Try our new research platform with insights from 80,000+ expert users
reviewer1596288 - PeerSpot reviewer
Specialist Consultant in Microsoft Security at a tech services company with 501-1,000 employees
Consultant
Jun 14, 2021
The tamper protection keeps hackers from entering a machine, encrypting it, and changing passwords
Pros and Cons
  • "Auto-remediation: When the product sees malware, it resolves the issue immediately. This protects the machine."
  • "Auto-remediation: When the product sees malware, it resolves the issue immediately."
  • "It needs to improve the cybersecurity for lateral movements. For example, when a hacker tries to enter a machine, they try to get the password by doing a lateral movement."
  • "It is so expensive. It isn't cheaper than McAfee or other solutions."

What is our primary use case?

We use it for antivirus. You can use it for malware and Zero Trust. Some people use it for fact-checking too. I can also use it with Intune, which is good. 

We deploy Microsoft Defender on all kinds of devices, including Microsoft, iOS, and Mac.

What is most valuable?

Auto-remediation: When the product sees malware, it resolves the issue immediately. This protects the machine.

I like the tamper protection. For example, if I buy a notebook with Windows 10 and put Microsoft Defender on it, then I can activate the tamper protection. This keeps people from entering the machine, encrypting it, and changing passwords.

Microsoft Defender is fully integrated with Azure Sentinel. In addition, GPO can be connected with Microsoft Defender and Azure AD.

What needs improvement?

It needs to improve the cybersecurity for lateral movements. For example, when a hacker tries to enter a machine, they try to get the password by doing a lateral movement. 

With Windows 10, version 18.0.3, I couldn't see the documentation to open the ports. If you don't open the ports, then the machine can't communicate with the console.

What do I think about the stability of the solution?

I like its stability a lot.

Buyer's Guide
Microsoft Defender for Endpoint
March 2026
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.

What do I think about the scalability of the solution?

You push out all the devices that you want. There is no limitation beyond money and licenses.

Which solution did I use previously and why did I switch?

In the past, I have used McAfee and Kaspersky. 

I only work with Microsoft products right now. It integrates well with other products. I also work with Microsoft Defender for Identity.

How was the initial setup?

The deployment process is not difficult because Microsoft Defender comes with Windows 10. You just right click, then it connects you with Azure. 

There are other processes that can be connected, e.g., Microsoft Download Center.

What about the implementation team?

I implement Microsoft Defender for Endpoint. It takes me one or two days to design Microsoft Defender for Endpoint. It is easy to do this, and the more you implement, the easier it gets over time.

Sometimes, when I change the configuration, I have to wait six to eight hours.

What's my experience with pricing, setup cost, and licensing?

It is so expensive. It isn't cheaper than McAfee or other solutions.

Which other solutions did I evaluate?

I prefer Microsoft Defender for Endpoint instead of McAfee, Kaspersky, and other products.

What other advice do I have?

I would rate this solution as 10 out of 10.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
IT Manager at a financial services firm with 1,001-5,000 employees
Real User
Jun 10, 2021
Quick and responsive support, stable, improves security, and requires little maintenance
Pros and Cons
  • "Microsoft's technical support is fantastic."
  • "This is a stable solution that has matured over the years."
  • "At times, the other antivirus products are now doing AI, in terms of understanding the behavior of the system and determining when there's an anomaly. This is something that Defender can improve on."
  • "At times, the other antivirus products are now doing AI, in terms of understanding the behavior of the system and determining when there's an anomaly. This is something that Defender can improve on."

What is our primary use case?

We primarily use this product to get antivirus protection in a cost-effective way.

How has it helped my organization?

This product tends to detect a lot more issues than the other antivirus solutions. This is because it's essentially tuned to Microsoft. It has some inbuilt intelligence, so they tend to understand the Microsoft environment and we don't need to do as much exclusion. With other antivirus products, we need to exclude certain files from being scanned.

What is most valuable?

The malware detection feature is very good.

What needs improvement?

At times, the other antivirus products are now doing AI, in terms of understanding the behavior of the system and determining when there's an anomaly. This is something that Defender can improve on.

For how long have I used the solution?

I have been working with Microsoft Defender Antivirus for between two and three years.

What do I think about the stability of the solution?

This is a stable solution that has matured over the years.

What do I think about the scalability of the solution?

