Try our new research platform with insights from 80,000+ expert users
reviewer2595123 - PeerSpot reviewer
Pre-Sales Product Specialist at a tech services company with 1,001-5,000 employees
Real User
Top 20
Helped us to avoid malware in the system and prevent unwanted emails from entering our system
Pros and Cons
  • "The most valuable aspect of Microsoft Defender for Office 365 is its ability to protect us from malware."
  • "The changes to customer service, specifically the new model for support agreements, are not favorable."

What is our primary use case?

We are using Microsoft Defender for Office 365 to avoid spam, malware, and similar threats.

How has it helped my organization?

Microsoft Defender for Office 365 helps us prioritize threats across our enterprise. I am able to let the system fix the malware while I focus on other tasks.

Microsoft Defender for Office 365 automates routine tasks and highlights critical alerts, significantly improving our security operations. This automation saves us time by reducing repetitive tasks, allowing us to focus on developing new services instead of solely on security operations.

The threat intelligence feature helps us take proactive steps to prevent threats.

Microsoft Defender for Office 365 saves us time and money and has helped decrease the time to detection and response.

It has helped us to avoid malware in the system and prevent unwanted emails from entering our system.

What is most valuable?

The most valuable aspect of Microsoft Defender for Office 365 is its ability to protect us from malware. This has effectively helped us avoid malware in the system and keep out unwanted emails. It allows us to spend less time on repeated tasks, enabling us to develop new services.

What needs improvement?

The changes to customer service, specifically the new model for support agreements, are not favorable. We have to pay $600 for every instance, making it too expensive. We might need to look at other support options.

Buyer's Guide
Microsoft Defender for Office 365
September 2025
Learn what your peers think about Microsoft Defender for Office 365. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
869,832 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Microsoft Defender for Office 365 for over ten years.

What do I think about the stability of the solution?

Microsoft Defender for Office 365 is stable. It's doing what it's supposed to do.

What do I think about the scalability of the solution?

The solution is scalable. Microsoft Defender for Office 365 is flexible with other security products we use. Our usage depends on Microsoft adding features.

How are customer service and support?

We have a premier support agreement. Initially, it worked well, but the new model, where we have to pay for every instance, is not satisfactory.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We used alternative solutions prior to implementing Microsoft Defender for Office 365. We selected it due to its superior integration with our existing security infrastructure.

What about the implementation team?

The implementation was completed in-house.

Which other solutions did I evaluate?

We evaluated other solutions before switching to Microsoft Defender for Office 365.

What other advice do I have?

I would rate Microsoft Defender for Office 365 ten out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Partners
PeerSpot user
Sachin Vinay - PeerSpot reviewer
Assistant Manager-Networks at Amrita
Real User
Top 5Leaderboard
Prioritizes threats across our enterprise and safeguards us from any incoming threats or viruses
Pros and Cons
  • "Microsoft Defender has a feature to protect each and every attachment. Even if it's an encrypted attachment, it will check for any potential threats."
  • "Microsoft should provide more documentation for users so they can self-educate. I would like to see more documentation for advanced security features."

What is our primary use case?

We mainly use Microsoft Defender for Office 365 to secure our Office 365 combined application package, which includes Outlook, Word, Excel, PowerPoint, OneDrive, Skype, and Teams. We have all of these combined packages in our cloud. 

Before we deployed Defender, we didn't have the right solution to safeguard these applications because our data was moved from multiple locations, from Outlook to OneDrive, for instance. After the introduction of Defender, we could instantly control most threats.

We also use Microsoft Defender for Identity and Cloud Apps. We deployed Identity recently. 

Integration is easy because Microsoft is the vendor of all of these security products. Most of these products are closely integrated, whether they're on-premise or deployed on the cloud.

These solutions work natively together to deliver coordinated detection and response across our environment. All of these features work on different security layers to ensure protection. Microsoft Defender for Identity gives protection to users. That's an application layer. Simultaneously, Defender for Cloud also provides a layer of security. Each Microsoft product offers a different layer of security, so our organization is secure.

These security products offer comprehensive threat protection. Each day, thousands of people send emails that contain malicious content. Microsoft Defender for Office 365 constantly monitors those attachments and gives us alerts so that we're able to focus on threats and prioritize them accordingly.

We use the bidirectional sync capabilities. It's an important feature to us because we need it for proper syncing and security, both on-premises and on the cloud.

The solution is deployed on a public cloud.

