I primarily use the solution as an engineer. I use the product to protect the endpoint and I use it to protect my customer's environment.
Cloud Productivity and Security Engineer at a tech consulting company with 11-50 employees
Good automation, nice centralized dashboard, and very helpful threat intelligence
Pros and Cons
- "The comprehensiveness of Microsoft's threat detection is good."
- "The only issue I've had is, when it comes to deployment, the steps I must take around policy setup. That is challenging."
What is our primary use case?
What is most valuable?
The web protection on offer is very good. For a company that doesn't have a firewall, it's quite useful.
It gives feedback and helps protect internet access. It provides you with analysis on the state of the environment and you have a direct link to Microsoft which is doing its own research on security. You're constantly getting feedback from Microsoft resources so that you can be up to date in your own environment and you'll have a better understanding of the security landscape.
The solution is great for companies on a budget.
Defender provides helpful visibility into threats. It covers a lot and comes with a next-gen antivirus. With that, you can register to the cloud, and, if you have cloud protection, your environment is protected even more.
It helps us prioritize the threats across our enterprise. It covers all of our devices. You can cover your entire operation with the license you purchase.
Microsoft 365 Defender is easy to integrate with other products. You just have to configure some things in order to integrate everything and you are SDR compliant. We currently have it integrated natively, so we don't have to worry about configurations.
The comprehensiveness of Microsoft's threat detection is good. Microsoft provides a lot of security. It gives you visibility and IT has a lot of control over everything. You can see your environment, including clouds. You can block things within your environment as needed. The applications are easy to manage. It also has app governance to be able to gain visibility into permissions.
The product has helped automate routine tasks and the finding of high-value alerts. It has an automatic investigation feature that you can enable. It's great for automation. Thanks to automation, it has helped reduce the time it takes to analyze security events and alerts. You don't have to wait to take action. If there is a threat, you can neutralize it faster and it will record everything for audit records. While I know it has saved us time, I can't quantify that into a specific amount of hours.
We no longer need to look at multiple dashboards. Now, everything is centralized under one dashboard.
The product's threat intelligence helps us prepare for potential threats and take proactive steps. Since we've been using it, we've had no security incidents.
What needs improvement?
The only issue I've had is, when it comes to deployment, the steps I must take around policy setup. That is challenging. We're working on the onboarding and configuration policies. We're collecting feedback from customers and partners in hopes of refining the future design for deployment.
For how long have I used the solution?
I've used the solution for about two years.
Buyer's Guide
Microsoft Defender XDR
November 2024
Learn what your peers think about Microsoft Defender XDR. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,660 professionals have used our research since 2012.
What do I think about the stability of the solution?
The feedback I have received from customers is that the stability is very good.
What do I think about the scalability of the solution?
The product scales well.
How are customer service and support?
If you have a license through a partner, it's the partner that will support you.
The only issue with Microsoft is the response times. They are very competent, however, sometimes you will send an email and get no response.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I previously used Sophos. I then switched to Microsoft Defender. The Sophos deployment is quite easy in comparison. You can do everything from a single portal. They had already achieved effective centralization.
How was the initial setup?
Right now, there are two different ways to onboard. You might have to have a different partner to configure policies. However, right now, you can also create policies from the activity center, so you don't have to do it from the device itself.
How long a deployment takes depends on your scope and the number of devices you are covering.
If you do not get a license for the portal, you'll have to use the manual to deploy. If you have an older server you may encounter some issues. However, if you upgrade the server at the same time, you'll have fewer problems.
What other advice do I have?
We do use more than one Microsoft security product. We've integrated with other products.
I do not make use of the directional sync capabilities at this time. I'm also not using Microsoft Sentinel.
I'd rate the solution eight out of ten. If the deployment of the agent was better, I'd move my grade closer to ten. It should be more automatic. You also shouldn't have to install the logs.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Systems Engineer at a consultancy with 201-500 employees
Helps save time, integrates well, and is stable
Pros and Cons
- "The integration with other Microsoft solutions is the most valuable feature."
