Try our new research platform with insights from 80,000+ expert users
Giovanni Emerenciano - PeerSpot reviewer
IT Manager at a manufacturing company with 51-200 employees
Real User
Helps our SOC team avoid manual work
Pros and Cons
  • "It gives us visibility into threats and, for endpoints, it helps us to prioritize threats. We used to have a lack of visibility, but now our time to detect and respond has decreased."
  • "About eight months ago, we started to measure the quantity of phishing and spam that we have been receiving, and it has been increasing a lot. That means that protection for our email is not as good as we were expecting."

What is our primary use case?

We have started using Defender on our endpoints, together with the basic Defender for email. We placed Defender on our endpoints through our XDR solution. It's connected to our SOC and the SIEM.

How has it helped my organization?

The fact that it's easy to integrate and implement has helped us to move forward with our project.

Also, on the clients, we have implemented automated identification and blocking, and these help our SOC team avoid doing manual work.

What is most valuable?

It gives us visibility into threats and, for endpoints, it helps us to prioritize threats. We used to have a lack of visibility, but now our time to detect and respond has decreased.

Also, in the beginning, Microsoft Defender for Office 365 saved us time because we had started a completely new company. Now that we are more established, we need another, more advanced solution with more machine learning and artificial intelligence related functionality.

What needs improvement?

About eight months ago, we started to measure the quantity of phishing and spam that we have been receiving, and it has been increasing a lot. That means that protection for our email is not as good as we were expecting.

Now that we have more visibility into threats, our orientation is to have a more top-market solution to give us more visibility and easier ways to respond to the threats that we find and also to identify threats better.

It is not really straightforward to get a lot of information from Microsoft Defender, so we have had to use Microsoft Graph to create some custom views to export custom information.

Buyer's Guide
Microsoft Defender for Office 365
September 2025
Learn what your peers think about Microsoft Defender for Office 365. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
869,832 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Microsoft Defender for Office 365 for four years.

What do I think about the stability of the solution?

The stability is really good. We have never had any problems related to Defender.

What do I think about the scalability of the solution?

The scalability is also very good. It's easy to increase usage, but that's expected.

We are a multinational company, so we have multiple locations, including Brazil and several countries in Europe. We have about 470 end-users.

How are customer service and support?

The technical support is really good. 

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We used Symantec when we were part of a big company. We decided to use Microsoft because it is a fully integrated solution and was embedded in our licenses. We did not take into consideration all the features.

Our company was sold by that big company that we used to be part of and we then consolidated and created a new company about four years ago. We wanted to move forward, as fast as possible, with as much security as possible.

How was the initial setup?

It was really straightforward to set up. We implemented it on our endpoint devices, and then we configured a lot of policies to manage and avoid threats, as well as policies for phishing and the cloud.

The maintenance is mostly related to fine-tuning phishing and other issues and is handled by one or two engineers, but it's not needed frequently.

What about the implementation team?

It was done in-house, with two or three of our resources.

What's my experience with pricing, setup cost, and licensing?

It is much more expensive than using another solution because we have had to include some options and upgrade our license. Be aware of the licensing model, because for certain features you need a different level of licensing.

Which other solutions did I evaluate?

We did not look at other options. The main reason we went with Microsoft was because of the complete integration.

What other advice do I have?

If I were asked whether to go with a single vendor or multiple vendors for security, I would say use multiple vendors. We are using Microsoft for collaboration, email, chat, and security. It's like having the wolf secure your house. Having different vendors would help give you different visibility and data and different people managing different solutions.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1463265 - PeerSpot reviewer
Solutions Architect at a computer software company with 1,001-5,000 employees
Real User
From process efficiency angle, we are definitely seeing benefits
Pros and Cons
  • "Defender for Office 365 has helped eliminate having to look at multiple dashboards and that is the aspect I like most about it. It is simpler, effective, and convenient. The users like the process efficiency."
  • "One area for improvement is integration. For example, when it comes to external SaaS platforms, we were not able to get a lot of information on integrations with such apps for security and authentication."

What is our primary use case?

We use it to monitor user behavior and activity. It also gives us analytics to protect the user identities and extensions stored in Active Directory. For one of the instances that we are managing, we have to sync it with Active Directory and protect user identity.

How has it helped my organization?

It is a basic SecOps tool. It has not increased or improved anything specifically for our organization, but I see it as a must-have for security ops.

It can help automate routine tasks and finding of high-value alerts. Our security operations are not very high-volume, but from the angle of process efficiency, it is definitely a very beneficial product.

Defender for Office 365 has helped eliminate having to look at multiple dashboards and that is the aspect I like most about it. It is simpler, effective, and convenient. The users like the process efficiency.

