I haven't experienced any problems.
Consultor Senior at a consultancy with 51-200 employees
A free solution that performs well
Pros and Cons
- "It performs well. The stability is seamless."
- "A concern is ransomware, whether people can penetrate and encrypt my data or steal my credit card/banking information."
What is most valuable?
What needs improvement?
They could improve the information about how they are dealing with people who could attack minors. This is my main concern.
Another concern is ransomware, whether people can penetrate and encrypt my data or steal my credit card/banking information.
For how long have I used the solution?
I have been using it since 2019.
What do I think about the stability of the solution?
It performs well. The stability is seamless.
Buyer's Guide
Microsoft Defender for Endpoint
March 2026
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,933 professionals have used our research since 2012.
What do I think about the scalability of the solution?
Scalability is not a problem because we don't have servers. We don't do anything more with the computers than use them for studies, reading papers and books, watching movies, and communicating with our family. So, we don't need to scale up.
How are customer service and support?
If they could send me more information, then I could evaluate, read more, and give them opinions. For example, if someone tells me about a problem, then I can give solutions and also write to Microsoft regarding this information.
Which solution did I use previously and why did I switch?
From the beginning of the pandemic, we received another kind of software when we had to be at home, but it caused us problems with the performance. So, I decided to quit the other software. Then, I installed Windows Defender on all my computers, including my grandchildren's computers.
I was using Sophos previously, but it was causing problems with the performance. For example, when my grandchildren were trying to assume a session, they opened Excel or Word with a 4 GB computer using Windows 10 and then they always lost the connection or the continuities because the computer slowed down. However, when we decided to quit using Sophos and install all the features of Windows Defender, then those problems were resolved.
How was the initial setup?
The initial setup is very easy and straightforward.
My deployment process: I put some checks in the questions that they have. It was very easy. I read about it in the tutorial. I installed it on my entire family's computers (six computers) in less than half an hour.
What's my experience with pricing, setup cost, and licensing?
It is free.
What other advice do I have?
We are totally satisfied with performance and price. However, there is still the question, "Is it safe and secure enough for home, primary-school-age children, and minors?" Despite having a Masters degree in Computer Sciences and Mathematics, I have not been able to say if Microsoft is doing bad or good things.
Many companies may say that they have the best product, but I recommend always watching the news about what a company is doing. Stay informed. Don't be complacent.
The solution is a nine out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Team Lead at Alepo
Effective firewall capabilities, regular antivirus updates, and it is preinstalled with Windows
Pros and Cons
- "The most valuable features are the Windows Firewall and the regular virus definition updates. These features are very helpful and have helped to improve our security."
- "This solution needs to move beyond relying on virus definitions alone and protect the system using behavioral analysis of the processes that are running."
What is our primary use case?
We use Microsoft Defender Antivirus for antivirus protection as part of our endpoint security solution. It protects our systems against attacks from any virus, malware, or trojan.
How has it helped my organization?
We rely on this product for endpoint protection in our organization because we have not subscribed to any antivirus, apart from Microsoft Defender. It comes for free with our Windows subscription and it has improved the way our organization functions because there have been no virus attacks to date on our laptops.
It has not negatively affected our end-user experience.
What is most valuable?
This solution takes care of most of the infections that are found in the system, and it comes included with Windows. These are the two main advantages of using it.
The most valuable features are the Windows Firewall and the regular virus definition updates. These features are very helpful and have helped to improve our security.
What needs improvement?
Microsoft Defender protects the computer by using virus definitions that we download through regular updates but nowadays, cybersecurity attacks have become more intelligent. This solution needs to move beyond relying on virus definitions alone and protect the system using behavioral analysis of the processes that are running. These can be vulnerable points and if a process causes a glitch in the system, it should be quarantined. Moreover, enhancements of this type should not detract from system performance. There should be no slowdown on the laptop, for example.
For how long have I used the solution?
I have been using Microsoft Defender Antivirus since I started using Windows 7, more than eight years ago.
What do I think about the stability of the solution?
Stability-wise, it is good, and it performs very nicely.
What do I think about the scalability of the solution?
The scalability is fine. We had more than 300 devices that are being protected.
How are customer service and technical support?
I have never had an opportunity to speak with technical support because everything has always worked very smoothly. As we have experienced no issues at all, we never contacted support.
Which solution did I use previously and why did I switch?
