No more typing reviews! Try our Samantha, our new voice AI agent.

Microsoft Defender Threat Intelligence [EOL] vs ThreatLocker Zero Trust Platform comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Mar 17, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
8.2
Microsoft Defender Threat Intelligence enhances security, saves on budgets, and improves detection, offering significant ROI and value.
Sentiment score
6.2
ThreatLocker Zero Trust Platform enhances security and productivity, offering cost savings and compliance, driving business growth and customer satisfaction.
It's a value-for-money product.
Mobility & IT Project Manager at Voicevine Pty Ltd
If something were to happen without ThreatLocker, the cost would be huge, and thus, having it is definitely worth it.
Tier 1 IT Engineer at a retailer with 11-50 employees
Based on what we use ThreatLocker Zero Trust Endpoint Protection Platform for with the same functionalities and packaging, it was around 13 or 14 hours.
Head Of Cyber Security at a outsourcing company with 201-500 employees
We have the MDR package as well, and just knowing someone is watching those endpoints at 3:00 a.m. is a lifesaver that you cannot put a dollar figure on.
System Administrator at Gwynedd Mercy University
 

Customer Service

Sentiment score
7.5
Microsoft Defender support is rated very good, with knowledgeable level two assistance, competent partners, and a helpful community platform.
Sentiment score
7.8
ThreatLocker Zero Trust Platform is praised for its rapid, effective customer service, despite occasional delays with chatbots.
Level two support is knowledgeable and knows how the product works, which is very good.
Cloud Solution architect at a tech services company with 51-200 employees
I would give Microsoft an eight for their technical support.
Mobility & IT Project Manager at Voicevine Pty Ltd
They have been very responsive, helpful, and knowledgeable.
Systems Security Analyst & Deputy Security Officer at a financial services firm with 201-500 employees
I would rate their customer support a ten out of ten.
Director, Managed Services at a consultancy with 11-50 employees
Their support is world-class.
Supervisor, Client Security at a consultancy with 11-50 employees
 

Scalability Issues

Sentiment score
7.4
Microsoft Defender Threat Intelligence is highly scalable, adaptable for businesses of all sizes, and supports thousands of endpoints efficiently.
Sentiment score
7.8
ThreatLocker Zero Trust Platform seamlessly scales and adapts for organizations of all sizes, ensuring flexibility, performance, and protection.
If there were some customizations available, I would rate its scalability as nine out of ten.
Cloud Solution architect at a tech services company with 51-200 employees
I started off with just the servers, and within a month and a half, I set up the entire company with ThreatLocker.
Technical Engineer at Cloud 1 Solutions
It seems to primarily operate on the endpoints rather than at a central location pushing out policies.
Systems Security Analyst & Deputy Security Officer at a financial services firm with 201-500 employees
ThreatLocker Zero Trust Endpoint Protection Platform scales very smoothly with our growing needs.
CEO at Mostro
 

Stability Issues

Sentiment score
8.0
Microsoft Defender Threat Intelligence is seen as stable and secure, with high reliability and effective phishing prevention despite occasional outages.
Sentiment score
7.9
ThreatLocker Zero Trust Platform is stable and reliable, with minimal issues, quickly resolved, and consistent performance across installations.
It provides a high level of security and avoids phishing and scam emails.
Cloud Solution architect at a tech services company with 51-200 employees
For five years, we have not had a problem.
Supervisor, Client Security at a consultancy with 11-50 employees
Once deployed, it downloads the policies locally, so even if the computer doesn't have internet, it doesn't matter.
Information Cybersecurity Technology Specialist at Freez.it
It has been very stable, reliable, and accessible.
COO at Panda Technology
 

Room For Improvement

Microsoft Defender needs price adjustments, improved integration, better accuracy, enhanced AI, and smoother user experience for evolving cybersecurity.
ThreatLocker Zero Trust Platform needs better training, support, integration, and user interface to address deployment challenges and improve usability.
Providing code customization would help keep pace with new vulnerabilities and threats.
Cloud Solution architect at a tech services company with 51-200 employees
The main area of improvement for Microsoft Defender Threat Intelligence is related to how information is conveyed.
Mobility & IT Project Manager at Voicevine Pty Ltd
From the telemetry data standpoint, I would prefer Defender data to be more open in future updates.
Consultant at Dell Technologies
Controlling the cloud environment, not just endpoints, is crucial.
COO at Panda Technology
ThreatLocker Zero Trust Endpoint Protection Platform could improve by being a little more hands-off, perhaps by having a team inside ThreatLocker that does all the vetting of patches; having one person hired by ThreatLocker to check out patches means that a million other industries using ThreatLocker Zero Trust Endpoint Protection Platform do not have to vet the same patch, ultimately saving time and money around the world.
Technical Support Engineer at CMIT Solutions of Central Orlando
This feedback would help us understand what is learned in real-time, especially during a one-hour learning mode setup, ensuring we remain aware of potentially unnecessary learned items.
Server Administrator at Clay County Sheriff's Office
 

