My main use case is to showcase Microsoft Defender for Office 365 to help demonstrate the product so we can assist Microsoft in selling it to other companies.
Manager at a comms service provider with 1,001-5,000 employees
Identifies phishing threats accurately and reduces time spent on manual email reviews
Pros and Cons
- "The coolest feature of Microsoft Defender for Office 365 is its ability to look for phishing emails."
- "Sometimes I have to recategorize things when it takes the wrong step and I do not want it to classify something as suspicious."
What is our primary use case?
What is most valuable?
The coolest feature of Microsoft Defender for Office 365 is its ability to look for phishing emails. That has been one of the biggest problems I have seen in my previous companies—detecting phishing emails and identifying bad actors who are trying to steal information, whether they are posing as managers to subordinates or even as our clients. Microsoft Defender for Office 365 stops that in its tracks.
Microsoft Defender for Office 365 works really well. It gets better each year as the technology develops. It saves us time—I would say it saves us 50% less time instead of having to manually look at emails in Outlook.
I use Microsoft Defender for Office 365 to automate tasks. You can use the AI agents to automate the tasks and then they can do it for you. That is where the time savings come in.
Microsoft Defender for Office 365 saves us time and money. Time is money, and money is time.
What needs improvement?
I think if Microsoft Defender for Office 365 could provide a report at the end of each month showing how many emails it has stopped and how well our systems are working, along with suggestions on ways we can improve our own systems and other products we could use that work better with it, that would be helpful. I do not see that functionality right now while we are developing this.
For how long have I used the solution?
Our company designs these products to showcase Microsoft Defender for Office 365, so I have been using it since I started two or three years ago.
Buyer's Guide
Microsoft Defender for Office 365
January 2026
Learn what your peers think about Microsoft Defender for Office 365. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
What do I think about the stability of the solution?
I have not noticed any downtime or crashes with Microsoft Defender for Office 365.
What do I think about the scalability of the solution?
Microsoft Defender for Office 365 scales with time. We try a lot of Microsoft products because they are our biggest client.
What other advice do I have?
Microsoft Defender for Office 365 works pretty. Sometimes I have to recategorize things when it takes the wrong step and I do not want it to classify something as suspicious. But most of the time it works when you play with the tool and make it work for you in a better way.
For the most part, Microsoft Defender for Office 365 prioritizes threats by making sure, especially in Office 365, that people do not click on links and things of that nature. If it detects a threat, I can go in and double check those emails to determine if it is correct or wrong. I think it does a pretty good job at that. But once in a while it goes the wrong way and I have to recategorize it.
Mostly the important threats are getting detected by Microsoft Defender for Office 365.
For us to design Microsoft Defender for Office 365 for Microsoft, we deployed it in our own email systems to see how it works and to figure out how many emails it stops. Once we know how the program functions, we can present it so Microsoft can sell it more effectively. I would rate this product a ten out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Nov 20, 2025
Flag as inappropriateTechnology Associate at a financial services firm with 51-200 employees
Protects sensitive financial data and prevents phishing threats through seamless integration
Pros and Cons
- "The features I appreciate most about Microsoft Defender for Office 365 are admin notifications for potential threats along with protecting our Microsoft apps such as Outlook from potential phishing attacks."
- "To improve Microsoft Defender for Office 365, it would be nice to have more accessibility for users to see on their end what they are doing that could cause a threat."
What is our primary use case?
My main use cases for Microsoft Defender for Office 365 include application and endpoint security for end users.
What is most valuable?
The features I appreciate most about Microsoft Defender for Office 365 are admin notifications for potential threats along with protecting our Microsoft apps such as Outlook from potential phishing attacks. These features have definitely benefited our organization, especially when we've had phishing attacks occur, and we have highly secure data because we're in financial services, so data security is pretty critical for us. Along with that, endpoint security for our applications is essential as a lot of our Excel files contain proprietary financial information that we want to protect. It's really important to have that capability.
What needs improvement?
To improve Microsoft Defender for Office 365, it would be nice to have more accessibility for users to see on their end what they are doing that could cause a threat. Sometimes users do things without realizing they may be causing an issue until we inform them, so better processes for notifications would be useful.