We have approximately 7,000 machines and we have not needed to scale beyond our original implementation.

How are customer service and technical support?

Microsoft's technical support is fantastic.

We subscribe to the Microsoft Premier Support Package and they tend to respond to our queries very fast. When our engineers contact them, they respond in a very short time.

Which solution did I use previously and why did I switch?

We currently use Cylance, in addition to Microsoft Defender. I'm not sure what the impact is of using two solutions, whether it is a good thing, or not. We do plan on narrowing this down to one solution in the future.

How was the initial setup?

This product was included with Windows 10, so we did not have to deploy it separately.

Once this product is set up, this solution requires very little maintenance.

What's my experience with pricing, setup cost, and licensing?

We already use Microsoft solutions and I found it cheaper to purchase the bundle, which includes Defender. By including the antivirus in the bundle, it makes it a little cheaper for us. If you purchase it outside of the bundle, it is a little bit expensive.

When you want the central administration functionality, it tends to be more expensive. The normal, standalone model is not expensive, but the enterprise model that includes the bundle with email and some web protection, is a bit more expensive.

What other advice do I have?

When we initially implemented Windows Defender, we were pessimistic about whether it would be good enough. However, it is a pretty mature product now.

My advice for anybody who is considering this product is that it's good, and it gets results early.

I would rate this solution an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Microsoft Defender for Endpoint
March 2026
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
it_user1216809 - PeerSpot reviewer
Information Security Engineer at a financial services firm with 1,001-5,000 employees
Real User
Jun 9, 2021
Has good stability but they update the platform too frequently
Pros and Cons
  • "It's pretty easy to scale."
  • "We used CrowdStrike but we switched to Microsoft because of the price."
  • "In terms of improvement, they update the platform it seems quite a bit. Every month something is in a new spot or something changed somewhere. There should be less of that."
  • "In terms of improvement, they update the platform it seems quite a bit. Every month something is in a new spot or something changed somewhere; there should be less of that."

What is our primary use case?

We use the most up-to-date version. 

Our primary use case is for basic EDRs for simple interfaces.

What needs improvement?

In terms of improvement, they update the platform it seems quite a bit. Every month something is in a new spot or something changed somewhere. There should be less of that.

For how long have I used the solution?

I have been using Microsoft Defender for Endpoint for a couple of months. 

What do I think about the stability of the solution?

It seems stable.

What do I think about the scalability of the solution?

It's pretty easy to scale.

A handful of people with each in charge of different areas are involved in the maintenance of the solution. It's people in system admin.

How are customer service and technical support?

I have dealt with tech support a couple of times. They're usually pretty responsive. The first person might not know what the deal is, but they usually are able to get us to the right person, get a resolution for us, and answer our questions pretty quickly.

Which solution did I use previously and why did I switch?

We used CrowdStrike but we switched to Microsoft because of the price. It's cheaper. There were other major differences. 

How was the initial setup?

The initial setup was pretty complex in the way the various tools integrate. Trying to figure out permissions and getting access to certain things is complex. 

Global admin uses the tool, but then you have to get additional roles for the data loss stuff.

What other advice do I have?

Make sure you read the documentation and understand what else is required before you get started.

I would rate it a seven out of ten. 

I don't think that another tool is doing anything better, or this one doesn't. It's just about using it and seeing where to find the stuff.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Juan Jose Anaya - PeerSpot reviewer
Technical Manager at SAPEC
Real User
May 24, 2021
Light on resources, easy installation, and reliable
Pros and Cons
  • "One of the main features is the solution is very light on resources and we do not have any problems with it."
  • "One of the main features is the solution is very light on resources and we do not have any problems with it."
  • "There is room to improve the security of the solution."
  • "There is room to improve the security of the solution."

What is our primary use case?

We use this solution for business security protection.

What is most valuable?

One of the main features is the solution is very light on resources and we do not have any problems with it.

What needs improvement?

There is room to improve the security of the solution.

We have plans to add an email security solution because this solution does not provide us with what we want.

For how long have I used the solution?

I have been using this solution for approximately three years.

What do I think about the stability of the solution?

The solution is stable.

What do I think about the scalability of the solution?

I have found the scalability of the solution good.

Which solution did I use previously and why did I switch?

We were previously using the Avast security solution.

How was the initial setup?

