We use Microsoft Defender XDR for malware detection and browser protection. We have around 500 devices to protect. We use it to get reports for each of these devices.
Information Technology Support Technician at a tech services company with 51-200 employees
Helps with malware detection and browser protection
Pros and Cons
- "We are connected to Microsoft and have every laptop enrolled. This acts as an endpoint. The tool helps me check security and compliance. I can also check what a device is doing."
- "We should be able to use the product on devices like Apple, Linux, etc."
What is our primary use case?
What is most valuable?
We are connected to Microsoft and have every laptop enrolled. This acts as an endpoint. The tool helps me check security and compliance. I can also check what a device is doing.
What needs improvement?
We should be able to use the product on devices like Apple, Linux, etc.
For how long have I used the solution?
I have been working with the product for three to four years.
Buyer's Guide
Microsoft Defender XDR
November 2024
Learn what your peers think about Microsoft Defender XDR. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.
What do I think about the scalability of the solution?
The tool's scalability is good.
How are customer service and support?
I research in forums or contact support whenever I encounter issues. We have four types of support plans available. I rate the cheapest plan a two or three out of ten since responses are slow. I rate ten out of ten for an expensive support plan.
How would you rate customer service and support?
Neutral
What's my experience with pricing, setup cost, and licensing?
We have a vendor who gives us a better price. The product is expensive. Selecting the entire Microsoft suite is cheaper than using random services or products.
Bitdefender costs around five dollars per month per device. However, Microsoft Defender XDR costs 2500 dollars per month.
We are evaluating Bitdefender for Windows.
Microsoft Defender XDR helps us save time for clients.
What other advice do I have?
Microsoft Defender XDR provides unified identity and access management. It is installed on every computer and checked from the Microsoft security admin center.
The tool is easy to use. You can use one account to log in to any Microsoft service.
We are aware of our compliance. We can now check the devices and get reports about it.
The product can adapt to evolving threats. We use it to manage only one tenant. We have Mac devices where Microsoft Defender XDR cannot help us.
We have the tool deployed across different locations like Germany and Denmark.
I rate the product an eight out of ten. You need to follow its guidelines.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Business Consultant at PeakUp
User-friendly and easy to set up threat protection solution with good scalability and stability
Pros and Cons
- "Setting up Microsoft 365 Defender is easy. It's a user-friendly solution that provides threat protection. It has good stability and scalability."
- "What could be improved in Microsoft 365 Defender is its licensing, e.g. it should be more consolidated and would be good if it has some optimizations. Improving the alerts and notifications, in terms of adding more details, would also be good for this solution."
What is our primary use case?
Microsoft 365 Defender is one of the first layers to our security. It's our first layer security product, e.g. we use it, then we also use Exchange Online Protection for email, Safelink, etc.
We always recommend these products to our customers, e.g. if the customer is using another third-party product. We are always recommending these compliance and security products, e.g. Microsoft 365 Defender, Cloud App Security, etc.
We usually recommend cloud security because it connects all of these security and compliance products in one center to take logs and make them meaningful, plus you can also create alerts. We are also recommending it because of Microsoft Teams usage, especially because in Microsoft Teams, users sometimes do mass deletion, mass download, etc. We always say: "Let's connect your Cloud App security with your Azure Information Protection, with Microsoft 365 Defender and your Microsoft Teams, your Engula, etc. We find cloud security to be very useful.
What is most valuable?
What I found most valuable in Microsoft 365 Defender is that it's able to scan emails and protect users from dangerous links or attachments. This is important in a first layer or base layer security product such as Microsoft 365 Defender. You can even combine Microsoft Defender for Endpoint with this solution to get the most benefits.
I also find Microsoft 365 Defender user-friendly, so that's another valuable feature of this solution.
What needs improvement?
