Endpoint detection and response — the tooling that watches every laptop and server for attacker behavior. List prices per endpoint per year:
| Entry | Full tier | Notes | |
|---|---|---|---|
| Microsoft Defender for Endpoint | P1 ~$36/yr | P2 ~$62/yr | often already in Microsoft 365 E5 |
| CrowdStrike Falcon | Go ~$60/yr | Pro ~$185/yr (Enterprise higher) | the analyst favorite; strong managed-hunting add-ons |
| SentinelOne Singularity | Core ~$70/yr | Complete ~$180/yr (list; ~$135–153 negotiated) | autonomous rollback, strong at mid-market |
The three are genuinely close on detection efficacy — all post near-perfect scores in independent MITRE ATT&CK evaluations. The decision is about price, ecosystem and operations.
Microsoft Defender for Endpoint is the cheapest by list, and if you're on Microsoft 365 E5 it's already included — no new contract. Plan 2 at roughly $62/endpoint/year is a strong baseline, and integration with the rest of the Microsoft security stack (Sentinel, Entra, Purview) is the tightest. The knock is that it's most effective when your whole environment is Microsoft.
CrowdStrike Falcon is the one security teams reach for first — the cleanest console, the best threat intelligence, and the Falcon OverWatch managed-hunting service if you want humans watching your environment 24/7. Pro is around $185/endpoint/year; the Go tier at ~$60 is aimed at small business but limited.
SentinelOne competes hard at mid-market with autonomous response — it can roll an endpoint back to its pre-attack state automatically — and negotiated pricing often lands 15–25% under list.
Already on M365 E5: Defender, it's paid for. Want the best analyst experience and managed hunting: CrowdStrike. Mid-market wanting autonomous rollback and room to negotiate: SentinelOne.