We are a Microsoft partner and we have clients who are Microsoft 365 administrators in several companies. They are looking for ways to secure their tenants and make sure that their security is top-notch. That's where Microsoft Defender comes in. We use Microsoft 365 Defender for security and compliance to secure tenants from malicious attacks, including spam and phishing attacks. And when it comes to compliance, it is used for data privacy and data protection to ensure that very sensitive data doesn't go out to the wrong location.
Security and Compliance Engineer - Data Protection at a tech services company with 1,001-5,000 employees
Vast range of audit log search options helps analysts carry out a full search
Pros and Cons
- "Many people don't realize that Microsoft Azure, Exchange Online, and the security and compliance portal all sync together. For instance, within the Azure portal you can set security restrictions and policies to help secure your tenants... The good part of it is that these products have already been integrated. When you sign on as an admin you have global admin rights and that gives you access to all these features."
- "Overall, the comprehensiveness of the threat protection is at 95 percent."
- "The message trace feature for investigating mail flow issues should add more detailed information to the summary report... if they could extend the summary report a little bit, make it more descriptive, ordinary administrators could understand what happened and that the emails failed at this or that point. That way they would know the location to go to try to correct it and to prevent it from occurring again."
- "Their response time is okay, it works fine, but the time it takes to resolve escalated cases needs improvement."
What is our primary use case?
How has it helped my organization?
It makes security and protection very seamless.
And Defender saves me time. For instance, if I get notified that a user isn't receiving emails from a particular person, I know that the first thing I have to do is a message trace. It saves me time to an extent because I have a go-to location. With message trace, I'm able to trace emails from, for example, abc@givendomain.com over the past two days. It gives me information about what actually happened in the mail flow. I'd rate the time it saves me as a seven out of 10.
It has also saved us money, on the order of 50 percent. And our time to respond has improved to the level of a six out of 10.
What is most valuable?
The features of the solution are vast and wide.
The most valuable feature is the content search feature in the compliance portal. It is very useful because it covers both audit log search and content search. The audit log search is very useful because, most of the time, you see several changes within the admin portal and it's hard to keep track of what happened. Our customers want to get to the root cause and see the activity that must have triggered those changes. That's where the audit log search comes in. They've enhanced the feature in such a way that it has a vast range of search options so that an analyst can carry out a full search.
The content search feature has also advanced to a point where you can carry out several searches with your keywords. You can point it to a certain location, such as Exchange Online or SharePoint Online, or Teams Online. You can narrow the search down to a particular individual or group of individuals. When administrators report that they have lost content or accidentally deleted a mailbox or the mailbox content, the content search feature is a good way to recover the content.
Another top feature is threat management. It helps prioritize threats across the enterprise.
In addition, you can navigate to the security compliance portal and set restrictions to block IP addresses from different locations. You can also choose to flag domains that are sending malicious attacks and block them and update the anti-spam policy to make it more strict to prevent attacks from happening in the future.
Many people don't realize that Microsoft Azure, Exchange Online, and the security and compliance portal all sync together. For instance, within the Azure portal, you can set security restrictions and policies to help secure your tenants, but most administrations do not know about that, including things like multi-factor authentication, conditional access policies, and privileged access.
We've had reports from clients about compromised accounts because someone got access to a password that they shouldn't have. Multi-factor authentication helps eliminate this. As for conditional access policies, you can set certain policy restrictions to certain locations or IP addresses so that emails or sign-ins only come from particular locations. That helps secure your environment against malicious sign-ons to your accounts.
The good part of it is that these products have already been integrated. When you sign on as an admin you have global admin rights and that gives you access to all these features. You will see Exchange Online, security and compliance, and Microsoft Azure. All you need to do is click and it takes you to the portals.
Overall, the comprehensiveness of the threat protection is at 95 percent. It's not 100 percent because of updates not being done on the Knowledge Base and technical know-how.
The alert feature allows you to set the severity of alerts. If there is a malicious or suspicious sign-on, an alert triggers immediately letting you know, as an administrator, to check what's going on in that account. For example, there was a time when one of our users' accounts was about to be compromised. We got an email notification which was sent to all administrators on the tenant. I was able to block that activity in real-time and then set the system to trigger more alerts for such sign-ons in the future. I also blocked the IP address. That particular feature has helped. The alert arrived in real time to prevent the account from being compromised.
