The solution is primarily used for antivirus and malware protection.
Reliable with a good online community and an easy initial setup
Pros and Cons
- "It does not make Windows slow, as compared to all of the third part antiviruses."
- "We would like more customization."
What is our primary use case?
How has it helped my organization?
It definitely improves the organization in terms of security and productivity. We integrate the Defender with the Microsoft Cloud platform as well. It provides us with sandboxing and other functionalities in real time, where we can have the protection we need.
It's integrated with advanced threat analysis so we can see how the threat is coming into our network, what it is doing, and more. We can see everything step by step if a threat comes, including how this threat impacted the organization, et cetera.
What is most valuable?
The first thing which I noticed is that it is completely compatible with Windows. It does not make Windows slow, as compared to all of the third part antiviruses.
The stability has been good.
Technical support is helpful and they have a very robust online community as well.
The product can scale very well.
What needs improvement?
We would like more customization, actually. They're not too customizable. We'd like the flexibility to be able to set some applications on a white list. We need more options.
Buyer's Guide
Microsoft Defender for Endpoint
May 2025

Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.
For how long have I used the solution?
I've used the solution for approximately five years.
What do I think about the stability of the solution?
The solution is stable and responsive.
What do I think about the scalability of the solution?
We have the solution deployed to around 350 users across four different locations.
It can scale to the thousands and thousands. I have seen customers here, some have approximately 12,000 devices and they're running that one program and it's going far without any issues.
How are customer service and support?
Technical support is good. They know things about the solution. The best part is that if anything happens, the Microsoft community is so big that any problem comes up, you can also just Google it and you will get the solution.
Which solution did I use previously and why did I switch?
We used McAfee and another solution as well and they both are great and amazing, however, they make PCs slow and every time something happens you have to call the vendor and they will help you support. The difference is, with Defender, it doesn't slow things done and you never have to call Microsoft.
How was the initial setup?
The initial setup is very straightforward. IT is actually my default. We actually helped our end-users with system centers, integrated Defender updates, Defender itself, patching, and Defender configuration using the consent and configuration manager. It's simple. It's not complex to set it up or manage.
It's a bulk operation to set it up, therefore, even if you have 100 PCs, it will only take you about an hour and you will be up and running with everyone. You only need one to two percent of your staff to handle the deployment and maintenance tasks.
What about the implementation team?
We used an integrator during the initial setup. They were quite helpful. Our experience with them was good.
What was our ROI?
We have seen an ROI.
What's my experience with pricing, setup cost, and licensing?
The solution is free for end-users.
What other advice do I have?
While we have the solution set up on our private cloud, you can also use a hybrid setup if that's better for your organization.
I would advise new users to connect it with an endpoint manager and connect it with the cloud and then let the real magic happen.
I'd rate the solution an eight out of ten.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner

Information Security Officer at Church of England
Scalable, good support, and straightforward implementation
Pros and Cons
- "The technical support from Microsoft is very good. We are part of the Microsoft Suite, and from being part of this we have consistent news regarding Microsoft Defender for Endpoint."
- "Microsoft Defender for Endpoint could improve by making the reporting better."
What is our primary use case?
We use Microsoft Defender for Endpoint for network and endpoint protection.
What needs improvement?
Microsoft Defender for Endpoint could improve by making the reporting better.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for approximately three years.
What do I think about the stability of the solution?
Microsoft Defender for Endpoint is stable in my usage.
What do I think about the scalability of the solution?
I have found Microsoft Defender for Endpoint to be scalable.
We have approximately 700 people using this solution and we plan to increase usage.
How are customer service and support?
The technical support from Microsoft is very good. We are part of the Microsoft Suite, and from being part of this we have consistent news regarding Microsoft Defender for Endpoint.
Which solution did I use previously and why did I switch?
I have previously used ESET.
How was the initial setup?
The initial setup of Microsoft Defender for Endpoint was straightforward.
What about the implementation team?
We have two engineers that do the implementation and maintenance of Microsoft Defender for Endpoint.