- "The mobile app support for Android and iOS is difficult and needs improvement."
What is our primary use case?
We use Microsoft Defender XDR to centralize our security solutions.
How has it helped my organization?
Microsoft Defender XDR has helped us save some time.
What is most valuable?
The integration with other Microsoft solutions is the most valuable feature.
What needs improvement?
The mobile app support for Android and iOS is difficult and needs improvement.
For how long have I used the solution?
I am currently using Microsoft Defender XDR.
What do I think about the stability of the solution?
Microsoft Defender XDR is stable.
What do I think about the scalability of the solution?
Microsoft Defender XDR is scalable.
How are customer service and support?
The technical support is good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
In addition to using Microsoft Defender XDR, we also use Fortinet. We implemented Microsoft Defender XDR as part of our organization's policy to use Microsoft solutions because of their integration.
How was the initial setup?
The initial deployment was straightforward. We completed the implementation within one year.
What other advice do I have?
I would rate Microsoft Defender XDR a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Microsoft Defender XDR
November 2024
Learn what your peers think about Microsoft Defender XDR. Get advice and tips from experienced pros sharing their opinions. Updated: November 2024.
816,660 professionals have used our research since 2012.
Country Manager at Arkano Software
Simple for new users, reliable, and scalable
Pros and Cons
- "Microsoft 365 Defender is a good solution and easy to use."
- "The support from Microsoft could improve. There are times I have to wait for a response from a qualified specialist."
What is our primary use case?
We have many clients that have large companies in the south region of Mexico. They use the solution for security.
What is most valuable?
Microsoft 365 Defender is a good solution and easy to use.
For how long have I used the solution?
I have been using Microsoft 365 Defender for approximately 15 years.
What do I think about the stability of the solution?
Microsoft 365 Defender is a stable solution.
What do I think about the scalability of the solution?
The scalability of Microsoft 365 Defender has been good.
How are customer service and support?
The support from Microsoft could improve. There are times I have to wait for a response from a qualified specialist.
How was the initial setup?
If the solution is deployed using a good specialist with the correct configuration it works very well for normal users.
What about the implementation team?
The amount of people needed for the deployment depends on the number of licenses the customer has. if it is a large company as we have with approximately 8,000 to 12,000 people, we need more people to do customer service in this case. However, for small to medium companies, we have two people that do the implementation.
What's my experience with pricing, setup cost, and licensing?
We have a lot of problems in Latin America regarding the price of Microsoft 365 Defender, because the relationship between dollars and the money of the different countries, it's is a lot. Many customers that have small businesses say that they would like the solution but it is too expensive. However, large companies do not find the cost an issue.
What other advice do I have?
I rate Microsoft 365 Defender an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
IT System Administrator at European Space Agency (ESA)
Reliable, good support, and simple upgrading
Pros and Cons
- "Microsoft 365 Defender is simple to upgrade."
- "The user interface of Microsoft 365 Defender could improve. They could make it simpler."
What is our primary use case?
We use Microsoft 365 Defender to help secure threats of the Office package, such as Word, Excel, and PowerPoint. Additionally, it can fix issues.
What is most valuable?
Microsoft 365 Defender is simple to upgrade.
What needs improvement?
The user interface of Microsoft 365 Defender could improve. They could make it simpler.
For how long have I used the solution?
I have been using Microsoft 365 Defender for approximately one year.
What do I think about the stability of the solution?
Microsoft 365 Defender has been a stable solution.
What do I think about the scalability of the solution?
We have approximately 1,000 people using this solution in my organization. If we expand then we will increase usage.
How are customer service and support?
The support for Microsoft 365 Defender is good.
How was the initial setup?
The installation of Microsoft 365 Defender was automatic when we did the installation of Microsoft Windows.
What about the implementation team?
My internal IT team does the supporting of the solution.
What other advice do I have?
I would recommend this solution to others.
I rate Microsoft 365 Defender a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Security Analyst at a tech vendor with 5,001-10,000 employees
Enhanced visibility, useful automated routines, and scales wells
Pros and Cons
- "The most valuable features of Microsoft 365 Defender are the combination of all the capabilities and centralized management."
