Try our new research platform with insights from 80,000+ expert users
reviewer2315670 - PeerSpot reviewer
Systems Manager at a energy/utilities company with 1,001-5,000 employees
Real User
Dec 20, 2023
Efficient protection against emerging cyber threats providing unified threat detection, incident response, and significant cost savings while streamlining operations
Pros and Cons
  • "The incident threat response and its ability to facilitate effective remediation against threats are the standout features."
  • "Stability could be improved by avoiding frequent changes to the interface."

What is our primary use case?

It is an integral part of our security infrastructure, primarily serving to monitor both our server and client environments comprehensively.

How has it helped my organization?

Its strength lies in providing a holistic view of the protection it offers. When a threat is detected, the system not only identifies the nature of the threat but also provides valuable insights into how and why it was detected. This thorough understanding empowers us to take well-informed steps to remediate the threat effectively. The unified Microsoft environment enhances overall ease of use, making it considerably simpler for our team members to collaborate and work efficiently, given our familiarity with Microsoft products. Unified identity and access benefits stand out as crucial, especially as we delve deeper into compliance considerations. The increasing importance lies in having a centralized view, streamlining visibility through a single interface rather than navigating across various sections in Defender.

What is most valuable?

The incident threat response and its ability to facilitate effective remediation against threats are the standout features. I haven't encountered a similar level of comprehensive incident response in other solutions before.

What needs improvement?

Perhaps there's room for visual enhancements to make the platform more appealing. Stability could be improved by avoiding frequent changes to the interface.

Buyer's Guide
Microsoft Defender XDR
December 2025
Learn what your peers think about Microsoft Defender XDR. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,371 professionals have used our research since 2012.

For how long have I used the solution?

We have been working with it for approximately a year.

What do I think about the scalability of the solution?

It has proven to be scalable within our organization, which, while not exceptionally large, consists of around eight hundred users globally. It strikes a balance, meeting our needs effectively without being overly complex.

How are customer service and support?

The technical support is generally good, but we sometimes find the first-line support process a bit cumbersome. After initiating a case, we, as experienced professionals, go through the standard script diligently (ABC), only to find that first-level support requests the same steps again. While I understand the need for thorough troubleshooting before escalation, it can be time-consuming. I would rate it six out of ten.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

Compared to antivirus or security products such as Trend Micro or McAfee, Microsoft Defender XDR appears notably more user-friendly and offers a clearer interface. The adoption of Microsoft Defender allowed us to phase out the use of other security products, including our long-standing reliance on McAfee and Trend Micro. The transition was prompted by the effectiveness of Advanced Threat Protection offered through Microsoft Defender 365. The decision to consolidate under Microsoft's umbrella proved advantageous, making the adoption process smoother and more efficient for our organization.

How was the initial setup?

The initial setup wasn't overly complicated. We only needed to create a few scripts, which were then executed on our local machines within the environment. This process seamlessly integrated the machines into Defender within our tenant.

What about the implementation team?

We use a third-party software tool for executing scripts and deploying software packages.

What was our ROI?

We've achieved significant cost savings, primarily in the realm of security. As Microsoft continues to enhance Defender, we anticipate further opportunities to streamline and consolidate various aspects of security monitoring and software under the Microsoft umbrella. I'd estimate the savings to be in the tens of thousands of dollars annually.Considering our relatively small team of around thirty IT professionals, especially those at the first level primarily using security products like Defender, the streamlined access within the same application prevents them from having to navigate through multiple applications. This efficiency translates to a potential saving of around a dozen hours per month per individual.

What's my experience with pricing, setup cost, and licensing?

Understanding the subscription model has been a bit challenging, as every feature or requirement comes with an additional cost.

What other advice do I have?

Overall, I would rate it eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer1945362 - PeerSpot reviewer
Consultant at a tech services company with 1,001-5,000 employees
Real User
Sep 7, 2022
Provides good insights, allows us to prioritize threats, and comes with a centralized portal
Pros and Cons
  • "The EDR features are valuable. By getting the EDR features, we have more control over the device. We have information about events in real-time and more protection against zero-day threats and zero-day vulnerabilities. We can monitor every event or action that a device is going through. We can get an idea if it is something malicious or if we have to take any actions."
  • "The onboarding and offboarding need improvement. I work with other vendors as well, and they have an option to add a device or remove a device from the portal, whereas with Microsoft 365 Defender, we need to do that manually. However, once you do that, everything can be controlled through the portal, but getting the device onboarded and offboarded is currently manual. If we have an option to simply remove a device from the portal or get a device added from the portal, it would be more convenient. The rest of the features are similar. This is the only area where I found it different from others. I would also like to be able to simply filter with a few of the queries that are already there."

