Try our new research platform with insights from 80,000+ expert users
Hoong Jon Lee - PeerSpot reviewer
Group IT Security Program Manager at Jotun
Real User
Native integration with OS gives it more granular capabilities, but management console needs work
Pros and Cons
  • "The most valuable feature is its ability to effectively detect threats. It has the EDR feature, endpoint detection and response, and that is very good."
  • "The management console is something that can be improved."

What is most valuable?

The most valuable feature is its ability to effectively detect threats. It has the EDR feature, endpoint detection and response, and that is very good.

What needs improvement?

The management console is something that can be improved.

For how long have I used the solution?

I have been using Microsoft Defender for Endpoint for about two years.

What do I think about the stability of the solution?

It is stable.

Buyer's Guide
Microsoft Defender for Endpoint
February 2025
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.

What do I think about the scalability of the solution?

It is scalable.

How was the initial setup?

The initial setup is quite simple because it is built into the operating system.

Which other solutions did I evaluate?

Microsoft Defender has more granular capabilities because of the native operating system that it is built into. It is better integrated into the operating system because both the product and the OS are from Microsoft. That is an advantage.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1757103 - PeerSpot reviewer
Cyber Security Manager at a manufacturing company with 1,001-5,000 employees
Real User
Comes with awesome threat hunting capabilities, and is great for investigating what's happening on machines
Pros and Cons
  • "It's great for investigating what's happening on a machine. They show a whole bunch of machine timeline events that are related to a security incident. They have quite good details on the things related to threat and vulnerability management, such as any weakness that has been disclosed publicly, assets that are exposed, and if there is an exploit active in the wild for that vulnerability. It can provide you with all such information, which is cool."
  • "It can get a bit laggy sometimes. Other than that, we don't have any issues. They constantly tweak it and fix it up based on users' feedback. It has improved a lot over the past four years. Defender for Endpoint never really used to be a good endpoint security solution, but over the past couple of years, Microsoft has invested heavily in it. So, it has come a long way in all aspects of endpoint security. If they want to make it better, they should just continue investing in the current path of what they've been doing over the past couple of years."

What is our primary use case?

It is an Endpoint Detection and Response system (EDR), and it seems the new term is XDR. We use it for anti-malware protection. It protects from a virus, worm, ransomware, and other similar things. 

How has it helped my organization?

It can automatically scan and remediate stuff without an administrator doing anything. We use it for threat and vulnerability management. There are components in there that will tell us about any vulnerable software running on endpoints. There are a whole bunch of other things too.

What is most valuable?

It's great for investigating what's happening on a machine. They show a whole bunch of machine timeline events that are related to a security incident. They have quite good details on the things related to threat and vulnerability management, such as any weakness that has been disclosed publicly, assets that are exposed, and if there is an exploit active in the wild for that vulnerability. It can provide you with all such information, which is cool. 

It has got some awesome threat hunting capabilities. It can search for malicious activity that could indicate that an asset is being compromised, but it is not something to which you would have necessarily got alerted.

We're fully Microsoft, it integrates with other Microsoft security products very well. Its interface is also fine.

What needs improvement?

It can get a bit laggy sometimes. Other than that, we don't have any issues. They constantly tweak it and fix it up based on users' feedback. It has improved a lot over the past four years. Defender for Endpoint never really used to be a good endpoint security solution, but over the past couple of years, Microsoft has invested heavily in it. So, it has come a long way in all aspects of endpoint security. If they want to make it better, they should just continue investing in the current path of what they've been doing over the past couple of years.

For how long have I used the solution?

I have been using this solution for nearly four years.

What do I think about the stability of the solution?

It can get a little laggy sometimes, but overall, it's fine when investigating events.

What do I think about the scalability of the solution?

It is easy to scale.

How are customer service and support?

There are different levels of technical support that you can purchase from Microsoft. We don't have the top level, but we used to have the top level, and that was good. I would rate them a five out of five. They've got a dedicated team specifically looking at threats for all their customers. 

How was the initial setup?

