Try our new research platform with insights from 80,000+ expert users
Senior IT Manager at a pharma/biotech company with 1-10 employees
Real User
Top 20Leaderboard
Good protection against phishing attacks and spam, but seamless integration with EDR is needed
Pros and Cons
  • "What I like most is the protection against phishing emails and anti-spam."
  • "If they integrate with the EDR then it will benefit this solution."

What is our primary use case?

We are using Microsoft Defender ATP to prevent anti-phishing, malware transportation, and unwanted spam emails.

What is most valuable?

What I like most is the protection against phishing emails and anti-spam.

What needs improvement?

The integration of the defense features is something that they are working on but it still needs improvement.

In the next release, I would like to have additional features integrated with DNS security and DNS resolution. It will add to the solution and work more like a firewall.

If they integrate with the EDR then it will benefit this solution. 

I would like ATP to be integrated with the EDR as one single license.

For how long have I used the solution?

I have been working with Microsoft Defender ATP for three years.

Buyer's Guide
Microsoft Defender for Endpoint
January 2025
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.

What do I think about the stability of the solution?

It is stable, but it depends on how you configure the existing ATP and what existing features you need to enable it.

Based on the features that are enabled, it will work perfectly. 60% to 80% will depend on the configuration that is done for the ATP trade products.

What do I think about the scalability of the solution?

Microsoft Defender ATP is scalable at any point of time.

How are customer service and support?

The technical support was good. 

I would rate technical support a four out of five.

How was the initial setup?

The initial setup was not easy but not complex. It was somewhere in between.

There were many things that needed to be integrated with the existing solution, which took some time. It took us a week to deploy this solution.

What's my experience with pricing, setup cost, and licensing?

When compared with other vendors, the pricing is very high.

There are several other features that can be integrated with Microsoft Defender ATP such as EDR. But, it doesn't already come integrated with ATP. It's available at an additional cost.

If you want the EDR feature, you would have to purchase an E-file license. The cost is three times higher to have more productivity with the dashboard.

What other advice do I have?

It's a good solution. I would recommend Microsoft Defender ATP to anyone who is interested in using it.

I would rate Microsoft Defender ATP a seven out of ten.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
PeerSpot user
reviewer2237718 - PeerSpot reviewer
Technical Account Manager at a comms service provider with 201-500 employees
Real User
Top 20
Helps prioritize threats, and protects against ransomware, but threat detection could use some improvement
Pros and Cons
  • "The ransomware and malware protection is the most valuable feature."
  • "Microsoft Defender for Endpoint is effective for validating work, but not ideal for investigations."

What is our primary use case?

I use Microsoft Defender for Endpoint to protect my computer when downloading files. Whether it's documents from my email or web browser, this is the first thing I use the solution for. It also provides protection against ransomware. Additionally, the monthly report indicates the number of infected files that were blocked during that month.

How has it helped my organization?

Microsoft Defender for Endpoint provides excellent visibility into known threats, thanks to their comprehensive database of malware information. 

Microsoft Defender for Endpoint helps us prioritize threats across our enterprise according to our needs. We focus on protecting against malware first, followed by email protection, and URLs.

Microsoft Defender for Endpoint has helped protect our organization against malware.

What is most valuable?

The ransomware and malware protection is the most valuable feature.

What needs improvement?

When there is a significant amount of malware, I believe that Microsoft Defender for Endpoint may not be as effective as other firewall solutions. I tested Microsoft Defender for Endpoint and found that it allowed me to download files infected with malware from certain sites, and its protection did not work as expected in that aspect of my work. I suspect this is because I use a GRAPH file with a password, and the solution only detects a file when it's related to clean files or open files. It doesn't seem to recognize encrypted log files that require a password for access.

Microsoft Defender for Endpoint does not assist in automating routine tasks or identifying high-value alerts. Therefore, we had to turn to other solutions like Cortex XDR by Palo Alto Networks. Additionally, Microsoft Defender for Endpoint lacks the capability to upload a list of IPs for blocking.

Microsoft Defender for Endpoint is effective for validating work, but not ideal for investigations. As a result, our experts have to dedicate more time when investigating threats using Microsoft Defender for Endpoint compared to other solutions.

The zero-day detection, as well as the sandboxing for unknown malware and URL detection, needs to be improved. These settings were not functional when we tested the solution.

For how long have I used the solution?

I have been using Microsoft Defender for Endpoint for one year.

What do I think about the stability of the solution?

I give the stability an eight out of ten.

What do I think about the scalability of the solution?

I give the scalability a ten out of ten.

How was the initial setup?

The deployment is straightforward.

What's my experience with pricing, setup cost, and licensing?

Microsoft Defender for Endpoint is more affordable compared to some other endpoint solutions.

Which other solutions did I evaluate?

We evaluated Cortex XDR by Palo Alto Networks and Fortinet. We found that Microsoft Defender for Endpoint was easier to deploy and offered a better price.