And there are a couple of aspects, time-wise. One is that the documentation makes everything so easy that we were able to understand it without much external support. The second is how it automates the process and gives everything in one console. It is helping us with process efficiency. I would estimate it is saving us 10 to 15 man-hours per month. But it is more an issue of process efficiency and having the right process in place. It is not for time-savings, primarily.

And it is likely to help us with our time to detect and respond, although we haven't faced one threat yet.

What is most valuable?

It's a little early to tell which features are most valuable, but by default, it gives analytics on user behavior. We have not been able to leverage it fully, but that is one of the interesting features. It's also very simple to use. The documentation has made it quite easy to implement and our team has been able to understand it.

And while we haven't had even one threat incident yet, functionality-wise, Defender for Office 365 can proactively detect threats and prevent them. It is not just a reactive mechanism.

What needs improvement?

One area for improvement is integration. For example, when it comes to external SaaS platforms, we were not able to get a lot of information on integrations with such apps for security and authentication. The awareness of ecosystem information that is provided needs to be better.

For how long have I used the solution?

We implemented Microsoft Defender for Office 365 over the last month.

What do I think about the stability of the solution?

The stability of Defender for Office 365 is competitive.

What do I think about the scalability of the solution?

It is very scalable. I've seen implementations in organizations with thousands of employees.

For us, it is being used across endpoints for all the users in our organization, and it is multi-geographic as well. We are a small organization with only 10 users.

How are customer service and support?

Microsoft technical support is very good. For this particular product we have not reached out to them, but otherwise, we find Microsoft support to be quite good. 

The product itself is so good that we rarely have to raise a support ticket. The product and documentation are self-explanatory and we are able to troubleshoot things ourselves.

How would you rate customer service and support?

Positive

What's my experience with pricing, setup cost, and licensing?

If we had compared it with other vendors, then I would have more to say about the cost, but we didn't. However, standalone, the cost is convenient.

Which other solutions did I evaluate?

We did not explore other vendors. This was a default choice for us.

What other advice do I have?

We have not faced any incidents so we are not able to comment on how well it handles them. But in our organization, we are using basic antivirus software and that aspect is covered in that solution as well. It also has functionality for prioritizing threats but we have not implemented it.

The solution does not require much maintenance. There is the setup and it is mainly a matter of monitoring after that.

When you consider a best-of-breed strategy versus a single vendor's security suite, I prefer a single vendor because of the failure points. If there are interconnected failure points, there is a single vendor to work with to fix them and identify the gaps. And when it is within the same ecosystem, the product releases are compatible with each other and, together, give us more value. While a multi-vendor strategy has its benefits, if we stick to a single vendor for the entire stack, it is a better scenario in which to manage and monitor.

If you're using Office 365, Defender for Office 365 is the default primary choice. There are no shortcomings in it, that I have seen, that should make someone look for an alternate solution. It is the default choice for this particular use case and it serves its purpose.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Microsoft Defender for Office 365
September 2025
Learn what your peers think about Microsoft Defender for Office 365. Get advice and tips from experienced pros sharing their opinions. Updated: September 2025.
869,832 professionals have used our research since 2012.
reviewer2315073 - PeerSpot reviewer
Sr. Manager, End User Experience at a comms service provider with 10,001+ employees
Real User
Top 20
Protects confidential and sensitive information
Pros and Cons
  • "Microsoft Defender for Office 365 helps people to work remotely. It is a secure solution. We don't need to use our company's computers or get VPN connections to the networks. I can control how they share screens and what they send to the devices. It keeps our organizations confidential and sensitive information safe."

    What is our primary use case?

    We use Microsoft Defender for Office 365 for our external developers. 

    How has it helped my organization?

    The tool offers the best experience to meet international contractors. 

    What is most valuable?

    Microsoft Defender for Office 365 helps people to work remotely. It is a secure solution. We don't need to use our company's computers or get VPN connections to the networks. I can control how they share screens and what they send to the devices. It keeps our organizations confidential and sensitive information safe. 

    What do I think about the scalability of the solution?

    Microsoft Defender for Office 365 is scalable. 

    How was the initial setup?

    Microsoft Defender for Office 365's deployment is straightforward. 

    What's my experience with pricing, setup cost, and licensing?

    The product is expensive. 

    What other advice do I have?

    The flexible tool helps hide windows from people trying to control the PC's remote. I rate it a seven out of ten. 

