Microsoft Defender for Endpoint provides visibility into our workstations at SOC.
IT Development Manager at S-ryhmä / S Group
Provides visibility into SOC workstations and stops threats from spreading to machines
Pros and Cons
- "We can react to threats faster and stop them from spreading from one machine to another. It protects from suspicious email attachment downloads. It will lock down the SOC and the workstations."
- "Microsoft Defender for Endpoint's licensing is confusing. It has conflicting information on the website. We also faced integration issues with other systems. It makes laptops slower than traditional antivirus systems."
What is our primary use case?
How has it helped my organization?
We can react to threats faster and stop them from spreading from one machine to another. It protects from suspicious email attachment downloads. It will lock down the SOC and the workstations.
What is most valuable?
It is an EDR product that offers much more information into what's happening at our workstations.
What needs improvement?
Microsoft Defender for Endpoint's licensing is confusing. It has conflicting information on the website. We also faced integration issues with other systems. It makes laptops slower than traditional antivirus systems.
Buyer's Guide
Microsoft Defender for Endpoint
December 2024
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,053 professionals have used our research since 2012.
For how long have I used the solution?
I have been working with the product for a year.
What do I think about the stability of the solution?
Microsoft Defender for Endpoint is stable.
What do I think about the scalability of the solution?
The tool's scalability is good, but we must consider the cost.
What was our ROI?
We get good ROI with the product's use.
What other advice do I have?
The product's threat intelligence prepares us for potential threats and helps us take proactive steps. Its vulnerability management feature is important to us.
Microsoft Defender for Endpoint has improved our security posture by giving visibility to our endpoints and vulnerabilities.
The tool helps us save months per year. It also helps us save money in manhours.
Microsoft Defender for Endpoint has reduced our time to respond and time to detect by a large margin.
We chose the product because we already use Microsoft products, and it better integrates with them.
I rate it an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Manager IT Server Operations at a energy/utilities company with 10,001+ employees
Helps to secure workstations, laptops, and servers
Pros and Cons
- "Microsoft Defender for Endpoint is free and part of the licensing stack of other Microsoft products."
- "The product should reduce updates since it is hard to keep up."
What is our primary use case?
We use Microsoft Defender for Endpoint to secure our workstations, laptops, and servers. It helps us to do virus scanning and malware protection.
What is most valuable?
Microsoft Defender for Endpoint is free and part of the licensing stack of other Microsoft products.
What needs improvement?
The product should reduce updates since it is hard to keep up.
For how long have I used the solution?
I have been using the product for three to four years.
How was the initial setup?
The tool's deployment was simple. It took about a month to complete since we have over 5000 servers across various platforms.
What other advice do I have?
Microsoft Defender for Endpoint helps us save time since we don't have to keep a separate semantic console.
We can see the threats as soon as they come in. Our security team gets notifications.
I rate it an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Microsoft Defender for Endpoint
December 2024
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: December 2024.
824,053 professionals have used our research since 2012.
Principle IT Support Engineer at a retailer with 201-500 employees
A robust, straightforward, and intuitive tool that's easy to manage from the admin center
Pros and Cons
- "Defender for Endpoint is a robust solution that works well out-of-the-box."
- "Our team's knowledge of the solution needs to be improved, and Microsoft could do a better job conveying the necessary information to users. We could proactively use the tool more and explore capabilities we are not yet utilizing."
What is our primary use case?
Our primary use case is anti-malware and virus protection for our machines. We don't operate a network as such; our setup is almost entirely in the cloud.
We use the solution across multiple departments and teams, with about 400 total end users.
How has it helped my organization?
Around 90% of our estate is Mac, so we rarely have security alerts, but we get daily reports. The solution lets us proactively advise users about security concerns, especially when downloading files.
What is most valuable?
The solution is a Microsoft built-in tool, so it's very straightforward to use and monitor from the admin center, it's intuitive.
As with all antivirus software, the benefits of using it far outweigh the risks of not having it. Protecting our estate, machines, and users is essential. We can take action quickly, for example, when a user downloads something suspicious and step in before the threat escalates. As an organization, we have encrypted files and data it is vital for us to protect.
Defender for Endpoint is a robust solution that works well out of the box.
We can monitor and manage our security picture from one dashboard, and that's one of the primary reasons we use the solution. Our machines are enrolled on Microsoft Intune, which further simplifies management. With the E5 license, everything is in the same place; that makes our job easier and allows us to be more proactive when confronting threats. Not having to log in and out of different systems to manage devices is an excellent improvement to our operation.
