TrustRadius: an HG Insights company

Microsoft Defender for Endpoint Information Reviews & Insights

Score8.7 out of 10

222 Reviews and Ratings

Reviews

10 Reviews
Information

A strong endpoint solutions for microsoft ecosystem.

Rating: 9 out of 10
Incentivized

Use Cases and Deployment Scope

In our organization, we use Microsoft Defender for Endpoint to protect against malware, phishing, and other advanced threats. It provides real-time threat detections and automated remediations. This application assists us in improving endpoint compliance and centralized control.

Pros

  • Endpoint detection and response.
  • Real time threat detection.
  • Centralized dashboard.
  • Role-based access.

Cons

  • High CPU usage, the application should be lighter.
  • Improvement needs in UI.
  • Rules customization in limited.
  • Mobile support is not as good as a desktop application.

Likelihood to Recommend

Microsoft Defender for Endpoint works very well in the Microsoft ecosystem, especially in the Windows environment, with integrated tools like Intune policy management and Enterprise ID. It has some compatibility issues on MAC and Linux OS.
Vetted Review
Microsoft Defender for Endpoint
2 years of experience

Defender is a more than viable antivirus protection solution.

Rating: 10 out of 10
Incentivized

Use Cases and Deployment Scope

We used Defender to replace Sophos. Being included as part of the Microsoft 365 package saved us the entirety of the cost of the previous provider. It also provides significantly more detailed security insights into our devices. Dashboard scores are used to help proactively respond to threats. The software also includes threat assessment to see all of the vectors an attacker would use.

Pros

  • Dashboard for threats.
  • Ease of installation.
  • Rapid response to threats.

Cons

  • PC reporting often lags behind, so scores remain unchanged longer than desired.
  • The portal interface changes regularly, moving objects and menus.
  • It needs a more defined client interface to resemble a traditional third-party antivirus.

Likelihood to Recommend

Because of its integration with Windows, it is very easy to deploy and manage. Any IT department should be able to leverage the software and interface. The admin portal provides weighted recommendations that comprise the Secure Store, offering admins, security teams, and business owners valuable insights into their security footprint without requiring a strong security background. The software would be ideal for small and mid-sized businesses that cannot dedicate resources to security. Larger enterprises would also benefit, but may require the enhanced license.

Microsoft Defender for Endpoint Review

Rating: 10 out of 10
Incentivized

Use Cases and Deployment Scope

Usually we are deploying Defender for Endpoint as an endpoint XDR tool. We're replacing an existing tool, so that is going to be a deployment in passive mode first, which is easy. Then we uninstall the legacy tool and we move this one to active mode and it takes over as your XDR. The reasons we're doing that is cost. Sometimes it is just better protection.

Pros

  • I would say it detects threats very well on the endpoints. Quarantine threats communicates with other instances of the endpoint agent across your organization, so you can more quickly quarantine threats that are perhaps spreading through your agents.

Cons

  • I would say moving it from passive to active mode. In some cases, depending on the tool that's there can be challenging because sometimes the legacy tool does not want to go into a passive mode, so you have to uninstall it and that can cause issues depending on the size of the organization and whether their apps are there.

Likelihood to Recommend

I would say organizations that are primarily Windows based, definitely very appropriate where they're moving from a legacy antivirus solution or older XDR tool to a more modern one, definitely well suited. Where it's more challenging is where you've got a mixed environment of let's say a lot of Mac users, a lot of Linux users, and although those platforms are supported by Defender for Endpoint, it's harder to deploy. Depending on the quantity of Mac in a client environment for example, sometimes it's a lot more challenging to deploy than if you have like 10,000 Windows PCs and 100 Mac, that's easy, but if you have 5,000 Macs, it's a lot harder.
Vetted Review
Microsoft Defender for Endpoint
5 years of experience

Best software to protect multiple platforms

Rating: 9 out of 10
Incentivized

Use Cases and Deployment Scope

It is providing a way to secure our device across multiple platforms like windows Linux and iot devices it scan all the files and protect against the harmful and suspicious virus it automatically monitor and analyse the files and protect our system it acts as a antivirus to the system which increases the platform efficiency.

