Try our new research platform with insights from 80,000+ expert users
reviewer2237718 - PeerSpot reviewer
Technical Account Manager at a comms service provider with 201-500 employees
Real User
Top 20
Helps prioritize threats, and protects against ransomware, but threat detection could use some improvement
Pros and Cons
  • "The ransomware and malware protection is the most valuable feature."
  • "Microsoft Defender for Endpoint is effective for validating work, but not ideal for investigations."

What is our primary use case?

I use Microsoft Defender for Endpoint to protect my computer when downloading files. Whether it's documents from my email or web browser, this is the first thing I use the solution for. It also provides protection against ransomware. Additionally, the monthly report indicates the number of infected files that were blocked during that month.

How has it helped my organization?

Microsoft Defender for Endpoint provides excellent visibility into known threats, thanks to their comprehensive database of malware information. 

Microsoft Defender for Endpoint helps us prioritize threats across our enterprise according to our needs. We focus on protecting against malware first, followed by email protection, and URLs.

Microsoft Defender for Endpoint has helped protect our organization against malware.

What is most valuable?

The ransomware and malware protection is the most valuable feature.

What needs improvement?

When there is a significant amount of malware, I believe that Microsoft Defender for Endpoint may not be as effective as other firewall solutions. I tested Microsoft Defender for Endpoint and found that it allowed me to download files infected with malware from certain sites, and its protection did not work as expected in that aspect of my work. I suspect this is because I use a GRAPH file with a password, and the solution only detects a file when it's related to clean files or open files. It doesn't seem to recognize encrypted log files that require a password for access.

Microsoft Defender for Endpoint does not assist in automating routine tasks or identifying high-value alerts. Therefore, we had to turn to other solutions like Cortex XDR by Palo Alto Networks. Additionally, Microsoft Defender for Endpoint lacks the capability to upload a list of IPs for blocking.

Microsoft Defender for Endpoint is effective for validating work, but not ideal for investigations. As a result, our experts have to dedicate more time when investigating threats using Microsoft Defender for Endpoint compared to other solutions.

The zero-day detection, as well as the sandboxing for unknown malware and URL detection, needs to be improved. These settings were not functional when we tested the solution.

Buyer's Guide
Microsoft Defender for Endpoint
December 2024
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,053 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Microsoft Defender for Endpoint for one year.

What do I think about the stability of the solution?

I give the stability an eight out of ten.

What do I think about the scalability of the solution?

I give the scalability a ten out of ten.

How was the initial setup?

The deployment is straightforward.

What's my experience with pricing, setup cost, and licensing?

Microsoft Defender for Endpoint is more affordable compared to some other endpoint solutions.

Which other solutions did I evaluate?

We evaluated Cortex XDR by Palo Alto Networks and Fortinet. We found that Microsoft Defender for Endpoint was easier to deploy and offered a better price.

What other advice do I have?

I would rate Microsoft Defender for Endpoint a seven out of ten. The solution is stable, easy to deploy, and scalable. However, threat detection could use some improvement.

Our organization is a cybersecurity company, and after using Microsoft Defender for Endpoint for one year, we found that it lacked features such as endpoint detection and response. Additionally, it was weak in certain areas, like detecting a set of malware and providing email protection. As a result, we started exploring other solutions, even though they may be more costly.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Carlo Du Plessis - PeerSpot reviewer
Security Specialist at Engen
Real User
Provides good security features and can be viewed in the central console
Pros and Cons
  • "Provides good security features and you can view it in the central console."
  • "Lacks some additional integration."

What is our primary use case?

We use this product for our endpoint detection and all the remediation.

What is most valuable?

The solution provides good security features. The key valuable feature for me is that you can view it in the central console.

What needs improvement?

I'd like to see more integration in the next release and the solution should be file protected.

For how long have I used the solution?

I've been using this solution for five years.

What do I think about the scalability of the solution?

The solution is scalable. 

How are customer service and support?

I'd like to see a quicker response time from the company's technical support. 

How was the initial setup?

The initial setup was straightforward. It didn't take long and was part of the deployment of our endpoints, and part of the integration. We currently have around 3,000 users and no plans to expand. We have four people involved with maintenance. 

What other advice do I have?

I recommend this solution and rate it eight out of 10. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Microsoft Defender for Endpoint
December 2024
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,053 professionals have used our research since 2012.
Fellipe Abib - PeerSpot reviewer
CEO at Datasirius TI
Real User
Easy to set up endpoint security solution with automated investigation and web content filtering features; has a vulnerability management dashboard
Pros and Cons
  • "Easy to understand and easy to set up endpoint security solution. It's a multifeatured product with web content filtering and automated investigation features. It also has a fantastic vulnerability management dashboard."
  • "The UI for Microsoft Defender for Endpoint needs to be better. Integration with client dashboards is also lacking in this product, e.g. client dashboards shouldn't just be viewable from the cloud, because when the client's computer is offline, you won't be able to see the client dashboard."

