Try our new research platform with insights from 80,000+ expert users
John Edwards - PeerSpot reviewer
Manager Cyber Security at Dept. of the Premier and Cabinet
Real User
Good endpoint detection response, and technical support, but the pricing could be improved
Pros and Cons
  • "Microsoft Defender for Endpoint is a robust platform."
  • "In the next release, I would like to see better management reporting."

What is our primary use case?

We are a government organization, and we use Microsoft Defender for Endpoint Protection.

We also use it for vulnerability scanning and assessment, which is very useful.

What is most valuable?

Microsoft Defender for Endpoint is a robust platform. The endpoint detection response is quite good.

What needs improvement?

Some executive reporting is inefficient, and we're looking into ways to improve it.

In the next release, I would like to see better management reporting.

For how long have I used the solution?

I have been working with Microsoft Defender for Endpoint for two years.

Buyer's Guide
Microsoft Defender for Endpoint
October 2025
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
871,469 professionals have used our research since 2012.

What do I think about the stability of the solution?

Microsoft Defender for Endpoint is a stable solution.

What do I think about the scalability of the solution?

Microsoft Defender for Endpoint is definitely scalable.

How are customer service and support?

Technical support is quite good.

Which solution did I use previously and why did I switch?

Previously, we didn't work with anything as sophisticated. We used a pretty old-style endpoint detection response.

How was the initial setup?

On new devices, the initial setup is quite easy, while some of the older devices had some issues unpicking the old EDR product that had nothing to do with Defender.

What's my experience with pricing, setup cost, and licensing?

Pricing can always be lower.

What other advice do I have?

To achieve the best results holistically, consider the total cost of ownership of the Microsoft suite of products.

I would rate Microsoft Defender for Endpoint a seven out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Works at a financial services firm with 51-200 employees
Real User
Simple to install and maintain, but the support could be faster, and more responsive
Pros and Cons
  • "The installation is straightforward."
  • "Phishing and Malware detection could be better."

What is our primary use case?

Microsoft Defender for Endpoint gives us a second layer of security as well as the third layer of security. One of them is interested in web security and email security. One of them, similar to Cisco, is a Cisco FirePOWER. These are a compilation or a group of devices for security.

What needs improvement?

We had some issues where phishing and malware were not detected and were allowed to pass unless I mentioned it or we forced the phishing or malware to be blocked, I can't rely on that alone.

Phishing and Malware detection could be better.

Technical support needs improvement.

For how long have I used the solution?

I have been working with Microsoft Defender for Endpoint for one year.

What do I think about the stability of the solution?

It is stable for the time being. 

What do I think about the scalability of the solution?

I can't add more layers of security because of my budget and business plan, so I try to choose the best and most preferable option for me and my company.

I would rate the scalability a seven out of ten.

In one company, we have two administrators and 30 employees who use this solution.

On a short-term plan, I will not increase the usage. On a larger scale, we intend to increase the license.

How are customer service and support?

In my opinion, technical support is not as effective as it was before. They take a long time to support and investigate the issue.

It takes a long time for them to support and investigate the issue. I believe they must crush the time in order to provide us with our needs, and our objectives.

Which solution did I use previously and why did I switch?

There are applications and solutions that we have used for five or more years. We almost used Microsoft Link but have since switched to Microsoft Teams and Skype for business. We almost exclusively use Cisco products such as Cisco EMC, Cisco Web security, and Cisco Meraki.

How was the initial setup?

The installation is straightforward. It's a cloud solution that requires some configuration running on the cloud.

The deployment takes a couple of hours to complete.

It's a different story when it comes to security. It takes a different approach. It requires two an administrator and a manager to maintain this solution.

What about the implementation team?

Sometimes the installation and deployment are done by the technical team, and sometimes it's done by others.

What's my experience with pricing, setup cost, and licensing?

Licensing fees are paid annually through a partner.

What other advice do I have?

If I do recommend it, it will not be solely for security purposes. It is possibly for a first-line security platform, and it is required to build a second, third, and possibly fourth business security layer.

I would rate Microsoft Defender for Endpoint a seven out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Microsoft Defender for Endpoint
October 2025
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
871,469 professionals have used our research since 2012.
reviewer1731429 - PeerSpot reviewer
Senior Consultant at a marketing services firm with 11-50 employees
Real User
Low impact on endpoints with an easy setup and fast technical support
Pros and Cons
  • "The intelligence mechanisms are good."
  • "The detection of viruses could be a little bit better."

What is our primary use case?

The product is useful for projects, finding tech, and finding firewall actions on computers. 

What is most valuable?

There's no impact on other applications. Most other solutions have more of a possibility of an impact on other applications and due to that, you must make some special configurations to those other applications. The Microsoft Defender impact is very small.

The intelligence mechanisms are good.

The initial setup is easy.

We have found the technical support to be helpful.

What needs improvement?

The detection of viruses could be a little bit better.

For how long have I used the solution?

We've used the solution for maybe two years.

What do I think about the scalability of the solution?

Our company is only a small company. We only have 10 people who use the solution. However, we have clients who have a lot of users. 

