EPP and EDR answer different questions. Most buyers purchase one believing they bought both.

Prevention stops what it recognises. Detection and response records what got through so a person can find it and act — and without that person, the EDR console is the most expensive dashboard nobody opens.

Microsoft 365 E3 includes Defender for Endpoint Plan 1 — prevention only. The EDR is Plan 2, and that is in E5. Check the SKU before assuming you own detection.

Already decided — before the detection-rate chart

Who will triage alertsset by headcount, before any demo
Microsoft 365 tier you holdE3 is P1; E5 is P2
Agents already on the machineUEM, RMM, backup — one real-time engine

Still yours to weigh

Prevention or responseEPP tier, or EDR tier
Rollback or containmenthow you get files back
Managed, or run it yourselfthe contract is the larger half
If you’ve never bought one

What endpoint protection actually is

An agent on every laptop, desktop, server and (usually) phone that does two jobs. The first is prevention: block known malware, exploits and ransomware behaviour before they run — the antivirus lineage, now machine-learning and behaviour-based. The second is detection and response: record process, file, network and identity events continuously, raise what looks wrong, and give a person the tools to investigate and act — isolate the machine, kill the process, roll files back, hunt across the estate.

The first job runs itself. The second does not — it produces alerts, and alerts need someone with time and skill to read them. That is why every vendor on this page also sells people: a managed detection and response service that runs the console for you. Whether you need the second job, and who will do it, decides this purchase more than any detection-rate chart.

The honest cut

EDR without someone to triage it is shelfware with a licence fee. If nobody on your side will open the console daily, buy the managed tier or stay with prevention — and say so in the evaluation, because the vendor’s demo will not.

EPP vs EDR vs XDR vs MDR — the sharpest confusion in the category

EPP prevents. EDR records and lets a person respond. XDR widens the recording to email, identity, cloud and network. MDR is not software — it is the vendor’s or a partner’s analysts running the EDR/XDR for you. Every product here sells the first two as tiers; most sell the fourth as a contract.

EPP vs UEM

UEM configures the device and proves its state; endpoint protection fights what is already on it. One enrols and encrypts; the other isolates and kills. A ransomware scare does not call for a UEM, and an unmanaged-device audit does not call for an EDR — the guides are here for both.

The fuller bench

This page ranks the nine endpoint-protection products carried in this category. TechBag also carries a deeper security bench — it will be ranked under the Security Operations cluster when that ships, and is linked here so nothing is hidden:

Often confused withUEM & MDM — configuring the fleet and proving its state →· RMM & Patch — the agent that deploys and watches your EDR →

The four routes of endpoint management — and which one is yours →

The narrowing instrument · the reasoning is the product

Narrow 9 products to your shortlist

Choose the constraints that are true for you. Products that fail one fade in place with the reason written on them; products we cannot verify for your case are marked and stay in. Every chip is reversible.

The six variables that decide it:Prevention vs response depthWho operates itAgent coexistenceRollback & remediationManaged optionPlatforms & hosting

Hosting

Commercial shape

Ransomware recovery

Platforms

Who runs it

Fleet size

Prevention-vs-EDR depth removes nothing as a chip — every vendor sells both tiers. It is the operating-capacity question, and it lives in the four-letters section and the reasoning below.

Still in9/ 9
CrowdStrike logo$59.99–184.99₹4,979

per device / year — Falcon Go (prevention) · Pro · Enterprise (EDR); Falcon Complete MDR on quote

Security teams that will run EDR properly — hunting, timeline, response — and want the reference cloud-native agent.

The catch: No automatic file rollback after ransomware (response is isolate, kill, Real Time Response); Falcon Complete MDR is enterprise-priced on quote; no on-prem console and no documented India data region.

EDR referencePublished listCloud-only
Intel page →
SentinelOne logo~$70–180₹5,809

per endpoint / year reseller list (Core · Control · Complete); street lower; Vigilance MDR add-on

Teams that want autonomous detection with a documented one-click rollback, and a Mumbai region for data residency.

