Microsoft Defender for Endpoint gives us a second layer of security as well as the third layer of security. One of them is interested in web security and email security. One of them, similar to Cisco, is a Cisco FirePOWER. These are a compilation or a group of devices for security.
Works at a financial services firm with 51-200 employees
Simple to install and maintain, but the support could be faster, and more responsive
Pros and Cons
- "The installation is straightforward."
- "Phishing and Malware detection could be better."
What is our primary use case?
What needs improvement?
We had some issues where phishing and malware were not detected and were allowed to pass unless I mentioned it or we forced the phishing or malware to be blocked, I can't rely on that alone.
Phishing and Malware detection could be better.
Technical support needs improvement.
For how long have I used the solution?
I have been working with Microsoft Defender for Endpoint for one year.
What do I think about the stability of the solution?
It is stable for the time being.
Buyer's Guide
Microsoft Defender for Endpoint
December 2024
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
What do I think about the scalability of the solution?
I can't add more layers of security because of my budget and business plan, so I try to choose the best and most preferable option for me and my company.
I would rate the scalability a seven out of ten.
In one company, we have two administrators and 30 employees who use this solution.
On a short-term plan, I will not increase the usage. On a larger scale, we intend to increase the license.
How are customer service and support?
In my opinion, technical support is not as effective as it was before. They take a long time to support and investigate the issue.
It takes a long time for them to support and investigate the issue. I believe they must crush the time in order to provide us with our needs, and our objectives.
Which solution did I use previously and why did I switch?
There are applications and solutions that we have used for five or more years. We almost used Microsoft Link but have since switched to Microsoft Teams and Skype for business. We almost exclusively use Cisco products such as Cisco EMC, Cisco Web security, and Cisco Meraki.
How was the initial setup?
The installation is straightforward. It's a cloud solution that requires some configuration running on the cloud.
The deployment takes a couple of hours to complete.
It's a different story when it comes to security. It takes a different approach. It requires two an administrator and a manager to maintain this solution.
What about the implementation team?
Sometimes the installation and deployment are done by the technical team, and sometimes it's done by others.
What's my experience with pricing, setup cost, and licensing?
Licensing fees are paid annually through a partner.
What other advice do I have?
If I do recommend it, it will not be solely for security purposes. It is possibly for a first-line security platform, and it is required to build a second, third, and possibly fourth business security layer.
I would rate Microsoft Defender for Endpoint a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cyber Security BA/BSA at a financial services firm with 10,001+ employees
Straightforward to set up with good technical support and good stability
Pros and Cons
- "Technical support is good."
- "There are likely some technical improvements or features that could be added, however, I cannot say, off the top of my head, what they would be."
What is our primary use case?
Usually, the solution is used in relation to keys management. We implemented a program for it, for the lifecycle of the keys. We've also used it for certificate management.
What is most valuable?
The initial setup is very straightforward.
The stability is very good.
Technical support is good.
The solution is in good condition and offers good functionality.
What needs improvement?
There are likely some technical improvements or features that could be added, however, I cannot say, off the top of my head, what they would be.
For how long have I used the solution?
I used the solution in relation to scoping a project. I was doing business analysis.
What do I think about the stability of the solution?
The solution was very stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
The technical support for Microsoft is very good.
How was the initial setup?
The initial setup is not difficult or complex. It's very simple and straightforward.
What's my experience with pricing, setup cost, and licensing?
I do not know how much it costs per month. I cannot say how it compares against the rates of the competition.
What other advice do I have?
We are a Microsoft Customer.
I'm not sure if I would recommend the solution to others. It depends on their requirements. It needs to fit a company's use cases.
I would rate the solution at an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Microsoft Defender for Endpoint
December 2024
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,067 professionals have used our research since 2012.
Managing Director at FORESEC
Fair price and useful for protection, but should have the ability to recover data from the last normal copy
Pros and Cons
- "We have just started to implement it. It is useful for protection from malware and ransomware."
- "Auto recovery is the most important feature that we would need from this solution. For decryption, similar to Malwarebytes, there should be something to be able to recover the data up to the last normal status. Its ability to recover data to the last normal copy must not exceed 5 to 10 minutes."