Defender is used in one tenant, and multiple departments use it. It provides security for about 2,000 users.

How has it helped my organization?

We have seen multiple benefits from using Defender. Our data was on-premises about five years ago. We migrated our data to the cloud to improve our security. It's awesome to get all of the security features in the cloud. To apply these features on-premises requires different hardware and multiple vendors. With Microsoft Defender, we're able to have a single manufacturer.

Microsoft Defender for 365 helps automate routine tasks and the finding of high-value alerts. It's a detection mechanism, so it doesn't solve the issue, but it will give us alerts and other notifications. It provides system alerting and patches.

The alerting automation definitely affects our security because our organization requires alerts constantly. The Defender setup for Office 365 applications gives us a clear alerting dashboard. The dashboard has multiple features that are linked to most of our applications, so it's more secure.

This solution helps eliminate the need to look at multiple dashboards. With different vendors for security, we obviously had vertical dashboards. Microsoft Defender gives us a single dashboard that we can link to other applications. 

Defender has reduced time spent by 50%.

It definitely saves us money because other vendor products cost more. The hardware itself costs money. Defender's subscription costs less. We have saved 50% compared to other solutions.

Defender decreases the time it takes to detect and respond. We're able to detect 20-30% faster.

What is most valuable?

Most of our files are being stored in OneDrive. We need to safeguard those links because users have to forward them to multiple locations. Microsoft Defender has a feature to protect each and every attachment. Even if it's an encrypted attachment, it will check for any potential threats.

If there are any spam contents in an email, we will be notified. With the implementation of Defender, we're able to correctly monitor attachments, files, and safeguard the required data. 

Microsoft Defender for Office 365 provides us with visibility into threats. Our emailing system is Microsoft Office Outlook. We also use a mail server from Microsoft. If there's an issue, we're able to troubleshoot it right away and give a solution. All of the administrators are properly alerted in their dashboards.

Microsoft Defender for Office 365 helps us prioritize threats across our enterprise. It safeguards us from any incoming threats or viruses. It scans every bit of information from the software cloud, including attachments, links, or malicious emails that hackers generate to break the security system.

It's definitely important that Defender helps us prioritize threats across the enterprise because some of the security breaches are less serious, so there is more time to troubleshoot. We're able to see everything in the dashboard, so we're notified about the important threats and can act accordingly to resolve them.

What needs improvement?

The advanced threat protection requires awareness and knowledge from administrators. Microsoft should provide more documentation for users so they can self-educate. I would like to see more documentation for advanced security features.

For how long have I used the solution?

I have used this solution for about five years.

What do I think about the stability of the solution?

It's completely stable.

What do I think about the scalability of the solution?

It's scalable.

How are customer service and support?

Technical support is really good. I would rate them as nine out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We haven't used any other solutions.

How was the initial setup?

The setup was straightforward.

Maintenance isn't required because the solution auto-updates.

What about the implementation team?

We received support from Microsoft for implementation. Four system administrators were needed for implementation.

What was our ROI?

We have definitely seen a return on investment. OneDrive stores a lot of data, and maintaining the security of that data is a large task. It would be expensive to integrate another solution for that task. Since implementing Defender, we have saved a lot of money.

There are other Microsoft products included in the package, so we're able to save more money. I think there's a great return on investment.

What's my experience with pricing, setup cost, and licensing?

The pricing is normal. Considering its popularity, it's not overpriced.

Which other solutions did I evaluate?

We haven't evaluated other options. To secure Microsoft Office 365 applications, we wouldn't necessarily go for other third-party solutions because Microsoft has its own proprietary solutions.

What other advice do I have?

I would rate this solution as nine out of ten.

My advice for other people who are in security is to try Defender. It's much better than other top security appliances and it's completely affordable. For large and medium enterprises, it's definitely worth trying because applications like OneDrive require constant monitoring. 

Multiple security solutions must be monitored constantly, and the maintenance cost will be much higher. Dependency issues will arise, and you will need multiple support people to troubleshoot issues. Sometimes the issue won't be found if it involves multiple dependencies from other vendors. We prefer to go with a single-vendor product like Microsoft because of their support.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Microsoft Defender for Office 365
September 2025
Learn what your peers think about Microsoft Defender for Office 365. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
869,832 professionals have used our research since 2012.
reviewer2104224 - PeerSpot reviewer
Solution Consultant Information Security at Ixtel
MSP
Helps prioritize threats across our enterprise by using an endpoint
Pros and Cons
  • "Microsoft Defender for Office 365's most valuable feature is its performance."
  • "The XDR dashboard has room for improvement."

