

Microsoft Defender for Endpoint and Microsoft Defender for Cloud compete in the cybersecurity category, each providing distinct protection capabilities. Microsoft Defender for Endpoint has the upper hand in enterprise customer environments due to its large user base and seamless integration with existing Windows licenses, offering immediate value and cost benefits, while Defender for Cloud excels in providing comprehensive cloud security solutions.
Features: Microsoft Defender for Endpoint offers robust protection with features like anti-spam, URL syntax checking, firewall, and anti-spyware. The unique "Secret Surf" feature allows private browsing, while its large user base facilitates superior threat intelligence. Microsoft Defender for Cloud focuses on cloud environments, offering extensive visibility into cloud infrastructure, automated investigations, and comprehensive attack surface management.
Room for Improvement: Microsoft Defender for Endpoint may enhance its customer service and troubleshooting services to address system performance and connectivity issues. Microsoft Defender for Cloud could improve integration with third-party systems and enhance real-time threat intelligence. Furthermore, complexities in updating and deployment processes for both solutions should be streamlined to enrich user experience.
Ease of Deployment and Customer Service: Microsoft Defender for Endpoint provides greater flexibility in deployment, offering support for on-premises systems and access to diverse technical support experiences. In comparison, Microsoft Defender for Cloud is tailored to public cloud setups and often includes user agreements that might limit direct interaction, necessitating cloud-specific expertise for efficient deployment and management.
Pricing and ROI: Microsoft Defender for Endpoint is integrated with Windows, minimizing additional expenses and providing great value, particularly with enterprise licenses such as E5 which offer flexibility in payment plans. Meanwhile, Microsoft Defender for Cloud may incur higher costs with additional features and third-party integrations but provides extensive cloud protection capabilities, justifying the cost for larger enterprises. Both solutions enhance ROI through comprehensive security management, with Defender for Endpoint offering a clearer immediate financial advantage due to integration in existing licenses.
Defender proactively indexes and analyzes documents, identifying potential threats even when inactive, enhancing preventative security.
Identifying potential vulnerabilities has helped us avoid costly data losses.
Compared to not having Microsoft Defender for Cloud in place, we definitely saw an advantage by not having downtime due to a security threat.
Without detection and protection measures, organizations would face substantial payments and reputational damage, including the necessity to inform customers about data breaches, potentially leading to loss of business.
Incident response time has significantly reduced, with MTTR reduced from two to three hours to less than one hour, mainly due to automation plus better visibility.
We have seen a return on investment when using Microsoft Defender for Endpoint, as it saves labor by reducing the need for staff to focus on it.
Since security is critical, we prefer a quicker response time.
The support is responsive and of high quality.
The support team was very responsive to queries.
The Microsoft agent, who did not actually work for Microsoft, is one of the vendors that Microsoft uses for support, said, 'Just to set expectations, my lunch break is in an hour and I am going to go away then.'
The level-one support seems disconnected from subject matter experts.
I rate Microsoft support 10 out of 10.
As we have reduced our on-premises infrastructure, it is about how we can migrate workloads to the cloud to make it easier, and then having everything fully encompassed and secured within that area makes it much easier for us to scale as needed and grow.
We are using infrastructure as a code, so we do not have any scalability issues with Microsoft Defender for Cloud implementation because our cloud automatically does it.
It has multiple licenses and features, covering infrastructures from a hundred to five hundred virtual machines, without any issues.
We managed to scale it out in a short amount of time, with two months of planning and three months of implementation on 10,000 computers.
Microsoft Defender for Endpoint is scalable enough to handle various devices across environments, whether they are laptops, Android devices, or operating in hybrid environments.
Compatibility is its main feature.
Defender's stability has been flawless for us.
I have not experienced any crashes or downtime.
Microsoft Defender for Cloud is very stable.
I haven't seen any outages with Microsoft.
I rate Defender 10 out of 10 for stability.
Defender for Endpoint is extremely stable.
Microsoft, in general, could significantly improve its communication and support.
It would be beneficial to streamline recommendations to avoid unnecessary alerts and to refine the severity of alerts based on specific environments or environmental attributes.