What is our primary use case?

Microsoft 365 Defender is an extension of Windows Defender. Windows Defender is an AV that is integrated with Windows OS, and with this extension, you also get the EDR functionality for security purposes. Microsoft 365 Defender gets more access to the device and provides more insights and control over that. Apart from the Windows platform, it also includes other OSs, such as Linux and macOS.

We do have multiple options for deployment. We did deploy it on the cloud. We got the on-cloud license, and we onboarded our devices to the portal. The portal is deployed on the Azure cloud.

How has it helped my organization?

It helps us prioritize threats across the enterprise. We also have options to prioritize a specific device and monitor it. We can keep a device on high alert or on the watch out for each and every event. There are different severity levels, such as critical, high, medium, and low. We can set severities on any of the devices. Based on the set severity level, Microsoft 365 Defender can track events, and we can monitor those events from the console.

We get more insights and more information about the devices that we have. Because most of them are Windows devices, we have integrations with Intune or SCCM. It is easy to transfer all the information and see everything in one single portal. If we want to configure anything or control the devices in the whole organization, it is easy because all of them are in the same environment. It is easy to manage and control them.

There are fewer compatibility issues and errors and a better ability to track events. With third-party solutions, I used to see more issues related to compatibility and setting the ports. For each and everything, we had to either go through the support documents or through the support to get information. Most of the Microsoft documentation is publicly available. It is not that you only get that when you open a support case. That's an advantage compared to others.

It helps to automate routine tasks and the finding of high-value alerts. We have KQL or SQL queries that we can set up. We can schedule them so that it automatically queries for a specific device or all the devices and gives us a report that we can simply export.

Its threat intelligence helps to prepare us for potential threats before they hit and take proactive steps. It has helped us to recover a few devices. Because it is integrated with the OS, we get information about failed logins.

It saves time and manual labor. Previously, we used to use a deployment portal such as Filezilla or GPOs. We used to manually update the signatures, but now, it is automatic. It saved me pretty much half a day's work.

It has decreased our time to detect and our time to respond. It has saved half a day's work. The sensor constantly connects to the console. In case of an issue, we get an email immediately. We also get a notification in the console. Previously, we used to manually scan the device or query something and then get the results. Because it is automated, we don't need to manually do that. Previously, we used to manually isolate or block a device, or we used to work with different teams to get the device offline, but now, we can simply search the device name in the console and isolate a device from there, which is convenient for us.

What is most valuable?

The EDR features are valuable. By getting the EDR features, we have more control over the device. We have information about events in real-time and more protection against zero-day threats and zero-day vulnerabilities. We can monitor every event or action that a device is going through. We can get an idea if it is something malicious or if we have to take any actions.

Because Microsoft 365 Defender is integrated with the OS, we get more insight into the events or threat activities. With a third-party solution, we could have some limitations or compatibility issues with the OS, whereas with Microsoft 365 Defender, there are no compatibility issues for Windows, and we get more insights and more information on the threats simply by logging into the console.

What needs improvement?

The onboarding and offboarding need improvement. I work with other vendors as well, and they have an option to add a device or remove a device from the portal, whereas with Microsoft 365 Defender, we need to do that manually. However, once you do that, everything can be controlled through the portal, but getting the device onboarded and offboarded is currently manual. If we have an option to simply remove a device from the portal or get a device added from the portal, it would be more convenient. The rest of the features are similar. This is the only area where I found it different from others. I would also like to be able to simply filter with a few of the queries that are already there. 

For how long have I used the solution?

It has been almost three months.

What do I think about the stability of the solution?

I would rate it a seven out of ten in terms of stability. It is quite stable but it can be improved for a few scenarios. It is still new for macOS and Linux, and for these OSs, I would rate it a six out of ten in terms of stability.

What do I think about the scalability of the solution?

It is scalable. We are using it pretty extensively. It is for multiple departments, and there are multiple teams handling it. In the tenant I have, there are 2,000 devices that are currently onboarded. We also get information about which devices are not onboarded. I can see that a few hundred devices are not onboarded. We also have a few other clients or partners who are using it but on a small scale. 

How are customer service and support?

It is good. We do get constant responses and inputs from them whenever we raise a case. They are quite helpful. I would rate them an eight out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I started working with this solution because I changed my organization. That was the major reason. 