I was not involved in its setup. I am only a user of the solution, but I'm pretty sure it's pretty straightforward. It's just deployed by Intune or a partial script or something like that.

What about the implementation team?

It was implemented internally. In terms of maintenance, it generally doesn't require any maintenance. There are some policy configuration changes that we can tweak, but the signatures, behavior analysis, and all similar things in the engine are kept up to date by them. We have four people who are dealing with this product.

What's my experience with pricing, setup cost, and licensing?

Licensing models of Microsoft are renowned for being complex. We just purchased the whole E5 stack. With E5 licenses for users, we get access to a bunch of features that are not just related to security. I would rate them a three out of five in terms of pricing.

Which other solutions did I evaluate?

One of the things that I like to constantly do is assess other vendors in the same space. We get vendor demonstrations, and for the most of it, it seems like Defender is well truly up there with the other best players in the market. I've never done a proof of concept with any other tool, so I can't really compare it with others. Most of the time, vendor demonstrations are all about glitz and glam to sell their product and show how much better they are than competitors.

What other advice do I have?

I would advise doing your due diligence. This is more than just an endpoint security solution, and sometimes, you've got to think of your technology stacks before applying or purchasing certain security solutions and see if they're applicable to your environment. 

I would rate it an eight out of 10. No endpoint solution is ever going to be able to be perfectly good at stopping all types of threats. No endpoint solution would ever get a 10 in my point of view. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Microsoft Defender for Endpoint
February 2025
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
838,713 professionals have used our research since 2012.
reviewer1596288 - PeerSpot reviewer
Specialist Consultant in Microsoft Security at a tech services company with 501-1,000 employees
Consultant
The tamper protection keeps hackers from entering a machine, encrypting it, and changing passwords
Pros and Cons
  • "Auto-remediation: When the product sees malware, it resolves the issue immediately. This protects the machine."
  • "It needs to improve the cybersecurity for lateral movements. For example, when a hacker tries to enter a machine, they try to get the password by doing a lateral movement."

What is our primary use case?

We use it for antivirus. You can use it for malware and Zero Trust. Some people use it for fact-checking too. I can also use it with Intune, which is good. 

We deploy Microsoft Defender on all kinds of devices, including Microsoft, iOS, and Mac.

What is most valuable?

Auto-remediation: When the product sees malware, it resolves the issue immediately. This protects the machine.

I like the tamper protection. For example, if I buy a notebook with Windows 10 and put Microsoft Defender on it, then I can activate the tamper protection. This keeps people from entering the machine, encrypting it, and changing passwords.

Microsoft Defender is fully integrated with Azure Sentinel. In addition, GPO can be connected with Microsoft Defender and Azure AD.

What needs improvement?

It needs to improve the cybersecurity for lateral movements. For example, when a hacker tries to enter a machine, they try to get the password by doing a lateral movement. 

With Windows 10, version 18.0.3, I couldn't see the documentation to open the ports. If you don't open the ports, then the machine can't communicate with the console.

What do I think about the stability of the solution?

I like its stability a lot.

What do I think about the scalability of the solution?

You push out all the devices that you want. There is no limitation beyond money and licenses.

Which solution did I use previously and why did I switch?

In the past, I have used McAfee and Kaspersky. 

I only work with Microsoft products right now. It integrates well with other products. I also work with Microsoft Defender for Identity.

How was the initial setup?

The deployment process is not difficult because Microsoft Defender comes with Windows 10. You just right click, then it connects you with Azure. 

There are other processes that can be connected, e.g., Microsoft Download Center.

What about the implementation team?

I implement Microsoft Defender for Endpoint. It takes me one or two days to design Microsoft Defender for Endpoint. It is easy to do this, and the more you implement, the easier it gets over time.

Sometimes, when I change the configuration, I have to wait six to eight hours.

What's my experience with pricing, setup cost, and licensing?

It is so expensive. It isn't cheaper than McAfee or other solutions.

Which other solutions did I evaluate?

