It is the end defense against anything coming into our computers and through other channels, e.g., we have some other measures. A lot of our users use Microsoft Remote Desktop Services, so all our servers are locked down. The solution handles what nothing else finds along the way. It is a standard endpoint for computers, servers, and tablets.
Head of IT at a engineering company with 10,001+ employees
Provides users protection without impacting their experience
Pros and Cons
- "Microsoft Defender is always running. It is doing its job, so it is fine. I don't have any issues with the way it was implemented or how we are running it. We have been upgrading IT throughout the years, but there have been no issues."
- "It provides peace of mind with really good pricing."
- "From an audit point of view, our auditors would like to have more reports on how things are used, if things go wrong, and how they went wrong. For example, if something got a warning, "Why?" So, we would like more versatility for tracing and reporting. That would improve the product, as long as the user interface doesn't get bogged down."
What is our primary use case?
How has it helped my organization?
What the user doesn't see or experience, the user is happy with. Every time our other services go in and put a stop pop-up in front of what they are doing when they want to visit a website, but the browser says, "No," or they are trying to download a link and then says, "Oh, no. This is dangerous," that upsets users because they can't do what they want to do. As long as we don't get any of that, then users are happy. If users don't feel it or know about it, then they are happy. Everything else will make them unhappy.
Our end users expect to be protected and that everything works. When IT doesn't work as they expect, then they get unhappy in some form. We kind of forced this solution upon them, so they don't have a choice. As long as it doesn't meddle with their normal work, they are fine. For example, when GDPR hit us in May of 2018, that was upsetting because they now had to do some of their work a little differently. So, they don't like GDPR because it interferes with their normal workflow. Normally, users come to me if they have issues with anything. However, if everything works as expected, they are happy. In addition, they expect that they are protected.
What is most valuable?
When you have something fail and you have three or four different vendors where the fail might be located, everyone just says, "Well, it's awful." Then, you have to go and find out where the fault is. That is really annoying and can cost the business money. For that reason, if I can have one single point of contact when I have a problem to help me out, and say, "Let's find the solution." That is much better instead of having me contact multiple companies to track errors down.
What needs improvement?
The protection will always need improvement:
- From a technical standpoint, I would like better artificial intelligence on how it does its stuff in the background. It will always be behind. However, at some point, it would be nice if it could get better. It is not bad, but it could always be better.
- From an audit point of view, our auditors would like to have more reports on how things are used, if things go wrong, and how they went wrong. For example, if something got a warning, "Why?" So, we would like more versatility for tracing and reporting. That would improve the product, as long as the user interface doesn't get bogged down.
Buyer's Guide
Microsoft Defender for Endpoint
September 2026
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,325 professionals have used our research since 2012.
For how long have I used the solution?
I have been using the current solution since 2014.
What do I think about the stability of the solution?
We haven't had any issues. I haven't had any bad experiences. I expect it to work, and it works. It is just there. For example, when you have Word or the whole Office package, as long as it works, people are happy. You just have it, and you don't have to say, "Oh, this version is really..." It is just Microsoft. For most users, Microsoft is Windows, Defender, and the Office package. As long as you just use that, then people will say, "Okay, we're just basically using Windows." They don't care about one thing or another, as long as IT works.
As long as things are slowly upgraded, it works, and we don't have any issues, then I am happy.
What do I think about the scalability of the solution?
I let my outsource company handle scalability. I only get involved if there are issues.
We have 50-plus servers with around 125 to 150 endpoints.
How are customer service and support?
Our consultancy has a deal with Microsoft where they can get access to Microsoft directly. We are part of that deal. When we have issues that need some type of Microsoft input, we can get it. However, I will let the consultancy do that. I wouldn't do that myself.
Which solution did I use previously and why did I switch?
We use different email solutions and web solutions to handle incoming and outgoing traffic. However, we have not previously used another endpoint protection solution.
How was the initial setup?