Being able to get the information simply from a single portal and the integration with other portals have been some of the benefits. Previously, we used to get data manually, and then we used a SIEM or event collector to send that data to other portals. Now, we can integrate with other Microsoft portals, such as Intune, and get the same information there as well. That's one convenience I have found.

How was the initial setup?

I am not involved with tenant deployment. I am involved with the onboarding of the devices. If you have the right knowledge, it is completely fine. They do have an admin console. You can deploy multiple tenants and also control through that console, but I don't have access to that. I only have access to my own tenant. I only have control over that. We can also include a tenant for a specific organization from the admin console. That admin console is deployed on Azure.

Most of the maintenance is automatic. Because we allow Windows updates, most of the Defender updates are also included in Windows updates. We don't have to specifically go and check. If we see any alert or we find any suspicious events or something on the console while we are investigating, then it might need manual checks. We do get some recommendations through the console itself for what we can do to improve the device security score. So, it requires some maintenance, but that's only when we detect something or we are investigating something. For maintenance, we have different teams in each section. We have around 15 to 20 people.

What was our ROI?

I don't have the metrics, but we started to see its benefits within a couple of weeks from the time of deployment.

What's my experience with pricing, setup cost, and licensing?

Its licensing and pricing are handled by someone else. My role is limited to incidents or issues with the portal, but you get what you pay for. It is worth the cost.

Which other solutions did I evaluate?

We did compare it with VMware Carbon Black and McAfee. We did check Symantec as well, but Symantec didn't have EDR capabilities. So, we dropped it. The final call was Microsoft because we found the integrations and other things easy. It saves time for us because we don't need to go through another team or get a separate team involved just for data transfers.

What other advice do I have?

I would definitely recommend this solution. Getting the product is easy. You simply get the license, but after getting the product, you need to go through the deployment and configuration of the product to match your environment. You can just try out the product and experiment in your own way and learn each and every feature. The documentation is completely public. 

I would rate it an eight out of ten because there are a few areas where it can be improved.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Microsoft Defender XDR
December 2025
Learn what your peers think about Microsoft Defender XDR. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,371 professionals have used our research since 2012.
Guilherme Queiroz - PeerSpot reviewer
Cyber Security Analyst at a tech services company with 10,001+ employees
MSP
Aug 15, 2022
Eliminates looking at multiple screens, giving us one XDR dashboard, and that saves time
Pros and Cons
  • "We also use Microsoft Sentinel, Defender for Cloud, Defender for Identity, and Microsoft Defender for Cloud Apps. They are all integrated and it was very easy to integrate them. In my experience with the integrations, it was just a click of a button and things were integrated. It's just a button."
  • "There are other SIEM solutions that are easier to use, mainly based on the creation of rules, use cases, and groups."

What is our primary use case?

It's the main tool that we use for the customer that we support. We don't use any other tools to monitor the environment.

How has it helped my organization?

It helps us prioritize threats.

In addition, Microsoft Sentinel enables you to ingest data from your entire ecosystem. One of the main reasons we use Sentinel is to receive logs from different sources and create analytical routines to generate alerts. Sentinel enables you to investigate threats and respond from one place and that is also very important because it becomes part of the monitoring team.

Microsoft 365 Defender has also helped eliminate looking at multiple dashboards, giving us one XDR dashboard. That means we don't have to spend too much time checking different pages. We just have one specific portal with all the information.

The solution has saved us time, although we haven't measured how much. It has reduced our time to detection and time to response by about 20 percent.

What is most valuable?

The most valuable features are the 

  • integration among all the Microsoft tools
  • details of the alerts.

We also use Microsoft Sentinel, Defender for Cloud, Defender for Identity, and Microsoft Defender for Cloud Apps. They are all integrated and it was very easy to integrate them. In my experience the with the integrations, it was just a click of a button and things were integrated. It's just a button.

They work natively together to deliver coordinated detection and response across the environment. We get more details when we integrate more tools, so it's relevant to have integration enabled. When it comes to monitoring an environment, this is very important, because you get different perspectives and points of view on the same alert.

I have a positive impression of the visibility into threats that the solution provides. It brings a lot of information and details related to the alerts or any security threat.

What needs improvement?

There are other SIEM solutions that are easier to use, mainly based on the creation of rules, use cases, and groups.

There could also be an improvement on the customization part. Sometimes we need to customize a few configurations but we can't.

For how long have I used the solution?

I have been using Microsoft 365 Defender for a year and a half.

