The product is useful for projects, finding tech, and finding firewall actions on computers.
Senior Consultant at a marketing services firm with 11-50 employees
Low impact on endpoints with an easy setup and fast technical support
Pros and Cons
- "The intelligence mechanisms are good."
- "The detection of viruses could be a little bit better."
What is our primary use case?
What is most valuable?
There's no impact on other applications. Most other solutions have more of a possibility of an impact on other applications and due to that, you must make some special configurations to those other applications. The Microsoft Defender impact is very small.
The intelligence mechanisms are good.
The initial setup is easy.
We have found the technical support to be helpful.
What needs improvement?
The detection of viruses could be a little bit better.
For how long have I used the solution?
We've used the solution for maybe two years.
Buyer's Guide
Microsoft Defender for Endpoint
January 2026
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,114 professionals have used our research since 2012.
What do I think about the scalability of the solution?
Our company is only a small company. We only have 10 people who use the solution. However, we have clients who have a lot of users.
We likely will increase usage in the future.
How are customer service and support?
We've been in touch with technical support. Their level of support is fine and they are very fast. We are satisfied with their level of service.
We had some problem and, after four hours, we had new signatures for the environment by our customers for more than a thousand clients so that we can protect and improve the new setup. It was a very quick turnaround.
How was the initial setup?
The initial setup is not difficult. It's simple. We have just rolled it out to 6,000 clients which have been, by far, more than other customers we've had so far. We have deployed a Microsoft configuration.
In the environment, we needed one or two days to deploy it. In smaller environments, you only need two hours of work.
It can be done by technical personnel in-house. If they have good knowledge of Microsoft environments, and how to use Microsoft tools, then it's easy.
It's always good if you know how to use OutShare. With OutShare, you can make many things extremely effective and extremely easy.
What about the implementation team?
It is possible to handle it in-house if you have a knowledgeable team. We implement the solution for our clients.
What's my experience with pricing, setup cost, and licensing?
Clients need to pay a yearly licensing fee.
What other advice do I have?
This is an on-premise solution where all connections have a cloud connection.
I would recommend the solution to other companies. I'd rate the solution at a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Delivery manager at a computer software company with 201-500 employees
One-stop solution with data capture, analytics, and threat intelligence
Pros and Cons
- "It captures data through machine learning, which is built-in on the back-end. It also provides built-in analytics and a threat intelligence feature. It is a one-stop solution that doesn't require an antivirus because it comes prebuilt into Windows 10."
- "Sometimes, there are different skews. In a basic skew, they should have basic log analysis without the need to integrate with any third-party or SIEM solutions, like Sentinel. This would make it so much easier for users who don't have log collection or log analysis."
What is our primary use case?
I lead a delivery team. I have a team of about 20 technology specialists and we do the deployment for Microsoft Defender.
Instead of having a third-party antivirus, then you can have a Microsoft ecosystem for your entire endpoint protection.
What is most valuable?
This solution has its own sensors, which is its best feature. It senses the behavior of your endpoints, whether it is logged in from a particular location or external of that location.
It captures data through machine learning, which is built-in on the back-end. It also provides built-in analytics and a threat intelligence feature. It is a one-stop solution that doesn't require an antivirus because it comes prebuilt into Windows 10.
What needs improvement?
Sometimes, there are different skews. In a basic skew, they should have basic log analysis without the need to integrate with any third-party or SIEM solutions, like Sentinel. This would make it so much easier for users who don't have log collection or log analysis.
For how long have I used the solution?
We have been using it for a year.
What do I think about the stability of the solution?
This solution is very much stable.
What do I think about the scalability of the solution?
This solution is scalable. It is a cloud solution.
If you have the Microsoft Azure ecosystem, you can collect logs and view them through Sentinel. You can also onboard your devices within Intune.
You can integrate Microsoft Defender for Endpoint with different Microsoft solutions, e.g., Defender for Cloud, Sentinel, Endpoint Manager for onboarding of Intune, and Defender for Office 365.
