We have many clients that have large companies in the south region of Mexico. They use the solution for security.
Country Manager at Arkano Software
Simple for new users, reliable, and scalable
Pros and Cons
- "Microsoft 365 Defender is a good solution and easy to use."
- "The support from Microsoft could improve. There are times I have to wait for a response from a qualified specialist."
What is our primary use case?
What is most valuable?
Microsoft 365 Defender is a good solution and easy to use.
For how long have I used the solution?
I have been using Microsoft 365 Defender for approximately 15 years.
What do I think about the stability of the solution?
Microsoft 365 Defender is a stable solution.
Buyer's Guide
Microsoft Defender XDR
June 2025

Learn what your peers think about Microsoft Defender XDR. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
What do I think about the scalability of the solution?
The scalability of Microsoft 365 Defender has been good.
How are customer service and support?
The support from Microsoft could improve. There are times I have to wait for a response from a qualified specialist.
How was the initial setup?
If the solution is deployed using a good specialist with the correct configuration it works very well for normal users.
What about the implementation team?
The amount of people needed for the deployment depends on the number of licenses the customer has. if it is a large company as we have with approximately 8,000 to 12,000 people, we need more people to do customer service in this case. However, for small to medium companies, we have two people that do the implementation.
What's my experience with pricing, setup cost, and licensing?
We have a lot of problems in Latin America regarding the price of Microsoft 365 Defender, because the relationship between dollars and the money of the different countries, it's is a lot. Many customers that have small businesses say that they would like the solution but it is too expensive. However, large companies do not find the cost an issue.
What other advice do I have?
I rate Microsoft 365 Defender an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner

IT System Administrator at European Space Agency (ESA)
Reliable, good support, and simple upgrading
Pros and Cons
- "Microsoft 365 Defender is simple to upgrade."
- "The user interface of Microsoft 365 Defender could improve. They could make it simpler."
What is our primary use case?
We use Microsoft 365 Defender to help secure threats of the Office package, such as Word, Excel, and PowerPoint. Additionally, it can fix issues.
What is most valuable?
Microsoft 365 Defender is simple to upgrade.
What needs improvement?
The user interface of Microsoft 365 Defender could improve. They could make it simpler.
For how long have I used the solution?
I have been using Microsoft 365 Defender for approximately one year.
What do I think about the stability of the solution?
Microsoft 365 Defender has been a stable solution.
What do I think about the scalability of the solution?
We have approximately 1,000 people using this solution in my organization. If we expand then we will increase usage.
How are customer service and support?
The support for Microsoft 365 Defender is good.
How was the initial setup?
The installation of Microsoft 365 Defender was automatic when we did the installation of Microsoft Windows.
What about the implementation team?
My internal IT team does the supporting of the solution.
What other advice do I have?
I would recommend this solution to others.
I rate Microsoft 365 Defender a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Microsoft Defender XDR
June 2025

Learn what your peers think about Microsoft Defender XDR. Get advice and tips from experienced pros sharing their opinions. Updated: June 2025.
860,592 professionals have used our research since 2012.
Security Solutions Architect at a computer software company with 10,001+ employees
Integrates well, has good native capabilities, and offers flexible configurations
Pros and Cons
- "It gives a lot of flexibility in terms of configuration and customization as per the business requirements."
- "I personally have not seen much evidence of how Defender can enhance the story of zero trust for enterprises."
What is our primary use case?
We have very strong DLP policies. The product will inspect each and every outgoing email and what kind of attachments they have, including if any have business-sensitive information such as outgoing email going to some public domain such as Gmail or Yahoo. If the solution detects this, it'll raise an alarm and notify the required teams. On top of that, the incoming email will scan attachments for any potential malware tech or any phishing link.
What is most valuable?
The native capabilities are quite good as it slips in seamlessly as part of our integration.
It integrates well without AD, Active Directory.
It gives a lot of flexibility in terms of configuration and customization as per the business requirements.
What needs improvement?
These days, in the security industry, there is a buzzword called zero trust. I personally have not seen much evidence of how Defender can enhance the story of Zero Trust for enterprises. Microsoft needs to offer more features here or spread awareness in the industry and the market about how Defender addresses Zero Trust issues.
For how long have I used the solution?
I've used the solution for more than a year now.
What do I think about the stability of the solution?
The stability is good. it's up to the mark.
What do I think about the scalability of the solution?
It's usually scalable.
We're using it on a daily basis.
The solution works for any size of organization. There is no such limitation for Microsoft as the ecosystem they have built doesn't really have a limiting factor. It will work for a small sized up to a big-sized organization. Our company is half a million strong. If it satisfies our needs, then definitely it can satisfy anybody else as well.
How are customer service and support?
I personally have never reached out to technical support as our in-house expertise is good enough.
It's good for the most part, as it is their own homegrown product and they understand it well.
Which solution did I use previously and why did I switch?
We haven't worked with any other products.
How was the initial setup?
The setup is a simple process, however, users can adopt the phase-in approach and start simple and then yeah. For example, over a period of time, you can achieve what you want to achieve, but not in a single shot. You can do it in phases and work everything in slowly.