Prior to using Microsoft Defender, we used McAfee and Avast Antivirus.
One of the main reasons that we switched away from McAfee is that it required purchasing a subscription. With Microsoft Defender, it is included with Windows. When we install the operating system, it is already there and we don't have to purchase an additional antivirus product.
For security, aside from a traditional antivirus, we have purchased the SentinelOne Endpoint Security solution. This product is more enhanced when compared to an antivirus product. It is modern and has better threat intelligence than other products. I don't know SentinelOne very well yet, as we have just purchased the subscription, but I know that the difference between products is not based on virus definitions.
SentinelOne has intelligence on the cloud and many other security features including the blocking of domain names, and the blocking of USB drives that users plug into their laptops. Although it has many more features than legacy antivirus software, I have no complaints about the performance of Microsoft Defender.
One of the reasons we are more heavily relying on endpoint security is that everybody is working from home and using the internet for work. This transition was made within the last two or three months. When people were working in the office, the firewall afforded them protection. However, as it is now, the endpoints are more vulnerable to attack. This is why we now rely more heavily on SentinelOne.
How was the initial setup?
Microsoft Defender comes preinstalled with the Windows operating system, so we do not have to deploy it separately.
What's my experience with pricing, setup cost, and licensing?
The subscription is part of Windows, so we don't have to pay anything extra for this product.
What other advice do I have?
This is definitely a product that I recommend people use because first of all, you do not have to pay anything extra to use it. The performance is very smooth and it protects your system, which is very much needed. All in all, I would say that this is a good antivirus solution.
I would rate Microsoft Defender Antivirus an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Microsoft Defender for Endpoint
March 2026
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: March 2026.
884,933 professionals have used our research since 2012.
Specialist Consultant in Microsoft Security at a tech services company with 501-1,000 employees
The tamper protection keeps hackers from entering a machine, encrypting it, and changing passwords
Pros and Cons
- "Auto-remediation: When the product sees malware, it resolves the issue immediately. This protects the machine."
- "It needs to improve the cybersecurity for lateral movements. For example, when a hacker tries to enter a machine, they try to get the password by doing a lateral movement."
What is our primary use case?
We use it for antivirus. You can use it for malware and Zero Trust. Some people use it for fact-checking too. I can also use it with Intune, which is good.
We deploy Microsoft Defender on all kinds of devices, including Microsoft, iOS, and Mac.
What is most valuable?
Auto-remediation: When the product sees malware, it resolves the issue immediately. This protects the machine.
I like the tamper protection. For example, if I buy a notebook with Windows 10 and put Microsoft Defender on it, then I can activate the tamper protection. This keeps people from entering the machine, encrypting it, and changing passwords.
Microsoft Defender is fully integrated with Azure Sentinel. In addition, GPO can be connected with Microsoft Defender and Azure AD.
What needs improvement?
It needs to improve the cybersecurity for lateral movements. For example, when a hacker tries to enter a machine, they try to get the password by doing a lateral movement.
With Windows 10, version 18.0.3, I couldn't see the documentation to open the ports. If you don't open the ports, then the machine can't communicate with the console.
What do I think about the stability of the solution?
I like its stability a lot.
What do I think about the scalability of the solution?
You push out all the devices that you want. There is no limitation beyond money and licenses.
Which solution did I use previously and why did I switch?
In the past, I have used McAfee and Kaspersky.
I only work with Microsoft products right now. It integrates well with other products. I also work with Microsoft Defender for Identity.
How was the initial setup?
The deployment process is not difficult because Microsoft Defender comes with Windows 10. You just right click, then it connects you with Azure.
There are other processes that can be connected, e.g., Microsoft Download Center.
What about the implementation team?
I implement Microsoft Defender for Endpoint. It takes me one or two days to design Microsoft Defender for Endpoint. It is easy to do this, and the more you implement, the easier it gets over time.
Sometimes, when I change the configuration, I have to wait six to eight hours.
What's my experience with pricing, setup cost, and licensing?
It is so expensive. It isn't cheaper than McAfee or other solutions.
Which other solutions did I evaluate?
I prefer Microsoft Defender for Endpoint instead of McAfee, Kaspersky, and other products.
What other advice do I have?
