We are a consulting company and we use this product for endpoint protection across the company, as well as for our clients.
Deliver Practice Director at a computer software company with 201-500 employees
Easy to manage, updated frequently, and comes included with Windows
Pros and Cons
- "The patch management is very easy, as it can be done automatically or added to a schedule."
- "I would like to see better integration with their other security products to give better visibility from a higher level."
What is our primary use case?
How has it helped my organization?
Windows Defender makes it easy to streamline the updates so we don't really worry about managing it.
What is most valuable?
The patch management is very easy, as it can be done automatically or added to a schedule. This will update all of the virus signatures.
We have a hook from our on-premises application to the cloud services for advanced threat protection, so the management is in the cloud. Centralized management allows us to schedule malware scans.
When you hook it up to the cloud's advanced threat protection, it gives you more than protection from ransomware. It covers different types of malware and allows you to see what malicious software is being executed on the machine.
The product allows you to manage your machine through it, similarly to the way SCCM does.
What needs improvement?
I would like to see better integration with their other security products to give better visibility from a higher level. Integrating with email, Azure, identity management, and other security applications, putting them all together, would be very good.
The first level of technical support is not very useful and it sometimes takes time to escalate to somebody more knowledgeable.
Buyer's Guide
Microsoft Defender for Endpoint
December 2025
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.
For how long have I used the solution?
We have been using Microsoft Windows Defender for years.
What do I think about the stability of the solution?
This product is pretty stable.
What do I think about the scalability of the solution?
We have had no issues with scalability. We deploy it anywhere from a small environment with a hundred users, to a large environment with 15,000 to 20,000 endpoints. The majority of our clients are small to medium-sized, with 3,000 to 4,000 users in the mid-range.
How are customer service and support?
I would rate Microsoft's technical support an eight out of ten. At the first level, the support is very limited. You have to escalate it to the more senior team to get good value.
Which solution did I use previously and why did I switch?
Some of our clients have used different products from vendors such as Symantec and McAfee, and they were not happy with them. We steered them towards Windows Defender and they switched because of the ATP hook to the cloud.
With other products, you have a management console, so you have to push the signature updates. We still do that now, but it's all in the cloud.
Both Symantec and McAfee come at an additional charge because they are not included in the operating system.
How was the initial setup?
The initial setup is very straightforward.
What's my experience with pricing, setup cost, and licensing?
We are using the version that is included with Windows 10. If you don't purchase the advanced threat protection then there is no additional charge.
What other advice do I have?
My advice for anybody who is implementing Windows Defender is to purchase the ATP, which is in addition to the version that comes with Windows 10. This will allow you to really get the benefits and manage your organization's endpoints as a whole. This requires a presence in the Microsoft environment, such as a subscription to Office 365 or Azure.
I think that people should explore Windows Defender before looking at third-party products. While they are not a pioneer in anti-malware and anti-virus software, they are attacking it and they have a good budget. The advanced threat protection has a large cloud presence in Azure that we can take advantage of, and they update their product frequently. As soon as there is a new threat, they act on it right away.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Account Manager at a comms service provider with 201-500 employees
Helps prioritize threats, and protects against ransomware, but threat detection could use some improvement
Pros and Cons
- "The ransomware and malware protection is the most valuable feature."
- "Microsoft Defender for Endpoint is effective for validating work, but not ideal for investigations."
What is our primary use case?
I use Microsoft Defender for Endpoint to protect my computer when downloading files. Whether it's documents from my email or web browser, this is the first thing I use the solution for. It also provides protection against ransomware. Additionally, the monthly report indicates the number of infected files that were blocked during that month.
How has it helped my organization?
Microsoft Defender for Endpoint provides excellent visibility into known threats, thanks to their comprehensive database of malware information.
Microsoft Defender for Endpoint helps us prioritize threats across our enterprise according to our needs. We focus on protecting against malware first, followed by email protection, and URLs.
Microsoft Defender for Endpoint has helped protect our organization against malware.
What is most valuable?
The ransomware and malware protection is the most valuable feature.
What needs improvement?
When there is a significant amount of malware, I believe that Microsoft Defender for Endpoint may not be as effective as other firewall solutions. I tested Microsoft Defender for Endpoint and found that it allowed me to download files infected with malware from certain sites, and its protection did not work as expected in that aspect of my work. I suspect this is because I use a GRAPH file with a password, and the solution only detects a file when it's related to clean files or open files. It doesn't seem to recognize encrypted log files that require a password for access.
Microsoft Defender for Endpoint does not assist in automating routine tasks or identifying high-value alerts. Therefore, we had to turn to other solutions like Cortex XDR by Palo Alto Networks. Additionally, Microsoft Defender for Endpoint lacks the capability to upload a list of IPs for blocking.
Microsoft Defender for Endpoint is effective for validating work, but not ideal for investigations. As a result, our experts have to dedicate more time when investigating threats using Microsoft Defender for Endpoint compared to other solutions.
