We use Microsoft Defender for Office 365 for our endpoint security.
Solution Consultant Information Security at Ixtel
Helps prioritize threats across our enterprise by using an endpoint
Pros and Cons
- "Microsoft Defender for Office 365's most valuable feature is its performance."
- "The XDR dashboard has room for improvement."
What is our primary use case?
How has it helped my organization?
Microsoft Defender for Office 365's visibility is good.
Microsoft Defender for Office 365 helps prioritize threats across our enterprise by using an endpoint.
Integrating with other Microsoft solutions is generally straightforward, as everything can be managed from a single console. However, there are some cases where the integration process can be complex, such as when it requires accessing a different dashboard. Overall, the benefits of managing multiple Microsoft solutions from a single place outweigh the occasional complexity of integration.
Our solutions work together natively to provide coordinated detection and response across our entire environment. This coordinated detection provides high-quality results because it is easy to check emails and endpoints for threats. We chose to bundle the solutions because of their ability to integrate.
Coordination and integration are essential in cybersecurity because there are many resources to monitor. The ability to coordinate and integrate from a single source makes it easier and helps to eliminate the need for multiple products.
Microsoft Defender for Office 365 has improved our security posture, especially around email. It integrates easily with our other Microsoft solutions and provides good visibility into our systems.
Microsoft Defender for Office 365 helps automate routine tasks.
Automation allows us to focus our resources on critical issues instead of the standard security tasks that can be automated.
Microsoft Defender for Office 365 saved our organization time.
Microsoft Defender for Office 365 increased our productivity, which resulted in cost savings.
Microsoft Defender for Office 365 helped decrease our time for detection and response.
What is most valuable?
Microsoft Defender for Office 365's most valuable feature is its performance.
The ransomware protection is good.
What needs improvement?
Microsoft Defender for Office 365 is a comprehensive security solution, but it could be improved. Compared to other solutions, Microsoft Defender for Office 365's security reports are not as detailed and the visibility into our network coverage could be better.
The IOC scanning has room for improvement.
The XDR dashboard has room for improvement. The dashboard needs more of a single pane of glass because currently, Microsoft Defender for Office 365 does not give me any options to scan an email thread or attachment for IOCs on my endpoint. I need to manually download the file from the email and then scan it with Microsoft Defender for Office 365. I think Microsoft Defender for Office 365 should be able to scan email threads and attachments directly, without the need for manual intervention.
Secondly, the Data Loss Prevention functionality in Microsoft Defender for Office 365 is very limited. It can only scan for certain types of data. Microsoft Defender for Office 365 should be able to scan for a wider variety of data types, such as customer lists and intellectual property.
Attack process management and breach attack simulation should be included in Microsoft Defender for Office 365.
Buyer's Guide
Microsoft Defender for Office 365
June 2026
Learn what your peers think about Microsoft Defender for Office 365. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
902,495 professionals have used our research since 2012.
For how long have I used the solution?
I have been using Microsoft Defender for Office 365 for six years.
What do I think about the stability of the solution?
Microsoft Defender for Office 365 is stable.
What do I think about the scalability of the solution?
Microsoft Defender for Office 365 is scalable.
How are customer service and support?
Technical support is generally helpful, but we often need to escalate tickets to resolve issues.
Which solution did I use previously and why did I switch?
I previously used Kaspersky Security for Mail Server, Trend Micro Email Security, CrowdStrike, and Mandiant. However, my organization now uses Microsoft Defender for Office 365. This is because we are a Microsoft customer and it makes sense in terms of cost and integration.
What was our ROI?
We have seen a return on investment using Microsoft Defender for Office 365.
What's my experience with pricing, setup cost, and licensing?
Compared to other brands, Microsoft Defender for Office 365's pricing is competitive.
What other advice do I have?
I give Microsoft Defender for Office 365 an eight out of ten.
The maintenance is seamless.
A single-vendor approach is better than a best-of-breed approach because it provides a more integrated and seamless solution. This means that there is no need to worry about compatibility issues or data silos and the overall security posture is better.
Microsoft works hard to provide customers with a single pane of glass so they can easily manage, scale, and maintain their solutions. I recommend Microsoft Defender for Office 365.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Supervisor, Information Technology at Hung Hing Printing Group Ltd
Effortless integration enhances security and reduces IT dependency with reliable support
Pros and Cons
- "It’s easy to handle integrations, and we don't need a lot of people in our IT team."
- "Sometimes, phishing emails manage to pass through the filter, so the system needs to enhance its phishing email detection capabilities."
What is our primary use case?
We are using Microsoft Defender for Office 365 primarily for security purposes.
How has it helped my organization?
The integration with Office 365 is seamless, and we don't need a large IT team to manage it. It helps in maintaining the basic security functions without additional complexity.
What is most valuable?
Since we are using the basic version, we find that it covers most of our requirements without needing additional configurations. It’s easy to handle integrations, and we don't need a lot of people in our IT team.
