Microsoft Defender for Endpoint is used for securing endpoints from threats.
Stable, embedded in Microsoft Windows, and high performance
Pros and Cons
- "The performance of Microsoft Defender for Endpoint has been good."
- "Microsoft Defender for Endpoint could improve by providing more user-friendly dashboards. They may be complicated for some."
What is our primary use case?
What is most valuable?
The performance of Microsoft Defender for Endpoint has been good.
What needs improvement?
Microsoft Defender for Endpoint could improve by providing more user-friendly dashboards. They may be complicated for some.
In a future release, they should add a feature for patch management.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for one year.
Buyer's Guide
Microsoft Defender for Endpoint
January 2025
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.
What do I think about the stability of the solution?
Microsoft Defender for Endpoint has been stable.
What do I think about the scalability of the solution?
The scalability of Microsoft Defender for Endpoint has been good.
We have approximately five clients using the solution. We have thousands of licensees for this solution within my company.
How are customer service and support?
The technical from Microsoft could be better. It is not as good as other solutions.
How was the initial setup?
The implementation of Microsoft Defender for Endpoint because it is pre-installed with Microsoft Windows. Other solutions you have to install separately, such as Check Point.
What's my experience with pricing, setup cost, and licensing?
The license for Microsoft Defender for Endpoint is included in the license for the Microsoft Windows operating system.
What other advice do I have?
I would recommend this solution to others.
I rate Microsoft Defender for Endpoint a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Performs well, easy to use, and intuitive implementation
Pros and Cons
- "Microsoft Defender for Endpoint's most valuable feature is its ease of use."
- "Microsoft Defender for Endpoint can improve by providing more and different types of reports."
What is our primary use case?
I am using Microsoft Defender for Endpoint for system alerts of any kind of suspicious items or unusual network traffic. I only use it for personal use.
The solution has shown me different kinds of requests from the websites that were made and cookies that have been created. It has provided me with statistics.
What is most valuable?
Microsoft Defender for Endpoint's most valuable feature is its ease of use.
What needs improvement?
Microsoft Defender for Endpoint can improve by providing more and different types of reports.
For how long have I used the solution?
I used Microsoft Defender for Endpoint within the past 12 months.
What do I think about the stability of the solution?
Microsoft Defender for Endpoint has been stable. It does not slow down my computer.
What do I think about the scalability of the solution?
The scalability of Microsoft Defender for Endpoint has been fine.
How are customer service and support?
I have not contacted the support from Microsoft.
How was the initial setup?
The initial setup of Microsoft Defender for Endpoint was intuitive, I didn't make any customization, I used what was preset. The installation was done with the Microsoft Windows installation.
What's my experience with pricing, setup cost, and licensing?
The license for Microsoft Windows covers Microsoft Defender for Endpoint.
What other advice do I have?
I rate Microsoft Defender for Endpoint an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Microsoft Defender for Endpoint
January 2025
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.
Delivery manager at a computer software company with 201-500 employees
One-stop solution with data capture, analytics, and threat intelligence
Pros and Cons
- "It captures data through machine learning, which is built-in on the back-end. It also provides built-in analytics and a threat intelligence feature. It is a one-stop solution that doesn't require an antivirus because it comes prebuilt into Windows 10."
- "Sometimes, there are different skews. In a basic skew, they should have basic log analysis without the need to integrate with any third-party or SIEM solutions, like Sentinel. This would make it so much easier for users who don't have log collection or log analysis."
What is our primary use case?
I lead a delivery team. I have a team of about 20 technology specialists and we do the deployment for Microsoft Defender.
Instead of having a third-party antivirus, then you can have a Microsoft ecosystem for your entire endpoint protection.
What is most valuable?
This solution has its own sensors, which is its best feature. It senses the behavior of your endpoints, whether it is logged in from a particular location or external of that location.
It captures data through machine learning, which is built-in on the back-end. It also provides built-in analytics and a threat intelligence feature. It is a one-stop solution that doesn't require an antivirus because it comes prebuilt into Windows 10.
What needs improvement?
Sometimes, there are different skews. In a basic skew, they should have basic log analysis without the need to integrate with any third-party or SIEM solutions, like Sentinel. This would make it so much easier for users who don't have log collection or log analysis.
