Currently, I'm working to build out DLP policies in Defender for Endpoints.
IT Security Engineer at a financial services firm with 1,001-5,000 employees
Offers excellent visibility into vulnerabilities and the attack surface itself
Pros and Cons
- "Attack surface reduction and limiting attack surface vectors are valuable features. It's helpful to isolate specific devices and get super granular with the features they offer."
- "The stability is great. I haven't seen any outages with Microsoft."
- "Defender for Endpoint is complex, and the documentation is detailed. At the same time, it's hard to navigate sometimes. You have to go through tons of documentation to find what you want."
- "Defender for Endpoint is complex, and the documentation is detailed. At the same time, it's hard to navigate sometimes."
What is our primary use case?
How has it helped my organization?
Defender for Endpoint enables us to see vulnerabilities on certain endpoints and investigate the attack surface. We've improved our Security Score to the industry standard. The solution has reduced the mean time to remediation, but it's hard to give a precise number because it varies on a case-to-case basis. Automatic remediation of certain vulnerabilities has allowed our SOC to work on other projects.
What is most valuable?
Attack surface reduction and limiting attack surface vectors are valuable features. It's helpful to isolate specific devices and get super granular with the features they offer. The visibility into the attack surface is good. It gets highly granular. I don't work on that side, but the people who do tell me they get more visibility.
What needs improvement?
Defender for Endpoint is complex, and the documentation is detailed. At the same time, it's hard to navigate sometimes. You have to go through tons of documentation to find what you want.
Buyer's Guide
Microsoft Defender for Endpoint
December 2025
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,986 professionals have used our research since 2012.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for one and a half years.
What do I think about the stability of the solution?
The stability is great. I haven't seen any outages with Microsoft.
What do I think about the scalability of the solution?
It's pretty easy to scale with Microsoft, as they make it easy if you look into the documentation.
How are customer service and support?
I rate Microsoft support eight out of 10. Customer service has been pretty good. I don't have any complaints.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We've had E5 licensing for a while now, but our security stacks were spread across multiple resources, so we are currently consolidating.
What's my experience with pricing, setup cost, and licensing?
I don't work much with the costs, but I have not heard of any issues with pricing, licensing, or setup costs for Microsoft Defender for Endpoint.
What other advice do I have?
I rate Microsoft Defender for Endpoint eight out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Lead security engineer at a computer software company with 11-50 employees
Real-time protections and automatic attack disruption have saved our time
Pros and Cons
- "The features of Microsoft Defender for Endpoint that I prefer most are the detections. It just works."
- "The automatic attack disruption feature in Microsoft Defender for Endpoint works great."
- "The log searches for Microsoft Defender for Endpoint are pretty difficult to navigate. It needs a better UI or more intuitive search and filter mechanisms to make it easy to get through and filter through all the data logs."
- "The log searches for Microsoft Defender for Endpoint are pretty difficult to navigate. It needs a better UI or more intuitive search and filter mechanisms to make it easy to get through and filter through all the data logs."
What is our primary use case?
We are an MSP. We've got a lot of clients that use Microsoft Defender for Endpoint as their EDR system. We support that.
A lot of the use cases for Microsoft Defender for Endpoint check the boxes for the EDR solution for that client. We use the endpoint portals to work through any alerts. Mostly, we feed all of the Azure Office 365 security logs into our SIEM and then take those alerts if we have to do more work, and see if we can get more details from that.
How has it helped my organization?
The automatic attack disruption feature in Microsoft Defender for Endpoint works great. Microsoft Defender for Endpoint's auto-deployed deception techniques also work great. It hasn't bothered me, so it just does its thing, which helps a lot because we have many things to deal with.
The visibility into the company's attack surface provided by Microsoft Defender for Endpoint is good. It's all in one place, which is great. I can see where things are going and make sure that it's deployed on all the machines that we work on.
Microsoft Defender for Endpoint has affected the security posture of our clients' organizations. It does its job fine. For some clients, we don't have to worry too much. Even if we're not getting tons of alerts from it, it's at least there, doing its job.