The solution's threat intelligence helps us prepare for potential threats and makes us more proactive. We have the information required to warn our users of threats, including malicious links and phishing emails. The product gives us an accurate picture of the threat landscape, enabling us to adapt our strategy to protect our most sensitive and vital data.
There is a difficult balance working in IT, as we don't want to put all our eggs in one basket; if one system goes down, we are compromised. We want the flexibility and reliability offered by different specialized solutions, but that complicates management. With Defender for Endpoint, we don't need to worry about machines slipping through the gaps and remaining unprotected because the product is connected to the user account and pushed by the tenant. There is no agent, and the solution isn't intrusive; the user doesn't even know it's there. Other vendors I dealt with in the past required clients to be installed and updated, with potential problems coming in if the client isn't up to date. This isn't an issue we have with Defender.
What needs improvement?
Our team's knowledge of the solution needs to be improved, and Microsoft could do a better job conveying the necessary information to users. We could proactively use the tool more and explore capabilities we are not yet utilizing.
For how long have I used the solution?
We have been using the solution for about six months.
What do I think about the stability of the solution?
The solution is stable; Microsoft goes down very rarely. It happened just a few times over my career. If it does go down, the impact is significant.
What do I think about the scalability of the solution?
The solution is very scalable. Microsoft makes that easy, and we plan to increase our Defender for Endpoint usage.
How are customer service and support?
I've only contacted Microsoft support a few times, and they were always helpful. I don't have any issues with the support; they're good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously used Symantec Endpoint Security. It was somewhat clunky. The engineers found it too intrusive as it required a client to be installed, dramatically slowing down the machines. We switched to Defender for Endpoint because it's part of the Microsoft suite, and we can use it across platforms for Windows and Mac.
How was the initial setup?
The initial setup is straightforward. Initially, we didn't use the E5 licensing, so it was a basic cloud setup with a license per user. Now we have our own tenants, and we're deploying E5 licenses, and Defender for Endpoint comes as part of the license. A user activates the app in the Office 365 tenant, and that's the setup.
The initial deployment didn't take very long; it was just a tick box exercise. We are moving tenants, so we're giving everyone a new E5 license when they move over. It's quick and easy to assign licenses via a tool we have, which provides users with access to the entire Microsoft suite, including Defender for Endpoint.
Five people were involved in the deployment, all of them IT staff.
I'm not directly involved in taking care of the solution, but it seems lightweight in terms of maintenance. Most of the updating is end-user-driven; users are prompted to restart their machines to stay up to date with security patches.
What was our ROI?
As we have only been using the solution for six months, I don't think we've seen an ROI yet. I imagine in another two years, we will see a return.
What's my experience with pricing, setup cost, and licensing?
AV solutions are pretty expensive because they are necessary, not just for protection, but many businesses need them to comply with regulatory bodies and receive accreditation. We recently purchased an E5 license, which gives us access to the entire Microsoft suite. I would say the pricing is competitive; most tools of this kind are similarly priced. There are minor differences between the competitors, but they aren't spectacularly different. Defender for Endpoint makes sense because all our solutions are in the same place, paid for with a single license. The subscription price is around £50 per user per month, though it may have increased slightly.
Which other solutions did I evaluate?
We evaluated Sophos Intercept X and Kaspersky Endpoint Security for Business.
What other advice do I have?
I would rate the solution an eight out of ten.
Defender for Endpoint helps us automate routine tasks, but I don't specifically know what kind of automation it does or what we use it for, as the InfoSec team is responsible for that.
No solution is completely foolproof, but the configuration has a large part to play in the quality of the protection.
We have been in business for two years, so we're a relatively small and young company. Nevertheless, it's vital to have protection against malicious actors. The threat landscape we face today is complex and diverse, so our threat protection needs to be up to par. That's the benefit of using the product; we need to protect our data, and having a tool that informs us of potential threats is excellent.
As an end user, the solution didn't personally save me time, but I imagine it did for the InfoSec team who deal with it directly. The security reporting will all be in one place, and we don't have to go to the marketplace to look for separate tools to fulfill different functions.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Reliable with a good online community and an easy initial setup
Pros and Cons
- "It does not make Windows slow, as compared to all of the third part antiviruses."
- "We would like more customization."
What is our primary use case?
The solution is primarily used for antivirus and malware protection.
How has it helped my organization?