We likely will increase usage in the future. 

How are customer service and support?

We've been in touch with technical support. Their level of support is fine and they are very fast. We are satisfied with their level of service. 

We had some problem and, after four hours, we had new signatures for the environment by our customers for more than a thousand clients so that we can protect and improve the new setup. It was a very quick turnaround.

How was the initial setup?

The initial setup is not difficult. It's simple. We have just rolled it out to 6,000 clients which have been, by far, more than other customers we've had so far. We have deployed a Microsoft configuration.

In the environment, we needed one or two days to deploy it. In smaller environments, you only need two hours of work.

It can be done by technical personnel in-house. If they have good knowledge of Microsoft environments, and how to use Microsoft tools, then it's easy.

It's always good if you know how to use OutShare. With OutShare, you can make many things extremely effective and extremely easy.

What about the implementation team?

It is possible to handle it in-house if you have a knowledgeable team. We implement the solution for our clients. 

What's my experience with pricing, setup cost, and licensing?

Clients need to pay a yearly licensing fee.

What other advice do I have?

This is an on-premise solution where all connections have a cloud connection.

I would recommend the solution to other companies. I'd rate the solution at a nine out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Sales Director at CLoud3 Solutions Pte Ltd
Real User
Secure, no maintenance required, and stable
Pros and Cons
  • "Microsoft Defender for Endpoint has been secure and there is zero maintenance required because it updates with Microsoft Windows."
  • "The solution can be more user-friendly."

What is our primary use case?

Microsoft Defender for Endpoint is integrated into Microsoft Windows and is used for system protection.

What is most valuable?

Microsoft Defender for Endpoint has been secure and there is zero maintenance required because it updates with Microsoft Windows.

What needs improvement?

The solution can be more user-friendly.

For how long have I used the solution?

I have been using Microsoft Defender for Endpoint for a few years.

What do I think about the stability of the solution?

Microsoft Defender for Endpoint is stable.

What do I think about the scalability of the solution?

The solution is scalable.

We have 30 users using the solution in my organization.

How was the initial setup?

The solution has no installation as it comes with Microsoft Windows.

What's my experience with pricing, setup cost, and licensing?

I do not have to purchase antivirus solutions anymore because Microsoft Defender for Endpoint is integrated into Windows and comes free.

What other advice do I have?

I would recommend this solution to others.

I rate Microsoft Defender for Endpoint a ten out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
MIS Specialist at a agriculture with 201-500 employees
Real User
Stable, scalable, and provides good protection
Pros and Cons
  • "Defender is stable. The performance is good."
  • "Defender is free for one year. Once that year is over, we will switch to Kaspersky."

What is most valuable?

Defender's endpoint protection is good.

For how long have I used the solution?

I've been using Defender for less than one year. Defender is free for one year. Once that year is over, we will switch to Kaspersky.

What do I think about the stability of the solution?

Defender is stable. The performance is good.

What do I think about the scalability of the solution?

In terms of scalability, I rate Defender 10 out of 10. 

How are customer service and support?

I haven't dealt with Microsoft support for this product.

How was the initial setup?

It's easy. Defender came pre-loaded on our computers.

What other advice do I have?

I rate Microsoft Defender for Endpoint eight out 10. I would recommend it to others.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Subject Matter Expert at Vision Software
Real User
Provides malware and ransomware protection and scales easily
Pros and Cons
  • "The most important and the most relevant features of Defender for Endpoint are the malware and ransomware protection."
  • "I would like to see the next generation of the tool improved to work with other operating systems, like Linux."

What is our primary use case?

It's used to protect endpoints and, for some customers, it is used to deploy Microsoft 365 suite features. Most of our clients are medium-sized businesses.

What is most valuable?

The most important and the most relevant features of Defender for Endpoint are the malware and ransomware protection.

What needs improvement?

I would like to see the next generation of the tool improved to work with other operating systems, like Linux.

For how long have I used the solution?

I have had about a year's worth of experience with Microsoft Defender for Endpoint. I am a subject matter expert for a Microsoft partner in Colombia. We develop portfolios and solutions for our customers that need Microsoft products in their infrastructure. My role deals with the architecture of solutions.

What do I think about the stability of the solution?

I don't recall any issues with the solution.

What do I think about the scalability of the solution?

It scales easily.

How are customer service and support?

I haven't had to use technical support for the solution.

How was the initial setup?

The setup depends on the customer, but it is generally simple.

What's my experience with pricing, setup cost, and licensing?

Some customers have the licensing of the suite and have all infrastructure prepared for the installation and deployment. But in some cases, when customers haven't deployed the solution and don't have licenses, it can be expensive to start from scratch.

What other advice do I have?

Customers haven't given us any feedback about difficulties with the solution. With its intelligence and tools over cloud infrastructure, it's a good product. We are developing some use cases and projects for customers with Microsoft Defender for Endpoint. It is good for us.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
K.O - PeerSpot reviewer
Application Manager at Financial Services
Real User
Good alert chaining and tool compatibility for endpoints with helpful heuristic capabilities
Pros and Cons
  • "We are able to productively integrate with existing on-prem, hybrid, or cloud applications."
  • "Features like device inventory continue to lack essential workstation drill-downs showing the entire device information with the least effort."