I would rate this solution as 10 out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Assistant Manager IT at a educational organization with 1,001-5,000 employees
Good performance, reliable, and offers effective ransomware protection
Pros and Cons
- "The most valuable feature is ransomware protection, which can detect malicious activity from IPs or a malicious payload in DLLs, or other things that can corrupt the system."
- "The file scanning has room for improvement. Many people use macros within their files, so there should be a mechanism that helps us to scan them for malicious payloads."
What is our primary use case?
We use Microsoft Defender Antivirus to scan for malicious payloads that may come in files, emails, a USB drive, or another type of external drive. It helps us to identify any malicious load that could compromise the security of any of our systems.
We are in a decentralized environment. We have multiple offices but they are not connected physically. The offices are directly managed from the internet.
We have a mixed environment with Linux and Windows machines.
We operate in the educational sector.
How has it helped my organization?
We have not fully considered how this product affects our overall security posture, although this is because we have not yet explored all of the features. Once we have all of our offices connected, it is something that we will be looking into. At this point, it does not affect all of our machines. On a scale from one to five, I would rate our security posture a four.
What is most valuable?
The most valuable feature is ransomware protection, which can detect malicious activity from IPs or a malicious payload in DLLs, or other things that can corrupt the system.
The performance is good. Usually, end-users complain that whenever background or real-time scanning is done, the effects are felt as there is a slowdown in the system. This is not the case with Microsoft Defender.
What needs improvement?
The file scanning has room for improvement. Many people use macros within their files, so there should be a mechanism that helps us to scan them for malicious payloads.
If there is a Word file then it is able to scan it, but if there is a malicious payload within its signature then it will not be detected. Deep packet scanning must be used to improve the overall product.
For how long have I used the solution?
We have been using Microsoft Defender Antivirus since we upgraded to Windows 10 from Windows 8.
What do I think about the stability of the solution?
This is a stable product. We have been using the standard version for a long time and it hasn't negatively affected our environment. Generally speaking, it is reliable.
What do I think about the scalability of the solution?
Microsoft is actively working on this product and I think that it is becoming more scalable, day by day. For example, prior to Windows 10, there was no ransomware support. Now, it comes with Windows 20S2 and Windows 20H1.
With our decentralized environment, I don't know the exact number of users or devices that we have. However, I can say that there are more than 500 devices being protected by this solution.
Most of the machines in our environment are in areas that don't have internet access. This is because they are stationed in remote areas of the country. This means that we need to use USB drives to update the machines manually. Given the number of devices and that the management is done manually at this time, it is pretty painful for our IT people.
How are customer service and technical support?
We have not purchased support for this product, although, for most products, we usually do have it. To this point, it hasn't been required.
Which solution did I use previously and why did I switch?
When we were running older operating systems including Windows XP and Windows Vista, we had a Symantec Endpoint solution. We had that for a long time but we opted out. After that, we used McAfee and other antivirus products. However, since Windows 10 was released, and with Microsoft Defender included by default, we felt that it was the solution for us.
As I recall, we stopped using McAfee and Symantec once we moved to Windows 8.
How was the initial setup?
This product came pre-installed with Windows 10 on the machines that we procured from the vendor. It is straightforward and easy to configure, as well. Once Windows is installed, setting up the antivirus and scheduling scans just involves clicking the Next button several times. It is pretty easy for anyone and if the user is non-technical, we guide them through the process.
It takes a maximum of 10 to 15 minutes to install and configure on a PC. Whenever a new configuration is required, you need to configure it on each individual machine that you have. This is why we are investigating a centralization solution. It will help us out in applying things on a global level. For example, we can apply settings based on what is in Active Directory or other policies.
What about the implementation team?
One person, in-house, is all that is required to set it up.
There is not much maintenance required, as our environment is pretty standard. Also, all of the updates come from the Microsoft update center and they are automatically installed on the machines.
What was our ROI?
It is difficult to determine ROI at this point. Once all of our PCs are joined together, we will have a better idea.
What's my experience with pricing, setup cost, and licensing?
As we operate in the educational sector, we are eligible for an educational discount.
Which other solutions did I evaluate?
We are currently looking into other solutions that will give us centralized control over Microsoft Defender. However, we are still strictly in the research phase.
Once we decide on a product and a solution is proposed, it is a long process that involves budgetary considerations. Once a PoC is completed, the budget constraints are considered, and this is part of a very long chain of processes that take place before final adoption.
