Try our new research platform with insights from 80,000+ expert users

Microsoft Defender XDR vs Trellix Active Response comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Sep 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.1
Microsoft Defender XDR provides high ROI by consolidating security tools, streamlining operations, and enhancing security, despite licensing costs.
Sentiment score
3.8
Trellix Active Response improved threat detection, reduced incident response times, increased efficiency, and enhanced productivity with an intuitive interface.
We can quarantine and isolate a device within minutes.
Information Security Analyst at a educational organization with 10,001+ employees
Microsoft Defender XDR has saved me at least 50% of my time.
House security operator at Cypress Creek Renewables
It helped stop multiple intrusion points where we would have had millions in lost revenue if the attackers got in.
Network Technician at T. Baker Smith, LLC
While we haven't yet quantified the financial benefits, we recognize that there has been a return on investment, particularly with operational efficiencies provided by the alerts.
Senior Manager Operational Technology and Cyber Security at Eskom Ltd
 

Customer Service

Sentiment score
6.1
Microsoft Defender XDR's support is timely and responsive, yet smaller organizations experience slower, less effective assistance than larger ones.
Sentiment score
7.8
Trellix Active Response's customer support is generally positive, but availability and contact speed could improve, rated seven out of ten.
You get stuck in low-level support for way longer than you should, instead of them escalating the issue up the chain.
Enterprise Application Engineer at a legal firm with 1,001-5,000 employees
It's critical to escalate SEV B issues immediately to a domestic engineer.
Infrastructure engineer at Cetera Financial Group
Once issues are escalated to the second or third layer, the support is much better.
Cyber Security Engineer at a financial services firm with 1-10 employees
I would rate technical support from Trellix Active Response as a seven because sometimes we face difficulties finding engineers quickly, leading to customer frustration.
Information Security Engineer at Nhq Distribution Ltd
 

Scalability Issues

Sentiment score
6.9
Microsoft Defender XDR scales well for various organizations, efficiently supporting growth and flexibility despite some network deployment challenges.
Sentiment score
4.1
Trellix Active Response is scalable, integrates easily, handles large data seamlessly, and maintains performance and security with minimal latency.
My concern is about the scale of events and alerts being generated, and the product is doing a very good job of only surfacing the important items for us.
Vice President, Information Technology at a construction company with 201-500 employees
Microsoft Defender XDR shows tremendous scalability, much more so than on-premises solutions.
Infrastructure engineer at Cetera Financial Group
Microsoft Defender XDR scales pretty well.
Information Security Analyst at a educational organization with 10,001+ employees
The scalability of Active Response is satisfactory.
Senior Manager Operational Technology and Cyber Security at Eskom Ltd
 

Stability Issues

Sentiment score
8.1
Microsoft Defender XDR is praised for high stability, reliable performance, minimal issues, frequent updates, and prompt issue resolution.
Sentiment score
4.6
Trellix Active Response is praised for reliability, efficient data handling, quick threat detection, adaptability, and stability with minimal downtime.
The service has remained consistently online, with any issues isolated to specific components, suggesting a well-designed and modular architecture.
Senior System Engineer at a sports company with 5,001-10,000 employees
The services within our ecosystem have been reliable, meeting their SLAs.
Infrastructure engineer at Cetera Financial Group
It provides high-fidelity signals.
Information Security Analyst at a educational organization with 10,001+ employees
 

Room For Improvement

Microsoft Defender XDR requires enhancements in speed, integration, automation, AI, ease-of-use, and industry-specific threat intelligence.
Trellix Active Response needs better resource management, advanced analytics, and improved integrations for efficient monitoring and AI features.
The licensing process needs improvement and clarification.
Owner at a consultancy with 11-50 employees
Improvements are needed in automated response capabilities.
Security manager at a consultancy with 10,001+ employees
Some inconsistencies exist between blades, which could be improved for a more seamless user and UI experience.
Infrastructure engineer at Cetera Financial Group
We would like Trellix to optimize the technology for these systems similarly to how it is deployed for normal endpoints.
Senior Manager Operational Technology and Cyber Security at Eskom Ltd
There is room for improvement in the platform area and security area to make the dashboard visibility clearer and easier for customers to monitor malicious activities occurring in their environment.
Information Security Engineer at Nhq Distribution Ltd
 

Setup Cost

Microsoft Defender XDR pricing is seen as complex but fair, with high costs alleviated in bundled Microsoft 365 packages.
There are certainly savings when using Microsoft Defender XDR, which can range from 30%, 40%, and even up to 50%.
Director, Sales at a tech vendor with 201-500 employees
I would rate the pricing as eight out of ten, indicating it is a reasonable cost for the product.
Security manager at a consultancy with 10,001+ employees
Microsoft purposefully obfuscates this through marketing ploys to hide costs.
Senior System Engineer at a sports company with 5,001-10,000 employees
Based on our evaluations, Trellix Active Response's pricing was the most feasible from a cost perspective.
Senior Manager Operational Technology and Cyber Security at Eskom Ltd
 

