Try our new research platform with insights from 80,000+ expert users

Microsoft Defender for Endpoint vs Symantec Advanced Threat Protection comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 1, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Microsoft Defender for Endp...
Ranking in Advanced Threat Protection (ATP)
2nd
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
194
Ranking in other categories
Endpoint Protection Platform (EPP) (1st), Anti-Malware Tools (1st), Endpoint Detection and Response (EDR) (3rd), Microsoft Security Suite (5th)
Symantec Advanced Threat Pr...
Ranking in Advanced Threat Protection (ATP)
16th
Average Rating
7.8
Reviews Sentiment
7.1
Number of Reviews
16
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of May 2025, in the Advanced Threat Protection (ATP) category, the mindshare of Microsoft Defender for Endpoint is 9.2%, down from 11.4% compared to the previous year. The mindshare of Symantec Advanced Threat Protection is 2.1%, down from 2.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Advanced Threat Protection (ATP)
 

Featured Reviews

AnuragSrivastava - PeerSpot reviewer
Provides detailed visibility into threats but the ability to add exceptions needs improvement
One major item for improvement is the ability to add exceptions. We can add some exceptions, but not at the level we need to. The second major area for improvement involves enhanced capabilities for different operating systems or platforms. That is, even though we have coverage for different operating systems or platforms such as Linux, we don't get all of the controls and enhanced capabilities that are available with Windows devices. Reporting could also be improved because, at present, we get limited results at times. For example, in an environment with more than 100,000 devices, you may just get 10,000 results when you run a report.
Dennis O'Reilly - PeerSpot reviewer
Provides end-to-end antivirus protection and has good stability
Symantec Endpoint Protection provides end-to-end protection. Along with antivirus protection, it has a lot of key areas, including intrusive prevention, firewall features, and application and device control. It can integrate with other Broadcom solutions, such as Symantec Messaging Gateway and Symantec DLP. If you want to send an email, it gets scanned through endpoint protection and DLP. We get all Symantec functionality in a single pane.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"We can run the virus scan across our entire environment."
"For threat-hunting, I'll put some threats in a test scenario. I've downloaded known viruses that are out in the public for testing. They're not really a virus but they've got a signature. Defender for Endpoint will automatically find those, quarantine them for me, and alert me to what it did. It gives me "automated eyes.""
"It's absolutely free to use."
"The most important and the most relevant features of Defender for Endpoint are the malware and ransomware protection."
"Defender works in the background monitoring the traffic for viruses."
"The solution has good performance, I have not seen a problem."
"It captures data through machine learning, which is built-in on the back-end. It also provides built-in analytics and a threat intelligence feature. It is a one-stop solution that doesn't require an antivirus because it comes prebuilt into Windows 10."
"Microsoft Defender for Endpoint is scalable. Currently, we have 600,000 users in our organization."
"The great advantage in using this product is it creates multiple services."
"It has certainly helped out our audit efforts because we each stay compliant in terms of various security standards."
"What I like most about Symantec Advanced Threat Protection is its notification capability."
"All of the solution's features are quite valuable for us. We especially like the threat protection it provides."
"The technical support services are excellent."
"Currently we have 800-plus nodes connected with this solution, without any issues. The solution is scalable."
"Real-time threat analysis is quick and takes action on threats immediately."
"They manage to solve detection quite nicely. There is some rather elaborate detection compared to other providers."
 

