Try our new research platform with insights from 80,000+ expert users
Nadeem Abdulla - PeerSpot reviewer
Assistant Manager IT Infrastructure at a manufacturing company with 501-1,000 employees
Real User
Top 20
Stable threat protection with good support but it's expensive and has license restrictions
Pros and Cons
  • "It shows us the risky sign-ins, and if a user's password has been compromised."
  • "I am not sure if I will be using this product in the future because of the price."

What is our primary use case?

We are using this solution for threat detection.

What is most valuable?

It shows us the risky sign-ins, and if a user's password has been compromised.

What needs improvement?

While have been using this solution for two years, I am not completely knowledgable. 

Due to license restrictions, we cannot use all of the features that are offered.

I am not sure if I will be using this product in the future because of the price.

I would like to see better pricing for this solution in the future.

For how long have I used the solution?

I have been working with Microsoft Defender ATP for two years.

We are always using the latest version because it's on the cloud.

Buyer's Guide
Microsoft Defender for Endpoint
October 2025
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
871,408 professionals have used our research since 2012.

What do I think about the stability of the solution?

With what we have seen, it's a stable solution.

What do I think about the scalability of the solution?

We are not using it widely because of the licensing limits.

We have three users only for Defender ATP, and if we are using the Microsoft ATA it applies to 500 users.

How are customer service and support?

Technical support is good.

Which solution did I use previously and why did I switch?

We did not use another solution previous to Microsoft Defender ATP.

How was the initial setup?

The initial setup is straightforward. It's included with the Windows 10 Operating System.

There is no time taken for deployment as it is included with the operating system.

What about the implementation team?

We completed the installation ourselves.

We have 15 administrators to deploy and maintain this solution.

What's my experience with pricing, setup cost, and licensing?

Microsoft Defender ATP is expensive.

What other advice do I have?

Because of my lack of knowledge or experience with the solutions full capacity, I cannot recommend this solution or offer any advice.

I would rate this solution a five out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Cloud Consultant at Brio Technologies Private Limited
Real User
Good with vulnerability assessment and integrates well with Office 365 and Azure
Pros and Cons
  • "Provides good vulnerability assessment."
  • "The GUI is very complex and could be more user friendly."

What is our primary use case?

This is an endpoint security product. It helps detect and prevent attacks and is very good when it comes to vulnerability assessment. It automatically detects attacks. It provides support for all the end devices, whether it is a Mac OS, Windows, mobiles, Android and iOS, it has support for all. I mostly deal with smaller and medium sized companies, I don't deal much with enterprises. I'm a customer of Microsoft and I work as a solution architect.

What is most valuable?

The product is very good when it comes to vulnerability assessment. It's a Microsoft flagship product and it integrates with Office 365. If my customers are using Office 365 or Azure or a Windows server, it helps to use Defender. Other products like Symantec or McAfee don't have that kind of integration with Microsoft products. In terms of identifying the attacks, it's far superior to Symantec. 

What needs improvement?

The GUI is very complex, particularly for normal users who work on it. It could be more user friendly. For future improvements, I'd be looking at internet security which we don't have as Microsoft does not distinguish whether a site is malicious or not. Kaspersky is very good at that but not Microsoft. It would be a big advantage for them if they were to include it. 

For how long have I used the solution?

I've been using this solution for seven months. 

What do I think about the stability of the solution?

It's a stable product. Microsoft only recently entered this market and nobody believed that Microsoft antivirus would be good. They are now trying to prove everyone wrong in that sense by having a good security product. 

What do I think about the scalability of the solution?

Scaling in or out is very easy. Scalability is really about licensing so you just have to request a registration license.

How are customer service and technical support?

Ninety-nine percent of the time, I'm able to solve the problem. I do not have access to Microsoft support so if I go to their open support page and try to login a request, it takes up to 24 hours for the support agent to get back to me. It's pretty average. If you have the premium support or if you're a support partner of Microsoft, they respond back in one or two hours, something like that.

Which solution did I use previously and why did I switch?

I tested the difference between Symantec and Defender by taking a malware from the internet and downloading it. Symantec allowed me to do it, even though it shouldn't have, but Defender, gave me notification and wouldn't allow me to do it. That said, Symantec is a very stable product that's been on the market for a long time. They have more expertise in endpoint protection than Microsoft. Symantec is not a cost-effective product for most customers. It's integrated with third party companies and is good in protecting endpoint. Because my customer base is companies that use Office 365 and Microsoft Azure so Microsoft integration with these products is very good.

How was the initial setup?

The initial setup is very simple, you just have to attach it to the user's email address. Once the user logs in, it automatically downloads and starts working. I do the implementation.  In terms of maintenance, sometimes my engagement with the client is one time but sometimes, I do maintenance as well. This is a subscription-based, cloud-based product. They have to call me every year to renew. 

What other advice do I have?

I would suggest that if you're already using Microsoft products, then I think it makes sense to go with Microsoft Defender over any other product.