What other advice do I have?
Since we started using this product, we have not had any breaches. When we were using the products by McAfee and Symantec, there were issues with viruses and malicious payloads. Now, it is better because we haven't had any major issues with the systems.
My advice for anybody who is implementing this product is to let the IT staff manage it, and not allow end-users to configure it or modify their own settings.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Manager at a financial services firm with 1,001-5,000 employees
Quick and responsive support, stable, improves security, and requires little maintenance
Pros and Cons
- "Microsoft's technical support is fantastic."
- "At times, the other antivirus products are now doing AI, in terms of understanding the behavior of the system and determining when there's an anomaly. This is something that Defender can improve on."
What is our primary use case?
We primarily use this product to get antivirus protection in a cost-effective way.
How has it helped my organization?
This product tends to detect a lot more issues than the other antivirus solutions. This is because it's essentially tuned to Microsoft. It has some inbuilt intelligence, so they tend to understand the Microsoft environment and we don't need to do as much exclusion. With other antivirus products, we need to exclude certain files from being scanned.
What is most valuable?
The malware detection feature is very good.
What needs improvement?
At times, the other antivirus products are now doing AI, in terms of understanding the behavior of the system and determining when there's an anomaly. This is something that Defender can improve on.
For how long have I used the solution?
I have been working with Microsoft Defender Antivirus for between two and three years.
What do I think about the stability of the solution?
This is a stable solution that has matured over the years.
What do I think about the scalability of the solution?
We have approximately 7,000 machines and we have not needed to scale beyond our original implementation.
How are customer service and technical support?
Microsoft's technical support is fantastic.
We subscribe to the Microsoft Premier Support Package and they tend to respond to our queries very fast. When our engineers contact them, they respond in a very short time.
Which solution did I use previously and why did I switch?
We currently use Cylance, in addition to Microsoft Defender. I'm not sure what the impact is of using two solutions, whether it is a good thing, or not. We do plan on narrowing this down to one solution in the future.
How was the initial setup?
This product was included with Windows 10, so we did not have to deploy it separately.
Once this product is set up, this solution requires very little maintenance.
What's my experience with pricing, setup cost, and licensing?
We already use Microsoft solutions and I found it cheaper to purchase the bundle, which includes Defender. By including the antivirus in the bundle, it makes it a little cheaper for us. If you purchase it outside of the bundle, it is a little bit expensive.
When you want the central administration functionality, it tends to be more expensive. The normal, standalone model is not expensive, but the enterprise model that includes the bundle with email and some web protection, is a bit more expensive.
What other advice do I have?
When we initially implemented Windows Defender, we were pessimistic about whether it would be good enough. However, it is a pretty mature product now.
My advice for anybody who is considering this product is that it's good, and it gets results early.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Engineer at a financial services firm with 1,001-5,000 employees
Has good stability but they update the platform too frequently
Pros and Cons
- "It's pretty easy to scale."
- "In terms of improvement, they update the platform it seems quite a bit. Every month something is in a new spot or something changed somewhere. There should be less of that."
What is our primary use case?
We use the most up-to-date version.
Our primary use case is for basic EDRs for simple interfaces.
What needs improvement?
In terms of improvement, they update the platform it seems quite a bit. Every month something is in a new spot or something changed somewhere. There should be less of that.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for a couple of months.
What do I think about the stability of the solution?
It seems stable.
What do I think about the scalability of the solution?
It's pretty easy to scale.
A handful of people with each in charge of different areas are involved in the maintenance of the solution. It's people in system admin.
How are customer service and technical support?
I have dealt with tech support a couple of times. They're usually pretty responsive. The first person might not know what the deal is, but they usually are able to get us to the right person, get a resolution for us, and answer our questions pretty quickly.
Which solution did I use previously and why did I switch?
We used CrowdStrike but we switched to Microsoft because of the price. It's cheaper. There were other major differences.
How was the initial setup?
The initial setup was pretty complex in the way the various tools integrate. Trying to figure out permissions and getting access to certain things is complex.
Global admin uses the tool, but then you have to get additional roles for the data loss stuff.
What other advice do I have?
Make sure you read the documentation and understand what else is required before you get started.
I would rate it a seven out of ten.
I don't think that another tool is doing anything better, or this one doesn't. It's just about using it and seeing where to find the stuff.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technical Manager at SAPEC
Light on resources, easy installation, and reliable
Pros and Cons
- "One of the main features is the solution is very light on resources and we do not have any problems with it."
