Usually, the solution is used in relation to keys management. We implemented a program for it, for the lifecycle of the keys. We've also used it for certificate management.
Cyber Security BA/BSA at a financial services firm with 10,001+ employees
Straightforward to set up with good technical support and good stability
Pros and Cons
- "Technical support is good."
- "There are likely some technical improvements or features that could be added, however, I cannot say, off the top of my head, what they would be."
What is our primary use case?
What is most valuable?
The initial setup is very straightforward.
The stability is very good.
Technical support is good.
The solution is in good condition and offers good functionality.
What needs improvement?
There are likely some technical improvements or features that could be added, however, I cannot say, off the top of my head, what they would be.
For how long have I used the solution?
I used the solution in relation to scoping a project. I was doing business analysis.
Buyer's Guide
Microsoft Defender for Endpoint
August 2025

Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
865,384 professionals have used our research since 2012.
What do I think about the stability of the solution?
The solution was very stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
The technical support for Microsoft is very good.
How was the initial setup?
The initial setup is not difficult or complex. It's very simple and straightforward.
What's my experience with pricing, setup cost, and licensing?
I do not know how much it costs per month. I cannot say how it compares against the rates of the competition.
What other advice do I have?
We are a Microsoft Customer.
I'm not sure if I would recommend the solution to others. It depends on their requirements. It needs to fit a company's use cases.
I would rate the solution at an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.

Senior System Administrator at Debre Markos University
Easy to use interface, user-friendly, and stable
Pros and Cons
- "The solution has an easy-to-use interface, is always updated, and is user-friendly."
- "The solution could improve by providing more integration."
What is our primary use case?
I use Microsoft Defender for Endpoint protection on my personal computer.
What is most valuable?
The solution has an easy-to-use interface, is always updated, and is user-friendly.
What needs improvement?
The solution could improve by providing more integration.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for approximately one year.
What do I think about the stability of the solution?
The solution is stable and secure.
What do I think about the scalability of the solution?
I have found the scalability quite good.
How was the initial setup?
The installation is simple.
What about the implementation team?
I did the implementation of the solution.
What's my experience with pricing, setup cost, and licensing?
The solution is free and comes with Windows.
What other advice do I have?
I rate Microsoft Defender for Endpoint a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Microsoft Defender for Endpoint
August 2025

Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: August 2025.
865,384 professionals have used our research since 2012.
Managing Director at FORESEC
Fair price and useful for protection, but should have the ability to recover data from the last normal copy
Pros and Cons
- "We have just started to implement it. It is useful for protection from malware and ransomware."
- "Auto recovery is the most important feature that we would need from this solution. For decryption, similar to Malwarebytes, there should be something to be able to recover the data up to the last normal status. Its ability to recover data to the last normal copy must not exceed 5 to 10 minutes."
What is our primary use case?
We are using it for protection. We had a request from one of our customers, and we just started to implement it. We don't have any great idea about it. We are in the process of implementing it for the first time.
We are using its latest version. It is on-prem. The problem with going for a cloud version is that most of our customers prefer to work with on-prem solutions. So, we need all the features to be available on-prem as well as on the cloud.
What is most valuable?
We have just started to implement it. It is useful for protection from malware and ransomware. We are not exactly sure about zero-day, but we are trying to see if it will be effective for everyday antivirus purposes.
What needs improvement?
Auto recovery is the most important feature that we would need from this solution. For decryption, similar to Malwarebytes, there should be something to be able to recover the data up to the last normal status. Its ability to recover data to the last normal copy must not exceed 5 to 10 minutes.
For how long have I used the solution?
We just started to use it.
What do I think about the stability of the solution?
We need to test its functionality in heavy environments.
How are customer service and technical support?
Their support could be faster through the phone. The support through chat is very unuseful. It takes a lot of time and effort and but does not help in any way. We provide the first line of support to customers, so it is not a big issue for us.
Which solution did I use previously and why did I switch?
We work on most of the protection products, such as Kaspersky, Malwarebytes. We normally use a lot of them. We had a request from one of our customers, so we started to implement Microsoft Defender for Endpoint.
How was the initial setup?
Its initial setup is straightforward. The solution itself doesn't take more than 15 to 20 minutes, but the configuration duration depends on the environment, such as the number of policies, users, etc. It will vary according to the environment in which you are doing the implementation.
What about the implementation team?
We implement it ourselves. Currently, we have only one customer of this solution.
What's my experience with pricing, setup cost, and licensing?
Its price is fair. It has approximately the same price as the other products such as Kaspersky. It is much cheaper than Malwarebytes.
