Microsoft Defender for Endpoint at Fleet Scale: The Limits That Actually Bind
Reviewed by ContraForce Security Operations Team ยท Updated 2026-09-01
Sizing Microsoft Defender for Endpoint across a very large estate is not a question of whether the platform can hold the devices. It is a question of which adjacent ceiling you hit first, and most of them are per tenant rather than per device.
This page collects the published figures that decide architecture for federal departments, telecommunications carriers, and service providers operating many customer tenants. Every number below is quoted from Microsoft's own documentation and linked to its source.
How many devices can one Microsoft Defender for Endpoint tenant onboard?
Microsoft publishes no maximum onboarded-device count for a single Microsoft Defender for Endpoint tenant. The minimum requirements article scopes itself to licensing, hardware, and software, and states no device ceiling. That absence is worth planning around rather than trusting, because several adjacent per-tenant limits bind long before any device count would.
What limits bind before device count in a large Defender estate?
Three, in the order most estates meet them. The Microsoft Entra ID directory service quota is 300,000 objects by default for a tenant with a verified domain, and device objects count toward it alongside users and groups. Custom indicators cap at 15,000 per tenant. Device groups cap at 2,000.
| Ceiling | Limit | Scope |
|---|---|---|
| Entra directory objects | 300,000 | Per tenant, raisable via support |
| Custom indicators | 15,000 | Per tenant, not raisable |
| Device groups | 2,000 | Per tenant |
| Devices per user (Entra joined or registered) | 50 default, 100 maximum | Per user |
| Concurrent devices per Plan 2 licence | 5 | Per licensed user |
What is the real device envelope of a Defender for Endpoint Plan 2 licence?
Microsoft Defender for Endpoint Plan 2 is licensed per user, and each user licence covers up to five concurrent onboarded devices. The commercial envelope is therefore licensed users multiplied by five, not a platform ceiling. Server workloads fall outside that entitlement and require Defender for Servers or Defender for Endpoint Server separately.
How many device groups can a Defender tenant have?
Microsoft Defender for Endpoint supports up to 2,000 device groups per tenant, and each group rule accepts a maximum of 10 rows of values per property type across tag, device name, and domain. That row limit is the one that bites: granular definitions force estates to fan out across more groups, consuming the 2,000 budget faster than device count alone suggests.
How long do Defender device group changes take to propagate?
Microsoft states that device group configuration changes typically take several minutes and can take several hours to fully propagate, with no numeric bound published. New groups may not appear as filter options immediately. Large estates should budget the longer figure for cutover windows rather than the typical one.
How many custom indicators can a Defender tenant hold?
There is a hard limit of 15,000 indicators per tenant covering file hashes, IP addresses, URLs and domains, and certificates combined. Microsoft states plainly that increases to this limit are not supported, which makes it the only ceiling here that a support ticket cannot move.
Why do IP indicators consume the budget faster than expected?
Microsoft Defender for Endpoint supports only single external IP addresses as network indicators, with no CIDR blocks or address ranges. A large routed estate therefore spends one indicator per address rather than one per subnet, which is how carriers and government networks exhaust a 15,000-indicator budget that looked generous on paper.
How quickly do Defender IP and URL indicators take effect?
Microsoft states that a URL or IP indicator policy can take up to 48 hours to take effect on a device, although most take effect in under two hours. Network indicators also require Custom network indicators to be enabled under Advanced features, and they function only when Microsoft Defender Antivirus is in active mode.
What are the Microsoft Defender for Endpoint API rate limits?
Most Microsoft Defender for Endpoint REST APIs, including List machines, List alerts, Isolate machine, and Collect investigation package, are limited to 100 calls per minute and 1,500 calls per hour per tenant. The Import Indicators API is lower at 30 calls per minute, with a maximum batch of 500 indicators per call.
What limits multi-tenant advanced hunting across a large fleet?
Multitenant advanced hunting returns a maximum of 50,000 records in total, and the result set from each individual tenant is capped at 50,000 divided by the number of tenants queried. The ceiling therefore tightens as a provider adds customers: fifty tenants yield a thousand records each.
What throttles advanced hunting in a large tenant?
Advanced hunting CPU resources are allocated per tenant based on tenant size. The portal warns above 10 percent consumption, and queries are blocked once a tenant reaches 100 percent until after the next 15-minute cycle. Each query may run for up to 10 minutes, returning at most 100,000 rows within a 64 MB result.
How many alerts can a Defender custom detection rule generate?
Each custom detection rule can generate at most 150 alerts per run. Rules run on fixed frequencies of every 24 hours, 12 hours, 3 hours, hourly, or Continuous near-real-time. Custom detection rules require Microsoft Defender for Endpoint Plan 2 and are not documented for Plan 1 or Defender for Business.
What are the automated investigation and response automation levels?
Microsoft Defender for Endpoint sets automation per device group across five levels: full remediation automatically, semi with approval for all folders, semi with approval for non-temp folders, semi with approval for core folders, and no automated response. Automated investigation and response requires Plan 2 or Defender for Business, and is Windows-only.
Which Defender response actions require Plan 2?
Microsoft Defender for Endpoint Plan 1 caps manual response at four actions: run antivirus scan, isolate device, stop and quarantine a file, and add an indicator to block or allow a file. Every other device action, including initiating an automated investigation and starting a live response session, requires Plan 2.
What differs for Microsoft Defender for Endpoint in GCC High and DoD?
Microsoft states that US Government cloud offerings are built on the same prevention, detection, investigation, and remediation as commercial, but that there are differences in the availability of capabilities. The live response library limit is one concrete example: 5 MB by default in US Government clouds against 250 MB in commercial, raisable only by support request.
Sources
Every figure on this page is quoted from Microsoft documentation:
- Device groups
- Indicators overview
- IP and URL indicators
- Import indicators API
- List machines API
- Multitenant advanced hunting
- Advanced hunting overview
- Custom detection rules
- Automation levels
- Subscription settings
- Directory service limits
- Manage device identities
- US Government cloud
Continue the evaluation
Sources and review method
Product capabilities were reviewed against the page-specific primary sources below on 2026-09-01. Performance claims require the population and limitations stated in the linked methodology.
- Microsoft Defender multitenant management requirements (verified 2026-09-01)
- Automation in Microsoft Sentinel (verified 2026-09-01)