- "There is room to improve the security of the solution."
What is our primary use case?
We use this solution for business security protection.
What is most valuable?
One of the main features is the solution is very light on resources and we do not have any problems with it.
What needs improvement?
There is room to improve the security of the solution.
We have plans to add an email security solution because this solution does not provide us with what we want.
For how long have I used the solution?
I have been using this solution for approximately three years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
I have found the scalability of the solution good.
Which solution did I use previously and why did I switch?
We were previously using the Avast security solution.
How was the initial setup?
The installation is very easy, it takes only one day.
What about the implementation team?
We did the implementation ourselves. We have approximately 10 engineers able to do the deployments and maintenance.
What's my experience with pricing, setup cost, and licensing?
There is not a license required for this particular solution.
What other advice do I have?
I would recommend this solution to others.
I rate Microsoft Defender Antivirus an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Engineer at a educational organization with 5,001-10,000 employees
Pre-installed, free, and easy to use, but the free version doesn't provide centralized management, EDR, and behavioral analysis
Pros and Cons
- "It is easy to use because it is already pre-installed in Windows 10. We don't have to do anything to configure it. You can also configure the firewall by using a group policy so that it can be easily adopted in an environment."
- "Microsoft Defender in the basic form is not very useful for managing the security environment. The free version is not capable of covering the needs of centralized management, EDR, and behavioral analysis. If you don't have the commercial version, you can't have centralized management and set up the policies and other things. Each client is a standalone installation, which is not useful for security in an enterprise model."
What is our primary use case?
We were using the basic endpoint from Sophos without Intercept X and the EDR model, and currently, we are in the selection process of a new platform that has EDR embedded. We are using Microsoft Defender Antivirus for the time being till we get the new platform.
What is most valuable?
It is easy to use because it is already pre-installed in Windows 10. We don't have to do anything to configure it. You can also configure the firewall by using a group policy so that it can be easily adopted in an environment.
What needs improvement?
Microsoft Defender in the basic form is not very useful for managing the security environment. The free version is not capable of covering the needs of centralized management, EDR, and behavioral analysis. If you don't have the commercial version, you can't have centralized management and set up the policies and other things. Each client is a standalone installation, which is not useful for security in an enterprise model.
For how long have I used the solution?
I have been using this solution for six months.
What do I think about the scalability of the solution?
Currently, we have about 2,000 users.
How are customer service and technical support?
I didn't use support for this solution.
How was the initial setup?
It was already pre-installed in Windows 10.
What's my experience with pricing, setup cost, and licensing?
It is free. It is included in Windows 10.
Which other solutions did I evaluate?
We are using Microsoft Defender only for the time being. We will switch to another endpoint platform that can offer us more advanced features, centralized management, and EDR. We have not chosen the solution at the moment, but we might go for Bitdefender. It is one of the products that we have evaluated, and it can be suitable for our environment. It has some use cases that are really in the same line as our requirements.
What other advice do I have?
I would recommend this solution only for small home environments. It is not for enterprise environments unless you buy the commercial version.
I would rate Microsoft Defender Antivirus a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2026
Product Categories
Endpoint Protection Platform (EPP) Advanced Threat Protection (ATP) Anti-Malware Tools Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
CrowdStrike Falcon
Microsoft Intune
Microsoft Entra ID
Microsoft Defender for Cloud
Cortex XDR by Palo Alto Networks
Microsoft Defender for Office 365
SentinelOne Singularity Complete
Microsoft Sentinel
IBM Security QRadar
Fortinet FortiEDR
HP Wolf Security
Huntress Managed EDR
Elastic Security
Microsoft Defender XDR
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Compare Microsoft Windows Defender and Symantec Endpoint Protection. How Do I Choose?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- What do you think of the integration of Azure AD Services, Defender for Endpoint, and Intune as comprehensive security solutions?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- Running Carbon Black Defense Along with Windows Defender
- How is Cortex XDR compared with Microsoft Defender?
- Which offers better endpoint security - Symantec or Microsoft Defender?
- How does Microsoft Defender for Endpoint compare with Carbon Black CB Defense?
- How would you compare between Microsoft Defender for Endpoint and Tanium EDR?













