We are using Microsoft Defender ATP to prevent anti-phishing, malware transportation, and unwanted spam emails.
Senior IT Manager at a pharma/biotech company with 1-10 employees
Good protection against phishing attacks and spam, but seamless integration with EDR is needed
Pros and Cons
- "What I like most is the protection against phishing emails and anti-spam."
- "If they integrate with the EDR then it will benefit this solution."
What is our primary use case?
What is most valuable?
What I like most is the protection against phishing emails and anti-spam.
What needs improvement?
The integration of the defense features is something that they are working on but it still needs improvement.
In the next release, I would like to have additional features integrated with DNS security and DNS resolution. It will add to the solution and work more like a firewall.
If they integrate with the EDR then it will benefit this solution.
I would like ATP to be integrated with the EDR as one single license.
For how long have I used the solution?
I have been working with Microsoft Defender ATP for three years.
Buyer's Guide
Microsoft Defender for Endpoint
December 2025
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.
What do I think about the stability of the solution?
It is stable, but it depends on how you configure the existing ATP and what existing features you need to enable it.
Based on the features that are enabled, it will work perfectly. 60% to 80% will depend on the configuration that is done for the ATP trade products.
What do I think about the scalability of the solution?
Microsoft Defender ATP is scalable at any point of time.
How are customer service and support?
The technical support was good.
I would rate technical support a four out of five.
How was the initial setup?
The initial setup was not easy but not complex. It was somewhere in between.
There were many things that needed to be integrated with the existing solution, which took some time. It took us a week to deploy this solution.
What's my experience with pricing, setup cost, and licensing?
When compared with other vendors, the pricing is very high.
There are several other features that can be integrated with Microsoft Defender ATP such as EDR. But, it doesn't already come integrated with ATP. It's available at an additional cost.
If you want the EDR feature, you would have to purchase an E-file license. The cost is three times higher to have more productivity with the dashboard.
What other advice do I have?
It's a good solution. I would recommend Microsoft Defender ATP to anyone who is interested in using it.
I would rate Microsoft Defender ATP a seven out of ten.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Provides real-time security, but requires time to understand how it works
Pros and Cons
- "Its real-time security is the most valuable."
- "I would like to see online updates for patches for this solution. I would also like to see online information about what is trending in the market in terms of spams, viruses, or trojans. It takes some time to understand how this solution works. A few things are unclear at the beginning, such as whether it actually restricts the virus or spam at the initial stage, or when there is a security update, how will we come to know and how will it get synchronized. It would be really helpful if there is some kind of knowledge base in the form of video, audio, or document that can explain in a user-friendly way the setup, features, risks, and process to mitigate the risks. Currently, I have installed endpoint security for every individual system. I could not install it like other endpoint solutions where we have a server and a client. It would be really helpful if Microsoft Windows Defender has a server-client based model so that I can save some bandwidth when it downloads or uploads features. It will be helpful if we have a LAN-based or WAN-based controlling system."
What is our primary use case?
We use MWD for detecting malware, viruses and protect from Ransomware.
How has it helped my organization?
We don't have third party software for EPS. We have started using Windows defender which is inbuilt one with windows to safeguard our systems from malware. It actually works as an anti-spyware program built to fight unauthorized access and protect our Windows computers from unwanted traffic.
What is most valuable?
Its a complete free version which came as in-built with windows and has no impact on our system performance. We don't need an extra software to be installed for security concerns and virus a such. It is very easy to use comparing to other available software's in the market.
What needs improvement?
I would like to see online updates for patches for this solution. I would also like to see online information about what is trending in the market in terms of spams, viruses, or trojans.
It takes some time to understand how this solution works. A few things are unclear at the beginning, such as whether it actually restricts the virus or spam at the initial stage, or when there is a security update, how will we come to know and how will it get synchronized. It would be really helpful if there is some kind of knowledge base in the form of video, audio, or document that can explain in a user-friendly way the setup, features, risks, and process to mitigate the risks.
Currently, I have installed endpoint security for every individual system. I could not install it like other endpoint solutions where we have a server and a client. It would be really helpful if Microsoft Windows Defender has a server-client based model so that I can save some bandwidth when it downloads or uploads features. It will be helpful if we have a LAN-based or WAN-based controlling system.
For how long have I used the solution?
I have been using Microsoft Windows Defender for the last six months.
What do I think about the stability of the solution?
In my experience, Microsoft Windows Defender has never caused any issues as such. It is pretty much stable and has not affected the system resources as per my observation.
What do I think about the scalability of the solution?
The solution is easily scalable. I'm always trying to increase the usage to maximize the capabilities of the product offering. As soon as new capabilities appear I will expand usage to include them.
How are customer service and technical support?