What other advice do I have?
Microsoft Defender for Endpoint has improved a lot over the years and it is a lot better now.
I would recommend this solution to others.
I rate Microsoft Defender for Endpoint an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Microsoft Defender for Endpoint
May 2025

Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: May 2025.
851,823 professionals have used our research since 2012.
Managing Director at a financial services firm with 10,001+ employees
Reliable, well-priced, and it is easy to install
Pros and Cons
- "We use Microsoft Defender for the antivirus."
- "The interface could be improved."
What is our primary use case?
There are endpoints that are not in our organization's network but are connected directly to the web. We use Microsoft Defender for the antivirus.
We are not dealing with this solution daily, just when there is an issue from time to time.
What needs improvement?
The interface could be improved.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for a couple of years.
What do I think about the stability of the solution?
It's a stable solution.
What do I think about the scalability of the solution?
We are only running it on a few workstations. The scalability is okay.
It's run on 10 out of 3,000 workstations and we plan to continue using it.
We have no more than 10 users in our organization.
Which solution did I use previously and why did I switch?
We are also using Symantec.
We have a few endpoints where we use Microsoft Defender because we cannot use the Symantec Sets.
How was the initial setup?
The initial setup was straightforward. It was easy to install and t only took a couple of minutes.
There is no team for maintenance. If there is an issue, the security team helps to resolve it.
What about the implementation team?
We completed the deployment and implementation ourselves.
What's my experience with pricing, setup cost, and licensing?
We don't have an issue with the price.
We have a bundle where the price includes all Microsoft products.
This is an area that I am not dealing with. I don't have all of the information.
What other advice do I have?
It's pretty good.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cyber Security Specialist at a healthcare company with 10,001+ employees
Good support and valuable EDR feature, but not stable and not suitable for enterprises with lots of other processes and third-party tools
Pros and Cons
- "The EDR feature is most valuable."
- "It is currently more suitable for end-users rather than enterprises with lots of other processes and third-party tools. It needs improvement on that front. We had many issues while integrating it with our enterprise solutions, such as Splunk, and third-party tools. It provides everything via APIs. Other vendors provide integration with third-party tools, but Microsoft doesn't do that. It is also logging too much and is not serialized from the process aspect. It has all the data, but it is not in a proper format or not properly indexed, which doesn't make it easier for enterprises to use this data. Other vendors provide troubleshooting information that can be used to troubleshoot issues, but Microsoft doesn't provide anything like that."
What is our primary use case?
We use it for our endpoint detection and response capability.
What is most valuable?
The EDR feature is most valuable.
What needs improvement?
It is currently more suitable for end-users rather than enterprises with lots of other processes and third-party tools. It needs improvement on that front. We had many issues while integrating it with our enterprise solutions, such as Splunk, and third-party tools. It provides everything via APIs. Other vendors provide integration with third-party tools, but Microsoft doesn't do that.
It is also logging too much and is not serialized from the process aspect. It has all the data, but it is not in a proper format or not properly indexed, which doesn't make it easier for enterprises to use this data.
Other vendors provide troubleshooting information that can be used to troubleshoot issues, but Microsoft doesn't provide anything like that.
For how long have I used the solution?
I have been using this solution for six months.
What do I think about the stability of the solution?
It is still a new product, and there are many reported bugs in terms of stability and impact on the endpoints.
What do I think about the scalability of the solution?
We have around 80,000 users.
How are customer service and technical support?
They are good. They take a little bit of time, but they are good.
How was the initial setup?
It was very complex. We had many issues in integrating it with our enterprise solutions, such as Splunk, and third-party tools.
What about the implementation team?
We have seven or eight engineers for its maintenance.
What other advice do I have?
I would recommend this solution to others if they don't have many third-party tools. It is a very good solution.
I would rate Microsoft Defender for Endpoint a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Product Manager at a comms service provider with 501-1,000 employees
Good management over endpoints but the technical support needs to be improved
Pros and Cons
- "The scanning is slow when it is working with incoming emails."
