This product is our antivirus for Windows 10 machines, Windows Server 2016, and in our Azure environment. In addition to this, we have a project for an oil company that is implemented in Azure, and we had to migrate the majority of their systems to that platform. Once the migration was complete, we configured Windows Defender as its antivirus.
Solution Architect at KIAN company
Simple to use, flexible, easy to update, but the central management console needs improvement
Pros and Cons
- "This product is flexible, and it is very easy to get updates from the Microsoft website."
- "It is very simple to use and easy to scan systems."
- "The central management console should be improved because it provides limited options to configure Windows Defender."
- "The central management console should be improved because it provides limited options to configure Windows Defender."
What is our primary use case?
What is most valuable?
It is very simple to use and easy to scan systems.
This product is flexible, and it is very easy to get updates from the Microsoft website.
We are using the firewall features.
What needs improvement?
The central management console should be improved because it provides limited options to configure Windows Defender. It should provide a lot of options and features, in the same way, that Symantec does, or the Kaspersky Central Management Console does. Essentially, we should have a central management console on Azure that can be used to manage Windows Defender on all of our machines.
What do I think about the stability of the solution?
This is a very stable solution and we plan to continue using it.
Buyer's Guide
Microsoft Defender for Endpoint
March 2026
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
What do I think about the scalability of the solution?
The company that I implemented this for has approximately 2,000 staff and 1,000 virtual machines on Azure.
How are customer service and support?
I have not been in contact with Microsoft support. Rather, I have learned by using the materials that are provided online.
Which solution did I use previously and why did I switch?
We were originally using a product from Symantec before we switched to using Windows Defender. After that, we adopted the Microsoft solution for Azure.
How was the initial setup?
I have configured Windows Defender for different locations by using Group Policy Settings and each time, it took between five and ten minutes, based on the guidelines.
What about the implementation team?
I configured it personally by downloading and reading materials that I found on the Microsoft website.
What's my experience with pricing, setup cost, and licensing?
This is an expensive product and licensing for all Microsoft products is a big issue. However, Volume Licensing and Educational Licensing are good options to decrease the cost.
What other advice do I have?
In general, Windows Defender is a good feature for the Windows Operating System.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Solutions Architect at SC PROSERVICECORP SRL
A simple solution with good integration, price, stability, scalability, and support
Pros and Cons
- "Its simplicity is the most valuable. It also has very good integration. We like it."
- "It is very stable, highly recommended, free with the purchase of Windows Server, and it is doing its job for Microsoft Windows Server as a good product."
- "Its interface can be improved a little bit. We would like to have some sort of centralization. It should have something like a central server that is managing all the other clients. There are solutions from Kaspersky or ESET NOD32 that are really doing this kind of thing currently. We would like to see something similar from Microsoft."
- "Its interface can be improved a little bit. We would like to have some sort of centralization."
What is our primary use case?
We are using Microsoft Windows Defender for Windows services because it is the default antivirus and protection solution with Windows Server 2016 and 2019. We are using it for Windows servers, file servers, and active directory.
What is most valuable?
Its simplicity is the most valuable. It also has very good integration. We like it.
What needs improvement?
Its interface can be improved a little bit. We would like to have some sort of centralization. It should have something like a central server that is managing all the other clients. There are solutions from Kaspersky or ESET NOD32 that are really doing this kind of thing currently. We would like to see something similar from Microsoft.
For how long have I used the solution?
We have been using this solution for more than two years.
What do I think about the stability of the solution?
It is very stable. It is highly recommended.
What do I think about the scalability of the solution?
It has good scalability. We are happy with it and plan to increase its usage. We currently have around 20 users.
How are customer service and technical support?
Technical support is good. We like Microsoft, and they provide good technical support.
How was the initial setup?
It is straightforward.
What about the implementation team?
We implemented it by ourselves.
What's my experience with pricing, setup cost, and licensing?
Currently, for us, Windows Defender is free with the purchase of Windows Server. Pricing is an important point for us when we are looking at the competitors of this solution. If we choose to go with another vendor, we will have to pay some license fees.
What other advice do I have?
