We primarily use this product to get antivirus protection in a cost-effective way.
IT Manager at a financial services firm with 1,001-5,000 employees
Quick and responsive support, stable, improves security, and requires little maintenance
Pros and Cons
- "Microsoft's technical support is fantastic."
- "This is a stable solution that has matured over the years."
- "At times, the other antivirus products are now doing AI, in terms of understanding the behavior of the system and determining when there's an anomaly. This is something that Defender can improve on."
- "At times, the other antivirus products are now doing AI, in terms of understanding the behavior of the system and determining when there's an anomaly. This is something that Defender can improve on."
What is our primary use case?
How has it helped my organization?
This product tends to detect a lot more issues than the other antivirus solutions. This is because it's essentially tuned to Microsoft. It has some inbuilt intelligence, so they tend to understand the Microsoft environment and we don't need to do as much exclusion. With other antivirus products, we need to exclude certain files from being scanned.
What is most valuable?
The malware detection feature is very good.
What needs improvement?
At times, the other antivirus products are now doing AI, in terms of understanding the behavior of the system and determining when there's an anomaly. This is something that Defender can improve on.
Buyer's Guide
Microsoft Defender for Endpoint
April 2026
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
893,244 professionals have used our research since 2012.
For how long have I used the solution?
I have been working with Microsoft Defender Antivirus for between two and three years.
What do I think about the stability of the solution?
This is a stable solution that has matured over the years.
What do I think about the scalability of the solution?
We have approximately 7,000 machines and we have not needed to scale beyond our original implementation.
How are customer service and support?
Microsoft's technical support is fantastic.
We subscribe to the Microsoft Premier Support Package and they tend to respond to our queries very fast. When our engineers contact them, they respond in a very short time.
Which solution did I use previously and why did I switch?
We currently use Cylance, in addition to Microsoft Defender. I'm not sure what the impact is of using two solutions, whether it is a good thing, or not. We do plan on narrowing this down to one solution in the future.
How was the initial setup?
This product was included with Windows 10, so we did not have to deploy it separately.
Once this product is set up, this solution requires very little maintenance.
What's my experience with pricing, setup cost, and licensing?
We already use Microsoft solutions and I found it cheaper to purchase the bundle, which includes Defender. By including the antivirus in the bundle, it makes it a little cheaper for us. If you purchase it outside of the bundle, it is a little bit expensive.
When you want the central administration functionality, it tends to be more expensive. The normal, standalone model is not expensive, but the enterprise model that includes the bundle with email and some web protection, is a bit more expensive.
What other advice do I have?
When we initially implemented Windows Defender, we were pessimistic about whether it would be good enough. However, it is a pretty mature product now.
My advice for anybody who is considering this product is that it's good, and it gets results early.
I would rate this solution an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Information Security Engineer at a financial services firm with 1,001-5,000 employees
Has good stability but they update the platform too frequently
Pros and Cons
- "It's pretty easy to scale."
- "We used CrowdStrike but we switched to Microsoft because of the price."
- "In terms of improvement, they update the platform it seems quite a bit. Every month something is in a new spot or something changed somewhere. There should be less of that."
- "In terms of improvement, they update the platform it seems quite a bit. Every month something is in a new spot or something changed somewhere; there should be less of that."
What is our primary use case?
We use the most up-to-date version.
Our primary use case is for basic EDRs for simple interfaces.
What needs improvement?
In terms of improvement, they update the platform it seems quite a bit. Every month something is in a new spot or something changed somewhere. There should be less of that.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for a couple of months.
What do I think about the stability of the solution?
It seems stable.
What do I think about the scalability of the solution?
It's pretty easy to scale.
A handful of people with each in charge of different areas are involved in the maintenance of the solution. It's people in system admin.
How are customer service and technical support?
I have dealt with tech support a couple of times. They're usually pretty responsive. The first person might not know what the deal is, but they usually are able to get us to the right person, get a resolution for us, and answer our questions pretty quickly.
Which solution did I use previously and why did I switch?
We used CrowdStrike but we switched to Microsoft because of the price. It's cheaper. There were other major differences.
How was the initial setup?
The initial setup was pretty complex in the way the various tools integrate. Trying to figure out permissions and getting access to certain things is complex.
Global admin uses the tool, but then you have to get additional roles for the data loss stuff.
What other advice do I have?
Make sure you read the documentation and understand what else is required before you get started.
I would rate it a seven out of ten.