In 2014, we upgraded from Windows 7. It was a completely new deployment of everything. Every server, every endpoint, and even the old laptops and desktops were upgraded. So, it wasn't just Defender. Microsoft Defender wasn't really the issue, as it worked. We had a lot of other IT that was annoying, but I don't remember that we had any struggles with Defender.
Microsoft Defender is always running. It is doing its job, so it is fine. I don't have any issues with the way it was implemented or how we are running it. We have been upgrading IT throughout the years, but there have been no issues.
We had a migration deadline set by our mother company. We had to stop using Windows 7 and server 2003 by 15th of June, and we started in April. So, it was done in just under two months right before June 1st.
What about the implementation team?
We are part of the aircraft industry. We have been going downhill for some time, and now we are sort of going up again. At the time of purchase, we simply bought the outsourcing with the solution, meaning we would get this many machines and servers using these services. They kind of supplied everything.
We outsourced the deployment to another company at that point in time, who put up all the consultants and stuff. Before that, we had everything internally and on-premises. At that point, we moved it out still on-premises, but not in our own house. So, we built a separate system, then moved users over.
We didn't have Microsoft in to specifically help us.
The administration of this solution is outsourced. We use a consultancy who has 50-plus employees/consultants. They take care of nearly all services: Defender, Teams, SQL, etc. I then only have to talk to one or two people who are specialized in what needs to be done.
I have been very happy with our current IT services provider. We have had them for about a year. They took over from the old consultancy who installed our IT in 2014. Our current consultancy took over in 2020 because I wasn't so happy with the old guys.
What's my experience with pricing, setup cost, and licensing?
It provides peace of mind with really good pricing. It won't be upsetting my budgets or anything like that.
Which other solutions did I evaluate?
Our outsourcer handled the decision that we were to use Defender, Remote Desktop Services, etc. They just said, "If you choose us, this will be your solution." It came as a package. Unfortunately, that company was bought by another IT services company, who bogged everything up. The service went downhill and stuff didn't get upgraded. So, we switched to another Danish supplier with whom we currently are happy.
What other advice do I have?
Go for it. It is a standard solution. If you use Windows, you might as well go for Defender. With this solution, you have your normal dependencies within Microsoft. This means that you don't have to talk to another company; you talk directly to Microsoft. Some people might go for something else, and that is fine too. However, depending on how big your company is, if you are a small or medium business, you may want to have as many eggs in one basket to have fewer points of contacts.
It is a good endpoint. All the administration is handed over to our outsource partner. So far, it has been good. We have been using it for years, so it is the de facto standard for us right now.
As far as I know, its capabilities are okay. It is up there with the rest of them. Sometimes, this is what Gartner says is the best, the next best, the 10th best, etc. That will always change. As long as we don't get hit, we are fine. If we get hit, then there are questions around what we can expect from it, what we can get out of it, what help did we get, etc., but I would let my outsource partner deal with that. Directly, I don't have my hands on it.
I would rate this solution as an eight out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Specialist at a healthcare company with 10,001+ employees
Automated Investigation and Response reduces workload of our SOC analysts, but lacks integration customization
Pros and Cons
- "One of the features which differentiates it from other EDR providers is the Automated Investigation and Response, which reduces the workload of SOC analysts or engineers. They don't have to manually investigate each and every alert on the endpoint, since it does so automatically. And you can automate the investigation part."
- "There are several features that have helped to improve our security posture at the prevention level, such as the attack surface reduction controls and the exploit prevention control."
- "Other vendors provide a lot of customization when it comes to integration, which every big organization requires. No big organization depends on one particular tool. Defender lacks that at this point."
- "One of the differences between other solutions I have used and Microsoft Defender for Endpoint is that the latter is not yet enterprise-ready to the same extent that the other vendors are."
What is our primary use case?
We use it for endpoint detection and response.
The agent is installed on the endpoint, on the laptop or desktop, but it's a SaaS solution.