What could be improved in Microsoft 365 Defender is its licensing. It needs to be more consolidated, because there are so many plans for Microsoft 365 Defender, and every other year, there will be new licensing options, e.g. plan one, plan two, etc., that become more and more different from each other. The most valuable product would be the most expensive product, and customers usually say: "We really need the last version, but that's really expensive for us, because we are in Turkey and the currency is very, very high now." Three years ago, this wasn't a problem, because $1 was three or four Turkish liras, but now it's 15.
In the licensing options, it would also be better if there can be some optimizations, similar to what Power BI Pro offers. There are two options in Power BI: user-based and capacity-based. It would be good if there can be another option for one consolidated product for the whole company with a higher price, but you cannot depend on user count.
What I'd like to see in the next release of Microsoft 365 Defender is for them to provide more details in the alerts and notifications they send out.
For how long have I used the solution?
We've been a partner for Microsoft for 10 years.
What do I think about the stability of the solution?
I found that the stability of Microsoft 365 Defender is good.
What do I think about the scalability of the solution?
Scalability is good in Microsoft 365 Defender.
How are customer service and support?
What we have is Premier Support from Microsoft, e.g. we are a CSP partner, so we were required to buy Premier Support and Cloud Consulting from Microsoft. We are really happy with the support we've been receiving for Microsoft 365 Defender, but on the customer side, they don't have Premier Support, and sometimes, depending on the case, they're not very satisfied with the support.
Our satisfaction is five out of five, but our customers would only have three or four out of five, in terms of their satisfaction with Microsoft 365 Defender support.
How was the initial setup?
The initial setup for Microsoft 365 Defender is really easy. It's not very complicated. I didn't see any other difficulties with setting it up, but customers sometimes think it's not very easy. They purchase consulting services from us, so it doesn't bother us, but sometimes the customer says: "I don't know how to start, but I use Microsoft Security." Microsoft is very late in the security niche, so customers sometimes say: "We have Symantec", or they would mention that they have other products from other vendors, and these vendors are very reliable for many, many years.
In the last three or four years, though, customers start to depend on Microsoft Security products, but they are not early adopters, because they usually tell us: "When we buy the product, some policies cannot be used, but after sometime we can use it." It's not really a problem, but I wanted to relay some of the feedback we get from our customers.
What's my experience with pricing, setup cost, and licensing?
The most valuable licensing option is expensive, so pricing could be improved. Licensing options for this solution also need to be consolidated, because they frequently change.
What other advice do I have?
We've been dealing with the latest version of Microsoft 365 Defender.
For an average project, deployment of Microsoft 365 Defender can take a week, but we do need some change management models, because we still need to train the users about safe links and attachments, so we sometimes have to expand the average time, but implementation is not very hard. If we only do the implementation, one week is more than enough.
We rely on just one to two persons, particularly engineers, for the deployment and maintenance of Microsoft 365 Defender.
My recommendation to others looking into implementing Microsoft 365 Defender is that reading the documentation is really good. If you are a Microsoft partner, you'll also have benefits, e.g. CDS tenants and demo tenants that are free to you for one year, so you can test the products first, before you implement. If you are a partner, my advice is to use your Microsoft partner benefits.
I'm giving Microsoft 365 Defender a rating of eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Microsoft Defender XDR
November 2024
Learn what your peers think about Microsoft Defender XDR. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,406 professionals have used our research since 2012.
Consultant at a tech services company with 1,001-5,000 employees
Provides good insights, allows us to prioritize threats, and comes with a centralized portal
Pros and Cons
- "The EDR features are valuable. By getting the EDR features, we have more control over the device. We have information about events in real-time and more protection against zero-day threats and zero-day vulnerabilities. We can monitor every event or action that a device is going through. We can get an idea if it is something malicious or if we have to take any actions."
- "The onboarding and offboarding need improvement. I work with other vendors as well, and they have an option to add a device or remove a device from the portal, whereas with Microsoft 365 Defender, we need to do that manually. However, once you do that, everything can be controlled through the portal, but getting the device onboarded and offboarded is currently manual. If we have an option to simply remove a device from the portal or get a device added from the portal, it would be more convenient. The rest of the features are similar. This is the only area where I found it different from others. I would also like to be able to simply filter with a few of the queries that are already there."