The amount of time it will take to deploy Defender depends, actually. If a customer is already sure about all the processes and reporting information they require, then to start, it should not take more than a couple of months, including planning.
There is some maintenance required. We need a team to run the show, however, when you compare it to other options, the maintenance requirements are reduced. We typically have a cloud operations team to oversee it, and it's business as usual. Our company is able to provide any needed maintenance services to our clients.
What about the implementation team?
Our company integrates this solution into our client's infrastructure.
What's my experience with pricing, setup cost, and licensing?
We have E3 and E5 licenses for our users and there is the default.
Depending on the user role, the senior people and critical positions have been allocated the E5 licenses and the intermediate users have been allocated E3 licenses.
Whether it is inexpensive or not is not a very straightforward question as, when you compare the total cost, you have to consider the total cost of ownership. It's not only a comparison between two products. You have to see the other dependencies when you deploy any other solution. That said, I would say it is more or less cost-effective.
What other advice do I have?
We are partners with Microsoft.
I'm in a customer-facing role where we propose different email security solutions to our customers. My role demands that I identify the required security solutions for the different needs of our customers.
We are on the latest version of the product.
I'd advise potential new users to define their business requirements first, however, it's likely Defender will need them and provide what they need.
I'd rate the solution at a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
SecOps Engineer at a computer software company with 11-50 employees
Saves investigation time and provides advanced hunting capabilities
Pros and Cons
- "Advanced hunting is good. I like that. We can drill down to lots of details."
- "At times, when we have an incident email and we click on the link for that incident, it opens a pop-up, but there is nothing. It has happened a couple of times."
What is our primary use case?
We are using it for incidents and alerts. It is helpful for threat hunting.
We have tied it to Azure AD or Microsoft Entra, and we are trying to implement it for Linux.
How has it helped my organization?
It saves the investigation time. There is a lot of information about the threats and other things.
What is most valuable?
Advanced hunting is good. I like that. We can drill down to lots of details.
It is user-friendly. It has a lot of parts. For me, it was pretty quick to get a sense of it.
What needs improvement?
It protects from phishing emails, but sometimes, some of the emails are not detected. They are getting delivered into the inbox, not in a junk folder or spam folder. Users are reporting them as phishing emails.
At times, when we have an incident email and we click on the link for that incident, it opens a pop-up, but there is nothing. It has happened a couple of times.
In terms of additional features, it is too early for me. I am still learning all the parts. I am just scratching the surface of the tool. One year is not enough to get every detail of it.
For how long have I used the solution?
I have been using Microsoft Defender XDR for about a year.
What do I think about the stability of the solution?
It is stable, but sometimes, we experience an issue. Clicking the link in an incident email opens a small window, but we cannot find anything there. This has happened a couple of times. There is a bug.
Other than that, we have not experienced any downtime or any big issues. It is pretty stable.
What do I think about the scalability of the solution?
We have plans to maximize its usage. We are trying to see how to get the most out of it, but my older colleagues would know more about it. I am still learning it.
How are customer service and support?
I have not contacted them.
Which solution did I use previously and why did I switch?
I am not sure. I am relatively new. I have only been working here for a year. They already had it in place.
I have not worked on a similar tool before. This is my first XDR tool.
How was the initial setup?
It is on the cloud. I am not aware of its deployment because it was already deployed before I joined.
What other advice do I have?
I cannot recommend it because this is the only tool for XDR that I have used. I have not used any other tool, but it is a good tool.
I would rate Microsoft Defender XDR a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Director of IT at a government with 501-1,000 employees
Integrates security into one tool instead of having third-party security tools
Pros and Cons
- "The product integrates security into one tool instead of having third-party security tools."
- "The solution does not offer a unified response and standard data."
What is our primary use case?
We use Microsoft Defender XDR to secure data.
How has it helped my organization?
Microsoft Defender XDR has reduced our security staff.
What is most valuable?
The product integrates security into one tool instead of having third-party security tools.
What needs improvement?
The solution does not offer a unified response and standard data.
For how long have I used the solution?
I have been using the product for three years.
What do I think about the stability of the solution?
Microsoft Defender XDR is stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
It takes weeks for the support to respond. They are not helpful.
How would you rate customer service and support?
Negative
How was the initial setup?
Microsoft Defender XDR's deployment was very easy.
What was our ROI?
We have seen ROI with the tool's use.
What's my experience with pricing, setup cost, and licensing?
Microsoft Defender XDR's licensing is complicated.
What other advice do I have?
Microsoft Defender XDR has helped us reduce two full-time employees.
The solution is our identity source, which protects our identities through Microsoft Intra ID.
The solution helped us save time by not flipping between the systems.
I rate it an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cloud Sales Specialist at a tech vendor with 201-500 employees
Emerging technologies, stable, but expensive
Pros and Cons
- "Microsoft 365 Defender is a stable solution."
- "Microsoft 365 Defender does not have a unique package with emerging endpoint security technologies, such as EDR and XDR."
What needs improvement?