What other advice do I have?
I would rate Microsoft Defender for Endpoint a seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Head, Information Security & Network Operations at a consumer goods company with 10,001+ employees
Nice interface and good reporting, but the alerts need to be more timely
Pros and Cons
- "This is not an inventory solution, but it helps you take count of how many workstations you have, as well as what software is installed on each of them."
- "Alerts need to be sent immediately because as it is now, you see some of them without delay and others arrive perhaps 30 minutes later, and it leaves important gaps in terms of information gathering."
What is our primary use case?
We combine Microsoft Defender with Advanced Threat Protection to manage, isolate, and scan our laptops and workstations for security threats. We have a dashboard that is embedded into Office 365 and it allows us to remotely scan for viruses and malware, so we don’t have to have the laptop present.
How has it helped my organization?
Using this product helps with device inventory. This is not an inventory solution, but it helps you take count of how many workstations you have, as well as what software is installed on each of them. It is important because any software installed on a workstation may be vulnerable to parts of the internet.
Microsoft Defender has features that have helped to add layers to our security posture. The most important of these features is visibility and the provision of detailed alerts. It correlates the data and using this information, I can identify a threat and see if any other workstation in the environment has been affected by it.
Using this product has not negatively affected our user experience. It is just like using Windows 10.
What is most valuable?
The GUI is very nice.
The reporting capabilities are fantastic.
In the future, I would like to have the ability to patch using this product. Specifically, in an enterprise environment, it would be very good if you could patch the workstations remotely.
What needs improvement?
The alerting is something that needs to be improved. Alerts need to be sent immediately because as it is now, you see some of them without delay and others arrive perhaps 30 minutes later, and it leaves important gaps in terms of information gathering.
For how long have I used the solution?
I have been working with Microsoft Defender Antivirus since it first came out, at least seven or eight years ago.
What do I think about the stability of the solution?
With respect to the stability of the product line, Microsoft has many products that do almost the same thing. The question becomes which one you want to use. This is a good product but at the same time, after a while, you don't know if it is the next one that Microsoft is going to stop releasing because of other products that practically do the same thing.
What do I think about the scalability of the solution?
Microsoft Defender is very scalable and there is a lot of room to expand and add extra layers. We have 2,500 endpoints and we plan to expand; however, we are thinking about using the Microsoft Endpoint Manager in place of it.
Once the decision is made to stay with this product or instead adopt Endpoint Manager, we will expand to cover 6,000 endpoints.
How are customer service and technical support?
I have not been in contact with technical support.
Which solution did I use previously and why did I switch?
Prior to Microsoft Defender, we tried quite a few different products from vendors such as Kaspersky and McAfee. One of the major reasons that we adopted Defender is because of the advantage that Microsoft owns the platform, Windows 10. As they have developed the operating system, it is believed that they understand how to guard it much better against a third party. An attacker has to learn a lot about Windows 10.
Another reason we selected Defender is the frequency of updates. Every other time that Windows is updated, Defender is updated. Again, this is because it is owned by Microsoft and exists on its platform.
We also use Microsoft ATP and we are currently looking at Microsoft Endpoint Manager.
How was the initial setup?
The initial setup is straightforward. Basically, once you have the competency with the product, it is straightforward and there are no surprises. It is not rocket science.
This product is built into the Windows 10 image that we install. As you roll out Windows 10, it is already set up and pre-configured, so there is no additional work required.
What was our ROI?
We saw a return on our investment within the first two years.
If I quantify the effort used for the setup and compare it with the pricing of the previous solution, value for the money was realized during the second year.
What's my experience with pricing, setup cost, and licensing?
We have an enterprise agreement so from my perspective, this is a product that ships with Windows and it is not priced standalone. It comes together with the other Microsoft products that we buy.
Which other solutions did I evaluate?
When we evaluated Kaspersky and McAfee, we found the scalability was better for Microsoft. You can do in-place upgrades of the endpoints with Defender but for the others, you would have to re-install the upgraded agents on the workstation. This takes a lot of time and it is not productive.
We are currently evaluating Microsoft Endpoint Manager by comparing the differences between it and Microsoft Defender. This is being done in advance of expanding our usage.
What other advice do I have?
My advice for anybody who is implementing this product is to first analyze their critical assets to have an understanding of what they are. Then, decide if they want a scalable solution. New threats are coming in every month and the way this is going, Microsoft is learning lessons from networks that have been compromised. With this information, they give updates and patches to everybody. In support of this product, you have to consider the patching, consider the visibility that it gives, and then consider the critical assets it is protecting.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Support Executive at a healthcare company with 51-200 employees
No need to purchase an additional solution because it comes bundled with Windows 10
Pros and Cons
- "It is already integrated with Windows 10, so you don't need to worry about that."