For how long have I used the solution?
We have been using it for a year.
What do I think about the stability of the solution?
This solution is very much stable.
What do I think about the scalability of the solution?
This solution is scalable. It is a cloud solution.
If you have the Microsoft Azure ecosystem, you can collect logs and view them through Sentinel. You can also onboard your devices within Intune.
You can integrate Microsoft Defender for Endpoint with different Microsoft solutions, e.g., Defender for Cloud, Sentinel, Endpoint Manager for onboarding of Intune, and Defender for Office 365.
We have a large number of customers.
How are customer service and support?
Premium support is okay. Professional support is not as good because it is free. You must wait because you are not paying.
How was the initial setup?
The initial setup was straightforward. There was nothing rocket science to it. It didn't take much time as we just enrolled the device and assigned the licenses, then it was done.
You just prepare it, doing a license evaluation licensing and some network configuration, then you can onboard your device.
What about the implementation team?
We do the implementation ourselves. We find it easy to deploy. We help customers adopt the solution and get better ROI.
What's my experience with pricing, setup cost, and licensing?
They have to pay for the Defender license. There are different licenses and skews, such as Plan 1, Plan 2, or the trial.
You do not need to pay any additional costs for antivirus and anti-malware solutions for endpoint protection.
What other advice do I have?
Anyone on Windows 10 Enterprise should choose this solution.
It really depends on the volume. You need one senior architect who can just define the entire thing: the device, network configuration, etc. You will also need some Level 1 engineers who need to keep on monitoring the devices and do onboarding. If they are using the latest version of Windows 10, then you can do the onboarding via Intune, Endpoint, etc.
My rating for this solution is an eight out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Works at a financial services firm with 51-200 employees
Simple to install and maintain, but the support could be faster, and more responsive
Pros and Cons
- "The installation is straightforward."
- "Phishing and Malware detection could be better."
What is our primary use case?
Microsoft Defender for Endpoint gives us a second layer of security as well as the third layer of security. One of them is interested in web security and email security. One of them, similar to Cisco, is a Cisco FirePOWER. These are a compilation or a group of devices for security.
What needs improvement?
We had some issues where phishing and malware were not detected and were allowed to pass unless I mentioned it or we forced the phishing or malware to be blocked, I can't rely on that alone.
Phishing and Malware detection could be better.
Technical support needs improvement.
For how long have I used the solution?
I have been working with Microsoft Defender for Endpoint for one year.
What do I think about the stability of the solution?
It is stable for the time being.
What do I think about the scalability of the solution?
I can't add more layers of security because of my budget and business plan, so I try to choose the best and most preferable option for me and my company.
I would rate the scalability a seven out of ten.
In one company, we have two administrators and 30 employees who use this solution.
On a short-term plan, I will not increase the usage. On a larger scale, we intend to increase the license.
How are customer service and support?
In my opinion, technical support is not as effective as it was before. They take a long time to support and investigate the issue.
It takes a long time for them to support and investigate the issue. I believe they must crush the time in order to provide us with our needs, and our objectives.
Which solution did I use previously and why did I switch?
There are applications and solutions that we have used for five or more years. We almost used Microsoft Link but have since switched to Microsoft Teams and Skype for business. We almost exclusively use Cisco products such as Cisco EMC, Cisco Web security, and Cisco Meraki.
How was the initial setup?
The installation is straightforward. It's a cloud solution that requires some configuration running on the cloud.
The deployment takes a couple of hours to complete.
It's a different story when it comes to security. It takes a different approach. It requires two an administrator and a manager to maintain this solution.
What about the implementation team?
Sometimes the installation and deployment are done by the technical team, and sometimes it's done by others.
What's my experience with pricing, setup cost, and licensing?
Licensing fees are paid annually through a partner.
What other advice do I have?
If I do recommend it, it will not be solely for security purposes. It is possibly for a first-line security platform, and it is required to build a second, third, and possibly fourth business security layer.
I would rate Microsoft Defender for Endpoint a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cyber Security Specialist at a healthcare company with 10,001+ employees
Good support and valuable EDR feature, but not stable and not suitable for enterprises with lots of other processes and third-party tools
Pros and Cons
- "The EDR feature is most valuable."