What is our primary use case?
We are using it for protection. We had a request from one of our customers, and we just started to implement it. We don't have any great idea about it. We are in the process of implementing it for the first time.
We are using its latest version. It is on-prem. The problem with going for a cloud version is that most of our customers prefer to work with on-prem solutions. So, we need all the features to be available on-prem as well as on the cloud.
What is most valuable?
We have just started to implement it. It is useful for protection from malware and ransomware. We are not exactly sure about zero-day, but we are trying to see if it will be effective for everyday antivirus purposes.
What needs improvement?
Auto recovery is the most important feature that we would need from this solution. For decryption, similar to Malwarebytes, there should be something to be able to recover the data up to the last normal status. Its ability to recover data to the last normal copy must not exceed 5 to 10 minutes.
For how long have I used the solution?
We just started to use it.
What do I think about the stability of the solution?
We need to test its functionality in heavy environments.
How are customer service and technical support?
Their support could be faster through the phone. The support through chat is very unuseful. It takes a lot of time and effort and but does not help in any way. We provide the first line of support to customers, so it is not a big issue for us.
Which solution did I use previously and why did I switch?
We work on most of the protection products, such as Kaspersky, Malwarebytes. We normally use a lot of them. We had a request from one of our customers, so we started to implement Microsoft Defender for Endpoint.
How was the initial setup?
Its initial setup is straightforward. The solution itself doesn't take more than 15 to 20 minutes, but the configuration duration depends on the environment, such as the number of policies, users, etc. It will vary according to the environment in which you are doing the implementation.
What about the implementation team?
We implement it ourselves. Currently, we have only one customer of this solution.
What's my experience with pricing, setup cost, and licensing?
Its price is fair. It has approximately the same price as the other products such as Kaspersky. It is much cheaper than Malwarebytes.
What other advice do I have?
I would rate Microsoft Defender for Endpoint a seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Cyber Security Specialist at a healthcare company with 10,001+ employees
Good support and valuable EDR feature, but not stable and not suitable for enterprises with lots of other processes and third-party tools
Pros and Cons
- "The EDR feature is most valuable."
- "It is currently more suitable for end-users rather than enterprises with lots of other processes and third-party tools. It needs improvement on that front. We had many issues while integrating it with our enterprise solutions, such as Splunk, and third-party tools. It provides everything via APIs. Other vendors provide integration with third-party tools, but Microsoft doesn't do that. It is also logging too much and is not serialized from the process aspect. It has all the data, but it is not in a proper format or not properly indexed, which doesn't make it easier for enterprises to use this data. Other vendors provide troubleshooting information that can be used to troubleshoot issues, but Microsoft doesn't provide anything like that."
What is our primary use case?
We use it for our endpoint detection and response capability.
What is most valuable?
The EDR feature is most valuable.
What needs improvement?
It is currently more suitable for end-users rather than enterprises with lots of other processes and third-party tools. It needs improvement on that front. We had many issues while integrating it with our enterprise solutions, such as Splunk, and third-party tools. It provides everything via APIs. Other vendors provide integration with third-party tools, but Microsoft doesn't do that.
It is also logging too much and is not serialized from the process aspect. It has all the data, but it is not in a proper format or not properly indexed, which doesn't make it easier for enterprises to use this data.
Other vendors provide troubleshooting information that can be used to troubleshoot issues, but Microsoft doesn't provide anything like that.
For how long have I used the solution?
I have been using this solution for six months.
What do I think about the stability of the solution?
It is still a new product, and there are many reported bugs in terms of stability and impact on the endpoints.
What do I think about the scalability of the solution?
We have around 80,000 users.
How are customer service and technical support?
They are good. They take a little bit of time, but they are good.
How was the initial setup?
It was very complex. We had many issues in integrating it with our enterprise solutions, such as Splunk, and third-party tools.
What about the implementation team?
We have seven or eight engineers for its maintenance.
What other advice do I have?
I would recommend this solution to others if they don't have many third-party tools. It is a very good solution.
