No more typing reviews! Try our Samantha, our new voice AI agent.

Microsoft Forefront [EOL] vs Symantec Endpoint Security comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Microsoft Forefront [EOL]
Average Rating
8.4
Number of Reviews
8
Ranking in other categories
No ranking in other categories
Symantec Endpoint Security
Average Rating
7.6
Reviews Sentiment
6.8
Number of Reviews
146
Ranking in other categories
Endpoint Protection Platform (EPP) (8th)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
it_user772620 - PeerSpot reviewer
Systems Consultant at a tech services company with 501-1,000 employees
There is simplicity in the management of the product compared to its competitors
Web proxy services along with the integrated firewall VPN Intrusion prevention Malware inspection URL filtering The simplicity of managing the product compared to its competitors, like BIG-IP F5 and Citrix NetScaler The ease of deploying mobile functionality through the web proxy has…
Abhimanyu Das - PeerSpot reviewer
Senior Cybersecurity Engineer at Kyndryl
Behavioral protection has blocked ransomware and now saves extensive recovery and audit time
The best feature of Symantec Endpoint Security is its effectiveness in malware protection. Its malware protection capabilities stand out due to their ease of management. Although multiple tools assist in this process, managing them all can sometimes be challenging. In terms of malware protection, Symantec Endpoint Security performs well, and its mechanisms, tactics, and techniques are effective. Symantec Endpoint Security offers robust features such as advanced reporting capabilities with a customizable dashboard that integrates EDR timelines, threat maps, and compliance metrics into a single view. Additionally, reports can be exported to PDF or CSV formats, making reporting one of its strong points. It also provides comprehensive device control features, which block unauthorized USB devices and support whitelisting. This helps prevent data exfiltration and phishing scenarios without disrupting user workflows.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"One thing that I like about Cortex XDR by Palo Alto Networks, it is detecting all the suspicious or malicious binaries, and it has integration with Palo Alto Firewall."
"Cortex is the best tool for endpoint detection, and I have used it to verify hashes or domains to identify malicious activity, trigger playbooks that automate and gather endpoint logs, block malicious processes, and update incident tickets, showcasing end-to-end processes with automation in investigation and reducing the analysis workflow."
"The biggest positive impact I see from Cortex XDR by Palo Alto Networks is a significant reduction in the number of people required to manage it."
"The user interface of the solution is sophisticated and straightforward."
"The product's initial setup phase is very easy."
"The dashboard is customizable."
"The product has an intuitive dashboard."
"From the Palo Alto side, whatever they buy, they integrate that really well into their integration suite, and that makes a massive difference."
"Our ROI is that we can provision users accounts within 30 minutes of them being put into the system."
"The snort engine, which is the muscle behind the Sourcefire IPS technology, has always been a joy for me to work with."
"It has automated the entire user and group management process, thus reducing manual work and help desk cost to a great extent."
"To date we have not had a virus infecting a desktop with Forefront installed - this is the main reason why we will not use another anti-virus solution."
"Product has been enough for our customers’ requirements."
"The simplicity of managing the product compared to its competitors, like BIG-IP F5 and Citrix NetScaler, is a valuable feature."
"Performance wise, it's one of the most effective anti-virus solutions we have ever used."
"It cost us approx. US$250k to set up and is roughly US$200 day to day."
"It is a solid antivirus security product."
"Protection from viruses, malware, Trojans, and malicious files is most valuable. It is also good in terms of application control. I can control the type of external media that can be connected with endpoint devices and protect them from malicious files and devices such as USB."
"The most valuable feature is that I don't feel that it is there."
"Symantec have everything – documentation, videos, data sheets."
"For what we are paying for, which is a signature-based antivirus, the product is fine."
"Basic features, as in every AV solutions, the virus and spyware protection are very good compare to other AV solutions in market."
"Offers good antivirus and local firewall."
"Almost all threats are detected by Symantec, which is a very good feature."
 

