No more typing reviews! Try our Samantha, our new voice AI agent.

Microsoft Defender for Endpoint vs Trend Micro Cloud App Security [EOL] comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 8, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
110
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (6th), Extended Detection and Response (XDR) (5th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Microsoft Defender for Endp...
Average Rating
8.2
Reviews Sentiment
7.0
Number of Reviews
215
Ranking in other categories
Endpoint Protection Platform (EPP) (2nd), Advanced Threat Protection (ATP) (4th), Anti-Malware Tools (1st), Endpoint Detection and Response (EDR) (3rd), Microsoft Security Suite (3rd)
Trend Micro Cloud App Secur...
Average Rating
8.2
Reviews Sentiment
6.2
Number of Reviews
9
Ranking in other categories
No ranking in other categories
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Kalpesh Pawar - PeerSpot reviewer
Technical Head Cloud Services at a media company with 501-1,000 employees
Unified threat visibility has reduced incident impact and streamlines response across our endpoints
From a customer or SOC perspective, the best features Microsoft Defender for Endpoint offers are the EDR with deep telemetry, which helps us with continuous behavioral monitoring. The automated investigation and remediation feature includes auto-isolation, file quarantine, and incident-level correlation. The advanced hunting KQL-based feature along with Attack Surface Reduction and vulnerability management proactively hardens exposures and provides visibility to reduce attack paths before exploitation. The advanced hunting and vulnerability management features in Microsoft Defender for Endpoint help my team day to day by allowing us to utilize Advanced hunting KQL for proactive threat hunting and validation of alerts, querying process trees, lateral movement, and IOC swipes across all endpoints in seconds. The vulnerability management feature gives us a real-time exposure view with risk-based prioritization. We align it with patching cycles and use security recommendations to reduce attack surface before exploitation. Device isolation and live response provide real operational value. This capability allows a SOC to instantly isolate compromised hosts and run remote forensics or commands without user impact, which is critical during active incidents.
Murali Krishnan L - PeerSpot reviewer
Technical Manager (SOC Operations) at Novac Technology Solutions
User-friendly solution with good scalability
We use the solution to block phishing, spam, and impersonated emails The solution's feature for high-profile users' domains helps us detect impersonated emails. Also, its API-based features help in easy integration. The solution is easy to integrate and has the best feature for high-profile…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The solution doesn't need a high level of technical training."
"The initial setup is easy."
"The solution allows us to make investigations. Other XDR solutions also provide similar capabilities but for investigation, Cortex XDR is better."
"One of the things that I enjoy the most is using policy extensions. It's like having host firewalls to control USB connections. I think it's a wonderful tool to restrict use when connecting to our computers. Another important tool is Home Insights. That is an add-on to the Cortex solution. I like that because we can see all the vulnerabilities in the environment and control what assets are connected to our network."
"It can automatically correlate events and logs, which is very helpful for an IT administrator. It can correlate different kinds of malware activities over a network, agent, or host system. You do not need to do it manually. It is a good feature. It is also a user-friendly solution. We have deployed it on the cloud because our space does not provide any flexibility for on-premises deployment, but Palo Alto has added some flexibility to install it on-premises. It must be like the same Cortex XDR agent for all the VPN services, web filtering services, and everything else."
"On a scale from one to ten, I would rate Cortex XDR by Palo Alto Networks a nine."
"We switched because there were a lot of added features with Palo Alto that Check Point didn't have, and it was an upgrade for us."
"The product's most valuable features are massive user and feature intelligence exploit detection."
"We apply the DLP policies across a range of endpoints and it is very accurate when reporting vulnerabilities, including those in email attachments."
"It's a stable solution."
"I would recommend this solution to others if they don't have many third-party tools."
"This product is flexible, and it is very easy to get updates from the Microsoft website."
"There are several features that have helped to improve our security posture at the prevention level, such as the attack surface reduction controls and the exploit prevention control."
"It's effective against most types of infection, and the firewall is perfect for protection."
"The solution integrates very well with Windows applications and Microsoft endpoint products."
"Most people don't realize M365/E5 licenses are an amazing deal."
"Our business emails are very important and Trend Micro Cloud App Security has provided a high level of protection. Additionally, there are updating the solution frequently."
"It has more intelligence features than other vendors."
"Dependable with ease of integration with other security products."
"Trend Micro Cloud App is easy to use and easy to install."
"Trend Micro has DLP features in it, which separates it from other solutions."
"The initial setup is pretty straightforward."
"The most valuable feature of Trend Micro Cloud App Security is its stability across all platforms."
"Trend Micro has DLP features in it, which separates it from other solutions."
 

