I use it for investigating incidents.
Cloud solution engineer at a computer software company with 51-200 employees
Helps me create reports during investigations
Pros and Cons
- "I like its investigation capabilities, as that is what is most important to me. It is fairly simple with a user-friendly interface."
- "They have moved features from one console to another. Things have been moved around in the interface and it takes me time to find where certain features are."
What is our primary use case?
How has it helped my organization?
It has helped eliminate looking at multiple dashboards, which is very useful. During the investigation of incidents, it helps in making reports.
It has saved me time and my nerves. It has also likely saved us money by blocking unexpected threats. It has also definitely decreased our time to detection and time to respond.
What is most valuable?
I like its investigation capabilities, as that is what is most important to me. It is fairly simple with a user-friendly interface.
Also, all Microsoft products can be used with each other, as opposed to other vendors' products that cannot be used with each other.
What needs improvement?
They have moved features from one console to another. Things have been moved around in the interface and it takes me time to find where certain features are.
Buyer's Guide
Microsoft Defender for Office 365
February 2025

Learn what your peers think about Microsoft Defender for Office 365. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
841,004 professionals have used our research since 2012.
For how long have I used the solution?
I've been working with Microsoft 365 for two years.
What do I think about the stability of the solution?
It's a stable solution. I have only had one serious incident, a few months ago, when Microsoft wrote that there were some difficulties with networking.
What do I think about the scalability of the solution?
It's scalable and this is important. I have had clients with 10 to 20 users and others with a few thousand.
How are customer service and support?
Unfortunately, support has become difficult. Very often I get a hyperlink from Microsoft as an answer, but I only submit requests after I have read all the information that is available. My questions are not simple. In the past, I would have rated their support a nine or 10 out of 10, but now it's a seven.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I used ESET and Fortinet at my previous companies.
How was the initial setup?
Our deployments are on private cloud, hybrid, and on-premises. Deployment time depends on the tasks involved. Some are done in a few days and others can take six weeks.
The initial setup can be straightforward or complex. For one client, due to authentication methods, some users couldn't access their old clients.
What's my experience with pricing, setup cost, and licensing?
One problem is its pricing because I was working in the government and it was too expensive for us to use our Microsoft products.
Which other solutions did I evaluate?
For protection, I like Microsoft Defender for Office 365 and ESET in this price range.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner

Solutions Architect at a computer software company with 1,001-5,000 employees
From process efficiency angle, we are definitely seeing benefits
Pros and Cons
- "Defender for Office 365 has helped eliminate having to look at multiple dashboards and that is the aspect I like most about it. It is simpler, effective, and convenient. The users like the process efficiency."
- "One area for improvement is integration. For example, when it comes to external SaaS platforms, we were not able to get a lot of information on integrations with such apps for security and authentication."
What is our primary use case?
We use it to monitor user behavior and activity. It also gives us analytics to protect the user identities and extensions stored in Active Directory. For one of the instances that we are managing, we have to sync it with Active Directory and protect user identity.
How has it helped my organization?
It is a basic SecOps tool. It has not increased or improved anything specifically for our organization, but I see it as a must-have for security ops.
It can help automate routine tasks and finding of high-value alerts. Our security operations are not very high-volume, but from the angle of process efficiency, it is definitely a very beneficial product.
Defender for Office 365 has helped eliminate having to look at multiple dashboards and that is the aspect I like most about it. It is simpler, effective, and convenient. The users like the process efficiency.
And there are a couple of aspects, time-wise. One is that the documentation makes everything so easy that we were able to understand it without much external support. The second is how it automates the process and gives everything in one console. It is helping us with process efficiency. I would estimate it is saving us 10 to 15 man-hours per month. But it is more an issue of process efficiency and having the right process in place. It is not for time-savings, primarily.
And it is likely to help us with our time to detect and respond, although we haven't faced one threat yet.
What is most valuable?
It's a little early to tell which features are most valuable, but by default, it gives analytics on user behavior. We have not been able to leverage it fully, but that is one of the interesting features. It's also very simple to use. The documentation has made it quite easy to implement and our team has been able to understand it.
And while we haven't had even one threat incident yet, functionality-wise, Defender for Office 365 can proactively detect threats and prevent them. It is not just a reactive mechanism.