I would rate this solution an eight out of 10. 

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Microsoft Defender for Endpoint
October 2025
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
871,408 professionals have used our research since 2012.
reviewer2237718 - PeerSpot reviewer
Technical Account Manager at a comms service provider with 201-500 employees
Real User
Helps prioritize threats, and protects against ransomware, but threat detection could use some improvement
Pros and Cons
  • "The ransomware and malware protection is the most valuable feature."
  • "Microsoft Defender for Endpoint is effective for validating work, but not ideal for investigations."

What is our primary use case?

I use Microsoft Defender for Endpoint to protect my computer when downloading files. Whether it's documents from my email or web browser, this is the first thing I use the solution for. It also provides protection against ransomware. Additionally, the monthly report indicates the number of infected files that were blocked during that month.

How has it helped my organization?

Microsoft Defender for Endpoint provides excellent visibility into known threats, thanks to their comprehensive database of malware information. 

Microsoft Defender for Endpoint helps us prioritize threats across our enterprise according to our needs. We focus on protecting against malware first, followed by email protection, and URLs.

Microsoft Defender for Endpoint has helped protect our organization against malware.

What is most valuable?

The ransomware and malware protection is the most valuable feature.

What needs improvement?

When there is a significant amount of malware, I believe that Microsoft Defender for Endpoint may not be as effective as other firewall solutions. I tested Microsoft Defender for Endpoint and found that it allowed me to download files infected with malware from certain sites, and its protection did not work as expected in that aspect of my work. I suspect this is because I use a GRAPH file with a password, and the solution only detects a file when it's related to clean files or open files. It doesn't seem to recognize encrypted log files that require a password for access.

Microsoft Defender for Endpoint does not assist in automating routine tasks or identifying high-value alerts. Therefore, we had to turn to other solutions like Cortex XDR by Palo Alto Networks. Additionally, Microsoft Defender for Endpoint lacks the capability to upload a list of IPs for blocking.

Microsoft Defender for Endpoint is effective for validating work, but not ideal for investigations. As a result, our experts have to dedicate more time when investigating threats using Microsoft Defender for Endpoint compared to other solutions.

The zero-day detection, as well as the sandboxing for unknown malware and URL detection, needs to be improved. These settings were not functional when we tested the solution.

For how long have I used the solution?

I have been using Microsoft Defender for Endpoint for one year.

What do I think about the stability of the solution?

I give the stability an eight out of ten.

What do I think about the scalability of the solution?

I give the scalability a ten out of ten.

How was the initial setup?

The deployment is straightforward.

What's my experience with pricing, setup cost, and licensing?

Microsoft Defender for Endpoint is more affordable compared to some other endpoint solutions.

Which other solutions did I evaluate?

We evaluated Cortex XDR by Palo Alto Networks and Fortinet. We found that Microsoft Defender for Endpoint was easier to deploy and offered a better price.

What other advice do I have?

I would rate Microsoft Defender for Endpoint a seven out of ten. The solution is stable, easy to deploy, and scalable. However, threat detection could use some improvement.

Our organization is a cybersecurity company, and after using Microsoft Defender for Endpoint for one year, we found that it lacked features such as endpoint detection and response. Additionally, it was weak in certain areas, like detecting a set of malware and providing email protection. As a result, we started exploring other solutions, even though they may be more costly.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Patrick Scolyer-Gray - PeerSpot reviewer
Founder & CEO at Pathbreaker Pty Ltd
Real User
Free, integrated with Windows, and no installation needed
Pros and Cons
  • "Microsoft Defender for Endpoint comes pre-installed in Microsoft Windows."
  • "Microsoft Defender for Endpoint should have more transparency. In the latest edition of Windows, Windows 11, it is a compulsory requirement to connect to a Microsoft account, which in turn has implications for Defender. This should be removed."

What is our primary use case?

Microsoft Defender for Endpoint is a basic endpoint protection solution. If you do not combine it with another solution then you will leave yourself open to vulnerabilities. I used Microsoft Defender for Endpoint in conjunction with other solutions, such as Cylance.

What needs improvement?

Microsoft Defender for Endpoint should have more transparency. In the latest edition of Windows, Windows 11, it is a compulsory requirement to connect to a Microsoft account, which in turn has implications for Defender. This should be removed.

For how long have I used the solution?

I have been using Microsoft Defender for Endpoint for a few years.

How are customer service and support?

I have not called Microsoft technical support.

How was the initial setup?

Microsoft Defender for Endpoint comes pre-installed in Microsoft Windows.

What's my experience with pricing, setup cost, and licensing?

The solution comes as part of Microsoft Windows. 

What other advice do I have?

I wouldn't call Microsoft Defender for Endpoint a solution, I'd call it part of a solution. I don't think I would be going around recommending it.