For how long have I used the solution?
I have been using Microsoft Defender for Office 365 for probably the past two years, around a year and a half.
What do I think about the stability of the solution?
The stability and reliability of Microsoft Defender for Office 365 is quite stable compared to our previous service, and while there are things that could be improved, it is definitely better and more cost-effective than other solutions we looked at. I have not experienced any downtime, crashes, or performance issues because of Defender.
What do I think about the scalability of the solution?
Microsoft Defender for Office 365 scales very well with the growing needs of my organization because we are a slower-growing organization and stay at the same pace, so there's not much scaling needed. However, it does perform well because it is within our Azure subscription and runs seamlessly within our tenant.
We have expanded usage by migrating everyone to Intune-managed devices so they are on Microsoft Defender for Office 365, which was one of our big projects this year to move off our old system.
How are customer service and support?
I would evaluate the customer service and technical support as great since we have been able to get pretty good service, and I haven't had any downtime or outages with our Azure service. On a scale from one to ten, I would rate my customer service and technical support as an eight. I give them an eight because I think a ten is hard to achieve since it would need to be almost perfect, and there have been some Azure outages causing minor issues. Overall, it has been a much better process than we used to have.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Prior to adopting Microsoft Defender for Office 365, we were using another solution to address similar needs. We used Sophos before, and several factors led us to consider a change including performance, cost, support, and scalability. It caused performance issues for end users because it needed to use a lot of resources, and it was also going to cost more to maintain. Additionally, it wasn't the most up-to-date cloud solution which we now get through Azure and Microsoft Defender for Office 365.
How was the initial setup?
My experience with the deployment has been a lot more seamless as we use Autopilot for that, so it's easier than manually installing a local cyber defending service on each user's endpoints, definitely saving us time there.
What was our ROI?
I believe I have seen a return on investment because in the long run, we're saving money on subscription costs for a different service and having everything under one roof.
What's my experience with pricing, setup cost, and licensing?
My experience with the pricing, setup costs, and licensing is not too specific, but having all our users with Entra ID accounts and being on Intune made it a lot more seamless and easy, as most of our devices and subscriptions are through Microsoft.
Which other solutions did I evaluate?
I am not too sure about the other solutions we considered before selecting Microsoft Defender for Office 365, but I know that Defender was our first and most ideal choice since we do use the Microsoft suite.
What other advice do I have?
My advice to another organization considering Microsoft Defender for Office 365 is that if you're already using Microsoft 365 for your end users, it's a great product to put on top of that because it integrates seamlessly within your existing Microsoft suite and is a lot easier to manage than having a separate security service. I would rate this product a nine.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Nov 19, 2025
Flag as inappropriateBuyer's Guide
Microsoft Defender for Office 365
January 2026
Learn what your peers think about Microsoft Defender for Office 365. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
Especialista en ciberseguridad at a university with 1,001-5,000 employees
Provides reliable security and peace of mind for personal use
Pros and Cons
- "I think that Microsoft Defender for Office 365 could be improved if it could use VirusTotal to compare the programs or anything that I download."
What is our primary use case?
I use Microsoft Defender for Office 365 on my personal computer, and it's easier here because I don't use the internet to visit inappropriate pages or download anything suspicious from rare sites.
I use Microsoft Defender for Office 365 only on-premises, not cloud, because for cloud services, I use my Gmail account.
Microsoft Defender for Office 365 meets my security needs, as it helps me monitor how my computer is performing. Although I am a cybersecurity specialist and have other tools, I use Microsoft Defender for Office 365 to check my computer and those of my parents or friends.
I am using Microsoft Defender for Office 365, as well as Microsoft Process Explorer, but not much else yet because I work everything in virtual machines.
What is most valuable?
Microsoft Defender for Office 365 is always active on Windows; I didn't need to configure anything, and if there's something different or suspicious, it alerts me immediately. It's very easy to use. I know that it's a very simple defense, but I use my computer very carefully.
