Microsoft Defender for Cloud Apps and Microsoft Defender for Endpoint are key players in the realm of cloud app security and endpoint protection. Microsoft Defender for Cloud Apps appears to have the edge due to its comprehensive cloud integration and identity security capabilities, while Defender for Endpoint is praised for its robust threat detection within the Microsoft ecosystem.
Features: Microsoft Defender for Cloud Apps offers excellent management of app security, integration across various cloud environments such as AWS and Salesforce, and provides updates on security posture with efficiency. Identity security and application investigations are also key strengths. Microsoft Defender for Endpoint is known for its robust threat detection capabilities and seamless integration within the Microsoft environment, offering real-time data and comprehensive protection features.
Room for Improvement: Microsoft Defender for Cloud Apps can enhance integration with Apple products, improve reporting, and aim for fewer false positives. Streamlined integration with third-party security solutions and faster policy applications are desired. Microsoft Defender for Endpoint needs to expand support for non-Windows systems and simplify management processes, reduce CPU usage, and provide better integration for hybrid environments.
Ease of Deployment and Customer Service: Microsoft Defender for Cloud Apps is favored for hybrid and public cloud deployments, praised for its help desk support despite some challenges with timely assistance. Microsoft Defender for Endpoint supports diverse deployment configurations across public and on-premises environments, with generally positive technical support feedback though occasionally noted for delayed responsiveness.
Pricing and ROI: Microsoft Defender for Cloud Apps is cost-effective when bundled with E3 and E5 licenses, although standalone pricing is high. Microsoft Defender for Endpoint's integration with Windows and Office 365 licensing offers significant cost benefits compared to standalone solutions, with noted ROI from its uptime benefits and integration efficiencies.
The biggest return on investment so far has been visibility, knowing what we have in our environment.
The return on investment is primarily in time savings and better observability of what's happening.
Their customer service is pretty good, but it's frustrating to go through three or four channels before reaching the right person.
Due to our size, we don't have access to direct technical support, but the knowledge base, Microsoft Learn, and the articles available are really good.
I rate Microsoft support 10 out of 10.
The level-one support seems disconnected from subject matter experts.
For what I know about the log collector and how much data it can take in, it is super scalable and capable of handling high workloads.
We managed to scale it out in a short amount of time, with two months of planning and three months of implementation on 10,000 computers.
It's pretty easy to scale with Microsoft, as they make it easy if you look into the documentation.
Defender's scalability is phenomenal, and it's going to be one of the keys to resolving issues for the SOC.
Like any other Microsoft product, the uptime is good.
Defender for Endpoint is extremely stable.
I haven't seen any outages with Microsoft.
I rate Defender 10 out of 10 for stability.
We are having trouble with our continuous reporting configuration and struggling with configuring the collector properly with our log parsing.
Repeated interactions are necessary due to Level One's lack of tools and knowledge, hindering efficient problem-solving and negatively impacting our experience with Microsoft support.
We have multiple endpoints, and we want to look for signals across tenants.
An additional feature that could be included in the next release is free Copilot.
Given our extensive Microsoft licensing, transitioning to Defender for Endpoint did not affect licensing costs.
The pricing, setup, and licensing were very easy and simple.
We have also locked down our consent apps, so users can no longer consent on their own behalf to create apps in our environment.
Defender for Endpoint's coverage across different platforms in our environment is pretty good. We have devices running Linux, Mac OS, Windows, iOS, and Android. It covers all of them.
Attack surface reduction and limiting attack surface vectors are valuable features.
Web filtering is the most valuable feature of Microsoft Defender for Endpoint because it effectively maintains security for website access.
Microsoft Defender for Cloud Apps is a comprehensive security solution that provides protection for cloud-based applications and services. It offers real-time threat detection and response, as well as advanced analytics and reporting capabilities. With Defender for Cloud Apps, organizations can ensure the security of their cloud environments and safeguard against cyber threats. Whether you're running SaaS applications, IaaS workloads, or PaaS services, Microsoft Defender for Cloud Apps can help you secure your cloud environment and protect your business from cyber threats.
Reviews from Real Users
Ram-Krish, Cloud Security & Governance at a financial services firm, says that Microsoft Defender for Cloud Apps "Integrates well and helps us in protecting sensitive information, but takes time to scan and apply the policies and cannot detect everything we need".
PeerSpot user, Senior Cloud & Security Consultant at a tech services, writes that Microsoft Defender for Cloud Apps "Great for monitoring user activity and protecting data while integrating well with other applications".
Simon Burgess,Infrastructure Engineer at SBITSC, states that Microsoft Defender for Cloud Apps is "A fluid, intelligent product for great visibility, centralized management, and increased uptime".
Microsoft Defender for Endpoint is a comprehensive security solution that provides advanced threat protection for organizations. It offers real-time protection against various types of cyber threats, including malware, viruses, ransomware, and phishing attacks.
With its powerful machine-learning capabilities, it can detect and block sophisticated attacks before they can cause any harm. The solution also includes endpoint detection and response (EDR) capabilities, allowing organizations to quickly investigate and respond to security incidents. It provides detailed insights into the attack timeline, enabling security teams to understand the scope and impact of an incident.
Microsoft Defender for Endpoint also offers proactive threat hunting, allowing organizations to proactively search for and identify potential threats within their network. It integrates seamlessly with other Microsoft security solutions, such as Microsoft Defender XDR, to provide a unified and holistic security approach. With its centralized management console, organizations can easily deploy, configure, and monitor the security solution across their entire network.
Microsoft Defender for Endpoint is a robust and scalable security solution that helps organizations protect their endpoints and data from evolving cyber threats.
We monitor all Advanced Threat Protection (ATP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.