We are considering moving to another solution, so we are trying to inform ourselves about the other products in the market that will fit our budget and needs. We are trying to see what the competitors offer in the server market. We are looking into ESET NOD32 because we know the product from back in the day.
I would recommend this solution. It is free, and it is doing its job for Microsoft Windows Server. It is a good product. I would rate Microsoft Defender for Endpoint a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Microsoft Defender for Endpoint
March 2026
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
885,264 professionals have used our research since 2012.
Product Manager at a comms service provider with 501-1,000 employees
Good management over endpoints but the technical support needs to be improved
Pros and Cons
- "From a management point of view, this product gives better control over endpoint devices because some processes can be stopped remotely."
- "The scanning is slow when it is working with incoming emails."
- "I don't recommend it to anybody as a standalone solution."
What is our primary use case?
We are a system integrator and I specialize in practically everything that is security-related. This is a product that we sell as part of Office 365, and rarely as a standalone solution.
Usually, if we have a customer with Office 365 and they need this type of solution then we increase the subscription to a point where it is included.
From the user's point of view, this is classic anti-virus software. From a management point of view, this product gives better control over endpoint devices because some processes can be stopped remotely. If you have a person that is watching over the system then they have a higher level of control over endpoints.
What is most valuable?
This is a cloud-based product so it is always updated by the end-user.
What needs improvement?
They have to improve the email scanning where email is coming from somewhere other than our private network. The scanning is slow when it is working with incoming emails. Often, I can see the email but the scanning process is not finished and I cannot open the attachment. In general, the scanning has to be faster.
What do I think about the stability of the solution?
This solution looks stable. Provided that Windows 10 is updated, everything is okay.
How are customer service and technical support?
I have not been in contact with technical support in regards to this product. However, technical support for Microsoft products is always of bad quality. In my experience, if you cannot find the solution yourself then you will have a huge problem because it is not an easy task to have them understand and support you.
You can lose a lot of time explaining the problem before you receive something that works.
My advice to is look for a good support library and try to find the solution yourself. This means that you don't need to contact support.
Which solution did I use previously and why did I switch?
We have worked with many different security solutions. For example, we are selling a Security Operations Center as a service. We implement EDR, Privileged Access Management, Identity Management, anti-fraud solutions, web application firewalls, database security, and more. We are working with practically everything in cybersecurity.
We are working with between 10 and 15 different vendors. Sometimes, this is too many, but it is useful to have information about each product, its quality, and how it compares to others. Two products that we are working with now are Cisco AMP and Carbon Black.
What's my experience with pricing, setup cost, and licensing?
There is a free version of Windows Defender, although the paid version has EDR functionality. We sell this product as part of Office 365 and it is not expensive.
What other advice do I have?
I have never touched this product. I'm just selling it, and I don't recommend it to anybody as a standalone solution.
I would rate this solution a five out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Assistant Manager IT Infrastructure at a manufacturing company with 501-1,000 employees
Stable threat protection with good support but it's expensive and has license restrictions
Pros and Cons
- "It shows us the risky sign-ins, and if a user's password has been compromised."
- "Technical support is good."
- "I am not sure if I will be using this product in the future because of the price."
- "I am not sure if I will be using this product in the future because of the price."
What is our primary use case?
We are using this solution for threat detection.
What is most valuable?
It shows us the risky sign-ins, and if a user's password has been compromised.
What needs improvement?
While have been using this solution for two years, I am not completely knowledgable.
Due to license restrictions, we cannot use all of the features that are offered.
I am not sure if I will be using this product in the future because of the price.
I would like to see better pricing for this solution in the future.
For how long have I used the solution?
I have been working with Microsoft Defender ATP for two years.
We are always using the latest version because it's on the cloud.
What do I think about the stability of the solution?
With what we have seen, it's a stable solution.
What do I think about the scalability of the solution?
We are not using it widely because of the licensing limits.
We have three users only for Defender ATP, and if we are using the Microsoft ATA it applies to 500 users.
How are customer service and technical support?
Technical support is good.
Which solution did I use previously and why did I switch?
We did not use another solution previous to Microsoft Defender ATP.
How was the initial setup?
The initial setup is straightforward. It's included with the Windows 10 Operating System.
There is no time taken for deployment as it is included with the operating system.