We never contacted their technical support. Indeed Microsoft technical support has always been great.
Which solution did I use previously and why did I switch?
I used to use McAfee & Norton as a different solution in my previous Organization.
How was the initial setup?
Its initial setup is fine. I did not find it too complex. We just installed and enabled it on all the systems.
What about the implementation team?
We implemented in-house.
What's my experience with pricing, setup cost, and licensing?
I pay for it through the Windows Professional or Standard license. It is a one-time cost for me, and I use the same license.
Which other solutions did I evaluate?
No
What other advice do I have?
I would really recommend this solution because it is an in-built Microsoft product, and it is at the OS level. We don't require a new layer to install it as a software application.
I would rate Microsoft Windows Defender a seven out of ten.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Microsoft Defender for Endpoint
December 2025
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,259 professionals have used our research since 2012.
Assistant Manager IT Infrastructure at a manufacturing company with 501-1,000 employees
Stable threat protection with good support but it's expensive and has license restrictions
Pros and Cons
- "It shows us the risky sign-ins, and if a user's password has been compromised."
- "I am not sure if I will be using this product in the future because of the price."
What is our primary use case?
We are using this solution for threat detection.
What is most valuable?
It shows us the risky sign-ins, and if a user's password has been compromised.
What needs improvement?
While have been using this solution for two years, I am not completely knowledgable.
Due to license restrictions, we cannot use all of the features that are offered.
I am not sure if I will be using this product in the future because of the price.
I would like to see better pricing for this solution in the future.
For how long have I used the solution?
I have been working with Microsoft Defender ATP for two years.
We are always using the latest version because it's on the cloud.
What do I think about the stability of the solution?
With what we have seen, it's a stable solution.
What do I think about the scalability of the solution?
We are not using it widely because of the licensing limits.
We have three users only for Defender ATP, and if we are using the Microsoft ATA it applies to 500 users.
How are customer service and technical support?
Technical support is good.
Which solution did I use previously and why did I switch?
We did not use another solution previous to Microsoft Defender ATP.
How was the initial setup?
The initial setup is straightforward. It's included with the Windows 10 Operating System.
There is no time taken for deployment as it is included with the operating system.
What about the implementation team?
We completed the installation ourselves.
We have 15 administrators to deploy and maintain this solution.
What's my experience with pricing, setup cost, and licensing?
Microsoft Defender ATP is expensive.
What other advice do I have?
Because of my lack of knowledge or experience with the solutions full capacity, I cannot recommend this solution or offer any advice.
I would rate this solution a five out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager Cyber Defense Operations Centre at a tech services company with 201-500 employees
Affordable and straightforward without much to improve for personal use
Pros and Cons
- "It is easy to install and use requiring little maintenance but applying updates."
- "It is inexpensive but could be cheaper like anything else."
What is our primary use case?
I installed Windows Defender for personal use for my protection of my personal PC. I use it as an antivirus system so that I do not have any exposure to viruses on my PC. Obviously, I do not want to leave my PC open to virus threats. I have only used it on my personal PCs with the license I got for Office 365. I keep my patches and descriptions updated on my PC.
Defender is installed only one one of my laptops. I am sure I will continue using it there as long as the licensing is valid.
What is most valuable?
I really have not really worked with it that much to be able to customize my approach with it or anything like that. It pretty straightforward to install and use.
What needs improvement?
I do not find that there is very much about it that needs to be improved. Everything can be cheaper I am sure. So, it could be less expansive.
For how long have I used the solution?
It has been about six months now since I started using Microsoft Windows Defender.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
I am sure it is a scalable product.
Which solution did I use previously and why did I switch?
I was just using or trying to get a personal PC secure using a product I got as part of the Office 365 package. There was no previous product installed.
How was the initial setup?
I found that it was pretty straightforward to install and use. You install it and it is working almost immediately.
What's my experience with pricing, setup cost, and licensing?
I think that the product is affordable. At least it was for me. It is part of the Office 365 package.
What other advice do I have?
I have used it enough to be sure that I could recommend it for home use on a PC.
On a scale from one to ten (where one is the worst and ten is the best), I would rate Defender as a nine-out-of-ten based on my experience.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head - IT Operations & Enterprise Systems Support at a financial services firm with 1,001-5,000 employees
Few false positives and comes bundled with the operating system, but it needs a comprehensive dashboard
Pros and Cons
- "The fact that it's from Microsoft, you don't have many false positives, unlike products from other vendors might have."
- "I would like to have a dashboard that shows an overview of the results for the enterprise."
What is our primary use case?
Our primary use is for protection against malware.
What is most valuable?
What I like best is that it is part of the operating system, as opposed to a third-party application.
