Try our new research platform with insights from 80,000+ expert users

CylanceOPTICS vs Microsoft Defender for Endpoint comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

CylanceOPTICS
Ranking in Endpoint Detection and Response (EDR)
45th
Average Rating
7.4
Reviews Sentiment
4.5
Number of Reviews
11
Ranking in other categories
No ranking in other categories
Microsoft Defender for Endp...
Ranking in Endpoint Detection and Response (EDR)
3rd
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
196
Ranking in other categories
Endpoint Protection Platform (EPP) (1st), Advanced Threat Protection (ATP) (2nd), Anti-Malware Tools (1st), Microsoft Security Suite (5th)
 

Mindshare comparison

As of May 2025, in the Endpoint Detection and Response (EDR) category, the mindshare of CylanceOPTICS is 0.2%, up from 0.1% compared to the previous year. The mindshare of Microsoft Defender for Endpoint is 10.5%, down from 14.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR)
 

Featured Reviews

HERNAN RODRIGUEZ - PeerSpot reviewer
Easy to use
CylanceOPTICS is easy to use.  The product's technical support is slow.  I have been using the product for three years.  CylanceOPTICS is easy to use.  I rate the solution a nine out of ten. 
AnuragSrivastava - PeerSpot reviewer
Provides detailed visibility into threats but the ability to add exceptions needs improvement
One major item for improvement is the ability to add exceptions. We can add some exceptions, but not at the level we need to. The second major area for improvement involves enhanced capabilities for different operating systems or platforms. That is, even though we have coverage for different operating systems or platforms such as Linux, we don't get all of the controls and enhanced capabilities that are available with Windows devices. Reporting could also be improved because, at present, we get limited results at times. For example, in an environment with more than 100,000 devices, you may just get 10,000 results when you run a report.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It automatically blocks the threats, helping us investigate if they harm the environment."
"It is a bit early in our evaluation process to give proper feedback, although so far, the overall feedback is good."
"Cylance is not a signature-based protection solution and instead works proactively using AI and ML models to patrol for malicious behavior."
"CylanceOPTICS is easy to use."
"CylanceOPTICS is pretty stable."
"The initial setup was fairly straightforward. To get a large health care organization sorted, we had to create exemptions because some of the scripts and some of the automations were broken."
"The most valuable feature is the ability to respond to zero-day and unknown threats."
"It's pretty unintrusive"
"The patch management is very easy, as it can be done automatically or added to a schedule."
"Attack surface reduction and limiting attack surface vectors are valuable features. It's helpful to isolate specific devices and get super granular with the features they offer."
"The attack surface reduction rules are the most valuable. We're able to have unattended remediation actions when the solution works side by side with a local antivirus like Microsoft Defender or Kaspersky. The attack surface reduction rules help us to proactively block and stop threats."
"One of the main features is the solution is very light on resources and we do not have any problems with it."
"The installation is straightforward."
"The solution has an easy-to-use interface, is always updated, and is user-friendly."
"One of the features which differentiates it from other EDR providers is the Automated Investigation and Response, which reduces the workload of SOC analysts or engineers. They don't have to manually investigate each and every alert on the endpoint, since it does so automatically. And you can automate the investigation part."
"The most valuable feature is that it comes with the package, so there is no additional installation of third-party software. It's also easy to use."
 

