Try our new research platform with insights from 80,000+ expert users

Cortex XDR by Palo Alto Networks vs Microsoft Defender for Business comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Apr 6, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.7
Cortex XDR secures data, reduces malware, lowers costs, and replaces systems, enhancing user satisfaction and operational efficiency.
Sentiment score
7.5
Microsoft Defender boosts productivity and security, integrating seamlessly with Office tools for significant budget savings despite ROI challenges.
They appreciate the rich telemetry data from the solution, as it provides in-depth threat identification.
Using Microsoft Defender for Business results in cost reductions as it consolidates various features under one product, saving around 20% to 30% of the budget.
It is pretty good because it offers various features such as Exchange, OfficeSuite, OneDrive, and SharePoint.
The value I see in Microsoft Defender for Business is in its ability to track and respond to application usage and security threats through its CASB and automation features, which are cost-beneficial.
 

Customer Service

Sentiment score
6.6
Cortex XDR support is praised for responsiveness but criticized for delayed responses and knowledge gaps in certain regions.
Sentiment score
5.2
Users have mixed reviews of Microsoft Defender's support, noting contact difficulties and inconsistent technical assistance despite good onboarding.
Every vendor has similar support; it depends on how the case is handled and raised.
Their support is efficient and responsive whenever I raise a ticket through my portal.
It is rated ten out of ten for its quality and assistance.
The onboarding support is exceptional, ensuring seamless integration and implementation.
Faster support is needed for endpoint security solutions.
 

Scalability Issues

Sentiment score
7.6
Cortex XDR offers scalable, efficient data handling across Linux, Mac, and Windows, praised for simplifying large enterprise management.
Sentiment score
8.2
Microsoft Defender for Business is scalable and effective across diverse environments, though special configurations might impact growth speed.
The cloud-based nature of the solution ensures high scalability.
The scalability of Microsoft Defender for Business is rated as ten, indicating it is very scalable.
In terms of scalability, I would rate Microsoft Defender for Business a ten.
 

Stability Issues

Sentiment score
8.1
Cortex XDR is praised for its stability and reliability, with minor issues noted but generally offering seamless protection.
Sentiment score
7.3
Microsoft Defender for Business is stable and reliable, with minimal crashes, but some report occasional bugs impacting stability.
Cortex XDR is stable, offering high quality and reliable performance.
No customer complaints about its functionality or reliability.
Although it generally works, there are occasional issues and errors that sometimes require a complete system format to rectify.
I would rate the stability of Microsoft Defender for Business with a three out of ten, where one is very bad.
 

Room For Improvement

Cortex XDR struggles with integration, high memory, false positives, limited features, complex setup, and lacks enhanced support and customization.
Microsoft Defender for Business needs better reporting, integration, simplified interface, and enhanced features to address various limitations and concerns.
The inclusion of this feature would allow the application of DLP policies alongside antivirus policies via a single agent and console, making it more competitive as other OEMs often offer DLP solutions as part of their antivirus products.
Cortex XDR could improve its sales support team, including better commission structures and referral programs.
Microsoft should provide batch management solutions with the application, integrating pass management with roles.
Features related to Advanced Persistent Threat detection vectors and cyber kill chain integrations are not available out-of-the-box.
There can be improvements in the user interface to make it more intuitive.
 

Setup Cost

Enterprise buyers view Cortex XDR as expensive yet flexible, offering scalable licensing with varying costs based on features and users.
Microsoft Defender for Business offers competitive pricing with enterprise value, though some users find costs high compared to competitors.
Cortex XDR is perceived as expensive by some customers, yet offers dynamic pricing.
Compared to competitors such as CrowdStrike and Sophos, the pricing of Cortex XDR by Palo Alto Networks is similar to CrowdStrike but more expensive than Sophos.
Single-year pricing remains good.
The pricing is quite affordable at the enterprise level with no extra expenses noted.
The package with Business Premium is good for what you get for the price.
 