What is our primary use case?

We use Microsoft Defender for Office 365 for our endpoint security.

How has it helped my organization?

Microsoft Defender for Office 365's visibility is good.

Microsoft Defender for Office 365 helps prioritize threats across our enterprise by using an endpoint.

Integrating with other Microsoft solutions is generally straightforward, as everything can be managed from a single console. However, there are some cases where the integration process can be complex, such as when it requires accessing a different dashboard. Overall, the benefits of managing multiple Microsoft solutions from a single place outweigh the occasional complexity of integration.

Our solutions work together natively to provide coordinated detection and response across our entire environment. This coordinated detection provides high-quality results because it is easy to check emails and endpoints for threats. We chose to bundle the solutions because of their ability to integrate.

Coordination and integration are essential in cybersecurity because there are many resources to monitor. The ability to coordinate and integrate from a single source makes it easier and helps to eliminate the need for multiple products.

Microsoft Defender for Office 365 has improved our security posture, especially around email. It integrates easily with our other Microsoft solutions and provides good visibility into our systems.

Microsoft Defender for Office 365 helps automate routine tasks.

Automation allows us to focus our resources on critical issues instead of the standard security tasks that can be automated.

Microsoft Defender for Office 365 saved our organization time.

Microsoft Defender for Office 365 increased our productivity, which resulted in cost savings.

Microsoft Defender for Office 365 helped decrease our time for detection and response. 

What is most valuable?

Microsoft Defender for Office 365's most valuable feature is its performance.

The ransomware protection is good.

What needs improvement?

Microsoft Defender for Office 365 is a comprehensive security solution, but it could be improved. Compared to other solutions, Microsoft Defender for Office 365's security reports are not as detailed and the visibility into our network coverage could be better.

The IOC scanning has room for improvement.

The XDR dashboard has room for improvement. The dashboard needs more of a single pane of glass because currently, Microsoft Defender for Office 365 does not give me any options to scan an email thread or attachment for IOCs on my endpoint. I need to manually download the file from the email and then scan it with Microsoft Defender for Office 365. I think Microsoft Defender for Office 365 should be able to scan email threads and attachments directly, without the need for manual intervention.

Secondly, the Data Loss Prevention functionality in Microsoft Defender for Office 365 is very limited. It can only scan for certain types of data. Microsoft Defender for Office 365 should be able to scan for a wider variety of data types, such as customer lists and intellectual property.

Attack process management and breach attack simulation should be included in Microsoft Defender for Office 365.

For how long have I used the solution?

I have been using Microsoft Defender for Office 365 for six years.

What do I think about the stability of the solution?

Microsoft Defender for Office 365 is stable.

What do I think about the scalability of the solution?

Microsoft Defender for Office 365 is scalable.

How are customer service and support?

Technical support is generally helpful, but we often need to escalate tickets to resolve issues.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

I previously used Kaspersky Security for Mail Server, Trend Micro Email Security, CrowdStrike, and Mandiant. However, my organization now uses Microsoft Defender for Office 365. This is because we are a Microsoft customer and it makes sense in terms of cost and integration.

What was our ROI?

We have seen a return on investment using Microsoft Defender for Office 365.

What's my experience with pricing, setup cost, and licensing?

Compared to other brands, Microsoft Defender for Office 365's pricing is competitive.

What other advice do I have?

I give Microsoft Defender for Office 365 an eight out of ten.

The maintenance is seamless.

A single-vendor approach is better than a best-of-breed approach because it provides a more integrated and seamless solution. This means that there is no need to worry about compatibility issues or data silos and the overall security posture is better.

Microsoft works hard to provide customers with a single pane of glass so they can easily manage, scale, and maintain their solutions. I recommend Microsoft Defender for Office 365.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Kishan Kishto - PeerSpot reviewer
Systems Administrator at Kishto Technologies
Real User
Top 10
Multiple people can collaborate on a single document but needs improvement in troubleshooting tools
Pros and Cons
  • "The benefit that stands out to me is the ability for multiple individuals to collaborate simultaneously within the same document. Additionally, there is the option to save the document directly in the integrated OneDrive or SharePoint."
  • "Microsoft Defender for Office 365 should improve the troubleshooting tools. It's unclear whether the device is blocked at the firewall level or at the device itself. The granularity needed for troubleshooting is currently lacking. From my perspective, Microsoft should address this issue to benefit many users who likely share the same sentiment."