What do I think about the stability of the solution?

We have never had any problem with downtime.

What do I think about the scalability of the solution?

The scalability is good.

How are customer service and support?

Sometimes, they still take too much time to reply. But when they do reply, it's positive support.

How would you rate customer service and support?

Neutral

How was the initial setup?

I was not involved in the initial setup, but there is no maintenance involved now.

What other advice do I have?

My advice would be to have someone from Microsoft involved in the deployment part to help. There are a lot of details that they have information about, and it's impossible to know everything.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Kyaw Htay - PeerSpot reviewer
Solutions Manager at a tech services company with 11-50 employees
Real User
Apr 9, 2022
Malware and endpoint security solution that is easy to use compared with other similar solutions
Pros and Cons
  • "We are able to consolidate licences and make use of many Microsoft products using this solution. If we have any Microsoft customers, we encourage them to use this solution for enterprise defence."
  • "This solution could be improved if it included features such as those offered by Malwarebytes."

What is our primary use case?

We make use of Microsoft Defender for Office 365 for endpoint security and email and we use Defender umbrella for impersonation and sales. Under Defender umbrella, we use a lot of products depending on the customer requirements. As a company, we use Defender for email as well as for endpoint security.

What is most valuable?

We are able to consolidate licences and make use of many Microsoft products using this solution. If we have any Microsoft customers, we encourage them to use this solution for enterprise defence. 

What needs improvement?

This solution could be improved if it included features such as those offered by Malwarebytes. 

For how long have I used the solution?

We have used this solution for many years and we are a Microsoft partner. We use this solution on a daily basis.

What do I think about the stability of the solution?

This is a stable solution. 

What do I think about the scalability of the solution?

This is a scalable solution.

How are customer service and support?

We have not yet needed to contact Microsoft for support with Defender. 

Which solution did I use previously and why did I switch?

We have previously used a number of different solutions including Trend Micro, Symantec, Sophos Intercept X and Malwarebytes. Overall, we are more comfortable using Defender.

How was the initial setup?

The initial setup was straightforward. 

What other advice do I have?

I would rate this solution a nine out of ten. 

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Alejandro Bartolomeo - PeerSpot reviewer
Country Manager at a computer software company with 51-200 employees
Real User
Apr 3, 2022
Simple for new users, reliable, and scalable
Pros and Cons
  • "Microsoft 365 Defender is a good solution and easy to use."
  • "The support from Microsoft could improve. There are times I have to wait for a response from a qualified specialist."

What is our primary use case?

We have many clients that have large companies in the south region of Mexico. They use the solution for security.

What is most valuable?

 Microsoft 365 Defender is a good solution and easy to use.

For how long have I used the solution?

I have been using Microsoft 365 Defender for approximately 15 years.

What do I think about the stability of the solution?

Microsoft 365 Defender is a stable solution.

What do I think about the scalability of the solution?

The scalability of Microsoft 365 Defender has been good.

How are customer service and support?

The support from Microsoft could improve. There are times I have to wait for a response from a qualified specialist.

How was the initial setup?

If the solution is deployed using a good specialist with the correct configuration it works very well for normal users.

What about the implementation team?

The amount of people needed for the deployment depends on the number of licenses the customer has. if it is a large company as we have with approximately 8,000 to 12,000 people, we need more people to do customer service in this case. However, for small to medium companies, we have two people that do the implementation.

What's my experience with pricing, setup cost, and licensing?

We have a lot of problems in Latin America regarding the price of Microsoft 365 Defender, because the relationship between dollars and the money of the different countries, it's is a lot. Many customers that have small businesses say that they would like the solution but it is too expensive. However, large companies do not find the cost an issue.

What other advice do I have?

I rate Microsoft 365 Defender an eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
IT System Administrator at a aerospace/defense firm with 1,001-5,000 employees
Real User
Feb 27, 2022
Reliable, good support, and simple upgrading
Pros and Cons
  • "Microsoft 365 Defender is simple to upgrade."
  • "The user interface of Microsoft 365 Defender could improve. They could make it simpler."

What is our primary use case?

We use Microsoft 365 Defender to help secure threats of the Office package, such as Word, Excel, and PowerPoint. Additionally, it can fix issues.

What is most valuable?

Microsoft 365 Defender is simple to upgrade.

What needs improvement?

The user interface of Microsoft 365 Defender could improve. They could make it simpler.

For how long have I used the solution?

I have been using Microsoft 365 Defender for approximately one year.

What do I think about the stability of the solution?

