My primary use cases for Microsoft Defender for Office 365 in my company revolve around endpoint security.
Microsoft 365 in general helps with security needs, and I could receive notifications about potential threats.
Designation Chief Consultant at Avtow
Automated threat detection enhances task efficiency and visibility
Pros and Cons
- "The ability to respond to threats if very important."
- "My experience deploying Microsoft Defender for Office 365 was seamless."
- "Specifically, within Microsoft Defender for Office 365, I want it to improve the DLP capabilities."
What is our primary use case?
How has it helped my organization?
It's easy for people who use the Microsoft environment.
What is most valuable?
The ability to respond to threats if very important. My company has close to 1000 users, managing through Microsoft endpoints, and we require protection of our files.
My impression of the visibility into threats that Microsoft Defender for Office 365 provides is that visibility is quite essential.
This solution helps automate routine tasks and helps automate the finding of high-value alerts. It's fairly robust.
Threat intelligence helps prepare for potential threats before they hit endpoints. Security operations people also get notifications to understand how the system is doing.
Time to detection has stayed the same.
What needs improvement?
Specifically, within Microsoft Defender for Office 365, I want it to improve the DLP capabilities.
Buyer's Guide
Microsoft Defender for Office 365
June 2026
Learn what your peers think about Microsoft Defender for Office 365. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
902,495 professionals have used our research since 2012.
For how long have I used the solution?
I have been using Microsoft Defender for Office 365 for more than three years.
What do I think about the stability of the solution?
We haven't had performance issues.
How are customer service and support?
I honestly have not actually seen anything demos for their support, so I don't have direct real experience.
Which solution did I use previously and why did I switch?
We did previously use a different solution. Defender helps us save time and energy and we don't have to manage seperate solutions.
How was the initial setup?
My experience deploying Microsoft Defender for Office 365 was seamless. We deployed 365 and Defender at the same time, and it just worked. We didn't have to do anything significantly separate.
What was our ROI?
I have realized other benefits from using Microsoft Defender for Office 365, such as cost. It is bundled into the 365 license. Overall, cost of owning and operating our system goes down.
The cost of operation has reduced.
What's my experience with pricing, setup cost, and licensing?
The cost is reasonable. Overall, the cost of owning and operating goes down. We've likely saved 30% of costs.
What other advice do I have?
We do not use the solution to prioritize threats.
Microsoft Defender for Office 365 has not yet fully integrated with other security solutions within my environment. On a scale of one to ten, I rate Microsoft Defender for Office 365 an eight. There's always room for improvement.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer.
Chief Architect at a tech vendor with 1,001-5,000 employees
Security features help prioritize and respond to threats quickly, contributing to rapid threat response
Pros and Cons
- "The DLP feature of Microsoft Defender for Office 365 is valuable, and we also use the DLP feature for email real-time detection."
- "We still see many false positives from time to time with Microsoft Defender for Office 365, so it would be good if we can reduce those false positives and provide better workflows for our end users, as sometimes they may not know what to do when they encounter a false positive."
How has it helped my organization?
We use many Microsoft Security products, and overall, it's helping us with our overall security posture. Though we see some challenges, we want to see if the Security Copilot can help, but overall, it's very helpful and essential to our operations.
Microsoft Defender for Office 365 helps prioritize threats across our enterprise. The security products provide good visibility, allowing us to see and prioritize various events, which is crucial given the daily volume of events. We can see what's going on and prioritize. Because there are many different events, we can focus on the most important ones first. This prioritization of threats is very important. Otherwise, it may not be usable because we will be handling thousands of events every day.
The threat intelligence offered by Microsoft Defender for Office 365 helps us prepare for potential threats before they hit. It offers visibility and a focused response needed to manage threats promptly. The security features can effectively and quickly identify and prioritize threats, contributing to rapid threat response.
Our application is a SaaS solution, so we have many customers, and the cloud infrastructure is essential to our business. The security features of Microsoft Defender for Office 365 can quickly identify and prioritize threats, allowing our SecOps team to act quickly to respond to the threats.
Microsoft Defender for Office 365 has saved us time and money. It has decreased our time to detection or time to respond by approximately 10 times because we have 100 gigabytes of logs every day, and without automation, it would be impossible for humans to handle.
This will be a potential risk because if there's any security incident, that will cause reputational and financial damage. Being able to maintain our overall security posture with Microsoft Defender for Office 365 is invaluable.
What is most valuable?
The DLP feature of Microsoft Defender for Office 365 is pretty good. The DLP feature of Microsoft Defender for Office 365 is valuable, and we also use the DLP feature for email real-time detection. The value of the DLP feature is significant to us because we have internal data, sometimes sensitive, and the users may not always be aware of security and privacy, which might lead them to send out information mistakenly to external parties.
What needs improvement?
We still see many false positives from time to time with Microsoft Defender for Office 365, so it would be good if we can reduce those false positives and provide better workflows for our end users, as sometimes they may not know what to do when they encounter a false positive. Those kinds of workflows will help make it easier to use.
For how long have I used the solution?
We have been using Microsoft Defender for Office 365 since 2018.
What do I think about the stability of the solution?
