No more typing reviews! Try our Samantha, our new voice AI agent.

Microsoft Forefront [EOL] vs Symantec Endpoint Security comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
117
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Microsoft Forefront [EOL]
Average Rating
8.4
Number of Reviews
8
Ranking in other categories
No ranking in other categories
Symantec Endpoint Security
Average Rating
7.6
Reviews Sentiment
6.8
Number of Reviews
146
Ranking in other categories
Endpoint Protection Platform (EPP) (8th)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
it_user772620 - PeerSpot reviewer
Systems Consultant at a tech services company with 501-1,000 employees
There is simplicity in the management of the product compared to its competitors
Web proxy services along with the integrated firewall VPN Intrusion prevention Malware inspection URL filtering The simplicity of managing the product compared to its competitors, like BIG-IP F5 and Citrix NetScaler The ease of deploying mobile functionality through the web proxy has…
Abhimanyu Das - PeerSpot reviewer
Senior Cybersecurity Engineer at Kyndryl
Behavioral protection has blocked ransomware and now saves extensive recovery and audit time
The best feature of Symantec Endpoint Security is its effectiveness in malware protection. Its malware protection capabilities stand out due to their ease of management. Although multiple tools assist in this process, managing them all can sometimes be challenging. In terms of malware protection, Symantec Endpoint Security performs well, and its mechanisms, tactics, and techniques are effective. Symantec Endpoint Security offers robust features such as advanced reporting capabilities with a customizable dashboard that integrates EDR timelines, threat maps, and compliance metrics into a single view. Additionally, reports can be exported to PDF or CSV formats, making reporting one of its strong points. It also provides comprehensive device control features, which block unauthorized USB devices and support whitelisting. This helps prevent data exfiltration and phishing scenarios without disrupting user workflows.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The product is very good, it has caught a lot of exploits that most products would not."
"Based on my experience with Cortex XDR by Palo Alto Networks, I highly recommend it due to its quick response to zero-day attacks and low utilization from end-user devices."
"The solution allows us to make investigations. Other XDR solutions also provide similar capabilities but for investigation, Cortex XDR is better."
"It can automatically correlate events and logs, which is very helpful for an IT administrator. It can correlate different kinds of malware activities over a network, agent, or host system. You do not need to do it manually. It is a good feature. It is also a user-friendly solution. We have deployed it on the cloud because our space does not provide any flexibility for on-premises deployment, but Palo Alto has added some flexibility to install it on-premises. It must be like the same Cortex XDR agent for all the VPN services, web filtering services, and everything else."
"We think that this product will help us grow, as it meets our needs currently and we can grow with it over time."
"We use it for malicious connections from malicious websites, to identify payloads that might be inside the traffic, to identify malicious processes or bugs that are running on the network, and any activities that tend to lead to data infiltration."
"In one single alert, we are getting the network telemetry, endpoint telemetry, email security telemetry, and proxy telemetry all in one single ticket, making it very easy."
"After deploying Traps, we saw the performance of the network improve by 65 to 70 percent."
"To date we have not had a virus infecting a desktop with Forefront installed - this is the main reason why we will not use another anti-virus solution."
"It cost us approx. US$250k to set up and is roughly US$200 day to day."
"The snort engine, which is the muscle behind the Sourcefire IPS technology, has always been a joy for me to work with."
"Performance wise, it's one of the most effective anti-virus solutions we have ever used."
"The simplicity of managing the product compared to its competitors, like BIG-IP F5 and Citrix NetScaler, is a valuable feature."
"Our ROI is that we can provision users accounts within 30 minutes of them being put into the system."
"It has automated the entire user and group management process, thus reducing manual work and help desk cost to a great extent."
"Product has been enough for our customers’ requirements."
"It's a robust product."
"Overall, we're pretty happy with the product."
"It is more than a classic Anti-virus solution: both SONAR and IPS help to protect the system."
"It is very easy to use and keeps us secure."
"This solution has helped us because it is really useful for blocking all kinds of viruses."
"Simply put, it is the one product that's an integrated holistic solution for the whole security suite for an endpoint."
"What I appreciate most about Symantec Endpoint Security is that it's easy to manage compared to other tools I have worked with, such as minimal endpoint security, McAfee, and CrowdStrike."
"A secure stable product, and good customer service of this product from the vendor."
 