What is our primary use case?
Microsoft 365 Defender is an extension of Windows Defender. Windows Defender is an AV that is integrated with Windows OS, and with this extension, you also get the EDR functionality for security purposes. Microsoft 365 Defender gets more access to the device and provides more insights and control over that. Apart from the Windows platform, it also includes other OSs, such as Linux and macOS.
We do have multiple options for deployment. We did deploy it on the cloud. We got the on-cloud license, and we onboarded our devices to the portal. The portal is deployed on the Azure cloud.
How has it helped my organization?
It helps us prioritize threats across the enterprise. We also have options to prioritize a specific device and monitor it. We can keep a device on high alert or on the watch out for each and every event. There are different severity levels, such as critical, high, medium, and low. We can set severities on any of the devices. Based on the set severity level, Microsoft 365 Defender can track events, and we can monitor those events from the console.
We get more insights and more information about the devices that we have. Because most of them are Windows devices, we have integrations with Intune or SCCM. It is easy to transfer all the information and see everything in one single portal. If we want to configure anything or control the devices in the whole organization, it is easy because all of them are in the same environment. It is easy to manage and control them.
There are fewer compatibility issues and errors and a better ability to track events. With third-party solutions, I used to see more issues related to compatibility and setting the ports. For each and everything, we had to either go through the support documents or through the support to get information. Most of the Microsoft documentation is publicly available. It is not that you only get that when you open a support case. That's an advantage compared to others.
It helps to automate routine tasks and the finding of high-value alerts. We have KQL or SQL queries that we can set up. We can schedule them so that it automatically queries for a specific device or all the devices and gives us a report that we can simply export.
Its threat intelligence helps to prepare us for potential threats before they hit and take proactive steps. It has helped us to recover a few devices. Because it is integrated with the OS, we get information about failed logins.
It saves time and manual labor. Previously, we used to use a deployment portal such as Filezilla or GPOs. We used to manually update the signatures, but now, it is automatic. It saved me pretty much half a day's work.
It has decreased our time to detect and our time to respond. It has saved half a day's work. The sensor constantly connects to the console. In case of an issue, we get an email immediately. We also get a notification in the console. Previously, we used to manually scan the device or query something and then get the results. Because it is automated, we don't need to manually do that. Previously, we used to manually isolate or block a device, or we used to work with different teams to get the device offline, but now, we can simply search the device name in the console and isolate a device from there, which is convenient for us.
What is most valuable?
The EDR features are valuable. By getting the EDR features, we have more control over the device. We have information about events in real-time and more protection against zero-day threats and zero-day vulnerabilities. We can monitor every event or action that a device is going through. We can get an idea if it is something malicious or if we have to take any actions.
Because Microsoft 365 Defender is integrated with the OS, we get more insight into the events or threat activities. With a third-party solution, we could have some limitations or compatibility issues with the OS, whereas with Microsoft 365 Defender, there are no compatibility issues for Windows, and we get more insights and more information on the threats simply by logging into the console.
What needs improvement?
The onboarding and offboarding need improvement. I work with other vendors as well, and they have an option to add a device or remove a device from the portal, whereas with Microsoft 365 Defender, we need to do that manually. However, once you do that, everything can be controlled through the portal, but getting the device onboarded and offboarded is currently manual. If we have an option to simply remove a device from the portal or get a device added from the portal, it would be more convenient. The rest of the features are similar. This is the only area where I found it different from others. I would also like to be able to simply filter with a few of the queries that are already there.
For how long have I used the solution?
It has been almost three months.
What do I think about the stability of the solution?
I would rate it a seven out of ten in terms of stability. It is quite stable but it can be improved for a few scenarios. It is still new for macOS and Linux, and for these OSs, I would rate it a six out of ten in terms of stability.
What do I think about the scalability of the solution?