How has it helped my organization?
One feature that has proven beneficial is the Threat and Vulnerability Management module of Defender for Endpoint, which provides information on the vulnerability of all the endpoints. We don't have to run active scans via network scanners. It is built-in. That has proven to be helpful, although we're still in the early phases. We have identified vulnerabilities that were in our organization for too long and nobody knew about those machines and the vulnerabilities on them. From a vulnerability remediation point of view, it has been quite helpful to us.
What is most valuable?
One of the features which differentiates it from other EDR providers is the Automated Investigation and Response, which reduces the workload of SOC analysts or engineers. They don't have to manually investigate each and every alert on the endpoint, since it does so automatically. And you can automate the investigation part.
In addition, there are several features that have helped to improve our security posture at the prevention level, such as the attack surface reduction controls and the exploit prevention control. The attack surface reduction comes with the solution, out-of-the-box. There is Application Control as well, which is kind of difficult to implement, but once you are through the pain of designing and implementing it, it is one of the very good features to have. These tools are some of the things that are missing from other vendors' products, as I have worked with McAfee, Symantec and Carbon Black.
What needs improvement?
One area for improvement is that, because it comes out-of-the-box, it does not interact well with many applications we have developed in-house. There is no way to exclude them because it interacts with everything on the endpoint. One of the issues is lagging: the in-house-developed applications suffer from this and they become slow. For a big enterprise, it is important that they include a feature so that we can exclude these applications.
Another area where it could be improved is that, while it collects a lot of data, it misses some data, which is important, such as the hardware version of the endpoint and the AV signature version. I think this improvement is in the Microsoft pipeline already but it is not in the solution yet.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for around one and a half years.
What do I think about the stability of the solution?
It has been quite stable up until now. It does not break. Microsoft is developing on it quite frequently and more and more features are coming in, but overall it is quite stable. It does not break that often.
As we have moved away from Microsoft Defender Antivirus and to the EDR solution, we have seen very few issues so far that users have faced with this. There have been very occasional performance issues for some users, but they have been very rare.
What do I think about the scalability of the solution?
Scalability is one thing which, I think, Microsoft is working on, because it is not yet very scalable. What it provides out-of-the-box is all it has. Any big organization needs customization, but the customization of it and running customized things on top of it are areas where it is lagging. That something Microsoft needs to work on. Examples include running custom playbooks or customizing the events which it is collecting.
We are protecting 100,000 endpoints with this solution. We may increase usage, but there is no plan for that as of yet.
How are customer service and technical support?
Microsoft technical support is good.
Which solution did I use previously and why did I switch?
Before Microsoft Defender for Endpoint we had Carbon Black. But when I came onboard, Defender for Endpoint had already been chosen.
How was the initial setup?
The setup process is not very complex, but it is also not very straightforward. It depends what solutions you have. If you have everything set up, which is usually the case for big organizations, then it is pretty smooth. But if there are some things that are not set up properly in the organization, like certain parts of the infra or the cloud onboarding, then it becomes cumbersome, not the installation part, but in setting up the backend which it needs.
Our implementation strategy was that we started with a few pilot machines, to onboard Defender for Endpoint. We noticed that we had around 70 to 80 percent failures. It was a learning phase and we identified the root cause of those failures. There are some settings in Defender AV that need tweaking when you want to onboard Defender for Endpoint. We struggled to tweak those settings, but once that was done, it went pretty smoothly for the next couple of pilots. Then we encountered another roadblock which was related to an OS version dependency.
Overall, it took us about one month to onboard the solution, but we are weak in infra.
What about the implementation team?
We had our consultant from Microsoft for the implementation. The engagement went on for three to four months. But one thing we noticed from this project was that it did not need a consultant. It was not that difficult to do. Maybe we did not get an expert consultant because, for solving issues, he also took time.
In addition to doing onboarding, we wanted our third-party integrations, but that was something they could not do because they were Microsoft. We had to do that ourselves. Over that three or four months, we realized that we didn't need them.
