

Trellix Network Detection and Response and Microsoft Defender for Office 365 compete in the cybersecurity sector, focusing on network and email threat detection. Trellix focuses on advanced network-level threat insights, while Defender integrates seamlessly within Microsoft environments.
Features: Trellix Network Detection and Response features advanced threat detection capabilities, detailed malware analysis, and robust sandboxing technology, offering comprehensive insights into application behavior and real-time response. In contrast, Microsoft Defender for Office 365 delivers email security with anti-phishing and anti-malware safeguards, Safe Links, and data loss prevention, ensuring a user-friendly and unified security experience within Microsoft environments.
Room for Improvement: Trellix could improve sandbox customization, better integration with third-party solutions, and cloud capabilities, with users requesting increased granularity in alerts and improved documentation. Microsoft Defender for Office 365 needs to bolster phishing filters, enhance SOC features, offer more proactive threat alerts, better tool integration, licensing clarity, threat visibility, phishing simulation, and cost-effectiveness.
Ease of Deployment and Customer Service: Trellix supports primarily on-premises deployments, suiting organizations seeking internal data management, and offers responsive customer service. Microsoft Defender for Office 365 typically deploys in hybrid or public cloud environments, ensuring easy integration with Microsoft products. Their global support is commendable, though feedback suggests improving the complexity of the setup process.
Pricing and ROI: Trellix Network Detection and Response is considered costly yet offers substantial ROI through improved threat detection and response times, reducing breaches. Microsoft Defender for Office 365's pricing is included within Office 365 packages, potentially more cost-effective for existing Microsoft users, although standalone purchases are seen as expensive. Both solutions highlight significant ROI by preventing breaches and increasing productivity.
It has also decreased our time to detection and response by about 15 to 20 percent.
Overall, cost of owning and operating our system goes down.
It's hard to quantify the return on investment we've seen from Microsoft Defender for Office 365.
Investigations are generally faster because analysts have immediate access to relevant network context instead of manually piecing together information from multiple sources.
The time was reduced because of the automated detections.
If a threat can enter any endpoint that is exposed to the internal network, there is a potential gateway for hackers, leading to a loss of production or significant financial impact to the network.
Over the past two years, there have been no critical problems.
we opened tickets, and they typically resolve them quickly.
With a subscription for Microsoft Defender for Office 365, it is an eight. Without it, it is a six.
The support team was responsive and knowledgeable.
Technical support needs improvement as sometimes engineers are not available promptly, especially during high-severity incidents.
They were constantly relaying our message to the engineering team and the engineering team was looping that back to them and then to us.
We have never faced scalability problems, and Microsoft manages it effectively.
Microsoft Defender for Office 365 scales transparently for us, as we grew from 1,000 users to 3,000 users, and we didn't notice much difference.
Microsoft Defender for Office 365 scales with the growing needs of my company well.
The scalability of Trellix Network Detection and Response is easy; I just have to add another license in the same cloud, and I can easily increase the number of endpoints.
Trellix Network Detection and Response has handled that growth while continuing to provide consistency, visibility, threat detection, and investigation capabilities.
The connectors were always out of sync and we have had multiple noise floods from these connectors which were not configured well.
I would rate the stability of Microsoft Defender for Office 365 as 10 over 10 because it's highly available, it works, and it does the job it is meant to do.
I have not experienced any downtime, crashes, or performance issues because of Defender.
The solution is stable, as we have been using it for the past two years.
In my day-to-day use, it has consistently provided the visibility and detection capabilities we rely on for security monitoring and investigations.
In our experience, it has had a positive impact on our production environment and has proven to be a dependable part of our security operations.
I encounter no issues with health or reliability when the recommended specifications are met.
The main area for improvement is simplifying the implementation and rollout process.
Microsoft could improve by offering recommendations for domain spoofing attacks, especially scenarios where DNS records like SPF, DKIM, and DMARC are not properly published.
There is a different console for different things; I just want one consolidated console.
There should be improvements in AI intelligence, faster decision-making, and a more responsive technical support team.
It would be best if Trellix Network Detection and Response sensors were converted into a next-generation firewall with built-in capabilities for routing, switching, and Layer 7 functionality, as most next-generation firewalls today include these features.