Microsoft Defender for Endpoint's coverage in client environments is comprehensive. Every device we support is a Microsoft Windows device. It covers pretty much all the endpoints and workstations for those clients.
Microsoft Defender for Endpoint has helped reduce our mean time to remediation. A lot of the reduction is due to the automatic disruption, so we don't have to sit there. It also gives us another data point to look at where the vulnerability might have been.
It has helped me free our SOC team to work on other projects or tasks. It has saved 5% to 10% of our time.
What is most valuable?
The features of Microsoft Defender for Endpoint that I prefer most are the detections. It just works. Malware getting on a machine and running is a big deal, so we can trust it to sit there and scan and have real-time protections.
What needs improvement?
The log searches for Microsoft Defender for Endpoint are pretty difficult to navigate. It needs a better UI or more intuitive search and filter mechanisms to make it easy to get through and filter through all the data logs.
For how long have I used the solution?
At the company, we've been using it for a long time. I've been here for about three months.
What do I think about the stability of the solution?
The stability of Microsoft Defender for Endpoint is good. I've never had it be unavailable. It's always available when I need it to be.
What do I think about the scalability of the solution?
It has been able to fulfill our needs. Everyone we work with is pretty small, so it's not usually an issue.
How are customer service and support?
I have never interacted with the customer service of Microsoft Defender for Endpoint, as it just does what I need it to. Based on my other experiences with Microsoft technical support, I would rate them an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We use Microsoft Defender for Endpoint along with some other products. Some of our clients choose to stick with Microsoft. There are other EDR products that we support as well.
How was the initial setup?
I've deployed it for a client. It was pretty smooth and simple. They're small shops, so there wasn't a whole lot of craziness to do with it.
What was our ROI?
The biggest return on investment for me when using Microsoft Defender for Endpoint is the time saving. It's an easy recommendation. If I have clients wanting to dive into more security products for their environments and are hesitant about going with an endpoint solution or a different software vendor, it's an easy recommendation.
What's my experience with pricing, setup cost, and licensing?
It's all pretty easy. For some clients, it's an easier sell because it's just an add-on to their existing Microsoft licensing and Office 365 licensing.
What other advice do I have?
I would rate Microsoft Defender for Endpoint a nine out of ten. The log search features are difficult. If I don't have visibility into another product, the log search functions of Microsoft Defender for Endpoint are pretty difficult to navigate.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Not sure
Last updated: Apr 30, 2025
Flag as inappropriateBuyer's Guide
Microsoft Defender for Endpoint
December 2025
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,986 professionals have used our research since 2012.
Snr. Infrastructure Architect (Data Centre) at a tech services company with 11-50 employees
Advanced threat protection improves security posture and device management
Pros and Cons
- "Microsoft Defender for Endpoint is a comprehensive and scalable solution for protecting on-premises and hybrid infrastructure."
- "The initial support process can be lacking as first-line support is sometimes not well-versed technically, resulting in repeated exchanges to finally engage a knowledgeable support person."
What is our primary use case?
Our customers use Microsoft Defender for Endpoint to protect their hybrid environments. We onboard the hybrid environment to the Azure Security posture with proper Intune integration. This setup ensures that devices are protected and secured with anti-malware, antivirus, and other protective measures. We deploy this primarily in hybrid environments.
What is most valuable?
Microsoft Defender for Endpoint provides a unified management interface allowing customers to manage their on-premises and hybrid infrastructures from a single pane. The integration with Intune enables control over devices like laptops, enhancing security. Automated Investigation and Remediation features are vital for advanced threat protection and beneficial for device protection. The ability to manage both devices and users efficiently is advantageous.
What needs improvement?
One area that needs improvement is the integration cost of logs with external solutions like Sentinel, which can be expensive. Additionally, Microsoft could allow storing logs locally within the Defender panel to reduce costs. It would also be beneficial if policies could be configured without relying on Microsoft Entra ID, allowing for better integration with local directories.
For how long have I used the solution?
I have been working with Microsoft Defender for Endpoint for three to four years.
What was my experience with deployment of the solution?
Sometimes devices do not sync properly with the Endpoint. We often need to diagnose whether the issue lies with the Endpoint or the device. This can delay proper deployment.