- "It is currently more suitable for end-users rather than enterprises with lots of other processes and third-party tools. It needs improvement on that front. We had many issues while integrating it with our enterprise solutions, such as Splunk, and third-party tools. It provides everything via APIs. Other vendors provide integration with third-party tools, but Microsoft doesn't do that. It is also logging too much and is not serialized from the process aspect. It has all the data, but it is not in a proper format or not properly indexed, which doesn't make it easier for enterprises to use this data. Other vendors provide troubleshooting information that can be used to troubleshoot issues, but Microsoft doesn't provide anything like that."
What is our primary use case?
We use it for our endpoint detection and response capability.
What is most valuable?
The EDR feature is most valuable.
What needs improvement?
It is currently more suitable for end-users rather than enterprises with lots of other processes and third-party tools. It needs improvement on that front. We had many issues while integrating it with our enterprise solutions, such as Splunk, and third-party tools. It provides everything via APIs. Other vendors provide integration with third-party tools, but Microsoft doesn't do that.
It is also logging too much and is not serialized from the process aspect. It has all the data, but it is not in a proper format or not properly indexed, which doesn't make it easier for enterprises to use this data.
Other vendors provide troubleshooting information that can be used to troubleshoot issues, but Microsoft doesn't provide anything like that.
For how long have I used the solution?
I have been using this solution for six months.
What do I think about the stability of the solution?
It is still a new product, and there are many reported bugs in terms of stability and impact on the endpoints.
What do I think about the scalability of the solution?
We have around 80,000 users.
How are customer service and technical support?
They are good. They take a little bit of time, but they are good.
How was the initial setup?
It was very complex. We had many issues in integrating it with our enterprise solutions, such as Splunk, and third-party tools.
What about the implementation team?
We have seven or eight engineers for its maintenance.
What other advice do I have?
I would recommend this solution to others if they don't have many third-party tools. It is a very good solution.
I would rate Microsoft Defender for Endpoint a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Assistant Manager IT Infrastructure at a manufacturing company with 501-1,000 employees
Stable threat protection with good support but it's expensive and has license restrictions
Pros and Cons
- "It shows us the risky sign-ins, and if a user's password has been compromised."
- "I am not sure if I will be using this product in the future because of the price."
What is our primary use case?
We are using this solution for threat detection.
What is most valuable?
It shows us the risky sign-ins, and if a user's password has been compromised.
What needs improvement?
While have been using this solution for two years, I am not completely knowledgable.
Due to license restrictions, we cannot use all of the features that are offered.
I am not sure if I will be using this product in the future because of the price.
I would like to see better pricing for this solution in the future.
For how long have I used the solution?
I have been working with Microsoft Defender ATP for two years.
We are always using the latest version because it's on the cloud.
What do I think about the stability of the solution?
With what we have seen, it's a stable solution.
What do I think about the scalability of the solution?
We are not using it widely because of the licensing limits.
We have three users only for Defender ATP, and if we are using the Microsoft ATA it applies to 500 users.
How are customer service and technical support?
Technical support is good.
Which solution did I use previously and why did I switch?
We did not use another solution previous to Microsoft Defender ATP.
How was the initial setup?
The initial setup is straightforward. It's included with the Windows 10 Operating System.
There is no time taken for deployment as it is included with the operating system.
What about the implementation team?
We completed the installation ourselves.
We have 15 administrators to deploy and maintain this solution.
What's my experience with pricing, setup cost, and licensing?
Microsoft Defender ATP is expensive.
What other advice do I have?
Because of my lack of knowledge or experience with the solutions full capacity, I cannot recommend this solution or offer any advice.
I would rate this solution a five out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Microsoft Enterprise administrator at a comms service provider with 1,001-5,000 employees
Has prevented all viruses since we implemented it
Pros and Cons
- "It's really stable. I've used a lot of stuff, a lot of products, like ESET and Kaspersky. None of them are comparable with this one. This one is much better."
- "The end-user also cannot do some advanced actions on it. It's a little bit complicated for our end-user, so it needs to be simplified."
What is most valuable?
The solution is really fast. I have never experienced any viruses since I've been using it.
What needs improvement?
I think the console can be better.
The end-user also cannot do some advanced actions on it. It's a little bit complicated for our end-user, so it needs to be simplified.