What is our primary use case?
We are a system integrator and I specialize in practically everything that is security-related. This is a product that we sell as part of Office 365, and rarely as a standalone solution.
Usually, if we have a customer with Office 365 and they need this type of solution then we increase the subscription to a point where it is included.
From the user's point of view, this is classic anti-virus software. From a management point of view, this product gives better control over endpoint devices because some processes can be stopped remotely. If you have a person that is watching over the system then they have a higher level of control over endpoints.
What is most valuable?
This is a cloud-based product so it is always updated by the end-user.
What needs improvement?
They have to improve the email scanning where email is coming from somewhere other than our private network. The scanning is slow when it is working with incoming emails. Often, I can see the email but the scanning process is not finished and I cannot open the attachment. In general, the scanning has to be faster.
What do I think about the stability of the solution?
This solution looks stable. Provided that Windows 10 is updated, everything is okay.
How are customer service and technical support?
I have not been in contact with technical support in regards to this product. However, technical support for Microsoft products is always of bad quality. In my experience, if you cannot find the solution yourself then you will have a huge problem because it is not an easy task to have them understand and support you.
You can lose a lot of time explaining the problem before you receive something that works.
My advice to is look for a good support library and try to find the solution yourself. This means that you don't need to contact support.
Which solution did I use previously and why did I switch?
We have worked with many different security solutions. For example, we are selling a Security Operations Center as a service. We implement EDR, Privileged Access Management, Identity Management, anti-fraud solutions, web application firewalls, database security, and more. We are working with practically everything in cybersecurity.
We are working with between 10 and 15 different vendors. Sometimes, this is too many, but it is useful to have information about each product, its quality, and how it compares to others. Two products that we are working with now are Cisco AMP and Carbon Black.
What's my experience with pricing, setup cost, and licensing?
There is a free version of Windows Defender, although the paid version has EDR functionality. We sell this product as part of Office 365 and it is not expensive.
What other advice do I have?
I have never touched this product. I'm just selling it, and I don't recommend it to anybody as a standalone solution.
I would rate this solution a five out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Engineer at a tech services company with 5,001-10,000 employees
Analyzes behaviors and provides great visibility
Pros and Cons
- "It has Kusto Query Language (KQL), so we can use our own queries to find anything."
- "We need better support to learn about the product. Documentation is available, but we need some kind of training program so that we can get a better understanding of the product."
What is our primary use case?
We are using it only for EDR, but we have a plan to extend it to Microsoft email as well as to the cloud.
How has it helped my organization?
Within one month of using Microsoft Defender for Endpoint, we could achieve great insights.
Microsoft Defender for Endpoint is a perfect solution. We have used several EDR products, and Microsoft Defender is the best one that I have worked with. It provides great visibility. It is very transparent. We can get so many details about a particular endpoint. It is a great product. I would rate it a five out of five in terms of visibility.
It helps us to identify process-based threats in our environment, not only the signature-based ones. We are able to identify some of the threats that were not detected previously.
We get severity levels from the solution itself. Based on them, we have developed our action plan to act upon any category of incident. It helps to achieve a better SLA to attend to incidents.
I am quite interested in the vulnerability dashboard. It provides vulnerability data according to the CVE database, which helps us to prioritize vulnerabilities in our environment and address them.
Microsoft Defender for Endpoint works with Windows and Linux, so we could cover them all. It is suitable for servers as well, not only for endpoints, so we could implement it on most devices in the organization. It has probably saved us 20% of the time.
What is most valuable?
It has Kusto Query Language (KQL), so we can use our own queries to find anything.
We can get real-time updates. It is not just signature-based. It provides results based on behavior and successors. It analyzes the behavior and the process. With that, we can achieve greater results that other products do not offer.
What needs improvement?
We need better support to learn about the product. Documentation is available, but we need some kind of training program so that we can get a better understanding of the product.
For how long have I used the solution?