What do I think about the stability of the solution?
Microsoft Defender for Endpoint is stable with no major issues reported. However, syncing of devices sometimes encounters problems, requiring us to investigate the root causes.
What do I think about the scalability of the solution?
Microsoft Defender for Endpoint is scalable enough to handle various devices across environments, whether they are laptops, Android devices, or operating in hybrid environments. Customers mostly use it in hybrid setups.
How are customer service and support?
The initial support process can be lacking as first-line support is sometimes not well-versed technically, resulting in repeated exchanges to finally engage a knowledgeable support person. This process is often slow and time-consuming.
How would you rate customer service and support?
Neutral
How was the initial setup?
Setting up Microsoft Defender for Endpoint requires technical knowledge of Microsoft Entra ID and policy configurations. While it is not easy for all customers, skilled technical personnel can handle it without major issues.
What's my experience with pricing, setup cost, and licensing?
The pricing of Microsoft Defender for Endpoint is reasonable. It costs $15 per VM for the P2 plan, which is seen as affordable for customers. Additional add-ons are priced at $5.
What other advice do I have?
Microsoft Defender for Endpoint is a comprehensive and scalable solution for protecting on-premises and hybrid infrastructure. It provides strong protection and management capabilities. Customers are advised to use this solution for its robust features like advanced threat protection and easy integration with other Azure applications. I rate Defender for Endpoint nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer.
Senior Systems Administrator at a tech services company with 501-1,000 employees
ASR rules have significantly reduced unsanctioned app usage and improved endpoint security
Pros and Cons
- "The feature I like the most about Microsoft Defender for Endpoint is that it's built into Microsoft; the ASR rules have really secured our endpoints."
- "I think the overall portal of Microsoft Defender for Endpoint could be improved; sometimes there's moving around to different spots and it's a little hard to navigate, so getting used to that was perhaps the biggest hurdle."
What is our primary use case?
My main use cases for Microsoft Defender for Endpoint are protecting our endpoints and ensuring our endpoints are secure.
What is most valuable?
The feature I like the most about Microsoft Defender for Endpoint is that it's built into Microsoft; the ASR rules have really secured our endpoints.An example of how Microsoft Defender for Endpoint has benefited our organization is that we had a lot of people running unsanctioned apps that we weren't aware of, so this really limited that a lot. That is probably our biggest benefit so far.
What needs improvement?
I think the overall portal of Microsoft Defender for Endpoint could be improved; sometimes there's moving around to different spots and it's a little hard to navigate, so getting used to that was perhaps the biggest hurdle.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for about six months.
What do I think about the stability of the solution?
I would assess the stability and reliability of Microsoft Defender for Endpoint as having no issues so far.
What do I think about the scalability of the solution?
I think Microsoft Defender for Endpoint scales with our growing needs in the company; it's easy to deploy.
How are customer service and support?
We did use customer service for Microsoft Defender for Endpoint to reach out for support on certain things we couldn't figure out.I would describe their help as being able to answer all of our questions pretty quickly, so we had no complaints there.If I had to rate the customer service of Microsoft Defender for Endpoint from one to ten, I would rate it an eight.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Before Microsoft Defender for Endpoint, we did use SentinelOne as our previous solution.
How was the initial setup?
For the deployment of Microsoft Defender for Endpoint, we just did a slow roll to certain departments in our company, onboarding them slowly over a couple-month period, and then we're slowly integrating each feature to a small test group, so it ended up taking a few months to roll out throughout the whole company for all the features.
What was our ROI?
I would say I've seen a return on investment since we have Microsoft Defender for Endpoint; I think it's made our jobs easier and it's secured our endpoints better than what we had prior.
What's my experience with pricing, setup cost, and licensing?
I'm not too familiar with the pricing, setup costs, and licensing for Microsoft Defender for Endpoint; it wasn't something I dealt with, but from what I heard, it wasn't too bad of a process.
Which other solutions did I evaluate?
When we switched to Microsoft Defender for Endpoint, we didn't consider something else; we saw Defender and we knew we already used a lot of Microsoft products, so we knew that was what we wanted to use. We probably looked at other products prior to going to SentinelOne and just chose SentinelOne at that time, but we didn't really consider too many other products.