I don't think that another tool is doing anything better, or this one doesn't. It's just about using it and seeing where to find the stuff.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Microsoft Defender for Endpoint
April 2026
Learn what your peers think about Microsoft Defender for Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: April 2026.
893,244 professionals have used our research since 2012.
Technical Manager at SAPEC
Light on resources, easy installation, and reliable
Pros and Cons
- "One of the main features is the solution is very light on resources and we do not have any problems with it."
- "One of the main features is the solution is very light on resources and we do not have any problems with it."
- "There is room to improve the security of the solution."
- "There is room to improve the security of the solution."
What is our primary use case?
We use this solution for business security protection.
What is most valuable?
One of the main features is the solution is very light on resources and we do not have any problems with it.
What needs improvement?
There is room to improve the security of the solution.
We have plans to add an email security solution because this solution does not provide us with what we want.
For how long have I used the solution?
I have been using this solution for approximately three years.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
I have found the scalability of the solution good.
Which solution did I use previously and why did I switch?
We were previously using the Avast security solution.
How was the initial setup?
The installation is very easy, it takes only one day.
What about the implementation team?
We did the implementation ourselves. We have approximately 10 engineers able to do the deployments and maintenance.
What's my experience with pricing, setup cost, and licensing?
There is not a license required for this particular solution.
What other advice do I have?
I would recommend this solution to others.
I rate Microsoft Defender Antivirus an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Engineer at a educational organization with 5,001-10,000 employees
Pre-installed, free, and easy to use, but the free version doesn't provide centralized management, EDR, and behavioral analysis
Pros and Cons
- "It is easy to use because it is already pre-installed in Windows 10. We don't have to do anything to configure it. You can also configure the firewall by using a group policy so that it can be easily adopted in an environment."
- "It is easy to use because it is already pre-installed in Windows 10."
- "Microsoft Defender in the basic form is not very useful for managing the security environment. The free version is not capable of covering the needs of centralized management, EDR, and behavioral analysis. If you don't have the commercial version, you can't have centralized management and set up the policies and other things. Each client is a standalone installation, which is not useful for security in an enterprise model."
- "Microsoft Defender in the basic form is not very useful for managing the security environment."
What is our primary use case?
We were using the basic endpoint from Sophos without Intercept X and the EDR model, and currently, we are in the selection process of a new platform that has EDR embedded. We are using Microsoft Defender Antivirus for the time being till we get the new platform.
What is most valuable?
It is easy to use because it is already pre-installed in Windows 10. We don't have to do anything to configure it. You can also configure the firewall by using a group policy so that it can be easily adopted in an environment.
What needs improvement?
Microsoft Defender in the basic form is not very useful for managing the security environment. The free version is not capable of covering the needs of centralized management, EDR, and behavioral analysis. If you don't have the commercial version, you can't have centralized management and set up the policies and other things. Each client is a standalone installation, which is not useful for security in an enterprise model.
For how long have I used the solution?
I have been using this solution for six months.
What do I think about the scalability of the solution?
Currently, we have about 2,000 users.
How are customer service and technical support?
I didn't use support for this solution.
How was the initial setup?
It was already pre-installed in Windows 10.
What's my experience with pricing, setup cost, and licensing?
It is free. It is included in Windows 10.
Which other solutions did I evaluate?
We are using Microsoft Defender only for the time being. We will switch to another endpoint platform that can offer us more advanced features, centralized management, and EDR. We have not chosen the solution at the moment, but we might go for Bitdefender. It is one of the products that we have evaluated, and it can be suitable for our environment. It has some use cases that are really in the same line as our requirements.
What other advice do I have?
I would recommend this solution only for small home environments. It is not for enterprise environments unless you buy the commercial version.
I would rate Microsoft Defender Antivirus a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Managing Director at a financial services firm with 10,001+ employees
Reliable, well-priced, and it is easy to install
Pros and Cons
- "We use Microsoft Defender for the antivirus."
- "It's a stable solution."
- "The interface could be improved."
- "The interface could be improved."
What is our primary use case?
There are endpoints that are not in our organization's network but are connected directly to the web. We use Microsoft Defender for the antivirus.
We are not dealing with this solution daily, just when there is an issue from time to time.
What needs improvement?
The interface could be improved.
For how long have I used the solution?
I have been using Microsoft Defender for Endpoint for a couple of years.
What do I think about the stability of the solution?
It's a stable solution.
What do I think about the scalability of the solution?
We are only running it on a few workstations. The scalability is okay.
It's run on 10 out of 3,000 workstations and we plan to continue using it.