What needs improvement?
When changes are done within either the admin or security and compliance portals, there should be a real-time update to administrators about the changes. Many times I'm supporting a case where someone says, "I used to do this like this, but I'm unable to do it that way anymore. What happened?" And I will have to say, "Oh, sorry. That doesn't work like that anymore. It's now done this way." So there should be a way to notify people about changes like that, and prompt information when changes are done within a portal.
I would also like to see regular updates about new features in the Knowledge Base. There are cases where I'm using a Knowledge Base article to try to educate a customer, but when I check the feature on the admin portal, and in the article, they don't look alike. For instance, it's saying, "Go to settings. From settings, go to options." Meanwhile, on the portal itself, I'm seeing "Settings, go to more settings, then go to options." It would help a whole lot if feature updates were updated in real-time in the documentation.
Also, the message trace feature for investigating mail flow issues should add more detailed information to the summary report. The summary report is what the administrators are able to understand. The extended reports are a very deep dive and the administrators will only understand them if they reach out to support engineers. But if they could extend the summary report a little bit, and make it more descriptive, ordinary administrators could understand what happened and that the emails failed at this or that point. That way they would know the location to go to try to correct it and prevent it from occurring again. Making that summary report more extensive and detailed would be of great help.
Buyer's Guide
Microsoft Defender XDR
August 2026
Learn what your peers think about Microsoft Defender XDR. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
912,818 professionals have used our research since 2012.
For how long have I used the solution?
I have been using Microsoft 365 Defender for a little over three years.
What do I think about the stability of the solution?
Overall, it is stable.
There are a few bugs but they generally don't impact the reliability. The bugs are not the kind that impact the work done by an organization. Processes can continue while they fix the bugs.
What do I think about the scalability of the solution?
It is scalable.
It is used across multiple departments with anywhere between one and 200 endpoints.
How are customer service and support?
Their response time is okay, it works fine, but the time it takes to resolve escalated cases needs improvement. An escalated case is when there is a bug. You could literally have reported a bug and it's still not resolved the following week. Bug fixes take a long time, especially when a very essential feature is not working as expected.
How was the initial setup?
It took me three to five months to understand it because it has a vast number of features. If you do not understand it, one click could mess up a whole lot of things.
What's my experience with pricing, setup cost, and licensing?
Microsoft should provide lower-level licensing options. They should do it in such a way that even an individual could purchase a license, and it should be entirely flexible. An individual should be able to access the solution at a very affordable rate.
Which other solutions did I evaluate?
Most administrators, in my experience so far, are reaching out to third parties for email filtering and to manage threats in their organization. According to them, Microsoft 365 Defender isn't giving them the information they need. And I realize that this is not correct. What they're missing out on is the proper information or technical know-how to utilize the features.
For example, if someone uses Barracuda as their third-party filtering service, I begin to ask questions such as, "Okay, why did you choose to use the Barracuda service when we have the ability to create good anti-spam policies that could help secure your tenant? You can create anti-phishing policies and rules that will help restrict IP addresses." Often, what they say is that Barracuda is better because it gives them more information and real-time data. At that point, I ask them to let me provide a deep dive into the features of Microsoft 365 Defender. I use the documentation and Knowledge Base articles to explain its features, one after the other, and they begin to say, "Oh wow." They didn't know these features actually exist. They'll begin to look at the possibility of utilizing the Microsoft solution since they have paid for it. Why should they pay additional money to a third party to get services that Microsoft provides? They feel very happy about the information I provide.
So far so good. The Microsoft 365 product hasn't given me a reason to want to check for other products and move to something else.
What other advice do I have?
For the best and most seamless user experience, it's best to go with a single vendor because there could be a lot of complications going with a best-of-breed strategy. It's easier to understand things with a single vendor.
When you don't understand a feature, ask questions and reach out for support. There are some features that are being used wrongly or that are underutilized.
Also, test the product beforehand. They provide trials so you can test the solution and see if it meets your expectations.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Senior Business Consultant at PeakUp
User-friendly and easy to set up threat protection solution with good scalability and stability
Pros and Cons
- "Setting up Microsoft 365 Defender is easy. It's a user-friendly solution that provides threat protection. It has good stability and scalability."