What I appreciate about Microsoft Defender for Office 365 is that it's free and comes as an on-premise product by default, so no additional setup is required. It comes by default and gives the client a safety sensation, allowing people to be careful and more relaxed with their computer.
I have seen benefits from using Microsoft Defender for Office 365, as it gives users a relaxed feeling of being protected. I don't usually experience any alerts unless I am playing in Hack The Box and using a virtual machine.
The integration of Microsoft Defender for Office 365 with other Microsoft products enhances my security, as I don't have any problems with the whole Microsoft product suite.
What needs improvement?
I think that Microsoft Defender for Office 365 could be improved if it could use VirusTotal to compare the programs or anything that I download. VirusTotal helps to identify viruses, malware, trojans, and worms. For example, if I download software to edit videos, if it could scan it through VirusTotal before I execute the installation, it would tell me if the software has anything suspicious.
For how long have I used the solution?
I have been using Microsoft Defender for Office 365 for approximately two years.
How are customer service and support?
I rate technical support from Microsoft a 10 because when I have a problem with my computer, they have always been very good.
How would you rate customer service and support?
Positive
Which other solutions did I evaluate?
At this moment, I'm not using any solutions because I was only making a market study of Proofpoint and Perception Point.
What other advice do I have?
The threat investigation tools in Microsoft Defender for Office 365 don't influence my security response times too much because now I am not working with it, but I am very careful with my computer since I know how the field is.
I am not using any artificial intelligence with Microsoft Defender for Office 365; I only use ChatGPT for my personal use.
I haven't recommended Microsoft Defender for Office 365 yet, but if I have a situation where I need to recommend it, I would do so.
I rate Microsoft Defender for Office 365 a nine out of ten.
Which deployment model are you using for this solution?
On-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Google
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Aug 11, 2025
Flag as inappropriateSolution Consultant at a tech services company with 51-200 employees
Offers seamless policy configuration and integration for improved security management
Pros and Cons
- "Overall, I would rate Microsoft Defender for Office 365 at a ten."
- "Microsoft could improve by offering recommendations for domain spoofing attacks, especially scenarios where DNS records like SPF, DKIM, and DMARC are not properly published."
What is our primary use case?
We use Microsoft Defender for Office 365 as part of Microsoft XDR solution. It offers native integration within Microsoft Ecosystem and provides proactive recommendations that help enhance our organization's security. Additionally, it is used to protect on-premises mail flow by redirecting it to Defender EOP.
How has it helped my organization?
The solution saves time due to its easy policy configuration and licensing process. It integrates naturally with Sentinel, which simplifies IT and technical configuration tasks with minimal clicks, offering flexibility and efficiency.
What is most valuable?
Microsoft Defender for Office 365 provides natively integrated cybersecurity tools that are part of Microsoft Ecosystem. It offers proactive recommendation tasks to enhance organizational security. It provides end-to-end visibility on email threats such as phishing, extending beyond Exchange Online Protection. The scalability is managed by Microsoft as a cloud-hosted tool, relieving us of those concerns.
What needs improvement?
Microsoft could improve by offering recommendations for domain spoofing attacks, especially scenarios where DNS records like SPF, DKIM, and DMARC are not properly published. It's essential to enhance awareness about these issues within organizations.
For how long have I used the solution?
I have experience in Microsoft Defender for Office 365 for the past three years.
What was my experience with deployment of the solution?
Deployment is straightforward due to a comprehensive guide provided by Microsoft. It's easy to deploy, and anyone with a security background can apply it without difficulty.
What do I think about the stability of the solution?
The solution is stable, as we have been using it for the past two years. Sometimes it generates false positive alerts, but adjusting policies resolves these issues. Security products occasionally provide false positives, so alignment of configuration is necessary.
What do I think about the scalability of the solution?
As a cloud-hosted tool, scalability is great. We have never faced scalability problems, and Microsoft manages it effectively. We only need to focus on configuring policies.
How are customer service and support?
I would rate customer service at a five out of five. Over the past two years, there have been no critical problems. Any issues are addressed quickly by Microsoft's support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Microsoft offers an affordable and feature-rich security solution compared to third-party email security tools like Trend Micro.
