Very first thing is to be brining "Zero-day trust".
If devices are covered, enrolled with INTUNE and M365 licenses (E3, E5) are already in place then Defender platform to secured devices is best option here instead of using third party Antimalware tool.
I would suggest you think about the zero-day trust framework. There are various solutions around us, and they will protect your organization with different levels or layers of access. Microsoft has a good slide to elaborate on the zero-day trust network.