TrustRadius: an HG Insights company

Microsoft Defender XDR

Score8.8 out of 10

153 Reviews and Ratings

What is Microsoft Defender XDR?

Microsoft 365 Defender combines SIEM and XDR capabilities for Microsoft 365 environments, encompassing threat detection, post-breach detection, automated investigation, and response for endpoints. Additionally, it protects cloud apps, emails and documents, and employee identities.

Media

AH Advanced Mode
AH Guided mode
CD example
CD Supported actions

1 / 4

My experience with Microsoft Defender XDR

Use Cases and Deployment Scope

We replaced our previous XDR with Microsoft Defender XDR 4 years ago and we don't regret the decision we made. The software has provided us with centralised visibility, real time threat management and anomaly detection. It has also provided us with comprehensive protection against malware and other sophiscated attacks. The software has amazing detection efficiency and automation capabilities. Through implementation of the tool we are able to stay ahead of evolving modern day threats and keep our endpoints safe and secure.

Pros

  • The software has broad integration capabilities and powerful automation systems.
  • Microsoft Defender XDR is easy to use and has a very user-friendly interface.
  • It is fast and reliable in detecting attacks
  • Effectiveness of the product in vulnerability management and threat intelligence.

Cons

  • Support services of the software are very unreliable. The take so much time before responding to customer queries.
  • Cost of software premium services and advanced protection is expensive.
  • Software configuration is complex.

Return on Investment

  • The software has helped us in catching threat fast and in responding to anomalies in real-time before they cause operation inefficiencies.
  • Use of the product in our organisation has ensured automated threats response and remediation.
  • Microsoft Defender XDR has provided us with extensive and powerful defence against modern cyber threats.

Usability

Other Software Used

Google Analytics, Google Ads, GoTo Meeting

MS Defender XDR

Use Cases and Deployment Scope

Microsoft Defender XDR actively monitors all our company endpoints for malicious software and URLS. It covers approx. 100 machines, and is accessed through our MS365 admin portal. It provides us with a real time view of any malicious activity, a break down of the chain of events lading up to it, the machines and user sinvolved and provides automated responses and recommendations on manual interventions.

Pros

  • Active/real time monitoring
  • dashboards
  • Automated responses

Cons

  • logs even informational incidents as active, even if there's no threat
  • little hard to navigate some of the consoles to find information sometimes
  • not always clear if action is needed

Return on Investment

  • No specific ROI, though has caught a small number of malicious attacks.
  • It's included with our MS365 Business Pro licenses, so the value is good as its essentially at no extra cost on top of the Office software and Azure AD we are using anyway.

Alternatives Considered

Trend Vision One Endpoint Security

Other Software Used

LogMeIn Central by GoTo, Smartsheet, OwnBackup

I recommend amazing

Use Cases and Deployment Scope

We use the full Microsoft 365 suite, so Microsoft Defender XDR is included and protects the corporate network.

Utilizamos todo o pacote Microsoft 365, portanto o Microsoft Defender XDR está incluído e protege a rede corporativa.

Pros

  • Antimalware
  • Web Protection
  • ID Monitoring

Cons

  • Improve resource usage when implemented. The slowness of the system is noticeable when the tool is scanning.

Return on Investment

  • The blocking action has been effective, avoiding many problems with personal and corporate data.

Alternatives Considered

Bitdefender Managed Detection and Response (MDR)

Other Software Used

Microsoft Teams, Trello, Infinera Transcend Network Management System (NMS)

Strong Security Shield with Smart Integrations

Use Cases and Deployment Scope

We use Microsoft Defender XDR to keep our computers safe from bad stuff like viruses and spam. It helps us stop the bad emails and things before they can hurt us. We use it on all our laptops and phones so everyone is safe. It is like a superhero for our computers and makes sure no sneaky hackers come in.

Pros

  • Unified threat detection across endpoints
  • Endpoint activity monitoring and logging
  • Rapid forensic data collection and analysis
  • Detailed threat analytics and reporting
  • Automated remediation workflows

Cons

  • Multi-tenant management complexity
  • Automated response configuration
  • User behavior analytics granularity
  • License complexity and cost

Return on Investment

  • Lower overall security costs.
  • Saves time on manual tasks.
  • Supports remote workforce security.
  • Detects insider threats.
  • Weak multi-tenant support.
  • False positives waste time.
  • Can’t automate all responses.

Alternatives Considered

CrowdStrike Falcon

Other Software Used

Microsoft Sentinel, CrowdStrike Falcon, Cisco SecureX

It gives system security very proficiently

Use Cases and Deployment Scope

It saves our system and mails from the cyber attacks. It blocks the threats immediately. This is knows has extended detection and response. It improves security by adding extra wall in our system. It gives protection across the system from the endpoints, emails to the system apps. It continuously work and deliver the secure and smooth experience to the system. It debug or fix the threat queries rapidly.

Pros

  • Rapidly detect and fix.
  • Seamless work on Microsoft ecosystem.
  • Advanced features that deliver better experience.

Cons

  • More third party integration needs to be add.
  • Require high configuration system.

Return on Investment

  • Better security than the others.
  • Quick response and detection system.
  • Reduce manual work and human errors.