What is most valuable?

The benefit that stands out to me is the ability for multiple individuals to collaborate simultaneously within the same document. Additionally, there is the option to save the document directly in the integrated OneDrive or SharePoint. 

What needs improvement?

Microsoft Defender for Office 365 should improve the troubleshooting tools. It's unclear whether the device is blocked at the firewall level or at the device itself. The granularity needed for troubleshooting is currently lacking.

From my perspective, Microsoft should address this issue to benefit many users who likely share the same sentiment.

For how long have I used the solution?

I have been using the product for three years. 

What do I think about the stability of the solution?

Microsoft Defender for Office 365 is stable. 

What do I think about the scalability of the solution?

You can scale up as you pay. 

How are customer service and support?

Evaluating Microsoft support can be a bit mixed. Sometimes, it's good, but not so much. The initial contact is typically with the help desk. When I call, I usually need someone at a higher level, maybe level three, to assist with more complex problems. The challenge is that it can take up to two weeks to resolve issues, and my main complaint is the waiting times and the basic nature of level-one support. Getting to the expert who can fix the problem often takes a couple of weeks.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

My clients used Norton and McAfee before Microsoft Defender for Office 365. It makes sense in the long term, especially when many clients already have Microsoft 365 in their licenses. Paying more to get the security features with Microsoft instead of additional licensing costs with a different company is a practical choice. It seems to be mainly about saving money.

How was the initial setup?

The tool's deployment is not straightforward. However, it has good documentation. 

What's my experience with pricing, setup cost, and licensing?

The solution is good but not cheap. It offers a big ecosystem where you can manage everything from one place. 

What other advice do I have?

Integrating identity and access management into Microsoft 365 Defender is important for my customers and me. The ability to centrally manage these aspects within the platform is highly valuable. Rather than navigating through numerous consoles to verify various aspects, having almost everything in a single location saves time. This integrated approach streamlines operations and reduces the complexity of learning and managing different products.

Nowadays, everyone uses not just Microsoft products but also third-party ones. It would be good if Microsoft could make its security tools work with all kinds of software. Nowadays, there are so many cyber attacks and security threats. Having one product that can handle and manage all these threats across the board is beneficial.

We have stopped using Trend Micro in a couple of places. I am not sure if it was due to cost or pricing. 

The product is more convenient to manage, and it saves time. Instead of navigating through different controls, having everything in one place allows the security team to take action on threats or issues.

I rate the product a nine out of ten. I have used it for security and compliance. In my experience, they're doing quite well; it's a good product. If people are considering Microsoft products, I would say, why not? It's just that support during implementation could be better sometimes. However, it's a good product with frequent updates. 

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. implementator
PeerSpot user
Information Technology Specialist at a pharma/biotech company with 1,001-5,000 employees
Real User
Saves us time with our investigations and provides safe attachments and safe links
Pros and Cons
  • "Microsoft Defender for Office 365's most valuable features are safe attachments and safe links."
  • "The GUI is sometimes slow to fetch the device report and could be improved."

What is our primary use case?

Microsoft Defender for Office 365 is used to protect our organization from attacks.

Our deployment is a hybrid model with 80 percent being on the cloud.

How has it helped my organization?

The visibility into threats is excellent. A dashboard provides real-time information on emails, blocked emails, blocked files, and blocked URLs.

We integrated Microsoft Sentinel and Microsoft Intune with Microsoft Defender for Office 365. Integrating Intune was a little difficult but we managed.

The solutions work natively together to provide coordinated detection and response across our environment. This is important.

The integrated Microsoft solutions provide comprehensive insights into threat issues through threat analytics.

Microsoft Sentinel allows us to ingest data from our entire ecosystem. This is important because it provides us with a vital security feature that allows our organization to monitor and respond to alerts and threats detected in our enterprise via Sentinel. We have configured custom alerts and triggers in Sentinel, which gives us a better understanding of the threats in our organization.

Microsoft provides a comprehensive view of alerts to help investigate issues and address malicious emails. We can investigate and share feedback in our message tracking log and the threat explorer in Defender to mitigate and resolve the root cause of the issues.

Microsoft Defender for Office 365 saves us time with our investigations.

We now use the cloud to maintain our email as a gateway which has saved us money by not requiring on-prem hardware.