- "What I found most valuable in Microsoft 365 Defender is that it's able to scan emails and protect users from dangerous links or attachments."
- "What could be improved in Microsoft 365 Defender is its licensing, e.g. it should be more consolidated and would be good if it has some optimizations. Improving the alerts and notifications, in terms of adding more details, would also be good for this solution."
- "What could be improved in Microsoft 365 Defender is its licensing; it needs to be more consolidated, because there are so many plans for Microsoft 365 Defender, and every other year, there will be new licensing options that become more and more different from each other."
What is our primary use case?
Microsoft 365 Defender is one of the first layers to our security. It's our first layer security product, e.g. we use it, then we also use Exchange Online Protection for email, Safelink, etc.
We always recommend these products to our customers, e.g. if the customer is using another third-party product. We are always recommending these compliance and security products, e.g. Microsoft 365 Defender, Cloud App Security, etc.
We usually recommend cloud security because it connects all of these security and compliance products in one center to take logs and make them meaningful, plus you can also create alerts. We are also recommending it because of Microsoft Teams usage, especially because in Microsoft Teams, users sometimes do mass deletion, mass download, etc. We always say: "Let's connect your Cloud App security with your Azure Information Protection, with Microsoft 365 Defender and your Microsoft Teams, your Engula, etc. We find cloud security to be very useful.
What is most valuable?
What I found most valuable in Microsoft 365 Defender is that it's able to scan emails and protect users from dangerous links or attachments. This is important in a first layer or base layer security product such as Microsoft 365 Defender. You can even combine Microsoft Defender for Endpoint with this solution to get the most benefits.
I also find Microsoft 365 Defender user-friendly, so that's another valuable feature of this solution.
What needs improvement?
What could be improved in Microsoft 365 Defender is its licensing. It needs to be more consolidated, because there are so many plans for Microsoft 365 Defender, and every other year, there will be new licensing options, e.g. plan one, plan two, etc., that become more and more different from each other. The most valuable product would be the most expensive product, and customers usually say: "We really need the last version, but that's really expensive for us, because we are in Turkey and the currency is very, very high now." Three years ago, this wasn't a problem, because $1 was three or four Turkish liras, but now it's 15.
In the licensing options, it would also be better if there can be some optimizations, similar to what Power BI Pro offers. There are two options in Power BI: user-based and capacity-based. It would be good if there can be another option for one consolidated product for the whole company with a higher price, but you cannot depend on user count.
What I'd like to see in the next release of Microsoft 365 Defender is for them to provide more details in the alerts and notifications they send out.
For how long have I used the solution?
We've been a partner for Microsoft for 10 years.
What do I think about the stability of the solution?
I found that the stability of Microsoft 365 Defender is good.
What do I think about the scalability of the solution?
Scalability is good in Microsoft 365 Defender.
How are customer service and support?
What we have is Premier Support from Microsoft, e.g. we are a CSP partner, so we were required to buy Premier Support and Cloud Consulting from Microsoft. We are really happy with the support we've been receiving for Microsoft 365 Defender, but on the customer side, they don't have Premier Support, and sometimes, depending on the case, they're not very satisfied with the support.
Our satisfaction is five out of five, but our customers would only have three or four out of five, in terms of their satisfaction with Microsoft 365 Defender support.
How was the initial setup?
The initial setup for Microsoft 365 Defender is really easy. It's not very complicated. I didn't see any other difficulties with setting it up, but customers sometimes think it's not very easy. They purchase consulting services from us, so it doesn't bother us, but sometimes the customer says: "I don't know how to start, but I use Microsoft Security." Microsoft is very late in the security niche, so customers sometimes say: "We have Symantec", or they would mention that they have other products from other vendors, and these vendors are very reliable for many, many years.
In the last three or four years, though, customers start to depend on Microsoft Security products, but they are not early adopters, because they usually tell us: "When we buy the product, some policies cannot be used, but after sometime we can use it." It's not really a problem, but I wanted to relay some of the feedback we get from our customers.
What's my experience with pricing, setup cost, and licensing?
The most valuable licensing option is expensive, so pricing could be improved. Licensing options for this solution also need to be consolidated, because they frequently change.
What other advice do I have?
We've been dealing with the latest version of Microsoft 365 Defender.