The catch: No vendor-published list (reseller listings only; street price varies widely), no on-prem console, and the MDR (Vigilance) is a per-endpoint add-on on top of Complete.

File rollbackIndia region (Mumbai)Cloud-only
Intel page →
Microsoft logo$3 / $5.20₹249

per user / month standalone (P1 / P2); $0 marginal when bundled

Microsoft 365 shops — the EPP/EDR you may already hold, with the tightest Intune and Entra integration there is.

The catch: E3 carries only P1 (no EDR); file rollback is OneDrive Files Restore, not the agent; Defender Experts (managed) needs E5 and a quote; passive-mode coexistence is strong, but the console assumes a Microsoft estate.

P1 in Microsoft 365 E3; P2 in E5 / E5 Security; Defender for Business in Business PremiumIn a bundle you may ownPublished listCloud-only
Intel page →

per user / year — Advanced · with XDR · MDR (reported ~$48 XDR; MDR from ~$80); Mumbai region

Teams that want the managed service to be the default — Sophos MDR priced for mid-market — with CryptoGuard rollback underneath.

The catch: No published list (estimates only), no on-prem console, and CryptoGuard needs ~3 GB free disk and cannot roll back if the process is stopped after encryption completes.

File rollbackMDR-firstIndia region (Mumbai)
Intel page →
Bitdefender logo$57–96₹4,731

per device / year — Small Business · Business Security · Premium (EDR); MDR and Enterprise on quote

Price-sensitive mixed fleets wanting published per-device pricing, an on-prem console option and a real EDR tier.

The catch: First-year promotional pricing renews at standard rates (users report 2–3× at renewal); XDR and MDR are quote-only; India cloud region not documented.

File rollbackPublished listOn-prem console
Intel page →
ESET logo$42.20–57.54₹3,503

per device / year — Entry · Advanced · Complete; Elite (XDR, min 25) and MDR on quote

Lean teams wanting a light agent, published tiers, on-prem or cloud console, and Ransomware Remediation with a protected backup store.

The catch: XDR (ESET Inspect) only arrives at the Elite tier — quote-only, 25-device minimum — so the published prices buy EPP, not EDR; India cloud region not documented.

File rollbackPublished listOn-prem console
Intel page →
Xcitium logo$2.39–8.49₹198

per endpoint / month, modular and postpaid; OpenEDR free to 50 endpoints

Teams that want unknown files contained at the kernel before they can run — a different bet from detect-then-respond — at modular published prices.

The catch: Containment is the mechanism, not rollback: nothing to restore because nothing ran, but also no file-restore if something is allowed; on-prem option and India region not documented; scale above 2,000 unverified.

OpenEDR free to 50 endpointsContainmentPublished listFree tier
Intel page →
Seqrite logo₹500–1,500

per user / year, INR-native through partners (EPS Core → Total); EDR / XDR / MDR on quote

India-regulated estates that need CERT-In-empanelled, INR-billed, India-hosted or on-prem endpoint protection with local support.

The catch: Mobile is a separate product (mSuite), ransomware recovery is restore-from-its-own-backup rather than automatic rollback, and scale above 2,000 endpoints is claimed, not documented.

India-builtOn-prem / India DCINR list
Intel page →

per user / month, modular (historically ~$7.50–9.50; public list removed at the 2026 rebrand)

SMBs that want endpoint, email, cloud-app and posture in one modular agent with a managed option, and no SOC of their own.

The catch: Linux agent is remote scan-only (no real-time protection), no documented file rollback, no on-prem, public pricing withdrawn in 2026, and scale above 2,000 endpoints unverified.

SMB-firstModularCloud-only
Intel page →
Why each constraint rules out what it doesShow the reasoning ↓

On-prem management consoleRules out CrowdStrike Falcon, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint, Sophos Intercept X and Coro Endpoint & EDR — cloud-only console. That leaves Bitdefender GravityZone, ESET PROTECT, Xcitium (ZeroDwell) and Seqrite Endpoint Protection. It flags Xcitium (ZeroDwell) — On-prem option not documented either way — marked on the cards, not removed.