We have no more than 10 users in our organization.
Which solution did I use previously and why did I switch?
We are also using Symantec.
We have a few endpoints where we use Microsoft Defender because we cannot use the Symantec Sets.
How was the initial setup?
The initial setup was straightforward. It was easy to install and t only took a couple of minutes.
There is no team for maintenance. If there is an issue, the security team helps to resolve it.
What about the implementation team?
We completed the deployment and implementation ourselves.
What's my experience with pricing, setup cost, and licensing?
We don't have an issue with the price.
We have a bundle where the price includes all Microsoft products.
This is an area that I am not dealing with. I don't have all of the information.
What other advice do I have?
It's pretty good.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Specialist at a healthcare company with 10,001+ employees
Good support and valuable EDR feature, but not stable and not suitable for enterprises with lots of other processes and third-party tools
Pros and Cons
- "The EDR feature is most valuable."
- "I would recommend this solution to others if they don't have many third-party tools."
- "It is currently more suitable for end-users rather than enterprises with lots of other processes and third-party tools. It needs improvement on that front. We had many issues while integrating it with our enterprise solutions, such as Splunk, and third-party tools. It provides everything via APIs. Other vendors provide integration with third-party tools, but Microsoft doesn't do that. It is also logging too much and is not serialized from the process aspect. It has all the data, but it is not in a proper format or not properly indexed, which doesn't make it easier for enterprises to use this data. Other vendors provide troubleshooting information that can be used to troubleshoot issues, but Microsoft doesn't provide anything like that."
- "It is also logging too much and is not serialized from the process aspect. It has all the data, but it is not in a proper format or not properly indexed, which doesn't make it easier for enterprises to use this data."
What is our primary use case?
We use it for our endpoint detection and response capability.
What is most valuable?
The EDR feature is most valuable.
What needs improvement?
It is currently more suitable for end-users rather than enterprises with lots of other processes and third-party tools. It needs improvement on that front. We had many issues while integrating it with our enterprise solutions, such as Splunk, and third-party tools. It provides everything via APIs. Other vendors provide integration with third-party tools, but Microsoft doesn't do that.
It is also logging too much and is not serialized from the process aspect. It has all the data, but it is not in a proper format or not properly indexed, which doesn't make it easier for enterprises to use this data.
Other vendors provide troubleshooting information that can be used to troubleshoot issues, but Microsoft doesn't provide anything like that.
For how long have I used the solution?
I have been using this solution for six months.
What do I think about the stability of the solution?
It is still a new product, and there are many reported bugs in terms of stability and impact on the endpoints.
What do I think about the scalability of the solution?
We have around 80,000 users.
How are customer service and technical support?
They are good. They take a little bit of time, but they are good.
How was the initial setup?
It was very complex. We had many issues in integrating it with our enterprise solutions, such as Splunk, and third-party tools.
What about the implementation team?
We have seven or eight engineers for its maintenance.
What other advice do I have?
I would recommend this solution to others if they don't have many third-party tools. It is a very good solution.
I would rate Microsoft Defender for Endpoint a seven out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Solution Architect at KIAN company
Simple to use, flexible, easy to update, but the central management console needs improvement
Pros and Cons
- "This product is flexible, and it is very easy to get updates from the Microsoft website."
- "It is very simple to use and easy to scan systems."
- "The central management console should be improved because it provides limited options to configure Windows Defender."
- "The central management console should be improved because it provides limited options to configure Windows Defender."
What is our primary use case?
This product is our antivirus for Windows 10 machines, Windows Server 2016, and in our Azure environment. In addition to this, we have a project for an oil company that is implemented in Azure, and we had to migrate the majority of their systems to that platform. Once the migration was complete, we configured Windows Defender as its antivirus.
What is most valuable?
It is very simple to use and easy to scan systems.
This product is flexible, and it is very easy to get updates from the Microsoft website.
We are using the firewall features.
What needs improvement?
The central management console should be improved because it provides limited options to configure Windows Defender. It should provide a lot of options and features, in the same way, that Symantec does, or the Kaspersky Central Management Console does. Essentially, we should have a central management console on Azure that can be used to manage Windows Defender on all of our machines.
What do I think about the stability of the solution?
This is a very stable solution and we plan to continue using it.
What do I think about the scalability of the solution?
The company that I implemented this for has approximately 2,000 staff and 1,000 virtual machines on Azure.
How are customer service and technical support?
I have not been in contact with Microsoft support. Rather, I have learned by using the materials that are provided online.