What needs improvement?
Sometimes, phishing emails manage to pass through the filter, so the system needs to enhance its phishing email detection capabilities. We also need alerting features for abnormal actions like unusual logins or abnormal activities in the mailbox.
For how long have I used the solution?
We have been using Microsoft Defender for Office 365 for seven to eight years.
What do I think about the stability of the solution?
Stability is generally good; I would rate it an eight out of ten.
What do I think about the scalability of the solution?
Scalability is also quite good. I would rate it an eight out of ten.
How are customer service and support?
Technical support from Microsoft is reliable and meets our expectations. I would rate it an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We chose Microsoft Defender as it integrates easily with our existing Office 365 setup, and we do not need to pay extra for security functions.
How was the initial setup?
The setup was easy and not time-consuming. We didn’t need to set up much as it was integrated with Office 365.
What about the implementation team?
The installation was handled by two engineers in our team.
What was our ROI?
Since we are using the basic functions, we don't need to invest a lot of money. It does help in cost reduction.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable since it comes integrated with our Office 365 license.
Which other solutions did I evaluate?
In our current situation, we are not considering other vendors for this purpose.
What other advice do I have?
Integration with Office 365 is one of the strongest points. I recommend it for easy handling and less need for additional IT resources.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Microsoft Defender for Office 365
June 2026
Learn what your peers think about Microsoft Defender for Office 365. Get advice and tips from experienced pros sharing their opinions. Updated: June 2026.
902,495 professionals have used our research since 2012.
Information Technology Specialist at a pharma/biotech company with 1,001-5,000 employees
Saves us time with our investigations and provides safe attachments and safe links
Pros and Cons
- "Microsoft Defender for Office 365's most valuable features are safe attachments and safe links."
- "The GUI is sometimes slow to fetch the device report and could be improved."
What is our primary use case?
Microsoft Defender for Office 365 is used to protect our organization from attacks.
Our deployment is a hybrid model with 80 percent being on the cloud.
How has it helped my organization?
The visibility into threats is excellent. A dashboard provides real-time information on emails, blocked emails, blocked files, and blocked URLs.
We integrated Microsoft Sentinel and Microsoft Intune with Microsoft Defender for Office 365. Integrating Intune was a little difficult but we managed.
The solutions work natively together to provide coordinated detection and response across our environment. This is important.
The integrated Microsoft solutions provide comprehensive insights into threat issues through threat analytics.
Microsoft Sentinel allows us to ingest data from our entire ecosystem. This is important because it provides us with a vital security feature that allows our organization to monitor and respond to alerts and threats detected in our enterprise via Sentinel. We have configured custom alerts and triggers in Sentinel, which gives us a better understanding of the threats in our organization.
Microsoft provides a comprehensive view of alerts to help investigate issues and address malicious emails. We can investigate and share feedback in our message tracking log and the threat explorer in Defender to mitigate and resolve the root cause of the issues.
Microsoft Defender for Office 365 saves us time with our investigations.
We now use the cloud to maintain our email as a gateway which has saved us money by not requiring on-prem hardware.
Our time to detect and respond to malicious emails was decreased. The solution provides the CPU resources needed to scan emails for malicious content, and it also makes it easy to track the number of administrative emails sent to users.
What is most valuable?
Microsoft Defender for Office 365's most valuable features are safe attachments and safe links.
What needs improvement?
The GUI is sometimes slow to fetch the device report and could be improved.
It would be great if Microsoft Defender for Office 365 were priced at the tenant level, rather than the user level. This is because the feature is used by all users in the tenant, not just individual users.
For how long have I used the solution?
I have been using Microsoft Defender for Office 365 for two years.
What do I think about the stability of the solution?
Microsoft Defender for Office 365 is stable.
What do I think about the scalability of the solution?
Microsoft Defender for Office 365 is scalable.
How are customer service and support?
Technical support is often unsatisfactory. When I open a ticket, the initial engineer I speak to often has no hands-on experience and needs to escalate the issue to someone else. This can take a long time, as the engineer needs to check with the internal team before they can provide any assistance. In the end, the issue is eventually resolved.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We previously used Barracuda Email Security Gateway, but it did not sandbox emails. After careful consideration, we decided to switch to Microsoft Defender for Office 365.
How was the initial setup?
The initial setup was straightforward. We just follow Microsoft's documentation and fine-tune the default custom policies as well as new days on custom policies for data management and checking. Two people were required for the deployment.
What about the implementation team?
The implementation was completed in-house.
What was our ROI?
We have seen a return on investment.
What's my experience with pricing, setup cost, and licensing?
The license is expensive because the cost is based on the number of users. The more users there are, the higher the cost.
What other advice do I have?
I give Microsoft Defender for Office 365 a nine out of ten.
We have four people that directly access the solution.