We switched to Microsoft Defender for Endpoint about one month ago.
What do I think about the stability of the solution?
I would rate it an eight out of ten in terms of stability.
What do I think about the scalability of the solution?
It is highly scalable. We have around 5,000 users. I would rate it a ten out of ten in terms of scalability.
Which solution did I use previously and why did I switch?
Previously, we were using a separate EDR product in our environment. We were using Sophos. Our organization moved into Microsoft 365, so we switched to Microsoft Defender for Endpoint.
We heard that it is one of the best products in the industry. We thought that we would get better results with Microsoft Defender for Endpoint. That is why we moved to Microsoft Defender for Endpoint, and we were able to achieve better results with it.
How was the initial setup?
It is a cloud deployment. It took us a few months to make the switch.
It does not require any maintenance from our end.
What other advice do I have?
Overall, I would rate Microsoft Defender for Endpoint a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Development Manager at S-ryhmä / S Group
Provides visibility into SOC workstations and stops threats from spreading to machines
Pros and Cons
- "We can react to threats faster and stop them from spreading from one machine to another. It protects from suspicious email attachment downloads. It will lock down the SOC and the workstations."
- "Microsoft Defender for Endpoint's licensing is confusing. It has conflicting information on the website. We also faced integration issues with other systems. It makes laptops slower than traditional antivirus systems."
What is our primary use case?
Microsoft Defender for Endpoint provides visibility into our workstations at SOC.
How has it helped my organization?
We can react to threats faster and stop them from spreading from one machine to another. It protects from suspicious email attachment downloads. It will lock down the SOC and the workstations.
What is most valuable?
It is an EDR product that offers much more information into what's happening at our workstations.
What needs improvement?
Microsoft Defender for Endpoint's licensing is confusing. It has conflicting information on the website. We also faced integration issues with other systems. It makes laptops slower than traditional antivirus systems.
For how long have I used the solution?
I have been working with the product for a year.
What do I think about the stability of the solution?
Microsoft Defender for Endpoint is stable.
What do I think about the scalability of the solution?
The tool's scalability is good, but we must consider the cost.
What was our ROI?
We get good ROI with the product's use.
What other advice do I have?
The product's threat intelligence prepares us for potential threats and helps us take proactive steps. Its vulnerability management feature is important to us.
Microsoft Defender for Endpoint has improved our security posture by giving visibility to our endpoints and vulnerabilities.
The tool helps us save months per year. It also helps us save money in manhours.
Microsoft Defender for Endpoint has reduced our time to respond and time to detect by a large margin.
We chose the product because we already use Microsoft products, and it better integrates with them.
I rate it an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Cyber Security Manager at a manufacturing company with 1,001-5,000 employees
Comes with awesome threat hunting capabilities, and is great for investigating what's happening on machines
Pros and Cons
- "It's great for investigating what's happening on a machine. They show a whole bunch of machine timeline events that are related to a security incident. They have quite good details on the things related to threat and vulnerability management, such as any weakness that has been disclosed publicly, assets that are exposed, and if there is an exploit active in the wild for that vulnerability. It can provide you with all such information, which is cool."
- "It can get a bit laggy sometimes. Other than that, we don't have any issues. They constantly tweak it and fix it up based on users' feedback. It has improved a lot over the past four years. Defender for Endpoint never really used to be a good endpoint security solution, but over the past couple of years, Microsoft has invested heavily in it. So, it has come a long way in all aspects of endpoint security. If they want to make it better, they should just continue investing in the current path of what they've been doing over the past couple of years."
What is our primary use case?
It is an Endpoint Detection and Response system (EDR), and it seems the new term is XDR. We use it for anti-malware protection. It protects from a virus, worm, ransomware, and other similar things.
How has it helped my organization?
It can automatically scan and remediate stuff without an administrator doing anything. We use it for threat and vulnerability management. There are components in there that will tell us about any vulnerable software running on endpoints. There are a whole bunch of other things too.
What is most valuable?