For an average project, deployment of Microsoft 365 Defender can take a week, but we do need some change management models, because we still need to train the users about safe links and attachments, so we sometimes have to expand the average time, but implementation is not very hard. If we only do the implementation, one week is more than enough.
We rely on just one to two persons, particularly engineers, for the deployment and maintenance of Microsoft 365 Defender.
My recommendation to others looking into implementing Microsoft 365 Defender is that reading the documentation is really good. If you are a Microsoft partner, you'll also have benefits, e.g. CDS tenants and demo tenants that are free to you for one year, so you can test the products first, before you implement. If you are a partner, my advice is to use your Microsoft partner benefits.
I'm giving Microsoft 365 Defender a rating of eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Microsoft Defender XDR
August 2026
Learn what your peers think about Microsoft Defender XDR. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
912,818 professionals have used our research since 2012.
Information Security Analyst II at a computer software company with 51-200 employees
An all-in-one solution that eliminates the need for multiple products or technical controls
Pros and Cons
- "What I like most about the product is its all-in-one solution. With Microsoft Defender XDR, we get coverage for various aspects like endpoint security, cloud security, and image-related cases, all within a single platform. This eliminates the need for multiple products or technical controls to address incidents. The main benefit became evident immediately after deployment, especially in its ability to analyze files and phishing emails quickly. By submitting suspicious files or emails, we receive quick results on whether they are legitimate, suspicious, or malicious, saving time."
- "The solution could enhance the threat Intelligence feature by making it more relevant to specific industries. Much of the threat intelligence information isn't directly applicable to our environment. It would be beneficial if the threat intelligence were tailored to the industry, such as healthcare or fintech, where the solution is being used."
What is our primary use case?
We use the solution for endpoints.
What is most valuable?
What I like most about the product is its all-in-one solution. With Microsoft Defender XDR, we get coverage for various aspects like endpoint security, cloud security, and image-related cases, all within a single platform. This eliminates the need for multiple products or technical controls to address incidents. The main benefit became evident immediately after deployment, especially in its ability to analyze files and phishing emails quickly. By submitting suspicious files or emails, we receive quick results on whether they are legitimate, suspicious, or malicious, saving time.
What needs improvement?
The solution could enhance the threat Intelligence feature by making it more relevant to specific industries. Much of the threat intelligence information isn't directly applicable to our environment. It would be beneficial if the threat intelligence were tailored to the industry, such as healthcare or fintech, where the solution is being used.
Additionally, the MDCA feature could be improved to provide more accurate data on how much data is uploaded or downloaded from the cloud. This might involve better implementation from our infrastructure team, but clearer and more precise reporting on cloud data activities would be valuable.
For how long have I used the solution?
I have been using the product for eight to ten months.
What do I think about the stability of the solution?
The solution works smoothly.
What do I think about the scalability of the solution?
The tool's scalability is good.
How are customer service and support?
If we open a case on the Microsoft portal, a support person from Microsoft helps resolve the queries. From our side, it usually involves two or three people. The Microsoft support person sometimes brings in another expert to resolve technical queries.
We've submitted our queries, and a tech support engineer comes through on a chat, a Zoom call, or another type of call. We discuss the queries with them, and they usually resolve the issues in one or two sessions.
Sometimes, if one engineer can't resolve the query, they will bring in another engineer, which can take an additional one or two days.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We chose Microsoft Defender XDR because it provides a one-stop solution. Everything related to endpoint security, email security, or cloud applications is integrated and visible in a single window. If we were to use other solutions, we would need to implement three different products to achieve the same level of integration and functionality.
How was the initial setup?
We had some issues while deploying the tool's on-prem version. Support helped us resolve them. The cloud version is easy to deploy, while the on-prem version takes one month and doesn't require any maintenance.
What other advice do I have?
I rate the overall product an eight out of ten. If a new customer is going to buy Microsoft Defender XDR, they should clearly state their needs in front of the Microsoft team. They need to specify what they want and what features they require. It's good for the Microsoft team and the customer to understand all the requirements before deployment clearly. This way, any potential issues can be addressed beforehand, making the deployment smoother.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director of IT at a government with 501-1,000 employees
Integrates security into one tool instead of having third-party security tools
Pros and Cons
- "The product integrates security into one tool instead of having third-party security tools."
- "The solution does not offer a unified response and standard data."