Setup Cost

Microsoft Defender Threat Intelligence is cost-effective in bundles, but SMEs face challenges with standalone pricing and evolving licensing.
ThreatLocker Zero Trust Platform offers competitive, flexible pricing with customizable options, valued features, and includes ongoing support for enterprises.
After conversations with other partners, it became clear we underpriced it initially, which caused most of our issues.
Director, Managed Services at a consultancy with 11-50 employees
We are moving towards the Unified solution, where they basically bundle everything together, providing us better stability with the ability to bring in new product offerings without having to go back to the customer and say, 'This is going to cost you.'
Supervisor, Client Security at a consultancy with 11-50 employees
Money is saved because it is not costly, and I would suggest it for other companies.
Helpdesk Engineer at Computer Network Infrastructure (CNI) Consultants
 

Valuable Features

Microsoft Defender Threat Intelligence excels in integration, threat detection, user interface, data retention, real-time protection, and analytics.
ThreatLocker enhances security with application control, Ringfencing, and intelligent features, offering flexible and efficient management.
If it wasn't for that real-time threat detection on the vulnerability, I think we would not have survived the attack.
Mobility & IT Project Manager at Voicevine Pty Ltd
One of the best features is that it provides a certain level of customization, allowing us to set our spam confidence levels.
Cloud Solution architect at a tech services company with 51-200 employees
Our threat detection is enhanced due to the AI agents in Microsoft Defender Threat Intelligence, which helps in detecting automatically.
Consultant at Dell Technologies
ThreatLocker Zero Trust Endpoint Protection Platform's ability to block access to unauthorized applications has been excellent.
Cyber Security Specialist at Bremmar Consulting
It protects our customers.
CTO at Zettabytes
The major benefit is fewer breaches overall, as nothing can be run without prior approval. This helps my company protect its data and secure itself effectively.
Tier 1 IT Engineer at a retailer with 11-50 employees
 

Categories and Ranking

Microsoft Defender Threat I...
Average Rating
8.4
Reviews Sentiment
7.3
Number of Reviews
32
Ranking in other categories
No ranking in other categories
ThreatLocker Zero Trust Pla...
Average Rating
9.2
Reviews Sentiment
7.1
Number of Reviews
82
Ranking in other categories
Network Access Control (NAC) (4th), Endpoint Protection Platform (EPP) (5th), Advanced Threat Protection (ATP) (4th), Application Control (1st), ZTNA as a Service (5th), ZTNA (5th), Ransomware Protection (1st)
 