Microsoft consultancy is good and bad. If you get good consultants, they are really good. But sometimes you get consultants who are not expert enough in their domains and you don't get enough from them.
What was our ROI?
We have not seen ROI yet, but we are hopeful that in the future it will provide that.
Which other solutions did I evaluate?
One of the differences between other solutions I have used and Microsoft Defender for Endpoint is that the latter is not yet enterprise-ready to the same extent that the other vendors are. Other vendors provide a lot of customization when it comes to integration, which every big organization requires. No big organization depends on one particular tool. Defender lacks that at this point.
What other advice do I have?
Defender for Endpoint is marketed as an endpoint detection and response tool, but for others who are looking at onboarding it, they should take it as a holistic tool that provides AV, EDR, and vulnerability management all in one. However, it does not provide very good integration with third parties.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Microsoft Defender for Endpoint
September 2026
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,325 professionals have used our research since 2012.
Engineer at a educational organization with 5,001-10,000 employees
Pre-installed, free, and easy to use, but the free version doesn't provide centralized management, EDR, and behavioral analysis
Pros and Cons
- "It is easy to use because it is already pre-installed in Windows 10. We don't have to do anything to configure it. You can also configure the firewall by using a group policy so that it can be easily adopted in an environment."
- "It is easy to use because it is already pre-installed in Windows 10."
- "Microsoft Defender in the basic form is not very useful for managing the security environment. The free version is not capable of covering the needs of centralized management, EDR, and behavioral analysis. If you don't have the commercial version, you can't have centralized management and set up the policies and other things. Each client is a standalone installation, which is not useful for security in an enterprise model."
- "Microsoft Defender in the basic form is not very useful for managing the security environment."
What is our primary use case?
We were using the basic endpoint from Sophos without Intercept X and the EDR model, and currently, we are in the selection process of a new platform that has EDR embedded. We are using Microsoft Defender Antivirus for the time being till we get the new platform.
What is most valuable?
It is easy to use because it is already pre-installed in Windows 10. We don't have to do anything to configure it. You can also configure the firewall by using a group policy so that it can be easily adopted in an environment.
What needs improvement?
Microsoft Defender in the basic form is not very useful for managing the security environment. The free version is not capable of covering the needs of centralized management, EDR, and behavioral analysis. If you don't have the commercial version, you can't have centralized management and set up the policies and other things. Each client is a standalone installation, which is not useful for security in an enterprise model.
For how long have I used the solution?
I have been using this solution for six months.
What do I think about the scalability of the solution?
Currently, we have about 2,000 users.
How are customer service and technical support?
I didn't use support for this solution.
How was the initial setup?
It was already pre-installed in Windows 10.
What's my experience with pricing, setup cost, and licensing?
It is free. It is included in Windows 10.
Which other solutions did I evaluate?
We are using Microsoft Defender only for the time being. We will switch to another endpoint platform that can offer us more advanced features, centralized management, and EDR. We have not chosen the solution at the moment, but we might go for Bitdefender. It is one of the products that we have evaluated, and it can be suitable for our environment. It has some use cases that are really in the same line as our requirements.
What other advice do I have?
I would recommend this solution only for small home environments. It is not for enterprise environments unless you buy the commercial version.
I would rate Microsoft Defender Antivirus a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Managing Director at a financial services firm with 10,001+ employees
Reliable, well-priced, and it is easy to install
Pros and Cons
- "We use Microsoft Defender for the antivirus."
- "It's a stable solution."
- "The interface could be improved."
What is our primary use case?
There are endpoints that are not in our organization's network but are connected directly to the web. We use Microsoft Defender for the antivirus.
We are not dealing with this solution daily, just when there is an issue from time to time.
What needs improvement?
The interface could be improved.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for a couple of years.
What do I think about the stability of the solution?
It's a stable solution.
What do I think about the scalability of the solution?