There is no maintenance required from our end.
Before using Microsoft Defender for Office 365, organizations must ensure that the policies are configured correctly to fit their specific needs.
It is better to choose a single vendor with high expertise in a specific area, rather than a best-of-breed strategy.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cloud Security Specialist at a tech services company with 1-10 employees
Covers customer’s IT assets and aggregates insights from different workloads
Pros and Cons
- "One of the best features of the tool is its capability to aggregate insights from different workloads, basically from the Office 365 and endpoints part."
- "Configuring the default strategies and policies in Microsoft Defender for Cloud Apps generates a lot of noise and false positives."
What is our primary use case?
As a specialist in SOC, we work closely with multiple customers to cover their IT assets using Microsoft 365 Defender. They have Microsoft Defender for Endpoint deployment, especially for Microsoft 365. We configure the tool to implement the different policies and requirements to cover the email security part and the cloud apps part with the different strategies available on the platform.
After that, we either work directly on the Microsoft 365 portal or configure the sending of the alerts from this portal to Microsoft Sentinel. This will act as a single pane of glass for us to follow the incidents and advise our customers based on that.
What is most valuable?
One of the best features of the tool is its capability to aggregate insights from different workloads, basically from the Office 365 and endpoints part. With the integration of Microsoft Defender for Identity and Microsoft Entra ID Protection, we will have insights from the identity part. Finally, with the Microsoft Defender for Cloud Apps, we'll also have insights about our cloud apps, either Microsoft 365 cloud apps or third-party cloud apps.
The aggregation of all of these insights into the tool's incident feature will help us have a global vision of the incidents and find multistage attacks at the first steps of the attacks.
What needs improvement?
Microsoft Defender for Cloud Apps is a very good solution that allows you to use a single port or tool to control everything happening with your organization's different cloud applications.
Configuring the default strategies and policies in Microsoft Defender for Cloud Apps generates a lot of noise and false positives. Also, the documentation does not have many details about that. The bad configuration and lack of good documentation prevent professionals from taking the most advantage of this tool.
One of the big problems that some customers face is that Microsoft always changes its products' names. For example, four to six months ago, Microsoft Defender for Office 365 was renamed Microsoft Defender XDR. Microsoft comes up with a new name for the tool every one or two years, which sometimes is hard for customers to follow.
Microsoft should improve some integrations in the Microsoft Defender for Cloud Apps sub-category. With a specific configuration to Microsoft Defender for Endpoint, we can get logs and insights from network devices and other workloads on our system.
For how long have I used the solution?
I have been using Microsoft Defender for Office 365 for two years.
What do I think about the stability of the solution?
I rate the solution an eight or nine out of ten for stability.
What do I think about the scalability of the solution?
We configure the tool for different clients, and thousands of people work with the solution. The tool scales out very well and can cover and monitor devices and users ranging from a few hundred to thousands without any problem. Our clients for Microsoft Defender for Office 365 are medium and small businesses. Microsoft Defender for Office 365 is a scalable solution. There are no issues with the solution's scalability or latency.
I rate the solution's scalability ten out of ten.
How are customer service and support?
The technical support for the solution is very good, and I didn't face any issues with it.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I have previously used CrowdStrike Falcon. Microsoft Defender for Office 365 and CrowdStrike Falcon are both great tools. Each has its advantages and disadvantages. In my opinion, CrowdStrike is more mature in the endpoint and classic antivirus parts. On the other hand, Microsoft Defender for Office 365 is more mature regarding identity and Office 365.
For artificial intelligence integration, Microsoft 365 Defender is far ahead of others with the integration of CoPilot within the portal. This feature that helps analysts reduce time to analyze and respond to incidents does not exist in CrowdStrike.
How was the initial setup?
The solution's initial setup is very straightforward. You have to go to the portal and click on the incident icon, and the tool will automatically start configuring itself. After that, the integration of the endpoints depends on your workload. For example, 1,000 devices will take much longer than two or three devices.
Automation tools are available within the platform to help us automatically deploy the sensors on different workloads that we will need to cover with this tool. The solution's initial configuration and deployment are very straightforward. A lot of videos and documentation are available for the same.
What about the implementation team?
The initial configuration and deployment of the tool for a specific tenant takes five to ten minutes. After that, it depends on what you want to do. You can implement specific strategies today. Based on the evolution of threats, you will need to configure different things tomorrow.
What other advice do I have?
We tried to solve a lot of issues by implementing the solution. The solution helps us detect problems related to the endpoints, like the detection of suspicious processes or suspicious installation of suspicious software. We will raise an alert, and it will show us a graph of the different entities included in the incident, including users, computers, or endpoints.
If it is related to email, it will show us the initial email and different insights about the incident. We'll go through those alerts and try to check them manually. Sometimes, the tool detects suspicious emails for some incidents and automatically quarantines them.
