Try our new research platform with insights from 80,000+ expert users

Microsoft Defender for Endpoint vs Trend Micro Cloud App Security [EOL] comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Feb 8, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
108
Ranking in other categories
Endpoint Protection Platform (EPP) (5th), Endpoint Detection and Response (EDR) (7th), Extended Detection and Response (XDR) (6th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (2nd)
Microsoft Defender for Endp...
Average Rating
8.2
Reviews Sentiment
6.9
Number of Reviews
213
Ranking in other categories
Endpoint Protection Platform (EPP) (2nd), Advanced Threat Protection (ATP) (5th), Anti-Malware Tools (1st), Endpoint Detection and Response (EDR) (3rd), Microsoft Security Suite (3rd)
Trend Micro Cloud App Secur...
Average Rating
8.2
Reviews Sentiment
6.2
Number of Reviews
9
Ranking in other categories
No ranking in other categories
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Robert Arbuckle - PeerSpot reviewer
Security Analyst III at a healthcare company with 10,001+ employees
Automatically isolates threats and integrates with logging to reduce response time
Overall, I would evaluate the Microsoft support level that I receive at probably about a seven, but that depends on the day. It has been spotty. We have had issues where the urgency level of the Microsoft support is not as high as ours, especially during a data breach or potential data breach situation. We have had issues with some of the offshore support being lackluster. One specific thing that comes to mind is we were on a support call with our CISO on the call, and the Microsoft agent, who did not actually work for Microsoft, is one of the vendors that Microsoft uses for support, said, "Just to set expectations, my lunch break is in an hour and I am going to go away then." For us, it was already ten o'clock at night and we had been working on this for a couple of hours, trying to get a security engineer on with us. For him to tell us that he was going to go away and have lunch, it was, "Okay, but go find somebody else if you need to." It was just the lackluster approach, and it seemed like he did not really care. We seem to get a lot of this when we get non-Microsoft support. I can identify areas for improvement with Microsoft Defender for Endpoint, as it is kind of a convoluted mess to try to take care of false positives. Especially when they have been identified as false positives but they keep going off over and over again. It is great for my pocketbook because it generates a lot of on-call action, but I would really prefer more sleep at two o'clock in the morning than dealing with false positives. I would say that the unified portal for managing Microsoft Defender for Endpoint is suitable for both teams as they are all in there. It would be great if they would stop moving things around and renaming things, which makes sense. The new XDR portal is pretty nice. Being able to have it central again inside of the regular Security Center without having to open up two windows is helpful. Overall, I think it is pretty good. There is always going to be something that could be improved, such as alerting and the ability to modify alerts would be a little bit helpful to have. Being able to add more data into the alerts and turn off alerts that are not as useful would be beneficial. It is hard to say what the quantitative impact the security exposure management feature has had on our company's security, because a lot of it is kind of subjective. I think we are sitting at around a fifty percent score still, and a lot of it is just kind of unusual circumstances that we cannot really implement without breaking the organization.
Murali Krishnan L - PeerSpot reviewer
Technical Manager (SOC Operations) at Novac Technology Solutions
User-friendly solution with good scalability
We use the solution to block phishing, spam, and impersonated emails The solution's feature for high-profile users' domains helps us detect impersonated emails. Also, its API-based features help in easy integration. The solution is easy to integrate and has the best feature for high-profile…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cortex XDR lets us manage several clients from the same console, and its endpoint defense is more advanced than traditional antivirus."
"Threat identification and detection are the most valuable features of this solution."
"I've found the solution to be highly scalable for enterprises."
"We can visualize and control the activities in the environment from anywhere."
"It has pretty much everything we need and works well within the Palo Alto ecosystem."
"Their XDR agent and their behavioral indicators of compromise (BIOC) are pretty nice. Their managed threat hunting is also pretty nice. They also have WildFire, which is a service for actively looking for malware. It's quite useful."
"The normal protection was really effective, and we detected situations that if we didn't have Cortex XDR by Palo Alto Networks, it's highly likely that we would have been affected, but it protected the infrastructure."
"After deploying Traps, we saw the performance of the network improve by 65 to 70 percent."
"The solution is highly scalable."
"The most valuable features are that it's easy to use and the updates are very simple."
"The feature I find most valuable in Microsoft Defender for Endpoint is that it blocks the process and keeps the endpoint from getting infected with malware."
"We had certain compliance and usage issues. For example, our company wanted to go with CIS, but we didn't have a proper way of measuring whether the endpoints have the right standards in place or whether they were compliant with CIS. Microsoft Defender was like a one-stop for most things because it gave us the vulnerability and patching scores so that our vulnerability management teams can focus on covering up the vulnerabilities and the patching team can check the vulnerable versions and deploy the right versions."
"The stability keeps getting better and better."
"There are some competitive products on the market, but the best is Microsoft Defender because it's very easy to integrate. That's one reason a lot of clients want Microsoft Defender. It's also very easy to implement compared to other solutions."
"Microsoft Defender for Endpoint's most valuable feature is its ease of use."
"It's absolutely free to use."
"Dependable with ease of integration with other security products."
"Trend Micro Cloud App is easy to use and easy to install."
"I find Trend Micro Cloud App Security useful for scanning our email boxes. We can scan them one by one, which is a good feature. It's not just gateway-level protection - we integrate the email system with it. They have special protection and parameters for phishing emails."
"Trend Micro has DLP features in it, which separates it from other solutions."
"The initial setup is pretty straightforward."
"The solution is easy to integrate."
"Our business emails are very important and Trend Micro Cloud App Security has provided a high level of protection. Additionally, there are updating the solution frequently."
"It has more intelligence features than other vendors."
 