What about the implementation team?
We completed the installation ourselves.
We have 15 administrators to deploy and maintain this solution.
What's my experience with pricing, setup cost, and licensing?
Microsoft Defender ATP is expensive.
What other advice do I have?
Because of my lack of knowledge or experience with the solutions full capacity, I cannot recommend this solution or offer any advice.
I would rate this solution a five out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cloud Consultant at Brio Technologies Private Limited
Good with vulnerability assessment and integrates well with Office 365 and Azure
Pros and Cons
- "Provides good vulnerability assessment."
- "The product is very good when it comes to vulnerability assessment and, as a Microsoft flagship product, it integrates with Office 365, Azure, and Windows Server, offering far superior attack identification compared to Symantec."
- "The GUI is very complex and could be more user friendly."
- "The GUI is very complex, particularly for normal users who work on it."
What is our primary use case?
This is an endpoint security product. It helps detect and prevent attacks and is very good when it comes to vulnerability assessment. It automatically detects attacks. It provides support for all the end devices, whether it is a Mac OS, Windows, mobiles, Android and iOS, it has support for all. I mostly deal with smaller and medium sized companies, I don't deal much with enterprises. I'm a customer of Microsoft and I work as a solution architect.
What is most valuable?
The product is very good when it comes to vulnerability assessment. It's a Microsoft flagship product and it integrates with Office 365. If my customers are using Office 365 or Azure or a Windows server, it helps to use Defender. Other products like Symantec or McAfee don't have that kind of integration with Microsoft products. In terms of identifying the attacks, it's far superior to Symantec.
What needs improvement?
The GUI is very complex, particularly for normal users who work on it. It could be more user friendly. For future improvements, I'd be looking at internet security which we don't have as Microsoft does not distinguish whether a site is malicious or not. Kaspersky is very good at that but not Microsoft. It would be a big advantage for them if they were to include it.
For how long have I used the solution?
I've been using this solution for seven months.
What do I think about the stability of the solution?
It's a stable product. Microsoft only recently entered this market and nobody believed that Microsoft antivirus would be good. They are now trying to prove everyone wrong in that sense by having a good security product.
What do I think about the scalability of the solution?
Scaling in or out is very easy. Scalability is really about licensing so you just have to request a registration license.
How are customer service and technical support?
Ninety-nine percent of the time, I'm able to solve the problem. I do not have access to Microsoft support so if I go to their open support page and try to login a request, it takes up to 24 hours for the support agent to get back to me. It's pretty average. If you have the premium support or if you're a support partner of Microsoft, they respond back in one or two hours, something like that.
Which solution did I use previously and why did I switch?
I tested the difference between Symantec and Defender by taking a malware from the internet and downloading it. Symantec allowed me to do it, even though it shouldn't have, but Defender, gave me notification and wouldn't allow me to do it. That said, Symantec is a very stable product that's been on the market for a long time. They have more expertise in endpoint protection than Microsoft. Symantec is not a cost-effective product for most customers. It's integrated with third party companies and is good in protecting endpoint. Because my customer base is companies that use Office 365 and Microsoft Azure so Microsoft integration with these products is very good.
How was the initial setup?
The initial setup is very simple, you just have to attach it to the user's email address. Once the user logs in, it automatically downloads and starts working. I do the implementation. In terms of maintenance, sometimes my engagement with the client is one time but sometimes, I do maintenance as well. This is a subscription-based, cloud-based product. They have to call me every year to renew.
What other advice do I have?
I would suggest that if you're already using Microsoft products, then I think it makes sense to go with Microsoft Defender over any other product.
I would rate this solution an eight out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Deliver Practice Director at DynTek
Easy to manage, updated frequently, and comes included with Windows
Pros and Cons
- "The patch management is very easy, as it can be done automatically or added to a schedule."
- "The advanced threat protection has a large cloud presence in Azure that we can take advantage of, and they update their product frequently."
- "I would like to see better integration with their other security products to give better visibility from a higher level."
- "I would like to see better integration with their other security products to give better visibility from a higher level."
What is our primary use case?
We are a consulting company and we use this product for endpoint protection across the company, as well as for our clients.
