Microsoft Defender for Endpoint Plan 1 (P1) provides the foundational layer of endpoint protection for organisations that need more than built-in antivirus but are not yet ready for full EDR capabilities. It focuses on prevention — reducing the attack surface and blocking threats before they execute — rather than detection and response after the fact.
What’s Included
- Next-generation antivirus — Cloud-delivered protection with real-time behavioural monitoring, machine learning detection, and automatic updates. Covers Windows, macOS, iOS, and Android.
- Attack Surface Reduction (ASR) rules — 16+ rules that block specific attack techniques at the OS level: blocking Office apps from spawning child processes, preventing credential theft, blocking untrusted executables from USB drives, and blocking JavaScript/VBScript from launching downloaded content.
- Device control — Manage which USB devices and removable media can be used on corporate devices. Block unauthorised USB drives while allowing approved devices by vendor ID, device ID, or device class.
- Web protection — Block access to phishing sites, malware distribution sites, and other malicious web content based on Microsoft’s threat intelligence. Works even when devices are off the corporate network.
- Network protection — Block outbound connections from all processes to malicious IP addresses and domains — not just browsers. Catches malware that uses PowerShell or other tools to call home.
- Controlled folder access — Protect files in designated folders (Documents, Desktop, Pictures) from unauthorised changes by ransomware or other malicious processes.
- Windows Firewall management — Centralised firewall policy management via Microsoft Intune or Group Policy.
- Microsoft 365 Defender portal — View alerts, device inventory, and security recommendations at security.microsoft.com.
P1 vs. P2
- P1 focuses on prevention — stop attacks before they run
- P2 adds detection and response — EDR, automated investigation, threat hunting, and Microsoft Threat Experts
- Upgrade to P2 if you need to investigate incidents after they occur or want automated remediation
Ideal For
Organisations that want strong preventive endpoint security beyond basic antivirus — USB control, ASR rules, and web protection — without the cost and complexity of a full EDR solution. A good starting point for companies building their security programme.
Keys Locker CSP Guarantee
- Genuine Microsoft CSP licence — provisioned directly through the official Microsoft partner channel
- 99.9% uptime SLA — Microsoft-backed service level agreement for all Microsoft 365 services
- Instant provisioning — subscription activated within minutes of payment confirming
- 7-day money-back guarantee — full refund if not provisioned or unused within 7 days
- Flexible cancellation — cancel monthly plans anytime; annual plans cancel at end of term
- 24/7 partner support — our team escalates issues directly to Microsoft on your behalf
- Scale up or down anytime — add or remove seats mid-cycle with no penalty