What needs improvement?
One area for improvement is integration. For example, when it comes to external SaaS platforms, we were not able to get a lot of information on integrations with such apps for security and authentication. The awareness of ecosystem information that is provided needs to be better.
For how long have I used the solution?
We implemented Microsoft Defender for Office 365 over the last month.
What do I think about the stability of the solution?
The stability of Defender for Office 365 is competitive.
What do I think about the scalability of the solution?
It is very scalable. I've seen implementations in organizations with thousands of employees.
For us, it is being used across endpoints for all the users in our organization, and it is multi-geographic as well. We are a small organization with only 10 users.
How are customer service and support?
Microsoft technical support is very good. For this particular product we have not reached out to them, but otherwise, we find Microsoft support to be quite good.
The product itself is so good that we rarely have to raise a support ticket. The product and documentation are self-explanatory and we are able to troubleshoot things ourselves.
How would you rate customer service and support?
Positive
What's my experience with pricing, setup cost, and licensing?
If we had compared it with other vendors, then I would have more to say about the cost, but we didn't. However, standalone, the cost is convenient.
Which other solutions did I evaluate?
We did not explore other vendors. This was a default choice for us.
What other advice do I have?
We have not faced any incidents so we are not able to comment on how well it handles them. But in our organization, we are using basic antivirus software and that aspect is covered in that solution as well. It also has functionality for prioritizing threats but we have not implemented it.
The solution does not require much maintenance. There is the setup and it is mainly a matter of monitoring after that.
When you consider a best-of-breed strategy versus a single vendor's security suite, I prefer a single vendor because of the failure points. If there are interconnected failure points, there is a single vendor to work with to fix them and identify the gaps. And when it is within the same ecosystem, the product releases are compatible with each other and, together, give us more value. While a multi-vendor strategy has its benefits, if we stick to a single vendor for the entire stack, it is a better scenario in which to manage and monitor.
If you're using Office 365, Defender for Office 365 is the default primary choice. There are no shortcomings in it, that I have seen, that should make someone look for an alternate solution. It is the default choice for this particular use case and it serves its purpose.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Microsoft Defender for Office 365
February 2025

Learn what your peers think about Microsoft Defender for Office 365. Get advice and tips from experienced pros sharing their opinions. Updated: February 2025.
841,004 professionals have used our research since 2012.
Sr. Manager, End User Experience at a comms service provider with 10,001+ employees
Protects confidential and sensitive information
Pros and Cons
- "Microsoft Defender for Office 365 helps people to work remotely. It is a secure solution. We don't need to use our company's computers or get VPN connections to the networks. I can control how they share screens and what they send to the devices. It keeps our organizations confidential and sensitive information safe."
What is our primary use case?
We use Microsoft Defender for Office 365 for our external developers.
How has it helped my organization?
The tool offers the best experience to meet international contractors.
What is most valuable?
Microsoft Defender for Office 365 helps people to work remotely. It is a secure solution. We don't need to use our company's computers or get VPN connections to the networks. I can control how they share screens and what they send to the devices. It keeps our organizations confidential and sensitive information safe.
What do I think about the scalability of the solution?
Microsoft Defender for Office 365 is scalable.
How was the initial setup?
Microsoft Defender for Office 365's deployment is straightforward.
What's my experience with pricing, setup cost, and licensing?
The product is expensive.
What other advice do I have?
The flexible tool helps hide windows from people trying to control the PC's remote. I rate it a seven out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Protects from zero-day threats and ensures that attachments and links are safe, but has a lot of false positives and should have only one plan that takes care of everything
Pros and Cons
- "Safe attachments, safe links, policies, and the ability to protect from zero-day threats are the most valuable features."
- "In some situations, it has not been able to pick impersonated emails having no attachments. Technical support definitely has a scope for improvement."
What is most valuable?
Safe attachments, safe links, policies, and the ability to protect from zero-day threats are the most valuable features.
What needs improvement?
In some situations, it has not been able to pick impersonated emails having no attachments. Technical support definitely has a scope for improvement.
For how long have I used the solution?
I have been using this solution for the last one year. I have its latest version.
What do I think about the stability of the solution?
It is stable. We didn't find any issues with that.
What do I think about the scalability of the solution?