- "The support could be more knowledgable to improve their offering."
What is our primary use case?
We rely on Microsoft 365 Defender for workstation detection across a number of categories, including virus detection, potential unknown application detection, and monitoring for suspicious website interactions, including clicks and access attempts.
I have used Microsoft 365 Defender in the cloud.
How has it helped my organization?
We have experienced significant advantages from implementing Microsoft 365 Defender, as it provides enhanced visibility into workstations and the ability to automatically remediate threats. This means that not every incident requires manual intervention, as certain tasks can be handled automatically, often in conjunction with Microsoft Sentinel.
We are able to ingest collected data from our entire ecosystem. This is an important feature.
We are able to prioritize threats accounts our whole environment.
The solution has helped automate routine tasks and help automate high-value alerts.
The threat intelligence has helped prepare us for potential threats before they hit and we took proactive steps. We are able to check our workstations are well.
We have saved some time by using the solution.
I have found that having solutions from multiple vendors is more helpful than from one.
What is most valuable?
The most valuable features of Microsoft 365 Defender are the combination of all the capabilities and centralized management.
What needs improvement?
The support could be more knowledgable to improve their offering.
For how long have I used the solution?
I have been using Microsoft 365 Defender for approximately one and a half years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
We have a few thousand people using this solution in my organization.
The scalability of Microsoft 365 Defender is scalable.
How are customer service and support?
I have used the support and they do not know how to fix the issues. Their knowledge could improve.
I rate the support from Microsoft 365 Defender a seven out of ten.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We have used Microsoft Sentinel. Microsoft Sentinel enables us to investigate threats and respond holistically quickly from one place.
The comprehensive features of Sentinel Security Protection are impressive, particularly its integrated SOIR and UEBA functionalities, as well as its robust threat intelligence capabilities.
I have used McAfee previously and Microsoft 365 Defender is much better.
What other advice do I have?
I rate Microsoft 365 Defender a ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Senior IT Executive and Operation at a tech services company with 51-200 employees
A unified enterprise defense suite that's very stable, but the price could be better
Pros and Cons
- "I like that it's stable. It's been stable for a long time, and Microsoft Defender has done a good job there."
- "The price could be better. It'll also help if they can continuously update and upgrade the solution. Every day there's a new virus uploaded into the network, and we have to keep updating it to identify all these things."
What is our primary use case?
The primary use case for Defender is to control the endpoint systems at the user level. On the networking level, we use it to analyze spam and see if any antivirus services are required or if there's a ransomware attack. As of now, I am just using it for monitoring.
What is most valuable?
I like that it's stable. It's been stable for a long time, and Microsoft Defender has done a good job there. I can see a lot of changes to Microsoft 365 Defender when I compare what we have now to what we had from 2007 to 2010. They have implemented a ransomware feature, and if any virus comes into the system, it triggers an alert.
What needs improvement?
The price could be better. It'll also help if they can continuously update and upgrade the solution. Every day there's a new virus uploaded into the network, and we have to keep updating it to identify all these things.
For how long have I used the solution?
I have been using Microsoft 365 Defender since 2007.
What do I think about the stability of the solution?
Microsoft Defender is very stable, and you can see that there is a 99.9% success rate when they give us good service. It's very helpful for configuring anything.
What do I think about the scalability of the solution?
It's definitely easy to scale. However, scalability depends on the plan and requirements.
How are customer service and technical support?
They have their norms and regulations that they use once a ticket is created. Whatever the technical issues are, they normally resolve them within the timeline or some days. They are good at the technical side of things.
How was the initial setup?
The initial setup is totally easy. It's not complex. It takes just a couple of minutes to deploy this solution.
What's my experience with pricing, setup cost, and licensing?
The price could be better. Normally, the costs depend on the country you're located in for the license. When we were in the initial stage, we went with the E5 license they call premium standard. It cost us around $5.20 per month for four users.
What other advice do I have?
I would recommend Microsoft Defender to new users. I would advise them to understand their exact requirements and check if it matches before taking it up.