Overall, the stability and reliability of Microsoft Defender for Office 365 are good, but we do see some hiccups from time to time. Maybe twice last year, we lost the Teams connection, but overall, it is within the SLA range.
What do I think about the scalability of the solution?
Microsoft Defender for Office 365 scales transparently for us, as we grew from 1,000 users to 3,000 users, and we didn't notice much difference.
How are customer service and support?
The technical support and customer support we received for Microsoft Defender for Office 365 are pretty good; we opened tickets, and they typically resolve them quickly.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have been using it from the beginning.
How was the initial setup?
It is pretty straightforward, but fine-tuning the rules takes time. We see false positives from time to time, so we need to find the rules to fix our situation.
We started with on-premises. Currently, it's like 80% cloud and 20% on-premises. Exchange and SharePoint are on the cloud, but AD is still hybrid.
What was our ROI?
Security is very important for us, and we are also a public company, so any security incident will cause serious damage, but it's hard to quantify the return on investment we've seen from Microsoft Defender for Office 365.
What's my experience with pricing, setup cost, and licensing?
It's within our expectations and also competitive in the market.
Which other solutions did I evaluate?
We didn't evaluate other solutions.
What other advice do I have?
Currently, we do not have automation actions with Microsoft Defender for Office 365. We mainly focus on the detection part because we find some false positives from time to time, so we are not 100% confident to turn on the fully automated mode.
I would rate Microsoft Defender for Office 365 a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Microsoft Defender for Office 365
June 2026
Learn what your peers think about Microsoft Defender for Office 365. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
902,495 professionals have used our research since 2012.
Technology support manager at Alfred State College
The solution enables efficient management and updates through the cloud
Pros and Cons
- "Microsoft Defender for Office 365 facilitates efficient management and updates through the cloud. We do not have to worry about incompatibilities. It just works."
- "The stability of Microsoft Defender for Office 365 is fantastic."
- "Defender has reduced the time our security team spends on tasks by 10 to 15 percent, allowing us to focus on other areas."
- "I am generally satisfied with how it currently is. If I could improve anything, I would reduce the cost."
What is our primary use case?
We mainly use Microsoft Defender for Office 365 for people who teach or work remotely. This allows us to effectively control and monitor them.
How has it helped my organization?
We have faculty who aren't even near the college. Some of our faculty are in other cities and teach remotely. Microsoft Defender for Office 365 enables us to manage everything through the cloud, so we don't have to ship anything back and forth. We can do updates or address any issues with computers remotely.
What is most valuable?
Microsoft Defender for Office 365 facilitates efficient management and updates through the cloud. We do not have to worry about incompatibilities. It just works. My team appreciates the threat visibility Defender offers. It ranks the threats and allows us to prioritize those hitting us the hardest, such as email threats.
What needs improvement?
I am generally satisfied with how it currently is. If I could improve anything, I would reduce the cost.
For how long have I used the solution?
The college has been using Microsoft Defender for Office 365 for more than two years. I have been there for a year.
What do I think about the stability of the solution?
The stability of Microsoft Defender for Office 365 is fantastic.
What do I think about the scalability of the solution?
The scalability of Microsoft Defender for Office 365 is fantastic, same as its stability.
How are customer service and support?
I rate Microsoft support nine out of 10. Customer service and support have been fantastic. We have direct Microsoft support, which we subscribe to and pay for.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I don't know which solution was used before since it was in place when I started.
How was the initial setup?
I can't provide specifics since I was not involved before my tenure, but based on my experience, it was seamless.
What about the implementation team?
The implementation was all done in-house, without the use of an integrator, reseller, or consultant.
What was our ROI?
Defender has reduced the time our security team spends on tasks by 10 to 15 percent, allowing us to focus on other areas. It has also decreased our time to detection and response by about 15 to 20 percent.
What's my experience with pricing, setup cost, and licensing?
I don't have detailed specifics on pricing, setup cost, or licensing.
Which other solutions did I evaluate?
I don't know about any other solutions that were evaluated before my tenure.
What other advice do I have?
I rate Microsoft Defender for Office 365 a nine out of 10 because it works seamlessly without any incompatibilities.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head of Department of Network Communications at Eko electricity
Great URL scanning and attachment scanning, but I would like more proactive threat analysis
Pros and Cons
- "The two main features that prove most beneficial for us are URL scanning and attachment scanning."
- "Microsoft Defender for Office 365 should be more proactive."
What is our primary use case?
We utilize Microsoft Defender for Office 365 to enhance our email protection.
All of our Office 365 solutions are stored in the cloud. We have recently acquired multiple licenses for Microsoft Defender for Office 365.
How has it helped my organization?
We also use DMS. I believe that integration comes out of the box because both products are from Microsoft and I haven't taken any steps to do any integration myself.
The comprehensiveness of DMS and Microsoft Defender for Office 365 has been incredibly helpful, particularly concerning email attachments. They have successfully identified numerous suspicious attachments, some of which were reported. The integration of these two solutions has proven to be extremely beneficial. Additionally, they have been effective in detecting phishing links and untrusted sites in emails on several occasions.