Valuable Features

Cortex XDR excels in cybersecurity with advanced detection, ease of use, and integration, offering scalable, efficient threat management.
Microsoft Defender for Business integrates seamlessly with Microsoft products, offering comprehensive security, scalability, and user-friendly features for effective threat management.
It incorporates AI for normal behavior detection, distinguishing unusual operations.
The product provides automation responses in case of a threat attack, severity assessments, centralized manageability, and comprehensive compliance features, resulting in reduced costs.
The threat detection capabilities are robust, with a dedicated research team and a continuously updated threat feed.
Its vulnerability management is regarded as one of the best in the industry.
The most effective features of Microsoft Defender for Business include its threat detection and response capabilities in managing vulnerabilities and ransomware attacks.
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Ranking in Endpoint Protection Platform (EPP)
4th
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
90
Ranking in other categories
Extended Detection and Response (XDR) (7th), Ransomware Protection (1st), AI-Powered Cybersecurity Platforms (4th)
Microsoft Defender for Busi...
Ranking in Endpoint Protection Platform (EPP)
23rd
Average Rating
7.8
Reviews Sentiment
7.0
Number of Reviews
19
Ranking in other categories
Microsoft Security Suite (16th)
 

Mindshare comparison

As of June 2025, in the Endpoint Protection Platform (EPP) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.8%, down from 5.0% compared to the previous year. The mindshare of Microsoft Defender for Business is 2.0%, up from 1.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Protection Platform (EPP)
 

Featured Reviews

NiteshSharma - PeerSpot reviewer
Automated threat response and behavioral control improve security measures
I recommend adding a data loss prevention (DLP ( /categories/data-loss-prevention-dlp )) solution to Cortex XDR ( /categories/extended-detection-and-response-xdr ) by Palo Alto Networks. The inclusion of this feature would allow the application of DLP ( /categories/data-loss-prevention-dlp ) policies alongside antivirus policies via a single agent and console, making it more competitive as other OEMs often offer DLP solutions as part of their antivirus products. Additionally, multi-tenancy and multi-cloud features are not available and should be considered for inclusion.
Takayuki-Umehara - PeerSpot reviewer
Product deployment protects assets but needs improvement in system support
I am doing maintenance for Microsoft Defender for Business, and I'm currently working with it. We don't need to use the latest version of Microsoft Defender for Business. We still use the latest virus definition file that Microsoft Defender for Business has automatically updated. We implement a basic update mechanism. Our compliance division manages how many servers and PCs we have and whether those servers have antivirus solutions. I am not certain about how Microsoft Defender for Business helps with AI-driven security strategies. I just use it normally and don't know if it uses AI technology. I rate Microsoft Defender for Business a six out of ten.
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
859,438 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
14%
Financial Services Firm
9%
Manufacturing Company
8%
Government
7%
Computer Software Company
19%
Comms Service Provider
8%
Retailer
7%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. The ability to reverse damage caused by ransomware with minimal interruptions to...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions that are very scalable, secure, and user-friendly. Cortex XDR by Palo Alto offers ...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface, applies behavioral-based endpoint protection and response, and includes risk-ba...
What do you like most about Microsoft Defender for Business?
A few things are valuable. One is the alerting we see when any kind of intrusion is happening, any kind of malware is being deployed across the endpoints, or any kind of suspicious activity is goin...
What is your experience regarding pricing and costs for Microsoft Defender for Business?
Microsoft Defender for Business offers the best pricing option in the market and is very cost-effective.
What needs improvement with Microsoft Defender for Business?
The areas where Microsoft Defender for Business could improve include the support, installation process, and wiki. I should be able to find solutions to issues quickly without having to delve too d...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Find out what your peers are saying about Cortex XDR by Palo Alto Networks vs. Microsoft Defender for Business and other solutions. Updated: June 2025.
859,438 professionals have used our research since 2012.