Regarding needed improvements for Trellix Network Detection and Response, there is always room for enhancement in terms of AI capability to include proactive triggers based on historical data, enabling AI to learn patterns and detect threats before they manifest.
We've likely saved 30% of costs.
Money-wise, it is a part of the Office 365 suite, making it slightly more expensive compared to Trend Micro.
Microsoft is quite affordable with a lot of features available for any size organization.
Trellix Network Detection and Response is an enterprise-grade security solution, so it represents a significant investment, but we believe that the value it provides in terms of threat detection, network visibility, and incident response justifies the cost.
The pricing model is not transparent, as they do not provide pricing ranges upfront, complicating the evaluation of costs across regions.
My experience with the pricing, setup cost, and licensing of Trellix Network Detection and Response is that they are very good and affordable for the customer range.
It ranks the threats and allows us to prioritize those hitting us the hardest, such as email threats.
It provides end-to-end visibility on email threats such as phishing, extending beyond Exchange Online Protection.
The value of the DLP feature is significant to us because we have internal data, sometimes sensitive, and the users may not always be aware of security and privacy, which might lead them to send out information mistakenly to external parties.
Per day we used to have 70 to 80 alerts and those could be reduced up to 40 to 30 a day. This is almost a 40 to 50% decrease.
Trellix Network Detection and Response has positively impacted my organization by addressing performance issues, specifically by offloading heavy traffic inspection and SSL inspection through sensors due to the limitations of the firewall.
Visibility is very important as it empowers users to understand what is happening; therefore, detection is one of the strongest features of Trellix Network Detection and Response.
| Product | Mindshare (%) |
|---|---|
| Microsoft Defender for Office 365 | 6.5% |
| Trellix Network Detection and Response | 4.1% |
| Other | 89.4% |


| Company Size | Count |
|---|---|
| Small Business | 24 |
| Midsize Enterprise | 11 |
| Large Enterprise | 32 |
| Company Size | Count |
|---|---|
| Small Business | 35 |
| Midsize Enterprise | 11 |
| Large Enterprise | 23 |
Microsoft Defender for Office 365 offers real-time email security, enhancing threat detection through integration within the Microsoft ecosystem. Its user-friendly interface and central management streamline operations, providing robust protection against phishing, ransomware, and malware.
Defender for Office 365 is focused on efficiently securing email communication by safeguarding against phishing, malware, and spam threats. With its strong integration with other Microsoft services, it is tailored to improve endpoint security and identity protection. Its centralized management tools simplify threat prioritization, while the automated threat response capabilities ensure swift actions against potential risks. Organizations leverage its capabilities to efficiently manage their cybersecurity efforts, particularly in remote work environments, while maintaining a secure system across Office 365 applications and Azure-hosted services.
What are the key features?Implementations of Defender for Office 365 vary across industries, optimizing email security for sectors such as finance, healthcare, and education. In finance, it aids in protecting sensitive financial data from phishing and fraud. Healthcare benefits from secure communications, ensuring patient data privacy. Educational institutions use it to maintain secure virtual learning environments against cyber threats.
Trellix Network Detection and Response provides robust threat protection with advanced detection of zero-day attacks and APTs. Its user-friendly dashboard and real-time response capabilities enhance security and visibility across networks.
Trellix Network Detection and Response stands out with its MVX engine, leveraging virtual machines for comprehensive behavioral analysis. The solution supports detection of advanced cyber threats through features like sandboxing and application filtering, offering real-time response and packet capture for detailed contextual insights. Companies benefit from seamless integration with other platforms, enhancing usability and overall protection. User-friendly interfaces improve network visibility, while stability and ease of configuration safeguard against both signature-based and signature-less threats.
What key features does Trellix offer?Companies in sectors like finance, healthcare, and enterprise security utilize Trellix Network Detection and Response for tasks such as network intrusion detection, endpoint protection, and securing data transmission paths. It aids in threat investigations, pre-sales demos, and network forensics, reducing risks by protecting against cyber threats like phishing.
We monitor all Advanced Threat Protection (ATP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.