I remember what actually prompted us to switch to using Microsoft Defender for Office 365. We had several people who were not tech-oriented receiving loads of phishing emails, and their credentials were almost compromised. It wasn't just them; we had many other users in the organization facing similar issues. To address this, we conducted a phishing simulation, and unfortunately, a lot of people failed the simulation. After analyzing the situation, we realized the need to provide better training and implement additional security measures in case someone made a mistake or failed to follow proper procedures. That's why we decided to go with Microsoft Defender for Office 365. So far, it has been effective in identifying a lot of threats. Previously, we received several complaints about compromised credentials, mainly due to phishing emails. However, since we started using Microsoft Defender for Office 365, the number of complaints has drastically reduced. Although some people still fail our phishing simulation during in-house tests, externally, Microsoft Defender for Office 365 has proven valuable in filtering out numerous threats. I'm confident that without it, many accounts would have been compromised.
Microsoft Defender eliminates the need for multiple dashboards. When I'm on the Office 365 dashboard, I don't see any reason why I would need to access another dashboard.
Microsoft Defender for Office 365 identifies various threats and notifies us whenever it detects something suspicious. Without Microsoft Defender for Office 365, it would be quite time-consuming. We used to receive numerous complaints about credential tests, but since its deployment, those complaints have drastically reduced. Microsoft Defender for Office 365 has saved me a considerable amount of time.
It indirectly helps our organization reduce costs. We encountered a situation where one of our financial officers had their credentials stolen, and someone attempted to impersonate them, trying to transfer funds to other accounts. However, the system flagged the suspicious activity, and we were able to prevent the unauthorized transfer.
Microsoft Defender for Office 365 improves our ability to detect and respond to threats. It easily identifies all potential threats and promptly notifies us. I can only imagine the consequences if it weren't in place. Numerous suspicious links and attachments might have gone through, resulting in additional work and time spent on finding ways to remediate, resolve, and contain the situation.
What is most valuable?
The two main features that prove most beneficial for us are URL scanning and attachment scanning.
URL scanning involves an automatic scan of links and emails. When a user clicks on a link within an email, the system promptly checks the link's safety. If the link is deemed safe, access is granted automatically. However, if it is flagged as unsafe, we receive feedback and notification to caution us about the potentially harmful link. At this point, we are presented with the option to proceed or return. I have personally witnessed the system identify a few unsafe links, making this the primary advantage of using the solution.
The second crucial aspect is the scanning of attachments. When an email containing an attachment arrives, we receive a notification of the new email, along with information that the attachment is being scanned for threats. This additional layer of security provides peace of mind for our organization.
While Microsoft Defender for Office 365 offers numerous features, these two stand out as particularly impressive and valuable to us.
What needs improvement?
Microsoft Defender for Office 365 should be more proactive. As a major global player, Microsoft possesses the platform to gather more information than any other company. Utilizing this information would enable them to make the system much more proactive. It would be sensible for Microsoft Defender for Office 365 to send occasional notifications, acting as advisories on how to prevent the latest threat trends. Similar to a newsletter, these notifications could guide users to take appropriate measures and review their organization's configurations, thereby ensuring maximum security.
For how long have I used the solution?
I have been using Microsoft Defender for Office 365 for around four years.
What do I think about the stability of the solution?
Microsoft Defender for Office 365 is extremely stable. I have not seen any downtime.
What do I think about the scalability of the solution?
Microsoft Defender for Office 365 is scalable. We only need to add licenses to include more users.
How are customer service and support?
Eighty percent of the time, the technical support is good. There are occasions when we are redirected, which can be annoying, but for the most part, they are good.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup was straightforward. There wasn't much to do for Defender. We simply purchased the licenses and applied them to the users. It was a seamless deployment. As for Office 365, we had a couple of E3 licenses and had to install Office on the users' desktops. That proved to be a tedious task.
To deploy Microsoft Defender for Office 365, we simply wrote a script to assign licenses to users in bulk. Three people, including myself, handled the deployment.
What's my experience with pricing, setup cost, and licensing?
For small and medium organizations, the pricing might not be affordable. Although Microsoft Defender for Office 365 is a good product; something all organizations should have. However, the question is, can all organizations afford it? For large enterprise organizations, they can definitely afford it, but for small and medium organizations, they might struggle to cover the expenses.
Which other solutions did I evaluate?
We also assessed Sophos Email before implementing Microsoft Defender for Office 365. Since we were already using Office 365, we believed it would be a seamless and more effective option to proceed with Microsoft Defender for Office 365.
What other advice do I have?
I would rate Microsoft Defender for Office 365 a seven out of ten. The solution meets my expectations, but I would appreciate information on current threats and an increase in the level of intelligence gathering to be more proactive. It would be helpful to receive information on steps I can take to prevent potential threats, as our organization might be a target based on the threat intelligence it has gathered.
I have had a couple of Microsoft resellers try using Sentinel with my organization. Perhaps it was due to the configuration, but it didn't seem like there was much setup required. Essentially, we weren't able to see as many details as we expected, likely because we already have an in-house sync solution, and we were attempting to integrate Sentinel alongside it. Consequently, we also continued using the other solution. However, what we obtained from Sentinel, didn't provide us with much information compared to our existing solution. This is why we decided not to proceed further with the Proof of Concept for Sentinel. It's possible that the reseller didn't configure something properly, or maybe it didn't demonstrate some of the things it was supposed to. But based on our end-user experience, we didn't receive sufficient information from Sentinel as we do with our current solution. Hence, we made the decision not to move forward with the POC for Sentinel.