How was the initial setup?
The initial setup is easy due to Microsoft's deployment guide.
What's my experience with pricing, setup cost, and licensing?
Microsoft is quite affordable with a lot of features available for any size organization.
What other advice do I have?
Overall, I would rate Microsoft Defender for Office 365 at a ten. My experience with the visibility into threats is positive; Microsoft provides transparency and regularly improves its products. Most of the customers using Microsoft Defender for Office 365 in our region belong to the financial sector.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Infrastructure and Security Lead at a program development consultancy with 201-500 employees
Centralized tenant enables group control but setup process complicates implementation
Pros and Cons
- "Scalability-wise, I do not think there are any issues so far."
- "The visibility into threats is not up to the mark, as I do not have control. I rate my experience with Microsoft Defender for Office 365 as six out of ten due to troubleshooting and pricing concerns."
What is our primary use case?
We replaced one earlier antivirus because earlier whatever was there, yeah.
What is most valuable?
Actually earlier, I used to have full controls with Trend Micro. Microsoft Defender for Office 365 is now part of a centralized tenant for my entire group. I don't have control on that, as another team is maintaining it. Since I don't have full visibility of the features, I cannot make significant comments.
What needs improvement?
The main area for improvement is simplifying the implementation and rollout process. There are many conditions to be met, making it challenging to ensure every system is protected. Troubleshooting is difficult, especially at the endpoint level.
For how long have I used the solution?
I have been using this solution for about one year.
What do I think about the stability of the solution?
I am not sure about stability.
What do I think about the scalability of the solution?
Scalability-wise, I do not think there are any issues so far.
How are customer service and support?
I am not aware of Microsoft support because I don't have access to the admin consoles. Therefore, I do not connect to technical support.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
We were using Trend Micro before switching to Microsoft Defender for Office 365. Trend Micro was more cost-effective and manageable.
How was the initial setup?
The initial setup is a bit challenging due to multiple dependencies, such as on SCCM and Intune, and the need for co-managed services.
What's my experience with pricing, setup cost, and licensing?
Money-wise, it is a part of the Office 365 suite, making it slightly more expensive compared to Trend Micro. Although Defender is free, you have to pay separately for EDR.
What other advice do I have?
The visibility into threats is not up to the mark, as I do not have control. I rate my experience with Microsoft Defender for Office 365 as six out of ten due to troubleshooting and pricing concerns. Overall product rating: 6
Which deployment model are you using for this solution?
NA
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Deputy Manager at a tech services company with 11-50 employees
It can integrate with third-party tools, improves compliance, and helps prevent advanced attacks
Pros and Cons
- "The most valuable feature of Microsoft Defender for Office 365 is data backups that we can provide through ticket requests."
- "Microsoft Defender for Office 365's Mac functionality requires improvement to deliver the same level of protection found on Windows devices."
What is our primary use case?
I use Microsoft Defender for Office 365 for various compliance tasks. For example, I can use it for eDiscovery to search mailbox content. Just today, a manager requested all emails for a departing user who no longer had an active license. Using Defender's content search feature, I exported the user's entire mailbox as a PST file for the manager to import into Outlook. Beyond eDiscovery, Defender also helps us monitor compliance and security scores, manage quarantine emails, investigate phishing alerts, and configure data classification, labeling, anti-spam, and anti-malware policies.
Before using Microsoft Defender for Office 365, we were plagued by phishing and ransomware emails, especially for our board members. To combat this, we implemented a Defender policy that triggers alerts for emails containing keywords like "bank account" or "credit card details." Additionally, a policy tip and disclaimer appear in user mailboxes for such emails. This disclaimer clarifies the email's external origin and allows users to move it directly to junk with a single click. Simultaneously, an alert goes to the administrator, who investigates the email: if legitimate, it's released, otherwise it's blocked.
Our organization operates a single, hybrid tenant environment with a mix of on-premises and cloud-based mailboxes, with the majority residing in the cloud. This small, non-multi-tenant setup supports approximately 2,000 users.
How has it helped my organization?
