Microsoft Defender for Endpoint provides visibility into our workstations at SOC.
IT Development Manager at S-ryhmä / S Group
Provides visibility into SOC workstations and stops threats from spreading to machines
Pros and Cons
- "We can react to threats faster and stop them from spreading from one machine to another. It protects from suspicious email attachment downloads. It will lock down the SOC and the workstations."
- "Microsoft Defender for Endpoint's licensing is confusing. It has conflicting information on the website. We also faced integration issues with other systems. It makes laptops slower than traditional antivirus systems."
What is our primary use case?
How has it helped my organization?
We can react to threats faster and stop them from spreading from one machine to another. It protects from suspicious email attachment downloads. It will lock down the SOC and the workstations.
What is most valuable?
It is an EDR product that offers much more information into what's happening at our workstations.
What needs improvement?
Microsoft Defender for Endpoint's licensing is confusing. It has conflicting information on the website. We also faced integration issues with other systems. It makes laptops slower than traditional antivirus systems.
Buyer's Guide
Microsoft Defender for Endpoint
January 2025
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
For how long have I used the solution?
I have been working with the product for a year.
What do I think about the stability of the solution?
Microsoft Defender for Endpoint is stable.
What do I think about the scalability of the solution?
The tool's scalability is good, but we must consider the cost.
What was our ROI?
We get good ROI with the product's use.
What other advice do I have?
The product's threat intelligence prepares us for potential threats and helps us take proactive steps. Its vulnerability management feature is important to us.
Microsoft Defender for Endpoint has improved our security posture by giving visibility to our endpoints and vulnerabilities.
The tool helps us save months per year. It also helps us save money in manhours.
Microsoft Defender for Endpoint has reduced our time to respond and time to detect by a large margin.
We chose the product because we already use Microsoft products, and it better integrates with them.
I rate it an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Group IT Security Program Manager at Jotun
Native integration with OS gives it more granular capabilities, but management console needs work
Pros and Cons
- "The most valuable feature is its ability to effectively detect threats. It has the EDR feature, endpoint detection and response, and that is very good."
- "The management console is something that can be improved."
What is most valuable?
The most valuable feature is its ability to effectively detect threats. It has the EDR feature, endpoint detection and response, and that is very good.
What needs improvement?
The management console is something that can be improved.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for about two years.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
It is scalable.
How was the initial setup?
The initial setup is quite simple because it is built into the operating system.
Which other solutions did I evaluate?
Microsoft Defender has more granular capabilities because of the native operating system that it is built into. It is better integrated into the operating system because both the product and the OS are from Microsoft. That is an advantage.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Microsoft Defender for Endpoint
January 2025
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.
Stable, embedded in Microsoft Windows, and high performance
Pros and Cons
- "The performance of Microsoft Defender for Endpoint has been good."
- "Microsoft Defender for Endpoint could improve by providing more user-friendly dashboards. They may be complicated for some."
What is our primary use case?
Microsoft Defender for Endpoint is used for securing endpoints from threats.
What is most valuable?
The performance of Microsoft Defender for Endpoint has been good.
What needs improvement?
Microsoft Defender for Endpoint could improve by providing more user-friendly dashboards. They may be complicated for some.
In a future release, they should add a feature for patch management.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for one year.
What do I think about the stability of the solution?
Microsoft Defender for Endpoint has been stable.
What do I think about the scalability of the solution?
The scalability of Microsoft Defender for Endpoint has been good.
We have approximately five clients using the solution. We have thousands of licensees for this solution within my company.
How are customer service and support?
The technical from Microsoft could be better. It is not as good as other solutions.
How was the initial setup?
The implementation of Microsoft Defender for Endpoint because it is pre-installed with Microsoft Windows. Other solutions you have to install separately, such as Check Point.
What's my experience with pricing, setup cost, and licensing?
The license for Microsoft Defender for Endpoint is included in the license for the Microsoft Windows operating system.
What other advice do I have?
I would recommend this solution to others.
