We use Microsoft Defender for Endpoint for threat protection.
Chief Technology Officer at a financial services firm with 1-10 employees
Easy to use, good support, but more visibility is needed
Pros and Cons
- "The most valuable features of Microsoft Defender for Endpoint are the ease of use and it was available within the operating system."
- "The most valuable features of Microsoft Defender for Endpoint are the ease of use and it was available within the operating system."
- "The biggest issue I had with Microsoft Defender for Endpoint was the antivirus and ransomware. I wanted central visibility over all the machines that we operate."
- "The biggest issue I had with Microsoft Defender for Endpoint was the antivirus and ransomware."
What is our primary use case?
What is most valuable?
The most valuable features of Microsoft Defender for Endpoint are the ease of use and it was available within the operating system.
What needs improvement?
The biggest issue I had with Microsoft Defender for Endpoint was the antivirus and ransomware. I wanted central visibility over all the machines that we operate.
For how long have I used the solution?
I have used Microsoft Defender for Endpoint within the past 12 months.
Buyer's Guide
Microsoft Defender for Endpoint
April 2026
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
893,244 professionals have used our research since 2012.
What do I think about the scalability of the solution?
We have approximately 10 to 15 people using the solution in my organization.
How are customer service and support?
The technical support from Microsoft is good.
How was the initial setup?
The initial installation could have been easier.
What's my experience with pricing, setup cost, and licensing?
There is an annual license required.
What other advice do I have?
I rate Microsoft Defender for Endpoint a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Systems Administrator at The Port Authority of Jamaica
It's a cost-effective solution for Microsoft shops
Pros and Cons
- "We are a Microsoft shop, and Defender is a Microsoft solution that provides some security at a reasonable cost."
- "We are a Microsoft shop, and Defender is a Microsoft solution that provides some security at a reasonable cost."
- "I want Microsoft Defender to have the ability to deal with some issues automatically, so I don't need to address that issue manually."
- "I want Microsoft Defender to have the ability to deal with some issues automatically, so I don't need to address that issue manually."
What is our primary use case?
We use Defendor for endpoint monitoring. It alerts us when a machine has issues, and we take the necessary steps to resolve them.
What is most valuable?
We are a Microsoft shop, and Defender is a Microsoft solution that provides some security at a reasonable cost.
What needs improvement?
I want Microsoft Defender to have the ability to deal with some issues automatically, so I don't need to address that issue manually.
For how long have I used the solution?
We started testing our endpoints and preparing to deploy Microsoft Defender about two months ago.
What do I think about the scalability of the solution?
I would say yes, it is.
How are customer service and support?
Microsoft support is excellent.
How was the initial setup?
Deploying Microsoft Defender took some time because we had to push it through. You can install Symantec using the GUI, but we have to use the GPO to push the agent. It would be nice if Defender streamlined that.
Defender isn't 100 percent deployed yet, but it's working for some employees. When a machine comes on board, Defender will deploy an agent on that device when the script runs. A person logs on, the agent installs, and the device is onboarded.
What other advice do I have?
I rate Microsoft Defender for Endpoint eight out of 10. It's a cost-effective solution for Microsoft shops.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Microsoft Defender for Endpoint
April 2026
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
893,244 professionals have used our research since 2012.
Group IT Security Program Manager at Jotun
Native integration with OS gives it more granular capabilities, but management console needs work
Pros and Cons
- "The most valuable feature is its ability to effectively detect threats. It has the EDR feature, endpoint detection and response, and that is very good."
- "The most valuable feature is its ability to effectively detect threats."
- "The management console is something that can be improved."
- "The management console is something that can be improved."
What is most valuable?
The most valuable feature is its ability to effectively detect threats. It has the EDR feature, endpoint detection and response, and that is very good.
What needs improvement?
The management console is something that can be improved.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for about two years.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
It is scalable.
How was the initial setup?
The initial setup is quite simple because it is built into the operating system.
Which other solutions did I evaluate?
Microsoft Defender has more granular capabilities because of the native operating system that it is built into. It is better integrated into the operating system because both the product and the OS are from Microsoft. That is an advantage.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Software Architect at Instirute of public health
Provides good, user-friendly protection
Pros and Cons
- "Defender is stable, I haven't had any problems with viruses when using it, and it's easy to update."
- "Defender is stable, I haven't had any problems with viruses when using it, and it's easy to update."
- "Defender's cloud integration could be improved."