We have a large number of customers.
How are customer service and support?
Premium support is okay. Professional support is not as good because it is free. You must wait because you are not paying.
How was the initial setup?
The initial setup was straightforward. There was nothing rocket science to it. It didn't take much time as we just enrolled the device and assigned the licenses, then it was done.
You just prepare it, doing a license evaluation licensing and some network configuration, then you can onboard your device.
What about the implementation team?
We do the implementation ourselves. We find it easy to deploy. We help customers adopt the solution and get better ROI.
What's my experience with pricing, setup cost, and licensing?
They have to pay for the Defender license. There are different licenses and skews, such as Plan 1, Plan 2, or the trial.
You do not need to pay any additional costs for antivirus and anti-malware solutions for endpoint protection.
What other advice do I have?
Anyone on Windows 10 Enterprise should choose this solution.
It really depends on the volume. You need one senior architect who can just define the entire thing: the device, network configuration, etc. You will also need some Level 1 engineers who need to keep on monitoring the devices and do onboarding. If they are using the latest version of Windows 10, then you can do the onboarding via Intune, Endpoint, etc.
My rating for this solution is an eight out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Microsoft Defender for Endpoint
January 2026
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,114 professionals have used our research since 2012.
Good security, scales well, and automatically updates
Pros and Cons
- "The patch updates and version updates are very good. Those happen on an automated basis whenever I'm connecting to the organization network, either through LAN or through the VPN."
- "The price, in general, could always be a little bit cheaper."
What is our primary use case?
We have a dedicated team that handles all security-related aspects of the solution, however, my understanding is that the solution helps guard the endpoints in our organization.
What is most valuable?
Along with security, there are certain IT policies in terms of accessibility of different sites, which are there in the organization. With everything put together, there haven't been any instances where I have seen any kind of issues such as malware or other malicious event getting through on my laptop. From that perspective, everything is fine.
The patch updates and version updates are very good. Those happen on an automated basis whenever I'm connecting to the organization network, either through LAN or through the VPN. I never have to worry about anything being out-of-date.
The solution scales well.
I have found the stability to be good.
What needs improvement?
From a general user perspective, I don't see any further improvements needed.
The price, in general, could always be a little bit cheaper.
For how long have I used the solution?
I've used the solution for two years or so. It's not much more than that.
What do I think about the stability of the solution?
The stability of the product is good. I have not dealt with bugs or glitches. It doesn't crash or freeze. the performance is good. It's reliable.
What do I think about the scalability of the solution?
The solution scales well. If a company needs to expand it, it can.
We have 1,000 to 2,000 people on the solution currently.
How are customer service and support?
I've never directly dealt with technical support for issues related to Defender. Many years ago I had reached out to Microsoft support for an issue related to Visio, a different product.
How was the initial setup?
The initial setup is straightforward. There are certain automatic patches as well that keep on updating and those automatically install.
I don't recall how long the product took to deploy. When any new laptop or anything is assigned in an organization, all these things are installed prior to coming to us. Therefore, I wasn't actually a part of the installation process.
We have a few contractors working with the in-house team. There may be around five to ten people. Any maintenance that is needed would be done by them.
What's my experience with pricing, setup cost, and licensing?
The pricing could be lower. That said, I cannot speak to the exact costs involved as I do not directly deal with that aspect of the product. I'm unsure if the company is set up with a monthly or yearly subscription package.
What other advice do I have?
I'm just a customer and an end-user.
I'd rate the solution at an eight out of ten. I've been very pleased with how it has worked for me over the last two years.
I would recommend the solution to others, however, I'm just a passive end-users and not as technically involved as those deploying the solution in our company. However, from my perspective, there has never been an issue on my machine with malware and therefore it seems to be doing what it's designed to do.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head of Information Security at a consultancy with 51-200 employees
Stable and easy to use, but needs quicker detection capability and more frequent updates
Pros and Cons
- "It is stable and easy to use. Everything is okay, and there are no performance issues."