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    PeerSpot user
    Supervisor of IT Infrastructure & Cybersecurity at a comms service provider with 51-200 employees
    Reseller
    Top 5Leaderboard
    Thorough examination of email and URLs for malicious content and great real-time updates
    Pros and Cons
    • "Does a thorough job of examining email and URLs for malicious content."
    • "Configuration requires going to a lot of places rather than just accessing one tab."

    What is our primary use case?

    We are resellers of this solution and Microsoft partners. 

    How has it helped my organization?

    Defender for Office 365 helps in securing your users' email which is the number one method of compromise for most networks.

    What is most valuable?

    The solution does a thorough job of examining emails for malicious content and examines the URLs and potential malicious content in emails. It offers peace of mind with more real-time updates as far as what they're looking for as opposed to a signature-based solution. It's probably the most valuable feature in my mind. I've deployed it for a couple of clients in a 365 environment and it seems to be a pretty solid solution. 

    What needs improvement?

    This is not really a defined product. You have to go to a lot of different places to enable things so it would be nice if you could go to one tab that says 365 Defender for Office 365 or something similar. You would be able to make all the settings and changes there, rather than having to go to lots of different places in the admin center to get it configured.

    Configuring Defender for Office 365 is not as easy as I would like but with some research and patience, you can tweak the solution to meet your needs. There are some pretty good articles online that assist in setting up Defender for Office 365 to meet your needs.

    Creating a path for your Security Awareness Training (SAT) phishing tests to go around the Defender filtering is way too complex for our current solution KnowBe4. But I learned that is a KnowBe4 limitation. Phin SAT has a much easier method of injecting test phishing emails that do not require such acrobatics to configure.

    For how long have I used the solution?

    I've been using this solution for two years. 

    What do I think about the stability of the solution?

    This is a stable solution. 

    What do I think about the scalability of the solution?

    Defender is very scalable, it sits on the 365 environment so however big your 365 environment is, is how much you can expand. We've probably set up 300 or 400 users so far. There's no maintenance and you don't have to deploy updates. It's all taken care of in the background by Microsoft so it's pretty much set and forget it once you get it configured.

    How are customer service and support?

    The support is mostly responsive, but I've had instances going for longer than a week that shouldn't have taken that long.

    Which solution did I use previously and why did I switch?

    There's no specific solution I would relate to, Microsoft just seems like a cleaner solution as opposed to having a third party. We've used some other solutions in the past where we have to send the mail to that solution and then forward it from there to Microsoft. In this case, it all takes place in the Microsoft environment. 

    How was the initial setup?

    Like most Microsoft products, it's not the easiest thing to get installed, but it seems to work once you have it deployed. You can easily do it in half a day, especially once you get familiar with it, but it's not particularly time-consuming. It's best to start out with more lenient definitions so you're not working on every mail, but we can tune it after that. Our in-house IT department deals with deployment. 

    What was our ROI?

    We haven't done any sort of analysis with regard to ROI, but in my mind, if you can stop one piece of ransomware or malware from getting onto your network, it's priceless.

    What's my experience with pricing, setup cost, and licensing?

    The solution is not too expensive. 

    Which other solutions did I evaluate?

    This is the first option I tried. I'm considering looking into others to see if they are easier to set up and manage.

    What other advice do I have?

    I'd highly recommend reading the documentation. It was pretty helpful in getting the solution set up.

    I rate the solution an eight out of 10. 

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    reviewer1547532 - PeerSpot reviewer
    Technical Support Specialist at a recruiting/HR firm with 11-50 employees
    Real User
    Helps prioritize tasks, and keeps our platform secure, but is not user-friendly
    Pros and Cons
    • "The technical support is good and quick to resolve issues."
    • "The UI needs to be more user-friendly."

    What is our primary use case?

    We use the solution to add and move staff when they leave to secure the laptops and other assets for the company. All our contractors work remotely.

    How has it helped my organization?

    The solution helps us prioritize threats across our entire enterprise. 

    I found the prioritization to be effective for the amount I have used it.

    The solution helps us automate routine tasks and find high-value alerts. We use automation to create printers in terms of notifications that notify us when a device is trying to gain access.

    The solution saved us between 24 and 48 hours of time.

    The solution saved us money.

    What is most valuable?

    We are a small Software as a Service company, so when we hire contractors for projects, we usually move on to a different contractor with the relevant expertise. This means we have a lot of contractors coming in and out of the company, and the solution helps to keep our platforms secure when they have finished working by removing their credentials.

    What needs improvement?

    The solution provides us with visibility into threats; however, there is room for improvement in the threat visibility, as it could be more granular, refined, and detailed.

    The UI needs to be more user-friendly. Some of the dashboard views are hard to follow and make the reporting complicated.

    For how long have I used the solution?

    I have been using the solution for two years.

