No more typing reviews! Try our Samantha, our new voice AI agent.

Microsoft Defender for Endpoint vs Symantec Protection Engine comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Microsoft Defender for Endp...
Ranking in Anti-Malware Tools
1st
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
212
Ranking in other categories
Endpoint Protection Platform (EPP) (1st), Advanced Threat Protection (ATP) (5th), Endpoint Detection and Response (EDR) (3rd), Microsoft Security Suite (3rd)
Symantec Protection Engine
Ranking in Anti-Malware Tools
20th
Average Rating
7.6
Reviews Sentiment
5.6
Number of Reviews
6
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of August 2026, in the Anti-Malware Tools category, the mindshare of Microsoft Defender for Endpoint is 6.3%, down from 15.1% compared to the previous year. The mindshare of Symantec Protection Engine is 0.6%, up from 0.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Anti-Malware Tools Mindshare Distribution
ProductMindshare (%)
Microsoft Defender for Endpoint6.3%
Symantec Protection Engine0.6%
Other93.1%
Anti-Malware Tools
 

Featured Reviews

Robert Arbuckle - PeerSpot reviewer
Security Analyst III at a healthcare company with 10,001+ employees
Automatically isolates threats and integrates with logging to reduce response time
Overall, I would evaluate the Microsoft support level that I receive at probably about a seven, but that depends on the day. It has been spotty. We have had issues where the urgency level of the Microsoft support is not as high as ours, especially during a data breach or potential data breach situation. We have had issues with some of the offshore support being lackluster. One specific thing that comes to mind is we were on a support call with our CISO on the call, and the Microsoft agent, who did not actually work for Microsoft, is one of the vendors that Microsoft uses for support, said, "Just to set expectations, my lunch break is in an hour and I am going to go away then." For us, it was already ten o'clock at night and we had been working on this for a couple of hours, trying to get a security engineer on with us. For him to tell us that he was going to go away and have lunch, it was, "Okay, but go find somebody else if you need to." It was just the lackluster approach, and it seemed like he did not really care. We seem to get a lot of this when we get non-Microsoft support. I can identify areas for improvement with Microsoft Defender for Endpoint, as it is kind of a convoluted mess to try to take care of false positives. Especially when they have been identified as false positives but they keep going off over and over again. It is great for my pocketbook because it generates a lot of on-call action, but I would really prefer more sleep at two o'clock in the morning than dealing with false positives. I would say that the unified portal for managing Microsoft Defender for Endpoint is suitable for both teams as they are all in there. It would be great if they would stop moving things around and renaming things, which makes sense. The new XDR portal is pretty nice. Being able to have it central again inside of the regular Security Center without having to open up two windows is helpful. Overall, I think it is pretty good. There is always going to be something that could be improved, such as alerting and the ability to modify alerts would be a little bit helpful to have. Being able to add more data into the alerts and turn off alerts that are not as useful would be beneficial. It is hard to say what the quantitative impact the security exposure management feature has had on our company's security, because a lot of it is kind of subjective. I think we are sitting at around a fifty percent score still, and a lot of it is just kind of unusual circumstances that we cannot really implement without breaking the organization.
Abhimanyu Das - PeerSpot reviewer
Senior Cybersecurity Engineer at Kyndryl
Real-time file security has reduced incident tickets and improves threat detection accuracy
The best features of Symantec Protection Engine include machine learning, file reputation, and real-time scanning. It efficiently handles heavy loads through ICAP and cloud-based processing, reducing the burden on endpoints compared to Trend Micro and other endpoint security solutions. Its centralized control is also noteworthy. Through machine learning, it detects both known and unknown malware and malicious URLs, in addition to performing signature-based scans that assist SOC teams in analysis. The solution is highly effective in leveraging both machine learning and file reputation. Regarding centralized control, it offers a unified management console for policy deployment and provides real-time visibility through dashboards, helping save significant administrative time. Symantec Protection Engine has had a positive impact on our organization by enhancing our overall security posture. It effectively blocks a high volume of file-based threats across more than 200 servers, saves SOC analysts time in endpoint remediation, and streamlines compliance processes. It further strengthens security through real-time scanning and machine learning-based quarantine, blocking phishing payloads in SharePoint uploads before they reach endpoints, thereby reducing incidents by 30–40% compared to signature-only tools.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It provides peace of mind with really good pricing."
"Since we started using this product, we have not had any breaches."
"Defender has very little impact on the end-user and the agent works quite well with a minimal impact on the client and server."
"We are still navigating through it, and it has been working very well."
"We are totally satisfied with performance and price."
"Microsoft Defender for Endpoint has improved a lot over the years and it is a lot better now."
"It has Kusto Query Language (KQL), so we can use our own queries to find anything."
"It is quite stable. We have not had any cases, i.e., viruses, that would require a reboot, etc. We have never had a situation where we needed to reinstall the tools as a result of the Defender application or a feature being corrupt."
"The best features that I like the most include the threat intelligence network, which is effective in protecting against evolving threats."
"Symantec Protection Engine's been a game-changer for us at Kantar—blocks like 80-85% of file-based threats right at the gateway before they hit our 200 servers, cutting down endpoint incidents big time."
"What I appreciate in Symantec Protection Engine is the Virtual Policy Manager (VPM) and the Application Name feature, which are really effective."
"The operational efficiency with the high-performance scanning of Symantec Protection Engine is very good."
"Symantec Protection Engine has improved my security posture by helping me identify potentially malicious files before they reach users or critical systems, and the automated scanning process has also reduced manual efforts for my team, allowing us to focus on other security tasks and respond to threats more efficiently."
"Symantec Protection Engine provides me with the option of both cloud and on-premise solutions, which stands out for both me and my clients."
 