We are only running it on a few workstations. The scalability is okay.
It's run on 10 out of 3,000 workstations and we plan to continue using it.
We have no more than 10 users in our organization.
Which solution did I use previously and why did I switch?
We are also using Symantec.
We have a few endpoints where we use Microsoft Defender because we cannot use the Symantec Sets.
How was the initial setup?
The initial setup was straightforward. It was easy to install and t only took a couple of minutes.
There is no team for maintenance. If there is an issue, the security team helps to resolve it.
What about the implementation team?
We completed the deployment and implementation ourselves.
What's my experience with pricing, setup cost, and licensing?
We don't have an issue with the price.
We have a bundle where the price includes all Microsoft products.
This is an area that I am not dealing with. I don't have all of the information.
What other advice do I have?
It's pretty good.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Specialist at a healthcare company with 10,001+ employees
Good support and valuable EDR feature, but not stable and not suitable for enterprises with lots of other processes and third-party tools
Pros and Cons
- "The EDR feature is most valuable."
- "I would recommend this solution to others if they don't have many third-party tools."
- "It is currently more suitable for end-users rather than enterprises with lots of other processes and third-party tools. It needs improvement on that front. We had many issues while integrating it with our enterprise solutions, such as Splunk, and third-party tools. It provides everything via APIs. Other vendors provide integration with third-party tools, but Microsoft doesn't do that. It is also logging too much and is not serialized from the process aspect. It has all the data, but it is not in a proper format or not properly indexed, which doesn't make it easier for enterprises to use this data. Other vendors provide troubleshooting information that can be used to troubleshoot issues, but Microsoft doesn't provide anything like that."
What is our primary use case?
We use it for our endpoint detection and response capability.
What is most valuable?
The EDR feature is most valuable.
What needs improvement?
It is currently more suitable for end-users rather than enterprises with lots of other processes and third-party tools. It needs improvement on that front. We had many issues while integrating it with our enterprise solutions, such as Splunk, and third-party tools. It provides everything via APIs. Other vendors provide integration with third-party tools, but Microsoft doesn't do that.
It is also logging too much and is not serialized from the process aspect. It has all the data, but it is not in a proper format or not properly indexed, which doesn't make it easier for enterprises to use this data.
Other vendors provide troubleshooting information that can be used to troubleshoot issues, but Microsoft doesn't provide anything like that.
For how long have I used the solution?
I have been using this solution for six months.
What do I think about the stability of the solution?
It is still a new product, and there are many reported bugs in terms of stability and impact on the endpoints.
What do I think about the scalability of the solution?
We have around 80,000 users.
How are customer service and technical support?
They are good. They take a little bit of time, but they are good.
How was the initial setup?
It was very complex. We had many issues in integrating it with our enterprise solutions, such as Splunk, and third-party tools.
What about the implementation team?
We have seven or eight engineers for its maintenance.
What other advice do I have?
I would recommend this solution to others if they don't have many third-party tools. It is a very good solution.
I would rate Microsoft Defender for Endpoint a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Solution Architect at KIAN company
Simple to use, flexible, easy to update, but the central management console needs improvement
Pros and Cons
- "This product is flexible, and it is very easy to get updates from the Microsoft website."
- "It is very simple to use and easy to scan systems."
- "The central management console should be improved because it provides limited options to configure Windows Defender."
What is our primary use case?
This product is our antivirus for Windows 10 machines, Windows Server 2016, and in our Azure environment. In addition to this, we have a project for an oil company that is implemented in Azure, and we had to migrate the majority of their systems to that platform. Once the migration was complete, we configured Windows Defender as its antivirus.
What is most valuable?
It is very simple to use and easy to scan systems.
This product is flexible, and it is very easy to get updates from the Microsoft website.
We are using the firewall features.
What needs improvement?
