2022-08-26T17:30:00Z
Ammar Jibarah - PeerSpot reviewer
IT Security at Aramex
  • 4
  • 141

Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?

Hi community,

I work as an IT Security person at a large Logistics company.

At the moment, I'm researching these 2 products for my organization: Microsoft Defender for Endpoint and Cortex XDR by Palo Alto Networks.

Most comparisons and reviews I found were done in late 2021 and early 2022.

As of now, considering all Microsoft Updates on their Defender, which product would you prefer to use? What are the pros and cons of each solution?

Thanks for your help.

4
PeerSpot user
4 Answers
ZA
Chief Manager at Arcil
Real User
Top 5Leaderboard
2022-09-07T05:25:19Z
Sep 7, 2022

I have not used Microsoft Defender and only used Cortex XDR by Palo Alto Networks. My experience with Cortex is not good as you need to whitelist each and every exe file of each adn every computer. My recommendation for you is to go for Cynet360 MDR which is far better than Cortex in terms of auto detection and remediation. You will get genuine alert.

Product comparison that may be of interest to you
Remy Ma - PeerSpot reviewer
Network Security Services at ACE Managed Securty Services
Real User
Top 5
2022-12-07T07:08:39Z
Dec 7, 2022

Choosing Microsoft Defender makes the most sense if you already have a Microsoft ecosystem. But in reality, you need an endpoint security solution that is proactive and comes with built-in artificial intelligence capabilities.


I value in-depth visibility across the endpoints, so I prefer CrowdStrike Falcon EDR. It’s the best solution for simplified endpoint detection and response. CrowdStrike EDR comes with advanced features and easily integrates with popular third-party solutions like Splunk and Palo Alto Networks. An easy-to-use and navigate interface reduces the learning curve. Personally, I think CrowdStrike Falcon is easier to use than Microsoft Defender.


MSSPs like ACE Managed Security Services provide Managed CrowdStrike EDR. If you’re looking for hassle-free deployment and a fully-managed solution, you should look into ACE.

MP
Senior CyberSecurity Architect and Mentor at BlueTeamAssess LLC
Reseller
Top 5
2022-09-08T02:48:59Z
Sep 8, 2022

Unless you are using Palo Alto elsewhere in your architecture, I would go with Microsoft if that were the only choice.


However, if you are using another network security issue such as Fortinet or Sophos, I would also look to their endpoint solutions.  They both have EDR and XDR capabilities and the endpoint solutions facilitate synchronization between the endpoint and the network control.


Microsoft has done lots of work in the endpoint space and the Zero Trust world over the past several months.  Defender integrates tightly with the Microsoft Cloud and there is much synchronization that occurs between the physical endpoint and the cloud infrastructure. This means that regardless where the endpoint is physically located it stays connected and controlled by the policies set in the Microsoft cloud.  Very much like the Group Policy Options we became accustomed to with the on premises domain controller.


I know that's a scratch on the surface and there are many other considerations, but you need to seek the solutions that promise management simplicity and the ability to control and protect the endpoints wherever they may be located. 

JH
Director, Customer Success at SecureWorks
User
2022-09-07T13:02:23Z
Sep 7, 2022

I would go for the one with the best independent threat intelligence, a platform that allows you to change, add, move IT and Security infrastructure without impacting your security platform.  I would also place a close attention to storage costs, service levels and the number of resources providing human intelligence on top of machine intelligence for investigation and incident response, all in one platform.  But I am biased ;-)

Find out what your peers are saying about Cortex XDR by Palo Alto Networks vs. Microsoft Defender for Endpoint and other solutions. Updated: January 2023.
670,523 professionals have used our research since 2012.
Related Questions
NC
Content Manager at PeerSpot (formerly IT Central Station)
Dec 15, 2022
Some people say it 's free and comes with Windows 10 and some people say it's expensive. So which is it?
See 1 answer
Navcharan Singh - PeerSpot reviewer
Senior Seo Executive at Ace Cloud Hosting
Dec 15, 2022
Microsoft Windows Defender is a part of Windows 10 and is available at no additional cost. It offers basic protection against malware and viruses. For more comprehensive protection, you can upgrade to a paid subscription to Microsoft Defender Advanced Threat Protection. ADTP is a cloud-based platform that delivers real-time security insights and advanced threat protection for endpoints across your enterprise. It features behavioral detection analytics, anti-ransomware, and anti-phishing technologies. Microsoft Defender ATP starts at $15 per user per month. Volume discounts are available.
Apr 4, 2022
Hi peers, I'm looking for a comparison study between Microsoft Defender for Endpoint and Tanium EDR solutions (with all the pros and cons) .  Can you please share the pros and cons of these products? I appreciate the help! 
See 1 answer
DM
Chief Information Security Officer at a construction company with 10,001+ employees
Apr 4, 2022
I don't. I prefer Cynet to both of them.
Related Articles
NC
Content Manager at PeerSpot (formerly IT Central Station)
Aug 5, 2022
PeerSpot’s crowdsourced user review platform helps technology decision-makers around the world to better connect with peers and other independent experts who provide advice without vendor bias. Our users have ranked these solutions according to their valuable features, and discuss which features they like most and why. You can read user reviews for the Top Extended Detection and Response (XDR...
See 1 comment
Jairo Willian Pereira - PeerSpot reviewer
Information Security Manager at a retailer with 10,001+ employees
Aug 5, 2022
Well, some times ago, EDR agents was moved to XDR but now, XDR is on "peak of inflated expectations", the second of five phases in product development hype. I'd rather wait a little bit, may be ZDR :)
Product Comparisons
Related Articles
NC
Content Manager at PeerSpot (formerly IT Central Station)
Aug 5, 2022
Top 8 Extended Detection and Response (XDR) Tools 2022
PeerSpot’s crowdsourced user review platform helps technology decision-makers around the world to...
Download Free Report
Download our FREE report comparing Cortex XDR by Palo Alto Networks and Microsoft Defender for Endpoint based on reviews, features, and more! Updated: January 2023.
DOWNLOAD NOW
670,523 professionals have used our research since 2012.