While Microsoft Defender for Office 365 integrates with third-party solutions, our organization prioritizes Microsoft technologies for security. We only integrate external tools with explicit management approval. This focus extends to data backup. Even though Office 365 is a cloud service, we recently purchased Barracuda, a tool that seamlessly integrates with Office 365 for data backup.
Prior to my arrival, our organization lacked a dedicated Office 365/Microsoft 365 security specialist, with IT admins relying on web searches for configuration. Upon identifying vulnerabilities, I implemented Microsoft Defender and other security measures. Our compliance score, which was around 30 percent a year and a half ago, now consistently ranges from 75 to 85 percent, thanks in large part to Microsoft Defender for Office 365.
Microsoft Defender for Office 365 helps prevent advanced attacks like business email compromise by stopping lateral movement within the network. It also includes data loss prevention features, where our custom policies have helped block malicious emails, ransomware, and spam before they ever reach our servers. While not perfect, Microsoft Defender has significantly improved our email security, offering around 80 to 90 percent effectiveness, which we're quite happy with.
Microsoft Defender for Office 365 has significantly improved our security team's efficiency. The comprehensive security analytics dashboard provides insightful information on threats, including the number of phishing attempts and attacks on our servers. This data can be easily exported for clear reporting to management. Overall, Microsoft Defender for Office 365 saves us time and simplifies security analysis presentations.
What is most valuable?
Our long-established organization has faced recent economic downturns, leading to employee departures. Managers frequently request departing users' SharePoint data, Mailboxes including PST files, and other associated information. So the most valuable feature of Microsoft Defender for Office 365 is data backups that we can provide through ticket requests.
What needs improvement?
Microsoft Defender for Office 365's Mac functionality requires improvement to deliver the same level of protection found on Windows devices.
For how long have I used the solution?
I have been using Microsoft Defender for Office 365 for two years.
What do I think about the stability of the solution?
I would rate the stability of Microsoft Defender for Office 365 nine out of ten.
What do I think about the scalability of the solution?
Microsoft Defender for Office 365 is highly scalable.
How are customer service and support?
I've found that Microsoft's third-party support teams are slow to resolve issues. While they do eventually fix the problem, it can take a week for issues that should only take a day or two. In contrast, Microsoft employees can typically resolve issues within two days.
How would you rate customer service and support?
Neutral
How was the initial setup?
While deploying Microsoft Defender for Office 365 in my previous organization with multiple tenants was complex, the current single-tenant setup was easy.
We had a team of four involved in the deployment. Two were in the United States and Belgium and two were in India.
What about the implementation team?
The implementation was completed in-house.
What's my experience with pricing, setup cost, and licensing?
While Microsoft Defender for Office 365 necessitates pricier E3 or E5 subscriptions, the extensive functionality offered by these licenses across various Microsoft products justifies the investment.
What other advice do I have?
I would rate Microsoft Defender for Office 365 eight out of ten.
Microsoft Defender for Office 365 is deployed in multiple regions in India, China, Belgium, Italy, and the United States.
So far, no maintenance has been required yet, but we regularly check Microsoft's security advisories and discuss them in our scrum meetings. If an advisory requires action, we'll address it accordingly.
I would recommend Microsoft Defender for Office 365 to others.
With over ten years of experience using Microsoft 365 and Microsoft 365 Defender exclusively, I've successfully implemented it at multiple companies. While the upfront cost may seem high, it delivers value based on your infrastructure size. Overall, Microsoft Defender is an excellent security product for any environment, regardless of size.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Technology support manager at a educational organization with 501-1,000 employees
The solution enables efficient management and updates through the cloud
Pros and Cons
- "Microsoft Defender for Office 365 facilitates efficient management and updates through the cloud. We do not have to worry about incompatibilities. It just works."
- "The stability of Microsoft Defender for Office 365 is fantastic."
- "I am generally satisfied with how it currently is. If I could improve anything, I would reduce the cost."
What is our primary use case?
We mainly use Microsoft Defender for Office 365 for people who teach or work remotely. This allows us to effectively control and monitor them.
How has it helped my organization?