On a scale from one to ten, I would give Microsoft 365 Defender a seven.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Desktop Architecture and Design at a tech services company with 1-10 employees
Blocks and Monitors for security purposes without needing multiple other products to do different tasks
Pros and Cons
- "We can use Defender to block and monitor for security purposes without needing multiple other products to do different tasks."
- "The logs could be better."
What is our primary use case?
We primarily use the solution for security. We removed all other antivirus products such as McAfee. We removed everything and now use Defender as Defender covers everything all third-party products used to cover.
What is most valuable?
Overall, we are satisfied with the product.
Instead of using three or four tools for security, we can use one. With one product, Defender, we have all of the features we need. We can use Defender to block and monitor for security purposes without needing multiple other products to do different tasks.
It's very user-friendly.
What needs improvement?
The dashboards could be improved. They have to improve something about the dashboard. It is good, however, they need to provide some more information under each account.
The logs could be better.
For how long have I used the solution?
I've been using the solution for two years.
What do I think about the stability of the solution?
The solution is a perfectly stable product.
What do I think about the scalability of the solution?
The scalability of the product is good.
How are customer service and support?
Technical support from Microsoft is good. We haven't had any issues with them. We are quite satisfied so far.
Which solution did I use previously and why did I switch?
We previously used McAfee, however, we wanted to have just one solution, Defender, to cover everything.
How was the initial setup?
The solution's initial setup is not complex yet not easy. We had to use some scripts and policies and a lot of things. If you set up a new environment with Defender, you have to integrate with the old policy and the same policy that was already set up. It needs time.
What about the implementation team?
I handled everything without any consultation from any outside sources.
What's my experience with pricing, setup cost, and licensing?
I don't know the cost. The costs are handled by management. I can't say if the cost is expensive or not. I don't handle that aspect.
What other advice do I have?
We're Microsoft partners.
I'd rate the solution at a ten out of ten. It's a pretty perfect product.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: partner
Senior Cloud Architects at Metro Systems Corporation Public Company Limited
Stable, scalable, but machine learning and AI could improve
Pros and Cons
- "I have found the ability to delete unwanted threats beneficial."
- "The solution could improve by having better machine learning and AI. Additionally, the interface, documentation, and integration could be better."
What is our primary use case?
I use the solution for security against system threats.
What is most valuable?
I have found the ability to delete unwanted threats beneficial.
What needs improvement?
The solution could improve by having better machine learning and AI. Additionally, the interface, documentation, and integration could be better.
For how long have I used the solution?
I have used this solution for approximately one year.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
Microsoft 365 Defender is scalable.
What's my experience with pricing, setup cost, and licensing?
The price of the solution is high compared to others and we have lost some customers because of it.
What other advice do I have?
I rate Microsoft 365 Defender a seven out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Download our free Microsoft Defender XDR Report and get advice and tips from experienced pros
sharing their opinions.
Updated: November 2024
Product Categories
Extended Detection and Response (XDR) Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
CrowdStrike Falcon
SentinelOne Singularity Complete
Cortex XDR by Palo Alto Networks
IBM Security QRadar
Elastic Security
Trellix Endpoint Security
Forescout Platform
Trend Vision One
Rapid7 InsightIDR
Mandiant Advantage
Stellar Cyber Open XDR
Fidelis Elevate
LogRhythm UEBA
Buyer's Guide
Download our free Microsoft Defender XDR Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the best EDR or XDR product for a company with 9000 employees?
- When evaluating Extended Detection and Response (XDR), what aspect do you think is the most important to look for?
- How do you decide about the alert severity in your Security Operations Center (SOC)?
- Which is better for Endpoint Security: EDR or XDR solutions?
- What are the main differences between XDR and SIEM?
- Why is Extended Detection and Response (XDR) important for companies?
- How do you use the MITRE ATT&CK framework for improving enterprise security?
- What tools and solutions do you use for automated incident response in an enterprise in 2022?
- FortiXDR vs Cortex Pro - which is the best?
- What is Cognitive Cybersecurity and what is it used for?