The artificial intelligence features could be expanded to allow the system to autonomously manage security issues without needing intervention from admins.
Repeated interactions are necessary due to Level One's lack of tools and knowledge, hindering efficient problem-solving and negatively impacting our experience with Microsoft support.
In contrast, competing products offer reduced pricing for long-term commitments, which makes it difficult for us in that environment.
We use Microsoft partners to help govern the platform, and as part of an alliance, we want to gather data from each tenant and combine them for a complete view.
Security has essentially no cost when compared to the cost of a breach.
Every time we consider expanding usage, we carefully evaluate the necessity due to cost concerns.
We appreciate the licensing approach based on employee count rather than a big enterprise license.
That has been the trend we have seen with Microsoft lately—it is just getting more and more expensive.
The standalone option can feel expensive if you opt for full P2 coverage.
Given our extensive Microsoft licensing, transitioning to Defender for Endpoint did not affect licensing costs.
The most valuable feature for me is the variety of APIs available.
This feature significantly aids in threat detection and enhances the user experience by streamlining security management.
The most valuable feature is the recommendations provided on how to improve security.
Defender for Endpoint's coverage across different platforms in our environment is pretty good. We have devices running Linux, Mac OS, Windows, iOS, and Android. It covers all of them.
Microsoft Defender for Endpoint provides a unified management interface allowing customers to manage their on-premises and hybrid infrastructures from a single pane.
One of the best features of Microsoft Defender for Endpoint is its database for identifying zero-day attacks or malware attacks.
| Product | Mindshare (%) |
|---|---|
| Microsoft Defender for Endpoint | 6.8% |
| Microsoft Defender for Cloud | 5.2% |
| Other | 88.0% |


| Company Size | Count |
|---|---|
| Small Business | 30 |
| Midsize Enterprise | 12 |
| Large Enterprise | 49 |
| Company Size | Count |
|---|---|
| Small Business | 82 |
| Midsize Enterprise | 43 |
| Large Enterprise | 95 |
Microsoft Defender for Cloud is a comprehensive security platform offering integration with Microsoft services, multi-cloud capability, AI-driven threat detection, compliance, and unified visibility for improved security operations.
Microsoft Defender for Cloud manages security operations by integrating with Microsoft services and supporting multi-cloud environments. Its features include AI-driven threat detection, compliance oversight, and advanced threat protection. It simplifies processes with unified visibility, threat intelligence, and automated workflows, enhancing security posture across various workloads. Despite its robust capabilities, improvements are needed in third-party tool integration, comprehensive AI-driven remediation, and a more intuitive dashboard. Users report complexity in licensing, inadequate documentation, and high costs, with room for enhancements in compliance reporting and multi-cloud support.
What are the key features of Microsoft Defender for Cloud?Industries leverage Microsoft Defender for Cloud for security posture management and endpoint protection. Many companies integrate it with Office 365 for enhanced functionality. It provides comprehensive security overviews by monitoring cloud vulnerabilities, limiting unauthorized access, and replacing existing tools with its extensive capabilities from network security to compliance checks, securing Azure infrastructure, and enhancing client security.
Microsoft Defender for Endpoint provides comprehensive threat protection that integrates well with current systems, offering proactive threat detection and automatic updates while reducing manual efforts.
The platform is designed for seamless integration with Microsoft products, facilitating efficient management and use. It offers proactive ransomware protection and valuable threat intelligence, crucial for timely response and increased visibility across devices. Users highlight its ability to secure endpoints from viruses and malware, integrating with Windows and Office 365 to enhance real-time detection capabilities in diverse environments, including hybrid and on-premises setups. However, enhancements are needed in Linux integration, detection accuracy, and policy implementations.
What are the key features of Microsoft Defender for Endpoint?Microsoft Defender for Endpoint is implemented across industries for securing endpoints, relying on its deep integration with Windows and Office 365 to protect against malware and viruses. Organizations benefit from its real-time detection and comprehensive management capabilities, particularly in hybrid environments where diverse digital infrastructures need safeguarding.
We monitor all Microsoft Security Suite reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.