What other advice do I have?

I would rate Microsoft Defender for Endpoint a seven out of ten. The solution is stable, easy to deploy, and scalable. However, threat detection could use some improvement.

Our organization is a cybersecurity company, and after using Microsoft Defender for Endpoint for one year, we found that it lacked features such as endpoint detection and response. Additionally, it was weak in certain areas, like detecting a set of malware and providing email protection. As a result, we started exploring other solutions, even though they may be more costly.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Microsoft Defender for Endpoint
January 2025
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
832,138 professionals have used our research since 2012.
Rajko Terzić - PeerSpot reviewer
Senior Software Architect at Instirute of public health
Real User
Provides good, user-friendly protection
Pros and Cons
  • "Defender is stable, I haven't had any problems with viruses when using it, and it's easy to update."
  • "Defender's cloud integration could be improved."

What is our primary use case?

I use Defender for protection.

What is most valuable?

The most valuable features are that Defender is user-friendly and part of Microsoft Windows.

What needs improvement?

Defender's cloud integration could be improved.

What do I think about the stability of the solution?

Defender is stable, I haven't had any problems with viruses when using it, and it's easy to update.

How was the initial setup?

The initial setup was easy.

What other advice do I have?

I would recommend Defender to anyone thinking of using it, and I rate it as eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Sales Director at CLoud3 Solutions Pte Ltd
Real User
Secure, no maintenance required, and stable
Pros and Cons
  • "Microsoft Defender for Endpoint has been secure and there is zero maintenance required because it updates with Microsoft Windows."
  • "The solution can be more user-friendly."

What is our primary use case?

Microsoft Defender for Endpoint is integrated into Microsoft Windows and is used for system protection.

What is most valuable?

Microsoft Defender for Endpoint has been secure and there is zero maintenance required because it updates with Microsoft Windows.

What needs improvement?

The solution can be more user-friendly.

For how long have I used the solution?

I have been using Microsoft Defender for Endpoint for a few years.

What do I think about the stability of the solution?

Microsoft Defender for Endpoint is stable.

What do I think about the scalability of the solution?

The solution is scalable.

We have 30 users using the solution in my organization.

How was the initial setup?

The solution has no installation as it comes with Microsoft Windows.

What's my experience with pricing, setup cost, and licensing?

I do not have to purchase antivirus solutions anymore because Microsoft Defender for Endpoint is integrated into Windows and comes free.

What other advice do I have?

I would recommend this solution to others.

I rate Microsoft Defender for Endpoint a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Consultor Senior at a consultancy with 51-200 employees
Real User
A free solution that performs well
Pros and Cons
  • "It performs well. The stability is seamless."
  • "A concern is ransomware, whether people can penetrate and encrypt my data or steal my credit card/banking information."

What is most valuable?

I haven't experienced any problems.

What needs improvement?

They could improve the information about how they are dealing with people who could attack minors. This is my main concern. 

Another concern is ransomware, whether people can penetrate and encrypt my data or steal my credit card/banking information. 

For how long have I used the solution?

I have been using it since 2019.

What do I think about the stability of the solution?

It performs well. The stability is seamless.

What do I think about the scalability of the solution?

Scalability is not a problem because we don't have servers. We don't do anything more with the computers than use them for studies, reading papers and books, watching movies, and communicating with our family. So, we don't need to scale up.

How are customer service and technical support?

If they could send me more information, then I could evaluate, read more, and give them opinions. For example, if someone tells me about a problem, then I can give solutions and also write to Microsoft regarding this information.

Which solution did I use previously and why did I switch?

From the beginning of the pandemic, we received another kind of software when we had to be at home, but it caused us problems with the performance. So, I decided to quit the other software. Then, I installed Windows Defender on all my computers, including my grandchildren's computers.

I was using Sophos previously, but it was causing problems with the performance. For example, when my grandchildren were trying to assume a session, they opened Excel or Word with a 4 GB computer using Windows 10 and then they always lost the connection or the continuities because the computer slowed down. However, when we decided to quit using Sophos and install all the features of Windows Defender, then those problems were resolved.

How was the initial setup?

The initial setup is very easy and straightforward.

My deployment process: I put some checks in the questions that they have. It was very easy. I read about it in the tutorial. I installed it on my entire family's computers (six computers) in less than half an hour.

What's my experience with pricing, setup cost, and licensing?

It is free.

What other advice do I have?

We are totally satisfied with performance and price. However, there is still the question, "Is it safe and secure enough for home, primary-school-age children, and minors?" Despite having a Masters degree in Computer Sciences and Mathematics, I have not been able to say if Microsoft is doing bad or good things.

Many companies may say that they have the best product, but I recommend always watching the news about what a company is doing. Stay informed. Don't be complacent. 

