First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Subscriptions/Microsoft Defender Vulnerability Management for GCC
Standalone and add-on optionsGovernment

Microsoft Defender Vulnerability Management for GCC — Pricing, Plans & What's Included

GCC vulnerability management licensing for public-sector teams evaluating Microsoft Defender Vulnerability Management for supported, onboarded assets, with tenant cloud and feature scope confirmed before purchase.

The Government catalog shows GCC purchasing options for Microsoft Defender Vulnerability Management: standalone, add-on, and add-on server. The right choice depends on tenant cloud, prerequisite licensing, commitment term, and the unit basis for the selected SKU.

GCC vulnerability management licensingSecurity and compliance procurementStandalone or add-on evaluationServer add-on reviewAgencies aligning Microsoft security licensing

What's included — and what isn't

Included

Access to Microsoft Defender Vulnerability Management for GCC under the specific SKU you purchase.
The selected GCC SKU type only: standalone, add-on, or add-on server, as applicable to the order.
For add-on or add-on server purchases, the add-on entitlement associated with that SKU, not any prerequisite base license unless that base license is separately held or purchased.

Not included

A GCC High entitlement unless confirmed for your tenant and offer set.
All standalone, add-on, and add-on server options bundled together in one purchase.
Prerequisite or base licenses for add-on SKUs unless separately held or purchased.
Full Microsoft Defender for Endpoint EDR/XDR capabilities unless separately included through your base licensing.
Microsoft Intune, Configuration Manager, third-party patching tools, deployment labor, or hands-on remediation services unless separately licensed or purchased.

Eligibility & fine print

Catalog constraints & variants
  • The listed Government SKUs are GCC offers; confirm GCC High availability and tenant fit separately before purchase.
  • Add-on prerequisite licenses are not listed in this catalog extract; confirm the exact eligible base license before ordering.
  • Server add-on licensing should be reviewed separately from user-based purchasing to avoid under- or over-buying.
  • The GCC standalone, add-on, and add-on server entries are alternative catalog options; a single purchase should not be treated as including all of them.
  • Use the live configurator for current pricing; page copy intentionally does not hardcode prices.
Commitment & payment summary

Government GCC offers in the catalog include monthly commitment, annual commitment paid upfront, and annual commitment paid monthly. In this catalog extract, annual paid upfront is the lower catalog-unit rate than annual paid monthly, while month-to-month is listed separately for flexibility. Confirm current pricing in the live configurator before purchase.

Frequently asked questions

What is Microsoft Defender Vulnerability Management for GCC?

Microsoft Defender Vulnerability Management for GCC is a Government Community Cloud licensing option for vulnerability and exposure management on supported, onboarded assets. It is intended for public-sector organizations that need a Microsoft vulnerability management entitlement aligned to a GCC tenant, because the Government catalog lists GCC standalone, add-on, and server add-on options.

Which Government purchasing options exist for Microsoft Defender Vulnerability Management?

The Government catalog includes three GCC option types: Microsoft Defender Vulnerability Management for GCC, Microsoft Defender Vulnerability Management Add-on for GCC, and Microsoft Defender Vulnerability Management Add-On Server for GCC. These are alternative catalog choices, because buying one does not automatically include the standalone, add-on, and server add-on entitlements together.

What is included with a Microsoft Defender Vulnerability Management GCC license?

A Microsoft Defender Vulnerability Management GCC purchase includes the entitlement associated with the specific GCC SKU ordered, such as standalone, add-on, or server add-on. The exact scope depends on the selected SKU and supported onboarded assets, because the catalog extract identifies the offer types but does not define every feature or assignment rule.

What is not included with Microsoft Defender Vulnerability Management for GCC?

Microsoft Defender Vulnerability Management for GCC does not automatically include GCC High rights, all SKU types bundled together, prerequisite base licenses for add-ons, Microsoft Intune, Configuration Manager, third-party patching tools, deployment labor, or hands-on remediation services. It also should not be treated as a full Microsoft Defender for Endpoint EDR/XDR purchase unless those broader capabilities are included through separate base licensing.

