The endpoint decision
- Inventory the actual laptops, desktops, servers and supported mobile devices before counting licenses.
- Confirm updates, encryption, protection coverage, alert routing and response authority.
- Check existing entitlements: Defender for Business is included with Microsoft 365 Business Premium.
- Buy EDR or managed response only for an unmet capability that someone can operate.
Last updated: September 24, 2026
Endpoint security is more than an antivirus subscription. A device can be unprotected because it is missing from the inventory, its agent is unhealthy, its operating system is unsupported or nobody reads the alert. CISA's StopRansomware Guide combines hardening, backups and response. Use this guide to find the operational gap first, then the endpoint shortlist for plan research.
What EPP, EDR and MDR solve
| Capability | What it provides | What it does not replace |
|---|---|---|
| Endpoint protection platform (EPP) | Prevention and policy on covered devices | Updates, identity controls or backup |
| Endpoint detection and response (EDR) | Device telemetry, investigation and containment tools | A responder who reviews and acts on alerts |
| Managed detection and response (MDR) | A contracted team to monitor and respond within agreed scope | Your authority, asset inventory and incident decisions |
Vendors package these features differently, so compare exact editions and service hours. A 24/7 claim needs a contract, coverage boundary and escalation process. Do not assume a product will isolate a device automatically or that doing so is safe for a critical business system.
Audit the fleet and what you already own
Export all managed devices and compare with staff, purchase records and remote-access logs. Flag unsupported operating systems, missing protection, failed updates and devices that have not checked in. Check the exact Microsoft 365 edition: Microsoft states that Defender for Business is included in Business Premium. Validate onboarding, policy assignment, alerts and any server or mobile licensing separately; inclusion on a plan page is not proof of deployment.
For an existing non-Microsoft stack, perform the same test. A well-operated current agent may be preferable to a new console. The Microsoft Defender for Business review, ThreatDown review and endpoint shortlist explain selected-plan considerations where available. Verify the current plan and destination before purchase.
Pilot response, not just detection
Choose representative devices and one test alert approved by your IT provider. Verify the alert reaches a named person, the responder can identify the device and user, and the team knows who may isolate it. Test off-hours escalation and document a rollback for accidental isolation. Run an update and unhealthy-agent scenario. Record the false-positive support burden as well as technical results.
| Pass/fail check | Evidence |
|---|---|
| Every in-scope device appears in inventory | Device export reconciled with staff/asset list |
| Policy and agent are healthy | Console report and sample device check |
| High-priority alert reaches a responder | Test ticket, timestamp and decision |
| Containment authority is clear | Runbook and approved pilot exercise |
| Recovery remains possible | Backup/restore test for critical data |
A practical 30/60/90-day rollout
In the first 30 days, reconcile inventory, remove unsupported devices from sensitive access where necessary and appoint an alert owner. By day 60, address coverage and update exceptions and complete a response pilot. By day 90, review unresolved devices, tune alerts, test a restore and agree on a monthly owner report. Link this to the 90-day security roadmap and incident-response plan.
Purchase only for the remaining gap
Write down the unsupported platform, detection or service-hour need that the current subscription cannot meet. Compare its license unit, minimum quantity, deployment support and renewal terms—not a generic per-employee estimate.
Sources checked September 24, 2026: CISA StopRansomware Guide, Microsoft Defender for Business overview, and NIST SP 1300. No hands-on EDR performance or product price is claimed here.