The solution is a nine out of 10.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Defendwind677 - PeerSpot reviewer
Associate System Engineer - Security Services at a educational organization with 10,001+ employees
Real User
Product has a decent detection rate, but there are some challenges related to reporting
Pros and Cons
  • "Within its class I think, it has a high and decent detection rate."
  • "There's a lot of manual effort involved to configure what we need."

What is our primary use case?

We use this as our antivirus solution.

What is most valuable?

Within its class I think, it has a high and decent detection rate.

What needs improvement?

There were a few detections that are not picked up, and then Microsoft picks up on that and they update it. That's just a normal thing you go through based on every antivirus solution. You're always going to have viruses and signatures that are coming out.

So, I wouldn't say it's the perfect solution because if you're looking at next-generation behavioral based things, for example, if you're going to use ATP, that's when you can get more methods out of it. With Defender, if you pay more you can get the ATP component, which is sold separately by Microsoft.

We do have some challenges in the reporting aspect of it. 

There's a lot of manual effort involved to configure what we need.

There are also a few issues with policies.

For how long have I used the solution?

I've been using this solution for six months.

What other advice do I have?

Defender by itself is not a solution. Defender is basically a functionality.

We have some issues with reporting, but I think it's just the way we've integrated right now, again not using ATP. So, we just use STC MS management. Then it's limited in terms of reporting.

From an operator's perspective, I think there are some policy detection issues where you've got a detection for a signature but how it translates into the FCCM dashboard where it doesn't really categorize that particular model. It picks something up as bad but it's just unknown.

So, I think that's a known issue with this particular thing. Because it doesn't know what it is classified as it doesn't really do anything. For it to do something, the policy has to recognize the category of that number. It could be a trojan horse or whatever it is, but it doesn't really do that. It could be what they call an autonomous detection where the system categorizes it as not recognized and hence it blocks it, but it's not going to let you delete it instantly. Usually, you can say if it's detected you want to block it, that's the first step. The second step is to be able to delete the file or quarantine the file. But it doesn't recognize that, so it doesn't know what it needs to do. Instead, it just blocks it. It only blocks it because it doesn't recognize it as being Malware.

I would rate this product a six out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1674681 - PeerSpot reviewer
Cyber Security BA/BSA at a financial services firm with 10,001+ employees
Real User
Straightforward to set up with good technical support and good stability
Pros and Cons
  • "Technical support is good."
  • "There are likely some technical improvements or features that could be added, however, I cannot say, off the top of my head, what they would be."

What is our primary use case?

Usually, the solution is used in relation to keys management. We implemented a program for it, for the lifecycle of the keys. We've also used it for certificate management.

What is most valuable?

The initial setup is very straightforward.

The stability is very good.

Technical support is good.

The solution is in good condition and offers good functionality.

What needs improvement?

There are likely some technical improvements or features that could be added, however, I cannot say, off the top of my head, what they would be.

For how long have I used the solution?

I used the solution in relation to scoping a project. I was doing business analysis.

What do I think about the stability of the solution?

The solution was very stable.

What do I think about the scalability of the solution?

The solution is scalable.

How are customer service and support?

The technical support for Microsoft is very good.

How was the initial setup?

The initial setup is not difficult or complex. It's very simple and straightforward. 

What's my experience with pricing, setup cost, and licensing?

I do not know how much it costs per month. I cannot say how it compares against the rates of the competition.

What other advice do I have?

We are a Microsoft Customer.

I'm not sure if I would recommend the solution to others. It depends on their requirements. It needs to fit a company's use cases.

I would rate the solution at an eight out of ten.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Carlo Du Plessis - PeerSpot reviewer
Security Specialist at Engen
Real User
Integrates well, continually updates, and reliable
Pros and Cons
  • "One of the valuable features of the solution is the small updates that keep my machine relatively clean from any infections."
  • "I would like the solution to be able to prevent unauthorized programs from installing and to block unauthorised URLs which is similar to web filtering product."

What is our primary use case?

The primary use of this solution is for the detection of malware and to stop phishing. 

What is most valuable?

One of the valuable features of the solution is the small updates that keep my machine relatively clean from any infections. Additionally, it has good integration with other Microsoft products.  

What needs improvement?

I would like the solution to be able to prevent unauthorized programs from installing and to block unauthorised URLs which is similar to web filtering product. 

For how long have I used the solution?

I have used the solution for approximately two years. 

What do I think about the stability of the solution?

I find the solution to be stable. 

What do I think about the scalability of the solution?

I find the solution to be quite easily extended into other environments. It is scalable, I have it on three devices. 

Which solution did I use previously and why did I switch?

I have previously used the McAfee Stinger product. 

How was the initial setup?

The installation of the solution is easy. I completed it myself and it took approximately 20 minutes. 

What's my experience with pricing, setup cost, and licensing?

The solution comes as a part of Windows 10 and it is covered under its license. 

What other advice do I have?

I will continue to use and would recommend the solution to others. 

I rate Microsoft Defender Antivirus an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2025
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros sharing their opinions.