- "Defender's cloud integration could be improved."
What is our primary use case?
I use Defender for protection.
What is most valuable?
The most valuable features are that Defender is user-friendly and part of Microsoft Windows.
What needs improvement?
Defender's cloud integration could be improved.
What do I think about the stability of the solution?
Defender is stable, I haven't had any problems with viruses when using it, and it's easy to update.
How was the initial setup?
The initial setup was easy.
What other advice do I have?
I would recommend Defender to anyone thinking of using it, and I rate it as eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Unified Communications Manager at Jouve
Easy to deploy with great cloud provisioning and excellent functionality
Pros and Cons
- "It's a Microsoft product; it's easier to deploy this product than other options."
- "The deployment is seamless and super simple; it's not complex at all, and that's the main selling point for us."
- "It would be helpful if they offered video tutorial guides."
- "It would be helpful if they offered video tutorial guides."
What is our primary use case?
We're using the solution on our endpoints.
What is most valuable?
The functionality is very important to us.
The cloud provisioning is great.
It's a Microsoft product, therefore, it's easier to deploy this product than other options. It's very important for us to have a simple way to deploy new PCs when we buy the new PCs. We don't want that deployment to be a burden. The easy deployment feature is very helpful.
What needs improvement?
At the moment we are currently testing it. We are not major users of the product, and therefore we have no idea of what it can and can't do just yet.
At this time we don't have any recommendations concerning the Windows product interface.
It would be helpful if they offered video tutorial guides.
For how long have I used the solution?
I've used the solution for three or four months.
What do I think about the stability of the solution?
We are testing it right now and we didn't get into the production state just yet. Therefore, it's hard to gauge the capabilities in terms of stability. So far, however, it has been stable.
What do I think about the scalability of the solution?
The scalability is okay.
How are customer service and support?
Support is always okay. I've always had a positive experience dealing with support.
How was the initial setup?
The deployment is seamless and super simple. It's not complex at all, and that's the main selling point for us.
What's my experience with pricing, setup cost, and licensing?
We did negotiate on the pricing, however, I can't speak to the exact costs involved.
Which other solutions did I evaluate?
We did not really compare this solution to other options. The advantage is that this solution is available on mobile devices, and we needed something that covered everything, from desktops and laptops to mobile. Therefore, we didn't really consider anything else.
What other advice do I have?
We are Microsoft customers. We don't have a special relationship with the organization.
We are using the latest version of the solution.
It's a good product overall. I would rate it an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Assistant Chief Manager at a financial services firm with 5,001-10,000 employees
Advanced threat protection fulfills a large number of security strategy requirements for our organization
Pros and Cons
- "We found that because the endpoint devices are based on Microsoft Windows devices and Windows Defender is integrated with the foundation and the core layer, it makes it more integrated and more agile in terms of responding to any security threats or changes or development"
- "We found that because the endpoint devices are based on Microsoft Windows devices and Windows Defender is integrated with the foundation and the core layer, it makes it more integrated and more agile in terms of responding to any security threats or changes or development."
- "In terms of the architecture of the management infrastructure, we found that other technologies are more simple. Microsoft Defender could be simpler too."
- "In terms of the architecture of the management infrastructure, we found that other technologies are more simple. Microsoft Defender could be simpler too."
What is our primary use case?
We are using Microsoft Defender for Endpoint with advanced threat production. Microsoft's enterprise mobility and security suite fulfills a large number of security strategy requirements for our organization. We are going to use this solution for identity production and for endpoint security.
It's a hybrid setup. The advanced threat protection only comes from the cloud intelligence engine. That's something of a new experience for us, but the rest of the components will be on-prem. We are using Microsoft's cloud.
The whole suite of security enhancement doesn't just include Microsoft Defender. It also covers many of the features that come with the Windows Enterprise version. With this option, we are actually upgrading to the Enterprise version as well and unlocking those security features which are not available in Windows Professional. Microsoft Defender is a whole suite, which is simply not comparable with a usual anti-virus, anti-malware product.
What needs improvement?
In terms of the architecture of the management infrastructure, we found that other technologies are more simple. Microsoft Defender could be simpler too. Plus, Microsoft's philosophy is that they leverage the technology they have already built in Windows or any other services within Windows. So, it is good from that standpoint, but it also becomes a bit cumbersome when it comes to the dependency. Having dependency on many things can be a weakness sometimes because you add up more points of failure to the services. Whereas the other vendors are doing the limited thing, and that's why they're not comparable in prices, but their solutions basically aren't dependent on Microsoft's other services or anything else. They're more dependent on their agent. With Microsoft, it is not just the agent. It is the operating systems that aren't working well. The technology won't give you the desired output.