It definitely improves the organization in terms of security and productivity. We integrate the Defender with the Microsoft Cloud platform as well. It provides us with sandboxing and other functionalities in real time, where we can have the protection we need.
It's integrated with advanced threat analysis so we can see how the threat is coming into our network, what it is doing, and more. We can see everything step by step if a threat comes, including how this threat impacted the organization, et cetera.
What is most valuable?
The first thing which I noticed is that it is completely compatible with Windows. It does not make Windows slow, as compared to all of the third part antiviruses.
The stability has been good.
Technical support is helpful and they have a very robust online community as well.
The product can scale very well.
What needs improvement?
We would like more customization, actually. They're not too customizable. We'd like the flexibility to be able to set some applications on a white list. We need more options.
For how long have I used the solution?
I've used the solution for approximately five years.
What do I think about the stability of the solution?
The solution is stable and responsive.
What do I think about the scalability of the solution?
We have the solution deployed to around 350 users across four different locations.
It can scale to the thousands and thousands. I have seen customers here, some have approximately 12,000 devices and they're running that one program and it's going far without any issues.
How are customer service and support?
Technical support is good. They know things about the solution. The best part is that if anything happens, the Microsoft community is so big that any problem comes up, you can also just Google it and you will get the solution.
Which solution did I use previously and why did I switch?
We used McAfee and another solution as well and they both are great and amazing, however, they make PCs slow and every time something happens you have to call the vendor and they will help you support. The difference is, with Defender, it doesn't slow things done and you never have to call Microsoft.
How was the initial setup?
The initial setup is very straightforward. IT is actually my default. We actually helped our end-users with system centers, integrated Defender updates, Defender itself, patching, and Defender configuration using the consent and configuration manager. It's simple. It's not complex to set it up or manage.
It's a bulk operation to set it up, therefore, even if you have 100 PCs, it will only take you about an hour and you will be up and running with everyone. You only need one to two percent of your staff to handle the deployment and maintenance tasks.
What about the implementation team?
We used an integrator during the initial setup. They were quite helpful. Our experience with them was good.
What was our ROI?
We have seen an ROI.
What's my experience with pricing, setup cost, and licensing?
The solution is free for end-users.
What other advice do I have?
While we have the solution set up on our private cloud, you can also use a hybrid setup if that's better for your organization.
I would advise new users to connect it with an endpoint manager and connect it with the cloud and then let the real magic happen.
I'd rate the solution an eight out of ten.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Head-IT/SAP at Barista Coffee Company Ltd.
Easy to enable and activate but could be more secure
Pros and Cons
- "Defender is a part of Windows; you just need to enable it. There is no need to install anything."
- "The solution could always be more secure."
What is our primary use case?
Defender is basically a protective seal that is used to protect your Windows applications. Whenever you enable it your system is safe. You feel safe and your data and your security are verified by Defender and protected by the Defender seal.
What is most valuable?
Defender is a part of Windows; you just need to enable it. There is no need to install anything.
It's quite good for security. We are using Windows 11 and Windows 10. In Windows 11, Defender is very, very strong. They built in good features, good seals. Earlier, ransomware protection was not there. However, now, new ransomware protection is also available in Defender.
The solution is stable.
What needs improvement?
The solution could always be more secure.
What do I think about the stability of the solution?
The solution is very stable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The scalability is totally based on your OS operating system as it's a part of the OS. You can't define it in a different way. If your Windows platform is working fine and is of a certain size, then you can say that it's quite good and it will cover that.
We have 200 to 300 people using the solution. Some of our employees use Windows and have Defender. Others use Mac devices.
How are customer service and support?
We've used technical support in the past and don't have anything negative to say about their services.
How was the initial setup?
There isn't really an installation process. It's already a part of Windows and just needs to be activated. You can install Windows in home or business devices and have Defender at your fingertips immediately.
While you don't need a technical team to install it per se, every organization has an IT team that likely would be able to install Windows and everything else. We have a 40-plus IT team. Everybody has a defined role.
What about the implementation team?
We handled the implementation in-house using our IT team.
What's my experience with pricing, setup cost, and licensing?
The solution is included with Microsoft Office 365 subscriptions.
What other advice do I have?
New users who are leveraging Microsoft can decide if they want to use Defender. It's already there - you can either activate it or not, depending on your preference. It's nice that you have a choice. Many companies find Defender is enough for them, however, if you want more security, you may be able to add other firewalls or security features to your existing infrastructure.