Microsoft 365 Defender offers emerging endpoint security technologies, such as EDR and XDR and Zero trust approach
For how long have I used the solution?
I have been using Microsoft 365 Defender for approximately two years.
What do I think about the stability of the solution?
Microsoft 365 Defender is a stable solution.
How are customer service and support?
I am satisfied with the technical support.
How was the initial setup?
The solution is included in Windows 10.
What's my experience with pricing, setup cost, and licensing?
Microsoft is not competitive with the pricing of the solution. The competitors are able to offer lower discounts. The price of the solution is higher.
What other advice do I have?
Microsoft 365 Defender is Microsofts first try at a security package as part of Windows.
They are offering different services with Zero Trust security, SIAM security, SOAR security with Azure. They converge all products in the same security center. Microsoft 365 Defender is one strong point to the overall security protection.
I rate Microsoft 365 Defender a five out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. partner
Senior Cloud Architects at Metro Systems Corporation Public Company Limited
Stable, scalable, but machine learning and AI could improve
Pros and Cons
- "I have found the ability to delete unwanted threats beneficial."
- "The solution could improve by having better machine learning and AI. Additionally, the interface, documentation, and integration could be better."
What is our primary use case?
I use the solution for security against system threats.
What is most valuable?
I have found the ability to delete unwanted threats beneficial.
What needs improvement?
The solution could improve by having better machine learning and AI. Additionally, the interface, documentation, and integration could be better.
For how long have I used the solution?
I have used this solution for approximately one year.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
Microsoft 365 Defender is scalable.
What's my experience with pricing, setup cost, and licensing?
The price of the solution is high compared to others and we have lost some customers because of it.
What other advice do I have?
I rate Microsoft 365 Defender a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior IT Executive and Operation at a tech services company with 51-200 employees
A unified enterprise defense suite that's very stable, but the price could be better
Pros and Cons
- "I like that it's stable. It's been stable for a long time, and Microsoft Defender has done a good job there."
- "The price could be better. It'll also help if they can continuously update and upgrade the solution. Every day there's a new virus uploaded into the network, and we have to keep updating it to identify all these things."
What is our primary use case?
The primary use case for Defender is to control the endpoint systems at the user level. On the networking level, we use it to analyze spam and see if any antivirus services are required or if there's a ransomware attack. As of now, I am just using it for monitoring.
What is most valuable?
I like that it's stable. It's been stable for a long time, and Microsoft Defender has done a good job there. I can see a lot of changes to Microsoft 365 Defender when I compare what we have now to what we had from 2007 to 2010. They have implemented a ransomware feature, and if any virus comes into the system, it triggers an alert.
What needs improvement?
The price could be better. It'll also help if they can continuously update and upgrade the solution. Every day there's a new virus uploaded into the network, and we have to keep updating it to identify all these things.
For how long have I used the solution?
I have been using Microsoft 365 Defender since 2007.
What do I think about the stability of the solution?
Microsoft Defender is very stable, and you can see that there is a 99.9% success rate when they give us good service. It's very helpful for configuring anything.
What do I think about the scalability of the solution?
It's definitely easy to scale. However, scalability depends on the plan and requirements.
How are customer service and technical support?
They have their norms and regulations that they use once a ticket is created. Whatever the technical issues are, they normally resolve them within the timeline or some days. They are good at the technical side of things.
How was the initial setup?
The initial setup is totally easy. It's not complex. It takes just a couple of minutes to deploy this solution.
What's my experience with pricing, setup cost, and licensing?
The price could be better. Normally, the costs depend on the country you're located in for the license. When we were in the initial stage, we went with the E5 license they call premium standard. It cost us around $5.20 per month for four users.
What other advice do I have?
I would recommend Microsoft Defender to new users. I would advise them to understand their exact requirements and check if it matches before taking it up.
On a scale from one to ten, I would give Microsoft 365 Defender a seven.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Buyer's Guide
Download our free Microsoft Defender XDR Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2025
Product Categories
Extended Detection and Response (XDR) Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
CrowdStrike Falcon
Microsoft Intune
Microsoft Defender for Endpoint
Fortinet FortiEDR
Microsoft Defender for Office 365
Microsoft Sentinel
Microsoft Entra ID
Microsoft Defender for Cloud
SentinelOne Singularity Complete
Microsoft Purview Data Governance
IBM Security QRadar
Cortex XDR by Palo Alto Networks
HP Wolf Security
Elastic Security
Buyer's Guide
Download our free Microsoft Defender XDR Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the best EDR or XDR product for a company with 9000 employees?
- When evaluating Extended Detection and Response (XDR), what aspect do you think is the most important to look for?
- How do you decide about the alert severity in your Security Operations Center (SOC)?
- Which is better for Endpoint Security: EDR or XDR solutions?
- What are the main differences between XDR and SIEM?
- Why is (XDR) Extended Detection and Response important for companies?
- How do you use the MITRE ATT&CK framework for improving enterprise security?
- What tools and solutions do you use for automated incident response in an enterprise in 2022?
- FortiXDR vs Cortex Pro - which is the best?
- What is Cognitive Cybersecurity and what is it used for?