- "Its detection is not as quick. There should also be more frequent updates."
What is our primary use case?
I use it mostly to detect threats or viruses. I am using its latest version.
What is most valuable?
It is stable and easy to use. Everything is okay, and there are no performance issues.
What needs improvement?
Its detection is not as quick. There should also be more frequent updates.
For how long have I used the solution?
I have been using this solution for maybe five years.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
We have about 20 users.
How are customer service and support?
I have not contacted Microsoft's technical support.
Which solution did I use previously and why did I switch?
I didn't use or evaluate other solutions.
How was the initial setup?
Its installation is very easy. It came with Windows.
What about the implementation team?
I can install it myself. We have three teams for deployment and maintenance.
What's my experience with pricing, setup cost, and licensing?
It came with Windows.
What other advice do I have?
I would recommend this solution. I would rate it a seven out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Engineer at a real estate/law firm with 201-500 employees
Effortless updating, full operating system integration, and secure
Pros and Cons
- "Microsoft Defender for Endpoint is beneficial because we are using Microsoft Windows and all the core solutions are made by Microsoft, such as the authentic platform, operating system, and antivirus protection. It is a heterogeneous environment. We had to use third-party solutions before and update everything separately. For example, the policy for antivirus. With Microsoft Defender for Endpoint, when Microsoft Windows receives updates it will update with it. This is one main advantage of this solution."
- "Microsoft Defender for Endpoint can improve by making the reporting faster. It takes some time to reflect back to the administration portal of what has been updated. For example, out of 100 Computers, approximately 90 computers received updates, but when you check the administration portal over one or two days, you will only see 75, even though 90 were updated."
What is our primary use case?
Microsoft Defender for Endpoint can be used for protecting personal information and file in my organization.
How has it helped my organization?
The solution has saved us time by not having to install separate third-party antivirus solutions.
What is most valuable?
Microsoft Defender for Endpoint is beneficial because we are using Microsoft Windows and all the core solutions are made by Microsoft, such as the authentic platform, operating system, and antivirus protection. It is a heterogeneous environment. We had to use third-party solutions before and update everything separately. For example, the policy for antivirus. With Microsoft Defender for Endpoint, when Microsoft Windows receives updates it will update with it. This is one main advantage of this solution.
What needs improvement?
Microsoft Defender for Endpoint can improve by making the reporting faster. It takes some time to reflect back to the administration portal of what has been updated. For example, out of 100 Computers, approximately 90 computers received updates, but when you check the administration portal over one or two days, you will only see 75, even though 90 were updated.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for approximately one year.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
Microsoft Defender for Endpoint has been scalable.
We have more than 200 users using this solution in my organization.
Which solution did I use previously and why did I switch?
Previously we used McAfee and Symantec Endpoint. Every five years we change the solution. However, this time we changed to Microsoft Defender for Endpoint because we wanted a unified platform.
How was the initial setup?
When you install Microsoft Windows 10, Microsoft Defender for Endpoint comes with it. There is no installation of the solution other than installing Windows 10. It saves time because you do not have to use any new kind of policy or deployment.
What about the implementation team?
We have a team of three that do the management of the solution.
What's my experience with pricing, setup cost, and licensing?
The solution comes free with Microsoft Windows 10.
What other advice do I have?
I rate Microsoft Defender for Endpoint a ten out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Application Manager at a financial services firm with 201-500 employees
Good alert chaining and tool compatibility for endpoints with helpful heuristic capabilities
Pros and Cons
- "We are able to productively integrate with existing on-prem, hybrid, or cloud applications."
- "Features like device inventory continue to lack essential workstation drill-downs showing the entire device information with the least effort."
What is our primary use case?
We primarily used the solution as Endpoint Detection and protection (EDR, EPP) with secondary benefits of threats and vulnerability management, security incident response, automated query and real-time device monitoring, and with the capability of email security, identity management (DFI), and task automation (Power automate). We used respective licenses where required.