It is not advisable to engage with different vendors. This is because there will be instances where issues arise, and a particular vendor may not take responsibility for the problem. Dealing with multiple vendors makes it challenging to accomplish tasks efficiently, as we often find ourselves unsure about which vendor is accountable for each aspect. On the other hand, opting for a single vendor, even if they cannot fulfill all our requirements, is still preferable. This choice allows us to have a clear point of contact when something goes wrong, and the integrations are smoother. Additionally, using multiple vendors can lead to integration problems.
To properly utilize Microsoft Defender for Office 365, we must first acquire an Office 365 subscription. If we are already using Office 365 and seeking enhanced protection, Microsoft Defender for Office 365 becomes an obvious choice. It offers seamless integration and straightforward usage. To proceed effectively, we need a clear understanding of the users requiring protection and precise guidance on configuring the policies to ensure they provide the necessary protection effectively.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Engineer at a healthcare company with 10,001+ employees
Strengthens organizational security with proactive visibility
Pros and Cons
- "The most valuable feature of Microsoft Defender for Office 365 is its spam filter."
- "Microsoft needs to broaden its global support presence by establishing teams of subject-matter experts in all regions."
What is our primary use case?
We use Microsoft Defender for Office 365 to protect our Outlook 365 inboxes. When opening links in emails, Defender's URL defense verifies the legitimacy of the URL, ensuring it's not a spam link. This protection is active whenever clicking on any link within Outlook 365.
How has it helped my organization?
Our organization's security has been strengthened with Microsoft Defender for Office 365. Regardless of the specific tools we use for our daily office tasks, our data remains protected.
It provides great visibility into vulnerabilities compared to its competitors. Its insights and timely identification of Common Vulnerabilities and Exposures enable proactive threat mitigation, making it the preferred choice for comprehensive security.
Microsoft Defender for Office 365 is critical for our organization's security and privacy because it helps prioritize enterprise-wide threats and protects our sensitive data. Data breaches pose a significant financial risk, potentially costing millions or even billions of dollars, making Defender's role in safeguarding our data vital.
It automates routine tasks and prioritizes high-value alerts, providing automated insights to our security team. This allows us to proactively block harmful activities like anonymous calls and intrusions, significantly enhancing our overall security automation.
Microsoft Defender for Office 365 provides threat intelligence, enabling proactive threat mitigation. It monitors all network traffic, both incoming and outgoing, allowing us to track data and protect our network perimeter. This comprehensive monitoring includes network calls, enhancing our overall system security.
Microsoft Defender for Office 365 has helped to save us time and money and has reduced our time to detect and respond.
What is most valuable?
The most valuable feature of Microsoft Defender for Office 365 is its spam filter. This filter effectively reduces wasted time by automatically identifying and blocking spam emails before they reach our inboxes, moving them directly to the spam folder. This prevents the constant need to manually review and delete these unwanted messages.
What needs improvement?
Microsoft needs to broaden its global support presence by establishing teams of subject-matter experts in all regions.
For how long have I used the solution?
I have been using Microsoft Defender for Office 365 for six months to one year.
What do I think about the stability of the solution?
Microsoft Defender for Office 365 is stable.
What do I think about the scalability of the solution?
Microsoft Defender for Office 365 offers excellent scalability, as evidenced by Microsoft's support of nearly all Fortune 10 companies.
How are customer service and support?
The technical support is good, providing a clear channel for submitting requests. Based on the severity level, C1, C2, or C3, they consistently provide appropriate responses within the agreed-upon four-hour service level agreement.
How would you rate customer service and support?
Positive
What was our ROI?
As a technical user of Microsoft Defender for Office 365, I've seen a positive return on investment in how it helps secure our environment and ecosystem. The insights and intelligence provided have also been invaluable to our security team in securing our enterprise's information.
What other advice do I have?
I would rate Microsoft Defender for Office 365 nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Solution Consultant at BIM Group of Companies
Offers seamless policy configuration and integration for improved security management
Pros and Cons
- "Overall, I would rate Microsoft Defender for Office 365 at a ten."
- "Microsoft could improve by offering recommendations for domain spoofing attacks, especially scenarios where DNS records like SPF, DKIM, and DMARC are not properly published."
What is our primary use case?
We use Microsoft Defender for Office 365 as part of Microsoft XDR solution. It offers native integration within Microsoft Ecosystem and provides proactive recommendations that help enhance our organization's security. Additionally, it is used to protect on-premises mail flow by redirecting it to Defender EOP.
How has it helped my organization?
The solution saves time due to its easy policy configuration and licensing process. It integrates naturally with Sentinel, which simplifies IT and technical configuration tasks with minimal clicks, offering flexibility and efficiency.
What is most valuable?
Microsoft Defender for Office 365 provides natively integrated cybersecurity tools that are part of Microsoft Ecosystem. It offers proactive recommendation tasks to enhance organizational security. It provides end-to-end visibility on email threats such as phishing, extending beyond Exchange Online Protection. The scalability is managed by Microsoft as a cloud-hosted tool, relieving us of those concerns.
