Try our new research platform with insights from 80,000+ expert users
System and network security engineer at Central Bank of Nigeria
Real User
Top 5Leaderboard
Assesses machines for vulnerabilities and gives remediations
Pros and Cons
  • "Microsoft Defender Threat Intelligence assesses machines for vulnerabilities and gives remediations."
  • "The tool's onboarding of users that use on-premise or hybrid environments needs to be improved."

What is our primary use case?

We use Microsoft Defender Threat Intelligence for security. It alerts us on anomalies. 

What is most valuable?

Microsoft Defender Threat Intelligence assesses machines for vulnerabilities and gives remediations. 

What needs improvement?

The tool's onboarding of users that use on-premise or hybrid environments needs to be improved. 

For how long have I used the solution?

I have been using the product for six years. 

Buyer's Guide
Microsoft Defender Threat Intelligence [EOL]
October 2025
Learn what your peers think about Microsoft Defender Threat Intelligence [EOL]. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
870,697 professionals have used our research since 2012.

What do I think about the stability of the solution?

I rate the product's stability a nine out of ten. 

What do I think about the scalability of the solution?

Microsoft Defender Threat Intelligence is scalable. My company has 7000 users for it. 

How was the initial setup?

Microsoft Defender Threat Intelligence's deployment is not straightforward. 

What was our ROI?

We have seen ROI with the product's use. 

What's my experience with pricing, setup cost, and licensing?

The tool is expensive as a stand-alone solution. However, it is not cheap when you purchase it as a bundle. 

What other advice do I have?

I rate Microsoft Defender Threat Intelligence a nine out of ten. 

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
MOHAMEDTRABELSI - PeerSpot reviewer
Senior infrastructure engineer at Cubic Information Systems
Real User
Top 20
Has efficient antivirus features and a simple setup process
Pros and Cons
  • "The product provides efficient email security for sending links and file attachments."
  • "We encounter problems connecting the product deployed on the user endpoints with the servers."

What is our primary use case?

We use the product as a defender for Office 365, endpoints, and security-dependable cloud apps.

What is most valuable?

The product provides efficient email security for sending links and file attachments. It has valuable features for anti-spam and antivirus. It integrates well with Microsoft Sentinel as well.

What needs improvement?

We encounter problems connecting the product deployed on the user endpoints with the servers. Additionally, the license model for the servers needs improvement.

For how long have I used the solution?

We have been using Microsoft Defender Threat Intelligence for two years.

What do I think about the stability of the solution?

It is a very stable product.

What do I think about the scalability of the solution?

Microsoft Defender Threat Intelligence is scalable.

How was the initial setup?

The initial setup is simple. However, it takes a lot of bandwidth to scan the device. It is challenging to deploy backups of thousands of computers. We have to configure the integration between the Defender for the endpoint and the server. The deployment and maintenance process requires one technical engineer to troubleshoot issues by reviewing PCs and setups.

What's my experience with pricing, setup cost, and licensing?

They offer two license plans: Microsoft Defender for endpoints and Microsoft Defender for businesses.

Which other solutions did I evaluate?

I have evaluated Kaspersky.

What other advice do I have?

I advise others to develop a good infrastructure and a vision for security before deploying any product. I rate Microsoft Defender Threat Intelligence a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Microsoft Defender Threat Intelligence [EOL]
October 2025
Learn what your peers think about Microsoft Defender Threat Intelligence [EOL]. Get advice and tips from experienced pros sharing their opinions. Updated: October 2025.
870,697 professionals have used our research since 2012.
AlfonsoNaranjo - PeerSpot reviewer
Senior Technology Consultant at SoftwareONE
Vendor
Top 5Leaderboard
Comes as part of the system and deployment depends on infrastructure complexity
Pros and Cons
  • "I rate the tool's stability a ten out of ten."
  • "Microsoft Defender Threat Intelligence should integrate with different platforms."

What needs improvement?

Microsoft Defender Threat Intelligence should integrate with different platforms. 