Cons

"I rate Microsoft support seven out of ten. I had some cases a while back and told an agent my issue, and when I called the next day, I had to explain everything again to a different person, so I found it annoying to repeat myself all over."
"Microsoft has some creative accounting when they promise an SLA of 99.99%. But it is generally good."
"The central console needs improvement. Both McAfee and Symantec antivirus have dashboards. These integrate with a server and work on my antivirus or some other product. However, with Microsoft Defender, you use Microsoft Group Policy Object. Defender does not provide a central console. Therefore, if you implement Defender, then maybe use another tool for the central view."
"The end-user also cannot do some advanced actions on it. It's a little bit complicated for our end-user, so it needs to be simplified."
"Integrating this with third-party systems has some complexity involved."
"The alerting is something that needs to be improved. Alerts need to be sent immediately because as it is now, you see some of them without delay and others arrive perhaps 30 minutes later, and it leaves important gaps in terms of information gathering."
"I would like to see the next generation of the tool improved to work with other operating systems, like Linux."
"There is room to improve the security of the solution."
"To improve Symantec Protection Engine, I suggest simplifying its integration with other tools, as it is more complex compared to Trend Micro and CrowdStrike."
"I would like to see improvements in reporting and troubleshooting capabilities for Symantec Protection Engine, as more detailed insights and simplified diagnostics would make day-to-day administration easier."
"For the improvement of Symantec Protection Engine, the engine did not work with their basic engine when I was working, which was almost three or four years before."
"I have concerns about scalability."
"While I have mentioned many advantages of Symantec Protection Engine, there are areas for improvement, particularly the dashboard features."
"Price is a significant area for improvement. The pricing is quite expensive, and it is particularly high for regular customers."
 

Pricing and Cost Advice

"I pay for it through the Windows Professional or Standard license. It is a one-time cost for me, and I use the same license."
"The price is higher than others because it is doing more than what the others are doing."
"The license cost is around $35 per machine, which is not expensive compared to other products."
"Licensing options vary. Some customers buy it as an enterprise agreement and pay yearly. Others buy it as a CSP, so they pay per month. It completely depends on the customer's needs."
"The cost is high for E5 licenses, but if we go with the E3 license, most of the features are not covered."
"This solution is part of Windows and comes included with it."
"The licensing fee is a function of your Office 365 license. The feature set you get is a function of the license as well. There is probably an E2 version, an E3 version, and an E5 version. There are several versions, and not all features are the same. So, you might want to check what features you're expecting because you might get shocked. If you only have an E3 license, the capability isn't the same."
"We have been using the free version."
Information not available
report
Use our free recommendation engine to learn which Anti-Malware Tools solutions are best for your needs.
909,725 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Manufacturing Company
10%
Financial Services Firm
9%
Computer Software Company
8%
Comms Service Provider
8%
Comms Service Provider
12%
Construction Company
12%
Healthcare Company
12%
Outsourcing Company
12%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business82
Midsize Enterprise45
Large Enterprise96
No data available
 

Questions from the Community

How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface, applies behavioral-based endpoint protection and response, and includes risk-ba...
Which offers better endpoint security - Symantec or Microsoft Defender?
We use Symantec because we do not use MS Enterprise products, but in my opinion, Microsoft Defender is a superior solution. Microsoft Defender for Endpoint is a cloud-delivered endpoint security s...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never push your machine hardware to "test", you don't have the usual "scan now" feature ...
What needs improvement with Symantec Protection Engine?
While I have mentioned many advantages of Symantec Protection Engine, there are areas for improvement, particularly the dashboard features. I find that some features are not available, leading us t...
What is your primary use case for Symantec Protection Engine?
Clients usually use Symantec Protection Engine primarily for protecting their computers from malware or any kind of attacks, which includes viruses or trojans, as a comprehensive security solution ...
 

Also Known As

Microsoft Defender ATP, Microsoft Defender Advanced Threat Protection, MS Defender for Endpoint, Microsoft Defender Antivirus
No data available
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

Petrofrac, Metro CSG, Christus Health
Information Not Available
Find out what your peers are saying about Microsoft Defender for Endpoint vs. Symantec Protection Engine and other solutions. Updated: August 2026.
909,725 professionals have used our research since 2012.