The solution was also used for an endpoint antivirus for workstations in a multi-OS environment, including Windows and Mac OS. We had file, device, and user trajectory monitoring for the security operations team.
How has it helped my organization?
The solution benefited the company via:
- OS-level/Tool compatibility for endpoints running Windows (since both are Microsoft products and Defender core files are included in Win10 or later delivery).
- Heuristic capability. Consistent usage of MDE indicates that the tools are continuously learning new prevention techniques by pulling real-time up-to-date cloud resources.
- Alert chaining. The solution makes security Incidents, events, and alerts less tedious from a Security Operation Center standpoint. This can result in false negatives or detriment for small to medium-scale firms running no or semi-automated threat response features.
What is most valuable?
The most valuable aspects of the solution include:
- Advanced hunting. The product offers flexibility, visibility, and automation capability using a user-friendly query language (KQL).
- Reporting. Clear and concisely plotted graphics show real-time data representation - which is valuable to upper management.
- Scalability/API. We are able to productively integrate with existing on-prem, hybrid, or cloud applications.
- Great OOB features. The solution comes with SIEM-ingestion-ready features for extensive visibility, automation, and integration, including advanced hunting, threats and vulnerability management, embedded simulation for end-to-end testing, ransomware prevention (Controlled Folder Access), and Attack Surface Reduction (ASR) rules.
What needs improvement?
Improvements could be made via:
- Clicks. There's a poor user experience with lots of optimizable opportunities of user interface particularly on the newly improved portal (https://security.microsoft.com/). Features like device inventory continue to lack essential workstation drill-downs showing the entire device information with the least effort.
- De-centralized console features. Discrepancies with enabling core features at the click of a button within the MDE portal is mostly due to prerequisites that are tied to the functionality or partial enforcement requirements from other Microsoft tools (Group policy, Azure, Sentinel, SCCM, Intune). EDR in block mode requires Intune security baselines and tamper protection requires MAPS enabled. Web content filtering also has security baseline dependencies
- No single pane of glass. There are too many loose ends with tiny bits and pieces to enforce essential security policies compared to other EDR solutions within the same caliber. A typical example is having to create exclusions in different locations for entirely different functionalities, such as: automation folder exclusion, group policy exclusions (per tenant), Controlled Folder Access (ASR) Allowed application, and Attack Surface Reduction (ASR).
- Service Requests. Noncritical cases with MDE technical support teams tend to be queued for over a week before the first customer engagement. Most of these tickets also end up in the hands of temporary or contracted non-Microsoft employees who are scripted and offer little attention to unique incidents.
Suggested additional features that should be included in the next release include:
- Digestible interface/filter for crown-jewel capabilities like ASR, CFA and Exploit mitigation occurrences.
- Restoration of an always visible search bar from the previous console view (https://securitycenter.windows.com).
- A definitive action plan for Secure Score recommendations and deduplicate of controls.
For how long have I used the solution?
We were using Microsoft Defender for Endpoint prior to its change of name from Defender ATP. We experienced a plethora of GA changes including, but not limited to, IOS/multiple OS support, device discovery, web content filtering, API updates, and continuous integrations with existing security tools.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security BA/BSA at a financial services firm with 10,001+ employees
Straightforward to set up with good technical support and good stability
Pros and Cons
- "Technical support is good."
- "There are likely some technical improvements or features that could be added, however, I cannot say, off the top of my head, what they would be."
What is our primary use case?
Usually, the solution is used in relation to keys management. We implemented a program for it, for the lifecycle of the keys. We've also used it for certificate management.
What is most valuable?
The initial setup is very straightforward.
The stability is very good.
Technical support is good.
The solution is in good condition and offers good functionality.
What needs improvement?
There are likely some technical improvements or features that could be added, however, I cannot say, off the top of my head, what they would be.