I think the solution is complicated. This one is one of the concerns that I like to talk about because some end-users do not know how to navigate through the console and how to work with them. I think this is not such a big deal, but I know that there will be other things that may be important to us like, how we can centrally manage users and reports are really important for us. For example, in Kaspersky, we had a problem where we couldn't detect the attacks that we had in some of our zones in our data center. I think if Microsoft Windows Defender can report these things, it's going to be great.
For how long have I used the solution?
I've been using the solution for six years.
What do I think about the stability of the solution?
It's really stable. I've used a lot of products, like ESET and Kaspersky. None of them are comparable with this one. This one is much better.
What do I think about the scalability of the solution?
To scale the solution, I think you need more licenses but I'm not sure. We have 100 to 1,000 users. We just use it for some end users, not for all the users. The users are mainly end-users and a few admins. We plan to increase users annually.
Which solution did I use previously and why did I switch?
We used other solutions, like ESET and Kaspersky. We had to change at first due to user complaints, especially about Kaspersky, because it used a lot of the resources. So we switched to ESET but after some time we just switched to Windows Defender.
How was the initial setup?
The initial setup was really easy, a no brainer.
What about the implementation team?
I installed the solution on my own.
What other advice do I have?
I would recommend the solution because I can confidently tell everyone that this product is working very well and it's stable. You are always sure that they are able to deal with a virus or something else that may interrupt your work.
I would rate this solution nine out of 10.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Development Manager at S-ryhmä / S Group
Provides visibility into SOC workstations and stops threats from spreading to machines
Pros and Cons
- "We can react to threats faster and stop them from spreading from one machine to another. It protects from suspicious email attachment downloads. It will lock down the SOC and the workstations."
- "Microsoft Defender for Endpoint's licensing is confusing. It has conflicting information on the website. We also faced integration issues with other systems. It makes laptops slower than traditional antivirus systems."
What is our primary use case?
Microsoft Defender for Endpoint provides visibility into our workstations at SOC.
How has it helped my organization?
We can react to threats faster and stop them from spreading from one machine to another. It protects from suspicious email attachment downloads. It will lock down the SOC and the workstations.
What is most valuable?
It is an EDR product that offers much more information into what's happening at our workstations.
What needs improvement?
Microsoft Defender for Endpoint's licensing is confusing. It has conflicting information on the website. We also faced integration issues with other systems. It makes laptops slower than traditional antivirus systems.
For how long have I used the solution?
I have been working with the product for a year.
What do I think about the stability of the solution?
Microsoft Defender for Endpoint is stable.
What do I think about the scalability of the solution?
The tool's scalability is good, but we must consider the cost.
What was our ROI?
We get good ROI with the product's use.
What other advice do I have?
The product's threat intelligence prepares us for potential threats and helps us take proactive steps. Its vulnerability management feature is important to us.
Microsoft Defender for Endpoint has improved our security posture by giving visibility to our endpoints and vulnerabilities.
The tool helps us save months per year. It also helps us save money in manhours.
Microsoft Defender for Endpoint has reduced our time to respond and time to detect by a large margin.
We chose the product because we already use Microsoft products, and it better integrates with them.
I rate it an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Endpoint Protection Platform (EPP) Advanced Threat Protection (ATP) Anti-Malware Tools Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
CrowdStrike Falcon
Cisco Secure Endpoint
SentinelOne Singularity Complete
Fortinet FortiClient
Cortex XDR by Palo Alto Networks
Symantec Endpoint Security
Intercept X Endpoint
Trend Vision One Endpoint Security
Trellix Endpoint Security
Kaspersky Endpoint Security for Business
ESET Endpoint Protection Platform
HP Wolf Security
Check Point Harmony Endpoint
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Compare Microsoft Windows Defender and Symantec Endpoint Protection. How Do I Choose?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- What do you think of the integration of Azure AD Services, Defender for Endpoint, and Intune as comprehensive security solutions?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- Running Carbon Black Defense Along with Windows Defender
- How is Cortex XDR compared with Microsoft Defender?
- Which offers better endpoint security - Symantec or Microsoft Defender?
- How does Microsoft Defender for Endpoint compare with Carbon Black CB Defense?
- How would you compare between Microsoft Defender for Endpoint and Tanium EDR?