Cons

"It is a complex solution to implement."
"I feel that it should not be a licensed activity because a feature should allow us to see applications running on end devices."
"Limited remote connection."
"Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth."
"In reporting they should have a customizable dashboard due to the fact that C-level people don't like reporting to the IT department. They prefer to have a real-time dashboard. That kind of dashboard needs to have various customizations."
"It would be good to have a better way to search for a file within the UI."
"It's not an ideal choice for smaller businesses, as you need a minimum of 200 endpoints to even use the solution at all."
"We would also like to have advanced tech protection and email scanning."
"They should come up with pre-built inner workflows."
"Microsoft Defender for Endpoint can improve by providing more and different types of reports."
"The system can always be simplified and have a better integration check."
"There are likely some technical improvements or features that could be added, however, I cannot say, off the top of my head, what they would be."
"Right now, the solution provides some recommendations on the dashboard but we don't have any priorities. It's a mix of all the vulnerabilities and all the security recommendations. I would like to see some priority or categorization of high, medium, and low so that we can fix the high ones first."
"The product development team makes frequent changes that affect the stability of the solution."
"The documentation could be better. When they update their manuals, sometimes they refer to products by their old names, so it is a little confusing. For example, the documentation might still say "Advanced Threat Protection" instead of Defender for Endpoint."
"The solution could be more friendly for end-users, with different type of scans or scheduled scans for it."
"In the next release, I would like to see the cost go down."
"The pricing of this solution is quite high, about double what other similar solutions cost."
"For improvements, I think it would be great if Trend Micro Cloud App Security could enhance their product to be a single SASE solution. It should be similar to competitors like Palo Alto."
"The solution's technical support services could be better."
"Documentation could be improved; product cost is quite high."
"They should provide separate corporate-level licenses for two to three instances."
"The price of the solution could improve by being lower."
"The granulation of the policy setup needs to be better. Right now, it is too basic."
 