What needs improvement?
Microsoft could improve by offering recommendations for domain spoofing attacks, especially scenarios where DNS records like SPF, DKIM, and DMARC are not properly published. It's essential to enhance awareness about these issues within organizations.
For how long have I used the solution?
I have experience in Microsoft Defender for Office 365 for the past three years.
What was my experience with deployment of the solution?
Deployment is straightforward due to a comprehensive guide provided by Microsoft. It's easy to deploy, and anyone with a security background can apply it without difficulty.
What do I think about the stability of the solution?
The solution is stable, as we have been using it for the past two years. Sometimes it generates false positive alerts, but adjusting policies resolves these issues. Security products occasionally provide false positives, so alignment of configuration is necessary.
What do I think about the scalability of the solution?
As a cloud-hosted tool, scalability is great. We have never faced scalability problems, and Microsoft manages it effectively. We only need to focus on configuring policies.
How are customer service and support?
I would rate customer service at a five out of five. Over the past two years, there have been no critical problems. Any issues are addressed quickly by Microsoft's support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Microsoft offers an affordable and feature-rich security solution compared to third-party email security tools like Trend Micro.
How was the initial setup?
The initial setup is easy due to Microsoft's deployment guide.
What's my experience with pricing, setup cost, and licensing?
Microsoft is quite affordable with a lot of features available for any size organization.
What other advice do I have?
Overall, I would rate Microsoft Defender for Office 365 at a ten. My experience with the visibility into threats is positive; Microsoft provides transparency and regularly improves its products. Most of the customers using Microsoft Defender for Office 365 in our region belong to the financial sector.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Director at a energy/utilities company with 11-50 employees
Allows for easy reporting of problems, valuable anti-phishing, and anti-malware support
Pros and Cons
- "There are several features that I consider valuable."
- "The phishing and spam filters could use some improvement."
What is our primary use case?
I am the IT director for my organization, a small municipality with a population of 20,000 located in New Mexico. We employ 250 staff members. Our cybersecurity measures encompass a wide range, including endpoint management and the utilization of Windows Defender for Office 365. This software is internally deployed and primarily focuses on monitoring our email systems. This is where the most intricate configuration is applied. It examines our email traffic, aiming to prevent a significant amount of spam and numerous phishing attempts, although it cannot catch everything due to inherent limitations, it effectively performs tasks such as antivirus and antimalware functions within our email communication.
How has it helped my organization?
I would rate the visibility into threats eight out of ten.
Microsoft Defender for Office 365 assists to some extent in prioritizing threats across our enterprise, but it is not our primary tool for this purpose. I would rate the significance of this capability in Microsoft Defender for Office 365 a five out of ten.
I also utilize Windows Defender for both our desktops and mobile devices running on iOS and Android. Additionally, we employ Azure AD for authentication. All of these solutions have been seamlessly integrated into a unified dashboard. This integration process is highly straightforward and occurs automatically during the setup phase.
Our integrated solutions all work natively together to deliver coordinated threat responses.
Microsoft Defender for Office 365 assists in automating routine tasks and identifying high-value alerts. This has led to a 100 percent improvement in our security operations, as we had not implemented anything prior to the adoption of Microsoft Defender for Office 365.
Microsoft Defender for Office 365 has aided in decreasing the number of dashboards we need to monitor, although it does not eliminate all of them. As a cybersecurity practitioner, I still require external vulnerability management for certain third-party risk assessments; Microsoft Defender for Office 365 does not cover those aspects. Consequently, I utilize a separate product for that purpose.
It currently lacks built-in security awareness features. However, efforts are being made to develop such features. The initial stages of the security awareness program can already be observed in the Microsoft platform. Defender for Office 365 provides us with a tool called Safe Links, which enables us to analyze attachments, including both files and data. If someone attempts to access content that is later identified as malicious, we receive a notification. This allows us to identify users who may have interacted with harmful content to some extent, addressing active and potentially harmful interactions. If an individual receives a suspicious link, Safe Links examines the link for potential phishing characteristics. Although the link's malicious nature might not be immediately apparent, it is delivered within a protective Safe Links wrapper. Consequently, if the recipient clicks on the link, this action is logged within the Microsoft environment. Later, if the link is identified as part of a credential phishing attack, appropriate measures are taken. This includes deleting the associated email and notifying the user who clicked on the link. Subsequent actions may involve remediation, such as password changes if deemed necessary. This integration works seamlessly and proves to be highly effective.
Microsoft Defender for Office 365 has helped our organization save around 20 hours of work time.
It saves our organization money. No one would accuse the Microsoft product of being cheap or inexpensive. However, the reality is that most of the security functionality is included in the licensing that I need to purchase to support my operation. In other words, I'm not buying these security products separately; I'm obtaining them as part of my Microsoft 365 licensing. It's not an add-on; they are required components of the government cloud licensing that I have purchased. Therefore, I must acquire Microsoft 365 to access applications such as Office, SharePoint, OneDrive, Exchange, and others. The security features are all integrated within this package; I don't need to source them from elsewhere. Additionally, I would have had to pay for the performance products regardless.