    How are customer service and support?

    The technical support is good and quick to resolve issues.

    How would you rate customer service and support?

    Positive

    What other advice do I have?

    I give the solution a six out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Microsoft Azure
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Rajitha Jayasekera - PeerSpot reviewer
    Associate Tech Lead at a computer software company with 51-200 employees
    Real User
    Helps us target software vulnerabilities and update software sooner
    Pros and Cons
    • "It also gives the vulnerability status according to the versions you have selected. Let's say you have Google Chrome. It mentions the versions it has, and it updates. Within two hours of an update, it is reflected in the dashboard. That's really nice to have."
    • "In one of the reports I can get the exact place where a vulnerable file resides. But for that, I need to explicitly go into the device and check. If they could include that file part in the report, without my having to go to the device itself, that would help."

    What is our primary use case?

    We mainly use it to identify software vulnerabilities. It reports all the software vulnerabilities installed in our web stations and servers.

    How has it helped my organization?

    With Defender for Office 365, we have been able to increase the security posture across our organization. Within the first month of using this product, we realized that benefit.

    When it comes to software vulnerabilities, we can target them and update the software as soon as we see that there is a vulnerability. And then we can make sure that they are updated and check that the update process was successful within a different department. That has really helped us improve our productivity.

    The solution saves us time because we don't have to go here and there to identify things. It's a single portal that has all the details we need. Their support is also good. These features have, again, helped us improve our productivity a lot. It saves us about 25 percent of our time.

    It has also saved us money because we don't have to pay for other security products like Nessus. This solution has almost everything we got from other products, so we don't have to go for an additional solution. It's saving us about 50 percent, cost-wise.

    Our time to detect threats has decreased. With products like Nessus, until their scan runs, we are not aware whether a threat is fixed or not. But with Defender, within one to two hours that information is reflected. With Nessus, sometimes we had to wait a day to see that information reflected in the portal. Because we are aware of issues earlier, we can act on them sooner.

    What is most valuable?

    The most valuable feature is the score. By looking at the score, you can identify if you are at risk or not.

    It also gives the vulnerability status according to the versions you have selected. Let's say you have Google Chrome. It mentions the versions it has, and it updates. Within two hours of an update, it is reflected in the dashboard. That's really nice to have.

    It gives me everything I need, visibility-wise. It also helps prioritize threats across our enterprise and that's very important. That means we can identify the critical vulnerabilities first and keep an eye on other vulnerabilities. By looking at the dashboard, I immediately get an idea of how critical an issue is and we can fix vulnerabilities before they result in an attack.

    It has also helped eliminate looking at multiple dashboards, giving us one XDR dashboard, which has made our security operations really easy. We can also create internal tickets within the portal itself. We can assign them to people and see how long it took them to close the tickets. That makes things really easy.

    What needs improvement?

    In one of the reports, I can get the exact place where a vulnerable file resides. But for that, I need to explicitly go into the device and check. If they could include that file part in the report, without my having to go to the device itself, that would help.

    For how long have I used the solution?

    I have been using Microsoft Defender for Office 365 for about two years.

    What do I think about the stability of the solution?

    It is stable.

    There are bugs here and there, but they have been able to rectify them.

    What do I think about the scalability of the solution?

    It's scalable. It discovers almost all of the workstations and servers across our organization. We have about 3,000 endpoints.

    How are customer service and support?

    Whenever we ask a question, they provide us with a solution. I'm happy with their technical support.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We previously used Nessus. We switched mainly because of the cost and the integration. With Nessus, we had to install an agent, but with Defender, since we were already using it, we could just turn it on with the cloud portal and deploy it very easily.

    How was the initial setup?

    I wasn't involved in the initial setup, but in terms of maintenance, we push it through Windows Update so we don't have to explicitly do any updates.

    What's my experience with pricing, setup cost, and licensing?

    I would recommend Microsoft Defender for Office 365. 

    If you already have a deployment method, like CCM or something similar, it will be easy. Even if not, there are several other deployment methods that could support any scenario.

    Which other solutions did I evaluate?

    We already had an Office subscription, so we just started a trial and we were happy with it and we went with it.

    What other advice do I have?

    In terms of a best-of-breed strategy rather than a single vendor security suite, a single vendor security suite is good when it comes to deployment and manageability. It's easy.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer1030527 - PeerSpot reviewer
    Chief Information Security Officer at a outsourcing company with 10,001+ employees
    Real User
    Deployment capability is a great feature but we're getting too many false positives
    Pros and Cons
    • "The deployment capability is a great feature."
    • "Too many false positives and lacks an accurate capability to detect malicious SharePoint sites."