After that, we, as analysts, will do the manual review. If we find an action suspicious, we use the tool to blocklist the domain that has sent the email. If we find that it's a false positive, we will reject this automatic action by the XDR, and the email will be delivered to the end user.
Unified identity and access management is a new feature on the Microsoft 365 Defender portal. It's all about having a single pane of glass to give you insights into the different identities available on your tenant. Those identities are either on-premises, cloud-based, or synchronized between the on-premises and cloud-based workloads.
The solution's security covers more than just Microsoft technologies. Microsoft Defender for Endpoint and Microsoft Defender for Cloud Apps have a specific configuration to get insights from third-party cloud applications or from within the Microsoft Defender for Endpoint sensors. We can also get logs and insights from other network devices present in our perimeter, like routers, switches, or firewalls. All those insights will help us gain some visibility into our security posture.
The product has gone through a lot of improvements, especially in the last few moments. It will be like a SOC unified platform with the integration of the Microsoft Sentinel tool within the Microsoft 365 Defender portal. This tool is available to cover all the perimeters. Even third-party solutions and workloads that do not have any security tools from where we can get insights, we can directly use something else to install the low connectors and get visibility about those.
Also, the most significant evolution is the integration of artificial intelligence with Microsoft Copilot for security. This is also a big added value that will help analysts investigate and minimize the meantime needed to respond to advanced threats.
The solution stops the lateral movement of advanced attacks, like ransomware or business email compromise, in a good way. Specific measures and configurations are implemented within the tool that will help us detect advanced attacks in the early stages. We can set configurations for business email compromise.
With the help of artificial intelligence, we'll get insights about emails that may be starting a business email compromise based on specific keywords. It's the same for ransomware and other advanced attacks.
The solution's integration into a company will help it be more resilient to cyber attacks. It will help the company prepare for attacks at an early stage and respond quickly, which will help it be more secure.
Being an XDR, the solution has detection and response capabilities. With adequate configuration, we can configure the required measures to stop or at least quarantine attacks and isolate the assets involved with the attacks in the early stage upon detection. After that, the manual site comes into the picture, and we do the manual review. Based on our review and feedback, the tool will learn from us and behave better in the next similar incident.
I saw a demo about the solution's multi-tenant management feature, and it's a very good feature. It will help big companies with multiple tenants and MSSPs that deal with multiple tenants for users. It will help them to work with multiple tenants by flipping a switch.
I'm a big fan of the solution. Having a Microsoft E5 license will help you to cover all the different types of security, including the identity, the endpoint, the email, and even the cloud. I'm just an engineer and work with whatever tool the client provides me. I noticed that many customers have a Microsoft E5 license, but they don't know a lot about the capabilities that come with it.
They buy or add other tools from third parties when they have that feature or capability included within the E5 license. Microsoft needs to talk to different customers and show them the capabilities that come with these types of licenses, which cover a lot of features.
The integration of Copilot has helped us a lot in concentrating on a single portal to get different insights. This will help a lot to reduce the meantime to respond to incidents by 50%.
The configuration of the Copilot assistant is very straightforward and doesn't take more than 30 minutes. After that, when the tool automatically detects incidents and you go to the analysis page of a specific incident, you will find an initial analysis of the whole incident by the Copilot security assistant.
You may also interact with it using chat, and it will help you if you haven't understood any specific terms from the initial analysis. It can be configured to automatically respond to specific incidents based on workbooks, which will help us automatically apply the measures to respond to specific incidents for remediation.
Microsoft Defender for Office 365 is a cloud-based solution. Since it's a cloud-based solution, Microsoft does all the maintenance for the tool. We are notified via email if there is a shortage or a problem. The SLAs are usually very good, and I have not noticed any problems in the last two years where we could not access the tool.
I would recommend the solution to other users because it's a very good solution and one of the best XDRs in the world right now. If you go through reviews from Gartner or other companies, you will see that Microsoft Defender for Office 365 is a leader in the XDR market. It has the capability to collect and aggregate insights from different sources, either cloud-based or on-premises.
The integration of artificial intelligence will greatly help final users and security practitioners respond to incidents adequately and efficiently.
Overall, I rate the solution an eight out of ten.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
Senior Manager Ict & Innovations at Bangalore International Airport Limited
The automated attack disruption works well if you have a strong policy configuration
Pros and Cons
- "Defender is a SaaS platform, so it offers more flexibility. Managing the permissions is easier. The solution's automated detection and response features are scalable."
- "You should be able to deploy Defender for every subscription without the need to add servers."
What is our primary use case?
365 Defender is a critical tool for mitigating attacks and preventing threats. We use it for email filtering and blocking phishing attacks throughout the entire enterprise. We have around 1,500 users.
How has it helped my organization?
365 Defender has improved our security across multiple categories. It's effective against advanced attacks like phishing and ransomware. Defender's attack disruption works well if you have a strong policy configuration. It will automatically block threats and filter them in most cases without the need to investigate. It will remedy the threat immediately.