I prefer Microsoft Defender for Endpoint instead of McAfee, Kaspersky, and other products.

What other advice do I have?

I would rate this solution as 10 out of 10.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Carlo Du Plessis - PeerSpot reviewer
Security Specialist at Engen
Real User
Provides good security features and can be viewed in the central console
Pros and Cons
  • "Provides good security features and you can view it in the central console."
  • "Lacks some additional integration."

What is our primary use case?

We use this product for our endpoint detection and all the remediation.

What is most valuable?

The solution provides good security features. The key valuable feature for me is that you can view it in the central console.

What needs improvement?

I'd like to see more integration in the next release and the solution should be file protected.

For how long have I used the solution?

I've been using this solution for five years.

What do I think about the scalability of the solution?

The solution is scalable. 

How are customer service and support?

I'd like to see a quicker response time from the company's technical support. 

How was the initial setup?

The initial setup was straightforward. It didn't take long and was part of the deployment of our endpoints, and part of the integration. We currently have around 3,000 users and no plans to expand. We have four people involved with maintenance. 

What other advice do I have?

I recommend this solution and rate it eight out of 10. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Philippe LUCAS - PeerSpot reviewer
Unified Communications Manager at Jouve
Real User
Easy to deploy with great cloud provisioning and excellent functionality
Pros and Cons
  • "It's a Microsoft product; it's easier to deploy this product than other options."
  • "It would be helpful if they offered video tutorial guides."

What is our primary use case?

We're using the solution on our endpoints.

What is most valuable?

The functionality is very important to us. 

The cloud provisioning is great. 

It's a Microsoft product, therefore, it's easier to deploy this product than other options. It's very important for us to have a simple way to deploy new PCs when we buy the new PCs. We don't want that deployment to be a burden. The easy deployment feature is very helpful.

What needs improvement?

At the moment we are currently testing it. We are not major users of the product, and therefore we have no idea of what it can and can't do just yet.

At this time we don't have any recommendations concerning the Windows product interface.

It would be helpful if they offered video tutorial guides. 

For how long have I used the solution?

I've used the solution for three or four months.

What do I think about the stability of the solution?

We are testing it right now and we didn't get into the production state just yet. Therefore, it's hard to gauge the capabilities in terms of stability. So far, however, it has been stable.

What do I think about the scalability of the solution?

The scalability is okay. 

How are customer service and support?

Support is always okay. I've always had a positive experience dealing with support. 

How was the initial setup?

The deployment is seamless and super simple. It's not complex at all, and that's the main selling point for us. 

What's my experience with pricing, setup cost, and licensing?

We did negotiate on the pricing, however, I can't speak to the exact costs involved. 

Which other solutions did I evaluate?

We did not really compare this solution to other options. The advantage is that this solution is available on mobile devices, and we needed something that covered everything, from desktops and laptops to mobile. Therefore, we didn't really consider anything else. 

What other advice do I have?

We are Microsoft customers. We don't have a special relationship with the organization. 

We are using the latest version of the solution. 

It's a good product overall. I would rate it an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
IT Director at Innovecs
Real User
Provides a centralized console and supports all the platforms that we use
Pros and Cons
  • "It's an enterprise solution that provides a centralized console and it supports all the platforms that we use, including Windows, Linux, Mac, iOS, and Android."
  • "Microsoft should improve support for third-party platforms, because not all functionality is available for all of them. It's a good product, but they should just extend the functionality for all platforms."

What is our primary use case?

It's an XDR (Extended Detection and Response) system.

What is most valuable?

It's an enterprise solution that provides a centralized console and it supports all the platforms that we use, including Windows, Linux, Mac, iOS, and Android. Microsoft Defender is embedded in Windows and is a basic anti-virus, but Defender for Endpoint is an enterprise-grade XDR system.

What needs improvement?

Microsoft should improve support for third-party platforms, because not all functionality is available for all of them. It's a good product, but they should just extend the functionality for all platforms.

For how long have I used the solution?

I have been using Microsoft Defender for Endpoint for about three months.

What do I think about the stability of the solution?