What do I think about the stability of the solution?

I rate the tool's stability a ten out of ten. 

How was the initial setup?

The tool's deployment depends on the infrastructure's complexity. I do the deployment for my customers. 

What other advice do I have?

Microsoft Defender Threat Intelligence is part of the system. I rate it a nine out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Oscar Abouchaaya - PeerSpot reviewer
Partner / Consultant at Procomix
Real User
A solution with a variety of applications bolstered by strong features and functionality
Pros and Cons
  • "I value how Threat Intelligence integrates with the different platforms in Microsoft."
  • "I would like to see more AI features and capabilities."

What is our primary use case?

Threat Intelligence is a modern antivirus XDR solution that we use to protect the environment, identities, data, and endpoints from attacks.

How has it helped my organization?

It was an excellent tool for its covered area and protected data, applications and controlled user access remotely.

What is most valuable?

I value how Threat Intelligence integrates with the different platforms in Microsoft.

What needs improvement?

I would like to see more AI features and capabilities.

For how long have I used the solution?

I've been providing the solution to customers for a little over two years.

What do I think about the stability of the solution?

I rate Microsoft Defender Threat Intelligence's stability a ten out of ten.

What do I think about the scalability of the solution?

I rate Microsoft Defender Threat Intelligence's scalability a ten out of ten. We have about 50 customers using the solution.

How are customer service and support?

The technical support for Threat Intelligence is very good.

Which solution did I use previously and why did I switch?

We have previously tried Trend Micro Palo Alto CrowdStrike and several others. We chose Microsoft Defender Threat Intelligence because it has more features and functionalities, is more effective with attacks, and integrates better with different platforms, especially Sentinel, which helped us build a SOC. Threat Intelligence has better reactivity, too, so this solution was what we needed. The other solutions were a bit more complicated and had limitations.

Another interesting thing was how the solution had other data applications, not only endpoints but also identity and so on.

How was the initial setup?

The initial setup is not complicated at all. Threat Intelligence is something engineers can develop and deploy properly. However, the initial setup's difficulty depends on the experience the engineers have with the cases that they need to deploy for, and this is where the skills come into play.

The time taken to deploy the solution depends really on the scenarios. And besides this company, we deployed the solution for small projects, which took less than ten days. There is also integration with Sentinel and third-party tools, so the time to deploy Threat Intelligence depends on what's needed. The deployment, when compared to other solutions, Is not complicated and does not take much time.

What's my experience with pricing, setup cost, and licensing?

The solution can be licensed, but most users would already have it in their Office 365 license. They just need to use it. The solution is very cost-effective and not expensive compared to what other vendors provide. Since the solution is part of a bigger bundle, customers would not have to pay extra.

What other advice do I have?

I rate Microsoft Defender Threat Intelligence a ten out of ten. People planning to implement this solution can confidently choose it. I wouldn't hesitate a minute to renew my license because it's very cost-effective and rich in functionalities. It has more features than other vendors' applications.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer1757103 - PeerSpot reviewer
Cyber Security Manager at a manufacturing company with 1,001-5,000 employees
Real User
Good threat intelligence, straightforward to set up and integrates across the whole Defender suite
Pros and Cons
  • "The user interface is pretty user-friendly."
  • "Technical support could be a bit better."

What is our primary use case?

We primarily use the solution not necessarily from a user point of view. Rather, we use it from an admin point of view. For example, the Log4j vulnerability. Last year, they released threat intelligence information on that vulnerability, put out the protections quickly, and updated their TVM module. It can easily identify what things are vulnerable and what assets you have that are vulnerable to attacks.

What is most valuable?

They seem to be pretty up to date with the latest threats in the world. That's a pretty good aspect.

The threat intelligence piece is pretty good.

The user interface is pretty user-friendly.

The integration integrates across the whole Defender suite, so that's pretty good.

It's very straightforward to set up.

The product scales well. 

What needs improvement?

I cannot recall any issues we've encountered or areas that need improvement.

Technical support could be a bit better. 