Our time to detect and respond to malicious emails was decreased. The solution provides the CPU resources needed to scan emails for malicious content, and it also makes it easy to track the number of administrative emails sent to users.

What is most valuable?

Microsoft Defender for Office 365's most valuable features are safe attachments and safe links.

What needs improvement?

The GUI is sometimes slow to fetch the device report and could be improved.

It would be great if Microsoft Defender for Office 365 were priced at the tenant level, rather than the user level. This is because the feature is used by all users in the tenant, not just individual users.

For how long have I used the solution?

I have been using Microsoft Defender for Office 365 for two years.

What do I think about the stability of the solution?

Microsoft Defender for Office 365 is stable.

What do I think about the scalability of the solution?

Microsoft Defender for Office 365 is scalable.

How are customer service and support?

Technical support is often unsatisfactory. When I open a ticket, the initial engineer I speak to often has no hands-on experience and needs to escalate the issue to someone else. This can take a long time, as the engineer needs to check with the internal team before they can provide any assistance. In the end, the issue is eventually resolved.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We previously used Barracuda Email Security Gateway, but it did not sandbox emails. After careful consideration, we decided to switch to Microsoft Defender for Office 365.

How was the initial setup?

The initial setup was straightforward. We just follow Microsoft's documentation and fine-tune the default custom policies as well as new days on custom policies for data management and checking. Two people were required for the deployment.

What about the implementation team?

The implementation was completed in-house.

What was our ROI?

We have seen a return on investment.

What's my experience with pricing, setup cost, and licensing?

The license is expensive because the cost is based on the number of users. The more users there are, the higher the cost.

What other advice do I have?

I give Microsoft Defender for Office 365 a nine out of ten.

We have four people that directly access the solution.

There is no maintenance required from our end.

Before using Microsoft Defender for Office 365, organizations must ensure that the policies are configured correctly to fit their specific needs.

It is better to choose a single vendor with high expertise in a specific area, rather than a best-of-breed strategy.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
HariOmKanth MS - PeerSpot reviewer
DevSecOps Engineer at a tech services company with 11-50 employees
Reseller
Top 10Leaderboard
Reduces our response time such that what once took at least an hour can now be resolved in minutes
Pros and Cons
  • "The email protection is excellent, especially in terms of anti-phishing policies."
  • "Several simulation options are available within 365, and the phishing simulation could be better."

What is our primary use case?

We're an MSP, and we deploy security solutions to our clients based in the UAE. We are currently implementing the product ourselves and developing the capacity to deploy it to our clients. We have around 200 total end users. 

In addition to Defender for Office 365, we also use Defender for Cloud and Microsoft Sentinel. The products are integrated.    

The integration was straightforward, as most of our clients and we operate an Azure environment, so integration is usually as simple as a few clicks.

How has it helped my organization?

Defender for Office 365 helps automate routine tasks and find high-value alerts, which we can do using Azure Logic Apps. We can create operations, automate them, and make a workflow using automation. One of our clients didn't have the budget to invest in a SOC team, but we deployed the solution for them, and they now run a SOC with only one analyst. They can achieve this kind of maturity through the product's automation.   

The solution's threat intelligence helps prepare us for potential threats before they hit and take proactive steps. Sentinel also features robust threat hunting, which provides indicators of possible attacks and is beneficial information to have.   

Defender for Office 365 saved us time, we have seen many improvements to the product, and Microsoft regularly brings out new features. The tool is at a good point right now and is on the path to improvement. Time saved is in the region of 30-40%.  

It decreased our time for detection and response, especially with its SOAR capabilities. We can activate automated runbooks in a few clicks and block a malicious or unauthorized user in a single click. We rapidly receive alerts, which reduces our response time such that what once took at least an hour can now be resolved in minutes.   

What is most valuable?

The email protection is excellent, especially in terms of anti-phishing policies. 

The solution's information protection around sensitive labels and compliance-related security features are also very valuable.

Defender for Office 365 provides excellent visibility into threats; we can see the attacks and phishing campaigns running against our users from the portal.  

The product helps us prioritize threats across the enterprise, which is essential because most of our clients come to us with alert fatigue. They have so many alerts they often need help determining which ones to work on, and the solution's threat prioritization helps us narrow that down.  

The comprehensiveness of the threat protection provided by Microsoft security products is excellent; we wouldn't use any other third-party security solutions, and it all comes packaged with Azure or an E5 license.    