Valuable Features

Microsoft Defender XDR integrates tools for comprehensive security, offering threat detection, automation, identity protection, and enhanced efficiency.
Trellix Active Response enhances analytics, user insights, and incident handling, excelling in detection and response with holistic EDR benefits.
With Microsoft threat intelligence information, it detects various types of threats, including insider attacks, malicious content, and data exfiltration.
Security manager at a consultancy with 10,001+ employees
This allows us to secure our systems in advance and proactively improve security, rather than waiting for incidents to occur.
Works at Hometrack
Once we have it on the security dashboard, we can see a real-time storyline.
Information Security Analyst at a educational organization with 10,001+ employees
They notify us immediately of any vulnerabilities on the endpoints, allowing us to deploy a response quickly.
Senior Manager Operational Technology and Cyber Security at Eskom Ltd
The most valuable feature of Trellix Active Response is that whenever any incident occurs, it allows us to disconnect from that particular network or area and shut down the system using commands.
Information Security Engineer at Nhq Distribution Ltd
 

Categories and Ranking

Microsoft Defender XDR
Ranking in Endpoint Detection and Response (EDR)
7th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
106
Ranking in other categories
Extended Detection and Response (XDR) (3rd), Microsoft Security Suite (5th)
Trellix Active Response
Ranking in Endpoint Detection and Response (EDR)
45th
Average Rating
7.0
Reviews Sentiment
5.1
Number of Reviews
5
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of January 2026, in the Endpoint Detection and Response (EDR) category, the mindshare of Microsoft Defender XDR is 2.6%, down from 3.2% compared to the previous year. The mindshare of Trellix Active Response is 0.4%, up from 0.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Detection and Response (EDR) Market Share Distribution
ProductMarket Share (%)
Microsoft Defender XDR2.6%
Trellix Active Response0.4%
Other97.0%
Endpoint Detection and Response (EDR)
 

Featured Reviews

KO
House security operator at Cypress Creek Renewables
Advanced threat hunting saves significant time in tracking and responding to incidents
Microsoft Defender XDR could be improved with a lower price. My main suggestion would essentially be what Copilot is providing, which is a single pane of glass, so I don't have to go to different windows. That's just a workflow consideration for me. It would be great to have all the information centralized into one particular data app. If I need to open up extra ones, I can, however, I would appreciate a future where everything I need is right there on one single pane of glass. Beyond that, there's really nothing else I see that I would want Microsoft to improve.
ED
Senior Manager Operational Technology and Cyber Security at Eskom Ltd
Operational efficiencies increase with immediate threat alerts for endpoints
We use Trellix Active Response primarily for our endpoints, including desktop computers. It monitors all the tools that our users use for their day-to-day work The alerts provided by Trellix Active Response are its most valuable feature. They notify us immediately of any vulnerabilities on the…
report
Use our free recommendation engine to learn which Endpoint Detection and Response (EDR) solutions are best for your needs.
881,114 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
13%
Financial Services Firm
9%
Manufacturing Company
8%
Comms Service Provider
7%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise25
Large Enterprise38
No data available
 

Questions from the Community

What do you like most about Microsoft 365 Defender?
Microsoft Defender XDR provides strong identity protection with comprehensive insights into risky user behavior and potential indicators of compromise.
What is your experience regarding pricing and costs for Microsoft 365 Defender?
My experience with pricing, setup, costs, and licensing of Microsoft Defender XDR is tied to our E5 subscription, which is very straightforward for us. We also purchase the uplift for our mobile us...
What needs improvement with Microsoft 365 Defender?
I am not aware of a mobile app that would be available for my team. With a single analyst, if she is ever away, it would be beneficial to have easier access. While she can use the web portal, the e...
What is your experience regarding pricing and costs for McAfee Active Response?
Based on our evaluations, Trellix Active Response's pricing was the most feasible from a cost perspective. I rate the pricing between a six and an eight. It is justified.
What needs improvement with McAfee Active Response?
For Trellix Active Response, there is room for improvement in the platform area and security area to make the dashboard visibility clearer and easier for customers to monitor malicious activities o...
What is your primary use case for McAfee Active Response?
The typical use case for Trellix Active Response is to provide quick incident response, as the product collects and correlates logs with the ePO dashboard, allowing customers to get visibility of t...
 

Also Known As

Microsoft 365 Defender, Microsoft Threat Protection, MS 365 Defender
McAfee Active Response
 

Overview

 

Sample Customers

Accenture, Deloitte, ExxonMobil, General Electric, IBM, Johnson & Johnson and many others.
Liquor Control Board of Ontario
Find out what your peers are saying about Microsoft Defender XDR vs. Trellix Active Response and other solutions. Updated: December 2025.
881,114 professionals have used our research since 2012.