The central management console should be improved because it provides limited options to configure Windows Defender. It should provide a lot of options and features, in the same way, that Symantec does, or the Kaspersky Central Management Console does. Essentially, we should have a central management console on Azure that can be used to manage Windows Defender on all of our machines.
What do I think about the stability of the solution?
This is a very stable solution and we plan to continue using it.
What do I think about the scalability of the solution?
The company that I implemented this for has approximately 2,000 staff and 1,000 virtual machines on Azure.
How are customer service and technical support?
I have not been in contact with Microsoft support. Rather, I have learned by using the materials that are provided online.
Which solution did I use previously and why did I switch?
We were originally using a product from Symantec before we switched to using Windows Defender. After that, we adopted the Microsoft solution for Azure.
How was the initial setup?
I have configured Windows Defender for different locations by using Group Policy Settings and each time, it took between five and ten minutes, based on the guidelines.
What about the implementation team?
I configured it personally by downloading and reading materials that I found on the Microsoft website.
What's my experience with pricing, setup cost, and licensing?
This is an expensive product and licensing for all Microsoft products is a big issue. However, Volume Licensing and Educational Licensing are good options to decrease the cost.
What other advice do I have?
In general, Windows Defender is a good feature for the Windows Operating System.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Solutions Architect at SC PROSERVICECORP SRL
A simple solution with good integration, price, stability, scalability, and support
Pros and Cons
- "Its simplicity is the most valuable. It also has very good integration. We like it."
- "It is very stable, highly recommended, free with the purchase of Windows Server, and it is doing its job for Microsoft Windows Server as a good product."
- "Its interface can be improved a little bit. We would like to have some sort of centralization. It should have something like a central server that is managing all the other clients. There are solutions from Kaspersky or ESET NOD32 that are really doing this kind of thing currently. We would like to see something similar from Microsoft."
- "Its interface can be improved a little bit. We would like to have some sort of centralization."
What is our primary use case?
We are using Microsoft Windows Defender for Windows services because it is the default antivirus and protection solution with Windows Server 2016 and 2019. We are using it for Windows servers, file servers, and active directory.
What is most valuable?
Its simplicity is the most valuable. It also has very good integration. We like it.
What needs improvement?
Its interface can be improved a little bit. We would like to have some sort of centralization. It should have something like a central server that is managing all the other clients. There are solutions from Kaspersky or ESET NOD32 that are really doing this kind of thing currently. We would like to see something similar from Microsoft.
For how long have I used the solution?
We have been using this solution for more than two years.
What do I think about the stability of the solution?
It is very stable. It is highly recommended.
What do I think about the scalability of the solution?
It has good scalability. We are happy with it and plan to increase its usage. We currently have around 20 users.
How are customer service and technical support?
Technical support is good. We like Microsoft, and they provide good technical support.
How was the initial setup?
It is straightforward.
What about the implementation team?
We implemented it by ourselves.
What's my experience with pricing, setup cost, and licensing?
Currently, for us, Windows Defender is free with the purchase of Windows Server. Pricing is an important point for us when we are looking at the competitors of this solution. If we choose to go with another vendor, we will have to pay some license fees.
What other advice do I have?
We are considering moving to another solution, so we are trying to inform ourselves about the other products in the market that will fit our budget and needs. We are trying to see what the competitors offer in the server market. We are looking into ESET NOD32 because we know the product from back in the day.
I would recommend this solution. It is free, and it is doing its job for Microsoft Windows Server. It is a good product. I would rate Microsoft Defender for Endpoint a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Product Manager at a comms service provider with 501-1,000 employees
Good management over endpoints but the technical support needs to be improved
Pros and Cons
- "From a management point of view, this product gives better control over endpoint devices because some processes can be stopped remotely."
- "The scanning is slow when it is working with incoming emails."
- "I don't recommend it to anybody as a standalone solution."
What is our primary use case?
We are a system integrator and I specialize in practically everything that is security-related. This is a product that we sell as part of Office 365, and rarely as a standalone solution.