Microsoft Sentinel enables us to ingest data from our entire ecosystem, which is vital because when we deliver security products for clients, one of their primary requirements is to collect all the on-prem logs and put them in the cloud. Sentinel is capable of this and requires some expertise to operate in this way. 

Sentinel allows us to investigate threats and respond holistically from one place; that's what it's built for. We work offsite as we aren't in the same region as our clients, so the ability to respond remotely is essential to us.  

What needs improvement?

Several simulation options are available within 365, and the phishing simulation could be better.

I want to see improvements that will make the tool easier to operate. 

For how long have I used the solution?

We've been using the solution for one year. 

What do I think about the stability of the solution?

The product is stable. 

What do I think about the scalability of the solution?

Defender for Office 365 is scalable. 

How are customer service and support?

We never had to contact technical support. When we encounter an issue, we can search for a solution on the internet or YouTube, for example, for specific configurations. There's excellent community support available.

Which solution did I use previously and why did I switch?

We didn't previously use a different solution. When I joined the company, we were and remained Microsoft Gold Partners, so we don't have any other third-party tools.

How was the initial setup?

I wasn't involved in the initial setup, and the solution is lightweight in terms of maintenance. A yearly configuration review is sufficient. 

What's my experience with pricing, setup cost, and licensing?

Defender for 365 comes in various plans and licenses, along with other Microsoft security solutions. Purchasing this kind of package or security bundle gives good value for money, and that's what I recommend.

To a colleague who says it's better to go with a best-of-breed strategy rather than a single vendor's security suite, in terms of pricing, it's better to get a good package for security solutions from one vendor rather than multiple vendors.  

What other advice do I have?

I rate the solution eight out of ten.

Multiple integrated Microsoft solutions work natively together to deliver coordinated detection and response across our environment, and we Microsoft Sentinel to our clients. It's a SIEM tool, and once we configure Defender, we can push alerts to Sentinel, which is valuable.   

We leverage Sentinel's SOAR capabilities with the help of Logic Apps, and many libraries are available to make automation easier. However, some complexity is involved in developing Logic Apps, so it requires some expertise.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
PeerSpot user
Reynaldo Ruiz Flores - PeerSpot reviewer
Self Employed, Freelance, Consultor, Sales - Learning Time at SpectralByte
Real User
It's a reasonably priced, scalable cloud-based solution
Pros and Cons
  • "Defender for 365 is a comprehensive cloud-based solution. The value of the cloud is that you aren't alone. Threat intelligence and analytics are shared in the cloud. We don't have to find the solution alone. If you face an unknown threat with traditional solutions like Trend Micro and Symantec, you need to open a case and send your information to them to analyze forensically and identify the source of the attack."
  • "The certification training for Defender for 365 needs to be deeper and incorporate Sentinel. I took all the security courses except one, and Sentinel isn't included."

What is our primary use case?

We primarily use Defender for 365 for email protection.

How has it helped my organization?

My company receives 100,000 emails daily. We implemented Defender to supplement our Broadcom anti-spam solution. Our Broadcom solution wasn't analyzing the server or the body of the messages. 

What is most valuable?

Defender for 365 is a comprehensive cloud-based solution. The value of the cloud is that you aren't alone. Threat intelligence and analytics are shared in the cloud. We don't have to find the solution alone. If you face an unknown threat with traditional solutions like Trend Micro and Symantec, you need to open a case and send your information to them to analyze forensically and identify the source of the attack. 

What needs improvement?

The certification training for Defender for 365 needs to be deeper and incorporate Sentinel. I took all the security courses except one, and Sentinel isn't included. 

For how long have I used the solution?

I have used Defender for three years.

What do I think about the stability of the solution?

Defender for 365 is stable. You can subscribe to all the alerts and notifications of every service in the cloud, and it won't affect the stability. Your devices will be seamlessly updated from the cloud automatically with no problems. 

What do I think about the scalability of the solution?

Defender for 365 is scalable because it's in the cloud. It will give you more resources as needed, whereas the scalability of an on-premise solution is determined by your processing power and other hardware limitations. 

How was the initial setup?

Deploying Defender isn't complex. You only need to buy the license and connect your devices to the cloud. 

What's my experience with pricing, setup cost, and licensing?

Defender for 365 is reasonably priced, but it isn't cheap. I think the price per user is $3 or $6, depending on the license.

What other advice do I have?

