Skip to main content
This capability matrix details which ContraForce features are available for Microsoft Defender for Endpoint based on your Microsoft 365 license tier. Use this reference to understand what capabilities you can leverage and what dependencies may apply.
This matrix only covers the Microsoft Defender for Endpoint module capabilities.

Understanding the Matrix

Legend

License Tiers

Business Premium

Small/medium business license with Defender for Business

Enterprise E3

Enterprise license with Defender for Endpoint P1

Enterprise E5

Full enterprise license with Defender for Endpoint P2

Incident Investigation

Core capabilities for investigating security incidents detected by Microsoft Defender for Endpoint.

Incident Management

All core incident management features are available across all license tiers. ContraForce provides full incident visibility regardless of your Microsoft 365 license.

Entity Enrichment & Triage

Capabilities for enriching entity data and correlating related incidents during investigation.

User Insights

(1) User insights require Microsoft Entra ID to be connected to ContraForce. Consent the appropriate enterprise applications during onboarding.

IP Address Insights

(2) IP sign-in activity requires Microsoft Sentinel connection (XDR + SIEM module).(3) Some IP insights require Defender for Endpoint Plan 2 on Business Premium and E3.

Device Insights

(3) Device timeline and related incidents require Defender for Endpoint Plan 2 add-on for Business Premium and E3 licenses.

Email Insights

File Insights

URL Insights


Advanced hunting and log query capabilities.
Log search requires Defender for Endpoint Plan 2 for Business Premium and E3 licenses. E5 includes this capability natively.

Endpoint Management

Capabilities for managing and monitoring endpoints through ContraForce.
All endpoint visibility features are available across all license tiers. ContraForce surfaces all devices managed by Defender for Endpoint.

Gamebook Response Actions

Automated response capabilities organized by entity type.

Endpoint Actions

Endpoint Gamebook actions require the Gamebooks for Microsoft Defender for Endpoint enterprise application to be consented.

File Actions

User Actions

(1) User Gamebook actions require Microsoft Entra ID connection and the Gamebooks for Identity enterprise application.

IP Address Actions

IP blocking via Azure Network Security Groups is planned for future release.

Email Actions

(4) Email actions require a Microsoft 365 Exchange license and the Microsoft 365 Response enterprise application.

Dependencies Reference

Dependency (1): Microsoft Entra ID

Required for: User insights, User Gamebook actions How to enable:
  1. During onboarding, consent the ContraForce enterprise applications
  2. The Gamebooks for Identity service principal must be consented for user response actions
Enterprise Applications:
  • ContraForce API
  • ContraForce Portal
  • Gamebooks for Identity

Dependency (2): Microsoft Sentinel

Required for: IP sign-in activity How to enable:
  1. Deploy the XDR + SIEM module instead of XDR-only
  2. Connect your Sentinel workspace during onboarding

Sentinel Onboarding

Complete Sentinel onboarding guide

Dependency (3): Defender for Endpoint Plan 2

Required for: Device timeline, IP/Email/URL detailed insights, Log search How to enable:
  • E5 licenses include Plan 2 natively
  • Business Premium and E3 require the Defender for Endpoint Plan 2 add-on
License options:

Dependency (4): Microsoft 365 Exchange

Required for: Email Gamebook actions (soft delete) How to enable:
  1. Ensure users have Exchange Online licenses
  2. Consent the Microsoft 365 Response enterprise application

M365 Response Application

Microsoft 365 Response enterprise application details

Complete Capability Summary

By License Tier

Full capabilities:
  • All incident management features
  • Endpoint management (view devices)
  • All endpoint Gamebook actions
  • File quarantine
  • Basic entity insights
With Entra ID:
  • User insights (sign-in, audit, profile)
  • User Gamebook actions
With Exchange:
  • Email soft delete
Requires Plan 2 add-on:
  • Device timeline
  • Advanced log search
  • Detailed IP/Email/URL insights

Quick Reference by Feature Area


Maximizing Your Capabilities

User insights and user Gamebook actions are essential for identity-based investigations. Ensure you consent all identity-related enterprise applications during onboarding.
If you frequently need device timelines, advanced hunting, or detailed entity insights, the Defender for Endpoint Plan 2 capabilities are worth the investment.
The XDR + SIEM module adds Sentinel incidents, advanced threat hunting, CMS, and IP sign-in insights. Consider upgrading if you use Sentinel.

XDR Onboarding

Deploy the Defender module

Enterprise Applications

All service principals and permissions

Gamebooks

Response action capabilities

Questions about capabilities or licensing? Contact us at support@contraforce.com.