The automated response reduces the manual work, saving our security team time. I would estimate it saves about six hours per day.
What is most valuable?
Defender is a SaaS platform, so it offers more flexibility. Managing the permissions is easier. The solution's automated detection and response features are scalable. It's a unified solution that doesn't just cover Microsoft products. We're a multi-cloud shop, and having that coverage is critical. It also includes the latest IAM features like two-factor and multifactor authentication, giving us the most robust solution.
What needs improvement?
You should be able to deploy Defender for every subscription without the need to add servers.
For how long have I used the solution?
I have used 365 Defender for almost six years
What do I think about the stability of the solution?
I rate Microsoft 365 Defender nine out of 10 for stability.
What do I think about the scalability of the solution?
I rate Microsoft 365 Defender nine out of 10 for scalability.
How are customer service and support?
I rate Microsoft support nine out of 10. Their support is excellent.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We migrated to 365 Defender from a McAfee solution.
How was the initial setup?
365 Defender is a cloud-based solution deployed on Azure. You can set it up in two days with some help from Microsoft support using two people.
What's my experience with pricing, setup cost, and licensing?
365 Defender is worth what we paid for it.
What other advice do I have?
I rate Microsoft 365 Defender nine out of 10. It's the most economical product you can buy, offering a range of features for safeguarding your enterprise.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Architect at BRF
Seamlessly integrated security enhances protection with an easy setup
Pros and Cons
- "We use Microsoft Defender for its ability to integrate with existing business technologies, which is beneficial for protecting business areas."
- "Configuration at the mid-level could be improved for the support team."
What is our primary use case?
I work in the industry where we use Microsoft 365 and its associated products like Office Works, PowerPoint, Excel, and Word.
How has it helped my organization?
We use Microsoft Defender to help protect our business areas by integrating it with our existing infrastructure, including Azure, which assists in defending the business areas.
What is most valuable?
We use Microsoft Defender for its ability to integrate with existing business technologies, which is beneficial for protecting business areas.
What needs improvement?
Configuration at the mid-level could be improved for the support team.
For how long have I used the solution?
I have about ten years of experience with Microsoft Defender for Office 365.
What do I think about the stability of the solution?
The solution is very stable, and Microsoft products have general high availability within the company.
What do I think about the scalability of the solution?
Microsoft 365 meets the needs of the company, which suggests that Microsoft Defender is a scalable solution.
How are customer service and support?
We have a premium contract for Microsoft support, which is rated nine or ten. Although I am not directly involved with their support, clients usually appear satisfied.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I do not have experience with other email security solutions.
How was the initial setup?
The setup is easy and not difficult.
What was our ROI?
I do not understand the question regarding return on investment.
What's my experience with pricing, setup cost, and licensing?
I do not know the value of the contracts or the cost compared to competitors.
Which other solutions did I evaluate?
I have not evaluated other solutions for email security.
What other advice do I have?
Configuration for end users is simple, but improvements can be made in mid-level configurations to make it better for the team.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Self Employed, Freelance, Consultor, Sales - Learning Time at SpectralByte
It's a reasonably priced, scalable cloud-based solution
Pros and Cons
- "Defender for 365 is a comprehensive cloud-based solution. The value of the cloud is that you aren't alone. Threat intelligence and analytics are shared in the cloud. We don't have to find the solution alone. If you face an unknown threat with traditional solutions like Trend Micro and Symantec, you need to open a case and send your information to them to analyze forensically and identify the source of the attack."
- "The certification training for Defender for 365 needs to be deeper and incorporate Sentinel. I took all the security courses except one, and Sentinel isn't included."
What is our primary use case?
We primarily use Defender for 365 for email protection.
How has it helped my organization?
My company receives 100,000 emails daily. We implemented Defender to supplement our Broadcom anti-spam solution. Our Broadcom solution wasn't analyzing the server or the body of the messages.
What is most valuable?
Defender for 365 is a comprehensive cloud-based solution. The value of the cloud is that you aren't alone. Threat intelligence and analytics are shared in the cloud. We don't have to find the solution alone. If you face an unknown threat with traditional solutions like Trend Micro and Symantec, you need to open a case and send your information to them to analyze forensically and identify the source of the attack.
What needs improvement?
The certification training for Defender for 365 needs to be deeper and incorporate Sentinel. I took all the security courses except one, and Sentinel isn't included.
For how long have I used the solution?
I have used Defender for three years.
What do I think about the stability of the solution?
Defender for 365 is stable. You can subscribe to all the alerts and notifications of every service in the cloud, and it won't affect the stability. Your devices will be seamlessly updated from the cloud automatically with no problems.
What do I think about the scalability of the solution?
Defender for 365 is scalable because it's in the cloud. It will give you more resources as needed, whereas the scalability of an on-premise solution is determined by your processing power and other hardware limitations.