What other advice do I have?
Regarding the automatic attack feature, I don't believe we've really utilized that yet.I believe we've pretty much utilized all the features of Microsoft Defender for Endpoint that were available to us.I don't believe we are using the Security Exposure Management feature of Microsoft Defender for Endpoint.I think Microsoft Defender for Endpoint has helped free up our SOC team to work on other projects or tasks; the portal and the alerts give us a lot of good information that we can act upon very quickly, so we can usually get things diagnosed in about fifteen minutes.I believe Microsoft Defender for Endpoint has helped reduce the mean time to remediation, MTTR; before, we were able to solve it within fifteen minutes or less.Sometimes with deploying some of the rules in Microsoft Defender for Endpoint, that would affect some end users not being able to do certain tasks, so we would have to work with them to make exceptions, mainly around the ASR rules.I would rate this review an eight overall.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Nov 19, 2025
Flag as inappropriateAnalyst at a financial services firm with 10,001+ employees
Reduces endpoint infection risk with efficient malware blocking and offers detailed attack surface visibility
Pros and Cons
- "The feature I find most valuable in Microsoft Defender for Endpoint is that it blocks the process and keeps the endpoint from getting infected with malware."
What is our primary use case?
My use cases for Microsoft Defender for Cloud Apps include email security.
My use cases for Microsoft Defender for Endpoint most likely involve scenarios where the endpoint has malware, as it shows the process of the malware detonation and that it was blocked.
What is most valuable?
The feature I find most valuable in Microsoft Defender for Endpoint is that it blocks the process and keeps the endpoint from getting infected with malware.
These features have benefited my organization as they help reduce the risk of the endpoint and show us what we are getting, so we know what they attempt to do, such as anything that came with official email.
My experience with the visibility into my organization's attack surface provided by Microsoft Defender for Endpoint is that the user interface gives us a lot of visibility.
Microsoft Defender for Endpoint helps protect our endpoint and also gives us visibility with the endpoint data.
For how long have I used the solution?
I have been using Microsoft Defender for Cloud Apps for a couple of years.
What do I think about the scalability of the solution?
Microsoft Defender for Endpoint scales very well with the growing needs of my organization because we have a lot of endpoints.
Which solution did I use previously and why did I switch?
Prior to adopting Microsoft Defender for Endpoint, I don't think we had anything in place to address similar needs.
What about the implementation team?
I was not part of the implementation process; I am just using it.
What was our ROI?
I have seen a return on investment, even though I don't know what the budget for that is.
I have seen a return on investment because it provides us with protection, which is the best investment we had.
I have seen a return on investment from that.
Which other solutions did I evaluate?
Before choosing Microsoft Defender for Endpoint, they might have considered other options, but I was not involved in that evaluation.
What other advice do I have?
My experience with the automatic attack disruption feature is that it is already incorporated into the blocking process of the malware.
It helped reduce my mean time to remediation from the start to process, from a couple of hours to less than an hour.
Microsoft Defender for Endpoint does not free up our SOC team's job, but it makes our job easier.
I don't know about the pricing, setup costs, and licensing because I'm just a user.
I prefer to remain anonymous when publishing the review.
I want to remain anonymous in terms of the company name as well.
On a scale of 1-10, I rate Microsoft Defender for Endpoint an 8.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: May 3, 2025
Flag as inappropriateTeam manager of it department at a financial services firm with 501-1,000 employees
Enables automatic resolutions if a unit is compromised or if a user clicks a malicious link
Pros and Cons
- "It was quite important to have extra security on our mobile platform because of geopolitical situations, as we are located close to some countries that represent a concern. Defender for Endpoint allows us automatic resolutions if a unit is compromised or if a user clicks a malicious link."
- "Defender for Endpoint allows us automatic resolutions if a unit is compromised or if a user clicks a malicious link."
- "The major area for improvement is the integration with a managed service provider. We use Microsoft partners to help govern the platform, and as part of an alliance, we want to gather data from each tenant and combine them for a complete view. This process has been complicated, though it has gotten better."