What is our primary use case?

Most of my clients use Microsoft Defender for Endpoint for attack and threat prevention. I always look at the alert page to get alert details. This solution is also used for EDR (endpoint detection and response). We also use it for web content filtering and for completely automated investigations.

What is most valuable?

What I found most valuable in Microsoft Defender for Endpoint is its vulnerability dashboard. It's fantastic for my clients and I.

What needs improvement?

In my experience, I only need the client dashboard in the cloud and in the server. For my dashboards in the cloud, I can set up and see everything. I can check alerts, e.g. I'm alerted when something happens, but when my client is offline, and I want to look for something offline, e.g. directly on his computer, I'm not able to see everything. My client's computer needs to be online for me to be able to see the information I need, and this is an area for improvement.

There should be integration of this solution with client dashboards. I need to see some of the dashboards directly from the computers of my clients, rather than just their cloud dashboards. If the dashboard is only viewable from the cloud, I will not be able to view it when the computer is offline.

What I'd like to see in the next release of Microsoft Defender for Endpoint is a better UI. Another suggestion to improve this solution is having endpoint protection offline, e.g. I'll set up a file on Microsoft Defender for Endpoint and all the network, so my ISP goes in and out through the Defender server. Rather than just being on cloud, they must make an appliance for on-premises deployment.

For how long have I used the solution?

I started using Microsoft Defender for Endpoint six months ago, so I've been using it for half a year.

What do I think about the stability of the solution?

Microsoft Defender for Endpoint is a very stable solution.

What do I think about the scalability of the solution?

Microsoft Defender for Endpoint is a scalable solution.

How are customer service and support?

I have no complaints about the technical support for Microsoft Defender for Endpoint.

How was the initial setup?

The initial setup for Microsoft Defender for Endpoint was super easy for me.

What about the implementation team?

Implementing this solution is done in-house. I'm the one implementing it. I can set it up for multiple clients weekly, e.g. five clients a week.

What other advice do I have?

I'm using Microsoft Defender for Endpoint for myself and for my clients. I'm a partner of Microsoft.

I'm the one in charge of the deployment and maintenance of this solution.

My advice to someone planning to use Microsoft Defender for Endpoint is that it's super easy to understand, whether you have no prior knowledge of it, or you want to learn more about it. You can also learn more about security, particularly information security.

My rating for Microsoft Defender for Endpoint is nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Technical Team Lead at Alepo
Vendor
Effective firewall capabilities, regular antivirus updates, and it is preinstalled with Windows
Pros and Cons
  • "The most valuable features are the Windows Firewall and the regular virus definition updates. These features are very helpful and have helped to improve our security."
  • "This solution needs to move beyond relying on virus definitions alone and protect the system using behavioral analysis of the processes that are running."

What is our primary use case?

We use Microsoft Defender Antivirus for antivirus protection as part of our endpoint security solution. It protects our systems against attacks from any virus, malware, or trojan. 

How has it helped my organization?

We rely on this product for endpoint protection in our organization because we have not subscribed to any antivirus, apart from Microsoft Defender. It comes for free with our Windows subscription and it has improved the way our organization functions because there have been no virus attacks to date on our laptops.

It has not negatively affected our end-user experience.

What is most valuable?

This solution takes care of most of the infections that are found in the system, and it comes included with Windows. These are the two main advantages of using it.

The most valuable features are the Windows Firewall and the regular virus definition updates. These features are very helpful and have helped to improve our security.

What needs improvement?

Microsoft Defender protects the computer by using virus definitions that we download through regular updates but nowadays, cybersecurity attacks have become more intelligent. This solution needs to move beyond relying on virus definitions alone and protect the system using behavioral analysis of the processes that are running. These can be vulnerable points and if a process causes a glitch in the system, it should be quarantined. Moreover, enhancements of this type should not detract from system performance. There should be no slowdown on the laptop, for example.

For how long have I used the solution?

I have been using Microsoft Defender Antivirus since I started using Windows 7, more than eight years ago.

What do I think about the stability of the solution?

Stability-wise, it is good, and it performs very nicely.

What do I think about the scalability of the solution?

The scalability is fine. We had more than 300 devices that are being protected.

How are customer service and technical support?

I have never had an opportunity to speak with technical support because everything has always worked very smoothly. As we have experienced no issues at all, we never contacted support.

Which solution did I use previously and why did I switch?