It is highly scalable. We have deployed for around 7,000 accounts. Performance is not impacted.
How are customer service and technical support?
Their technical support can definitely be improved. They can avoid using templatized response.
Which solution did I use previously and why did I switch?
We had basic Exchange Online Protection.
How was the initial setup?
It was easy to configure and with one/two skilled the ongoing maintenance can be handled.
What's my experience with pricing, setup cost, and licensing?
It has a simple interface to configure and manage. From the pricing point of view, like any other product in the market, there is scope for negotiation.
Which other solutions did I evaluate?
Before we chose to settle with this product, we experimented with Cisco, Forcepoint, etc.
What other advice do I have?
I would advise others to do a proof of concept for at least a month before taking a decision.
I would rate Microsoft Defender for Office 365 a eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Chief Information Security Officer at a outsourcing company with 10,001+ employees
Deployment capability is a great feature but we're getting too many false positives
Pros and Cons
- "The deployment capability is a great feature."
- "Too many false positives and lacks an accurate capability to detect malicious SharePoint sites."
What is our primary use case?
We use Microsoft Defender for Office 365 for email security. We are partners of Microsoft and I'm the company's chief operation security officer.
What is most valuable?
The deployment capability is a great feature. We're able to activate this feature throughout France with a click.
What needs improvement?
I'd like to see fewer false positives and potentially have an accurate capability to detect malicious SharePoint sites. There could also be an improvement in some of the features related to training. In a phishing test campaign, for example, it should be more user-friendly and include the capability to evaluate and assess users' understanding of the content provided.
For how long have I used the solution?
I've been using this solution for several years.
How are customer service and support?
The customer support could be more advanced at the technical level and more responsive. There should also be more communication on updates.
Which solution did I use previously and why did I switch?
We previously had some reinforced email security features with Microsoft; this is just an improvement on what we had.
What's my experience with pricing, setup cost, and licensing?
This is quite an expensive solution and understanding the pricing model and features is quite complicated and it can, in fact, be a nightmare when dealing with Microsoft.
Which other solutions did I evaluate?
We reviewed several on-premise solutions such as Forcepoint that could be integrated with other components within our infrastructure. The reason we didn't go with them is that we have to respond quickly to threats and at an international level. Given the complexity of our situation in terms of architecture, we decided to go with a ready-to-use solution.
What other advice do I have?
We haven't had a review recently, so I can't say that this is the best solution on the market. Things are evolving all the time with new features constantly being added to all solutions. For now, I would rate this solution seven out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Co-Founder with 11-50 employees
A highly efficient solution that saves us time
Pros and Cons
- "Defender helps us prioritize threats across our organization."
- "The pre-sales cost calculations could be more transparent."
What is our primary use case?
Defender for Office 365 protects Office 365, which is the industry standard office software suite. It is the only Microsoft security solution we use. We don't use any specialized features. It's a standard deployment.
What is most valuable?
Defender helps us prioritize threats across our organization. Defender for 365 is highly efficient and saves us time. We save about 35 percent compared to other solutions.
What needs improvement?
The pre-sales cost calculations could be more transparent.
For how long have I used the solution?
I have used Defender for Office 365 for the last three years.
How are customer service and support?
We mostly rely on internal support at my organization. They are not certified by Microsoft, but they have some experience with Microsoft solutions. We contact Microsoft if we need additional support. I would rate them highly.
How was the initial setup?
Setting up Defender for 365 is straightforward, and we did it ourselves following the standard Office 365 setup.
What other advice do I have?
I rate Microsoft Defender for Office 365 an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cybersecurity and Business Continuity Consultant at a tech services company with 201-500 employees
Reliable, simple setup, but best practice information needed
Pros and Cons
- "The most valuable feature of Microsoft Defender for Office 365 is the ease of use."
- "Microsoft Defender for Office 365 could improve by giving customers information on techniques to prevent threats. For example, information about best practices on how to protect their own devices against hackers and scammers, such as educational information or training. This would help others have a better understanding of cyber security. Additionally, there can be more security features added."
What is our primary use case?
We are using Microsoft Defender for Office 365 to defend against computer threats.
What is most valuable?
The most valuable feature of Microsoft Defender for Office 365 is the ease of use.
What needs improvement?
