AI agents — not a tool for building or running them. It extends the same Entra, Purview, and Defender controls that govern human users to cover AI agents as well, giving security teams visibility into what agents are accessing, what actions they are taking, and whether policy is being enforced. As organizations move from AI pilots into operational deployments, that governance layer becomes a security requirement, not a nice-to-have.
How does Reach support Microsoft licensing decisions? Reach maps active threats in your environment against your current control coverage, making the upgrade decision evidence-based rather than assumption-based. If you are heading into a renewal conversation and want data to back the call, that is exactly where Reach is useful. Start at this webpage.
What you should do next...
1. Want to go deeper? Explore case studies, whitepapers, research reports, and more in the Reach Resource Center.
2. See what Gartner is saying. Reach was recognized in the Gartner Emerging Tech Report on Domain-Specific Language Models for SecOps. Read the report to see why the analyst community is paying attention.
3. Ready to see Reach in action?Request a demo and see exactly where your security controls have drifted, what's underutilized, and where you're most exposed.