So, that's something that Microsoft may need to improve: making services more independent wherever possible. That's something of their philosophy. When they build something on their OS layer, they add on technologies, and then there's something for the ISV. That's their strategy, but we keep arguing with them that they have to compare the dependence as other vendors are doing.
From the Microsoft end, the design working depends on the health of other services and other components of the operating system. Whereas if you compare it with the Symantec technology, just the agent health has to be there. That's the case with McAfee as well. They build up their products on developed agents only.
For how long have I used the solution?
We did the POC around 18 months ago, and then we consolidated our findings. As per the organization procedure, we proposed to the committee and then got the recommendation to move on with the pilot and decide the future roadmap.
Microsoft Defender is just one part of the advanced risk protection and advanced malware protection functionality that comes with the Microsoft product. It came with a lot of security, advisories, reviews, and consultancy during the last couple of years. There was a stack of 15-20 requirements that we had to fulfill, like mobile device management and identity protection. We found that Windows Defender meets most of our requirements.
How are customer service and support?
We have had good experience with tech support so far.
We have a direct support agreement with Microsoft. One of the major reasons for moving from the current endpoint security is the support. The quality is not up to the mark. That's something incomparable with the kind of support Microsoft provides.
I would give Microsoft's support a 5 out of 5.
Which solution did I use previously and why did I switch?
In terms of the technical aspect, I'm the lead of the area, which actually takes care of endpoint management, and we have been using Symantec products for that purpose. We have evaluated Microsoft Defender and Microsoft security products, and we are going to switch over to that product. We found that because the endpoint devices are based on Microsoft Windows devices and Windows Defender is integrated with the foundation and the core layer, it makes it more integrated and more agile in terms of responding to any security threats or changes or development, whereas compared to the other vendors who develop anything on top of that platform, they're always lagging behind.
Symantec support is very pathetic. They are very methodical. They're very slow. We seldom find them providing solutions to any incident or issue in a reasonable time. It can take from days to weeks. In the case of Microsoft, their resolution time is reasonably faster than Symantec. Even in the case of VMware and Redhead, Microsoft stands on top of all those vendors.
How was the initial setup?
I wouldn't say the setup is easier than other solutions but it's not bad. It's almost equivalent to what we have been using currently, but the strength comes in what it does and how it secures that part. The setup is similar to the other competitors. For Symantec, we use their endpoint manager deployment and then a deployment across the sites and branches.
What about the implementation team?
We are doing deployment with Microsoft's tech support. But for the implementations and rollout of technologies, we have seldom used Microsoft. We have our own technical team who are trained and who keep on updating on their skills, and we continue to inject new resources to the team as well. When a new technology comes in, then we do a combo, whereby the in-house team actually learns with the local authorized partner.
What's my experience with pricing, setup cost, and licensing?
Microsoft Defender is not comparable to a single endpoint security product, like Trend Micro, Symantec, or McAfee. Because of that, the price is higher than others because it is doing more than what the others are doing.
What other advice do I have?
I would rate this solution 7 out of 10.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Reliable with a good online community and an easy initial setup
Pros and Cons
- "It does not make Windows slow, as compared to all of the third part antiviruses."
- "It definitely improves the organization in terms of security and productivity."
- "We would like more customization."
- "We would like more customization, actually."
What is our primary use case?
The solution is primarily used for antivirus and malware protection.
How has it helped my organization?
It definitely improves the organization in terms of security and productivity. We integrate the Defender with the Microsoft Cloud platform as well. It provides us with sandboxing and other functionalities in real time, where we can have the protection we need.
It's integrated with advanced threat analysis so we can see how the threat is coming into our network, what it is doing, and more. We can see everything step by step if a threat comes, including how this threat impacted the organization, et cetera.
What is most valuable?
The first thing which I noticed is that it is completely compatible with Windows. It does not make Windows slow, as compared to all of the third part antiviruses.
The stability has been good.
Technical support is helpful and they have a very robust online community as well.
The product can scale very well.
What needs improvement?
We would like more customization, actually. They're not too customizable. We'd like the flexibility to be able to set some applications on a white list. We need more options.