Cons

"Traps doesn't work with McAfee. You need to remove McAfee to install Traps. This is very common, and its nothing that should be an issue. Some antivirus engines recognize Traps as an threat component, so maybe they need to shake hands somewhere."
"We had a problem with getting our older endpoints up to date, but their newest updates have been really good. I've been pleased with it in terms of what our needs are. It's doing what we want it to do."
"They've been having some issues with updating their endpoint agents, and it has been quite frustrating."
"It automatically detects security issues. It should be able to protect our network devices while operating autonomously."
"There is a severe gap in functionality between Windows, Linux, and Mac versions."
"The solution could improve by providing better integration with their own products and others."
"I would like to see better protection, specifically to protect email applications."
"Product might have some bugs."
"There is room to improve the security of the solution."
"It seems there are challenges associated with IP addresses at times."
"Its interface can be improved a little bit. We would like to have some sort of centralization. It should have something like a central server that is managing all the other clients. There are solutions from Kaspersky or ESET NOD32 that are really doing this kind of thing currently. We would like to see something similar from Microsoft."
"What I think can be improved on Microsoft Defender for Endpoint is that the whitelisting abilities are pitiful, and the understanding of how you go about doing that by the support techs that you speak with is really bad, so that I think is an area where Microsoft Defender for Endpoint needs improvement; the understanding and support of that and what actually works is pretty buggy."
"Their support is okay. We get support through Insight, which is also our CSP."
"Microsoft Defender for Endpoint does not offer default templates for alerts, requiring us to configure everything ourselves to avoid numerous false positives."
"It makes your Surface devices hot. It is resource-intensive."
"Sometimes the software doesn't work the way we expect it to, and in those cases, we can't communicate with a device because it may be infected."
"The granulation of the policy setup needs to be better. Right now, it is too basic."
"The price of the solution could improve by being lower."
"There is room for improvement in the DLP component of Trend Micro Cloud App Security."
"The cost of the license is on the high side."
"Documentation could be improved; product cost is quite high."
"It would be great if Trend Mail Cloud App Security would be joined with a web security solution, making it a multiple-network solution."
"For improvements, I think it would be great if Trend Micro Cloud App Security could enhance their product to be a single SASE solution. It should be similar to competitors like Palo Alto."
"The solution's technical support services could be better."
 

Pricing and Cost Advice

"Every customer has to pay for a license because it doesn't work with what you get from a managed services provider."
"In terms of the cost Cortex XDR by Palo Alto Networks is very expensive because we are a Mexican company and when you translate dollars to pesos the cost is very high. The solution is very expensive for Mexican companies. I understand that they have international prices, but I do not think it offsets the price enough for many companies in countries, such as Mexico. The amount it is reduced is not a massive percentage."
"Cortex XDR's pricing is ok."
"The pricing is a little high. It is per user per year."
"I don't recall what the cost was, but it wasn't really that expensive."
"I don't like that they have different types of licenses."
"Very costly product."
"Licensing for Palo Alto Networks Cortex XDR can be costly, especially when it comes to a hundred users. A license is required for each user, and the subscription must be renewed on a yearly basis."
"The licensing costs for Microsoft Defender for Endpoint are reasonable."
"The E5 license is the one that I recommend because it comes with Cloud App Security, which is a good thing to have on top of Microsoft Defender."
"We have seen ROI. Most of the other competing alternatives will cost up to around $30 per user device. We average 400 devices. Therefore, the amount that we save each year is 400 times $30."
"The base price for an E5 license, which includes Enterprise Mobility + Security E5, is $57 per user per month."
"As we operate in the educational sector, we are eligible for an educational discount."
"The normal, standalone model, is not expensive, but the enterprise model that includes the bundle with email and some web protection, is a bit more expensive."
"We have a bundle where the price includes all Microsoft products."
"This is an expensive product and licensing for all Microsoft products is a big issue."
"The solution's price is mid-ranged."
"The product's pricing is reasonable compared to other vendors."
"The pricing of the solution could be better."
"The cost of the license is on the high side. It's a yearly subscription."
"The price of Trend Micro Cloud App Security is expensive for regular users. There are not any hidden fees. First-time users of the solution should purchase implementation packages or professional services."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
892,776 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
12%
Construction Company
12%
Comms Service Provider
8%
Manufacturing Company
8%
Computer Software Company
10%
Financial Services Firm
9%
Manufacturing Company
9%
Government
8%
Performing Arts
13%
Manufacturing Company
10%
Financial Services Firm
7%
Construction Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise20
Large Enterprise48
By reviewers
Company SizeCount
Small Business82
Midsize Enterprise43
Large Enterprise95
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise1
Large Enterprise2
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
Which offers better endpoint security - Symantec or Microsoft Defender?
We use Symantec because we do not use MS Enterprise products, but in my opinion, Microsoft Defender is a superior sol...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never pu...
What is your experience regarding pricing and costs for Microsoft Defender for Endpoint?
We have been discussing pricing, setup cost, and licensing, and we are currently on an E3. We are discussing going to...
What needs improvement with Trend Micro Cloud App Security?
For improvements, I think it would be great if Trend Micro Cloud App Security could enhance their product to be a sin...
What is your primary use case for Trend Micro Cloud App Security?
We use the solution for cloud data protection, particularly for email and file-sharing systems. It integrates with Mi...
What advice do you have for others considering Trend Micro Cloud App Security?
We chose the solution because they've been Gartner leaders for over 15 years, have a good customer base, and are a we...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Microsoft Defender ATP, Microsoft Defender Advanced Threat Protection, MS Defender for Endpoint, Microsoft Defender Antivirus
No data available
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Petrofrac, Metro CSG, Christus Health
MedImpact Healthcare Systems, ClubCorp USA, Copa Airlines, Aava, Azra Solutions, BSN INET Co, Ltd, Carhartt
Find out what your peers are saying about Microsoft Defender for Endpoint vs. Trend Micro Cloud App Security [EOL] and other solutions. Updated: July 2024.
892,776 professionals have used our research since 2012.