Which solution did I use previously and why did I switch?
We were originally using a product from Symantec before we switched to using Windows Defender. After that, we adopted the Microsoft solution for Azure.
How was the initial setup?
I have configured Windows Defender for different locations by using Group Policy Settings and each time, it took between five and ten minutes, based on the guidelines.
What about the implementation team?
I configured it personally by downloading and reading materials that I found on the Microsoft website.
What's my experience with pricing, setup cost, and licensing?
This is an expensive product and licensing for all Microsoft products is a big issue. However, Volume Licensing and Educational Licensing are good options to decrease the cost.
What other advice do I have?
In general, Windows Defender is a good feature for the Windows Operating System.
I would rate this solution a seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Solutions Architect at SC PROSERVICECORP SRL
A simple solution with good integration, price, stability, scalability, and support
Pros and Cons
- "Its simplicity is the most valuable. It also has very good integration. We like it."
- "It is very stable, highly recommended, free with the purchase of Windows Server, and it is doing its job for Microsoft Windows Server as a good product."
- "Its interface can be improved a little bit. We would like to have some sort of centralization. It should have something like a central server that is managing all the other clients. There are solutions from Kaspersky or ESET NOD32 that are really doing this kind of thing currently. We would like to see something similar from Microsoft."
- "Its interface can be improved a little bit. We would like to have some sort of centralization."
What is our primary use case?
We are using Microsoft Windows Defender for Windows services because it is the default antivirus and protection solution with Windows Server 2016 and 2019. We are using it for Windows servers, file servers, and active directory.
What is most valuable?
Its simplicity is the most valuable. It also has very good integration. We like it.
What needs improvement?
Its interface can be improved a little bit. We would like to have some sort of centralization. It should have something like a central server that is managing all the other clients. There are solutions from Kaspersky or ESET NOD32 that are really doing this kind of thing currently. We would like to see something similar from Microsoft.
For how long have I used the solution?
We have been using this solution for more than two years.
What do I think about the stability of the solution?
It is very stable. It is highly recommended.
What do I think about the scalability of the solution?
It has good scalability. We are happy with it and plan to increase its usage. We currently have around 20 users.
How are customer service and technical support?
Technical support is good. We like Microsoft, and they provide good technical support.
How was the initial setup?
It is straightforward.
What about the implementation team?
We implemented it by ourselves.
What's my experience with pricing, setup cost, and licensing?
Currently, for us, Windows Defender is free with the purchase of Windows Server. Pricing is an important point for us when we are looking at the competitors of this solution. If we choose to go with another vendor, we will have to pay some license fees.
What other advice do I have?
We are considering moving to another solution, so we are trying to inform ourselves about the other products in the market that will fit our budget and needs. We are trying to see what the competitors offer in the server market. We are looking into ESET NOD32 because we know the product from back in the day.
I would recommend this solution. It is free, and it is doing its job for Microsoft Windows Server. It is a good product. I would rate Microsoft Defender for Endpoint a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2026
Product Categories
Endpoint Protection Platform (EPP) Advanced Threat Protection (ATP) Anti-Malware Tools Endpoint Detection and Response (EDR) Microsoft Security SuitePopular Comparisons
CrowdStrike Falcon
Microsoft Intune
Cortex XDR by Palo Alto Networks
Microsoft Entra ID
Microsoft Defender for Cloud
SentinelOne Singularity Endpoint
IBM Security QRadar
Microsoft Defender for Office 365
Microsoft Sentinel
Huntress Managed EDR
Elastic Security
HP Wolf Security
Trellix Endpoint Security Platform
Microsoft Defender XDR
Buyer's Guide
Download our free Microsoft Defender for Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Compare Microsoft Windows Defender and Symantec Endpoint Protection. How Do I Choose?
- Which product would you choose: Microsoft Defender for Endpoint vs Cortex XDR by Palo Alto Networks?
- What do you think of the integration of Azure AD Services, Defender for Endpoint, and Intune as comprehensive security solutions?
- CrowdStrike Falcon vs Microsoft Defender ATP: Comparison of features and performance
- How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
- Running Carbon Black Defense Along with Windows Defender
- How is Cortex XDR compared with Microsoft Defender?
- Which offers better endpoint security - Symantec or Microsoft Defender?
- How does Microsoft Defender for Endpoint compare with Carbon Black CB Defense?
- How would you compare between Microsoft Defender for Endpoint and Tanium EDR?