What is our primary use case?
We use Microsoft Defender XDR to secure data.
How has it helped my organization?
Microsoft Defender XDR has reduced our security staff.
What is most valuable?
The product integrates security into one tool instead of having third-party security tools.
What needs improvement?
The solution does not offer a unified response and standard data.
For how long have I used the solution?
I have been using the product for three years.
What do I think about the stability of the solution?
Microsoft Defender XDR is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
It takes weeks for the support to respond. They are not helpful.
How would you rate customer service and support?
Negative
How was the initial setup?
Microsoft Defender XDR's deployment was very easy.
What was our ROI?
We have seen ROI with the tool's use.
What's my experience with pricing, setup cost, and licensing?
Microsoft Defender XDR's licensing is complicated.
What other advice do I have?
Microsoft Defender XDR has helped us reduce two full-time employees.
The solution is our identity source, which protects our identities through Microsoft Intra ID.
The solution helped us save time by not flipping between the systems.
I rate it an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Technology Support Technician at a tech services company with 51-200 employees
Helps with malware detection and browser protection
Pros and Cons
- "We are connected to Microsoft and have every laptop enrolled. This acts as an endpoint. The tool helps me check security and compliance. I can also check what a device is doing."
- "We should be able to use the product on devices like Apple, Linux, etc."
What is our primary use case?
We use Microsoft Defender XDR for malware detection and browser protection. We have around 500 devices to protect. We use it to get reports for each of these devices.
What is most valuable?
We are connected to Microsoft and have every laptop enrolled. This acts as an endpoint. The tool helps me check security and compliance. I can also check what a device is doing.
What needs improvement?
We should be able to use the product on devices like Apple, Linux, etc.
For how long have I used the solution?
I have been working with the product for three to four years.
What do I think about the scalability of the solution?
The tool's scalability is good.
How are customer service and support?
I research in forums or contact support whenever I encounter issues. We have four types of support plans available. I rate the cheapest plan a two or three out of ten since responses are slow. I rate ten out of ten for an expensive support plan.
How would you rate customer service and support?
Neutral
What's my experience with pricing, setup cost, and licensing?
We have a vendor who gives us a better price. The product is expensive. Selecting the entire Microsoft suite is cheaper than using random services or products.
Bitdefender costs around five dollars per month per device. However, Microsoft Defender XDR costs 2500 dollars per month.
We are evaluating Bitdefender for Windows.
Microsoft Defender XDR helps us save time for clients.
What other advice do I have?
Microsoft Defender XDR provides unified identity and access management. It is installed on every computer and checked from the Microsoft security admin center.
The tool is easy to use. You can use one account to log in to any Microsoft service.
We are aware of our compliance. We can now check the devices and get reports about it.
The product can adapt to evolving threats. We use it to manage only one tenant. We have Mac devices where Microsoft Defender XDR cannot help us.
We have the tool deployed across different locations like Germany and Denmark.
I rate the product an eight out of ten. You need to follow its guidelines.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Malware and endpoint security solution that is easy to use compared with other similar solutions
Pros and Cons
- "We are able to consolidate licences and make use of many Microsoft products using this solution, and if we have any Microsoft customers, we encourage them to use this solution for enterprise defence."
- "This solution could be improved if it included features such as those offered by Malwarebytes."
What is our primary use case?
We make use of Microsoft Defender for Office 365 for endpoint security and email and we use Defender umbrella for impersonation and sales. Under Defender umbrella, we use a lot of products depending on the customer requirements. As a company, we use Defender for email as well as for endpoint security.
What is most valuable?
We are able to consolidate licences and make use of many Microsoft products using this solution. If we have any Microsoft customers, we encourage them to use this solution for enterprise defence.
What needs improvement?
This solution could be improved if it included features such as those offered by Malwarebytes.
For how long have I used the solution?
We have used this solution for many years and we are a Microsoft partner. We use this solution on a daily basis.
What do I think about the stability of the solution?
This is a stable solution.
What do I think about the scalability of the solution?
This is a scalable solution.
How are customer service and support?
We have not yet needed to contact Microsoft for support with Defender.
Which solution did I use previously and why did I switch?
We have previously used a number of different solutions including Trend Micro, Symantec, Sophos Intercept X and Malwarebytes. Overall, we are more comfortable using Defender.