I rate Microsoft Defender for Office 365 nine out of 10. Before deploying Defender, you can compare its engine with that of Symantec, Trend Micro, and other brands.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2315811 - PeerSpot reviewer
Security analyst at a educational organization with 1,001-5,000 employees
Real User
Top 20
Comprehensive protection for email security with responsive support and valuable features like attack simulation offering robust threat detection, efficient automation, and excellent scalability
Pros and Cons
  • "Threat Explorer is an invaluable tool for me, and it plays a crucial role in helping me discern the origins of various email campaigns, pinpointing where they emanate from, and identifying the individuals within our organization who are affected."
  • "There's room for improvement regarding the time frame for retrieving emails."

What is our primary use case?

It allows us to effectively detect and manage malicious URLs within emails. This proactive approach allows your team to identify and resolve security incidents promptly. We optimize our security by incorporating Microsoft's IOCs into both Defender for Office 365 and endpoint protection. This integration prevents our devices from accessing known threats, saving significant time weekly. Centralized management of threat indicators proves highly efficient, potentially saving hours. This comprehensive strategy enhances our proactive security measures across our systems.

How has it helped my organization?

When dealing with a large volume of emails, whether received or sent by users, Defender solutions, particularly Threat Explorer, prove to be highly effective. In instances where users may have inadvertently interacted with potentially harmful emails, it enables me to isolate and analyze these emails by placing them in a secure sandbox environment. This insight is crucial for addressing incidents promptly and collaboratively, fostering a cooperative approach to resolving potential security issues within the organization. In Defender 365, we've implemented a dual-pronged approach for automating tasks and managing security incidents. When alerts like a user clicking on a malicious URL occur, data is directed to Sentinel or Log Analytics. A logic app is then employed to analyze the user's actions using Defender for Endpoint, tracking device activities, and making informed decisions. This integrated system enables us to swiftly identify, analyze, and respond to security incidents, enhancing our ability to manage and mitigate potential threats effectively. It has significantly reduced our time to detect and respond to security incidents. While I don't have an exact figure, the impact has been substantial. By consolidating multiple solutions into logic apps and gaining visibility, we can now respond much more efficiently than before. Without this integrated approach, lacking visibility hampers our ability to identify and address potential threats promptly.

What is most valuable?

Threat Explorer is an invaluable tool for me, and it plays a crucial role in helping me discern the origins of various email campaigns, pinpointing where they emanate from, and identifying the individuals within our organization who are affected. The convenience of having a centralized location for extracting comprehensive data is particularly noteworthy. With Threat Explorer, I can efficiently manage and mitigate the impact of these campaigns by removing problematic emails from mailboxes, all in one centralized location, eliminating the need to navigate through multiple areas. Effectively prioritizing threats across our enterprise is crucial for us, given that the primary avenue of attack is often through phishing emails. By having robust protection in place, we're able to significantly mitigate this prevalent threat, essentially clearing a major portion of the cybersecurity landscape.

What needs improvement?

There's room for improvement regarding the time frame for retrieving emails. Currently, the limitation allows users to go back only thirty days when pulling emails or conducting related actions. Enhancing this capability to extend the timeframe, perhaps to sixty or ninety days, would be beneficial.

For how long have I used the solution?

I have been working with it for three years.

What do I think about the stability of the solution?

It has been reliable. I haven't encountered any instances of downtime or significant bugs; occasionally, signing out and back in resolves minor issues.

What do I think about the scalability of the solution?

In terms of scalability, our institution has expanded with more students and staff, and we haven't experienced any performance issues with Defender for Office 365. It has proven to be effective and adaptable to the growth of our organization. We currently have approximately four thousand staff members.

How are customer service and support?

The support team, not only for Defender for Office 365 but for any issues I've encountered, has been exceptional. Whether reaching out through email or submitting a support ticket, I typically receive a callback within hours. I've never personally faced any challenges in contacting Microsoft support—they've consistently been prompt and responsive. The account managers, or whatever they're officially called, have been quick to answer and address any inquiries, making the support experience highly satisfactory. I would rate it ten out of ten.

How would you rate customer service and support?

Positive

What other advice do I have?

I would highly recommend it as it offers numerous features that can significantly enhance your security posture. Overall, I would rate it ten out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Microsoft Defender for Office 365 Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2025
Buyer's Guide
Download our free Microsoft Defender for Office 365 Report and get advice and tips from experienced pros sharing their opinions.