We have faculty who aren't even near the college. Some of our faculty are in other cities and teach remotely. Microsoft Defender for Office 365 enables us to manage everything through the cloud, so we don't have to ship anything back and forth. We can do updates or address any issues with computers remotely.
What is most valuable?
Microsoft Defender for Office 365 facilitates efficient management and updates through the cloud. We do not have to worry about incompatibilities. It just works. My team appreciates the threat visibility Defender offers. It ranks the threats and allows us to prioritize those hitting us the hardest, such as email threats.
What needs improvement?
I am generally satisfied with how it currently is. If I could improve anything, I would reduce the cost.
For how long have I used the solution?
The college has been using Microsoft Defender for Office 365 for more than two years. I have been there for a year.
What do I think about the stability of the solution?
The stability of Microsoft Defender for Office 365 is fantastic.
What do I think about the scalability of the solution?
The scalability of Microsoft Defender for Office 365 is fantastic, same as its stability.
How are customer service and support?
I rate Microsoft support nine out of 10. Customer service and support have been fantastic. We have direct Microsoft support, which we subscribe to and pay for.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I don't know which solution was used before since it was in place when I started.
How was the initial setup?
I can't provide specifics since I was not involved before my tenure, but based on my experience, it was seamless.
What about the implementation team?
The implementation was all done in-house, without the use of an integrator, reseller, or consultant.
What was our ROI?
Defender has reduced the time our security team spends on tasks by 10 to 15 percent, allowing us to focus on other areas. It has also decreased our time to detection and response by about 15 to 20 percent.
What's my experience with pricing, setup cost, and licensing?
I don't have detailed specifics on pricing, setup cost, or licensing.
Which other solutions did I evaluate?
I don't know about any other solutions that were evaluated before my tenure.
What other advice do I have?
I rate Microsoft Defender for Office 365 a nine out of 10 because it works seamlessly without any incompatibilities.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cloud Security Specialist at a tech services company with 1-10 employees
Covers customer’s IT assets and aggregates insights from different workloads
Pros and Cons
- "One of the best features of the tool is its capability to aggregate insights from different workloads, basically from the Office 365 and endpoints part."
- "Configuring the default strategies and policies in Microsoft Defender for Cloud Apps generates a lot of noise and false positives."
What is our primary use case?
As a specialist in SOC, we work closely with multiple customers to cover their IT assets using Microsoft 365 Defender. They have Microsoft Defender for Endpoint deployment, especially for Microsoft 365. We configure the tool to implement the different policies and requirements to cover the email security part and the cloud apps part with the different strategies available on the platform.
After that, we either work directly on the Microsoft 365 portal or configure the sending of the alerts from this portal to Microsoft Sentinel. This will act as a single pane of glass for us to follow the incidents and advise our customers based on that.
What is most valuable?
One of the best features of the tool is its capability to aggregate insights from different workloads, basically from the Office 365 and endpoints part. With the integration of Microsoft Defender for Identity and Microsoft Entra ID Protection, we will have insights from the identity part. Finally, with the Microsoft Defender for Cloud Apps, we'll also have insights about our cloud apps, either Microsoft 365 cloud apps or third-party cloud apps.
The aggregation of all of these insights into the tool's incident feature will help us have a global vision of the incidents and find multistage attacks at the first steps of the attacks.
What needs improvement?
Microsoft Defender for Cloud Apps is a very good solution that allows you to use a single port or tool to control everything happening with your organization's different cloud applications.
Configuring the default strategies and policies in Microsoft Defender for Cloud Apps generates a lot of noise and false positives. Also, the documentation does not have many details about that. The bad configuration and lack of good documentation prevent professionals from taking the most advantage of this tool.
One of the big problems that some customers face is that Microsoft always changes its products' names. For example, four to six months ago, Microsoft Defender for Office 365 was renamed Microsoft Defender XDR. Microsoft comes up with a new name for the tool every one or two years, which sometimes is hard for customers to follow.
Microsoft should improve some integrations in the Microsoft Defender for Cloud Apps sub-category. With a specific configuration to Microsoft Defender for Endpoint, we can get logs and insights from network devices and other workloads on our system.