Pros

  • Protect devices from the virues
  • Support multi platform
  • Monitor and analyse end point activity

Cons

  • Well suited for antivirus
  • Easy to use
  • Provide fast response against the threads

Likelihood to Recommend

It is a well and advance tool for protecting our device from the virues and also helps to investigate the threads which helps us to fixing the problem as soon as possible without getting crash also it provides immediate response and alerts to the user if anything found in the system along with that they support multiple platforms which is very good part of this software
Vetted Review
Microsoft Defender for Endpoint
2 years of experience

Microsoft Defender for Endpoint Review

Rating: 9 out of 10
Incentivized

Use Cases and Deployment Scope

So we have suggested the Microsoft Defender for Endpoint for supporting and protecting the client's endpoint, so that's a complete C-Suite, Microsoft Suite we have implemented.

Pros

  • It's quite responsive in protecting the endpoints and electing the organization. MDM workflows and other aspects.

Cons

  • Some UI needs to be repositioned because some customers feel the UI is a bit cumbersome and hard to navigate. Some minor usability functionalities.

Likelihood to Recommend

So it's well it's a financial services client, so for them protecting the endpoints like the servers, computers, mobile devices, was a key priority so that we have implemented a complete Microsoft Suite. So it's all in one with interface. No scenarios where it's less appropriate. Nothing specific on top of mind. The client is fine.

Comprehensive Security with Microsoft Defender for Endpoint: Enhancing Protection of networks

Rating: 10 out of 10
Incentivized

Use Cases and Deployment Scope

We have been using Microsoft Defender for Endpoint to augment our cybersecurity processes by protecting our network for advanced threats and attacks, this product helps with critical bussiness problems like malware, spyware, philsing, data breaches, and it provides a real time detection and response, with the signature of Microsoft products, we have been grateful for its perfomance in our organization, and it has ensured that all our devices are secure, free of viruses, and minimized cybersecurity risks in our networks.

Pros

  • Real time protection for organizations of all sizes
  • Advanced and updated database of known threats
  • Monitoring endpoints across the organization ensuring device safety

Cons

  • Integration with non-Microsoft tools can be quite challenging
  • UI can be overwhelming for new users
  • More comprehensive and easier to understand documentation would be great for this product

Likelihood to Recommend

This product is well suited for organizations that need comprehensive threat detection and resppnse across multiple endpoints, ensuring robust security and protection against malware, spyware, philsing attacks. It could be less appropiate for small business with limited IT resources, and its features and complexity sometimes could be overwhelming for inexperienced security teams.

Microsoft Defender for Endpoint Review

Rating: 10 out of 10
Incentivized

Use Cases and Deployment Scope

Currently we use the EDR product together with Entra ID and we also use it as a third-party EDR product. And normally what happens is we use Defender as an audit tool and login tool. So whenever there is an incident raised in any means by security products, which can be Defender or another product, we use the extended capabilities of auditing and logging of Defender to drill down and see what the user has to face and identify what the problem is. Then we contact the user and we try to help them.

Pros

  • It is very good in detecting what has happened on the endpoint. So tracking all the actions, what the user clicked, if there was a malicious program that touched the mailbox, anything like that is excellent.

Cons

  • While it's a very good product for auditing, it has a very hard time to distinguish what is malicious and is an attack, what is not. Very rarely we get indication of a real malicious attack. We got lots of hours for off the shelf malware that it cleans up automatically. So basically we never get to look at it, which is a positive thing, but threats are detected by the third party endpoint, so it will not be enough by itself.