Vendor-published list priceRules out SentinelOne Singularity Endpoint, Sophos Intercept X, Seqrite Endpoint Protection and Coro Endpoint & EDR — quote-only (reseller listings at most). That leaves CrowdStrike Falcon, Microsoft Defender for Endpoint, Bitdefender GravityZone, ESET PROTECT and Xcitium (ZeroDwell).

Automatic file rollback after ransomwareRules out CrowdStrike Falcon, Microsoft Defender for Endpoint and Coro Endpoint & EDR — no documented automatic file rollback (response is isolate, kill, restore from your own backups). That leaves SentinelOne Singularity Endpoint, Sophos Intercept X, Bitdefender GravityZone, ESET PROTECT, Xcitium (ZeroDwell) and Seqrite Endpoint Protection. It flags Xcitium (ZeroDwell) — Prevents by containing unknown files before they run and Seqrite Endpoint Protection — Restores from its own ransomware backup rather than automatic rollback — marked on the cards, not removed.

Linux servers with real-time protectionRules out Coro Endpoint & EDR — Linux agent is remote scan-only, no real-time protection. That leaves CrowdStrike Falcon, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint, Sophos Intercept X, Bitdefender GravityZone, ESET PROTECT, Xcitium (ZeroDwell) and Seqrite Endpoint Protection.

Phones and tablets in the same consoleRules out Seqrite Endpoint Protection — mobile is a separate product (Seqrite mSuite). That leaves CrowdStrike Falcon, SentinelOne Singularity Endpoint, Microsoft Defender for Endpoint, Sophos Intercept X, Bitdefender GravityZone, ESET PROTECT, Xcitium (ZeroDwell) and Coro Endpoint & EDR.

Nobody to triage alertsRules nothing out on published terms. It flags CrowdStrike Falcon — Managed tier is enterprise-gated (quote / E5) and Microsoft Defender for Endpoint — Managed tier is enterprise-gated (quote / E5) — marked on the cards, not removed.

Above 2,000 endpointsRules nothing out on published terms. It flags Xcitium (ZeroDwell) — Unverified above 2,000 endpoints, Seqrite Endpoint Protection — Unverified above 2,000 endpoints and Coro Endpoint & EDR — Unverified above 2,000 endpoints — marked on the cards, not removed.

Prevention only, or full EDRRules nothing out on SKU lines: every vendor here sells a prevention-only tier and an EDR tier (Falcon Go → Enterprise; Singularity Core → Complete; Defender P1 → P2; Intercept X Advanced → with XDR; GravityZone Business → Premium; ESET Entry → Elite; Seqrite EPS → EDR; Xcitium and Coro by module). The cut is not which product — it is which tier, and whether anyone will open the EDR console. That is the operating-capacity question above.

India data residency in the cloudDocumented: SentinelOne (Mumbai), Sophos Central (Mumbai) and Seqrite (India data centres, on-prem). Not documented either way for the rest — so no chip, and no product is ruled out on it. Ask for the region in writing before you sign.

Coexisting with the agents you already runRules nothing out, but decides the rollout: on Windows, Microsoft Defender Antivirus drops to passive mode automatically when another engine registers, so a third-party EPP coexists with Defender for Endpoint's EDR telemetry; two third-party real-time engines do not coexist. RMMs (NinjaOne, Atera, TeamViewer, Splashtop) resell or integrate several of these — which means a second engine arrives unannounced if you are not watching.

Under 50 endpointsRules nothing out on published minimums — Xcitium OpenEDR is free to 50, ESET starts at 5 devices (Elite at 25), Defender for Business is sized to 300 users, Bitdefender and CrowdStrike Falcon Go sell in small packs. Which enterprise-tier SKUs are a poor fit at this size is delivery-team judgement: [TechBag to confirm].

Narrow to your situation

Eight situations, eight shortlists — with the operating question answered

Each shortlist states who will run it. If the answer is nobody, the shortlist changes — that is the point.