I rate Microsoft Defender for Endpoint an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1600098 - PeerSpot reviewer
Chief Technology Officer at a financial services firm with 1-10 employees
Real User
Easy to use, good support, but more visibility is needed
Pros and Cons
  • "The most valuable features of Microsoft Defender for Endpoint are the ease of use and it was available within the operating system."
  • "The biggest issue I had with Microsoft Defender for Endpoint was the antivirus and ransomware. I wanted central visibility over all the machines that we operate."

What is our primary use case?

We use Microsoft Defender for Endpoint for threat protection.

What is most valuable?

The most valuable features of Microsoft Defender for Endpoint are the ease of use and it was available within the operating system.

What needs improvement?

The biggest issue I had with Microsoft Defender for Endpoint was the antivirus and ransomware. I wanted central visibility over all the machines that we operate.

For how long have I used the solution?

I have used Microsoft Defender for Endpoint within the past 12 months.

What do I think about the scalability of the solution?

We have approximately 10 to 15 people using the solution in my organization.

How are customer service and support?

The technical support from Microsoft is good.

How was the initial setup?

The initial installation could have been easier.

What's my experience with pricing, setup cost, and licensing?

There is an annual license required.

What other advice do I have?

I rate Microsoft Defender for Endpoint a seven out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Systems Administrator at The Port Authority of Jamaica
Real User
It's a cost-effective solution for Microsoft shops
Pros and Cons
  • "We are a Microsoft shop, and Defender is a Microsoft solution that provides some security at a reasonable cost."
  • "I want Microsoft Defender to have the ability to deal with some issues automatically, so I don't need to address that issue manually."

What is our primary use case?

We use Defendor for endpoint monitoring. It alerts us when a machine has issues, and we take the necessary steps to resolve them.

What is most valuable?

We are a Microsoft shop, and Defender is a Microsoft solution that provides some security at a reasonable cost.

What needs improvement?

I want Microsoft Defender to have the ability to deal with some issues automatically, so I don't need to address that issue manually.

For how long have I used the solution?

We started testing our endpoints and preparing to deploy Microsoft Defender about two months ago. 

What do I think about the scalability of the solution?

I would say yes, it is.

How are customer service and support?

Microsoft support is excellent.

How was the initial setup?

Deploying Microsoft Defender took some time because we had to push it through. You can install Symantec using the GUI, but we have to use the GPO to push the agent. It would be nice if Defender streamlined that.

Defender isn't 100 percent deployed yet, but it's working for some employees. When a machine comes on board, Defender will deploy an agent on that device when the script runs. A person logs on, the agent installs, and the device is onboarded.

What other advice do I have?

I rate Microsoft Defender for Endpoint eight out of 10. It's a cost-effective solution for Microsoft shops.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
IT RM at KNV
Real User
It runs in the background
Pros and Cons
  • "Defender works in the background monitoring the traffic for viruses."
  • "Defender could be more secure and stable."

What is our primary use case?

Defender is an antivirus solution deployed on all Microsoft PCs. Thousands of employees at my company use it. 

What is most valuable?

Defender works in the background monitoring the traffic for viruses.  

What needs improvement?

Defender could be more secure and stable.

For how long have I used the solution?

We've been using Microsoft Defender for a couple of years.

How was the initial setup?

Setting up Defender is straightforward. My administrator takes care of all that. 

What other advice do I have?

I rate Microsoft Defender eight out of 10. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
JamesYa - PeerSpot reviewer
Senior Solutions Architect at Cloud4C Services
Real User
Stable, embedded in Microsoft Windows, and high performance
Pros and Cons
  • "The performance of Microsoft Defender for Endpoint has been good."
  • "Microsoft Defender for Endpoint could improve by providing more user-friendly dashboards. They may be complicated for some."

What is our primary use case?

Microsoft Defender for Endpoint is used for securing endpoints from threats.

What is most valuable?

The performance of Microsoft Defender for Endpoint has been good.

What needs improvement?

Microsoft Defender for Endpoint could improve by providing more user-friendly dashboards. They may be complicated for some.

In a future release, they should add a feature for patch management.

For how long have I used the solution?

I have been using Microsoft Defender for Endpoint for one year.

What do I think about the stability of the solution?

Microsoft Defender for Endpoint has been stable.

What do I think about the scalability of the solution?

The scalability of Microsoft Defender for Endpoint has been good.

We have approximately five clients using the solution. We have thousands of licensees for this solution within my company.

How are customer service and support?

The technical from Microsoft could be better. It is not as good as other solutions.

How was the initial setup?

The implementation of Microsoft Defender for Endpoint because it is pre-installed with Microsoft Windows. Other solutions you have to install separately, such as Check Point.

What's my experience with pricing, setup cost, and licensing?

The license for Microsoft Defender for Endpoint is included in the license for the Microsoft Windows operating system.

What other advice do I have?

I would recommend this solution to others.

I rate Microsoft Defender for Endpoint a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros sharing their opinions.
Updated: October 2025
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros sharing their opinions.