It's great for investigating what's happening on a machine. They show a whole bunch of machine timeline events that are related to a security incident. They have quite good details on the things related to threat and vulnerability management, such as any weakness that has been disclosed publicly, assets that are exposed, and if there is an exploit active in the wild for that vulnerability. It can provide you with all such information, which is cool.
It has got some awesome threat hunting capabilities. It can search for malicious activity that could indicate that an asset is being compromised, but it is not something to which you would have necessarily got alerted.
We're fully Microsoft, it integrates with other Microsoft security products very well. Its interface is also fine.
What needs improvement?
It can get a bit laggy sometimes. Other than that, we don't have any issues. They constantly tweak it and fix it up based on users' feedback. It has improved a lot over the past four years. Defender for Endpoint never really used to be a good endpoint security solution, but over the past couple of years, Microsoft has invested heavily in it. So, it has come a long way in all aspects of endpoint security. If they want to make it better, they should just continue investing in the current path of what they've been doing over the past couple of years.
For how long have I used the solution?
I have been using this solution for nearly four years.
What do I think about the stability of the solution?
It can get a little laggy sometimes, but overall, it's fine when investigating events.
What do I think about the scalability of the solution?
It is easy to scale.
How are customer service and support?
There are different levels of technical support that you can purchase from Microsoft. We don't have the top level, but we used to have the top level, and that was good. I would rate them a five out of five. They've got a dedicated team specifically looking at threats for all their customers.
How was the initial setup?
I was not involved in its setup. I am only a user of the solution, but I'm pretty sure it's pretty straightforward. It's just deployed by Intune or a partial script or something like that.
What about the implementation team?
It was implemented internally. In terms of maintenance, it generally doesn't require any maintenance. There are some policy configuration changes that we can tweak, but the signatures, behavior analysis, and all similar things in the engine are kept up to date by them. We have four people who are dealing with this product.
What's my experience with pricing, setup cost, and licensing?
Licensing models of Microsoft are renowned for being complex. We just purchased the whole E5 stack. With E5 licenses for users, we get access to a bunch of features that are not just related to security. I would rate them a three out of five in terms of pricing.
Which other solutions did I evaluate?
One of the things that I like to constantly do is assess other vendors in the same space. We get vendor demonstrations, and for the most of it, it seems like Defender is well truly up there with the other best players in the market. I've never done a proof of concept with any other tool, so I can't really compare it with others. Most of the time, vendor demonstrations are all about glitz and glam to sell their product and show how much better they are than competitors.
What other advice do I have?
I would advise doing your due diligence. This is more than just an endpoint security solution, and sometimes, you've got to think of your technology stacks before applying or purchasing certain security solutions and see if they're applicable to your environment.
I would rate it an eight out of 10. No endpoint solution is ever going to be able to be perfectly good at stopping all types of threats. No endpoint solution would ever get a 10 in my point of view.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2025
Product Categories
Endpoint Protection Platform (EPP) Advanced Threat Protection (ATP) Anti-Malware Tools Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
CrowdStrike Falcon
Microsoft Intune
Fortinet FortiEDR
Microsoft Defender for Office 365
Microsoft Sentinel
Microsoft Entra ID
Microsoft Defender for Cloud
SentinelOne Singularity Complete
Microsoft Defender XDR
Cortex XDR by Palo Alto Networks
Microsoft Purview Data Governance
Fortinet FortiClient
Elastic Security
Symantec Endpoint Security
Azure Firewall
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Compare Microsoft Windows Defender and Symantec Endpoint Protection. How Do I Choose?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- What do you think of the integration of Azure AD Services, Defender for Endpoint, and Intune as comprehensive security solutions?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- Running Carbon Black Defense Along with Windows Defender
- How is Cortex XDR compared with Microsoft Defender?
- Which offers better endpoint security - Symantec or Microsoft Defender?
- How does Microsoft Defender for Endpoint compare with Carbon Black CB Defense?
- How would you compare between Microsoft Defender for Endpoint and Tanium EDR?