50–500 seats, no security team — someone else must watch it

Why: Managed detection priced for mid-market, sold with the agent by the same vendor; Sophos leads with MDR as the default product, Bitdefender and ESET sell MDR on top of published tiers.

The trade-off: MDR scope is endpoint-first — identity, email and cloud are separate services — and the contract, not the agent, is what you are buying. Coro is the all-in-one alternative if email and posture matter more than depth.

Microsoft 365 E5 (or E5 Security) already in place

Why: Defender for Endpoint P2 is already paid for; buying a second EDR duplicates it. On E3 you hold only P1 — prevention, no EDR — so the question becomes E5 Security versus a third-party EDR.

The trade-off: No file rollback in the agent, managed (Defender Experts) is a quote, and the console assumes Intune and Entra. One survivor here is the right answer, not a gap.

Ransomware-scarred — file rollback is the requirement

Why: Documented automatic rollback: SentinelOne (one-click, Windows), Sophos CryptoGuard (protected copies / VSS), ESET Ransomware Remediation (protected backup store). Bitdefender's Ransomware Mitigation qualifies too.

The trade-off: Rollback has limits — disk space (Sophos ~3 GB), Windows-first, and it restores files, not the breach. Xcitium's containment is the other bet: nothing to roll back because nothing ran.

A security team exists and wants to hunt

Why: Full EDR telemetry, advanced hunting, forensic timeline and scripted response; CrowdStrike and SentinelOne are the reference agents, Defender P2 is the Microsoft-estate equivalent.

The trade-off: Self-run EDR is a staffing decision: budget analysts or an MDR contract beside the licence. CrowdStrike has no file rollback; SentinelOne has no published list.

India-regulated — on-prem console or India data centre

Why: On-prem consoles (Seqrite, ESET PROTECT On-Prem, GravityZone virtual appliance), and Seqrite's India data centres with CERT-In empanelment and INR billing.

The trade-off: On-prem means you run the console server. If cloud with an India region is acceptable, SentinelOne (Mumbai) and Sophos Central (Mumbai) reopen the field.

Budget decides — published prices, no sales cycle

Why: ESET from $42.20 and Bitdefender from $57 per device per year on the vendors' own pages; Xcitium modular from $2.39 per endpoint per month and OpenEDR free to 50.

The trade-off: Published entry tiers are prevention-only; EDR costs more at every vendor (ESET's is Elite, quote). Bitdefender's first-year price renews higher — price the renewal, not the promotion.

SMB wanting one agent for endpoint, email, cloud apps and posture

Why: Coro's modular single agent covers endpoint, email, cloud-app and device posture with a managed option; Sophos Central and ESET PROTECT Complete bundle email and endpoint under one console.

The trade-off: Breadth over depth: Coro's Linux agent is scan-only and public pricing is gone; Sophos and ESET go deeper on the endpoint and lighter on the rest.

You already run a UEM and an RMM agent — adding a third

Why: Defender coexists natively (passive mode, EDR block mode) with whatever the UEM pushes; Xcitium documents EDR-on-top-of-Defender; SentinelOne, CrowdStrike and Bitdefender are the engines the RMMs (NinjaOne, Atera) deploy and watch.

The trade-off: Three agents is normal; two real-time engines is the failure. Document exclusions both ways and make the RMM deploy the EDR agent, never manage it.

The spine of the decision

Four letters, four different purchases

The same vendor sells all four. They are priced, staffed and audited differently — and the tier you sign is the one you operate, not the one in the demo.

EPP

Prevention

Blocks known malware, exploit techniques and ransomware behaviour at the endpoint. Runs itself; the console is for policy and reporting. Every vendor’s entry tier.

Who operates itNobody, daily

EDR

Detection & response

Continuous recording of process, file, network and identity events; alerts; a console to investigate, isolate, kill, hunt and — at some vendors — roll files back. Produces work.

Who operates itAn analyst, every day

XDR

Extended telemetry

EDR’s recording joined with email, identity, cloud and network signals so one incident is one story. More to see; more to staff. Useful when the other sources exist and someone correlates them.