Cons

"With regards to the interface, a challenge I found was that there was not enough documentation on how to tune it. I had to read multiple sources on the internet to learn how to configure the tool appropriately."
"Microsoft Defender for Endpoint should include better automation that will make it faster to detect the latest threats happening across the world."
"A concern is ransomware, whether people can penetrate and encrypt my data or steal my credit card/banking information."
"They're in the process of pulling more things together. They can continue with the integrations and provide a better way of seeing the impact of security changes, especially on the endpoint side. Before we actually flip the switch, we should be able to see the impact of security changes on the business or business applications. It would prevent breaking any business applications."
"I would like to have a dashboard that shows an overview of the results for the enterprise."
"Microsoft Defender for Endpoint could provide us with a more holistic approach, such as collaboration. They can provide us with an environment from where we can manage all the endpoints from one central location, such as overall management."
"Microsoft Defender for Endpoint is effective for validating work, but not ideal for investigations."
"If they integrate with the EDR then it will benefit this solution."
"There are some ‎features that would add value to this product. One of them would be a graphical presentation of threats that the system has encountered."
"Scalability could be better."
"An improvement could be made on the reporting because then it would be easier to collect information and submit it for compliance."
"It's a strange situation where the infrastructure of the consumer or customer is behind some kind of firewall and they have always used some kind of customized proxy. In this situation, the ATP has a very tough time to pass the information to the cloud and back. To fix, it requires a more elaborate and complex configuration for that particular case."
"Symantec appliances need improvement. The whole appliance environment is a robust system and it needs a massive amount of storage space. If you have to increase or speed up the background storage it's a pretty complicated process. The scalability and sizing is critical, and if you do it wrong you run into issues pretty quickly."
"The cloud platform needs to have improvement in terms of the user interface and the different capabilities it has available. It needs to match the other leading next-gen EDR products that are available in the market. That's the reason why we are stepping away from Symantec. Their cloud environment is just generally lacking in comparison to others."
"There are limits with respect to blocking files by hash value or blocking IP addresses, and these limits should be removed."
"The product's support services need improvement."
 

Pricing and Cost Advice

"Microsoft has different plans for buying this product. The price depends on the configuration of the full set of products that you buy and on the licensing program in your contract."
"Pricing can always be lower."
"Its price at the moment is very good because you get a lot of value for your money, especially with the subscriptions. If you have the E1, E3, or E5 enterprise subscription, you pay per month per user, and you get almost an infinite number of solutions. If you compare the price to the number of solutions that you get, it is a very good deal."
"The solution comes as part of Microsoft Windows."
"I do not have to purchase antivirus solutions anymore because Microsoft Defender for Endpoint is integrated into Windows and comes free."
"You need a license to use this solution."
"It isn't cheap, but it's reasonable and fair."
"I recently switched from education to private business, and all I can say is that private business licensing from Microsoft is not cheap until you hit certain quantities or scale. That does not mean that it is not comparable to other industries. It is similar pricing, but it is still crazy to me how much you pay for a client. I feel it is high, but it is in line with other vendors."
"Symantec Endpoint Protection has an average price."
"The pricing of this solution is inexpensive and affordable."
"The price is quite expensive."
"Symantec Advanced Threat Protection's pricing is comparable."
"Pricing is good. It is nice to have a great product at a fair price."
report
Use our free recommendation engine to learn which Advanced Threat Protection (ATP) solutions are best for your needs.
850,028 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Educational Organization
25%
Computer Software Company
12%
Government
7%
Financial Services Firm
7%
Educational Organization
72%
Financial Services Firm
6%
Manufacturing Company
3%
University
3%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface, applies behavioral-based endpoint protection and response, and includes risk-ba...
Which offers better endpoint security - Symantec or Microsoft Defender?
We use Symantec because we do not use MS Enterprise products, but in my opinion, Microsoft Defender is a superior solution. Microsoft Defender for Endpoint is a cloud-delivered endpoint security s...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never push your machine hardware to "test", you don't have the usual "scan now" feature ...
What do you like most about Symantec Advanced Threat Protection?
Symantec Endpoint Protection provides end-to-end protection. Along with antivirus protection, it has a lot of key areas, including intrusive prevention, firewall features, and application and devic...
What is your experience regarding pricing and costs for Symantec Advanced Threat Protection?
The price is quite expensive because a different entity has taken over the company.
What needs improvement with Symantec Advanced Threat Protection?
One area for improvement could be the pricing model. Future releases could further enhance integration capabilities with other platforms and simplify the licensing model to compete more with Micros...
 

Also Known As

Microsoft Defender ATP, Microsoft Defender Advanced Threat Protection, MS Defender for Endpoint, Microsoft Defender Antivirus
No data available
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Petrofrac, Metro CSG, Christus Health
ECI
Find out what your peers are saying about Microsoft Defender for Endpoint vs. Symantec Advanced Threat Protection and other solutions. Updated: April 2025.
850,028 professionals have used our research since 2012.