I would rate Microsoft Defender for Endpoint a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Infrastructure Analyst at a energy/utilities company with 1,001-5,000 employees
Covers almost all threats, doesn't slow down systems, and helps with compliance and business uptime
Pros and Cons
- "It doesn't cause the slowness of the system, which is one of the reasons why I like it."
- "They should bring back the feature of a dedicated proxy device for communication to the cloud. As of now, all the agents are required to send the logs directly to the cloud. There should be a solution where you can put a proxy and all the logs are consolidated, like a forwarder."
What is our primary use case?
I have tried so many antiviruses personally, but this one is integrated with the operating system. That's one of the main reasons for considering this.
How has it helped my organization?
The main benefits are compliance and protection from threats.
It helps us to avoid disruption in the business. It helps us see if other solutions are causing any slowness to our end-user machines. We can see if there are any service availability issues. Operations-wise, it helps us a lot to maintain the uptime of our business.
It helps us prioritize threats across our enterprise, which is very important and one of our priorities.
We have the Defender for cloud applications. It's very easy to integrate. It's straightforward. These solutions work natively together to deliver coordinated detection and response across our environment, which is very important for us.
We did extensive testing of its functionality, and it's very effective. It covers almost all the new, unknown, and known threats.
It helps automate routine tasks and the finding of high-value alerts, which is helpful for incident response and SLAs. It has saved us 50% of the time to respond to the incident.
It helps us to be proactive. It can detect unknown threats and alerts us. We're able to identify any malicious sign-ins or logins.
It has decreased our time to detect and respond. Previously, we were doing it manually. It took one hour to two hours to detect and respond. Now, it takes us minutes.
What is most valuable?
It has very good detection and protection capabilities. They have a new feature for ransomware protection.
It doesn't cause the slowness of the system, which is one of the reasons why I like it.
What needs improvement?
There is complexity in accessing the dashboard. Microsoft security suite has a different URL per service or per application. If there was one single place of information, that would help.
They should bring back the feature of a dedicated proxy device for communication to the cloud. As of now, all the agents are required to send the logs directly to the cloud. There should be a solution where you can put a proxy and all the logs are consolidated, like a forwarder.
For how long have I used the solution?
I've been using it for about five years.
What do I think about the stability of the solution?
It's very stable.
What do I think about the scalability of the solution?
It's very scalable. We have deployed it only to 250 endpoints for now. It's not enterprise-wide. We have plans to increase its usage.
How are customer service and support?
I haven't encountered many issues so far. Their support is good. I would rate them an 8 out of 10.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used another solution. The switch over to this solution was a management decision.
How was the initial setup?
We have a hybrid deployment with the Microsoft Azure cloud. The initial setup was complex. There were some issues because a lot of prerequisites needed to be accomplished. It took us about three months.
We had a staged approach. We first onboarded non-critical assets and then moved to critical assets.
It takes time to realize the benefits from the time of deployment. It took us about two years.
What about the implementation team?
We had around five people for deployment. Some of them were testers, and some of them were admins for the configuration and deployment of agents.
It requires maintenance. We have cloud administrators and desktop support for endpoints.
Which other solutions did I evaluate?
We did look into other solutions. We have criteria for evaluation. The features that stood out were their reputation and innovation.
What other advice do I have?
I would recommend Microsoft Defender. They are a leader, and they have many deployment use cases. However, it also depends on the requirements of a company. There is no one-size-fits-all. Each company has its own unique requirements.
I would rate it an 8 out of 10.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Stable, embedded in Microsoft Windows, and high performance
Pros and Cons
- "The performance of Microsoft Defender for Endpoint has been good."
- "Microsoft Defender for Endpoint could improve by providing more user-friendly dashboards. They may be complicated for some."
What is our primary use case?
Microsoft Defender for Endpoint is used for securing endpoints from threats.
What is most valuable?
The performance of Microsoft Defender for Endpoint has been good.
What needs improvement?
Microsoft Defender for Endpoint could improve by providing more user-friendly dashboards. They may be complicated for some.
In a future release, they should add a feature for patch management.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for one year.
What do I think about the stability of the solution?