Who operates itA team, or the vendor’s

MDR

People, not software

The vendor or a partner runs the EDR/XDR 24/7: triage, investigation, containment, a call at 3am. Scope is written in the contract — endpoint-first, often not identity or email, response means contain, rarely rebuild.

Who operates itThe vendor — read the scope
Recovery

“Rollback” is four mechanisms and one absence

Protected copy, then restore

Sophos CryptoGuard keeps a temporary copy when a business file is opened for write and restores it if the original is maliciously encrypted — from its copies or VSS; needs ~3 GB free and cannot act if the process is stopped only after encryption completes. ESET’s Ransomware Remediation keeps a protected backup store the attacker cannot modify (2-week retention by default).

Agent-level one-click rollback

SentinelOne restores encrypted files from its own snapshots on Windows in one action from the console; Bitdefender’s Ransomware Mitigation backs up and restores files touched by a detected attack.

Contain before it runs

Xcitium’s ZeroDwell virtualises unknown files at the kernel so nothing unrecognised touches production — there is nothing to roll back because nothing executed. The trade: a genuinely new-but-safe binary runs contained until verdicted.

Isolate, kill, restore from your backups

CrowdStrike, Defender for Endpoint and Coro stop the process and isolate the host; files come back from your backup or OneDrive Files Restore, not from the agent. Seqrite restores from its own ransomware backup. Strong response, no rollback — know which you bought.

Agent coexistence

One real-time engine per machine. Everything else can share.

  • Windows does the handshake for you: when a third-party engine registers with Windows Security Center, Microsoft Defender Antivirus drops to passive mode automatically — Defender for Endpoint keeps collecting EDR telemetry and can still block in EDR block mode. Automated investigation needs Defender AV present (passive or active), not removed.
  • Two third-party real-time engines do not coexist. The RMM’s “endpoint security” SKU and the UEM’s bundled AV are the usual way a second one arrives. Uninstall needs the tamper-protection password — plan it.
  • UEM and RMM agents are fine beside any of these with exclusions both ways: the EDR trusts the RMM’s installers and scripts; the RMM deploys and watches the EDR agent and never updates it.

Who runs it — the four operating models

  • Prevention only, run by IT. Entry tiers; the console is opened weekly for policy. Honest for many estates under ~300 seats — accept that nothing is hunting.
  • EDR run by your own analysts. Budget people, not just licences. CrowdStrike, SentinelOne and Defender P2 are built for this model.
  • MDR from the vendor. Sophos MDR, SentinelOne Vigilance, Bitdefender MDR, ESET MDR, Xcitium MDR, Seqrite MDR, Coro managed, CrowdStrike Falcon Complete, Defender Experts. Read the scope line: endpoint-only or wider, contain or rebuild, hours or 24/7.
  • MDR from a partner / MSSP on whichever agent you chose. Often the India-time-zone answer. Which partners TechBag has delivered with: [TechBag to confirm].
What breaks as you grow

What changes at 200, 2,000 and 10,000 endpoints

Detection quality barely moves with size. Alert volume per analyst, exclusion sprawl and the managed contract’s scope are what move — and they decide whether the EDR tier is real or nominal.

200endpoints

The operating model is the constraint

  • Prevention-only is often the honest tier here; an EDR console with no owner becomes noise by week three.
  • Defender for Business, Falcon Go, ESET Entry, GravityZone Business and Xcitium’s free tier are all sized for this band.
  • If you buy EDR, buy the managed tier with it — the licence is the smaller half.

Put this in your PoC

Run a detection-only week: count alerts, count the ones a human read, count the ones acted on.

2,000endpoints

Alert volume and exclusions are the constraint

  • Untuned EDR produces more alerts than a small team can triage; tuning and exclusions become an engineering task with an owner.
  • Agent coexistence with the UEM and RMM fleets must be documented per OS — one bad exclusion at this size is an outage.
  • MDR scope matters now: which alerts they take, which they hand back, what ‘response’ means in the SLA.

Put this in your PoC

Deploy to a 200-device ring with the RMM and UEM agents present; measure false positives and CPU for a week; read the MDR SLA aloud.