How was the initial setup?
The initial setup was straightforward.
What other advice do I have?
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Country Manager at Arkano Software
Simple for new users, reliable, and scalable
Pros and Cons
- "Microsoft 365 Defender is a good solution and easy to use."
- "The support from Microsoft could improve. There are times I have to wait for a response from a qualified specialist."
What is our primary use case?
We have many clients that have large companies in the south region of Mexico. They use the solution for security.
What is most valuable?
Microsoft 365 Defender is a good solution and easy to use.
For how long have I used the solution?
I have been using Microsoft 365 Defender for approximately 15 years.
What do I think about the stability of the solution?
Microsoft 365 Defender is a stable solution.
What do I think about the scalability of the solution?
The scalability of Microsoft 365 Defender has been good.
How are customer service and support?
The support from Microsoft could improve. There are times I have to wait for a response from a qualified specialist.
How was the initial setup?
If the solution is deployed using a good specialist with the correct configuration it works very well for normal users.
What about the implementation team?
The amount of people needed for the deployment depends on the number of licenses the customer has. if it is a large company as we have with approximately 8,000 to 12,000 people, we need more people to do customer service in this case. However, for small to medium companies, we have two people that do the implementation.
What's my experience with pricing, setup cost, and licensing?
We have a lot of problems in Latin America regarding the price of Microsoft 365 Defender, because the relationship between dollars and the money of the different countries, it's is a lot. Many customers that have small businesses say that they would like the solution but it is too expensive. However, large companies do not find the cost an issue.
What other advice do I have?
I rate Microsoft 365 Defender an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
IT System Administrator at European Space Agency (ESA)
Reliable, good support, and simple upgrading
Pros and Cons
- "Microsoft 365 Defender is simple to upgrade."
- "We use Microsoft 365 Defender to help secure threats of the Office package, such as Word, Excel, and PowerPoint, and additionally, it can fix issues."
- "The user interface of Microsoft 365 Defender could improve. They could make it simpler."
What is our primary use case?
We use Microsoft 365 Defender to help secure threats of the Office package, such as Word, Excel, and PowerPoint. Additionally, it can fix issues.
What is most valuable?
Microsoft 365 Defender is simple to upgrade.
What needs improvement?
The user interface of Microsoft 365 Defender could improve. They could make it simpler.
For how long have I used the solution?
I have been using Microsoft 365 Defender for approximately one year.
What do I think about the stability of the solution?
Microsoft 365 Defender has been a stable solution.
What do I think about the scalability of the solution?
We have approximately 1,000 people using this solution in my organization. If we expand then we will increase usage.
How are customer service and support?
The support for Microsoft 365 Defender is good.
How was the initial setup?
The installation of Microsoft 365 Defender was automatic when we did the installation of Microsoft Windows.
What about the implementation team?
My internal IT team does the supporting of the solution.
What other advice do I have?
I would recommend this solution to others.
I rate Microsoft 365 Defender a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
SecOps Engineer at a computer software company with 11-50 employees
Saves investigation time and provides advanced hunting capabilities
Pros and Cons
- "Advanced hunting is good. I like that. We can drill down to lots of details."
- "At times, when we have an incident email and we click on the link for that incident, it opens a pop-up, but there is nothing. It has happened a couple of times."
What is our primary use case?
We are using it for incidents and alerts. It is helpful for threat hunting.
We have tied it to Azure AD or Microsoft Entra, and we are trying to implement it for Linux.
How has it helped my organization?
It saves the investigation time. There is a lot of information about the threats and other things.
What is most valuable?
Advanced hunting is good. I like that. We can drill down to lots of details.
It is user-friendly. It has a lot of parts. For me, it was pretty quick to get a sense of it.
What needs improvement?
It protects from phishing emails, but sometimes, some of the emails are not detected. They are getting delivered into the inbox, not in a junk folder or spam folder. Users are reporting them as phishing emails.
At times, when we have an incident email and we click on the link for that incident, it opens a pop-up, but there is nothing. It has happened a couple of times.
In terms of additional features, it is too early for me. I am still learning all the parts. I am just scratching the surface of the tool. One year is not enough to get every detail of it.
For how long have I used the solution?
I have been using Microsoft Defender XDR for about a year.