Cons

"Impact on system performance is horrible, adding a lot of delays for users."
"Cortex XDR could be improved with more GUI features."
"Currently, we are monitoring all USB drives and ports but we would like to improve our device control capabilities."
"The solution needs better reports. I think they should let the customer go in and customize the reports."
"The solution should add unwanted malicious hash values to a block list so that whenever the action is triggered, it will automatically prevent the malicious content."
"The deployment is pretty hard."
"It is an enterprise-level solution. Its price could be less expensive."
"Whenever the tool releases a new version when deploying the product across the organization, I feel like there are some disturbances in the CPU usage after upgrading the tool to the latest version."
"More out of box connectors and conducting awareness of the product along with more marketing."
"The product has unfortunately reach its End-Of-Life (EOL) at Microsoft and is now replaced by several products."
"Pretty awful. A large initial investment with something that could have been done by one person full time over six years with less hassle."
"Without a local Windows Update Server, the client seems to update very slowly and may take a lot of time."
"When using Forefront in a domain network, it is quite difficult to create the group policies needed for definition/engine updates using WSUS."
"One of the biggest pain points was that username changes were not automated and caused problems."
"Web user interface from 1990s. Users laugh at it."
"I’d personally like to see some additional customization capabilities in the reporting section."
"The device can be outdated. More enhancement of network and discovery would help already great features."
"It would be interesting if Symantec Endpoint protection could also manage Windows Defender. If they were to add a feature, it would be nice if you could see the Symantec client and the Windows Defender client in case you choose to deploy both."
"We were having a problem in Version 14, where the client machines used to go into the health state and once it restarted, and never came back again."
"We are essentially left with a vulnerability."
"The malware and ransomware protections could be improved, which was ultimately the reason why I stopped using the solution."
"They provide the updates of the client, and those clients need a reboot after the upgrade, which is something we don't like. We don't like to reboot the server after the upgrade because we have live applications. If we do a reboot, it can impact the business as well."
"Its interface needs improvement. Its interface is very old, and it needs a new look. Other solutions, such as Sophos and BitDefender, have a better and more modern interface, whereas Symantec has had the same interface for a while. There has been no enhancement in the interface. They should update and provide a better interface in 2022 for a better user experience for their customers."
"It seems that its not working very well with VMWare."
 

Pricing and Cost Advice

"The solution has one subscription for endpoint protection and one subscription for detection and response. The two licenses combined give you the BRO version."
"It is cost-effective compared to similar solutions. It fits for the small businesses through to the big businesses."
"Licensing for Palo Alto Networks Cortex XDR can be costly, especially when it comes to a hundred users. A license is required for each user, and the subscription must be renewed on a yearly basis."
"The solution is expensive. It's pricing is on a yearly-basis."
"The price of the product is not very economical."
"It is present, but when compared to other competitive products, I would say it is not less expensive; however, when all of the other added values are considered, the price is reasonable."
"If one wishes to work with another team or large number of users at a future point, he must purchase a license for them."
"The cost depends on your chosen license type, like Pro or other licenses."
Information not available
"The licensing is okay. Symantec has a very granular licensing model, so you only buy what you need."
"Licensing is per user. Therefore, it makes it easy to do licensing."
"Zero-day threat or advanced attacks should be part of the endpoint. The product should not require you to buy a separate license."
"Licensing is based on a yearly subscription."
"Compared to other products and brands here in Mexico, the price is okay, somewhere in the middle. Our solution is unique in that it can adapt to a variety of pricing and licensing constraints considering we have the corporate, government, and academic mandates. The"
"Each annual client license is around 1200 or 1600 INR."
"Symantec Endpoint Security is an expensive solution."
"The price of Symantec End-User Endpoint Security is okay. When comparing the price of this solution is not expensive."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
913,683 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Financial Services Firm
9%
No data available
Outsourcing Company
13%
Comms Service Provider
13%
Financial Services Firm
9%
Construction Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise4
Large Enterprise2
By reviewers
Company SizeCount
Small Business69
Midsize Enterprise32
Large Enterprise63
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
Ask a question
Earn 20 points
Which is better - Cortex XDR or Symantec End-User Endpoint Security?
Aqua Security is easy to use and very manageable. Its main focus is on Kubernetes and Docker. Security is a very valu...
Which offers better endpoint security - Symantec or Microsoft Defender?
We use Symantec because we do not use MS Enterprise products, but in my opinion, Microsoft Defender is a superior sol...
What is your experience regarding pricing and costs for Symantec End-User Endpoint Security?
Symantec Endpoint Security's pricing is better than most offerings based on my research. It seems to be half the cost...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
MS Forefront [EOL]
Symantec EPP, Symantec Endpoint Protection (SEP)
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
EUROVIA CS, a. s., King Abdullah Bin Abdulaziz Public Education Devel, Bank Alfalah Ltd., CLEAResult, St. Lucie County Public Schools, Wiltshire Council
Audio Visual Dynamics, Red Deer Advocate, Asia Pacific Telecom Co. Ltd., Kibbutz Ein Gedi, and AMETEK, Inc.
Find out what your peers are saying about Microsoft, SentinelOne, CrowdStrike and others in Endpoint Protection Platform (EPP). Updated: September 2026.
913,683 professionals have used our research since 2012.