It is scalable. We are using it pretty extensively. It is for multiple departments, and there are multiple teams handling it. In the tenant I have, there are 2,000 devices that are currently onboarded. We also get information about which devices are not onboarded. I can see that a few hundred devices are not onboarded. We also have a few other clients or partners who are using it but on a small scale.
How are customer service and support?
It is good. We do get constant responses and inputs from them whenever we raise a case. They are quite helpful. I would rate them an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I started working with this solution because I changed my organization. That was the major reason.
Being able to get the information simply from a single portal and the integration with other portals have been some of the benefits. Previously, we used to get data manually, and then we used a SIEM or event collector to send that data to other portals. Now, we can integrate with other Microsoft portals, such as Intune, and get the same information there as well. That's one convenience I have found.
How was the initial setup?
I am not involved with tenant deployment. I am involved with the onboarding of the devices. If you have the right knowledge, it is completely fine. They do have an admin console. You can deploy multiple tenants and also control through that console, but I don't have access to that. I only have access to my own tenant. I only have control over that. We can also include a tenant for a specific organization from the admin console. That admin console is deployed on Azure.
Most of the maintenance is automatic. Because we allow Windows updates, most of the Defender updates are also included in Windows updates. We don't have to specifically go and check. If we see any alert or we find any suspicious events or something on the console while we are investigating, then it might need manual checks. We do get some recommendations through the console itself for what we can do to improve the device security score. So, it requires some maintenance, but that's only when we detect something or we are investigating something. For maintenance, we have different teams in each section. We have around 15 to 20 people.
What was our ROI?
I don't have the metrics, but we started to see its benefits within a couple of weeks from the time of deployment.
What's my experience with pricing, setup cost, and licensing?
Its licensing and pricing are handled by someone else. My role is limited to incidents or issues with the portal, but you get what you pay for. It is worth the cost.
Which other solutions did I evaluate?
We did compare it with VMware Carbon Black and McAfee. We did check Symantec as well, but Symantec didn't have EDR capabilities. So, we dropped it. The final call was Microsoft because we found the integrations and other things easy. It saves time for us because we don't need to go through another team or get a separate team involved just for data transfers.
What other advice do I have?
I would definitely recommend this solution. Getting the product is easy. You simply get the license, but after getting the product, you need to go through the deployment and configuration of the product to match your environment. You can just try out the product and experiment in your own way and learn each and every feature. The documentation is completely public.
I would rate it an eight out of ten because there are a few areas where it can be improved.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Security analyst trainee at a tech services company with 11-50 employees
The solution can replace multiple security products because it covers everything
Pros and Cons
- "The advantage of Microsoft Defender XDR has over other XDRs in the market is that it's easy to use. You can quickly differentiate between alerts, incidents, devices, software, etc. It's easier to investigate an incident, and you have so many options. You can automate investigations and use playbooks. There's also the live response session, which is something you can't find in any other XDR."
- "The design of the user interface could use some work. Sometimes it's hard to find the exact information you need."
How has it helped my organization?
Defender XDR can replace multiple security products. It covers everything, including phishing protection, network security, device security, applications, etc.
The solution has reduced time spent on manual tasks because almost everything is automated. You don't have to do anything. If something happens, you'll get a notification, and it will instantly run the playbook for the incident. For example, a phishing email might take an hour to investigate manually. If you have Defender, you will have all the information you need on the incident page. It's all there, so you can investigate the incident in around 5 to 10 minutes.
Adopting Defender cuts costs. While the solution is a little pricey, you only need two products—XDR and Sentinel—so you don't need to add other security products. You only need to use the Microsoft security stack.
What is most valuable?
The advantage Microsoft Defender XDR has over other XDRs in the market is that it's easy to use. You can quickly differentiate between alerts, incidents, devices, software, etc. It's easier to investigate an incident, and you have so many options. You can automate investigations and use playbooks. There's also the live response session, which is something you can't find in any other XDR.
The identity protection is excellent. It uses some rules, including some built-in rules from Microsoft itself. It identifies risky users and differentiates between a user who is trying to sign in and isn't the actual user. Identity and access management is a valuable component of Defender.