I'd rate the solution at a seven out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
SOC Analyst with 1-10 employees
Provides comprehensive logs and the live response feature allows me to remotely access different endpoints and investigate malicious files
Pros and Cons
- "I enjoy using the live response feature, which allows me to remotely access different endpoints and investigate malicious files, such as malware that people may have downloaded, and other related issues."
- "Threat intelligence has the potential for improvement, particularly by integrating more sources."
What is our primary use case?
I am a SOC analyst and I use Microsoft Defender for Endpoint to investigate endpoints in our environment and malicious activity.
How has it helped my organization?
The visibility into threats that Defender provides is excellent. The logs I receive are quite comprehensive, allowing me to see what is happening on each endpoint, including the running processes and generated alerts. It does a pretty good job of detecting when certain events occur, which helps me stay attentive to potential issues. Overall, it offers significant visibility.
Defender does a good job in helping to prioritize threats across our entire enterprise because it provides me with context by distinguishing between high and medium threats.
We also utilize Azure Sentinel, Defender for Cloud Apps, Defender for Identity, and Office 365. These solutions are integrated together, and whenever one of them receives an alert, it is sent to the main alert queue. I would give the integration an eight out of ten.
Sentinel allows us to collect data from our entire ecosystem. We primarily use it for the network firewall logs, but it can also handle other types of logs.
Sentinel does an excellent job of providing us with comprehensive security protection and visibility into security alerts and incidents. It informs us about policy violations, such as foreign user sign-ins and sign-ins from multiple or different devices, among other things. Therefore, it offers greater visibility beyond just phishing alerts.
Microsoft Defender for Endpoint has significantly improved our organization by identifying the activities of individual users and effectively hunting for any threatening activities they might engage in. For instance, if a user downloads a malicious file or clicks on a malware-infected link, the software can promptly detect and mitigate the issue on the server.
Defender helps to automate routine tasks and the identification of high-value alerts. Sentinel aids in the automation process by allowing me to address the issue of numerous false positives. Specifically, I automated the handling of certain false positives that originated from a particular IP range. This IP range was generating false positives due to a flagged server, even though the server itself was not actually malicious. In such cases, Sentinel proved to be beneficial as it facilitated the automation and removal of unnecessary noise.
Microsoft Defender for Endpoint has helped save us the trouble of looking at multiple dashboards by providing a single XDR dashboard.
Microsoft Defender for Endpoint has been instrumental in saving us time, especially by identifying true positives instead of wasting time on false positives.
What is most valuable?
I enjoy using the live response feature, which allows me to remotely access different endpoints and investigate malicious files, such as malware that people may have downloaded, and other related issues.
What needs improvement?
Threat intelligence has the potential for improvement, particularly by integrating more sources. This will enable us to accurately identify when a domain or an IP is malicious. If we could obtain information from external sources, it would reduce the need to use different open source tools to verify whether a domain or IP is malicious or not.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for a year and a half.
What do I think about the stability of the solution?
Microsoft Defender for Endpoint is stable. I have only experienced one crash.
What do I think about the scalability of the solution?
Microsoft Defender for Endpoint proved to be scalable in our environment, supporting over 500 endpoints.
Which solution did I use previously and why did I switch?
I have also used Splunk. Splunk is more modular and portable, allowing us to integrate it with a wide range of different tools. In contrast, features of Defender and Sentinel, such as those provided by Microsoft, do not integrate well with as many other options.
What other advice do I have?
I would rate Microsoft Defender for Endpoint a nine out of ten. It provides me with greater certainty regarding malicious activity compared to Splunk, which demands much more analysis. Defender for Endpoint performs a significant amount of work in terms of identifying and validating malicious elements. This saves us from having to read and interpret a large number of logs. It takes care of the interpretation and conducts about half of the log analysis on our behalf.
I still have to conduct threat intelligence on my own, such as open-source intelligence. I don't automatically search VirusTotal for things, but I still end up doing my own source searching.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Head of IT & Database Management at a educational organization with 51-200 employees
Is easy to use and implement, and decreases the threat detection and response times
Pros and Cons
- "I like the simplicity of the portal and the integration with Microsoft Intune. Microsoft Defender for Endpoint is easy to use and implement."
- "Right now, there's a portal for Azure, portals for Microsoft Office, and portals for endpoints. It would be good to have only one portal and integrate everything."
What is our primary use case?
We use it to prevent malware attacks.
How has it helped my organization?
The automatic report is very good, and it is easy to see which user or device has a problem. The benefit we were able to realize immediately was protection.