The zero-day detection, as well as the sandboxing for unknown malware and URL detection, needs to be improved. These settings were not functional when we tested the solution.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for one year.
What do I think about the stability of the solution?
I give the stability an eight out of ten.
What do I think about the scalability of the solution?
I give the scalability a ten out of ten.
How was the initial setup?
The deployment is straightforward.
What's my experience with pricing, setup cost, and licensing?
Microsoft Defender for Endpoint is more affordable compared to some other endpoint solutions.
Which other solutions did I evaluate?
We evaluated Cortex XDR by Palo Alto Networks and Fortinet. We found that Microsoft Defender for Endpoint was easier to deploy and offered a better price.
What other advice do I have?
I would rate Microsoft Defender for Endpoint a seven out of ten. The solution is stable, easy to deploy, and scalable. However, threat detection could use some improvement.
Our organization is a cybersecurity company, and after using Microsoft Defender for Endpoint for one year, we found that it lacked features such as endpoint detection and response. Additionally, it was weak in certain areas, like detecting a set of malware and providing email protection. As a result, we started exploring other solutions, even though they may be more costly.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Microsoft Defender for Endpoint
December 2025
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.
Founder & CEO at a tech services company with 1-10 employees
Free, integrated with Windows, and no installation needed
Pros and Cons
- "Microsoft Defender for Endpoint comes pre-installed in Microsoft Windows."
- "Microsoft Defender for Endpoint should have more transparency. In the latest edition of Windows, Windows 11, it is a compulsory requirement to connect to a Microsoft account, which in turn has implications for Defender. This should be removed."
What is our primary use case?
Microsoft Defender for Endpoint is a basic endpoint protection solution. If you do not combine it with another solution then you will leave yourself open to vulnerabilities. I used Microsoft Defender for Endpoint in conjunction with other solutions, such as Cylance.
What needs improvement?
Microsoft Defender for Endpoint should have more transparency. In the latest edition of Windows, Windows 11, it is a compulsory requirement to connect to a Microsoft account, which in turn has implications for Defender. This should be removed.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for a few years.
How are customer service and support?
I have not called Microsoft technical support.
How was the initial setup?
Microsoft Defender for Endpoint comes pre-installed in Microsoft Windows.
What's my experience with pricing, setup cost, and licensing?
The solution comes as part of Microsoft Windows.
What other advice do I have?
I wouldn't call Microsoft Defender for Endpoint a solution, I'd call it part of a solution. I don't think I would be going around recommending it.
I rate Microsoft Defender for Endpoint an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Chief Technology Officer at a financial services firm with 1-10 employees
Easy to use, good support, but more visibility is needed
Pros and Cons
- "The most valuable features of Microsoft Defender for Endpoint are the ease of use and it was available within the operating system."
- "The biggest issue I had with Microsoft Defender for Endpoint was the antivirus and ransomware. I wanted central visibility over all the machines that we operate."
What is our primary use case?
We use Microsoft Defender for Endpoint for threat protection.
What is most valuable?
The most valuable features of Microsoft Defender for Endpoint are the ease of use and it was available within the operating system.
What needs improvement?
The biggest issue I had with Microsoft Defender for Endpoint was the antivirus and ransomware. I wanted central visibility over all the machines that we operate.
For how long have I used the solution?
I have used Microsoft Defender for Endpoint within the past 12 months.
What do I think about the scalability of the solution?
We have approximately 10 to 15 people using the solution in my organization.
How are customer service and support?
The technical support from Microsoft is good.
How was the initial setup?
The initial installation could have been easier.
What's my experience with pricing, setup cost, and licensing?
There is an annual license required.
What other advice do I have?
I rate Microsoft Defender for Endpoint a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Systems Administrator at a government with 51-200 employees
It's a cost-effective solution for Microsoft shops
Pros and Cons
- "We are a Microsoft shop, and Defender is a Microsoft solution that provides some security at a reasonable cost."
- "I want Microsoft Defender to have the ability to deal with some issues automatically, so I don't need to address that issue manually."
What is our primary use case?
We use Defendor for endpoint monitoring. It alerts us when a machine has issues, and we take the necessary steps to resolve them.
What is most valuable?
We are a Microsoft shop, and Defender is a Microsoft solution that provides some security at a reasonable cost.
What needs improvement?
I want Microsoft Defender to have the ability to deal with some issues automatically, so I don't need to address that issue manually.
For how long have I used the solution?
We started testing our endpoints and preparing to deploy Microsoft Defender about two months ago.
What do I think about the scalability of the solution?
I would say yes, it is.
How are customer service and support?
Microsoft support is excellent.
How was the initial setup?
Deploying Microsoft Defender took some time because we had to push it through. You can install Symantec using the GUI, but we have to use the GPO to push the agent. It would be nice if Defender streamlined that.