For how long have I used the solution?
I have been using Microsoft Defender for Office 365 for two years.
What do I think about the stability of the solution?
I rate the solution an eight or nine out of ten for stability.
What do I think about the scalability of the solution?
We configure the tool for different clients, and thousands of people work with the solution. The tool scales out very well and can cover and monitor devices and users ranging from a few hundred to thousands without any problem. Our clients for Microsoft Defender for Office 365 are medium and small businesses. Microsoft Defender for Office 365 is a scalable solution. There are no issues with the solution's scalability or latency.
I rate the solution's scalability ten out of ten.
How are customer service and support?
The technical support for the solution is very good, and I didn't face any issues with it.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have previously used CrowdStrike Falcon. Microsoft Defender for Office 365 and CrowdStrike Falcon are both great tools. Each has its advantages and disadvantages. In my opinion, CrowdStrike is more mature in the endpoint and classic antivirus parts. On the other hand, Microsoft Defender for Office 365 is more mature regarding identity and Office 365.
For artificial intelligence integration, Microsoft 365 Defender is far ahead of others with the integration of CoPilot within the portal. This feature that helps analysts reduce time to analyze and respond to incidents does not exist in CrowdStrike.
How was the initial setup?
The solution's initial setup is very straightforward. You have to go to the portal and click on the incident icon, and the tool will automatically start configuring itself. After that, the integration of the endpoints depends on your workload. For example, 1,000 devices will take much longer than two or three devices.
Automation tools are available within the platform to help us automatically deploy the sensors on different workloads that we will need to cover with this tool. The solution's initial configuration and deployment are very straightforward. A lot of videos and documentation are available for the same.
What about the implementation team?
The initial configuration and deployment of the tool for a specific tenant takes five to ten minutes. After that, it depends on what you want to do. You can implement specific strategies today. Based on the evolution of threats, you will need to configure different things tomorrow.
What other advice do I have?
We tried to solve a lot of issues by implementing the solution. The solution helps us detect problems related to the endpoints, like the detection of suspicious processes or suspicious installation of suspicious software. We will raise an alert, and it will show us a graph of the different entities included in the incident, including users, computers, or endpoints.
If it is related to email, it will show us the initial email and different insights about the incident. We'll go through those alerts and try to check them manually. Sometimes, the tool detects suspicious emails for some incidents and automatically quarantines them.
After that, we, as analysts, will do the manual review. If we find an action suspicious, we use the tool to blocklist the domain that has sent the email. If we find that it's a false positive, we will reject this automatic action by the XDR, and the email will be delivered to the end user.
Unified identity and access management is a new feature on the Microsoft 365 Defender portal. It's all about having a single pane of glass to give you insights into the different identities available on your tenant. Those identities are either on-premises, cloud-based, or synchronized between the on-premises and cloud-based workloads.
The solution's security covers more than just Microsoft technologies. Microsoft Defender for Endpoint and Microsoft Defender for Cloud Apps have a specific configuration to get insights from third-party cloud applications or from within the Microsoft Defender for Endpoint sensors. We can also get logs and insights from other network devices present in our perimeter, like routers, switches, or firewalls. All those insights will help us gain some visibility into our security posture.
The product has gone through a lot of improvements, especially in the last few moments. It will be like a SOC unified platform with the integration of the Microsoft Sentinel tool within the Microsoft 365 Defender portal. This tool is available to cover all the perimeters. Even third-party solutions and workloads that do not have any security tools from where we can get insights, we can directly use something else to install the low connectors and get visibility about those.
Also, the most significant evolution is the integration of artificial intelligence with Microsoft Copilot for security. This is also a big added value that will help analysts investigate and minimize the meantime needed to respond to advanced threats.
The solution stops the lateral movement of advanced attacks, like ransomware or business email compromise, in a good way. Specific measures and configurations are implemented within the tool that will help us detect advanced attacks in the early stages. We can set configurations for business email compromise.
With the help of artificial intelligence, we'll get insights about emails that may be starting a business email compromise based on specific keywords. It's the same for ransomware and other advanced attacks.