What is most valuable?
I like the simplicity of the portal and the integration with Microsoft Intune. Microsoft Defender for Endpoint is easy to use and implement.
It has helped automate routine tasks and the finding of high-value alerts. However, we have a small IT team, and we have not automated many tasks.
It has also helped us save a little time, but we have saved more time with email protection. We have saved money as well because of ransomware protection.
Microsoft Defender for Endpoint's threat intelligence has helped us prepare for potential threats before they hit and take proactive steps. We have a scoreboard of each device and can quickly see which device needs an upgrade.
This solution has made our threat detection and response time faster by a few hours.
What needs improvement?
Right now, there's a portal for Azure, portals for Microsoft Office, and portals for endpoints. It would be good to have only one portal and integrate everything.
For how long have I used the solution?
I've been using this solution for five years.
What do I think about the stability of the solution?
Because it is in the cloud, the stability is good.
What do I think about the scalability of the solution?
It is easy to scale and increase capacity.
We are at one location with multiple departments such as IT, marketing, sales, invoicing, etc. We are a small company and have 53 users of Microsoft Defender for Endpoint.
How are customer service and support?
I have contacted Microsoft technical support a few times a year, and they have responded quickly. I'd give them a rating of nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used a different solution and switched to Microsoft Defender for Endpoint because the integration and alignment with Microsoft was great. The previous solution was heavy, and it took a long time to update.
How was the initial setup?
The initial deployment was easy and took a few hours.
It is deployed to the cloud, and I don't have to spend time on maintenance.
What about the implementation team?
I deployed it myself.
What was our ROI?
The ROI is very difficult to calculate, but it may be 20% ROI. We don't have any problems with ransomware or malware.
What's my experience with pricing, setup cost, and licensing?
It is an expensive solution. It would be nice if it could be included with the Microsoft Office package.
What other advice do I have?
In theory, the best-of-breed strategy is not secure, and practically, a single vendor's suite is better because there is only one contact.
I would recommend trying Microsoft Defender for Endpoint and would give it an overall rating of nine on a scale from one to ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Technical Specialist at a retailer with 10,001+ employees
Very user-friendly, offering safety, security and providing a phenomenal amount of good information
Pros and Cons
- "User-friendly, offering safety and security."
What is our primary use case?
It's an antivirus product, so its main use is to protect us.
What is most valuable?
This is a really good product, it's user-friendly and offers us safety and security.
What needs improvement?
The technical support could be improved.
For how long have I used the solution?
I've been using this solution for three years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
In terms of scalability, we went from 10 pilot machines to 35,000 devices.
How are customer service and support?
The technical support isn't too bad but their responsiveness needs to be improved. I'd say it's their biggest issue.
How was the initial setup?
The initial setup is very easy, probably one of the easiest onboarding processes I've done. Implementation was done in-house and takes a few minutes per device; click it and go. I deal with anything related to antivirus patching and encryption and we have four cyber analysts that look after whatever comes out of ATP or Defender for Endpoint.
What other advice do I have?
My advice would be to plan carefully and make sure you take notice of what's coming out because it pushes out a lot of very useful information. It's a matter of having sufficient staff because the amount of information it gives you is phenomenal. If a company doesn't have sufficient resources then any other antivirus might work, but this thing produces so much useful information that if you're implementing this solution it's worthwhile having the staff to deal with it.
I rate this product 10 out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2024
Product Categories
Endpoint Protection Platform (EPP) Advanced Threat Protection (ATP) Anti-Malware Tools Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
CrowdStrike Falcon
Cisco Secure Endpoint
SentinelOne Singularity Complete
Fortinet FortiClient
Cortex XDR by Palo Alto Networks
Symantec Endpoint Security
Intercept X Endpoint
Trend Vision One Endpoint Security
Trellix Endpoint Security
Kaspersky Endpoint Security for Business
ESET Endpoint Protection Platform
Check Point Harmony Endpoint
VMware Carbon Black Endpoint
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- What do you think of the integration of Azure AD Services, Defender for Endpoint, and Intune as comprehensive security solutions?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- Running Carbon Black Defense Along with Windows Defender
- How is Cortex XDR compared with Microsoft Defender?
- Which offers better endpoint security - Symantec or Microsoft Defender?
- How does Microsoft Defender for Endpoint compare with Carbon Black CB Defense?
- How would you compare between Microsoft Defender for Endpoint and Tanium EDR?
- How does pricing work for Microsoft Defender for Endpoint?