Defender covers non-Microsoft technologies if you're using the full Microsoft stack with Sentinel and Defender. You can ingest logs from other solutions, like Palo Alto and Fortinet firewalls.
It stops advanced attacks like ransomware and phishing in real time and prevents them from entering your environment. There's a feature called Security Advisory that shows you all the latest threats and vulnerabilities in the market so that you can make rules for them. It helps you understand them more.
With Sentinel and Microsoft Lighthouse, you can use multi-tenant access. It allows you to connect multiple tenants to one tenant, which you can use to monitor everything from there. Before we had Microsoft Defender, we had to go to each tenant, log n from your account, and investigate the incident if it's there. Lighthouse has one page with all the alerts, and they're all connected together. You can investigate every alert from one page.
What needs improvement?
The design of the user interface could use some work. Sometimes it's hard to find the exact information you need.
What do I think about the stability of the solution?
I rate Microsoft Defender XDR 7 out of 10 for stability. There are some performance issues maybe 5% of the time.
What do I think about the scalability of the solution?
I rate Microsoft Defender XDR 9 out of 10. It's easy to scale.
How are customer service and support?
I rate Microsoft support 8 out of 10. They answer quickly. If you open a ticket, they will respond immediately. You can chat with them or schedule a call.
How would you rate customer service and support?
Positive
How was the initial setup?
The setup is straightforward. You only need to buy the product and onboard every device. It's like a script for Microsoft Intune. The process takes a couple of days for a small company, but a larger business may require three or four days.
What's my experience with pricing, setup cost, and licensing?
Defender XDR is fairly priced.
What other advice do I have?
I rate Microsoft XDR Defender 8 out of 10. I recommend giving the product a try. If it doesn't work for you, try something else until you find a suitable product. There might be other solutions that are a better fit. It's good for my case, but it might not be right for everyone.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Last updated: Feb 27, 2024
Flag as inappropriateDirector of IT at a government with 501-1,000 employees
Integrates security into one tool instead of having third-party security tools
Pros and Cons
- "The product integrates security into one tool instead of having third-party security tools."
- "The solution does not offer a unified response and standard data."
What is our primary use case?
We use Microsoft Defender XDR to secure data.
How has it helped my organization?
Microsoft Defender XDR has reduced our security staff.
What is most valuable?
The product integrates security into one tool instead of having third-party security tools.
What needs improvement?
The solution does not offer a unified response and standard data.
For how long have I used the solution?
I have been using the product for three years.
What do I think about the stability of the solution?
Microsoft Defender XDR is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
It takes weeks for the support to respond. They are not helpful.
How would you rate customer service and support?
Negative
How was the initial setup?
Microsoft Defender XDR's deployment was very easy.
What was our ROI?
We have seen ROI with the tool's use.
What's my experience with pricing, setup cost, and licensing?
Microsoft Defender XDR's licensing is complicated.
What other advice do I have?
Microsoft Defender XDR has helped us reduce two full-time employees.
The solution is our identity source, which protects our identities through Microsoft Intra ID.
The solution helped us save time by not flipping between the systems.
I rate it an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cyber Security Analyst at a tech services company with 10,001+ employees
Eliminates looking at multiple screens, giving us one XDR dashboard, and that saves time
Pros and Cons
- "We also use Microsoft Sentinel, Defender for Cloud, Defender for Identity, and Microsoft Defender for Cloud Apps. They are all integrated and it was very easy to integrate them. In my experience with the integrations, it was just a click of a button and things were integrated. It's just a button."
- "There are other SIEM solutions that are easier to use, mainly based on the creation of rules, use cases, and groups."
What is our primary use case?
It's the main tool that we use for the customer that we support. We don't use any other tools to monitor the environment.
How has it helped my organization?
It helps us prioritize threats.