Microsoft Defender for Endpoint has been stable.
What do I think about the scalability of the solution?
The scalability of Microsoft Defender for Endpoint has been good.
We have approximately five clients using the solution. We have thousands of licensees for this solution within my company.
How are customer service and support?
The technical from Microsoft could be better. It is not as good as other solutions.
How was the initial setup?
The implementation of Microsoft Defender for Endpoint because it is pre-installed with Microsoft Windows. Other solutions you have to install separately, such as Check Point.
What's my experience with pricing, setup cost, and licensing?
The license for Microsoft Defender for Endpoint is included in the license for the Microsoft Windows operating system.
What other advice do I have?
I would recommend this solution to others.
I rate Microsoft Defender for Endpoint a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Security Consultant at a tech services company with 51-200 employees
Makes monitoring a lot easier and minimizes on-prem administration
Pros and Cons
- "DFE organizational security posture has been a positive experience. We're a Microsoft house. It works. Once it's deployed and once it's configured, it works and our clients tend to be happy with it. I haven't really experienced anyone who has been so unsatisfied with the platform that they wanted to go a couple of different directions, that has never happened to me."
- "Monitoring can always be better, onboarding can be a little bit faster, log collection could be easier, they could streamline the dashboard. They could maybe split it up into different workspaces and have the ability to segment groups a little bit more."
What is our primary use case?
The area that I focus on the most is Endpoint Protection. We use Intune to build custom devices and configurations, to push out group policies, and do quite a bit with Azure Log Analytics.
I'm writing a script from a multi-home deployment of the MMA Agent. The use case varies a lot, depending on the clients' needs. Our clients tend to be pretty big companies. The smallest client I have is about 600 people. Our biggest client is about 50,000.
How has it helped my organization?
DFE organizational security posture has been a positive experience. We're a Microsoft house. It works. Once it's deployed and once it's configured, it works and our clients tend to be happy with it. I haven't really experienced anyone who has been so unsatisfied with the platform that they wanted to go a couple of different directions, that has never happened to me.
What is most valuable?
It's Microsoft native. Microsoft is the corporate default, so it makes sense to use security platforms that are baked into the Microsoft platform. That's probably the most valuable aspect of it.
It has specific features that improve our customer's security posture. It makes the monitoring a lot easier and minimizes on-prem administration. A lot of the administrative stuff is all folded into Azure. It makes things easier.
The platform just makes things easier compared to on-prem or hybrid solutions because if you start working in an on-prem solution, most of the time it's going to be a battlefield.
DFE affects the end-user experience when it's deployed. The more freedom a user has on the device, the more they're used to doing things their own way. By locking things down, by having device configurations, you disrupt the workflow. You need a lot of user education where you have to explain why you're doing these things. I'm a part of security. It's twofold, in that users have to get used to the new configurations. And the reason why we might take a little bit longer with pilot phases is that we have to identify how it'll affect the users and how the differences of different business units will be affected. Developers need a more open environment than other solutions.
What needs improvement?
Everything can always be improved. Improvements would depend on the client.
Monitoring can always be better, onboarding can be a little bit faster, log collection could be easier, they could streamline the dashboard. They could maybe split it up into different workspaces and have the ability to segment groups a little bit more.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint on and off for about three or four years.
It's only the last two and a half years that it's been a big part of my job.
What do I think about the stability of the solution?
Microsoft has some creative accounting when they promise an SLA of 99.99%. But it is generally good. There's always going to be a problem with the cloud. If it works 99% of the time, that's great.
The frustrating thing is, you're not sure if there's a problem with your configuration or if the service itself is down because Microsoft tends to only report that the service is down much later than when you started experiencing things. So sometimes I have to jump onto a private forum or a Slack channel and ask other consultants if they experienced something similar. But when it works, it works. There's never going to be a cloud solution that has 100% uptime.
What do I think about the scalability of the solution?
Scalability is fine. I mainly work with implementation, so I haven't really had to mess around with the scalability. I'm responsible for setting up security policies, and then if they want to do scalability, that's another team. I sit in security.
How are customer service and technical support?
I haven't worked with support. I generally don't use Microsoft Support.