    What is our primary use case?

    We use Microsoft Defender for Office 365 for email security. We are partners of Microsoft and I'm the company's chief operation security officer. 

    What is most valuable?

    The deployment capability is a great feature. We're able to activate this feature throughout France with a click.

    What needs improvement?

    I'd like to see fewer false positives and potentially have an accurate capability to detect malicious SharePoint sites. There could also be an improvement in some of the features related to training. In a phishing test campaign, for example, it should be more user-friendly and include the capability to evaluate and assess users' understanding of the content provided. 

    For how long have I used the solution?

    I've been using this solution for several years. 

    How are customer service and support?

    The customer support could be more advanced at the technical level and more responsive. There should also be more communication on updates.

    Which solution did I use previously and why did I switch?

    We previously had some reinforced email security features with Microsoft; this is just an improvement on what we had.

    What's my experience with pricing, setup cost, and licensing?

    This is quite an expensive solution and understanding the pricing model and features is quite complicated and it can, in fact, be a nightmare when dealing with Microsoft.

    Which other solutions did I evaluate?

    We reviewed several on-premise solutions such as Forcepoint that could be integrated with other components within our infrastructure. The reason we didn't go with them is that we have to respond quickly to threats and at an international level. Given the complexity of our situation in terms of architecture, we decided to go with a ready-to-use solution.

    What other advice do I have?

    We haven't had a review recently, so I can't say that this is the best solution on the market. Things are evolving all the time with new features constantly being added to all solutions. For now, I would rate this solution seven out of 10. 

    Disclosure: My company has a business relationship with this vendor other than being a customer. partner
    PeerSpot user
    Corporate IT Infrastructure Manager at United Test and Assembly Center Ltd.
    Real User
    Improves security awareness and security posture and blocks known threats immediately
    Pros and Cons
    • "The risk level notifications are most valuable. We get to know what kind of intrusion or attack is there, and we can fix a problem on time."
    • "The visibility for the weaknesses in the system and unauthorized access can be improved."

    What is our primary use case?

    We use it for detecting any kind of breach or intrusion. It is not enabled for everyone because we have our own antivirus.

    How has it helped my organization?

    It has helped us in improving our security posture. It detects any kind of attack or abnormal behavior in accessing the system and sends an alert to the administrator who can check, understand, and review on time to ensure that all activities are legit.

    It blocks all known threats immediately and sends alerts to follow up. It is not used on all devices. On the devices on which it is being used, it has improved the security by 80%.

    It has improved our security awareness. It helped us in understanding the weaknesses in our configuration that needed to be fixed to avoid any kind of breach. It has increased our security level and mitigated the risk of being compromised.

    What is most valuable?

    The risk level notifications are most valuable. We get to know what kind of intrusion or attack is there, and we can fix a problem on time.

    What needs improvement?

    The visibility for the weaknesses in the system and unauthorized access can be improved.

    Its price should be improved. Its cost is a major concern for us.

    For how long have I used the solution?

    We started using it in 2019.

    What do I think about the stability of the solution?

    Its stability is good.

    What do I think about the scalability of the solution?

    Its scalability is good. It is able to leverage more and more functions, which is essential because cybersecurity threats are increasing nowadays.

    Initially, we had only 10 users, and currently, most of the users are switching to another platform. We only have one user, and only the system administrator is managing it.

    How are customer service and technical support?

    I didn't need any tech support because the documentation and the procedures are simple and easy to understand.

    Which solution did I use previously and why did I switch?

    We have Symantec Endpoint Protection, and we also use Sophos. We are using Defender only on our Azure system because it is a suitable tool for the Microsoft environment.

    How was the initial setup?

    Its initial setup is straightforward. Because it is cloud-based, when we assign the license for Office 365, it can be automatically deployed from the console. Because the number was small, we manually installed it on each device one by one. Its deployment requires minimal staff. Depending on the connectivity, it can take about 30 minutes for each device.

    What was our ROI?

    We have not seen an ROI yet.

    What's my experience with pricing, setup cost, and licensing?

    Defender is a little bit more expensive as compared to others. We are in the manufacturing environment. So, we don't have a high budget for all of our endpoint devices. Its cost is a major concern for us.

    What other advice do I have?

    It is a good product, but its price is the most critical point for consideration. In terms of technology and capability, I would rate Microsoft Defender an eight out of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Microsoft Azure
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Microsoft Defender for Office 365 Report and get advice and tips from experienced pros sharing their opinions.
    Updated: September 2025
    Buyer's Guide
    Download our free Microsoft Defender for Office 365 Report and get advice and tips from experienced pros sharing their opinions.