For how long have I used the solution?
I used the solution in relation to scoping a project. I was doing business analysis.
What do I think about the stability of the solution?
The solution was very stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
The technical support for Microsoft is very good.
How was the initial setup?
The initial setup is not difficult or complex. It's very simple and straightforward.
What's my experience with pricing, setup cost, and licensing?
I do not know how much it costs per month. I cannot say how it compares against the rates of the competition.
What other advice do I have?
We are a Microsoft Customer.
I'm not sure if I would recommend the solution to others. It depends on their requirements. It needs to fit a company's use cases.
I would rate the solution at an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager of Information Systems at a engineering company with 51-200 employees
Easy to scale, reliable, and extremely easy to install
Pros and Cons
- "We like that it has a free version available."
- "The frequency of the patching, and the frequency of the updates, are not included with the free version."
What is our primary use case?
We use it at home on some personal machines at home, and there are a few machines inside of the Enterprise that has it.
We use this solution for general antivirus protection.
What is most valuable?
We like that it has a free version available.
What needs improvement?
The frequency of the patching, and the frequency of the updates, are not included with the free version.
The platform I used in the past would check every hour and deploy every two hours down to the client, every patch that came through.
It was actively looking for updates, the latest threats, which is something that the Microsoft Defender product did not have in the free version.
The Enterprise version that we had, didn't have visibility. If somebody were to uninstall it or turn it off, I'd have trouble seeing that easily. There are tools that I can install, but from a reporting standpoint who has it on and off is included with the Enterprise package that you pay for, or it comes included with Office 365 Enterprise, but not in the free version.
For how long have I used the solution?
We have been using Microsoft Defender for Endpoint for two and a half years.
We are using the latest version. It is always up-to-date.
What do I think about the stability of the solution?
We had absolutely no issues with the stability of Microsoft Defender for Endpoint. We did not experience any bugs or glitches.
What do I think about the scalability of the solution?
It is pretty easy to scale. it was basically one click to agree that you wanted to use it.
How are customer service and technical support?
We did not contact technical support.
Which solution did I use previously and why did I switch?
Previously, we were using another solution and were forced to uninstall it to patch Windows. It was an annoyance to reinstall it.
How was the initial setup?
The initial setup was straightforward. It was extremely simple.
What's my experience with pricing, setup cost, and licensing?
We are using the free version.
When you are centrally managing it, you can't get there without a much more expensive Microsoft solution to control the rollout and to make sure that it is up-to-date.
We didn't research that, it was a stop-gap measure until we figured out what we're going to do in the long term.
Which other solutions did I evaluate?
We are looking into a product that gets into the EDR, XDR, the fully managed patching, and everything else, versus just the anti-virus that package includes.
What other advice do I have?
I would rate Microsoft Defender for Endpoint and eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Endpoint Protection Platform (EPP) Advanced Threat Protection (ATP) Anti-Malware Tools Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
CrowdStrike Falcon
Microsoft Intune
Microsoft Entra ID
Microsoft Defender for Cloud
Microsoft Defender for Office 365
Fortinet FortiEDR
Microsoft Sentinel
SentinelOne Singularity Complete
IBM Security QRadar
HP Wolf Security
Cortex XDR by Palo Alto Networks
Microsoft Purview Data Governance
Microsoft Defender XDR
Elastic Security
Huntress Managed EDR
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Compare Microsoft Windows Defender and Symantec Endpoint Protection. How Do I Choose?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- What do you think of the integration of Azure AD Services, Defender for Endpoint, and Intune as comprehensive security solutions?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- Running Carbon Black Defense Along with Windows Defender
- How is Cortex XDR compared with Microsoft Defender?
- Which offers better endpoint security - Symantec or Microsoft Defender?
- How does Microsoft Defender for Endpoint compare with Carbon Black CB Defense?
- How would you compare between Microsoft Defender for Endpoint and Tanium EDR?