In addition, Microsoft Sentinel enables you to ingest data from your entire ecosystem. One of the main reasons we use Sentinel is to receive logs from different sources and create analytical routines to generate alerts. Sentinel enables you to investigate threats and respond from one place and that is also very important because it becomes part of the monitoring team.
Microsoft 365 Defender has also helped eliminate looking at multiple dashboards, giving us one XDR dashboard. That means we don't have to spend too much time checking different pages. We just have one specific portal with all the information.
The solution has saved us time, although we haven't measured how much. It has reduced our time to detection and time to response by about 20 percent.
What is most valuable?
The most valuable features are the
- integration among all the Microsoft tools
- details of the alerts.
We also use Microsoft Sentinel, Defender for Cloud, Defender for Identity, and Microsoft Defender for Cloud Apps. They are all integrated and it was very easy to integrate them. In my experience the with the integrations, it was just a click of a button and things were integrated. It's just a button.
They work natively together to deliver coordinated detection and response across the environment. We get more details when we integrate more tools, so it's relevant to have integration enabled. When it comes to monitoring an environment, this is very important, because you get different perspectives and points of view on the same alert.
I have a positive impression of the visibility into threats that the solution provides. It brings a lot of information and details related to the alerts or any security threat.
What needs improvement?
There are other SIEM solutions that are easier to use, mainly based on the creation of rules, use cases, and groups.
There could also be an improvement on the customization part. Sometimes we need to customize a few configurations but we can't.
For how long have I used the solution?
I have been using Microsoft 365 Defender for a year and a half.
What do I think about the stability of the solution?
We have never had any problem with downtime.
What do I think about the scalability of the solution?
The scalability is good.
How are customer service and support?
Sometimes, they still take too much time to reply. But when they do reply, it's positive support.
How would you rate customer service and support?
Neutral
How was the initial setup?
I was not involved in the initial setup, but there is no maintenance involved now.
What other advice do I have?
My advice would be to have someone from Microsoft involved in the deployment part to help. There are a lot of details that they have information about, and it's impossible to know everything.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Cloud Productivity and Security Engineer at a tech consulting company with 11-50 employees
Good automation, nice centralized dashboard, and very helpful threat intelligence
Pros and Cons
- "The comprehensiveness of Microsoft's threat detection is good."
- "The only issue I've had is, when it comes to deployment, the steps I must take around policy setup. That is challenging."
What is our primary use case?
I primarily use the solution as an engineer. I use the product to protect the endpoint and I use it to protect my customer's environment.
What is most valuable?
The web protection on offer is very good. For a company that doesn't have a firewall, it's quite useful.
It gives feedback and helps protect internet access. It provides you with analysis on the state of the environment and you have a direct link to Microsoft which is doing its own research on security. You're constantly getting feedback from Microsoft resources so that you can be up to date in your own environment and you'll have a better understanding of the security landscape.
The solution is great for companies on a budget.
Defender provides helpful visibility into threats. It covers a lot and comes with a next-gen antivirus. With that, you can register to the cloud, and, if you have cloud protection, your environment is protected even more.
It helps us prioritize the threats across our enterprise. It covers all of our devices. You can cover your entire operation with the license you purchase.
Microsoft 365 Defender is easy to integrate with other products. You just have to configure some things in order to integrate everything and you are SDR compliant. We currently have it integrated natively, so we don't have to worry about configurations.
The comprehensiveness of Microsoft's threat detection is good. Microsoft provides a lot of security. It gives you visibility and IT has a lot of control over everything. You can see your environment, including clouds. You can block things within your environment as needed. The applications are easy to manage. It also has app governance to be able to gain visibility into permissions.
The product has helped automate routine tasks and the finding of high-value alerts. It has an automatic investigation feature that you can enable. It's great for automation. Thanks to automation, it has helped reduce the time it takes to analyze security events and alerts. You don't have to wait to take action. If there is a threat, you can neutralize it faster and it will record everything for audit records. While I know it has saved us time, I can't quantify that into a specific amount of hours.
We no longer need to look at multiple dashboards. Now, everything is centralized under one dashboard.