What is most valuable?
There are several features that I consider valuable. These include anti-malware and anti-phishing capabilities, along with certain remediation abilities for addressing issues once identified. Moreover, the system allows for easy reporting of problems. In the event of a phishing attack, we can conveniently initiate a comprehensive search to identify all related elements of the campaign and remove them from users' mailboxes.
Additionally, the platform offers anti-spoofing measures targeting well-known high-value targets. This proactive approach helps in mitigating business email compromise by designating our high-value personnel. Consequently, any communication purporting to originate from these individuals undergoes a more rigorous verification process to ascertain its authenticity and whether it genuinely stems from a valid account associated with the respective individual.
What needs improvement?
Microsoft Defender for Office 365 lacks proactivity in assisting us with preparing for potential threats before they occur. While they employ a substantial amount of threat intelligence to preemptively prevent incidents, their effectiveness diminishes when it comes to delivering proactive threat intelligence alerts from Microsoft. Their focus primarily revolves around managing the internal environment. On the other hand, my other vendor, Check Point, along with my membership in MS-ISAC, supplements me with this type of information.
The phishing and spam filters could use some improvement. It is adequate, but it doesn't match the quality of Proofpoint or Mimecast. However, it comes close in effectiveness. Plus, if we're obtaining it for free, investing in the other products seems impractical.
For how long have I used the solution?
I have been using Microsoft Defender for Office 365 for around seven years.
How are customer service and support?
Obtaining technical services is challenging.
How would you rate customer service and support?
Negative
What other advice do I have?
I would rate Microsoft Defender for Office 365 eight out of ten.
I would rate the comprehensiveness of our integrated Microsoft products for threat protection a six out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Infrastructure and Security Lead at Vedanta
Centralized tenant enables group control but setup process complicates implementation
Pros and Cons
- "Scalability-wise, I do not think there are any issues so far."
- "The visibility into threats is not up to the mark, as I do not have control. I rate my experience with Microsoft Defender for Office 365 as six out of ten due to troubleshooting and pricing concerns."
What is our primary use case?
We replaced one earlier antivirus because earlier whatever was there, yeah.
What is most valuable?
Actually earlier, I used to have full controls with Trend Micro. Microsoft Defender for Office 365 is now part of a centralized tenant for my entire group. I don't have control on that, as another team is maintaining it. Since I don't have full visibility of the features, I cannot make significant comments.
What needs improvement?
The main area for improvement is simplifying the implementation and rollout process. There are many conditions to be met, making it challenging to ensure every system is protected. Troubleshooting is difficult, especially at the endpoint level.
For how long have I used the solution?
I have been using this solution for about one year.
What do I think about the stability of the solution?
I am not sure about stability.
What do I think about the scalability of the solution?
Scalability-wise, I do not think there are any issues so far.
How are customer service and support?
I am not aware of Microsoft support because I don't have access to the admin consoles. Therefore, I do not connect to technical support.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
We were using Trend Micro before switching to Microsoft Defender for Office 365. Trend Micro was more cost-effective and manageable.
How was the initial setup?
The initial setup is a bit challenging due to multiple dependencies, such as on SCCM and Intune, and the need for co-managed services.
What's my experience with pricing, setup cost, and licensing?
Money-wise, it is a part of the Office 365 suite, making it slightly more expensive compared to Trend Micro. Although Defender is free, you have to pay separately for EDR.
What other advice do I have?
The visibility into threats is not up to the mark, as I do not have control. I rate my experience with Microsoft Defender for Office 365 as six out of ten due to troubleshooting and pricing concerns. Overall product rating: 6
Which deployment model are you using for this solution?
NA
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Deputy Manager at Punchpower dream
It can integrate with third-party tools, improves compliance, and helps prevent advanced attacks
Pros and Cons
- "The most valuable feature of Microsoft Defender for Office 365 is data backups that we can provide through ticket requests."
- "Microsoft Defender for Office 365's Mac functionality requires improvement to deliver the same level of protection found on Windows devices."
What is our primary use case?
I use Microsoft Defender for Office 365 for various compliance tasks. For example, I can use it for eDiscovery to search mailbox content. Just today, a manager requested all emails for a departing user who no longer had an active license. Using Defender's content search feature, I exported the user's entire mailbox as a PST file for the manager to import into Outlook. Beyond eDiscovery, Defender also helps us monitor compliance and security scores, manage quarantine emails, investigate phishing alerts, and configure data classification, labeling, anti-spam, and anti-malware policies.
Before using Microsoft Defender for Office 365, we were plagued by phishing and ransomware emails, especially for our board members. To combat this, we implemented a Defender policy that triggers alerts for emails containing keywords like "bank account" or "credit card details." Additionally, a policy tip and disclaimer appear in user mailboxes for such emails. This disclaimer clarifies the email's external origin and allows users to move it directly to junk with a single click. Simultaneously, an alert goes to the administrator, who investigates the email: if legitimate, it's released, otherwise it's blocked.
Our organization operates a single, hybrid tenant environment with a mix of on-premises and cloud-based mailboxes, with the majority residing in the cloud. This small, non-multi-tenant setup supports approximately 2,000 users.