The fact that it's from Microsoft, you don't have many false positives, unlike products from other vendors might have.
Updates occur frequently throughout the day.
What needs improvement?
I would like to have a dashboard that shows an overview of the results for the enterprise.
For how long have I used the solution?
We just began using Windows Defender in the company.
How are customer service and technical support?
We have premium support, which is part of our enterprise agreement with Microsoft.
How was the initial setup?
The deployment takes place with the operating system, so it was not complex.
What about the implementation team?
We used a Microsoft consultant to assist with our implementation.
What's my experience with pricing, setup cost, and licensing?
This product is included in the pricing for Windows.
What other advice do I have?
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Team Lead at a tech services company with 1-10 employees
Easy to use with great anti-malware features and quite stable
Pros and Cons
- "It's absolutely free to use."
- "The anti-ransomware features need to be improved upon."
What is our primary use case?
We primarily use it due to the fact that it comes with the Windows 10 bundle and is free. We use it for security purposes. It scans for viruses and malware for us.
What is most valuable?
The solution was highly ranked in the Gartner Report.
It's absolutely free to use.
The anti-malware features are great.
It doesn't use up a lot of resources on my laptop, so it's not slowing anything down.
The product is very easy to use.
What needs improvement?
The anti-ransomware features need to be improved upon.
For how long have I used the solution?
I've been using the solution for about a year. I switched over when I updated my computer to Windows 10.
What do I think about the stability of the solution?
The solution is very stable. So far I haven't had any issues on my laptop. It uses very little resources. It doesn't crash or freeze. There aren't bugs or glitches that I have noticed. It's reliable.
What do I think about the scalability of the solution?
I'm currently only using it on my laptop. I'm not sure if the solution can scale per se.
I will continue to use the solution, regardless of its scalability potential.
How are customer service and technical support?
I've never had a reason to reach out to technical support, as the solution runs very well. As I've never contacted them, I can't speak to the quality of their service at this time.
Which solution did I use previously and why did I switch?
I did previously try to use the free version of Avast. It's not really user friendly like Defender and it used to use a lot of my laptop's resources. I switched to Defender as it was also free and came with my Windows 10.
How was the initial setup?
The initial setup is not complex. It's very straightforward. When you download Windows 10 it comes pre-loaded and ready to go. It's a default now. Previously, it was a little more difficult.
What's my experience with pricing, setup cost, and licensing?
The solution is free. Once a user downloads Windows 10, they automatically get the product.
What other advice do I have?
I'd recommend the solution. Why not, after all? It's already there within Windows 10 and is part of a user's Microsoft bundle.
Overall, I'd rate the product eight out of ten. If it had more ransomware protection, I'd rate it higher. As it is, the solution offers great malware features, is ranked pretty highly in Gartner and is easy to implement and use. Plus, it doesn't drain a lot of your machine's resources, which is a bonus.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Deputy General Manager at a tech services company with 5,001-10,000 employees
Gets updated with new security features on a regular basis but there is no behavior analytics for devices and endpoints
Pros and Cons
- "We have liked the fact that it comes with Microsoft Windows 10 and it is constantly updated with all new virus definitions. It is also updated with new security features on a regular basis."
- "There is no behavior analytics for devices and endpoints. There is no behavior-based protection."
What is our primary use case?
We use Microsoft Windows Defender for normal internet security. We use it to detect viruses. We have about 100 users.
What is most valuable?
We have liked the fact that it comes with Microsoft Windows 10 and it is constantly updated with all new virus definitions. It is also updated with new security features on a regular basis. We don't use any other third party products.
What needs improvement?
There is no behavior analytics for devices and endpoints. There is no behavior-based protection. It does not allow us to pull data from ransomware and zero-day attacks.
For how long have I used the solution?
We have used Microsoft Windows Defender since 2010. We used Microsoft Essentials with Windows 7 then we upgraded to Windows 10. Since then we have used Microsoft Windows Defender.
What do I think about the stability of the solution?
Microsoft Windows Defender is stable.
What do I think about the scalability of the solution?
We have had no issues with scalability.
How are customer service and technical support?
We have not needed any support from Microsoft so far so there are not any complications with customer support so far.
Which solution did I use previously and why did I switch?
Recently we tested another product that employs Endpoint Detection and Response and also behavior analysis protection. It also was able to filter activities or data. These are things that Microsoft Windows Defender does not do. We stayed with Windows Defender because of the cost.
How was the initial setup?
Microsoft Windows Defender is easy to set up and easy to manage.
What about the implementation team?
We were able to set it up in-house. We have two people in-house that manage Windows Defender.
What other advice do I have?
