We use this product for our endpoint detection and all the remediation.
Security Specialist at Engen
Provides good security features and can be viewed in the central console
Pros and Cons
- "Provides good security features and you can view it in the central console."
- "Lacks some additional integration."
What is our primary use case?
What is most valuable?
The solution provides good security features. The key valuable feature for me is that you can view it in the central console.
What needs improvement?
I'd like to see more integration in the next release and the solution should be file protected.
For how long have I used the solution?
I've been using this solution for five years.
Buyer's Guide
Microsoft Defender for Endpoint
March 2026
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,933 professionals have used our research since 2012.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
I'd like to see a quicker response time from the company's technical support.
How was the initial setup?
The initial setup was straightforward. It didn't take long and was part of the deployment of our endpoints, and part of the integration. We currently have around 3,000 users and no plans to expand. We have four people involved with maintenance.
What other advice do I have?
I recommend this solution and rate it eight out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Group IT Security Program Manager at Jotun
Native integration with OS gives it more granular capabilities, but management console needs work
Pros and Cons
- "The most valuable feature is its ability to effectively detect threats. It has the EDR feature, endpoint detection and response, and that is very good."
- "The management console is something that can be improved."
What is most valuable?
The most valuable feature is its ability to effectively detect threats. It has the EDR feature, endpoint detection and response, and that is very good.
What needs improvement?
The management console is something that can be improved.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for about two years.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
It is scalable.
How was the initial setup?
The initial setup is quite simple because it is built into the operating system.
Which other solutions did I evaluate?
Microsoft Defender has more granular capabilities because of the native operating system that it is built into. It is better integrated into the operating system because both the product and the OS are from Microsoft. That is an advantage.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Microsoft Defender for Endpoint
March 2026
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,933 professionals have used our research since 2012.
Senior Software Architect at Instirute of public health
Provides good, user-friendly protection
Pros and Cons
- "Defender is stable, I haven't had any problems with viruses when using it, and it's easy to update."
- "Defender's cloud integration could be improved."
What is our primary use case?
I use Defender for protection.
What is most valuable?
The most valuable features are that Defender is user-friendly and part of Microsoft Windows.
What needs improvement?
Defender's cloud integration could be improved.
What do I think about the stability of the solution?
Defender is stable, I haven't had any problems with viruses when using it, and it's easy to update.
How was the initial setup?
The initial setup was easy.
What other advice do I have?
I would recommend Defender to anyone thinking of using it, and I rate it as eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Unified Communications Manager at Jouve
Easy to deploy with great cloud provisioning and excellent functionality
Pros and Cons
- "It's a Microsoft product; it's easier to deploy this product than other options."
- "It would be helpful if they offered video tutorial guides."
What is our primary use case?
We're using the solution on our endpoints.
What is most valuable?
The functionality is very important to us.
The cloud provisioning is great.
It's a Microsoft product, therefore, it's easier to deploy this product than other options. It's very important for us to have a simple way to deploy new PCs when we buy the new PCs. We don't want that deployment to be a burden. The easy deployment feature is very helpful.
What needs improvement?
At the moment we are currently testing it. We are not major users of the product, and therefore we have no idea of what it can and can't do just yet.
At this time we don't have any recommendations concerning the Windows product interface.
It would be helpful if they offered video tutorial guides.
For how long have I used the solution?
I've used the solution for three or four months.
What do I think about the stability of the solution?
We are testing it right now and we didn't get into the production state just yet. Therefore, it's hard to gauge the capabilities in terms of stability. So far, however, it has been stable.
What do I think about the scalability of the solution?
The scalability is okay.
How are customer service and support?
Support is always okay. I've always had a positive experience dealing with support.
How was the initial setup?
The deployment is seamless and super simple. It's not complex at all, and that's the main selling point for us.
What's my experience with pricing, setup cost, and licensing?
We did negotiate on the pricing, however, I can't speak to the exact costs involved.
Which other solutions did I evaluate?
We did not really compare this solution to other options. The advantage is that this solution is available on mobile devices, and we needed something that covered everything, from desktops and laptops to mobile. Therefore, we didn't really consider anything else.
What other advice do I have?
We are Microsoft customers. We don't have a special relationship with the organization.
We are using the latest version of the solution.
It's a good product overall. I would rate it an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Performs well, easy to use, and intuitive implementation
Pros and Cons
- "Microsoft Defender for Endpoint's most valuable feature is its ease of use."
- "Microsoft Defender for Endpoint can improve by providing more and different types of reports."
What is our primary use case?
I am using Microsoft Defender for Endpoint for system alerts of any kind of suspicious items or unusual network traffic. I only use it for personal use.
The solution has shown me different kinds of requests from the websites that were made and cookies that have been created. It has provided me with statistics.
What is most valuable?
Microsoft Defender for Endpoint's most valuable feature is its ease of use.
What needs improvement?
Microsoft Defender for Endpoint can improve by providing more and different types of reports.
For how long have I used the solution?
I used Microsoft Defender for Endpoint within the past 12 months.
What do I think about the stability of the solution?
Microsoft Defender for Endpoint has been stable. It does not slow down my computer.