How has it helped my organization?
While Microsoft Defender for Office 365 integrates with third-party solutions, our organization prioritizes Microsoft technologies for security. We only integrate external tools with explicit management approval. This focus extends to data backup. Even though Office 365 is a cloud service, we recently purchased Barracuda, a tool that seamlessly integrates with Office 365 for data backup.
Prior to my arrival, our organization lacked a dedicated Office 365/Microsoft 365 security specialist, with IT admins relying on web searches for configuration. Upon identifying vulnerabilities, I implemented Microsoft Defender and other security measures. Our compliance score, which was around 30 percent a year and a half ago, now consistently ranges from 75 to 85 percent, thanks in large part to Microsoft Defender for Office 365.
Microsoft Defender for Office 365 helps prevent advanced attacks like business email compromise by stopping lateral movement within the network. It also includes data loss prevention features, where our custom policies have helped block malicious emails, ransomware, and spam before they ever reach our servers. While not perfect, Microsoft Defender has significantly improved our email security, offering around 80 to 90 percent effectiveness, which we're quite happy with.
Microsoft Defender for Office 365 has significantly improved our security team's efficiency. The comprehensive security analytics dashboard provides insightful information on threats, including the number of phishing attempts and attacks on our servers. This data can be easily exported for clear reporting to management. Overall, Microsoft Defender for Office 365 saves us time and simplifies security analysis presentations.
What is most valuable?
Our long-established organization has faced recent economic downturns, leading to employee departures. Managers frequently request departing users' SharePoint data, Mailboxes including PST files, and other associated information. So the most valuable feature of Microsoft Defender for Office 365 is data backups that we can provide through ticket requests.
What needs improvement?
Microsoft Defender for Office 365's Mac functionality requires improvement to deliver the same level of protection found on Windows devices.
For how long have I used the solution?
I have been using Microsoft Defender for Office 365 for two years.
What do I think about the stability of the solution?
I would rate the stability of Microsoft Defender for Office 365 nine out of ten.
What do I think about the scalability of the solution?
Microsoft Defender for Office 365 is highly scalable.
How are customer service and support?
I've found that Microsoft's third-party support teams are slow to resolve issues. While they do eventually fix the problem, it can take a week for issues that should only take a day or two. In contrast, Microsoft employees can typically resolve issues within two days.
How would you rate customer service and support?
Neutral
How was the initial setup?
While deploying Microsoft Defender for Office 365 in my previous organization with multiple tenants was complex, the current single-tenant setup was easy.
We had a team of four involved in the deployment. Two were in the United States and Belgium and two were in India.
What about the implementation team?
The implementation was completed in-house.
What's my experience with pricing, setup cost, and licensing?
While Microsoft Defender for Office 365 necessitates pricier E3 or E5 subscriptions, the extensive functionality offered by these licenses across various Microsoft products justifies the investment.
What other advice do I have?
I would rate Microsoft Defender for Office 365 eight out of ten.
Microsoft Defender for Office 365 is deployed in multiple regions in India, China, Belgium, Italy, and the United States.
So far, no maintenance has been required yet, but we regularly check Microsoft's security advisories and discuss them in our scrum meetings. If an advisory requires action, we'll address it accordingly.
I would recommend Microsoft Defender for Office 365 to others.
With over ten years of experience using Microsoft 365 and Microsoft 365 Defender exclusively, I've successfully implemented it at multiple companies. While the upfront cost may seem high, it delivers value based on your infrastructure size. Overall, Microsoft Defender is an excellent security product for any environment, regardless of size.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Collaboration Services Manager at Dow
File-sharing options and ease of collaboration or meetings allow for quick collaborations and chats
Pros and Cons
- "The product's scalability is good."
- "Microsoft wants its well-paying customers to finish testing some of its half-baked products, find bugs, and report bugs back to Microsoft's team, which is a little frustrating for those who have to manage it and roll it up to thousands of people across the organization."
What is our primary use case?
Over 4,000 employees across my organization use all of the products under Office 365, as it is super pervasive. Everybody uses them every day in my organization. My organization is a manufacturing company, where Office 365 has become a daily necessity.
How has it helped my organization?
I am a little biased towards Microsoft Teams because it is what I use and helps me pay my bills. In Microsoft Teams, file-sharing options and ease of collaboration or meetings allow for quick collaborations and chats.
What is most valuable?
I work in my company's IT department, so I use all of the products under Office 365 daily, including Microsoft Word, Microsoft PowerPoint, Microsoft Teams, and all the other components in the product. My company can't make it through a day or go by without using the products offered under Office 365. Some of our manufacturing workers may use Office 365 a lot less, but it is still necessary for things like Microsoft Outlook and Exchange.
I found Microsoft Teams to be the most valuable feature of the solution, along with all of the products and features offered under Office 365. My organization has remote workers, and we can't run the company without meetings organized with the help of Microsoft Teams.
What needs improvement?
It seems like Microsoft has begun to roll out products before they are fully baked. Microsoft wants its well-paying customers to finish testing some of its half-baked products, find bugs, and report bugs back to Microsoft's team, which is a little frustrating for those who have to manage it and roll it up to thousands of people across the organization. I would say that Microsoft should release or launch better or fully baked products before going ahead with the GA phase.