How was the initial setup?
Deploying Defender isn't complex. You only need to buy the license and connect your devices to the cloud.
What's my experience with pricing, setup cost, and licensing?
Defender for 365 is reasonably priced, but it isn't cheap. I think the price per user is $3 or $6, depending on the license.
What other advice do I have?
I rate Microsoft Defender for Office 365 nine out of 10. Before deploying Defender, you can compare its engine with that of Symantec, Trend Micro, and other brands.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Pre-Sales Product Specialist at a tech services company with 1,001-5,000 employees
Helped us to avoid malware in the system and prevent unwanted emails from entering our system
Pros and Cons
- "The most valuable aspect of Microsoft Defender for Office 365 is its ability to protect us from malware."
- "The changes to customer service, specifically the new model for support agreements, are not favorable."
What is our primary use case?
We are using Microsoft Defender for Office 365 to avoid spam, malware, and similar threats.
How has it helped my organization?
Microsoft Defender for Office 365 helps us prioritize threats across our enterprise. I am able to let the system fix the malware while I focus on other tasks.
Microsoft Defender for Office 365 automates routine tasks and highlights critical alerts, significantly improving our security operations. This automation saves us time by reducing repetitive tasks, allowing us to focus on developing new services instead of solely on security operations.
The threat intelligence feature helps us take proactive steps to prevent threats.
Microsoft Defender for Office 365 saves us time and money and has helped decrease the time to detection and response.
It has helped us to avoid malware in the system and prevent unwanted emails from entering our system.
What is most valuable?
The most valuable aspect of Microsoft Defender for Office 365 is its ability to protect us from malware. This has effectively helped us avoid malware in the system and keep out unwanted emails. It allows us to spend less time on repeated tasks, enabling us to develop new services.
What needs improvement?
The changes to customer service, specifically the new model for support agreements, are not favorable. We have to pay $600 for every instance, making it too expensive. We might need to look at other support options.
For how long have I used the solution?
I have been using Microsoft Defender for Office 365 for over ten years.
What do I think about the stability of the solution?
Microsoft Defender for Office 365 is stable. It's doing what it's supposed to do.
What do I think about the scalability of the solution?
The solution is scalable. Microsoft Defender for Office 365 is flexible with other security products we use. Our usage depends on Microsoft adding features.
How are customer service and support?
We have a premier support agreement. Initially, it worked well, but the new model, where we have to pay for every instance, is not satisfactory.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used alternative solutions prior to implementing Microsoft Defender for Office 365. We selected it due to its superior integration with our existing security infrastructure.
What about the implementation team?
The implementation was completed in-house.
Which other solutions did I evaluate?
We evaluated other solutions before switching to Microsoft Defender for Office 365.
What other advice do I have?
I would rate Microsoft Defender for Office 365 ten out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Partners
Information Security Analyst at a tech services company with 51-200 employees
It reduces the work we need to do for our clients because we can quickly find the information we need and take action
Pros and Cons
- "Defender enables us to secure all 365-related activity from a single place. It gives us visibility into everything happening in Outlook, protecting us against phishing and other email-based threats. Defender helps us detect any suspicious behaviors."
- "Microsoft sometimes has downtime, and we'll get several incidents coming in back to back. We have a huge backlog of notifications, many of which may be false positives. However, there might be serious alerts, so we can't risk dismissing all of them at once."
What is our primary use case?
We use Defender with Sentinel to investigate user activity on Office 365 applications.
How has it helped my organization?
Defender enables us to secure all 365-related activity from a single place. It gives us visibility into everything happening in Outlook, protecting us against phishing and other email-based threats. Defender helps us detect any suspicious behaviors.
The solution helps us automate some tasks. For example, instead of going through alerts one at a time, we can ping using Sentinel, and everything will be reduced to one group because it is already done in Defender. I don't need to write a KQL or investigate everything. It reduces the time spent and helps me to prioritize. Sentinel usually resolves the low-level alerts on its own, so I don't need to spend much time.
Defender lets us consolidate dashboards, so we can see all the information we need in one place. It's time-consuming to switch between multiple dashboards to find what you need.
The solution's threat intelligence helps us stay on top of new attacks. Novel threats are flagged in Microsoft Defender. It will show you what to look for, and you can learn the recommended remediation steps, so you can take steps to mitigate risk before the issue occurs.
It reduces the work we need to do for our clients because we can quickly find the information we need and take action. Every alert takes some time to respond to. If we see something suspicious, we can gather all the details and provide them to the client. We do about 90 percent of the work; the other 10 percent is the client's responsibility.
What is most valuable?
Defender provides all the details and evidence we need about an incident, so you don't need to look for it. Once you enter the tab, you get all the information about the user's activity and everything you need to know within the alert.
It also helps us identify vulnerabilities. When a new threat is discovered, Defender will flag the client's vulnerable assets and tell us what needs to be patched. That is helpful information to share with our clients. They can patch the vulnerability before being affected.