I rate Microsoft Defender for Endpoint a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Specialist Consultant in Microsoft Security at a tech services company with 501-1,000 employees
The tamper protection keeps hackers from entering a machine, encrypting it, and changing passwords
Pros and Cons
- "Auto-remediation: When the product sees malware, it resolves the issue immediately. This protects the machine."
- "It needs to improve the cybersecurity for lateral movements. For example, when a hacker tries to enter a machine, they try to get the password by doing a lateral movement."
What is our primary use case?
We use it for antivirus. You can use it for malware and Zero Trust. Some people use it for fact-checking too. I can also use it with Intune, which is good.
We deploy Microsoft Defender on all kinds of devices, including Microsoft, iOS, and Mac.
What is most valuable?
Auto-remediation: When the product sees malware, it resolves the issue immediately. This protects the machine.
I like the tamper protection. For example, if I buy a notebook with Windows 10 and put Microsoft Defender on it, then I can activate the tamper protection. This keeps people from entering the machine, encrypting it, and changing passwords.
Microsoft Defender is fully integrated with Azure Sentinel. In addition, GPO can be connected with Microsoft Defender and Azure AD.
What needs improvement?
It needs to improve the cybersecurity for lateral movements. For example, when a hacker tries to enter a machine, they try to get the password by doing a lateral movement.
With Windows 10, version 18.0.3, I couldn't see the documentation to open the ports. If you don't open the ports, then the machine can't communicate with the console.
What do I think about the stability of the solution?
I like its stability a lot.
What do I think about the scalability of the solution?
You push out all the devices that you want. There is no limitation beyond money and licenses.
Which solution did I use previously and why did I switch?
In the past, I have used McAfee and Kaspersky.
I only work with Microsoft products right now. It integrates well with other products. I also work with Microsoft Defender for Identity.
How was the initial setup?
The deployment process is not difficult because Microsoft Defender comes with Windows 10. You just right click, then it connects you with Azure.
There are other processes that can be connected, e.g., Microsoft Download Center.
What about the implementation team?
I implement Microsoft Defender for Endpoint. It takes me one or two days to design Microsoft Defender for Endpoint. It is easy to do this, and the more you implement, the easier it gets over time.
Sometimes, when I change the configuration, I have to wait six to eight hours.
What's my experience with pricing, setup cost, and licensing?
It is so expensive. It isn't cheaper than McAfee or other solutions.
Which other solutions did I evaluate?
I prefer Microsoft Defender for Endpoint instead of McAfee, Kaspersky, and other products.
What other advice do I have?
I would rate this solution as 10 out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Security Specialist at Engen
Provides good security features and can be viewed in the central console
Pros and Cons
- "Provides good security features and you can view it in the central console."
- "Lacks some additional integration."
What is our primary use case?
We use this product for our endpoint detection and all the remediation.
What is most valuable?
The solution provides good security features. The key valuable feature for me is that you can view it in the central console.
What needs improvement?
I'd like to see more integration in the next release and the solution should be file protected.
For how long have I used the solution?
I've been using this solution for five years.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
I'd like to see a quicker response time from the company's technical support.
How was the initial setup?
The initial setup was straightforward. It didn't take long and was part of the deployment of our endpoints, and part of the integration. We currently have around 3,000 users and no plans to expand. We have four people involved with maintenance.
What other advice do I have?
I recommend this solution and rate it eight out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Unified Communications Manager at Jouve
Easy to deploy with great cloud provisioning and excellent functionality
Pros and Cons
- "It's a Microsoft product; it's easier to deploy this product than other options."
- "It would be helpful if they offered video tutorial guides."
What is our primary use case?
We're using the solution on our endpoints.
What is most valuable?
The functionality is very important to us.
The cloud provisioning is great.
It's a Microsoft product, therefore, it's easier to deploy this product than other options. It's very important for us to have a simple way to deploy new PCs when we buy the new PCs. We don't want that deployment to be a burden. The easy deployment feature is very helpful.
What needs improvement?
At the moment we are currently testing it. We are not major users of the product, and therefore we have no idea of what it can and can't do just yet.
At this time we don't have any recommendations concerning the Windows product interface.