- "The major area for improvement is the integration with a managed service provider."
What is our primary use case?
We have two phases with Defender for Endpoint because we have been using it on mobile since 2019, and we started this year changing out our Carbon Black Symantec deployment with Defender for Endpoint on our computers. Currently, the Defender for Endpoint deployment on computers like clients is mainly just a one-to-one takeover from Symantec. In the long run, we are exploring possibilities to use it for more advanced functions as it can work as a sensor and comply with the policies in Defender for Cloud apps and DLP policies.
How has it helped my organization?
From a security point of view, our mobile clients allow us to sleep at night. The current implementation on our client is economical because we have the E5 license, which we have anyway. In the long run, it would mean a more secure information security posture for our company, but we need to implement it first and then start the second phase.
What is most valuable?
It was quite important to have extra security on our mobile platform because of geopolitical situations, as we are located close to some countries that represent a concern. Defender for Endpoint allows us automatic resolutions if a unit is compromised or if a user clicks a malicious link. Importantly, the experience of an automatic attack disruption is quite positive for the end users. They don't feel supervised, which is essential for mobile phones since they are more private than work computers.
The auto-deployed anti-deception techniques are excellent because we have a large fleet on the Norwegian scale. We deployed it for 10,000 clients and about 5,000 servers in three months.
Defender for Endpoint's coverage across different platforms in our environment is pretty good. We have devices running Linux, Mac OS, Windows, iOS, and Android. It covers all of them.
What needs improvement?
The major area for improvement is the integration with a managed service provider. We use Microsoft partners to help govern the platform, and as part of an alliance, we want to gather data from each tenant and combine them for a complete view. This process has been complicated, though it has gotten better.
We see the possibilities in terms of visibility into our attack surface, but we haven't been able to enforce all the insights we can get from it. We have multiple endpoints, and we want to look for signals across tenants.
For how long have I used the solution?
We have been using it on mobile since 2019 and just started transitioning from Carbon Black Symantec to Defender for Endpoint on our computers this year.
What do I think about the stability of the solution?
I rate Defender 10 out of 10 for stability. We haven't had any issues with it.
What do I think about the scalability of the solution?
We managed to scale it out in a short amount of time, with two months of planning and three months of implementation on 10,000 computers. It is a scalable platform.
How are customer service and support?
I rate Microsoft support 10 out of 10. We have a unified support agreement with Microsoft involving biweekly or more frequent contact. We are supported by both Microsoft and our customer success manager.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We previously used Carbon Black and Symantec for endpoint protection but transitioned to Defender for Endpoint as it was included in our license. Our ultimate goal was achieving a complete security posture, not just endpoint protection.
How was the initial setup?
The initial setup and the deployment process have been easy, especially since we are using it with Azure.
What about the implementation team?
We are working with a Microsoft partner called Supercellus as we transition to them from our previous managed service provider.
What was our ROI?
We are aiming to fully utilize the E5 license, using more of its features than before. However, the return on investment is not fully realized yet, as we are still implementing.
What's my experience with pricing, setup cost, and licensing?
Given our extensive Microsoft licensing, transitioning to Defender for Endpoint did not affect licensing costs.
Which other solutions did I evaluate?
We did not evaluate other solutions, primarily because we were satisfied with our existing one. Still, when the license agreement with the other parts expired, we took the opportunity to switch.
What other advice do I have?
I rate Microsoft Defender for Endpoint eight out of 10. While I think highly of it, there are issues with sharing data across tenants, which is a particular request but still affects our satisfaction.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Systems engineers at a insurance company with 51-200 employees
We have benefited from fewer attacks, reduced risk, and less exposure
Pros and Cons
- "The notification and reporting features are most valuable because we are part of a compliance project, and maintaining SOC 2 compliance is critical."
- "Defender for Endpoint has significantly improved our security posture."
- "The only issue I would say is our mobile endpoints do not have Defender installed for part of them. An additional feature that could be included in the next release is free Copilot."
What is our primary use case?
We have used Microsoft Defender for Endpoint for various purposes, from tracking different vulnerabilities to monitoring potential issues with attacks.
How has it helped my organization?