Usually, if we have a customer with Office 365 and they need this type of solution then we increase the subscription to a point where it is included.
From the user's point of view, this is classic anti-virus software. From a management point of view, this product gives better control over endpoint devices because some processes can be stopped remotely. If you have a person that is watching over the system then they have a higher level of control over endpoints.
What is most valuable?
This is a cloud-based product so it is always updated by the end-user.
What needs improvement?
They have to improve the email scanning where email is coming from somewhere other than our private network. The scanning is slow when it is working with incoming emails. Often, I can see the email but the scanning process is not finished and I cannot open the attachment. In general, the scanning has to be faster.
What do I think about the stability of the solution?
This solution looks stable. Provided that Windows 10 is updated, everything is okay.
How are customer service and technical support?
I have not been in contact with technical support in regards to this product. However, technical support for Microsoft products is always of bad quality. In my experience, if you cannot find the solution yourself then you will have a huge problem because it is not an easy task to have them understand and support you.
You can lose a lot of time explaining the problem before you receive something that works.
My advice to is look for a good support library and try to find the solution yourself. This means that you don't need to contact support.
Which solution did I use previously and why did I switch?
We have worked with many different security solutions. For example, we are selling a Security Operations Center as a service. We implement EDR, Privileged Access Management, Identity Management, anti-fraud solutions, web application firewalls, database security, and more. We are working with practically everything in cybersecurity.
We are working with between 10 and 15 different vendors. Sometimes, this is too many, but it is useful to have information about each product, its quality, and how it compares to others. Two products that we are working with now are Cisco AMP and Carbon Black.
What's my experience with pricing, setup cost, and licensing?
There is a free version of Windows Defender, although the paid version has EDR functionality. We sell this product as part of Office 365 and it is not expensive.
What other advice do I have?
I have never touched this product. I'm just selling it, and I don't recommend it to anybody as a standalone solution.
I would rate this solution a five out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Assistant Manager IT Infrastructure at a manufacturing company with 501-1,000 employees
Stable threat protection with good support but it's expensive and has license restrictions
Pros and Cons
- "It shows us the risky sign-ins, and if a user's password has been compromised."
- "Technical support is good."
- "I am not sure if I will be using this product in the future because of the price."
What is our primary use case?
We are using this solution for threat detection.
What is most valuable?
It shows us the risky sign-ins, and if a user's password has been compromised.
What needs improvement?
While have been using this solution for two years, I am not completely knowledgable.
Due to license restrictions, we cannot use all of the features that are offered.
I am not sure if I will be using this product in the future because of the price.
I would like to see better pricing for this solution in the future.
For how long have I used the solution?
I have been working with Microsoft Defender ATP for two years.
We are always using the latest version because it's on the cloud.
What do I think about the stability of the solution?
With what we have seen, it's a stable solution.
What do I think about the scalability of the solution?
We are not using it widely because of the licensing limits.
We have three users only for Defender ATP, and if we are using the Microsoft ATA it applies to 500 users.
How are customer service and technical support?
Technical support is good.
Which solution did I use previously and why did I switch?
We did not use another solution previous to Microsoft Defender ATP.
How was the initial setup?
The initial setup is straightforward. It's included with the Windows 10 Operating System.
There is no time taken for deployment as it is included with the operating system.
What about the implementation team?
We completed the installation ourselves.
We have 15 administrators to deploy and maintain this solution.
What's my experience with pricing, setup cost, and licensing?
Microsoft Defender ATP is expensive.
What other advice do I have?
Because of my lack of knowledge or experience with the solutions full capacity, I cannot recommend this solution or offer any advice.
I would rate this solution a five out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Deliver Practice Director at DynTek
Easy to manage, updated frequently, and comes included with Windows
Pros and Cons
- "The patch management is very easy, as it can be done automatically or added to a schedule."
- "The advanced threat protection has a large cloud presence in Azure that we can take advantage of, and they update their product frequently."