The installation is very easy, it takes only one day.

What about the implementation team?

We did the implementation ourselves. We have approximately 10 engineers able to do the deployments and maintenance. 

What's my experience with pricing, setup cost, and licensing?

There is not a license required for this particular solution.

What other advice do I have?

I would recommend this solution to others.

I rate Microsoft Defender Antivirus an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Fabrizio Fioravanti - PeerSpot reviewer
Engineer at a educational organization with 5,001-10,000 employees
Real User
Apr 18, 2021
Pre-installed, free, and easy to use, but the free version doesn't provide centralized management, EDR, and behavioral analysis
Pros and Cons
  • "It is easy to use because it is already pre-installed in Windows 10. We don't have to do anything to configure it. You can also configure the firewall by using a group policy so that it can be easily adopted in an environment."
  • "It is easy to use because it is already pre-installed in Windows 10."
  • "Microsoft Defender in the basic form is not very useful for managing the security environment. The free version is not capable of covering the needs of centralized management, EDR, and behavioral analysis. If you don't have the commercial version, you can't have centralized management and set up the policies and other things. Each client is a standalone installation, which is not useful for security in an enterprise model."
  • "Microsoft Defender in the basic form is not very useful for managing the security environment."

What is our primary use case?

We were using the basic endpoint from Sophos without Intercept X and the EDR model, and currently, we are in the selection process of a new platform that has EDR embedded. We are using Microsoft Defender Antivirus for the time being till we get the new platform.

What is most valuable?

It is easy to use because it is already pre-installed in Windows 10. We don't have to do anything to configure it. You can also configure the firewall by using a group policy so that it can be easily adopted in an environment.

What needs improvement?

Microsoft Defender in the basic form is not very useful for managing the security environment. The free version is not capable of covering the needs of centralized management, EDR, and behavioral analysis. If you don't have the commercial version, you can't have centralized management and set up the policies and other things. Each client is a standalone installation, which is not useful for security in an enterprise model.

For how long have I used the solution?

I have been using this solution for six months.

What do I think about the scalability of the solution?

Currently, we have about 2,000 users.

How are customer service and technical support?

I didn't use support for this solution.

How was the initial setup?

It was already pre-installed in Windows 10.

What's my experience with pricing, setup cost, and licensing?

It is free. It is included in Windows 10.

Which other solutions did I evaluate?

We are using Microsoft Defender only for the time being. We will switch to another endpoint platform that can offer us more advanced features, centralized management, and EDR. We have not chosen the solution at the moment, but we might go for Bitdefender. It is one of the products that we have evaluated, and it can be suitable for our environment. It has some use cases that are really in the same line as our requirements.

What other advice do I have?

I would recommend this solution only for small home environments. It is not for enterprise environments unless you buy the commercial version.

I would rate Microsoft Defender Antivirus a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Carlo Du Plessis - PeerSpot reviewer
Security Specialist at Engen
Real User
Apr 10, 2021
Integrates well, continually updates, and reliable
Pros and Cons
  • "One of the valuable features of the solution is the small updates that keep my machine relatively clean from any infections."
  • "One of the valuable features of the solution is the small updates that keep my machine relatively clean from any infections."
  • "I would like the solution to be able to prevent unauthorized programs from installing and to block unauthorised URLs which is similar to web filtering product."
  • "I would like the solution to be able to prevent unauthorized programs from installing and to block unauthorised URLs which is similar to web filtering product."

What is our primary use case?

The primary use of this solution is for the detection of malware and to stop phishing. 

What is most valuable?

One of the valuable features of the solution is the small updates that keep my machine relatively clean from any infections. Additionally, it has good integration with other Microsoft products.  

What needs improvement?

I would like the solution to be able to prevent unauthorized programs from installing and to block unauthorised URLs which is similar to web filtering product. 

For how long have I used the solution?

I have used the solution for approximately two years. 

What do I think about the stability of the solution?

I find the solution to be stable. 

What do I think about the scalability of the solution?

I find the solution to be quite easily extended into other environments. It is scalable, I have it on three devices. 

Which solution did I use previously and why did I switch?

I have previously used the McAfee Stinger product. 

How was the initial setup?

The installation of the solution is easy. I completed it myself and it took approximately 20 minutes. 

What's my experience with pricing, setup cost, and licensing?

