Symantec Endpoint Security and Microsoft Defender for Endpoint are key competitors in the endpoint security market. Microsoft Defender for Endpoint holds an advantage due to its strong cloud integration, real-time threat detection, and cost-effectiveness, especially for organizations using Microsoft's ecosystem.
Features: Symantec Endpoint Security provides an array of protective features including anti-virus, anti-spyware, firewall, intrusion prevention, and centralized management. Its stable operation across Windows and Linux is notable. Microsoft Defender for Endpoint excels in cloud integration, automation of routine tasks, and offers comprehensive threat intelligence that benefits from deep integration with other Microsoft products.
Room for Improvement: Symantec Endpoint Security needs enhancements to reduce high resource consumption and improve zero-day threat detection. Its interface can be more user-friendly, and support for remote users needs optimization. Microsoft Defender for Endpoint could improve in ease of use and automation while expanding integration capabilities with non-Windows systems. It would benefit from offering better customization and quicker threat detection alerts.
Ease of Deployment and Customer Service: Symantec Endpoint Security deployment can be complex when on-premises, whereas Microsoft Defender for Endpoint's cloud-based options are more seamless, particularly for Microsoft-centric systems. Symantec's customer support has seen some decline post-Broadcom acquisition, while Microsoft's support documentation, although comprehensive, can be overwhelming.
Pricing and ROI: Symantec Endpoint Security is relatively expensive but offers a solid ROI with its protective efficacy. Microsoft Defender for Endpoint is cost-effective, often included in Microsoft 365 bundles, reducing the need for additional security investments. Microsoft's flexible pricing strategy offers significant cost savings.
The return on investment is primarily in time savings and better observability of what's happening.
Due to our size, we don't have access to direct technical support, but the knowledge base, Microsoft Learn, and the articles available are really good.
I rate Microsoft support 10 out of 10.
The level-one support seems disconnected from subject matter experts.
In some cases, it rates as high as ten out of ten, while in others, it can be as low as eight.
We managed to scale it out in a short amount of time, with two months of planning and three months of implementation on 10,000 computers.
It's pretty easy to scale with Microsoft, as they make it easy if you look into the documentation.
Defender's scalability is phenomenal, and it's going to be one of the keys to resolving issues for the SOC.
Defender for Endpoint is extremely stable.
I haven't seen any outages with Microsoft.
I rate Defender 10 out of 10 for stability.
Repeated interactions are necessary due to Level One's lack of tools and knowledge, hindering efficient problem-solving and negatively impacting our experience with Microsoft support.
We have multiple endpoints, and we want to look for signals across tenants.
An additional feature that could be included in the next release is free Copilot.
Device management is not very good and I am not enabling it in my organization due to security reasons.
I would like to see improvements in the scanning part of the solution, specifically to enhance the CPU and hard disk usage during scanning and updates to prevent disruption during work hours.
Given our extensive Microsoft licensing, transitioning to Defender for Endpoint did not affect licensing costs.
The pricing, setup, and licensing were very easy and simple.
The pricing is very low compared to other companies like SentinelOne and others.
I rate the pricing, setup cost, and licensing around nine out of ten.
Defender for Endpoint's coverage across different platforms in our environment is pretty good. We have devices running Linux, Mac OS, Windows, iOS, and Android. It covers all of them.
Attack surface reduction and limiting attack surface vectors are valuable features.
Web filtering is the most valuable feature of Microsoft Defender for Endpoint because it effectively maintains security for website access.
Symantec Endpoint Security offers many valuable features, such as file explosion, application learning, DLP, injection detection, and EDR solutions for traffic control.
The incident response capabilities allow me to resolve authentication and support issues promptly, ensuring the system operates without downtime.
Microsoft Defender for Endpoint is a comprehensive security solution that provides advanced threat protection for organizations. It offers real-time protection against various types of cyber threats, including malware, viruses, ransomware, and phishing attacks.
With its powerful machine-learning capabilities, it can detect and block sophisticated attacks before they can cause any harm. The solution also includes endpoint detection and response (EDR) capabilities, allowing organizations to quickly investigate and respond to security incidents. It provides detailed insights into the attack timeline, enabling security teams to understand the scope and impact of an incident.
Microsoft Defender for Endpoint also offers proactive threat hunting, allowing organizations to proactively search for and identify potential threats within their network. It integrates seamlessly with other Microsoft security solutions, such as Microsoft Defender XDR, to provide a unified and holistic security approach. With its centralized management console, organizations can easily deploy, configure, and monitor the security solution across their entire network.
Microsoft Defender for Endpoint is a robust and scalable security solution that helps organizations protect their endpoints and data from evolving cyber threats.
Symantec Endpoint Security is a robust and reliable product that provides complete protection against viruses, malware, Trojans, and malicious files. It offers application and device control, ease of use in deploying and updating, a central control console, stability, scalability, auto-discovery capabilities, patch management, endpoint detection and response capabilities, intrusion detection module.
The Symantec Global Intelligence Network (GIN) provides threat intelligence and detection across endpoints, email, and web traffic. It has helped organizations reduce downtime, increase productivity, and improve security posture. Symantec Endpoint Security is easy to use, has a flexible administration, and offers more value than expected.
We monitor all Endpoint Protection Platform (EPP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.