What is our primary use case?

We primarily used the solution as Endpoint Detection and protection (EDR, EPP) with secondary benefits of threats and vulnerability management, security incident response, automated query and real-time device monitoring, and with the capability of email security, identity management (DFI), and task automation (Power automate). We used respective licenses where required.

The solution was also used for an endpoint antivirus for workstations in a multi-OS environment, including Windows and Mac OS. We had file, device, and user trajectory monitoring for the security operations team.

How has it helped my organization?

The solution benefited the company via:

  • OS-level/Tool compatibility for endpoints running Windows (since both are Microsoft products and Defender core files are included in Win10 or later delivery).
  • Heuristic capability. Consistent usage of MDE indicates that the tools are continuously learning new prevention techniques by pulling real-time up-to-date cloud resources.
  • Alert chaining. The solution makes security Incidents, events, and alerts less tedious from a Security Operation Center standpoint. This can result in false negatives or detriment for small to medium-scale firms running no or semi-automated threat response features.

What is most valuable?

The most valuable aspects of the solution include:

  • Advanced hunting. The product offers flexibility, visibility, and automation capability using a user-friendly query language (KQL).
  • Reporting. Clear and concisely plotted graphics show real-time data representation - which is valuable to upper management.
  • Scalability/API. We are able to productively integrate with existing on-prem, hybrid, or cloud applications. 
  • Great OOB features. The solution comes with SIEM-ingestion-ready features for extensive visibility, automation, and integration, including advanced hunting, threats and vulnerability management, embedded simulation for end-to-end testing, ransomware prevention (Controlled Folder Access), and Attack Surface Reduction (ASR) rules.

What needs improvement?

Improvements could be made via:

  • Clicks. There's a poor user experience with lots of optimizable opportunities of user interface particularly on the newly improved portal (https://security.microsoft.com/). Features like device inventory continue to lack essential workstation drill-downs showing the entire device information with the least effort.
  • De-centralized console features. Discrepancies with enabling core features at the click of a button within the MDE portal is mostly due to prerequisites that are tied to the functionality or partial enforcement requirements from other Microsoft tools (Group policy, Azure, Sentinel, SCCM, Intune). EDR in block mode requires Intune security baselines and tamper protection requires MAPS enabled. Web content filtering also has security baseline dependencies
  • No single pane of glass. There are too many loose ends with tiny bits and pieces to enforce essential security policies compared to other EDR solutions within the same caliber. A typical example is having to create exclusions in different locations for entirely different functionalities, such as: automation folder exclusion, group policy exclusions (per tenant), Controlled Folder Access (ASR) Allowed application, and Attack Surface Reduction (ASR).
  • Service Requests. Noncritical cases with MDE technical support teams tend to be queued for over a week before the first customer engagement. Most of these tickets also end up in the hands of temporary or contracted non-Microsoft employees who are scripted and offer little attention to unique incidents.

Suggested additional features that should be included in the next release include:

  • Digestible interface/filter for crown-jewel capabilities like ASR, CFA and Exploit mitigation occurrences.
  • Restoration of an always visible search bar from the previous console view (https://securitycenter.windows.com).
  • A definitive action plan for Secure Score recommendations and deduplicate of controls.

For how long have I used the solution?

We were using Microsoft Defender for Endpoint prior to its change of name from Defender ATP. We experienced a plethora of GA changes including, but not limited to, IOS/multiple OS support, device discovery, web content filtering, API updates, and continuous integrations with existing security tools.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1674681 - PeerSpot reviewer
Cyber Security BA/BSA at a financial services firm with 10,001+ employees
Real User
Straightforward to set up with good technical support and good stability
Pros and Cons
  • "Technical support is good."
  • "There are likely some technical improvements or features that could be added, however, I cannot say, off the top of my head, what they would be."

What is our primary use case?

Usually, the solution is used in relation to keys management. We implemented a program for it, for the lifecycle of the keys. We've also used it for certificate management.

What is most valuable?

The initial setup is very straightforward.

The stability is very good.

Technical support is good.

The solution is in good condition and offers good functionality.

What needs improvement?

There are likely some technical improvements or features that could be added, however, I cannot say, off the top of my head, what they would be.

For how long have I used the solution?

I used the solution in relation to scoping a project. I was doing business analysis.

What do I think about the stability of the solution?

The solution was very stable.

What do I think about the scalability of the solution?

The solution is scalable.

How are customer service and support?

The technical support for Microsoft is very good.

How was the initial setup?

The initial setup is not difficult or complex. It's very simple and straightforward. 

What's my experience with pricing, setup cost, and licensing?

I do not know how much it costs per month. I cannot say how it compares against the rates of the competition.

What other advice do I have?

We are a Microsoft Customer.

I'm not sure if I would recommend the solution to others. It depends on their requirements. It needs to fit a company's use cases.

I would rate the solution at an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros sharing their opinions.
Updated: October 2025
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros sharing their opinions.