The solution comes as a part of Windows 10 and it is covered under its license. 

What other advice do I have?

I will continue to use and would recommend the solution to others. 

I rate Microsoft Defender Antivirus an eight out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1435104 - PeerSpot reviewer
Managing Director at a financial services firm with 10,001+ employees
Real User
Mar 29, 2021
Reliable, well-priced, and it is easy to install
Pros and Cons
  • "We use Microsoft Defender for the antivirus."
  • "It's a stable solution."
  • "The interface could be improved."
  • "The interface could be improved."

What is our primary use case?

There are endpoints that are not in our organization's network but are connected directly to the web. We use Microsoft Defender for the antivirus.

We are not dealing with this solution daily, just when there is an issue from time to time.

What needs improvement?

The interface could be improved.

For how long have I used the solution?

I have been using Microsoft Defender for Endpoint for a couple of years.

What do I think about the stability of the solution?

It's a stable solution.

What do I think about the scalability of the solution?

We are only running it on a few workstations. The scalability is okay.

It's run on 10 out of 3,000 workstations and we plan to continue using it.

We have no more than 10 users in our organization.

Which solution did I use previously and why did I switch?

We are also using Symantec. 

We have a few endpoints where we use Microsoft Defender because we cannot use the Symantec Sets.

How was the initial setup?

The initial setup was straightforward. It was easy to install and t only took a couple of minutes.

There is no team for maintenance. If there is an issue, the security team helps to resolve it.

What about the implementation team?

We completed the deployment and implementation ourselves.

What's my experience with pricing, setup cost, and licensing?

We don't have an issue with the price. 

We have a bundle where the price includes all Microsoft products.

This is an area that I am not dealing with. I don't have all of the information.

What other advice do I have?

It's pretty good.

I would rate this solution a nine out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Cyber Security Specialist at a healthcare company with 10,001+ employees
Real User
Mar 16, 2021
Good support and valuable EDR feature, but not stable and not suitable for enterprises with lots of other processes and third-party tools
Pros and Cons
  • "The EDR feature is most valuable."
  • "I would recommend this solution to others if they don't have many third-party tools."
  • "It is currently more suitable for end-users rather than enterprises with lots of other processes and third-party tools. It needs improvement on that front. We had many issues while integrating it with our enterprise solutions, such as Splunk, and third-party tools. It provides everything via APIs. Other vendors provide integration with third-party tools, but Microsoft doesn't do that. It is also logging too much and is not serialized from the process aspect. It has all the data, but it is not in a proper format or not properly indexed, which doesn't make it easier for enterprises to use this data. Other vendors provide troubleshooting information that can be used to troubleshoot issues, but Microsoft doesn't provide anything like that."
  • "It is also logging too much and is not serialized from the process aspect. It has all the data, but it is not in a proper format or not properly indexed, which doesn't make it easier for enterprises to use this data."

What is our primary use case?

We use it for our endpoint detection and response capability.

What is most valuable?

The EDR feature is most valuable.

What needs improvement?

It is currently more suitable for end-users rather than enterprises with lots of other processes and third-party tools. It needs improvement on that front. We had many issues while integrating it with our enterprise solutions, such as Splunk, and third-party tools. It provides everything via APIs. Other vendors provide integration with third-party tools, but Microsoft doesn't do that.

It is also logging too much and is not serialized from the process aspect. It has all the data, but it is not in a proper format or not properly indexed, which doesn't make it easier for enterprises to use this data.

Other vendors provide troubleshooting information that can be used to troubleshoot issues, but Microsoft doesn't provide anything like that.

For how long have I used the solution?

I have been using this solution for six months.

What do I think about the stability of the solution?

It is still a new product, and there are many reported bugs in terms of stability and impact on the endpoints.

What do I think about the scalability of the solution?

We have around 80,000 users.

How are customer service and technical support?

They are good. They take a little bit of time, but they are good.

How was the initial setup?

It was very complex. We had many issues in integrating it with our enterprise solutions, such as Splunk, and third-party tools.

What about the implementation team?

We have seven or eight engineers for its maintenance.

What other advice do I have?

I would recommend this solution to others if they don't have many third-party tools. It is a very good solution.

I would rate Microsoft Defender for Endpoint a seven out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros sharing their opinions.
Updated: March 2026
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros sharing their opinions.