Clients might prefer a lowering of the price. 

For how long have I used the solution?

I've used the solution for probably over four years. 

What do I think about the stability of the solution?

The stability has been pretty good. I'd rate it nine out of ten in terms of its reliability. The performance has been great. 

What do I think about the scalability of the solution?

It's very easy to scale as needed. 

We're across the Defender Suite. In terms of analysts that use it, there are five of us.

How are customer service and support?

Technical support is okay. It could be better. 

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We pretty much use all Microsoft, so not much else is used. We use 

Defender for everything, so Defender for the cloud app, Defender for Cloud, Defender for Android and Defender for IOS, Defender for Identity, and others. We also use Microsoft Sentinel. It's all Microsoft stuff.

How was the initial setup?

The solution is very straightforward. It's easy to set up. 

What's my experience with pricing, setup cost, and licensing?

It's bundled into an E5 license, so it comes with a bunch of other things as well. I'd say it's fairly well-priced.

Which other solutions did I evaluate?

We did compare Microsoft Defender Threat Intelligence with ESET and Kaspersky, among others. Defender is not necessarily better. However, it just suits our security strategy and risk appetite.

What other advice do I have?

We have a partnership with Microsoft.

I'd rate the solution a nine out of ten. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
reviewer2264217 - PeerSpot reviewer
Testing and Production Engineer at a tech services company with 51-200 employees
Real User
Offers a scalable solution that can be managed without the need for extensive infrastructure handling
Pros and Cons
  • "Microsoft collects trillions of signals from all over the world, which is incredibly valuable. It helps us identify zero-day vulnerabilities and global threats."
  • "One area that can be improved is reducing false positives."

What is our primary use case?

In terms of threat intelligence, let's take Microsoft Sentinel as an example. We onboard threat intelligence from different sources, such as open-source MISP and AlienVault. We also develop our own threat intelligence signals based on the threats we observe. For instance,  Cisco TALOS is another example. 

We integrate all these threat intelligence feeds into Microsoft Sentinel and create detections based on them. For instance, if we integrate threat intelligence data for specific IP addresses, we create detections to monitor for activity from those IPs. We also conduct hunting based on these feeds. 

In addition, we use automated tools like VirusTotal and AlienVault OTX to scan entities, URLs, and API connections when incidents occur, providing results on whether they are malicious or safe. These are some of the integration scenarios we typically work on in terms of threat intelligence.

What is most valuable?

Microsoft collects trillions of signals from all over the world, which is incredibly valuable. It helps us identify zero-day vulnerabilities and global threats. 

The vast amount of threat data that Microsoft gathers globally is a significant advantage. It's built into their protection mechanisms and helps us stay ahead of emerging threats.

What needs improvement?

One area that can be improved is reducing false positives. They could be more finely tuned. For instance, if we see regular alerts from an IP that isn't malicious, we modify those rules and hunt things to ensure we don't produce more false positives. We do fine-grain the environment. Some procedures could be more refined to reduce these false positives. That's a basic issue I've seen with Microsoft products.

For how long have I used the solution?

In terms of Microsoft, almost all Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, and Defender for Cloud, all of these are within the Microsoft ecosystem. I work in a complete Microsoft environment. 

So, starting from Sentinel, all these Defender products come together. We also integrate data from third-party products like firewalls. Essentially, we create a SOC scenario to onboard SOC services based on different products or services. 

I typically work on onboarding SOC services for multiple clients, including Cybercon, cloud security personal management, and cloud security assessment, among other things.

What do I think about the scalability of the solution?

Scalability is well-managed in Microsoft Defender Threat Intelligence. It's a built-in service that doesn't require us to handle the underlying infrastructure. When we use it as a service from a public cloud provider, they take care of the infrastructure management. 

If we were to configure it ourselves, we'd need to set up servers, ensure high availability, and enhance security with load balancers and firewalls. 

However, when using managed services from providers, we don't have to concern ourselves with the underlying infrastructure. So, it's a matter of choice. 

