Try our new research platform with insights from 80,000+ expert users

Microsoft Defender for Endpoint vs Symantec Endpoint Security vs Trend Micro Smart Protection comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.2
Microsoft Defender for Endpoint offers cost savings, enhanced protection, and efficient threat management, with anticipated future benefits.
Sentiment score
7.5
Symantec Endpoint Security delivers positive ROI by enhancing virus protection, reducing downtime, and improving operational efficiency with minimal disruption.
Sentiment score
8.5
Many users saw ROI with Trend Micro Smart Protection, notably long-term, despite one user not observing value yet.
The return on investment is primarily in time savings and better observability of what's happening.
Symantec Endpoint Security filled gaps in our toolset, particularly with the ability to control network firewall on hosts remotely, which was greatly appreciated.
 

Customer Service

Sentiment score
6.5
Support for Microsoft Defender for Endpoint varies, with premium tiers offering quicker responses, while basic support can be slow.
Sentiment score
7.2
Symantec Endpoint Security's support is praised but varies post-Broadcom, with delays and regional differences affecting effectiveness.
Sentiment score
7.1
Trend Micro Smart Protection's customer service varies, with quick premium support and slower response times for standard and regional support.
The level-one support seems disconnected from subject matter experts.
I rate Microsoft support 10 out of 10.
Due to our size, we don't have access to direct technical support, but the knowledge base, Microsoft Learn, and the articles available are really good.
In some cases, it rates as high as ten out of ten, while in others, it can be as low as eight.
There is no support in the German language, which is a problem for many public tenders.
 

Scalability Issues

Sentiment score
7.7
Microsoft Defender for Endpoint is a scalable solution integrating smoothly with Microsoft, ideal for diverse organizational needs and configurations.
Sentiment score
7.8
Symantec Endpoint Security is scalable, user-friendly, and ideal for large organizations, effortlessly integrating with existing systems.
Sentiment score
7.9
Trend Micro Smart Protection is highly scalable, supporting diverse businesses and users with seamless expansion across various sectors.
We managed to scale it out in a short amount of time, with two months of planning and three months of implementation on 10,000 computers.
Microsoft Defender for Endpoint is scalable enough to handle various devices across environments, whether they are laptops, Android devices, or operating in hybrid environments.
It's pretty easy to scale with Microsoft, as they make it easy if you look into the documentation.
Symantec Endpoint Security is quite scalable, and it is very important for large clients.
 

Stability Issues

Sentiment score
7.9
Microsoft Defender for Endpoint is stable and reliable, with integration ease, despite occasional lags and minor update bugs.
Sentiment score
7.8
Symantec Endpoint Security is generally reliable, though updates and operating system variations can occasionally disrupt stability and resource usage.
Sentiment score
8.4
Trend Micro Smart Protection is stable and reliable, with few performance issues, although Windows compatibility may vary.
I haven't seen any outages with Microsoft.
I rate Defender 10 out of 10 for stability.
Defender for Endpoint is extremely stable.
I have encountered issues where I had to uninstall and reinstall the product on end users' computers to view the logs again.
 

Room For Improvement

Microsoft Defender for Endpoint needs frequent updates, improved integration, user-friendly interface, enhanced analytics, and better support documentation.
Symantec Endpoint Security faces performance issues, complex management, insufficient threat detection, and compatibility problems affecting usability and support.
Trend Micro Smart Protection needs improved insights, management, pricing, support, integration, resource usage, compatibility, compliance, and security features.
Repeated interactions are necessary due to Level One's lack of tools and knowledge, hindering efficient problem-solving and negatively impacting our experience with Microsoft support.
We use Microsoft partners to help govern the platform, and as part of an alliance, we want to gather data from each tenant and combine them for a complete view.
Providing more detailed information on how Microsoft Defender for Endpoint detects vulnerabilities.
Device management is not very good and I am not enabling it in my organization due to security reasons.
I would like to see improvements in the scanning part of the solution, specifically to enhance the CPU and hard disk usage during scanning and updates to prevent disruption during work hours.
It is cumbersome to use, particularly in handling firewall management.
We've experienced compatibility issues with Windows endpoint protection.
 

Setup Cost

Microsoft Defender for Endpoint is cost-effective with bundled licenses, but advanced features may incur additional fees.
Symantec Endpoint Security is valued for its cost-effective pricing, flexible plans, and discounts for long-term or special contracts.
Trend Micro Smart Protection's cost, ranging from 50,000 to 6,000 Euros, is often justified by its features and discounts.
Given our extensive Microsoft licensing, transitioning to Defender for Endpoint did not affect licensing costs.
It costs $15 per VM for the P2 plan, which is seen as affordable for customers.
The pricing, setup, and licensing were very easy and simple.
It seems to be half the cost or more affordable than other solutions.
The pricing is very low compared to other companies like SentinelOne and others.
I rate the pricing, setup cost, and licensing around nine out of ten.
However, their pricing is comparable to CrowdStrike.
 

Valuable Features

Microsoft Defender for Endpoint offers seamless integration, real-time threat detection, and efficient management, enhancing security with minimal system impact.
Symantec Endpoint Security provides comprehensive protection with device control, intrusion prevention, anti-virus, centralized management, and cross-platform integration.
Trend Micro Smart Protection offers robust security features, praised for integration, user-friendliness, scalability, and reliable threat prevention capabilities.
Defender for Endpoint's coverage across different platforms in our environment is pretty good. We have devices running Linux, Mac OS, Windows, iOS, and Android. It covers all of them.
Microsoft Defender for Endpoint provides a unified management interface allowing customers to manage their on-premises and hybrid infrastructures from a single pane.
Web filtering is the most valuable feature of Microsoft Defender for Endpoint because it effectively maintains security for website access.
Symantec Endpoint Security offers many valuable features, such as file explosion, application learning, DLP, injection detection, and EDR solutions for traffic control.
The incident response capabilities allow me to resolve authentication and support issues promptly, ensuring the system operates without downtime.
One important feature is the EDR function, necessary for many public customers due to upcoming laws in Germany, which is available through Symantec Endpoint Security Complete.
The most effective features of Trend Micro Smart Protection are its antivirus and malware capabilities.
 

