Can admins with E5/Defender P2 licenses purge phishing emails from E3‑licensed mailboxes using Threat Explorer?

Puri7y 45 Reputation points
2026-04-17T00:26:32.06+00:00

Good evening,

Our company recently downgraded most users from Microsoft 365 E5 Security to Microsoft 365 E3.

Before the downgrade, we used Threat Explorer to identify and purge phishing emails from user mailboxes. After the downgrade, we lost access to Threat Explorer unless the admin performing the action has an E5/P2 license.

We have been told by our CSP that even if the IT team has E5/P2 licenses, we are not allowed to use Threat Explorer or purge actions on mailboxes that are licensed with E3. They claim that purging emails from E3 mailboxes using E5‑licensed admin accounts is not permitted.

Can Microsoft please clarify:

If an admin has an E5 Security / Defender for Office 365 Plan 2 license, are they allowed to use Threat Explorer to purge malicious emails from mailboxes that are licensed with E3?

Is there any licensing restriction that prevents an E5/P2‑licensed admin from performing purge actions on E3 mailboxes?

Is this scenario supported in mixed‑license environments?

We want to ensure we are following Microsoft’s licensing rules correctly.

Thank you.

Microsoft Security | Microsoft Defender | Microsoft Defender for Office 365
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-04-17T00:26:45.0833333+00:00

    The provided context describes how Threat Explorer and remediation work, but does not state any licensing rules about which mailboxes (E3 vs E5/P2) an E5/P2‑licensed admin is allowed to act on. It only states that:

    • Threat Explorer/Real‑time detections require Defender for Office 365 licensing and appropriate permissions for the user performing the actions.
    • Email remediation (soft delete, hard delete, move to junk/deleted, etc.) is a Defender for Office 365 Plan 2 capability and requires the Search and Purge role or equivalent permissions.

    From the context:

    • “To use Threat Explorer or Real-time detections, you need to be assigned a license for Defender for Office 365… Threat Explorer or Real-time detections contains data for users with Defender for Office 365 licenses assigned to them.”
    • “Microsoft Defender for Office 365 Plan 2 … enables security teams to remediate threats in email… through manual and automated investigation.”
    • “Email remediation is an already existing feature that helps admins act on emails that are threats… What you need: 1. Microsoft Defender for Office 365 Plan 2… 2. Sufficient permissions (be sure to grant the account Search and Purge role).”

    The context does not provide any explicit statement about:

    • Whether an E5/P2‑licensed admin may or may not purge messages from mailboxes that are only licensed with E3.
    • Any prohibition or restriction on using Threat Explorer or purge actions against E3‑licensed mailboxes in a mixed‑license tenant.

    Because this specific licensing scenario is not covered in the supplied material, no definitive answer can be given from the context.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.