- "It is using a large space in your memory all the time. While an antivirus will use some of your memory, if they could reduce the load of the antivirus to some extent that would be good."
What is our primary use case?
It is an antivirus. It is like any other antivirus, except it comes with Windows and you don't need to install anything extra.
How has it helped my organization?
People will ask you, "My system does not have an antivirus," because it is so hidden and subtle. You don't feel like you have an antivirus. Many users will wonder and come to you, saying, "I don't have an antivirus installed. Is that company policy? Do we need to get it from outside and install it?" So, we have to tell them, "No, there is an antivirus. It is there."
It is so seamless that people don't even feel or see it. It is just protecting everybody. If you are some kind of techie or have some experience with Windows Operating System, only then do you know that this thing is already built-in. If you go into the Task Manager, you can find the antivirus using up a lot of memory and a bit of CPU power, then you will understand that is the antivirus doing this. Normally, many people don't realize this.
What is most valuable?
It is already integrated with Windows 10, so you don't need to worry about that.
It is a basic firewall with some additional anti-exploit measures and parental controls already built in.
What needs improvement?
It is using a large space in your memory all the time. While an antivirus will use some of your memory, if they could reduce the load of the antivirus to some extent that would be good.
For how long have I used the solution?
We started using it when they started bundling it with Windows 10, which has been around three or four years.
What do I think about the stability of the solution?
It is very stable.
You do not need to worry about maintenance. It is automatically updated. Sometimes it will show you a red marker to do a system scan. People normally kind of ignore that, but I suggest people do a system scan from time to time. Now, what happens is just a bubble icon showing a red cross sign, but that may not be enough. It should give a pop-up window to remind people to scan the system once a month or quarter. It should be built-in scanning, without asking anybody, once per month or quarter.
What do I think about the scalability of the solution?
It is scalable.
There is no need to get an additional solution because it comes bundled with Windows.
We are protecting around 60 to 70 endpoints in India. In the entire company, there may be around 400 to 500.
Which solution did I use previously and why did I switch?
We have used other antiviruses, like McAfee and Avira Antivirus.
The same thing can be viewed as a pro and a con:
Pro: It is more than silent; you do not even realize that it is an antivirus. Any other antivirus third-party will nag you with pop ups for any small threats. They want to show that they are doing something because you pay them money. They are funny, colorful pop-ups, whatever color they use is like an advertisement for them, e.g., "They are doing it wrong, and we pointed it out." Windows Defender does not do that. In a way, this is good for the people who know the threat sender. They do not really need to be nagged by the antivirus every time you open a site or click on a file.
Con: For normal people who do not know anything about the security side, some pop ups should be there. Some pop-ups call people's attention that you are doing it the wrong way. For example, "This is potentially wrong. Don't visit this site. Don't potentially open this link, file, or attachment." This is missing in Windows Defender.
What was our ROI?
It has a good return on investment, especially since we are used to paying for antivirus. Now, it is part of the Windows purchase.
What's my experience with pricing, setup cost, and licensing?
You don't need to worry about the renewal and purchase of antivirus products. It is bundled with Windows 10, so you don't need to worry about separately purchasing any antiviruses.
Which other solutions did I evaluate?
Whenever you purchase an antivirus, there are so many factors to consider, such as, weighing, doing a comparison, studying everything, and analyzing the cost-benefit factors. You don't need to consider any of this with Windows Defender because it all comes with it. So, you don't need to worry about it.
With Windows Defender, Microsoft is protecting their own operating system from hackers, viruses, malware, etc. It is better to use Windows Defender over other third-party providers. Microsoft knows what best is for the solutions.
What other advice do I have?
If your computers or users are limited and you are not worried about using your computers for a lot of other browsing purposes or a lot of communication from the public, then you can depend on Microsoft Defender as your only solution. However, when your company is a lot more public facing, then you get a lot of mail from the public and must interact with the public. Also, if you must connect your computer to other computers not in your company, then I would suggest going for either a top-of-the line antivirus solution or third-party solutions. Totally depending on Microsoft Defender is not going to work for a company who is facing a lot of public interactions with their computer system.
I would rate it as an eight out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Consultor Senior at a consultancy with 51-200 employees
A free solution that performs well
Pros and Cons
- "It performs well. The stability is seamless."
- "A concern is ransomware, whether people can penetrate and encrypt my data or steal my credit card/banking information."
What is most valuable?
I haven't experienced any problems.
What needs improvement?