What do I think about the scalability of the solution?
The scalability of Microsoft Defender for Endpoint has been fine.
How are customer service and support?
I have not contacted the support from Microsoft.
How was the initial setup?
The initial setup of Microsoft Defender for Endpoint was intuitive, I didn't make any customization, I used what was preset. The installation was done with the Microsoft Windows installation.
What's my experience with pricing, setup cost, and licensing?
The license for Microsoft Windows covers Microsoft Defender for Endpoint.
What other advice do I have?
I rate Microsoft Defender for Endpoint an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Works at a financial services firm with 51-200 employees
Simple to install and maintain, but the support could be faster, and more responsive
Pros and Cons
- "The installation is straightforward."
- "Phishing and Malware detection could be better."
What is our primary use case?
Microsoft Defender for Endpoint gives us a second layer of security as well as the third layer of security. One of them is interested in web security and email security. One of them, similar to Cisco, is a Cisco FirePOWER. These are a compilation or a group of devices for security.
What needs improvement?
We had some issues where phishing and malware were not detected and were allowed to pass unless I mentioned it or we forced the phishing or malware to be blocked, I can't rely on that alone.
Phishing and Malware detection could be better.
Technical support needs improvement.
For how long have I used the solution?
I have been working with Microsoft Defender for Endpoint for one year.
What do I think about the stability of the solution?
It is stable for the time being.
What do I think about the scalability of the solution?
I can't add more layers of security because of my budget and business plan, so I try to choose the best and most preferable option for me and my company.
I would rate the scalability a seven out of ten.
In one company, we have two administrators and 30 employees who use this solution.
On a short-term plan, I will not increase the usage. On a larger scale, we intend to increase the license.
How are customer service and support?
In my opinion, technical support is not as effective as it was before. They take a long time to support and investigate the issue.
It takes a long time for them to support and investigate the issue. I believe they must crush the time in order to provide us with our needs, and our objectives.
Which solution did I use previously and why did I switch?
There are applications and solutions that we have used for five or more years. We almost used Microsoft Link but have since switched to Microsoft Teams and Skype for business. We almost exclusively use Cisco products such as Cisco EMC, Cisco Web security, and Cisco Meraki.
How was the initial setup?
The installation is straightforward. It's a cloud solution that requires some configuration running on the cloud.
The deployment takes a couple of hours to complete.
It's a different story when it comes to security. It takes a different approach. It requires two an administrator and a manager to maintain this solution.
What about the implementation team?
Sometimes the installation and deployment are done by the technical team, and sometimes it's done by others.
What's my experience with pricing, setup cost, and licensing?
Licensing fees are paid annually through a partner.
What other advice do I have?
If I do recommend it, it will not be solely for security purposes. It is possibly for a first-line security platform, and it is required to build a second, third, and possibly fourth business security layer.
I would rate Microsoft Defender for Endpoint a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head-IT/SAP at Barista Coffee Company Ltd.
Easy to enable and activate but could be more secure
Pros and Cons
- "Defender is a part of Windows; you just need to enable it. There is no need to install anything."
- "The solution could always be more secure."
What is our primary use case?
Defender is basically a protective seal that is used to protect your Windows applications. Whenever you enable it your system is safe. You feel safe and your data and your security are verified by Defender and protected by the Defender seal.
What is most valuable?
Defender is a part of Windows; you just need to enable it. There is no need to install anything.
It's quite good for security. We are using Windows 11 and Windows 10. In Windows 11, Defender is very, very strong. They built in good features, good seals. Earlier, ransomware protection was not there. However, now, new ransomware protection is also available in Defender.
The solution is stable.
What needs improvement?
The solution could always be more secure.
What do I think about the stability of the solution?
The solution is very stable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The scalability is totally based on your OS operating system as it's a part of the OS. You can't define it in a different way. If your Windows platform is working fine and is of a certain size, then you can say that it's quite good and it will cover that.
We have 200 to 300 people using the solution. Some of our employees use Windows and have Defender. Others use Mac devices.
How are customer service and support?
We've used technical support in the past and don't have anything negative to say about their services.
How was the initial setup?
There isn't really an installation process. It's already a part of Windows and just needs to be activated. You can install Windows in home or business devices and have Defender at your fingertips immediately.
While you don't need a technical team to install it per se, every organization has an IT team that likely would be able to install Windows and everything else. We have a 40-plus IT team. Everybody has a defined role.
What about the implementation team?
We handled the implementation in-house using our IT team.
What's my experience with pricing, setup cost, and licensing?
The solution is included with Microsoft Office 365 subscriptions.
What other advice do I have?
New users who are leveraging Microsoft can decide if they want to use Defender. It's already there - you can either activate it or not, depending on your preference. It's nice that you have a choice. Many companies find Defender is enough for them, however, if you want more security, you may be able to add other firewalls or security features to your existing infrastructure.