How has it helped my organization?
Windows Defender makes it easy to streamline the updates so we don't really worry about managing it.
What is most valuable?
The patch management is very easy, as it can be done automatically or added to a schedule. This will update all of the virus signatures.
We have a hook from our on-premises application to the cloud services for advanced threat protection, so the management is in the cloud. Centralized management allows us to schedule malware scans.
When you hook it up to the cloud's advanced threat protection, it gives you more than protection from ransomware. It covers different types of malware and allows you to see what malicious software is being executed on the machine.
The product allows you to manage your machine through it, similarly to the way SCCM does.
What needs improvement?
I would like to see better integration with their other security products to give better visibility from a higher level. Integrating with email, Azure, identity management, and other security applications, putting them all together, would be very good.
The first level of technical support is not very useful and it sometimes takes time to escalate to somebody more knowledgeable.
For how long have I used the solution?
We have been using Microsoft Windows Defender for years.
What do I think about the stability of the solution?
This product is pretty stable.
What do I think about the scalability of the solution?
We have had no issues with scalability. We deploy it anywhere from a small environment with a hundred users, to a large environment with 15,000 to 20,000 endpoints. The majority of our clients are small to medium-sized, with 3,000 to 4,000 users in the mid-range.
How are customer service and technical support?
I would rate Microsoft's technical support an eight out of ten. At the first level, the support is very limited. You have to escalate it to the more senior team to get good value.
Which solution did I use previously and why did I switch?
Some of our clients have used different products from vendors such as Symantec and McAfee, and they were not happy with them. We steered them towards Windows Defender and they switched because of the ATP hook to the cloud.
With other products, you have a management console, so you have to push the signature updates. We still do that now, but it's all in the cloud.
Both Symantec and McAfee come at an additional charge because they are not included in the operating system.
How was the initial setup?
The initial setup is very straightforward.
What's my experience with pricing, setup cost, and licensing?
We are using the version that is included with Windows 10. If you don't purchase the advanced threat protection then there is no additional charge.
What other advice do I have?
My advice for anybody who is implementing Windows Defender is to purchase the ATP, which is in addition to the version that comes with Windows 10. This will allow you to really get the benefits and manage your organization's endpoints as a whole. This requires a presence in the Microsoft environment, such as a subscription to Office 365 or Azure.
I think that people should explore Windows Defender before looking at third-party products. While they are not a pioneer in anti-malware and anti-virus software, they are attacking it and they have a good budget. The advanced threat protection has a large cloud presence in Azure that we can take advantage of, and they update their product frequently. As soon as there is a new threat, they act on it right away.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Account Manager at a comms service provider with 201-500 employees
Helps prioritize threats, and protects against ransomware, but threat detection could use some improvement
Pros and Cons
- "The ransomware and malware protection is the most valuable feature."
- "Microsoft Defender for Endpoint is effective for validating work, but not ideal for investigations."
What is our primary use case?
I use Microsoft Defender for Endpoint to protect my computer when downloading files. Whether it's documents from my email or web browser, this is the first thing I use the solution for. It also provides protection against ransomware. Additionally, the monthly report indicates the number of infected files that were blocked during that month.
How has it helped my organization?
Microsoft Defender for Endpoint provides excellent visibility into known threats, thanks to their comprehensive database of malware information.
Microsoft Defender for Endpoint helps us prioritize threats across our enterprise according to our needs. We focus on protecting against malware first, followed by email protection, and URLs.
Microsoft Defender for Endpoint has helped protect our organization against malware.
What is most valuable?
The ransomware and malware protection is the most valuable feature.
What needs improvement?
When there is a significant amount of malware, I believe that Microsoft Defender for Endpoint may not be as effective as other firewall solutions. I tested Microsoft Defender for Endpoint and found that it allowed me to download files infected with malware from certain sites, and its protection did not work as expected in that aspect of my work. I suspect this is because I use a GRAPH file with a password, and the solution only detects a file when it's related to clean files or open files. It doesn't seem to recognize encrypted log files that require a password for access.
Microsoft Defender for Endpoint does not assist in automating routine tasks or identifying high-value alerts. Therefore, we had to turn to other solutions like Cortex XDR by Palo Alto Networks. Additionally, Microsoft Defender for Endpoint lacks the capability to upload a list of IPs for blocking.