Mindshare comparison

As of April 2025, in the Endpoint Protection Platform (EPP) category, the mindshare of Microsoft Defender for Endpoint is 10.9%, down from 14.8% compared to the previous year. The mindshare of Symantec Endpoint Security is 4.0%, down from 4.9% compared to the previous year. The mindshare of Trend Micro Smart Protection is 0.6%, up from 0.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Protection Platform (EPP)
 

Featured Reviews

AnuragSrivastava - PeerSpot reviewer
Provides detailed visibility into threats but the ability to add exceptions needs improvement
One major item for improvement is the ability to add exceptions. We can add some exceptions, but not at the level we need to. The second major area for improvement involves enhanced capabilities for different operating systems or platforms. That is, even though we have coverage for different operating systems or platforms such as Linux, we don't get all of the controls and enhanced capabilities that are available with Windows devices. Reporting could also be improved because, at present, we get limited results at times. For example, in an environment with more than 100,000 devices, you may just get 10,000 results when you run a report.
Hakeem_Abdulkareem - PeerSpot reviewer
The solution has given us visibility into compliance within our whole system and helped us ensure everything is updated
Symantec's application security module needs some improvement. You need to create a lot of fingerprints for application security. For instance, let's say I have different brands of ATMs in my environment, like Wincor and NCR. I use GRG to deploy an application control to whitelist some applications. I have to get the exact image of the different models of ATMs. When I tested in the past, some machines would not connect to the server without that. Only the approved software on the ATM should run. Anything outside that should not even come up at all. We did this so that an outside person doesn't introduce malicious software to the ATM. That's the essence of locking down with application control. Using Symantec for application control has been hectic, so I use Carbon Black to do the lockdown. Checking that data security will work fine with Carbon Black. Carbon Black worked fine. Setting up approval in Carbon Black works differently than Symantec. In Symantec, we first need the fingerprints of the applications running underneath. Before setting up Carbon Black, you first install the agent, allowing it to learn the environment. It will analyze all the software's behavior and provide recommendations for what should be allowed. It's more straightforward, whereas configuring application control in Symantec is a bit cumbersome.
Amey Darekar - PeerSpot reviewer
Offers centralized security management and flexibility
The improvements required in the product depend on how it is used, meaning it can be used for endpoint security or email and collaboration security. The web gateway is used along with anti-malware, advanced protection, URL filtering, application control, and data protection. I don't have any improvements to suggest in the tool as of now, and not at least for now, as per my security assessment. There are certain concerns with the product's stability, so it is an area where improvements are required.
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
849,475 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
26%
Computer Software Company
11%
Government
7%
Financial Services Firm
7%
Computer Software Company
15%
Financial Services Firm
12%
Manufacturing Company
10%
Government
8%
Computer Software Company
15%
Manufacturing Company
11%
Government
8%
Financial Services Firm
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
Which offers better endpoint security - Symantec or Microsoft Defender?
We use Symantec because we do not use MS Enterprise products, but in my opinion, Microsoft Defender is a superior sol...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never pu...
Which is better - Cortex XDR or Symantec End-User Endpoint Security?
Aqua Security is easy to use and very manageable. Its main focus is on Kubernetes and Docker. Security is a very valu...
What do you like most about Symantec End-User Endpoint Security?
Symantec have everything – documentation, videos, data sheets.
What is your experience regarding pricing and costs for Symantec End-User Endpoint Security?
Symantec Endpoint Security's pricing is better than most offerings based on my research. It seems to be half the cost...
What do you like most about Trend Micro Smart Protection?
The tool offers centralized security management. The tool's deployment is flexible.
What is your experience regarding pricing and costs for Trend Micro Smart Protection?
I'm not involved in licensing, so I have no idea of the cost. However, their pricing is comparable to CrowdStrike. No...
What needs improvement with Trend Micro Smart Protection?
The dashboard could be easier to manage. We've experienced compatibility issues with Windows endpoint protection. Mor...
 

Also Known As

Microsoft Defender ATP, Microsoft Defender Advanced Threat Protection, MS Defender for Endpoint, Microsoft Defender Antivirus
Symantec EPP, Symantec Endpoint Protection (SEP)
Trend Micro Smart Protection Complete
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

Petrofrac, Metro CSG, Christus Health
Audio Visual Dynamics, Red Deer Advocate, Asia Pacific Telecom Co. Ltd., Kibbutz Ein Gedi, and AMETEK, Inc.
Atma Jaya Catholic University of Indonesia, Blekinge County Council, Bulgarian American Credit Bank, Cancer Research UK, Delacour, Evalueserve, Gulftainer, Hiroshima Red Cross Hospital & Atomic-bomb Survivors Hospital, Mazda Motor Logistics Europe, MEDHOST, Nikigolf, Ochsner Health System, SIAX Computing Solutions, Tegen
Find out what your peers are saying about Microsoft, CrowdStrike, SentinelOne and others in Endpoint Protection Platform (EPP). Updated: April 2025.
849,475 professionals have used our research since 2012.