The product's threat intelligence helps us prepare for potential threats and take proactive steps. Since we've been using it, we've had no security incidents.
What needs improvement?
The only issue I've had is, when it comes to deployment, the steps I must take around policy setup. That is challenging. We're working on the onboarding and configuration policies. We're collecting feedback from customers and partners in hopes of refining the future design for deployment.
For how long have I used the solution?
I've used the solution for about two years.
What do I think about the stability of the solution?
The feedback I have received from customers is that the stability is very good.
What do I think about the scalability of the solution?
The product scales well.
How are customer service and support?
If you have a license through a partner, it's the partner that will support you.
The only issue with Microsoft is the response times. They are very competent, however, sometimes you will send an email and get no response.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I previously used Sophos. I then switched to Microsoft Defender. The Sophos deployment is quite easy in comparison. You can do everything from a single portal. They had already achieved effective centralization.
How was the initial setup?
Right now, there are two different ways to onboard. You might have to have a different partner to configure policies. However, right now, you can also create policies from the activity center, so you don't have to do it from the device itself.
How long a deployment takes depends on your scope and the number of devices you are covering.
If you do not get a license for the portal, you'll have to use the manual to deploy. If you have an older server you may encounter some issues. However, if you upgrade the server at the same time, you'll have fewer problems.
What other advice do I have?
We do use more than one Microsoft security product. We've integrated with other products.
I do not make use of the directional sync capabilities at this time. I'm also not using Microsoft Sentinel.
I'd rate the solution eight out of ten. If the deployment of the agent was better, I'd move my grade closer to ten. It should be more automatic. You also shouldn't have to install the logs.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Systems Engineer at a consultancy with 201-500 employees
Helps save time, integrates well, and is stable
Pros and Cons
- "The integration with other Microsoft solutions is the most valuable feature."
- "The mobile app support for Android and iOS is difficult and needs improvement."
What is our primary use case?
We use Microsoft Defender XDR to centralize our security solutions.
How has it helped my organization?
Microsoft Defender XDR has helped us save some time.
What is most valuable?
The integration with other Microsoft solutions is the most valuable feature.
What needs improvement?
The mobile app support for Android and iOS is difficult and needs improvement.
For how long have I used the solution?
I am currently using Microsoft Defender XDR.
What do I think about the stability of the solution?
Microsoft Defender XDR is stable.
What do I think about the scalability of the solution?
Microsoft Defender XDR is scalable.
How are customer service and support?
The technical support is good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
In addition to using Microsoft Defender XDR, we also use Fortinet. We implemented Microsoft Defender XDR as part of our organization's policy to use Microsoft solutions because of their integration.
How was the initial setup?
The initial deployment was straightforward. We completed the implementation within one year.
What other advice do I have?
I would rate Microsoft Defender XDR a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Microsoft Defender XDR Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Product Categories
Extended Detection and Response (XDR) Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
CrowdStrike Falcon
SentinelOne Singularity Complete
Cortex XDR by Palo Alto Networks
IBM Security QRadar
Elastic Security
Trellix Endpoint Security
Forescout Platform
Trend Vision One
Rapid7 InsightIDR
Mandiant Advantage
Stellar Cyber Open XDR
Fidelis Elevate
LogRhythm UEBA
Buyer's Guide
Download our free Microsoft Defender XDR Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the best EDR or XDR product for a company with 9000 employees?
- When evaluating Extended Detection and Response (XDR), what aspect do you think is the most important to look for?
- How do you decide about the alert severity in your Security Operations Center (SOC)?
- Which is better for Endpoint Security: EDR or XDR solutions?
- What are the main differences between XDR and SIEM?
- Why is Extended Detection and Response (XDR) important for companies?
- How do you use the MITRE ATT&CK framework for improving enterprise security?
- What tools and solutions do you use for automated incident response in an enterprise in 2022?
- FortiXDR vs Cortex Pro - which is the best?
- What is Cognitive Cybersecurity and what is it used for?