Prior to using Microsoft Defender, we used McAfee and Avast Antivirus.

One of the main reasons that we switched away from McAfee is that it required purchasing a subscription. With Microsoft Defender, it is included with Windows. When we install the operating system, it is already there and we don't have to purchase an additional antivirus product.

For security, aside from a traditional antivirus, we have purchased the SentinelOne Endpoint Security solution. This product is more enhanced when compared to an antivirus product. It is modern and has better threat intelligence than other products. I don't know SentinelOne very well yet, as we have just purchased the subscription, but I know that the difference between products is not based on virus definitions.

SentinelOne has intelligence on the cloud and many other security features including the blocking of domain names, and the blocking of USB drives that users plug into their laptops. Although it has many more features than legacy antivirus software, I have no complaints about the performance of Microsoft Defender.

One of the reasons we are more heavily relying on endpoint security is that everybody is working from home and using the internet for work. This transition was made within the last two or three months. When people were working in the office, the firewall afforded them protection. However, as it is now, the endpoints are more vulnerable to attack. This is why we now rely more heavily on SentinelOne.

How was the initial setup?

Microsoft Defender comes preinstalled with the Windows operating system, so we do not have to deploy it separately.

What's my experience with pricing, setup cost, and licensing?

The subscription is part of Windows, so we don't have to pay anything extra for this product.

What other advice do I have?

This is definitely a product that I recommend people use because first of all, you do not have to pay anything extra to use it. The performance is very smooth and it protects your system, which is very much needed. All in all, I would say that this is a good antivirus solution.

I would rate Microsoft Defender Antivirus an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
IT Manager at a financial services firm with 1,001-5,000 employees
Real User
Quick and responsive support, stable, improves security, and requires little maintenance
Pros and Cons
  • "Microsoft's technical support is fantastic."
  • "At times, the other antivirus products are now doing AI, in terms of understanding the behavior of the system and determining when there's an anomaly. This is something that Defender can improve on."

What is our primary use case?

We primarily use this product to get antivirus protection in a cost-effective way.

How has it helped my organization?

This product tends to detect a lot more issues than the other antivirus solutions. This is because it's essentially tuned to Microsoft. It has some inbuilt intelligence, so they tend to understand the Microsoft environment and we don't need to do as much exclusion. With other antivirus products, we need to exclude certain files from being scanned.

What is most valuable?

The malware detection feature is very good.

What needs improvement?

At times, the other antivirus products are now doing AI, in terms of understanding the behavior of the system and determining when there's an anomaly. This is something that Defender can improve on.

For how long have I used the solution?

I have been working with Microsoft Defender Antivirus for between two and three years.

What do I think about the stability of the solution?

This is a stable solution that has matured over the years.

What do I think about the scalability of the solution?

We have approximately 7,000 machines and we have not needed to scale beyond our original implementation.

How are customer service and technical support?

Microsoft's technical support is fantastic.

We subscribe to the Microsoft Premier Support Package and they tend to respond to our queries very fast. When our engineers contact them, they respond in a very short time.

Which solution did I use previously and why did I switch?

We currently use Cylance, in addition to Microsoft Defender. I'm not sure what the impact is of using two solutions, whether it is a good thing, or not. We do plan on narrowing this down to one solution in the future.

How was the initial setup?

This product was included with Windows 10, so we did not have to deploy it separately.

Once this product is set up, this solution requires very little maintenance.

What's my experience with pricing, setup cost, and licensing?

We already use Microsoft solutions and I found it cheaper to purchase the bundle, which includes Defender. By including the antivirus in the bundle, it makes it a little cheaper for us. If you purchase it outside of the bundle, it is a little bit expensive.

When you want the central administration functionality, it tends to be more expensive. The normal, standalone model is not expensive, but the enterprise model that includes the bundle with email and some web protection, is a bit more expensive.

What other advice do I have?

When we initially implemented Windows Defender, we were pessimistic about whether it would be good enough. However, it is a pretty mature product now.

My advice for anybody who is considering this product is that it's good, and it gets results early.

I would rate this solution an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
reviewer1293498 - PeerSpot reviewer
Sr. Consultant at a computer software company with 51-200 employees
Consultant
Expandable and reliable with helpful technical support
Pros and Cons
  • "The stability keeps getting better and better."
  • "It's not quite a mature solution just yet. It needs more time to grow and develop."

What is our primary use case?

We're using it in the backend, just for securing our environment. We're not an end-user, we are a Microsoft partner and we are using it as a B2B solution. It's more for customers. From the software side, we provide solutions that are mainly Microsoft-based. 

What is most valuable?

It's a solution that can exist in the cloud, which makes it very scalable.

The stability keeps getting better and better.