They could improve the information about how they are dealing with people who could attack minors. This is my main concern.
Another concern is ransomware, whether people can penetrate and encrypt my data or steal my credit card/banking information.
For how long have I used the solution?
I have been using it since 2019.
What do I think about the stability of the solution?
It performs well. The stability is seamless.
What do I think about the scalability of the solution?
Scalability is not a problem because we don't have servers. We don't do anything more with the computers than use them for studies, reading papers and books, watching movies, and communicating with our family. So, we don't need to scale up.
How are customer service and technical support?
If they could send me more information, then I could evaluate, read more, and give them opinions. For example, if someone tells me about a problem, then I can give solutions and also write to Microsoft regarding this information.
Which solution did I use previously and why did I switch?
From the beginning of the pandemic, we received another kind of software when we had to be at home, but it caused us problems with the performance. So, I decided to quit the other software. Then, I installed Windows Defender on all my computers, including my grandchildren's computers.
I was using Sophos previously, but it was causing problems with the performance. For example, when my grandchildren were trying to assume a session, they opened Excel or Word with a 4 GB computer using Windows 10 and then they always lost the connection or the continuities because the computer slowed down. However, when we decided to quit using Sophos and install all the features of Windows Defender, then those problems were resolved.
How was the initial setup?
The initial setup is very easy and straightforward.
My deployment process: I put some checks in the questions that they have. It was very easy. I read about it in the tutorial. I installed it on my entire family's computers (six computers) in less than half an hour.
What's my experience with pricing, setup cost, and licensing?
It is free.
What other advice do I have?
We are totally satisfied with performance and price. However, there is still the question, "Is it safe and secure enough for home, primary-school-age children, and minors?" Despite having a Masters degree in Computer Sciences and Mathematics, I have not been able to say if Microsoft is doing bad or good things.
Many companies may say that they have the best product, but I recommend always watching the news about what a company is doing. Stay informed. Don't be complacent.
The solution is a nine out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Team Lead at Alepo
Effective firewall capabilities, regular antivirus updates, and it is preinstalled with Windows
Pros and Cons
- "The most valuable features are the Windows Firewall and the regular virus definition updates. These features are very helpful and have helped to improve our security."
- "This solution needs to move beyond relying on virus definitions alone and protect the system using behavioral analysis of the processes that are running."
What is our primary use case?
We use Microsoft Defender Antivirus for antivirus protection as part of our endpoint security solution. It protects our systems against attacks from any virus, malware, or trojan.
How has it helped my organization?
We rely on this product for endpoint protection in our organization because we have not subscribed to any antivirus, apart from Microsoft Defender. It comes for free with our Windows subscription and it has improved the way our organization functions because there have been no virus attacks to date on our laptops.
It has not negatively affected our end-user experience.
What is most valuable?
This solution takes care of most of the infections that are found in the system, and it comes included with Windows. These are the two main advantages of using it.
The most valuable features are the Windows Firewall and the regular virus definition updates. These features are very helpful and have helped to improve our security.
What needs improvement?
Microsoft Defender protects the computer by using virus definitions that we download through regular updates but nowadays, cybersecurity attacks have become more intelligent. This solution needs to move beyond relying on virus definitions alone and protect the system using behavioral analysis of the processes that are running. These can be vulnerable points and if a process causes a glitch in the system, it should be quarantined. Moreover, enhancements of this type should not detract from system performance. There should be no slowdown on the laptop, for example.
For how long have I used the solution?
I have been using Microsoft Defender Antivirus since I started using Windows 7, more than eight years ago.
What do I think about the stability of the solution?
Stability-wise, it is good, and it performs very nicely.
What do I think about the scalability of the solution?
The scalability is fine. We had more than 300 devices that are being protected.
How are customer service and technical support?
I have never had an opportunity to speak with technical support because everything has always worked very smoothly. As we have experienced no issues at all, we never contacted support.
Which solution did I use previously and why did I switch?
Prior to using Microsoft Defender, we used McAfee and Avast Antivirus.
One of the main reasons that we switched away from McAfee is that it required purchasing a subscription. With Microsoft Defender, it is included with Windows. When we install the operating system, it is already there and we don't have to purchase an additional antivirus product.
For security, aside from a traditional antivirus, we have purchased the SentinelOne Endpoint Security solution. This product is more enhanced when compared to an antivirus product. It is modern and has better threat intelligence than other products. I don't know SentinelOne very well yet, as we have just purchased the subscription, but I know that the difference between products is not based on virus definitions.