It's quite stable. Sometimes it can overload the CPU of endpoints, but Microsoft provides ways to solve this problem.

What do I think about the scalability of the solution?

Microsoft Defender for Endpoint is scalable. It's the ground-level service for other Microsoft security services. Microsoft provides a full range of security services and you have the ability to extend it anytime and in a simple way. You can scale the range of security services by just buying the license and implementing some extra service.

We have close to 200 users in our organization, but we plan to deploy this product to the whole company, with a total of nearly 800 people.

How are customer service and support?

We have not had to contact Microsoft's technical support because we get support from our partner.

How was the initial setup?

When it comes to the initial setup, Microsoft is very strong in that area and it is very simple. That's why we use it in our company. Some products are hard to deploy. Another solution was declined because it was not possible to roll it out in a bigger company.

We don't have a dedicated person to maintain the solution. Two people share the role. One is a Layer-1 specialist who maintains a daily routine, and the other is a Layer-2 engineer.

What about the implementation team?

We started to install this product for ourselves, but Microsoft proposed some different kinds of programs in which an integrator helps key customers deploy services and products. We accepted the proposition and we are happy we did so because the partner was very professional with very deep experience with the product.

What's my experience with pricing, setup cost, and licensing?

Microsoft has different plans for buying this product. The price depends on the configuration of the full set of products that you buy and on the licensing program in your contract. Microsoft provides a flexible licensing program and you can choose what you want.

Which other solutions did I evaluate?

The pros of Microsoft Defender for Endpoint are that it's simple to deploy and has all the required functionality. The drawback is that it lacks some functionality for other platforms, such as Linux.

What other advice do I have?

I would recommend implementing this solution together with a certified partner. That will help to avoid a lot of mistakes and save you money, because licensing is a big part of the project.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Head of Information Security at K2 Baseline Sdn Bhd
Real User
Top 5
Stable and easy to use, but needs quicker detection capability and more frequent updates
Pros and Cons
  • "It is stable and easy to use. Everything is okay, and there are no performance issues."
  • "Its detection is not as quick. There should also be more frequent updates."

What is our primary use case?

I use it mostly to detect threats or viruses. I am using its latest version.

What is most valuable?

It is stable and easy to use. Everything is okay, and there are no performance issues.

What needs improvement?

Its detection is not as quick. There should also be more frequent updates.

For how long have I used the solution?

I have been using this solution for maybe five years.

What do I think about the stability of the solution?

It is stable.

What do I think about the scalability of the solution?

We have about 20 users.

How are customer service and support?

I have not contacted Microsoft's technical support.

Which solution did I use previously and why did I switch?

I didn't use or evaluate other solutions.

How was the initial setup?

Its installation is very easy. It came with Windows.

What about the implementation team?

I can install it myself. We have three teams for deployment and maintenance.

What's my experience with pricing, setup cost, and licensing?

It came with Windows.

What other advice do I have?

I would recommend this solution. I would rate it a seven out of 10.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Senior System Administrator at Debre Markos University
Real User
Easy to use interface, user-friendly, and stable
Pros and Cons
  • "The solution has an easy-to-use interface, is always updated, and is user-friendly."
  • "The solution could improve by providing more integration."

What is our primary use case?

I use Microsoft Defender for Endpoint protection on my personal computer.

What is most valuable?

The solution has an easy-to-use interface, is always updated, and is user-friendly.

What needs improvement?

The solution could improve by providing more integration.

For how long have I used the solution?

I have been using Microsoft Defender for Endpoint for approximately one year.

What do I think about the stability of the solution?

The solution is stable and secure.

What do I think about the scalability of the solution?

I have found the scalability quite good.

How was the initial setup?

The installation is simple.

What about the implementation team?

I did the implementation of the solution.

What's my experience with pricing, setup cost, and licensing?

The solution is free and comes with Windows.

What other advice do I have?

I rate Microsoft Defender for Endpoint a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros sharing their opinions.
Updated: February 2025
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros sharing their opinions.