Microsoft Defender enables us to prioritize threats. It's crucial because if we ignore critical alerts, we might miss a severe vulnerability, and the user host could be affected if that happens. We must prioritize alerts to address the ones with the highest risk first. Next, we move on to the medium or low-risk alerts and the purely informational notifications.
We use Defender for 365 with Defender for Cloud and Sentinel. Microsoft Defender for Cloud is primarily for checking the client's security posture. Sentinel ingests data from our entire ecosystem and helps us correlate events from the logs to understand user activity better.
We can run queries on user behavior or check the logs for any activity related to the alert. Integrating Sentinel and Defender is vital because getting the information from the logs is much easier. We don't need to look at the metadata because we can see the events in a structured format. A few of the alerts can always be resolved by SIEM analysis. If it isn't a high-priority alert, Sentinel can clear it.
Having everything available in one place is helpful for our investigation. We can forward those details to our clients so they can take action. All the information is in the logs.
Sentinel allows us to analyze user behavior and assign user risk based on patterns. For example, we can see if a user attempts to log in with an abusive IP. It detects the behavior, so we don't need to search the logs or look through the threat intel. Sentinel gives us a report of all the risky users. The sign-in logs and audits are neatly formatted so we can click through instead of searching manually.
What needs improvement?
Microsoft sometimes has downtime, and we'll get several incidents coming back-to-back. We have a huge backlog of notifications, many of which may be false positives. However, there might be serious alerts, so we can't risk dismissing all of them at once.
A few days ago, we had an issue where everything that came into the user's mailbox was flagged. We got hundreds of notifications. It was problematic for us, but the investigation was easy.
For how long have I used the solution?
I have used Defender for 365 for around six months.
What do I think about the stability of the solution?
I rate Defender for 365 an eight out of ten for stability.
What do I think about the scalability of the solution?
I rate Defender a nine out of ten for scalability.
How are customer service and support?
I rate Microsoft's support a nine out of ten.
How would you rate customer service and support?
Positive
What other advice do I have?
I rate Microsoft Defender for Office 365 a nine out of ten. We work in more of an investigative role. Defender helps us automate many tasks. It's better to go with a single vendor instead of a best-of-breed strategy.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Assistant Manager-Networks at a university with 1,001-5,000 employees
Prioritizes threats across our enterprise and safeguards us from any incoming threats or viruses
Pros and Cons
- "Microsoft Defender has a feature to protect each and every attachment. Even if it's an encrypted attachment, it will check for any potential threats."
- "Microsoft should provide more documentation for users so they can self-educate. I would like to see more documentation for advanced security features."
What is our primary use case?
We mainly use Microsoft Defender for Office 365 to secure our Office 365 combined application package, which includes Outlook, Word, Excel, PowerPoint, OneDrive, Skype, and Teams. We have all of these combined packages in our cloud.
Before we deployed Defender, we didn't have the right solution to safeguard these applications because our data was moved from multiple locations, from Outlook to OneDrive, for instance. After the introduction of Defender, we could instantly control most threats.
We also use Microsoft Defender for Identity and Cloud Apps. We deployed Identity recently.
Integration is easy because Microsoft is the vendor of all of these security products. Most of these products are closely integrated, whether they're on-premise or deployed on the cloud.
These solutions work natively together to deliver coordinated detection and response across our environment. All of these features work on different security layers to ensure protection. Microsoft Defender for Identity gives protection to users. That's an application layer. Simultaneously, Defender for Cloud also provides a layer of security. Each Microsoft product offers a different layer of security, so our organization is secure.
These security products offer comprehensive threat protection. Each day, thousands of people send emails that contain malicious content. Microsoft Defender for Office 365 constantly monitors those attachments and gives us alerts so that we're able to focus on threats and prioritize them accordingly.
We use the bidirectional sync capabilities. It's an important feature to us because we need it for proper syncing and security, both on-premises and on the cloud.
The solution is deployed on a public cloud.
Defender is used in one tenant, and multiple departments use it. It provides security for about 2,000 users.
How has it helped my organization?
We have seen multiple benefits from using Defender. Our data was on-premises about five years ago. We migrated our data to the cloud to improve our security. It's awesome to get all of the security features in the cloud. To apply these features on-premises requires different hardware and multiple vendors. With Microsoft Defender, we're able to have a single manufacturer.
Microsoft Defender for 365 helps automate routine tasks and the finding of high-value alerts. It's a detection mechanism, so it doesn't solve the issue, but it will give us alerts and other notifications. It provides system alerting and patches.
The alerting automation definitely affects our security because our organization requires alerts constantly. The Defender setup for Office 365 applications gives us a clear alerting dashboard. The dashboard has multiple features that are linked to most of our applications, so it's more secure.