Pricing and Cost Advice

"I don't like that they have different types of licenses."
"It is "expensive" and flexible."
"If one wishes to work with another team or large number of users at a future point, he must purchase a license for them."
"I am using the Community edition."
"Cortex XDR’s pricing is very reasonable."
"Its pricing is kind of in line with its competitors and everybody else out there."
"Our license will require renewal in August, after which the maintenance will continue as usual."
"The price was fine."
"Because Microsoft Defender comes as an add-on, it can be a bit expensive if you're trying to buying it separately. Another option is to upgrade, but the enterprise licenses for Microsoft can also be quite a bit pricey. Overall, the cost of Microsoft Defender compared to that of other endpoint detection solutions is slightly higher."
"Licensing options vary. Some customers buy it as an enterprise agreement and pay yearly. Others buy it as a CSP, so they pay per month. It completely depends on the customer's needs."
"The cost is competitive and reasonable because most of the expense is log analytics, storage, and data consumption and ingestion. These things can be throttled and controlled, so they are highly flexible. Defender has a lot of advantages over competing products."
"Pricing for Microsoft Defender for Endpoint is competitive. Out of the bundle, you will get a lot of security, if I talk about Microsoft E5, for example, and get a lot of benefits. If the customer goes and purchases a different solution, it will cost more, so pricing for Microsoft Defender for Endpoint is quite reasonable at the moment. There isn't any challenge in terms of pricing, for example, I didn't see a customer who pulled back because of the price. Some prices could be negotiable, and sometimes, as a sales point, the two become negotiable, but they don't bill one and pull back because of the pricing. If you have an E5 license, you get everything."
"The price is higher than others because it is doing more than what the others are doing."
"I pay for it through the Windows Professional or Standard license. It is a one-time cost for me, and I use the same license."
"The solution is an open source version and was free with a paid version of Windows 10."
"We have seen ROI. Most of the other competing alternatives will cost up to around $30 per user device. We average 400 devices. Therefore, the amount that we save each year is 400 times $30."
"The cost of the license is on the high side. It's a yearly subscription."
"The solution's price is mid-ranged."
"The pricing of the solution could be better."
"The product's pricing is reasonable compared to other vendors."
"The price of Trend Micro Cloud App Security is expensive for regular users. There are not any hidden fees. First-time users of the solution should purchase implementation packages or professional services."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
884,933 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
9%
Manufacturing Company
9%
Financial Services Firm
9%
Comms Service Provider
7%
Computer Software Company
10%
Manufacturing Company
9%
Financial Services Firm
8%
Government
8%
Performing Arts
13%
Manufacturing Company
10%
Computer Software Company
7%
Financial Services Firm
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business44
Midsize Enterprise20
Large Enterprise47
By reviewers
Company SizeCount
Small Business81
Midsize Enterprise40
Large Enterprise95
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise1
Large Enterprise2
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
Which offers better endpoint security - Symantec or Microsoft Defender?
We use Symantec because we do not use MS Enterprise products, but in my opinion, Microsoft Defender is a superior sol...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never pu...
What is your experience regarding pricing and costs for Microsoft Defender for Endpoint?
I'm not too familiar with the pricing, setup costs, and licensing for Microsoft Defender for Endpoint; it wasn't some...
What needs improvement with Trend Micro Cloud App Security?
For improvements, I think it would be great if Trend Micro Cloud App Security could enhance their product to be a sin...
What is your primary use case for Trend Micro Cloud App Security?
We use the solution for cloud data protection, particularly for email and file-sharing systems. It integrates with Mi...
What advice do you have for others considering Trend Micro Cloud App Security?
We chose the solution because they've been Gartner leaders for over 15 years, have a good customer base, and are a we...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Microsoft Defender ATP, Microsoft Defender Advanced Threat Protection, MS Defender for Endpoint, Microsoft Defender Antivirus
No data available
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Petrofrac, Metro CSG, Christus Health
MedImpact Healthcare Systems, ClubCorp USA, Copa Airlines, Aava, Azra Solutions, BSN INET Co, Ltd, Carhartt
Find out what your peers are saying about Microsoft Defender for Endpoint vs. Trend Micro Cloud App Security [EOL] and other solutions. Updated: July 2024.
884,933 professionals have used our research since 2012.