- "I would like to see better integration with their other security products to give better visibility from a higher level."
What is our primary use case?
We are a consulting company and we use this product for endpoint protection across the company, as well as for our clients.
How has it helped my organization?
Windows Defender makes it easy to streamline the updates so we don't really worry about managing it.
What is most valuable?
The patch management is very easy, as it can be done automatically or added to a schedule. This will update all of the virus signatures.
We have a hook from our on-premises application to the cloud services for advanced threat protection, so the management is in the cloud. Centralized management allows us to schedule malware scans.
When you hook it up to the cloud's advanced threat protection, it gives you more than protection from ransomware. It covers different types of malware and allows you to see what malicious software is being executed on the machine.
The product allows you to manage your machine through it, similarly to the way SCCM does.
What needs improvement?
I would like to see better integration with their other security products to give better visibility from a higher level. Integrating with email, Azure, identity management, and other security applications, putting them all together, would be very good.
The first level of technical support is not very useful and it sometimes takes time to escalate to somebody more knowledgeable.
For how long have I used the solution?
We have been using Microsoft Windows Defender for years.
What do I think about the stability of the solution?
This product is pretty stable.
What do I think about the scalability of the solution?
We have had no issues with scalability. We deploy it anywhere from a small environment with a hundred users, to a large environment with 15,000 to 20,000 endpoints. The majority of our clients are small to medium-sized, with 3,000 to 4,000 users in the mid-range.
How are customer service and technical support?
I would rate Microsoft's technical support an eight out of ten. At the first level, the support is very limited. You have to escalate it to the more senior team to get good value.
Which solution did I use previously and why did I switch?
Some of our clients have used different products from vendors such as Symantec and McAfee, and they were not happy with them. We steered them towards Windows Defender and they switched because of the ATP hook to the cloud.
With other products, you have a management console, so you have to push the signature updates. We still do that now, but it's all in the cloud.
Both Symantec and McAfee come at an additional charge because they are not included in the operating system.
How was the initial setup?
The initial setup is very straightforward.
What's my experience with pricing, setup cost, and licensing?
We are using the version that is included with Windows 10. If you don't purchase the advanced threat protection then there is no additional charge.
What other advice do I have?
My advice for anybody who is implementing Windows Defender is to purchase the ATP, which is in addition to the version that comes with Windows 10. This will allow you to really get the benefits and manage your organization's endpoints as a whole. This requires a presence in the Microsoft environment, such as a subscription to Office 365 or Azure.
I think that people should explore Windows Defender before looking at third-party products. While they are not a pioneer in anti-malware and anti-virus software, they are attacking it and they have a good budget. The advanced threat protection has a large cloud presence in Azure that we can take advantage of, and they update their product frequently. As soon as there is a new threat, they act on it right away.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
Endpoint Protection Platform (EPP) Advanced Threat Protection (ATP) Anti-Malware Tools Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
Cortex XDR by Palo Alto Networks
CrowdStrike Falcon
Microsoft Intune
Microsoft Entra ID
SentinelOne Singularity Endpoint
Microsoft Defender for Cloud
IBM Security QRadar
Microsoft Sentinel
Elastic Security
Microsoft Defender for Office 365
Huntress Managed EDR
TrendAI Vision One
Trellix Endpoint Security Platform
WatchGuard Firebox
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Compare Microsoft Windows Defender and Symantec Endpoint Protection. How Do I Choose?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- What do you think of the integration of Azure AD Services, Defender for Endpoint, and Intune as comprehensive security solutions?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- Running Carbon Black Defense Along with Windows Defender
- How is Cortex XDR compared with Microsoft Defender?
- Which offers better endpoint security - Symantec or Microsoft Defender?
- How does Microsoft Defender for Endpoint compare with Carbon Black CB Defense?
- How would you compare between Microsoft Defender for Endpoint and Tanium EDR?