For how long have I used the solution?
I've used the solution for approximately five years.
What do I think about the stability of the solution?
The solution is stable and responsive.
What do I think about the scalability of the solution?
We have the solution deployed to around 350 users across four different locations.
It can scale to the thousands and thousands. I have seen customers here, some have approximately 12,000 devices and they're running that one program and it's going far without any issues.
How are customer service and support?
Technical support is good. They know things about the solution. The best part is that if anything happens, the Microsoft community is so big that any problem comes up, you can also just Google it and you will get the solution.
Which solution did I use previously and why did I switch?
We used McAfee and another solution as well and they both are great and amazing, however, they make PCs slow and every time something happens you have to call the vendor and they will help you support. The difference is, with Defender, it doesn't slow things done and you never have to call Microsoft.
How was the initial setup?
The initial setup is very straightforward. IT is actually my default. We actually helped our end-users with system centers, integrated Defender updates, Defender itself, patching, and Defender configuration using the consent and configuration manager. It's simple. It's not complex to set it up or manage.
It's a bulk operation to set it up, therefore, even if you have 100 PCs, it will only take you about an hour and you will be up and running with everyone. You only need one to two percent of your staff to handle the deployment and maintenance tasks.
What about the implementation team?
We used an integrator during the initial setup. They were quite helpful. Our experience with them was good.
What was our ROI?
We have seen an ROI.
What's my experience with pricing, setup cost, and licensing?
The solution is free for end-users.
What other advice do I have?
While we have the solution set up on our private cloud, you can also use a hybrid setup if that's better for your organization.
I would advise new users to connect it with an endpoint manager and connect it with the cloud and then let the real magic happen.
I'd rate the solution an eight out of ten.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Performs well, easy to use, and intuitive implementation
Pros and Cons
- "Microsoft Defender for Endpoint's most valuable feature is its ease of use."
- "Microsoft Defender for Endpoint's most valuable feature is its ease of use."
- "Microsoft Defender for Endpoint can improve by providing more and different types of reports."
- "Microsoft Defender for Endpoint can improve by providing more and different types of reports."
What is our primary use case?
I am using Microsoft Defender for Endpoint for system alerts of any kind of suspicious items or unusual network traffic. I only use it for personal use.
The solution has shown me different kinds of requests from the websites that were made and cookies that have been created. It has provided me with statistics.
What is most valuable?
Microsoft Defender for Endpoint's most valuable feature is its ease of use.
What needs improvement?
Microsoft Defender for Endpoint can improve by providing more and different types of reports.
For how long have I used the solution?
I used Microsoft Defender for Endpoint within the past 12 months.
What do I think about the stability of the solution?
Microsoft Defender for Endpoint has been stable. It does not slow down my computer.
What do I think about the scalability of the solution?
The scalability of Microsoft Defender for Endpoint has been fine.
How are customer service and support?
I have not contacted the support from Microsoft.
How was the initial setup?
The initial setup of Microsoft Defender for Endpoint was intuitive, I didn't make any customization, I used what was preset. The installation was done with the Microsoft Windows installation.
What's my experience with pricing, setup cost, and licensing?
The license for Microsoft Windows covers Microsoft Defender for Endpoint.
What other advice do I have?
I rate Microsoft Defender for Endpoint an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2026
Product Categories
Endpoint Protection Platform (EPP) Advanced Threat Protection (ATP) Anti-Malware Tools Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
CrowdStrike Falcon
Microsoft Intune
Cortex XDR by Palo Alto Networks
Microsoft Entra ID
Microsoft Defender for Cloud
SentinelOne Singularity Endpoint
IBM Security QRadar
Microsoft Defender for Office 365
Microsoft Sentinel
Huntress Managed EDR
Elastic Security
HP Wolf Security
Trellix Endpoint Security Platform
Microsoft Defender XDR
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Compare Microsoft Windows Defender and Symantec Endpoint Protection. How Do I Choose?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- What do you think of the integration of Azure AD Services, Defender for Endpoint, and Intune as comprehensive security solutions?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- Running Carbon Black Defense Along with Windows Defender
- How is Cortex XDR compared with Microsoft Defender?
- Which offers better endpoint security - Symantec or Microsoft Defender?
- How does Microsoft Defender for Endpoint compare with Carbon Black CB Defense?
- How would you compare between Microsoft Defender for Endpoint and Tanium EDR?