It would be helpful if they offered video tutorial guides.
For how long have I used the solution?
I've used the solution for three or four months.
What do I think about the stability of the solution?
We are testing it right now and we didn't get into the production state just yet. Therefore, it's hard to gauge the capabilities in terms of stability. So far, however, it has been stable.
What do I think about the scalability of the solution?
The scalability is okay.
How are customer service and support?
Support is always okay. I've always had a positive experience dealing with support.
How was the initial setup?
The deployment is seamless and super simple. It's not complex at all, and that's the main selling point for us.
What's my experience with pricing, setup cost, and licensing?
We did negotiate on the pricing, however, I can't speak to the exact costs involved.
Which other solutions did I evaluate?
We did not really compare this solution to other options. The advantage is that this solution is available on mobile devices, and we needed something that covered everything, from desktops and laptops to mobile. Therefore, we didn't really consider anything else.
What other advice do I have?
We are Microsoft customers. We don't have a special relationship with the organization.
We are using the latest version of the solution.
It's a good product overall. I would rate it an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Head of Information Security at K2 Baseline Sdn Bhd
Stable and easy to use, but needs quicker detection capability and more frequent updates
Pros and Cons
- "It is stable and easy to use. Everything is okay, and there are no performance issues."
- "Its detection is not as quick. There should also be more frequent updates."
What is our primary use case?
I use it mostly to detect threats or viruses. I am using its latest version.
What is most valuable?
It is stable and easy to use. Everything is okay, and there are no performance issues.
What needs improvement?
Its detection is not as quick. There should also be more frequent updates.
For how long have I used the solution?
I have been using this solution for maybe five years.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
We have about 20 users.
How are customer service and support?
I have not contacted Microsoft's technical support.
Which solution did I use previously and why did I switch?
I didn't use or evaluate other solutions.
How was the initial setup?
Its installation is very easy. It came with Windows.
What about the implementation team?
I can install it myself. We have three teams for deployment and maintenance.
What's my experience with pricing, setup cost, and licensing?
It came with Windows.
What other advice do I have?
I would recommend this solution. I would rate it a seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior System Administrator at Debre Markos University
Easy to use interface, user-friendly, and stable
Pros and Cons
- "The solution has an easy-to-use interface, is always updated, and is user-friendly."
- "The solution could improve by providing more integration."
What is our primary use case?
I use Microsoft Defender for Endpoint protection on my personal computer.
What is most valuable?
The solution has an easy-to-use interface, is always updated, and is user-friendly.
What needs improvement?
The solution could improve by providing more integration.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for approximately one year.
What do I think about the stability of the solution?
The solution is stable and secure.
What do I think about the scalability of the solution?
I have found the scalability quite good.
How was the initial setup?
The installation is simple.
What about the implementation team?
I did the implementation of the solution.
What's my experience with pricing, setup cost, and licensing?
The solution is free and comes with Windows.
What other advice do I have?
I rate Microsoft Defender for Endpoint a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2025
Product Categories
Endpoint Protection Platform (EPP) Advanced Threat Protection (ATP) Anti-Malware Tools Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
CrowdStrike Falcon
Cisco Secure Endpoint
SentinelOne Singularity Complete
Fortinet FortiClient
Cortex XDR by Palo Alto Networks
Symantec Endpoint Security
Intercept X Endpoint
Trend Vision One Endpoint Security
Trellix Endpoint Security
Kaspersky Endpoint Security for Business
ESET Endpoint Protection Platform
HP Wolf Security
Check Point Harmony Endpoint
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Compare Microsoft Windows Defender and Symantec Endpoint Protection. How Do I Choose?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- What do you think of the integration of Azure AD Services, Defender for Endpoint, and Intune as comprehensive security solutions?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- Running Carbon Black Defense Along with Windows Defender
- How is Cortex XDR compared with Microsoft Defender?
- Which offers better endpoint security - Symantec or Microsoft Defender?
- How does Microsoft Defender for Endpoint compare with Carbon Black CB Defense?
- How would you compare between Microsoft Defender for Endpoint and Tanium EDR?