Microsoft Defender for Office 365 could improve by giving customers information on techniques to prevent threats. For example, information about best practices on how to protect their own devices against hackers and scammers, such as educational information or training. This would help others have a better understanding of cyber security. Additionally, there can be more security features added.
For how long have I used the solution?
I have been using Microsoft Defender for Office 365 for approximately five years.
What do I think about the stability of the solution?
Microsoft Defender for Office 365 is a stable solution.
What do I think about the scalability of the solution?
The solution is scalable in my usage.
How are customer service and support?
I have not used the technical support from Microsoft. I managed to fix any issues I had myself.
How was the initial setup?
The implementation is simple and Microsoft Defender for Office 365 because it comes with Microsoft Windows, works as soon as the computer is on.
What's my experience with pricing, setup cost, and licensing?
Microsoft Defender for Office 365 comes with Microsoft Windows. It is free with the operating system.
What other advice do I have?
I rate Microsoft Defender for Office 365 a seven out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Sales Account Manager at a tech services company with 51-200 employees
Simple implementation, effective email threat detection, and secure
Pros and Cons
- "The solution is very easy to use. All you have to do is to assign the license to the end-user and it's done. The customer will only have the feature activated, and the solution will monitor the emails to determine if they are a threat or not."
- "They can improve their security in a way where a customer can know if all their attachments are safe or not to open through a report. The solution does its job perfectly, but it never reports to the customer whether those attachments have been stopped before or not."
What is our primary use case?
Microsoft Defender for Office 365 was a product called Advanced Threat Protection(ATP) in the beginning and it was changed. Microsoft Defender for Office 365 is an email security. Our customers should know that it is only email security and not a full security feature solution. It is for checking the attachments of emails, and it will move them on if they are secure, and if they are not secure it will not move them forward.
What is most valuable?
The solution is very easy to use. All you have to do is to assign the license to the end-user and it's done. The customer will only have the feature activated, and the solution will monitor the emails to determine if they are a threat or not.
What needs improvement?
They can improve their security in a way where a customer can know if all their attachments are safe or not to open through a report. The solution does its job perfectly, but it never reports to the customer whether those attachments have been stopped before or not.
For how long have I used the solution?
I have been using Microsoft Defender for Office 365
What do I think about the scalability of the solution?
Microsoft Defender for Office 365 has been scalable.
How was the initial setup?
The implementation is simple, once you have the license you assign it to the end-user.
What was our ROI?
We have seen a return on investment because if we would have received a phishing email, Microsoft Defender for Office 365 would help out to detect the threat instead of crashing down the whole company. The solution keeps emails protected with high security benefiting the company, whether it's an inbound or outbound email.
What's my experience with pricing, setup cost, and licensing?
Microsoft Defender for Office 365 is an add-on to the Office license. Many customers are purchasing this solution.
What other advice do I have?
I would advise every customer who requires email security to purchase Microsoft Defender for Office 365.
I rate Microsoft Defender for Office 365 a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer:

Buyer's Guide
Download our free Microsoft Defender for Office 365 Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2025
Popular Comparisons
Proofpoint Email Protection
Cisco Secure Email
Microsoft Exchange Online Protection (EOP)
Cloudflare One
Fortinet FortiMail
Check Point Harmony Email & Collaboration
Abnormal Security
Trend Micro Email Security
TitanHQ SpamTitan
Perception Point Advanced Email Security
Trellix Collaboration Security
Buyer's Guide
Download our free Microsoft Defender for Office 365 Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which solution do you prefer: Microsoft Defender for Office 365 or Proofpoint Email Protection?
- Is Defender for Office 365 enough? Or should we be using a product like Mimecast?
- Have you done a comparison between BeyondTrust Endpoint Privilege Management and Microsoft Defender?
- Which product do you prefer: Symantec Messaging Gateway or Microsoft Defender?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- When evaluating Messaging Security, what aspect do you think is the most important to look for?
- Which Email Security enterprise solution would you choose: Cisco Secure Email vs Forcepoint Email Security vs Barracuda Email Security Gateway?
- What is the best email encryption software for small enterprises using Office 365?
- What security measures should businesses prioritize to support secure remote work?
- When evaluating Email Security tools, what aspects do you think are the most important to look for?