Cons

"The reporting is very weak and not very good at all."
"It takes more time to investigate or dig up and understand what's going on."
"The product's technical support is slow."
"The detection component is something that they have to work on."
"CylanceOPTICS could benefit from more granular control in the timeline-building process. Ideally, users would be able to drill deeper into the analysis rather than have the machine dictate the direction."
"One minor issue that somebody mentioned was that they didn't like their management console."
"The technical support could be improved although it's probably better than you get with a lot of the other traditional antivirus solutions"
"Too many false positives are reported."
"Something that is unique to Microsoft is its licensing model. When you go out and you buy McAfee or Symantec, you know what you're getting out of the box, but with Microsoft, often, when you're looking to achieve a certain set of capabilities, those capabilities are spread across different products. You might try to do something you could do with CrowdStrike, but then find out that you also need to purchase Microsoft Defender for Identity or Microsoft Defender for Azure. You realize that when they talk about what they can offer within the Microsoft platform, it's really the suite of investments. So, sometimes, you may find yourself buying Defender for Endpoint thinking that it matches CrowdStrike, but then you find that Microsoft really needs to sell you something else. One plus one will equal three, but when you have a very concise platform, such as CrowdStrike, you know what you're going to get."
"I had some cases a while back and told an agent my issue. When I called the next day, I had to explain everything again to a different person, so I found it annoying to repeat myself all over."
"It can be more secure."
"Microsoft Defender for Endpoint does not provide much flexibility in terms of threats."
"In terms of improvements for their technical support, a focus on enhancing response times could be beneficial."
"We encountered some misbehavior between Microsoft Office Suite and Defender. We had issues of old macros being blocked and some stuff going around the usage of Win32 APIs. There is some improvement between the Office products and Defender, and there is a bunch of stuff that you can configure in your antivirus solutions, but you have several baselines, such as security baselines for Edge, security baselines for Defender, and security baselines for MDM. You have configuration profiles as well. So, there a lot of parts where we can configure our antivirus solution, and we're getting conflicting configurations. This is the major part with which we're struggling in this solution. We are having calls and calls with Microsoft for getting rid of all configuration conflicts that we have. That's really the part that needs to be improved."
"With the XDR dashboard, when you're doing an investigation and you're drilling down to obtain further details it tends to open many different tabs that take you away from your main tabs. You can end up having 10 tabs open for one investigation. This is another area for improvement because you can end up getting lost in the multiple tabs. Therefore, the central console can be improved so that it does not take you to several different pages for each investigation."
"Features like device inventory continue to lack essential workstation drill-downs showing the entire device information with the least effort."
 

Pricing and Cost Advice

"I would rate the pricing a three out of five."
"The pricing for CylanceOPTICS is very good; I would rate it around a nine on a scale of one to ten, with ten being the lowest. It's one of the most affordable options I've seen."
"We pay for the number of endpoints we have and that is about it. On a monthly basis, the licensing cost is $55 per user."
"CylanceOPTICS is probably priced equal to other EDRs in the market."
"For most people, the price of the license is not something that they have to worry about."
"The price for Microsoft Defender for Endpoint is about three euros, which is considered reasonably priced."
"The solution is included with Microsoft Windows."
"There are different licenses, such as E3 and E5."
"We have the E5 security license, and the solution comes with that."
"There is no licensing fee."
"AV solutions are pretty expensive because they are necessary, not just for protection, but many businesses need them to comply with regulatory bodies and receive accreditation. We recently purchased an E5 license, which gives us access to the entire Microsoft suite. I would say the pricing is competitive; most tools of this kind are similarly priced. There are minor differences between the competitors, but they aren't spectacularly different. Defender for Endpoint makes sense because all our solutions are in the same place, paid for with a single license. The subscription price is around £50 per user per month, though it may have increased slightly."
"Compared to ESET, the pricing for Microsoft Defender for Endpoint is on the higher side."
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
850,671 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
21%
Computer Software Company
19%
Government
9%
Financial Services Firm
7%
Educational Organization
24%
Computer Software Company
12%
Government
7%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Blackberry Optics?
I would rate the stability a nine out of ten. I would give it a close ten as possible because, like SentinelOne, I've seen incompatibility. Whereas Cylance, I've seen none.
What is your experience regarding pricing and costs for Blackberry Optics?
CylanceOPTICS is probably priced equal to other EDRs in the market. Price-wise, considering what it has to offer, you could probably get a better product.
What needs improvement with Blackberry Optics?
The solution's contextual analysis is sometimes not very clear compared to some modern EDRs like CrowdStrike. Compared to other EDR tools, CylanceOPTICS lacks some information. It takes more time t...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface, applies behavioral-based endpoint protection and response, and includes risk-ba...
Which offers better endpoint security - Symantec or Microsoft Defender?
We use Symantec because we do not use MS Enterprise products, but in my opinion, Microsoft Defender is a superior solution. Microsoft Defender for Endpoint is a cloud-delivered endpoint security s...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never push your machine hardware to "test", you don't have the usual "scan now" feature ...
 

Also Known As

No data available
Microsoft Defender ATP, Microsoft Defender Advanced Threat Protection, MS Defender for Endpoint, Microsoft Defender Antivirus
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Cerdant, Washoe County School District
Petrofrac, Metro CSG, Christus Health
Find out what your peers are saying about CylanceOPTICS vs. Microsoft Defender for Endpoint and other solutions. Updated: April 2025.
850,671 professionals have used our research since 2012.