Defender isn't 100 percent deployed yet, but it's working for some employees. When a machine comes on board, Defender will deploy an agent on that device when the script runs. A person logs on, the agent installs, and the device is onboarded.
What other advice do I have?
I rate Microsoft Defender for Endpoint eight out of 10. It's a cost-effective solution for Microsoft shops.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT RM at a financial services firm with 1-10 employees
It runs in the background
Pros and Cons
- "Defender works in the background monitoring the traffic for viruses."
- "Defender could be more secure and stable."
What is our primary use case?
Defender is an antivirus solution deployed on all Microsoft PCs. Thousands of employees at my company use it.
What is most valuable?
Defender works in the background monitoring the traffic for viruses.
What needs improvement?
Defender could be more secure and stable.
For how long have I used the solution?
We've been using Microsoft Defender for a couple of years.
How was the initial setup?
Setting up Defender is straightforward. My administrator takes care of all that.
What other advice do I have?
I rate Microsoft Defender eight out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Solutions Architect at a computer software company with 501-1,000 employees
Stable, embedded in Microsoft Windows, and high performance
Pros and Cons
- "The performance of Microsoft Defender for Endpoint has been good."
- "Microsoft Defender for Endpoint could improve by providing more user-friendly dashboards. They may be complicated for some."
What is our primary use case?
Microsoft Defender for Endpoint is used for securing endpoints from threats.
What is most valuable?
The performance of Microsoft Defender for Endpoint has been good.
What needs improvement?
Microsoft Defender for Endpoint could improve by providing more user-friendly dashboards. They may be complicated for some.
In a future release, they should add a feature for patch management.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for one year.
What do I think about the stability of the solution?
Microsoft Defender for Endpoint has been stable.
What do I think about the scalability of the solution?
The scalability of Microsoft Defender for Endpoint has been good.
We have approximately five clients using the solution. We have thousands of licensees for this solution within my company.
How are customer service and support?
The technical from Microsoft could be better. It is not as good as other solutions.
How was the initial setup?
The implementation of Microsoft Defender for Endpoint because it is pre-installed with Microsoft Windows. Other solutions you have to install separately, such as Check Point.
What's my experience with pricing, setup cost, and licensing?
The license for Microsoft Defender for Endpoint is included in the license for the Microsoft Windows operating system.
What other advice do I have?
I would recommend this solution to others.
I rate Microsoft Defender for Endpoint a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
IT Operations Lead at a energy/utilities company with 5,001-10,000 employees
Basic protection, better central management needed, but simple setup
Pros and Cons
- "The solution has good performance, I have not seen a problem."
- "Microsoft Defender for Endpoint could provide us with a more holistic approach, such as collaboration. They can provide us with an environment from where we can manage all the endpoints from one central location, such as overall management."
What is our primary use case?
I use Microsoft Defender for Endpoint for an antivirus solution.
What needs improvement?
Microsoft Defender for Endpoint could provide us with a more holistic approach, such as collaboration. They can provide us with an environment from where we can manage all the endpoints from one central location, such as overall management.
For how long have I used the solution?
I have used Microsoft Defender for Endpoint within the last 12 months.
What do I think about the stability of the solution?
The solution has good performance, I have not seen a problem.
Which solution did I use previously and why did I switch?
I have used ClowdStrike previously.
How was the initial setup?
The initial setup is easy.
What about the implementation team?
I did the implementation of Microsoft Defender for Endpoint.
What's my experience with pricing, setup cost, and licensing?
The price of Microsoft Defender for Endpoint is reasonable. Other solutions are more expensive, such as ClowdStrike.
What other advice do I have?
Microsoft Defender for Endpoint only provides a basic level of security. I don't find it overly useful or appealing. I can trade it with another endpoint security solution. It's an addition to other endpoint security solutions.
I rate Microsoft Defender for Endpoint a five out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2025
Product Categories
Endpoint Protection Platform (EPP) Advanced Threat Protection (ATP) Anti-Malware Tools Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
CrowdStrike Falcon
Microsoft Intune
Microsoft Entra ID
Microsoft Defender for Office 365
Fortinet FortiEDR
Microsoft Defender for Cloud
Microsoft Sentinel
SentinelOne Singularity Complete
IBM Security QRadar
HP Wolf Security
Microsoft Purview Data Governance
Cortex XDR by Palo Alto Networks
Microsoft Defender XDR
Elastic Security
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Compare Microsoft Windows Defender and Symantec Endpoint Protection. How Do I Choose?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- What do you think of the integration of Azure AD Services, Defender for Endpoint, and Intune as comprehensive security solutions?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- Running Carbon Black Defense Along with Windows Defender
- How is Cortex XDR compared with Microsoft Defender?
- Which offers better endpoint security - Symantec or Microsoft Defender?
- How does Microsoft Defender for Endpoint compare with Carbon Black CB Defense?
- How would you compare between Microsoft Defender for Endpoint and Tanium EDR?