Defender for Endpoint has significantly improved our security posture. We run two MDRs, and Defender catches more threats than the other. We've benefited from fewer attacks, reduced risk, and less exposure. We passed our recent physical penetration test audit with excellent results, partially due to Microsoft Defender.
Because of the notification and reporting, our mean time to resolution has drastically reduced. It's easier to find the issue by clicking through the notifications. Our SOC team has saved a lot of time, allowing them to focus on audits and other tasks.
What is most valuable?
The notification and reporting features are most valuable because we are part of a compliance project, and maintaining SOC 2 compliance is critical. The reporting, dashboards, and automatic notifications of potential issues greatly improve visibility. Luckily, we haven't had to use automatic attack disruption, but we are happy it's there.
What needs improvement?
The only issue is that our mobile endpoints do not have Defender installed for part of them. An additional feature that could be included in the next release is free Copilot.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for at least two years now.
What do I think about the stability of the solution?
Defender for Endpoint is extremely stable. I haven't seen anything that would give me any cause to doubt it.
What do I think about the scalability of the solution?
Defender's scalability is phenomenal, and it's going to be one of the keys to resolving issues for the SOC.
How are customer service and support?
We haven't had much need to use customer service and technical support. Due to our size, we don't have access to direct technical support, but the knowledge base, Microsoft Learn, and the articles available are really good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We use both Microsoft Defender and SentinelOne for extra coverage. We evaluated CrowdStrike and other options, but Microsoft Defender makes logical sense as part of our E5 license.
How was the initial setup?
Deploying Defender was extremely easy. We built a package and rolled out everything without our end users noticing.
What about the implementation team?
We did the deployment ourselves in-house. We're that good.
What was our ROI?
The return on investment is primarily in time savings and better observability of what's happening. Although I don't know the exact numbers associated with the time savings, it has definitely improved efficiency.
What's my experience with pricing, setup cost, and licensing?
The pricing, setup, and licensing were very easy and simple. I've really enjoyed it.
Which other solutions did I evaluate?
We looked at CrowdStrike and several other options, but Microsoft's integration, communication, and Copilot make it the better product. Other solutions lacked integration and visibility across the entire estate.
What other advice do I have?
I'd rate Microsoft Defender for Endpoint nine out of 10. I don't give anything a 10, and it's about as good as a nine can get.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Enterprise Architect at a non-profit with 501-1,000 employees
Easy to update with good protection and a useful cloud portal
Pros and Cons
- "Updates and upgrades are quite smooth and seamless."
- "We'd like to see integrations with more vulnerability scanning solutions like Tenable."
What is our primary use case?
The solution is primarily used for securing endpoints, mainly desktops and laptops.
How has it helped my organization?
We're taking the adoption in phases. We started with endpoints and we want to expand into other capabilities at the application level.
What is most valuable?
We've mainly used it for endpoints. However, we've also used it for DLP as well. We're also in the process of implementing it for cloud and identity as well. However, it's very good for endpoints, and that's our main focus.
The malware protection is good.
The visibility it provides is very useful. We can combine visibility with wider security features and alerts around malware, misconfiguration, or any other kinds of threats. The cloud portal is quite good. From there, we are able to see alerts and have colleagues review issues and monitor to see if any patterns arise. It's serving us quite well overall. It allows us to look at other items, like application and browser control.
It helps us prioritize threats. We have a process in place now where we can review issues and remediate them effectively.
We have been able to integrate a variety of Microsoft security products together. We use Azure AD, for example, and we've begun to implement DLP, among other items. We're looking at labeling and tagging and will expand into that soon.
Defender has more stringent system requirements than, for example, Check Point. So when we implemented the Check Point Endpoint agent, that solution didn't mind what version of Windows you were using. When we moved to Defender, Defender had certain system prerequisites that had to be met. So we had to make sure that we're on a minimum version of Windows when we're utilizing Office, and Office has to be a particular version as well. It has more stringent system requirements that have to be met before you can implement it.
It works natively together with other Microsoft solutions. Once you get more and more of those different components across the environment, then you start to get better visibility. So, rather than having lots of different solutions, you have fewer solutions and a single vendor solution. That way, you start getting into a position where you get better visibility and integration as well.