Microsoft Defender for Endpoint is effective for validating work, but not ideal for investigations. As a result, our experts have to dedicate more time when investigating threats using Microsoft Defender for Endpoint compared to other solutions.
The zero-day detection, as well as the sandboxing for unknown malware and URL detection, needs to be improved. These settings were not functional when we tested the solution.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for one year.
What do I think about the stability of the solution?
I give the stability an eight out of ten.
What do I think about the scalability of the solution?
I give the scalability a ten out of ten.
How was the initial setup?
The deployment is straightforward.
What's my experience with pricing, setup cost, and licensing?
Microsoft Defender for Endpoint is more affordable compared to some other endpoint solutions.
Which other solutions did I evaluate?
We evaluated Cortex XDR by Palo Alto Networks and Fortinet. We found that Microsoft Defender for Endpoint was easier to deploy and offered a better price.
What other advice do I have?
I would rate Microsoft Defender for Endpoint a seven out of ten. The solution is stable, easy to deploy, and scalable. However, threat detection could use some improvement.
Our organization is a cybersecurity company, and after using Microsoft Defender for Endpoint for one year, we found that it lacked features such as endpoint detection and response. Additionally, it was weak in certain areas, like detecting a set of malware and providing email protection. As a result, we started exploring other solutions, even though they may be more costly.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Founder & CEO at Pathbreaker Pty Ltd
Free, integrated with Windows, and no installation needed
Pros and Cons
- "Microsoft Defender for Endpoint comes pre-installed in Microsoft Windows."
- "Microsoft Defender for Endpoint comes pre-installed in Microsoft Windows."
- "Microsoft Defender for Endpoint should have more transparency. In the latest edition of Windows, Windows 11, it is a compulsory requirement to connect to a Microsoft account, which in turn has implications for Defender. This should be removed."
- "Microsoft Defender for Endpoint is a basic endpoint protection solution. If you do not combine it with another solution then you will leave yourself open to vulnerabilities."
What is our primary use case?
Microsoft Defender for Endpoint is a basic endpoint protection solution. If you do not combine it with another solution then you will leave yourself open to vulnerabilities. I used Microsoft Defender for Endpoint in conjunction with other solutions, such as Cylance.
What needs improvement?
Microsoft Defender for Endpoint should have more transparency. In the latest edition of Windows, Windows 11, it is a compulsory requirement to connect to a Microsoft account, which in turn has implications for Defender. This should be removed.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for a few years.
How are customer service and support?
I have not called Microsoft technical support.
How was the initial setup?
Microsoft Defender for Endpoint comes pre-installed in Microsoft Windows.
What's my experience with pricing, setup cost, and licensing?
The solution comes as part of Microsoft Windows.
What other advice do I have?
I wouldn't call Microsoft Defender for Endpoint a solution, I'd call it part of a solution. I don't think I would be going around recommending it.
I rate Microsoft Defender for Endpoint an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2026
Product Categories
Endpoint Protection Platform (EPP) Advanced Threat Protection (ATP) Anti-Malware Tools Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
CrowdStrike Falcon
Microsoft Intune
Microsoft Entra ID
Microsoft Defender for Cloud
Cortex XDR by Palo Alto Networks
Microsoft Defender for Office 365
SentinelOne Singularity Complete
IBM Security QRadar
Microsoft Sentinel
Fortinet FortiEDR
HP Wolf Security
Huntress Managed EDR
Elastic Security
Microsoft Defender XDR
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Compare Microsoft Windows Defender and Symantec Endpoint Protection. How Do I Choose?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- What do you think of the integration of Azure AD Services, Defender for Endpoint, and Intune as comprehensive security solutions?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- Running Carbon Black Defense Along with Windows Defender
- How is Cortex XDR compared with Microsoft Defender?
- Which offers better endpoint security - Symantec or Microsoft Defender?
- How does Microsoft Defender for Endpoint compare with Carbon Black CB Defense?
- How would you compare between Microsoft Defender for Endpoint and Tanium EDR?














