What is our primary use case?
We utilize Microsoft Defender for Office 365 to enhance our email protection.
All of our Office 365 solutions are stored in the cloud. We have recently acquired multiple licenses for Microsoft Defender for Office 365.
How has it helped my organization?
We also use DMS. I believe that integration comes out of the box because both products are from Microsoft and I haven't taken any steps to do any integration myself.
The comprehensiveness of DMS and Microsoft Defender for Office 365 has been incredibly helpful, particularly concerning email attachments. They have successfully identified numerous suspicious attachments, some of which were reported. The integration of these two solutions has proven to be extremely beneficial. Additionally, they have been effective in detecting phishing links and untrusted sites in emails on several occasions.
I remember what actually prompted us to switch to using Microsoft Defender for Office 365. We had several people who were not tech-oriented receiving loads of phishing emails, and their credentials were almost compromised. It wasn't just them; we had many other users in the organization facing similar issues. To address this, we conducted a phishing simulation, and unfortunately, a lot of people failed the simulation. After analyzing the situation, we realized the need to provide better training and implement additional security measures in case someone made a mistake or failed to follow proper procedures. That's why we decided to go with Microsoft Defender for Office 365. So far, it has been effective in identifying a lot of threats. Previously, we received several complaints about compromised credentials, mainly due to phishing emails. However, since we started using Microsoft Defender for Office 365, the number of complaints has drastically reduced. Although some people still fail our phishing simulation during in-house tests, externally, Microsoft Defender for Office 365 has proven valuable in filtering out numerous threats. I'm confident that without it, many accounts would have been compromised.
Microsoft Defender eliminates the need for multiple dashboards. When I'm on the Office 365 dashboard, I don't see any reason why I would need to access another dashboard.
Microsoft Defender for Office 365 identifies various threats and notifies us whenever it detects something suspicious. Without Microsoft Defender for Office 365, it would be quite time-consuming. We used to receive numerous complaints about credential tests, but since its deployment, those complaints have drastically reduced. Microsoft Defender for Office 365 has saved me a considerable amount of time.
It indirectly helps our organization reduce costs. We encountered a situation where one of our financial officers had their credentials stolen, and someone attempted to impersonate them, trying to transfer funds to other accounts. However, the system flagged the suspicious activity, and we were able to prevent the unauthorized transfer.
Microsoft Defender for Office 365 improves our ability to detect and respond to threats. It easily identifies all potential threats and promptly notifies us. I can only imagine the consequences if it weren't in place. Numerous suspicious links and attachments might have gone through, resulting in additional work and time spent on finding ways to remediate, resolve, and contain the situation.
What is most valuable?
The two main features that prove most beneficial for us are URL scanning and attachment scanning.
URL scanning involves an automatic scan of links and emails. When a user clicks on a link within an email, the system promptly checks the link's safety. If the link is deemed safe, access is granted automatically. However, if it is flagged as unsafe, we receive feedback and notification to caution us about the potentially harmful link. At this point, we are presented with the option to proceed or return. I have personally witnessed the system identify a few unsafe links, making this the primary advantage of using the solution.
The second crucial aspect is the scanning of attachments. When an email containing an attachment arrives, we receive a notification of the new email, along with information that the attachment is being scanned for threats. This additional layer of security provides peace of mind for our organization.
While Microsoft Defender for Office 365 offers numerous features, these two stand out as particularly impressive and valuable to us.
What needs improvement?
Microsoft Defender for Office 365 should be more proactive. As a major global player, Microsoft possesses the platform to gather more information than any other company. Utilizing this information would enable them to make the system much more proactive. It would be sensible for Microsoft Defender for Office 365 to send occasional notifications, acting as advisories on how to prevent the latest threat trends. Similar to a newsletter, these notifications could guide users to take appropriate measures and review their organization's configurations, thereby ensuring maximum security.
For how long have I used the solution?
I have been using Microsoft Defender for Office 365 for around four years.
What do I think about the stability of the solution?
Microsoft Defender for Office 365 is extremely stable. I have not seen any downtime.
What do I think about the scalability of the solution?
Microsoft Defender for Office 365 is scalable. We only need to add licenses to include more users.
How are customer service and support?
Eighty percent of the time, the technical support is good. There are occasions when we are redirected, which can be annoying, but for the most part, they are good.
How would you rate customer service and support?
How was the initial setup?
The initial setup was straightforward. There wasn't much to do for Defender. We simply purchased the licenses and applied them to the users. It was a seamless deployment. As for Office 365, we had a couple of E3 licenses and had to install Office on the users' desktops. That proved to be a tedious task.
To deploy Microsoft Defender for Office 365, we simply wrote a script to assign licenses to users in bulk. Three people, including myself, handled the deployment.
What's my experience with pricing, setup cost, and licensing?
For small and medium organizations, the pricing might not be affordable. Although Microsoft Defender for Office 365 is a good product; something all organizations should have. However, the question is, can all organizations afford it? For large enterprise organizations, they can definitely afford it, but for small and medium organizations, they might struggle to cover the expenses.
Which other solutions did I evaluate?
We also assessed Sophos Email before implementing Microsoft Defender for Office 365. Since we were already using Office 365, we believed it would be a seamless and more effective option to proceed with Microsoft Defender for Office 365.
What other advice do I have?
I would rate Microsoft Defender for Office 365 a seven out of ten. The solution meets my expectations, but I would appreciate information on current threats and an increase in the level of intelligence gathering to be more proactive. It would be helpful to receive information on steps I can take to prevent potential threats, as our organization might be a target based on the threat intelligence it has gathered.
I have had a couple of Microsoft resellers try using Sentinel with my organization. Perhaps it was due to the configuration, but it didn't seem like there was much setup required. Essentially, we weren't able to see as many details as we expected, likely because we already have an in-house sync solution, and we were attempting to integrate Sentinel alongside it. Consequently, we also continued using the other solution. However, what we obtained from Sentinel, didn't provide us with much information compared to our existing solution. This is why we decided not to proceed further with the Proof of Concept for Sentinel. It's possible that the reseller didn't configure something properly, or maybe it didn't demonstrate some of the things it was supposed to. But based on our end-user experience, we didn't receive sufficient information from Sentinel as we do with our current solution. Hence, we made the decision not to move forward with the POC for Sentinel.
It is not advisable to engage with different vendors. This is because there will be instances where issues arise, and a particular vendor may not take responsibility for the problem. Dealing with multiple vendors makes it challenging to accomplish tasks efficiently, as we often find ourselves unsure about which vendor is accountable for each aspect. On the other hand, opting for a single vendor, even if they cannot fulfill all our requirements, is still preferable. This choice allows us to have a clear point of contact when something goes wrong, and the integrations are smoother. Additionally, using multiple vendors can lead to integration problems.
To properly utilize Microsoft Defender for Office 365, we must first acquire an Office 365 subscription. If we are already using Office 365 and seeking enhanced protection, Microsoft Defender for Office 365 becomes an obvious choice. It offers seamless integration and straightforward usage. To proceed effectively, we need a clear understanding of the users requiring protection and precise guidance on configuring the policies to ensure they provide the necessary protection effectively.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.