The standardization is good. It's important. It's helping me with monitoring and learning.
Updates and upgrades are quite smooth and seamless.
Defender helps us automate routine tasks. Quite a lot of Microsoft is straightforward for us now. Previously, we didn't have enough resources and were unable to look at the alerts. Having this in place makes things a lot more straightforward for us. We have both the technology and the people in place now, alongside the process. We do see the benefits in that, and that's why we're continuing our adoption across the estate in terms of client and server as well.
It's helping us avoid looking at multiple dashboards and centralized monitoring. We're not fully there yet. We're getting there.
While we haven't witnessed time saving yet, once it's fully deployed, it will. By then, we'll have standardized processes across a single solution. We have saved money, however, as we continue to reduce non-Mircosft systems. Since we won't be using various competing technologies, we can save on licensing costs. We've likely so far saved 15%.
While it's hard to estimate exactly how much, the solution has helped us decrease time to detection and time to respond.
What needs improvement?
We'd like to see integrations with more vulnerability scanning solutions like Tenable. It would be good to be able to compare both systems to threats that are arising.
For how long have I used the solution?
I've used the solution for the past couple of years. I haven't used it, however, on an active basis. It's not a solution that requires active engagement.
What do I think about the stability of the solution?
The solution is stable. We've had no issues.
What do I think about the scalability of the solution?
We've had no issues with scaling. We're scaling up to just under 2,500 systems.
How are customer service and support?
We haven't had much cause for raising tickets; however, largely support is very good. We did receive initial support during deployment and have a unified support agreement. It's simple and straightforward when we do need help.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We have used a Check Point solution as well in the past. We're moving away from other competing technologies. We had a number of issues with Check Point in terms of the mix of client devices and operating it in a VDI environment. It wasn't as reliable as we would have liked. It might have also been a resourcing issue - not just a Check Point issue.
How was the initial setup?
In terms of the actual implementation, once everything is in place, it's quite smooth, and you see the benefits quite quickly as well.
I was not directly involved in the deployment of Defender. I was more involved in procurement.
What's my experience with pricing, setup cost, and licensing?
Defender is part of the plan we signed up for. Overall, it's part of a wider suite and is representing well, although it's hard to gauge how much of our overall licensing price is based on Defender as a product. It's part of a wider investment in Microsft 365.
Which other solutions did I evaluate?
We have been through a merger in the last five years, so there were multiple solutions we were using, such as Trend Micro and Kaspersky, as well as Cisco, that we considered before deciding to standardize under Microsoft.
What other advice do I have?
We are starting to also use Microsoft Defender for Cloud. We have a small POC that we are getting off the ground. We have not yet explored bidirectional sync capabilities.
I'd rate the solution nine out of ten.
I would advise new users to just be mindful of system requirements. You do need to have a relatively up-to-date Windows estate. Take into account legacy considerations in terms of displacing other non-Mircosoft solutions.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2025
Product Categories
Endpoint Protection Platform (EPP) Advanced Threat Protection (ATP) Anti-Malware Tools Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
CrowdStrike Falcon
Microsoft Intune
Microsoft Entra ID
Microsoft Defender for Office 365
Microsoft Defender for Cloud
Fortinet FortiEDR
Microsoft Sentinel
SentinelOne Singularity Complete
IBM Security QRadar
HP Wolf Security
Cortex XDR by Palo Alto Networks
Microsoft Purview Data Governance
Microsoft Defender XDR
Elastic Security
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Compare Microsoft Windows Defender and Symantec Endpoint Protection. How Do I Choose?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- What do you think of the integration of Azure AD Services, Defender for Endpoint, and Intune as comprehensive security solutions?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- Running Carbon Black Defense Along with Windows Defender
- How is Cortex XDR compared with Microsoft Defender?
- Which offers better endpoint security - Symantec or Microsoft Defender?
- How does Microsoft Defender for Endpoint compare with Carbon Black CB Defense?
- How would you compare between Microsoft Defender for Endpoint and Tanium EDR?