Likelihood to Recommend

Well, I just say that, so you are a Microsoft shop, there is no reason not to install it. You should definitely have it.
Vetted Review
Microsoft Defender for Endpoint
3 years of experience

Endpoint protection products that are easy to use and configure

Rating: 8 out of 10
Incentivized

Use Cases and Deployment Scope

Defender for Endpoint provides a platform that allows our analysts to quickly and accurately answer important questions during investigations.Most importantly, by simulating these capabilities in the API, we can more efficiently provide high-quality detection and response based on the Defender for Endpoint platform. Microsoft Defender ATP mainly has built-in Threat & Vulnerability Management (TVM), which is a risk-based approach to discover, prioritize and repair vulnerabilities and incorrect configurations of each endpoint to prevent current and future threats and vulnerabilities! TVM can effectively identify, assess and repair endpoint defects, and at the same time score the enterprise's vulnerability level. Therefore, it is very important for IT personnel to implement computer security and health plans and reduce risks to the company's organization.

Pros

  • The ability to provide decision support (or content about alerts) is powerful and allows us to become experts in analytics rather than in a specific technology
  • Microsoft Defender provides security for unmanaged devices on corporate networks
  • Microsoft Defender for Endpoint is a service in the Microsoft Defender Security Center. By adding and deploying client provisioning profiles, configuration administrators can monitor deployment status and obtain endpoint agent health status using Microsoft Defender.

Cons

  • Windows Defender isn't perfect. It may miss some threats, especially new and sophisticated threats. So it’s important to supplement it with other security measures.
  • Even though Windows Defender does a good job, it can't protect you from everything. Therefore, it is important to be aware of the risks and take steps to protect your computer, such as using complex passwords and being careful about clicking on anything, especially email attachments and some tech support scam calls.

Likelihood to Recommend

適合企業VDI運行環境,搭配企業級防病毒系統。填補企業設備側信息安全防護空白。
Vetted Review
Microsoft Defender for Endpoint
3 years of experience

Microsoft Endpoint Defender - A powerful security system in place

Rating: 8 out of 10
Incentivized

Use Cases and Deployment Scope

Microsoft defender for endpoint has helped me prevent my organization network from malwares, ransomware etc. We have also used it in incidence response. For a possible breach we are using defender for Endpoints to quickly identify the compromised endpoint, investigate the incident, and automatically initiate remediation actions, isolating the threat. This rapid response minimizes damage and prevents lateral movement across the network.

Pros

  • Incidence Response
  • Threat Intelligence
  • Real time monitoring

Cons

  • Third party integration with Microsoft defender for endpoint is tough as its not compatible with many systems
  • Custom rule creation and enhanced analytics features needs a lot of improvement
  • It should be compatible with MacOS and Linux as well

Likelihood to Recommend

According to me, because of the cost, it can be used where budget is moderate to high, and the system mostly relies on Microsoft based systems i.e. Windows centric environments. But with less budget, the cost of using this is too high. also for non Windows based system like MacOS or Linux based system this is not compatible. Also if there is already a security architecture in place, then integrating this defender with the third party system is way difficult and sometimes unachievable.

Great AV solution that's low on system resources!

Rating: 8 out of 10
Incentivized

Use Cases and Deployment Scope

We use MS Defender ATP on all of our systems. It uses low resources compared to other AV providers and full integration into Windows OS. You don't experience the breakage that happens when you have a 3rd part AV providers when there are feature roll-up updates and hotfixes issued by Microsoft. Also is MS ATP is competitive compared to 3rd part AV providers.

Pros

  • It does not take up a lot of system resources, unlike other 3rd part AV providers.
  • Integrated into the MS product line without having to touch it too much, unlike 3rd part AV providers.
  • Easy to set-up and manage endpoints.
  • It does not break Windows OS like 3rd party AV providers whenever a patch or roll updated is deployed.

Cons

  • Detection rates are less than some of the competitors out there.
  • Too many false positives with 3rd part applications.
  • For smaller deployments can get expensive compared to competitors.

Likelihood to Recommend

MS ATP is great for any organization that wants to protect itself from AV, malware, spyware, and ransomware threats. I can't imagine any organization doing without an AV protection provider. Small deployment can get expensive compared to the competition.
Vetted Review
Microsoft Defender for Endpoint
3 years of experience