10,000endpoints

Telemetry, retention and the API are the constraint

  • Retention windows (days of searchable telemetry) and hunting query performance become line items.
  • Delegated, scoped administration by region or business unit is mandatory; console and API rate limits decide what you can automate.
  • Agent updates need rings of their own — a bad sensor release across 10,000 machines is the category’s worst day, and it has happened.

Put this in your PoC

Pull 30 days of telemetry through the API; run your three hardest hunts; confirm staged sensor-update control in writing.

CrowdStrike, SentinelOne, Defender, Sophos, Bitdefender and ESET document estates far above 2,000 endpoints; Xcitium, Seqrite and Coro are flagged unverified at that size, not ruled out. At what size a given console starts to strain for your estate is delivery-team experience: [TechBag to confirm].

The switching cost

Swapping an EPP is a security event, not an install

The agent swap is scriptable through your UEM or RMM. What makes it expensive is the gap: the minutes between old engine off and new engine on, on every machine, and the tamper-protection password nobody remembers.

The agent

Push the new agent first (passive where the vendor supports it), then remove the old with its tamper-protection credential, then activate. Never the other order.

Exit costScriptable, in rings

Policies and exclusions

Exclusions for your line-of-business apps, the RMM, the UEM and backup agents are rebuilt by hand. Miss one and the first week is an outage.

Exit costRebuild

Detection history

Alerts, timelines and hunting data stay in the old console. Export what an audit might ask for before the licence ends.

Exit costExport or lose

The managed contract

MDR terms run on their own calendar. Overlap two services or end one early — either is a cost line nobody put in the licence comparison.

Exit costOverlap or gap

Cut-over plan and hours for your estate: [TechBag to confirm] — TechBag scopes it from your OS mix, the agents already present and the managed contract dates.

What it costs

The licence is the smaller half

What you may already hold, what the tiers cost in USD and INR, and the part that never appears on the licence line — the people who run it.

01

Do you already own one?

Three licences you may hold carry endpoint protection. One of them is usually the answer for a Microsoft estate.

Microsoft 365
Yes, if E5 or E5 Security (Defender for Endpoint P2 — full EDR) or Business Premium (Defender for Business). E3 carries P1 only: prevention, no EDR.
Your RMM
Sometimes NinjaOne, Atera, TeamViewer and Splashtop resell or integrate SentinelOne, Bitdefender, CrowdStrike or an antivirus. Check which engine — and make sure it is not a second one.
Your UEM
No Intune, Jamf, Scalefusion and the rest configure and prove; none of them is an EPP. Intune can deploy and report on Defender; it does not replace it.

If Defender P2 is already on your invoice, we say so first — and then talk about who will run it.

02

What the tiers cost

Published USD with INR at ≈₹83/$ for scale; per device per year unless the vendor prices per user per month; the EDR tier named separately from the prevention tier wherever the vendor publishes both. Seqrite’s INR is the list and the USD is the conversion.

ESET PROTECT
Entry$42.20 ₹3,503Advanced$55 ₹4,565Complete$57.54 ₹4,776Elite (XDR)Quote

Term: per device / year; 5-device packs; Elite min 25; MDR on quote.

Bitdefender GravityZone
Small Business$57 ₹4,731Business Security$74 ₹6,142Premium (EDR)$95.89 ₹7,959Enterprise / MDRQuote

Term: per device / year, first-year promotional; renewals reported 2–3× higher.

CrowdStrike Falcon
Go (prevention)$59.99 ₹4,979Pro$99.99 ₹8,299Enterprise (EDR)$184.99 ₹15,354Complete (MDR)Quote

Term: per device / year; breakpoints at 500 / 1,000 / 5,000.

SentinelOne Singularity
Core~$69.99 ₹5,809Control~$79.99 ₹6,639Complete (EDR)~$179.99 ₹14,939Vigilance MDRAdd-on

Term: per endpoint / year reseller list — no vendor list; street commonly $48–96 for Complete.