Cons

"Limited remote connection."
"However, if you do not have Palo Alto in your environment, you are paying these additional services just for Cortex XDR by Palo Alto Networks, so it is not a cost-effective solution."
"I think sometimes Cortex XDR agent automatically stops event capturing from the device, and then even the dashboard does not get any notifications from the agent."
"Whenever the tool releases a new version when deploying the product across the organization, I feel like there are some disturbances in the CPU usage after upgrading the tool to the latest version."
"For working with the solution, you only really need a web browser, however, we've found that working on Chrome, for example, is horrible."
"The playbooks could be improved to include more functionalities or actions."
"It is an enterprise-level solution. Its price could be less expensive."
"Cortex XDR by Palo Alto Networks could improve its user interface, which is more complicated compared to competitors such as SentinelOne."
"Pretty awful. A large initial investment with something that could have been done by one person full time over six years with less hassle."
"When using Forefront in a domain network, it is quite difficult to create the group policies needed for definition/engine updates using WSUS."
"One of the biggest pain points was that username changes were not automated and caused problems."
"The product has unfortunately reach its End-Of-Life (EOL) at Microsoft and is now replaced by several products."
"More out of box connectors and conducting awareness of the product along with more marketing."
"Web user interface from 1990s. Users laugh at it."
"Without a local Windows Update Server, the client seems to update very slowly and may take a lot of time."
"I’d personally like to see some additional customization capabilities in the reporting section."
"Reporting in this solution needs improvement."
"It can be improved in terms of features and integration. It should have more advanced features and more integration."
"The device control level and application control level should improve."
"The bottom line is that when it comes to management, reliability of management, reporting, alerting, installation, and licensing, if these don't work reliably you can't trust the product's security capability."
"It would be interesting if Symantec Endpoint protection could also manage Windows Defender. If they were to add a feature, it would be nice if you could see the Symantec client and the Windows Defender client in case you choose to deploy both."
"I know they were just bought out by Broadcom and there have been some difficulties with Broadcom as far as getting license renewals, etc. Mostly, due to the fact that it's confusing, even for the vendor, people are turned off by it. The vendors are telling us that it can take weeks for them to get a renewal quote, nevermind the actual renewal."
"Must push to EXE files to the endpoints."
"Technical support is a bit of an issue."
 

Pricing and Cost Advice

"The pricing is okay, although direct support can be expensive."
"Our license will require renewal in August, after which the maintenance will continue as usual."
"This is an expensive solution."
"The cost depends on your chosen license type, like Pro or other licenses."
"The pricing is a little high. It is per user per year."
"Cortex XDR’s pricing is very reasonable."
"Our customers have expressed that the price is high."
"I did PoCs on products called Cylance and CrowdStrike. Although, I consider these products and they were also good, when it come to cost and budgetary factors, Traps has been proven to be better than the other two products. It is quite cost-effective and delivers all the entire solution which we require."
Information not available
"There is a yearly license."
"One great benefit is we do not need to activate a license for every endpoint. The price is fair."
"The licensing is okay. Symantec has a very granular licensing model, so you only buy what you need."
"I rate the product's pricing a six out of ten."
"It is the better product, even if it is a little on the higher side."
"Its price should be reasonable."
"Pricing and licensing are important to us when choosing a product."
"They're on the reasonable side. They are at mid-level. They're not too expensive as compared to their competitors. They're also not too cheap. In terms of price structure, hopefully, they could do a subscription."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
913,349 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Manufacturing Company
9%
No data available
Outsourcing Company
13%
Comms Service Provider
13%
Financial Services Firm
9%
Construction Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise54
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise4
Large Enterprise2
By reviewers
Company SizeCount
Small Business69
Midsize Enterprise32
Large Enterprise63
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
Ask a question
Earn 20 points
Which is better - Cortex XDR or Symantec End-User Endpoint Security?
Aqua Security is easy to use and very manageable. Its main focus is on Kubernetes and Docker. Security is a very valu...
Which offers better endpoint security - Symantec or Microsoft Defender?
We use Symantec because we do not use MS Enterprise products, but in my opinion, Microsoft Defender is a superior sol...
What is your experience regarding pricing and costs for Symantec End-User Endpoint Security?
Symantec Endpoint Security's pricing is better than most offerings based on my research. It seems to be half the cost...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
MS Forefront [EOL]
Symantec EPP, Symantec Endpoint Protection (SEP)
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
EUROVIA CS, a. s., King Abdullah Bin Abdulaziz Public Education Devel, Bank Alfalah Ltd., CLEAResult, St. Lucie County Public Schools, Wiltshire Council
Audio Visual Dynamics, Red Deer Advocate, Asia Pacific Telecom Co. Ltd., Kibbutz Ein Gedi, and AMETEK, Inc.
Find out what your peers are saying about Microsoft, SentinelOne, CrowdStrike and others in Endpoint Protection Platform (EPP). Updated: September 2026.
913,349 professionals have used our research since 2012.