What needs improvement?

Sometimes it's complicated. It's not intuitive in terms of installation and deployment. When we are making some POCs for customers before engaging and we are testing all the Microsoft security solutions for our customers. We've found it hard so far.

It's not quite a mature solution just yet. It needs more time to grow and develop.

The setup can be a bit difficult. This is expected. We sometimes deal with difficult environments. 

For how long have I used the solution?

I've been using the solution for two years now. It hasn't been too long. 

What do I think about the stability of the solution?

The stability is great. It just keeps getting more and more stable. As it matures, it's going to be very good.

What do I think about the scalability of the solution?

The scalability in general is quite good. If a company needs to expand it, it can do so.

Today, we have dozens of clients using the solution and we're expecting to add more. This is our target - to increase the number of customers using the solution.

How are customer service and support?

So far, technical support is okay. We have no complaints. 

How was the initial setup?

The initial setup can be a bit difficult. I have had some feedback from engineers that say sometimes they are struggling and it's not as easy as we would hope. That said, we are dealing with quite complicated solutions, and it's normal to not be as easy. This is not a plug-and-play product. You need to configure it and to add and change parameters and you have to adapt it to the different environments.

How big your technical team needs to be varies according to each deployment. It depends on what is expected and what needs to be done. 

What about the implementation team?

We tend to implement the solution for our clients. 

What's my experience with pricing, setup cost, and licensing?

Clients do need to pay for a license. They vary. Some are charged monthly, others, yearly. There are various options. 

What other advice do I have?

While I cannot speak to the exact version number, we are likely on the latest version. We have an administrative team that makes sure it is updated and takes care of everything for us. 

I would recommend the solution to others. So far, it has been a good product.

I'd rate it overall at an eight out of ten.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
reviewer1396728 - PeerSpot reviewer
Technology Consultant at a computer software company with 10,001+ employees
Real User
Useful for threat protection; Stable and scalable solution
Pros and Cons
  • "Microsoft Defender for Endpoint is scalable. Currently, we have 600,000 users in our organization."
  • "The deployment of Microsoft Defender for Endpoint on Windows 10 is not quite so straightforward. This could be made easier."

What is our primary use case?

Microsoft Defender for Endpoint is useful for the protection of your business information and threat prevention.

What needs improvement?

The deployment of Microsoft Defender for Endpoint on Windows 10 is not quite so straightforward. This could be made easier.

For how long have I used the solution?

I have been using Microsoft Defender for Endpoint for four years. 

What do I think about the stability of the solution?

I am satisfied with the stability of Microsoft Defender for Endpoint. 

What do I think about the scalability of the solution?

Microsoft Defender for Endpoint is scalable. Currently, we have 600,000 users in our organization.

How are customer service and support?

I have never contacted the technical support. 

What's my experience with pricing, setup cost, and licensing?

The company pays for the license so I do not know much about that. 

What other advice do I have?

I would recommend Microsoft Defender for Endpoint.

Which deployment model are you using for this solution?

On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Subject Matter Expert at Vision Software
Real User
Provides malware and ransomware protection and scales easily
Pros and Cons
  • "The most important and the most relevant features of Defender for Endpoint are the malware and ransomware protection."
  • "I would like to see the next generation of the tool improved to work with other operating systems, like Linux."

What is our primary use case?

It's used to protect endpoints and, for some customers, it is used to deploy Microsoft 365 suite features. Most of our clients are medium-sized businesses.

What is most valuable?

The most important and the most relevant features of Defender for Endpoint are the malware and ransomware protection.

What needs improvement?

I would like to see the next generation of the tool improved to work with other operating systems, like Linux.

For how long have I used the solution?

I have had about a year's worth of experience with Microsoft Defender for Endpoint. I am a subject matter expert for a Microsoft partner in Colombia. We develop portfolios and solutions for our customers that need Microsoft products in their infrastructure. My role deals with the architecture of solutions.

What do I think about the stability of the solution?

I don't recall any issues with the solution.

What do I think about the scalability of the solution?

It scales easily.

How are customer service and support?

I haven't had to use technical support for the solution.

How was the initial setup?

The setup depends on the customer, but it is generally simple.

What's my experience with pricing, setup cost, and licensing?

Some customers have the licensing of the suite and have all infrastructure prepared for the installation and deployment. But in some cases, when customers haven't deployed the solution and don't have licenses, it can be expensive to start from scratch.

What other advice do I have?

Customers haven't given us any feedback about difficulties with the solution. With its intelligence and tools over cloud infrastructure, it's a good product. We are developing some use cases and projects for customers with Microsoft Defender for Endpoint. It is good for us.

Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2024
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros sharing their opinions.