SentinelOne has intelligence on the cloud and many other security features including the blocking of domain names, and the blocking of USB drives that users plug into their laptops. Although it has many more features than legacy antivirus software, I have no complaints about the performance of Microsoft Defender.
One of the reasons we are more heavily relying on endpoint security is that everybody is working from home and using the internet for work. This transition was made within the last two or three months. When people were working in the office, the firewall afforded them protection. However, as it is now, the endpoints are more vulnerable to attack. This is why we now rely more heavily on SentinelOne.
How was the initial setup?
Microsoft Defender comes preinstalled with the Windows operating system, so we do not have to deploy it separately.
What's my experience with pricing, setup cost, and licensing?
The subscription is part of Windows, so we don't have to pay anything extra for this product.
What other advice do I have?
This is definitely a product that I recommend people use because first of all, you do not have to pay anything extra to use it. The performance is very smooth and it protects your system, which is very much needed. All in all, I would say that this is a good antivirus solution.
I would rate Microsoft Defender Antivirus an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Specialist Consultant in Microsoft Security at a tech services company with 501-1,000 employees
The tamper protection keeps hackers from entering a machine, encrypting it, and changing passwords
Pros and Cons
- "Auto-remediation: When the product sees malware, it resolves the issue immediately. This protects the machine."
- "It needs to improve the cybersecurity for lateral movements. For example, when a hacker tries to enter a machine, they try to get the password by doing a lateral movement."
What is our primary use case?
We use it for antivirus. You can use it for malware and Zero Trust. Some people use it for fact-checking too. I can also use it with Intune, which is good.
We deploy Microsoft Defender on all kinds of devices, including Microsoft, iOS, and Mac.
What is most valuable?
Auto-remediation: When the product sees malware, it resolves the issue immediately. This protects the machine.
I like the tamper protection. For example, if I buy a notebook with Windows 10 and put Microsoft Defender on it, then I can activate the tamper protection. This keeps people from entering the machine, encrypting it, and changing passwords.
Microsoft Defender is fully integrated with Azure Sentinel. In addition, GPO can be connected with Microsoft Defender and Azure AD.
What needs improvement?
It needs to improve the cybersecurity for lateral movements. For example, when a hacker tries to enter a machine, they try to get the password by doing a lateral movement.
With Windows 10, version 18.0.3, I couldn't see the documentation to open the ports. If you don't open the ports, then the machine can't communicate with the console.
What do I think about the stability of the solution?
I like its stability a lot.
What do I think about the scalability of the solution?
You push out all the devices that you want. There is no limitation beyond money and licenses.
Which solution did I use previously and why did I switch?
In the past, I have used McAfee and Kaspersky.
I only work with Microsoft products right now. It integrates well with other products. I also work with Microsoft Defender for Identity.
How was the initial setup?
The deployment process is not difficult because Microsoft Defender comes with Windows 10. You just right click, then it connects you with Azure.
There are other processes that can be connected, e.g., Microsoft Download Center.
What about the implementation team?
I implement Microsoft Defender for Endpoint. It takes me one or two days to design Microsoft Defender for Endpoint. It is easy to do this, and the more you implement, the easier it gets over time.
Sometimes, when I change the configuration, I have to wait six to eight hours.
What's my experience with pricing, setup cost, and licensing?
It is so expensive. It isn't cheaper than McAfee or other solutions.
Which other solutions did I evaluate?
I prefer Microsoft Defender for Endpoint instead of McAfee, Kaspersky, and other products.
What other advice do I have?
I would rate this solution as 10 out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner

Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2025
Product Categories
Endpoint Protection Platform (EPP) Advanced Threat Protection (ATP) Anti-Malware Tools Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
CrowdStrike Falcon
Microsoft Intune
Fortinet FortiEDR
Microsoft Defender for Office 365
Microsoft Sentinel
Microsoft Entra ID
Microsoft Defender for Cloud
SentinelOne Singularity Complete
Microsoft Defender XDR
Microsoft Purview Data Governance
Cortex XDR by Palo Alto Networks
HP Wolf Security
Fortinet FortiClient
Elastic Security
WatchGuard Firebox
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Compare Microsoft Windows Defender and Symantec Endpoint Protection. How Do I Choose?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- What do you think of the integration of Azure AD Services, Defender for Endpoint, and Intune as comprehensive security solutions?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- Running Carbon Black Defense Along with Windows Defender
- How is Cortex XDR compared with Microsoft Defender?
- Which offers better endpoint security - Symantec or Microsoft Defender?
- How does Microsoft Defender for Endpoint compare with Carbon Black CB Defense?
- How would you compare between Microsoft Defender for Endpoint and Tanium EDR?