The solution's integration into a company will help it be more resilient to cyber attacks. It will help the company prepare for attacks at an early stage and respond quickly, which will help it be more secure.
Being an XDR, the solution has detection and response capabilities. With adequate configuration, we can configure the required measures to stop or at least quarantine attacks and isolate the assets involved with the attacks in the early stage upon detection. After that, the manual site comes into the picture, and we do the manual review. Based on our review and feedback, the tool will learn from us and behave better in the next similar incident.
I saw a demo about the solution's multi-tenant management feature, and it's a very good feature. It will help big companies with multiple tenants and MSSPs that deal with multiple tenants for users. It will help them to work with multiple tenants by flipping a switch.
I'm a big fan of the solution. Having a Microsoft E5 license will help you to cover all the different types of security, including the identity, the endpoint, the email, and even the cloud. I'm just an engineer and work with whatever tool the client provides me. I noticed that many customers have a Microsoft E5 license, but they don't know a lot about the capabilities that come with it.
They buy or add other tools from third parties when they have that feature or capability included within the E5 license. Microsoft needs to talk to different customers and show them the capabilities that come with these types of licenses, which cover a lot of features.
The integration of Copilot has helped us a lot in concentrating on a single portal to get different insights. This will help a lot to reduce the meantime to respond to incidents by 50%.
The configuration of the Copilot assistant is very straightforward and doesn't take more than 30 minutes. After that, when the tool automatically detects incidents and you go to the analysis page of a specific incident, you will find an initial analysis of the whole incident by the Copilot security assistant.
You may also interact with it using chat, and it will help you if you haven't understood any specific terms from the initial analysis. It can be configured to automatically respond to specific incidents based on workbooks, which will help us automatically apply the measures to respond to specific incidents for remediation.
Microsoft Defender for Office 365 is a cloud-based solution. Since it's a cloud-based solution, Microsoft does all the maintenance for the tool. We are notified via email if there is a shortage or a problem. The SLAs are usually very good, and I have not noticed any problems in the last two years where we could not access the tool.
I would recommend the solution to other users because it's a very good solution and one of the best XDRs in the world right now. If you go through reviews from Gartner or other companies, you will see that Microsoft Defender for Office 365 is a leader in the XDR market. It has the capability to collect and aggregate insights from different sources, either cloud-based or on-premises.
The integration of artificial intelligence will greatly help final users and security practitioners respond to incidents adequately and efficiently.
Overall, I rate the solution an eight out of ten.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
Buyer's Guide
Download our free Microsoft Defender for Office 365 Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Email Security Email Archiving Advanced Threat Protection (ATP) Microsoft Security Suite Secure Email Gateway (SEG)Popular Comparisons
Microsoft Intune
Microsoft Defender for Endpoint
Microsoft Entra ID
Microsoft Defender for Cloud
Microsoft Purview Data Governance
Microsoft Defender XDR
Cloudflare One
Proofpoint Email Protection
ESET Endpoint Protection Platform
Check Point Harmony Email & Collaboration
Palo Alto Networks WildFire
Cisco Secure Email
Microsoft Exchange Online Protection (EOP)
Microsoft Defender for Cloud Apps
Buyer's Guide
Download our free Microsoft Defender for Office 365 Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which solution do you prefer: Microsoft Defender for Office 365 or Proofpoint Email Protection?
- Is Defender for Office 365 enough? Or should we be using a product like Mimecast?
- Have you done a comparison between BeyondTrust Endpoint Privilege Management and Microsoft Defender?
- Which product do you prefer: Symantec Messaging Gateway or Microsoft Defender?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- When evaluating Messaging Security, what aspect do you think is the most important to look for?
- Which Email Security enterprise solution would you choose: Cisco Secure Email vs Forcepoint Email Security vs Barracuda Email Security Gateway?
- What is the best email encryption software for small enterprises using Office 365?
- What security measures should businesses prioritize to support secure remote work?
- When evaluating Email Security tools, what aspects do you think are the most important to look for?