Microsoft Defender for Endpoint
P1$3 ₹249P2 (EDR)$5.20 ₹432E5 Security add-on$12 ₹996Bundled$0

Term: per user / month standalone; $0 marginal inside E3 (P1) / E5 (P2) / Business Premium (DfB).

Xcitium
Module (e.g. containment)$2.39 ₹198Endpoint security bundle$8.49 ₹705OpenEDR ≤50Free MDRQuote

Term: per endpoint / month, modular, postpaid, no long-term contract.

Sophos Intercept X
AdvancedQuote with XDR~$48 reported ₹3,984MDR~$80–200+ reported ₹6,640–₹16,600

Term: per user / year; Sophos publishes no list — estimates only.

Seqrite Endpoint Protection
EPS Core → Total₹500–1,500 ≈ $6–18EDR / XDR / MDRQuote

Term: per user / year, INR-native through partners, GST invoiced.

Coro
Essentials (historical)~$9.50 ₹789Per module (historical)~$7.50 ₹623CurrentQuote

Term: per user / month; public list removed at the 2026 rebrand.

TechBag gives INR pricing, GST, PO cycle, minimums and tier-matched quotes. The INR above is conversion for scale; the tier-matched INR quote — with the EDR tier and the managed contract priced as one line — is ours.

03

What the licence line leaves out

The analyst, or the MDR contract

An EDR tier without a person is a licence for a dashboard. Price the analyst headcount or the managed service beside the tier — Sophos MDR is reported at $80 ≈ ₹6,640$200 ≈ ₹16,600 per user per year on top of the agent; CrowdStrike Falcon Complete and Defender Experts are quotes. That line is usually larger than the licence.

The renewal, not the promotion

First-year prices (Bitdefender’s in particular) renew at standard rates; reseller street prices (SentinelOne) move with volume; Microsoft’s E5 moved to $60 in July 2026. Ask for the year-two number in writing before comparing year one.

Removing the engine you replace

Tamper-protection credentials, a staged cut-over, exclusion rebuilds and a week of tuning — people-hours, not licence dollars. It sits in the switching-cost section, and the hours for your estate are [TechBag to confirm].

Before you commit

What goes wrong — the failure modes we can document

Each of these is documented vendor behaviour; the matching to real TechBag engagements happens before any becomes a named case. They are cheaper to read now than to live through after the contract.

EDR bought, nobody triages it

The console fills; nobody owns it; by month three it is closed. The licence was the cheap half of a purchase that needed a person or a managed contract.

Two real-time engines on one machine

The RMM’s security add-on or the UEM’s bundled AV lands beside the EPP you chose. Both degrade; one blocks the other’s updates. Only Defender is designed to step aside.

Assuming EPP covers response

Prevention tiers stop what they recognise and report the rest. When something gets through there is no timeline, no isolation, no hunt — because that was the next tier.

MDR scope narrower than expected

The contract covers endpoints; the incident started in email or identity. ‘Response’ meant contain the host, not rebuild it. Read the scope line before the incident, not during.

E3 ‘includes Defender’ — Plan 1, not Plan 2

Prevention only. The EDR is P2, in E5 or E5 Security. A buyer who stops at ‘included’ has no detection and believes they do.

Tamper protection blocks the migration

The old agent will not uninstall without its credential; the project stalls at machine one. Recover the password before you sign the new contract.

Rollback has conditions

Windows-first; needs free disk (Sophos ~3 GB); no rollback if the process was stopped after encryption finished. It restores files, not the breach — and it is absent at CrowdStrike, Defender and Coro.

Year-two price shock

Promotional first-year pricing (Bitdefender), reseller street pricing (SentinelOne) and the July 2026 E5 rise all move at renewal. Compare year-two numbers, tier-matched, or the comparison is fiction.

Three doors — pick by where you are

Researching

See the whole landscape and where each product sits.

Endpoint-management map →

Evaluating

Get your shortlist scoped against your real fleet.

Scope my shortlist →

Buying

Tier-matched USD + INR quote with GST.

Get a quote →

Vendor-neutral. No gated content.