This solution helps eliminate the need to look at multiple dashboards. With different vendors for security, we obviously had vertical dashboards. Microsoft Defender gives us a single dashboard that we can link to other applications.
Defender has reduced time spent by 50%.
It definitely saves us money because other vendor products cost more. The hardware itself costs money. Defender's subscription costs less. We have saved 50% compared to other solutions.
Defender decreases the time it takes to detect and respond. We're able to detect 20-30% faster.
What is most valuable?
Most of our files are being stored in OneDrive. We need to safeguard those links because users have to forward them to multiple locations. Microsoft Defender has a feature to protect each and every attachment. Even if it's an encrypted attachment, it will check for any potential threats.
If there are any spam contents in an email, we will be notified. With the implementation of Defender, we're able to correctly monitor attachments, files, and safeguard the required data.
Microsoft Defender for Office 365 provides us with visibility into threats. Our emailing system is Microsoft Office Outlook. We also use a mail server from Microsoft. If there's an issue, we're able to troubleshoot it right away and give a solution. All of the administrators are properly alerted in their dashboards.
Microsoft Defender for Office 365 helps us prioritize threats across our enterprise. It safeguards us from any incoming threats or viruses. It scans every bit of information from the software cloud, including attachments, links, or malicious emails that hackers generate to break the security system.
It's definitely important that Defender helps us prioritize threats across the enterprise because some of the security breaches are less serious, so there is more time to troubleshoot. We're able to see everything in the dashboard, so we're notified about the important threats and can act accordingly to resolve them.
What needs improvement?
The advanced threat protection requires awareness and knowledge from administrators. Microsoft should provide more documentation for users so they can self-educate. I would like to see more documentation for advanced security features.
For how long have I used the solution?
I have used this solution for about five years.
What do I think about the stability of the solution?
It's completely stable.
What do I think about the scalability of the solution?
It's scalable.
How are customer service and support?
Technical support is really good. I would rate them as nine out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We haven't used any other solutions.
How was the initial setup?
The setup was straightforward.
Maintenance isn't required because the solution auto-updates.
What about the implementation team?
We received support from Microsoft for implementation. Four system administrators were needed for implementation.
What was our ROI?
We have definitely seen a return on investment. OneDrive stores a lot of data, and maintaining the security of that data is a large task. It would be expensive to integrate another solution for that task. Since implementing Defender, we have saved a lot of money.
There are other Microsoft products included in the package, so we're able to save more money. I think there's a great return on investment.
What's my experience with pricing, setup cost, and licensing?
The pricing is normal. Considering its popularity, it's not overpriced.
Which other solutions did I evaluate?
We haven't evaluated other options. To secure Microsoft Office 365 applications, we wouldn't necessarily go for other third-party solutions because Microsoft has its own proprietary solutions.
What other advice do I have?
I would rate this solution as nine out of ten.
My advice for other people who are in security is to try Defender. It's much better than other top security appliances and it's completely affordable. For large and medium enterprises, it's definitely worth trying because applications like OneDrive require constant monitoring.
Multiple security solutions must be monitored constantly, and the maintenance cost will be much higher. Dependency issues will arise, and you will need multiple support people to troubleshoot issues. Sometimes the issue won't be found if it involves multiple dependencies from other vendors. We prefer to go with a single-vendor product like Microsoft because of their support.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Microsoft Defender for Office 365 Report and get advice and tips from experienced pros
sharing their opinions.
Updated: June 2026
Product Categories
Email Security Email Archiving Advanced Threat Protection (ATP) Microsoft Security Suite Secure Email Gateway (SEG)Popular Comparisons
Microsoft Intune
Microsoft Defender for Endpoint
Cloudflare One
Microsoft Entra ID
Microsoft Defender for Cloud
Microsoft Purview Data Governance
Proofpoint Email Protection
Microsoft Defender XDR
Check Point Email Security (formerly Harmony Email & Collaboration)
ESET Endpoint Protection Platform
Palo Alto Networks WildFire
Mimecast Advanced Email Security
Cisco Secure Email
Buyer's Guide
Download our free Microsoft Defender for Office 365 Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Which solution do you prefer: Microsoft Defender for Office 365 or Proofpoint Email Protection?
- Is Defender for Office 365 enough? Or should we be using a product like Mimecast?
- Have you done a comparison between BeyondTrust Endpoint Privilege Management and Microsoft Defender?
- Which product do you prefer: Symantec Messaging Gateway or Microsoft Defender?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- When evaluating Messaging Security, what aspect do you think is the most important to look for?
- Which Email Security enterprise solution would you choose: Cisco Secure Email vs Forcepoint Email Security vs Barracuda Email Security Gateway?
- What is the best email encryption software for small enterprises using Office 365?
- What security measures should businesses prioritize to support secure remote work?
- When evaluating Email Security tools, what aspects do you think are the most important to look for?
