Should a government agency buy the standalone GCC SKU or the add-on GCC SKU?

A government agency should buy the standalone GCC SKU when it needs a direct Microsoft Defender Vulnerability Management entitlement and should buy an add-on SKU only when it already has an eligible prerequisite base license. This distinction matters because the catalog lists add-on offers but does not state the exact eligible base licenses, so IT Partner should confirm prerequisites before ordering.

What is the Microsoft Defender Vulnerability Management Add-On Server for GCC used for?

The Add-On Server for GCC is a separate Government catalog option intended for server-related add-on licensing rather than a generic user purchase. It should be reviewed separately from user-based licensing, because server coverage and assignment rules can differ and the catalog extract does not state the unit basis.

Do Microsoft Defender Vulnerability Management add-on SKUs include the required base license?

No, the add-on SKUs should not be assumed to include the required base license, because an add-on typically extends an eligible underlying Microsoft security entitlement. The provided Government catalog names the add-on offers but does not list eligible prerequisite licenses, so the base license must be confirmed before purchase.

Is Microsoft Defender Vulnerability Management available for GCC High?

The provided Government catalog entries are labeled for GCC, not GCC High. GCC High availability should be confirmed separately before purchase, because GCC and GCC High are different government cloud environments with different offer availability and compliance boundaries.

Does Microsoft Defender Vulnerability Management for GCC satisfy government data residency requirements?

It may fit organizations using GCC, but data residency and compliance suitability must be confirmed against the agency’s tenant cloud and Microsoft’s current service documentation. This is necessary because the catalog confirms GCC-labeled offers but does not provide a full residency, compliance, or GCC High feature statement.

Does Microsoft Defender Vulnerability Management for GCC include vulnerability recommendations and remediation tracking?

Microsoft Defender Vulnerability Management is designed for vulnerability and exposure insight workflows, but the exact GCC feature scope should be verified against Microsoft’s current product documentation for the selected SKU. This confirmation is important because Government cloud capabilities can differ from Commercial cloud capabilities and should not be conflated with broader Defender XDR or Defender for Endpoint functionality.

Does Microsoft Defender Vulnerability Management for GCC include Microsoft Defender for Endpoint EDR or XDR?

No, Microsoft Defender Vulnerability Management for GCC should not be treated as a full Defender for Endpoint EDR or Defender XDR license by itself. It provides the vulnerability management entitlement for the selected SKU, while endpoint detection, response, and broader XDR capabilities must come from eligible base licensing or separate purchases.

Does this product include Microsoft Teams, Microsoft 365 Copilot, or Copilot for Security?

No, Microsoft Defender Vulnerability Management for GCC is not a Teams or Microsoft 365 Copilot license. Any Teams, Microsoft 365 Copilot, Copilot for Security, or related AI entitlement must be licensed separately, because the Government catalog entries here are for Defender Vulnerability Management.

Does Microsoft Defender Vulnerability Management for GCC include patch deployment tools?

No, it should not be assumed to include Microsoft Intune, Configuration Manager, third-party patching tools, or remediation labor. Vulnerability management can help identify and track exposure, but deployment tooling and operational remediation services are separate licensing or service decisions.

How does a government organization get started with Microsoft Defender Vulnerability Management for GCC?

A government organization should first confirm its tenant cloud, eligible base licenses, supported asset types, and whether the correct purchase is standalone, add-on, or server add-on. After licensing is validated, assets must be supported and onboarded according to Microsoft’s documentation, because visibility depends on the assets and integrations actually in scope.

Can a government agency move from Commercial licensing to Microsoft Defender Vulnerability Management for GCC?

A move from Commercial to GCC is not just a license swap, because Commercial and GCC tenants operate in different cloud environments and may require tenant, identity, and data migration planning. IT Partner should validate tenant eligibility, licensing availability, and migration path before purchase to avoid buying a SKU that does not match the agency’s environment.