For how long have I used the solution?
I use Office 365 in my company as we have an enterprise contract with Microsoft from 2020 that ends in 2025, but it may get extended.
What do I think about the stability of the solution?
It is tough to speak about the stability-related area of the solution, especially considering that the newly released Microsoft Teams is not so great. The classic version of Microsoft Teams was relatively stable compared to its new version, but in our company, we faced some challenges with network performance. I don't know if there were any network performance issues at our end, with the ISPs, or at Microsoft's end, making it tough to pin it down.
What do I think about the scalability of the solution?
The product's scalability is good.
How are customer service and support?
Microsoft's support was great during the rollout period, especially since it was the product's operational phase. Microsoft's support team has scaled back, so my company has Microsoft365DSC for Microsoft Teams specifically. My company sometimes struggles with getting direct answers and real insights from Microsoft's support team, especially when we need a higher level of insight while no super technical questions need to be answered, leading to some frustrations.
I rate the technical support a seven out of ten.
How would you rate customer service and support?
Neutral
How was the initial setup?
I was involved in the deployment of Microsoft Teams but not the rest of Office 365. Nowadays, everything is complex, but the deployment of Microsoft Teams was pretty straightforward since my company got a lot of help from Microsoft directly.
What about the implementation team?
My company received direct help from Microsoft during our organization's deployment phase of Microsoft Teams.
What was our ROI?
I have seen a return on investment from the use of the product. With the product in place, my company no longer needs to rely on paper and pen in many ways, which has helped us save time, energy, effort, and money while ensuring an increase in productivity.
What's my experience with pricing, setup cost, and licensing?
I know that the product is incredibly expensive. I know that my company has high expectations from Microsoft because of the high cost. I also know that Microsoft delivers tremendous value for our company in terms of productivity and collaboration. With Copilot coming along, the value Microsoft provides to my company will be even higher than what it was previously, owing to the productivity gain and the reformulation of how we work because of AI.
Which other solutions did I evaluate?
I believe that my organization will get ready to start looking into other solutions in the market because our contract with Microsoft will come to an end in 2025. I think that the evaluation process will be something that is on the horizon next year. My company may evaluate all of the available options in the market against Microsoft.
What other advice do I have?
Unfortunately, I can't speak much about the visibility into threats that Microsoft's security solution provides.
I am unsure if the solution helps our organization prioritize threats across our enterprise, but I think it does. I get to leave the security part to be handled by the smart security personnel in my company.
I believe that Microsoft's security solution helps automate routine tasks and routine finding of high-value alerts. It is not my area of expertise, but the security team in my company seems to be pretty happy with the vendor.
I think the solution's threat intelligence helps my company prepare for potential threats before they hit us and helps us take some active steps.
I know that my company's security team is very aware of what Microsoft does, especially with Microsoft Defender and its related products. My company's security team is better equipped to stay at the front of any curve. My company's security team had approached me to speak about Microsoft Teams and asked me to tweak certain settings based on industry standards and the developments Microsoft has been coming forward with lately. The aforementioned aspects explain how threat intelligence affected my company's security operations.
Microsoft's security solution has helped my company save a lot of time, as we believe in being more proactive than cleaning up the mess at a later stage.
I am sure that the product helps my company save money, especially since it aids us in finding threats before they actually become a reality. Probably, my company saves millions in terms of money since we don't have to clean up any mess as the product has already prevented it.
I believe that the solution has helped my organization decrease the time to detect and respond to threats, but I can't explain how or how much.
I would suggest that others who plan to use it just find the right contact within Microsoft, work very closely with them, and lean on them as much as needed.
I rate the overall tool an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Microsoft Defender for Office 365 Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Product Categories
Email Security Email Archiving Advanced Threat Protection (ATP) Microsoft Security Suite Secure Email Gateway (SEG)Popular Comparisons
Microsoft Intune
Microsoft Defender for Endpoint
Cloudflare One
Microsoft Entra ID
Microsoft Defender for Cloud
Microsoft Purview Data Governance
Proofpoint Email Protection
Microsoft Defender XDR
Check Point Email Security (formerly Harmony Email & Collaboration)
ESET Endpoint Protection Platform
Palo Alto Networks WildFire
Mimecast Advanced Email Security
Cisco Secure Email
Buyer's Guide
Download our free Microsoft Defender for Office 365 Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which solution do you prefer: Microsoft Defender for Office 365 or Proofpoint Email Protection?
- Is Defender for Office 365 enough? Or should we be using a product like Mimecast?
- Have you done a comparison between BeyondTrust Endpoint Privilege Management and Microsoft Defender?
- Which product do you prefer: Symantec Messaging Gateway or Microsoft Defender?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- When evaluating Messaging Security, what aspect do you think is the most important to look for?
- Which Email Security enterprise solution would you choose: Cisco Secure Email vs Forcepoint Email Security vs Barracuda Email Security Gateway?
- What is the best email encryption software for small enterprises using Office 365?
- What security measures should businesses prioritize to support secure remote work?
- When evaluating Email Security tools, what aspects do you think are the most important to look for?
