If you require Endpoint Detection and Response or Behavior Analysis and you can afford it then go with those products. I would rate Microsoft Windows Defender a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Navision Consultant and user support at a non-profit with 11-50 employees
If any viruses are found, they are cleaned automatically
Pros and Cons
- "Automatic scanning and cleaning of viruses is the best and most valuable feature helping this tool to thrive. If any viruses are found, they are cleaned automatically."
- "With increase of cyber threats and cybersecurity issues, I would recommend that the product be developed like an AI product with more features which can counter any threat in the coming eras."
What is our primary use case?
I have used Windows Defender to protect my computer from viruses or harmful websites on either flash drives and other removable devices when I am online which tend to attack my computer and corrupt it causing inefficiencies in my computer working processes.
I usually check from time to time if the hard disks of my computer has been infected and remove the files that are harmful to my systems. Another purpose of this tool is blocking and filtering sites that are harmful or appear threatening to my system.
How has it helped my organization?
Windows Defender has improved my organisation's security in many ways which ensure that my systems are being safeguarded. Since we are mostly online doing our projects and research, we tend to enter into harmful sites that may damage our computers. But Windows Defender does great work in blocking and warning you of those sites. Another advantageous part is that when removable devices are connected to our systems they are scanned for viruses and cleaned immediately. Hence, it ensures no viruses from external devices enter into our systems. It automatically scans and checks for viruses on the hard drive from time to time ensuring good security in our systems.
I have used the solution for more than five years and the solution has greatly influenced my work. It gives good results in protecting my systems and data.
What is most valuable?
Automatic scanning and cleaning of viruses is the best and most valuable feature helping this tool to thrive. If any viruses are found, they are cleaned automatically.
Another feature is the ability to filter sites and block harmful ones, which makes it to enter sites with full protection. This ensures no harmful Trojans can be sent into our systems through those sites and are always blocked when detected.
Another great feature is the ability to warn the system user, making it easier to know when a virus has been found on our system.
It is easy to use and has a lot functionality to make systems safeguarded in the right manner.
What needs improvement?
The product should keep updating its software as to counter incoming threats since threats are becoming more advance with time. The product should be strong in all parts.
I would recommend if the product continues to be updated that the way it updates is faster for downloading and updating in our system. The stability is good and should continue to perform well in that way.
With increase of cyber threats and cybersecurity issues, I would recommend that the product be developed like an AI product with more features which can counter any threat in the coming eras.
For how long have I used the solution?
I have used the product more than five years. It is a great tool.
What do I think about the stability of the solution?
The solution is very stable. It has good features that make it efficient in the security aspects of our systems.
What do I think about the scalability of the solution?
The product has performed very well in my computers. I don't have any complains about its functionality.
Which solution did I use previously and why did I switch?
I have never used any solution apart from Windows Defender when safeguarding my systems.
How was the initial setup?
The solution comes pre-installed in the Windows Operating System so you do not have to install it manually. You are required to connect to the Internet and update the solution to the latest version.
What about the implementation team?
I am just an end user of the solution.
I hired a technical guy to keep the solution up-to-date since it could be more stable and work more efficiently.
What was our ROI?
I invested in Windows Defender since it has good functionalities.
What's my experience with pricing, setup cost, and licensing?
The product is free of charge and comes integrated into Windows.
Which other solutions did I evaluate?
I chose Windows Defender for system safety, its ease of use, and the continuous update of the product.
What other advice do I have?
Windows is a great tool that I have used. It has helped my organisation in achieving what it does daily and protected our data in a great way.
I would recommend every user who has a computer or laptop to consider using Windows Defender since it is the best tool to safeguard your system from malware and attacks.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2025
Product Categories
Endpoint Protection Platform (EPP) Advanced Threat Protection (ATP) Anti-Malware Tools Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
CrowdStrike Falcon
Microsoft Intune
Microsoft Entra ID
Microsoft Defender for Office 365
Fortinet FortiEDR
Microsoft Defender for Cloud
Microsoft Sentinel
SentinelOne Singularity Complete
IBM Security QRadar
HP Wolf Security
Microsoft Purview Data Governance
Cortex XDR by Palo Alto Networks
Microsoft Defender XDR
Elastic Security
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Compare Microsoft Windows Defender and Symantec Endpoint Protection. How Do I Choose?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- What do you think of the integration of Azure AD Services, Defender for Endpoint, and Intune as comprehensive security solutions?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- Running Carbon Black Defense Along with Windows Defender
- How is Cortex XDR compared with Microsoft Defender?
- Which offers better endpoint security - Symantec or Microsoft Defender?
- How does Microsoft Defender for Endpoint compare with Carbon Black CB Defense?
- How would you compare between Microsoft Defender for Endpoint and Tanium EDR?