Microsoft 365 Defender has been a stable solution.

What do I think about the scalability of the solution?

We have approximately 1,000 people using this solution in my organization. If we expand then we will increase usage.

How are customer service and support?

The support for Microsoft 365 Defender is good.

How was the initial setup?

The installation of Microsoft 365 Defender was automatic when we did the installation of Microsoft Windows.

What about the implementation team?

My internal IT team does the supporting of the solution.

What other advice do I have?

I would recommend this solution to others.

I rate Microsoft 365 Defender a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2282451 - PeerSpot reviewer
SecOps Engineer at a computer software company with 11-50 employees
Real User
Top 20
Feb 28, 2024
Saves investigation time and provides advanced hunting capabilities
Pros and Cons
  • "Advanced hunting is good. I like that. We can drill down to lots of details."
  • "At times, when we have an incident email and we click on the link for that incident, it opens a pop-up, but there is nothing. It has happened a couple of times."

What is our primary use case?

We are using it for incidents and alerts. It is helpful for threat hunting.

We have tied it to Azure AD or Microsoft Entra, and we are trying to implement it for Linux.

How has it helped my organization?

It saves the investigation time. There is a lot of information about the threats and other things.

What is most valuable?

Advanced hunting is good. I like that. We can drill down to lots of details.

It is user-friendly. It has a lot of parts. For me, it was pretty quick to get a sense of it.

What needs improvement?

It protects from phishing emails, but sometimes, some of the emails are not detected. They are getting delivered into the inbox, not in a junk folder or spam folder. Users are reporting them as phishing emails.

At times, when we have an incident email and we click on the link for that incident, it opens a pop-up, but there is nothing. It has happened a couple of times. 

In terms of additional features, it is too early for me. I am still learning all the parts. I am just scratching the surface of the tool. One year is not enough to get every detail of it.

For how long have I used the solution?

I have been using Microsoft Defender XDR for about a year.

What do I think about the stability of the solution?

It is stable, but sometimes, we experience an issue. Clicking the link in an incident email opens a small window, but we cannot find anything there. This has happened a couple of times. There is a bug.

Other than that, we have not experienced any downtime or any big issues. It is pretty stable.

What do I think about the scalability of the solution?

We have plans to maximize its usage. We are trying to see how to get the most out of it, but my older colleagues would know more about it. I am still learning it.

How are customer service and support?

I have not contacted them.

Which solution did I use previously and why did I switch?

I am not sure. I am relatively new. I have only been working here for a year. They already had it in place.

I have not worked on a similar tool before. This is my first XDR tool.

How was the initial setup?

It is on the cloud. I am not aware of its deployment because it was already deployed before I joined.

What other advice do I have?

I cannot recommend it because this is the only tool for XDR that I have used. I have not used any other tool, but it is a good tool.

I would rate Microsoft Defender XDR a nine out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2315640 - PeerSpot reviewer
Director of IT at a government with 501-1,000 employees
Real User
Dec 14, 2023
Integrates security into one tool instead of having third-party security tools
Pros and Cons
  • "The product integrates security into one tool instead of having third-party security tools."
  • "The solution does not offer a unified response and standard data."

What is our primary use case?

We use Microsoft Defender XDR to secure data. 

How has it helped my organization?

Microsoft Defender XDR has reduced our security staff. 

What is most valuable?

The product integrates security into one tool instead of having third-party security tools. 

What needs improvement?

The solution does not offer a unified response and standard data. 

For how long have I used the solution?

I have been using the product for three years. 

What do I think about the stability of the solution?

Microsoft Defender XDR is stable. 

What do I think about the scalability of the solution?

The solution is scalable. 

How are customer service and support?

It takes weeks for the support to respond. They are not helpful. 

How would you rate customer service and support?

Negative

How was the initial setup?

Microsoft Defender XDR's deployment was very easy. 

What was our ROI?

We have seen ROI with the tool's use. 

What's my experience with pricing, setup cost, and licensing?

Microsoft Defender XDR's licensing is complicated. 

What other advice do I have?

Microsoft Defender XDR has helped us reduce two full-time employees. 

The solution is our identity source, which protects our identities through Microsoft Intra ID.

The solution helped us save time by not flipping between the systems.  

I rate it an eight out of ten. 

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Microsoft Defender XDR Report and get advice and tips from experienced pros sharing their opinions.
Updated: December 2025
Buyer's Guide
Download our free Microsoft Defender XDR Report and get advice and tips from experienced pros sharing their opinions.