Is there a trial for Microsoft Defender Vulnerability Management in the Government segment?

The product catalog indicates that a trial exists for Microsoft Defender Vulnerability Management, but the provided Government pricing list does not show a specific GCC trial line. A GCC trial should therefore be confirmed in the live configurator or with IT Partner before assuming it is available for a particular government tenant.

Can Microsoft Defender Vulnerability Management for GCC be transferred to IT Partner as CSP without downtime?

Yes, a CSP partner transfer is typically an administrative change to the reseller relationship rather than a tenant migration, so it should not interrupt users or security data when the same Microsoft tenant and subscriptions remain in place. IT Partner should still review the subscription IDs, renewal dates, and licensing mix before transfer to prevent provisioning or billing gaps.

Does moving Microsoft Defender Vulnerability Management for GCC to IT Partner change the Microsoft catalog price?

No, changing CSP provider does not change the underlying Microsoft catalog offer for the same tenant, SKU, term, and billing plan. The final invoice can still reflect partner-specific terms, taxes, or services, so IT Partner should provide a current quote before the transfer.

What renewal, cancellation, and seat-change rules apply to the Government GCC offers?

The Government catalog includes monthly commitment, annual commitment paid upfront, and annual commitment paid monthly options, and the rules differ by commitment. Month-to-month generally provides more flexibility, while annual commitments are more restrictive during the term, so cancellation and reduction timing should be checked before checkout.

Can a government agency increase or decrease Microsoft Defender Vulnerability Management licenses mid-term?

A government agency can usually add licenses during a term, but reductions are governed by the selected commitment and Microsoft CSP cancellation windows. This matters because annual paid upfront, annual paid monthly, and monthly commitment options have different flexibility, so IT Partner should confirm the exact change rules and co-terming plan before purchase.

Can a government buyer use Charity, Education, or Commercial Microsoft Defender Vulnerability Management SKUs instead of GCC?

A government buyer should use the SKU segment that matches its eligibility and tenant cloud, because Charity, Education, Commercial, and Government offers are separate catalog segments. Nonprofit grants, student or faculty licensing, and standard business pricing do not automatically apply to a Government GCC tenant.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Same Microsoft price — more on your side

IT Partner helps government buyers map the right GCC security SKU to the right tenant cloud, commitment term, and underlying Microsoft licensing before checkout.

  • Guidance for GCC purchasing, renewals, and tenant alignment.
  • Help distinguishing standalone, add-on, and server add-on options.
  • Support with co-terming, license changes, and renewal planning.
  • A practical licensing review before you commit budget.

Microsoft SKUs for Microsoft Defender Vulnerability Management

Microsoft's catalog identifies this plan as ProductId CFQ7TTC0JPGV. Every full SKU below — the identifier format from Partner Center, Microsoft invoices, and o365hq.com quote links — resolves to this page, priced from the current US CSP price list. Ask us if your paperwork shows a SKU that isn’t listed.

Our SKU (order token)Microsoft SKUOfferPrice
CFQ7TTC0JPGV-000K-P1Y-ACFQ7TTC0JPGV:000KMicrosoft Defender Vulnerability Management for GCC (Governmental Community Cloud Pricing) — Government · 1-year commitment · annual billing$36.00/yr · $3.00/user/mo eq.
CFQ7TTC0JPGV-000K-P1Y-MCFQ7TTC0JPGV:000KMicrosoft Defender Vulnerability Management for GCC (Governmental Community Cloud Pricing) — Government · 1-year commitment · monthly billing$3.15/mo · $3.15/user/mo eq.
CFQ7TTC0JPGV-000K-P1M-MCFQ7TTC0JPGV:000KMicrosoft Defender Vulnerability Management for GCC (Governmental Community Cloud Pricing) — Government · 1-month commitment · monthly billing$3.60/mo · $3.60/user/mo eq.

Format: ProductId-SkuId-Term-Billing(A = annual billing, M = monthly, T = triennial). Prices are Microsoft ERP for the segment shown and change with Microsoft’s monthly price list.