If I were to set it up independently, I'd ensure high availability, robust security measures, and efficient load balancing. But if we opt for managed services, there's no need to deal with the infrastructure intricacies. It really depends on our specific needs and preferences.

How are customer service and support?

The customer service and support are a bit hard to reach. It's sometimes really hard to get a hold of them.

How would you rate customer service and support?

Neutral

How was the initial setup?

Setting up the SOC service from scratch requires a great amount of familiarity, experience, and visibility in the cybersecurity space. You need to understand coverage for identity, applications, endpoints, networks, and more. 

There's the task of understanding the umbrella and defining the architecture, whether it's multi-tenant or single-tenant, and how it's user-based. 

It's complex, especially when onboarding from scratch. So, these kinds of things I do on a regular basis, so I would say making the architecture, defining the coverage thing, tune-up the customer environment, and setting up another 24/7 monitoring service. It's a job which requires a lot of experience and skills.

Given the intricacies and the experience needed, I would rate it as an eight out of ten in terms of complexity.

What about the implementation team?

The deployment duration varies. For Threat Intelligence, it also depends on the platform and the integration data connector you have. If you factor in the entire setup of SOC services, it can take a while. It depends on the number of users, the licenses, and network devices. 

If we're talking about just Threat Intelligence, are they integrating only paid sources, or are they using open source or creating their own Threat Intelligence?  So, taking all those things into account, it takes a fair amount of time to get everything up and running in terms of SOC services.  

What other advice do I have?

The overall product is very good. I've worked with multiple operations using Microsoft's security suite, including Defender. Threat Intelligence is nice. It's flagged numerous security vulnerabilities, even some zero-days. Comparing it to other solutions, it often outperforms. 

Overall, I would rate the solution a nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
System Engineer at CMC CSI saigon
Real User
Top 5Leaderboard
The solution is affordable and easy to set up

What needs improvement?

Improvements could be made in updating and transitioning to the cloud, enhancing internet security, and aligning with customer requirements. The stability of the solution could be improved.

For how long have I used the solution?

I have been using the solution for the past ten years.

What do I think about the stability of the solution?

The solution is generally stable. The stability could be improved.

What do I think about the scalability of the solution?

The solution is scalable. We have 350 users.

How was the initial setup?

The initial setup was straightforward. The deployment process involves licensing, deployment services, engaging with the customer to finalize the design, conducting training, tuning, and ultimately handing over to the IT team.

What's my experience with pricing, setup cost, and licensing?

The pricing is cheaper compared to its competitors.

What other advice do I have?

I recommend using the solution and rate it an eight out of ten.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2339469 - PeerSpot reviewer
Project Manager at a tech services company with 11-50 employees
Real User
Top 20
Offers endpoint protection from malware
Pros and Cons
  • "The product is useful when the end user downloads malware files."
  • "Having up-to-date documentation and real-time reflections in all portals would be beneficial to keep users informed about any changes. Additionally, the frequent changes in Microsoft's UI and the movement of features between different products in the set pose difficulties."

What is our primary use case?

The solution provides endpoint protection from malware. 

What is most valuable?

The product is useful when the end user downloads malware files. 

What needs improvement?

Having up-to-date documentation and real-time reflections in all portals would be beneficial to keep users informed about any changes. Additionally, the frequent changes in Microsoft's UI and the movement of features between different products in the set pose difficulties.

For how long have I used the solution?

I have been using the product for two years. 

What do I think about the stability of the solution?

I rate Microsoft Defender Threat Intelligence's stability a nine out of ten. 

How are customer service and support?

My experience with the support team is not good. It takes ages for them to respond. 

What other advice do I have?

I rate Microsoft Defender Threat Intelligence a seven out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Microsoft Defender Threat Intelligence [EOL] Report and get advice and tips from experienced pros sharing their opinions.
Updated: October 2025
Buyer's Guide
Download our free Microsoft Defender Threat Intelligence [EOL] Report and get advice and tips from experienced pros sharing their opinions.