I'd rate the solution at a seven out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Manager at a manufacturing company with 1,001-5,000 employees
Comes with awesome threat hunting capabilities, and is great for investigating what's happening on machines
Pros and Cons
- "It's great for investigating what's happening on a machine. They show a whole bunch of machine timeline events that are related to a security incident. They have quite good details on the things related to threat and vulnerability management, such as any weakness that has been disclosed publicly, assets that are exposed, and if there is an exploit active in the wild for that vulnerability. It can provide you with all such information, which is cool."
- "It can get a bit laggy sometimes. Other than that, we don't have any issues. They constantly tweak it and fix it up based on users' feedback. It has improved a lot over the past four years. Defender for Endpoint never really used to be a good endpoint security solution, but over the past couple of years, Microsoft has invested heavily in it. So, it has come a long way in all aspects of endpoint security. If they want to make it better, they should just continue investing in the current path of what they've been doing over the past couple of years."
What is our primary use case?
It is an Endpoint Detection and Response system (EDR), and it seems the new term is XDR. We use it for anti-malware protection. It protects from a virus, worm, ransomware, and other similar things.
How has it helped my organization?
It can automatically scan and remediate stuff without an administrator doing anything. We use it for threat and vulnerability management. There are components in there that will tell us about any vulnerable software running on endpoints. There are a whole bunch of other things too.
What is most valuable?
It's great for investigating what's happening on a machine. They show a whole bunch of machine timeline events that are related to a security incident. They have quite good details on the things related to threat and vulnerability management, such as any weakness that has been disclosed publicly, assets that are exposed, and if there is an exploit active in the wild for that vulnerability. It can provide you with all such information, which is cool.
It has got some awesome threat hunting capabilities. It can search for malicious activity that could indicate that an asset is being compromised, but it is not something to which you would have necessarily got alerted.
We're fully Microsoft, it integrates with other Microsoft security products very well. Its interface is also fine.
What needs improvement?
It can get a bit laggy sometimes. Other than that, we don't have any issues. They constantly tweak it and fix it up based on users' feedback. It has improved a lot over the past four years. Defender for Endpoint never really used to be a good endpoint security solution, but over the past couple of years, Microsoft has invested heavily in it. So, it has come a long way in all aspects of endpoint security. If they want to make it better, they should just continue investing in the current path of what they've been doing over the past couple of years.
For how long have I used the solution?
I have been using this solution for nearly four years.
What do I think about the stability of the solution?
It can get a little laggy sometimes, but overall, it's fine when investigating events.
What do I think about the scalability of the solution?
It is easy to scale.
How are customer service and support?
There are different levels of technical support that you can purchase from Microsoft. We don't have the top level, but we used to have the top level, and that was good. I would rate them a five out of five. They've got a dedicated team specifically looking at threats for all their customers.
How was the initial setup?
I was not involved in its setup. I am only a user of the solution, but I'm pretty sure it's pretty straightforward. It's just deployed by Intune or a partial script or something like that.
What about the implementation team?
It was implemented internally. In terms of maintenance, it generally doesn't require any maintenance. There are some policy configuration changes that we can tweak, but the signatures, behavior analysis, and all similar things in the engine are kept up to date by them. We have four people who are dealing with this product.
What's my experience with pricing, setup cost, and licensing?
Licensing models of Microsoft are renowned for being complex. We just purchased the whole E5 stack. With E5 licenses for users, we get access to a bunch of features that are not just related to security. I would rate them a three out of five in terms of pricing.
Which other solutions did I evaluate?
One of the things that I like to constantly do is assess other vendors in the same space. We get vendor demonstrations, and for the most of it, it seems like Defender is well truly up there with the other best players in the market. I've never done a proof of concept with any other tool, so I can't really compare it with others. Most of the time, vendor demonstrations are all about glitz and glam to sell their product and show how much better they are than competitors.
What other advice do I have?
I would advise doing your due diligence. This is more than just an endpoint security solution, and sometimes, you've got to think of your technology stacks before applying or purchasing certain security solutions and see if they're applicable to your environment.
I would rate it an eight out of 10. No endpoint solution is ever going to be able to be perfectly good at stopping all types of threats. No endpoint solution would ever get a 10 in my point of view.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2026
Product Categories
Endpoint Protection Platform (EPP) Advanced Threat Protection (ATP) Anti-Malware Tools Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
CrowdStrike Falcon
Microsoft Intune
Microsoft Entra ID
Microsoft Defender for Cloud
Cortex XDR by Palo Alto Networks
Microsoft Defender for Office 365
SentinelOne Singularity Complete
Microsoft Sentinel
IBM Security QRadar
Fortinet FortiEDR
HP Wolf Security
Huntress Managed EDR
Elastic Security
Microsoft Defender XDR
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Compare Microsoft Windows Defender and Symantec Endpoint Protection. How Do I Choose?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- What do you think of the integration of Azure AD Services, Defender for Endpoint, and Intune as comprehensive security solutions?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- Running Carbon Black Defense Along with Windows Defender
- How is Cortex XDR compared with Microsoft Defender?
- Which offers better endpoint security - Symantec or Microsoft Defender?
- How does Microsoft Defender for Endpoint compare with Carbon Black CB Defense?
- How would you compare between Microsoft Defender for Endpoint and Tanium EDR?