We were Microsoft partners last year. We're gold partners where we won security partners of the year, so we have an account manager. If it really hits the fan, then I would just talk to him.
Which solution did I use previously and why did I switch?
I've been an IaaS specialist since I began my career. I've done Apple MDM solutions and I've done Google Workspace, but when it comes to actual IaaS, I can't really compare. Because we're a Microsoft house, we generally don't use third parties or competitors.
How was the initial setup?
The complexity of the setup depends on the environment. If it's Greenfield, it's super easy. I've been doing this for two to three years now. Most of the time it's easy. The larger companies have more complex networks and systems. The smaller the company, the easier it is to deploy.
The beginning of the project, like scoping, implementation, the entire process, or just the actual deployment depends on the size of the company. For smaller companies, we'll push some policies out. We'll do a week or two of a pilot phase where we identify different stakeholders and different business units. We collect feedback from them, keep an eye out on the audit logs and if that goes well, then we go into phase two, which takes another week or two where we slowly push out, if it's an accounting department with 60 people, then we'll do batches of 20. We'll have a pilot group of five and then we'll push it out to 20 people at a time.
What's my experience with pricing, setup cost, and licensing?
The project managers worry about the licenses. I get my scope, I know the limitations I have to work with, and then I just make a solution based on that. I'm a very technical consultant and I don't really care about licenses, that doesn't really have anything to do with me.
What other advice do I have?
My advice would be to start small, don't start a project thinking that it's the best solution, and bowl it out straight away. Take your time. Don't think that you'll be able to incorporate the platform within a month, although that would depend on the size of your business. Take your time, there's no rush, be patient. Because there will always be some problems.
I would rate it an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Managing Director at a financial services firm with 10,001+ employees
Reliable, well-priced, and it is easy to install
Pros and Cons
- "We use Microsoft Defender for the antivirus."
- "The interface could be improved."
What is our primary use case?
There are endpoints that are not in our organization's network but are connected directly to the web. We use Microsoft Defender for the antivirus.
We are not dealing with this solution daily, just when there is an issue from time to time.
What needs improvement?
The interface could be improved.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for a couple of years.
What do I think about the stability of the solution?
It's a stable solution.
What do I think about the scalability of the solution?
We are only running it on a few workstations. The scalability is okay.
It's run on 10 out of 3,000 workstations and we plan to continue using it.
We have no more than 10 users in our organization.
Which solution did I use previously and why did I switch?
We are also using Symantec.
We have a few endpoints where we use Microsoft Defender because we cannot use the Symantec Sets.
How was the initial setup?
The initial setup was straightforward. It was easy to install and t only took a couple of minutes.
There is no team for maintenance. If there is an issue, the security team helps to resolve it.
What about the implementation team?
We completed the deployment and implementation ourselves.
What's my experience with pricing, setup cost, and licensing?
We don't have an issue with the price.
We have a bundle where the price includes all Microsoft products.
This is an area that I am not dealing with. I don't have all of the information.
What other advice do I have?
It's pretty good.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Endpoint Protection Platform (EPP) Advanced Threat Protection (ATP) Anti-Malware Tools Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
CrowdStrike Falcon
Cisco Secure Endpoint
SentinelOne Singularity Complete
Fortinet FortiClient
Cortex XDR by Palo Alto Networks
Symantec Endpoint Security
Intercept X Endpoint
Trend Vision One Endpoint Security
Trellix Endpoint Security
Kaspersky Endpoint Security for Business
ESET Endpoint Protection Platform
Check Point Harmony Endpoint
VMware Carbon Black Endpoint
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- What do you think of the integration of Azure AD Services, Defender for Endpoint, and Intune as comprehensive security solutions?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- Running Carbon Black Defense Along with Windows Defender
- How is Cortex XDR compared with Microsoft Defender?
- Which offers better endpoint security - Symantec or Microsoft Defender?
- How does Microsoft Defender for Endpoint compare with Carbon Black CB Defense?
- How would you compare between Microsoft Defender for Endpoint and Tanium EDR?
- How does pricing work for Microsoft Defender for Endpoint?