Featured Reviews

Charles Mokoena - PeerSpot reviewer
Mobility & IT Project Manager at Voicevine Pty Ltd
Has strengthened our ability to detect threats in real time and improved internal security decision-making
The features that I find most valuable in Microsoft Defender Threat Intelligence include the Sentinel part of it. There are several features we've looked at, including Sentinel as well as extended Defender, which is XDR. I've used those two, and that's what I've found quite useful for us, especially in the hardening and analysis part of the whole threat analysis. We use the real-time threat detection features in Microsoft Defender Threat Intelligence. If it wasn't for that real-time threat detection on the vulnerability, I think we would not have survived the attack. The integration capabilities of Microsoft Defender Threat Intelligence with other Microsoft security tools have benefited our organization's threat management process by initially being quite a challenge, especially coming from other security tools such as Fortinet and Check Point. However, once you've gotten used to it, it's quite easy and user-friendly. The dashboard, especially the threat analysis dashboard, is quite detailed in terms of providing a view of which areas in our environment need attention, making it quite useful.
Santo Joy - PeerSpot reviewer
Head Of Cyber Security at a outsourcing company with 201-500 employees
Security controls have been strengthened with granular application, ringfencing, and access policies
The features of ThreatLocker Zero Trust Endpoint Protection Platform that I like the most are the Ringfencing, elevation control, storage control, and application whitelisting functionality. For examples of how these features benefit my company, we were looking for a solution across various vendors to actually implement application whitelisting controls. ThreatLocker's agent, which is very lightweight and does not use much CPU or RAM, helped us achieve that solution. Ringfencing was an add-on that ticked off a lot of Australian framework security controls, which is the reason we chose it. My impression of the allowlisting feature in terms of managing which software, scripts, and libraries run on my devices is that ThreatLocker's community page has a lot of information around this, which is very helpful. Not only that, the Cyber Hero support that ThreatLocker provides gives us insights and best practices, helping us achieve that solution and guiding us to the right platform. The impact of Ringfencing on controlling the behavior of approved applications has been a big winner for us because it is something that many other platforms do not provide as a functionality. Having that allowed us to identify what applications talk to each other, which is something that many other platforms do not do. The network control feature impacts my ability to manage network traffic across my endpoints and servers. We have not used this widely across all our partners, but wherever required, we use it. It has been an easy solution for those customers to get that control implemented. The elevation feature's role in facilitating just-in-time administrative access for approved applications shows that elevation control helps in many use cases involving remote control platforms, door usage, and security system platforms that require local admins. There are many solutions that provide this functionality, but the licensing cost seems to be expensive, and it also adds another solution into the mix. Rather than doing that, we try to use ThreatLocker Zero Trust Endpoint Protection Platform to achieve that control. Regarding the storage control feature, I have used it. The primary function is USB blocking, which is very widely adopted, and also just locking down and allowing certain users to access certain file locations helps us there. When it comes to enforcing policy-driven access over various storage devices, it depends on the business risk adapted by the companies that we support, but generally the use case is USB and external storage devices where companies know that is a risk, but they do not have appropriate solutions. There are EDR platforms that claim to do this, but ThreatLocker Zero Trust Endpoint Protection Platform does it at an advanced level. My assessment of the efficiency of the real-time threat intelligence and category controls employed by Web Control in blocking malicious and non-compliant sites leads me to think that Web Control is another functionality within ThreatLocker Zero Trust Endpoint Protection Platform that is an add-on on top of the current set. That is another solution that we use based on what is required for the company, but again, that is not widely adapted yet for our partners.
report
Use our free recommendation engine to learn which Advanced Threat Protection (ATP) solutions are best for your needs.
911,436 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
18%
Outsourcing Company
9%
Manufacturing Company
8%
Educational Organization
8%
Computer Software Company
11%
Manufacturing Company
11%
Financial Services Firm
11%
Outsourcing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business17
Midsize Enterprise2
Large Enterprise15
By reviewers
Company SizeCount
Small Business56
Midsize Enterprise14
Large Enterprise13
 

Questions from the Community

What needs improvement with Microsoft Defender Threat Intelligence?
From the telemetry data standpoint, I would prefer Defender data to be more open in future updates.
What is your primary use case for Microsoft Defender Threat Intelligence?
We have tried Microsoft Defender Threat Intelligence. I have expertise with Microsoft Defender products. I am not familiar with Microsoft Defender for IoT because we did not use that in our environ...
What advice do you have for others considering Microsoft Defender Threat Intelligence?
I will recommend Microsoft Defender Threat Intelligence because it is a complete automation solution for threat production detection and an end-to-end solution for client security. Unfortunately, s...
What is your experience regarding pricing and costs for ThreatLocker Allowlisting?
My experience with pricing, setup cost, and licensing for ThreatLocker Zero Trust Platform is that the pricing is reasonable, the cost is fair, and the licensing is not too high.
What needs improvement with ThreatLocker Allowlisting?
I would suggest adding an AI-based policy recommendation feature to ThreatLocker Zero Trust Platform because we have to create every policy manually. If there were a custom AI that could help with ...
What is your primary use case for ThreatLocker Allowlisting?
Our main use case for ThreatLocker Zero Trust Platform is to provide endpoint security and to control each and every application end-to-end that can run on the company's devices, primarily to secur...
 

Also Known As

No data available
Protect, Allowlisting, Network Control, Ringfencing
 

Overview

Find out what your peers are saying about Palo Alto Networks, Proofpoint, Microsoft and others in Advanced Threat Protection (ATP). Updated: August 2026.
911,436 professionals have used our research since 2012.