What do I think about the stability of the solution?
It is stable, but sometimes, we experience an issue. Clicking the link in an incident email opens a small window, but we cannot find anything there. This has happened a couple of times. There is a bug.
Other than that, we have not experienced any downtime or any big issues. It is pretty stable.
What do I think about the scalability of the solution?
We have plans to maximize its usage. We are trying to see how to get the most out of it, but my older colleagues would know more about it. I am still learning it.
How are customer service and support?
I have not contacted them.
Which solution did I use previously and why did I switch?
I am not sure. I am relatively new. I have only been working here for a year. They already had it in place.
I have not worked on a similar tool before. This is my first XDR tool.
How was the initial setup?
It is on the cloud. I am not aware of its deployment because it was already deployed before I joined.
What other advice do I have?
I cannot recommend it because this is the only tool for XDR that I have used. I have not used any other tool, but it is a good tool.
I would rate Microsoft Defender XDR a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Analyst at a tech vendor with 5,001-10,000 employees
Enhanced visibility, useful automated routines, and scales wells
Pros and Cons
- "The most valuable features of Microsoft 365 Defender are the combination of all the capabilities and centralized management."
- "The support could be more knowledgable to improve their offering."
What is our primary use case?
We rely on Microsoft 365 Defender for workstation detection across a number of categories, including virus detection, potential unknown application detection, and monitoring for suspicious website interactions, including clicks and access attempts.
I have used Microsoft 365 Defender in the cloud.
How has it helped my organization?
We have experienced significant advantages from implementing Microsoft 365 Defender, as it provides enhanced visibility into workstations and the ability to automatically remediate threats. This means that not every incident requires manual intervention, as certain tasks can be handled automatically, often in conjunction with Microsoft Sentinel.
We are able to ingest collected data from our entire ecosystem. This is an important feature.
We are able to prioritize threats accounts our whole environment.
The solution has helped automate routine tasks and help automate high-value alerts.
The threat intelligence has helped prepare us for potential threats before they hit and we took proactive steps. We are able to check our workstations are well.
We have saved some time by using the solution.
I have found that having solutions from multiple vendors is more helpful than from one.
What is most valuable?
The most valuable features of Microsoft 365 Defender are the combination of all the capabilities and centralized management.
What needs improvement?
The support could be more knowledgable to improve their offering.
For how long have I used the solution?
I have been using Microsoft 365 Defender for approximately one and a half years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
We have a few thousand people using this solution in my organization.
The scalability of Microsoft 365 Defender is scalable.
How are customer service and support?
I have used the support and they do not know how to fix the issues. Their knowledge could improve.
I rate the support from Microsoft 365 Defender a seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We have used Microsoft Sentinel. Microsoft Sentinel enables us to investigate threats and respond holistically quickly from one place.
The comprehensive features of Sentinel Security Protection are impressive, particularly its integrated SOIR and UEBA functionalities, as well as its robust threat intelligence capabilities.
I have used McAfee previously and Microsoft 365 Defender is much better.
What other advice do I have?
I rate Microsoft 365 Defender a ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
Download our free Microsoft Defender XDR Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Product Categories
Extended Detection and Response (XDR) Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
CrowdStrike Falcon
Cortex XDR by Palo Alto Networks
Microsoft Intune
Microsoft Defender for Endpoint
Microsoft Entra ID
SentinelOne Singularity Endpoint
Microsoft Defender for Cloud
Darktrace
IBM Security QRadar
Microsoft Sentinel
Microsoft Defender for Office 365
Elastic Security
Huntress Managed EDR
Buyer's Guide
Download our free Microsoft Defender XDR Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the best EDR or XDR product for a company with 9000 employees?
- When evaluating Extended Detection and Response (XDR), what aspect do you think is the most important to look for?
- How do you decide about the alert severity in your Security Operations Center (SOC)?
- Which is better for Endpoint Security: EDR or XDR solutions?
- What are the main differences between XDR and SIEM?
- Why is (XDR) Extended Detection and Response important for companies?
- How do you use the MITRE ATT&CK framework for improving enterprise security?
- What tools and solutions do you use for automated incident response in an enterprise in 2022?
- FortiXDR vs Cortex Pro - which is the best?
- What is Cognitive Cybersecurity and what is it used for?
















