ConnectWise Automate, formerly LabTech, is a remote monitoring and management (RMM) platform. It provides powerful automation to discover and manage devices, monitor for problems, and scripts repetitive action.
$700
Microsoft Defender XDR
Score8.7 out of 10
N/A
Microsoft 365 Defender combines SIEM and XDR capabilities for Microsoft 365 environments, encompassing threat detection, post-breach detection, automated investigation, and response for endpoints. Additionally, it protects cloud apps, emails and documents, and employee identities.
I recommend it to all IT colleagues; regardless of the size of the PCs with which you work most of the time, the application allows connection stability between computers that make it possible to continue working or taking care of the infrastructure from afar.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
In our experience, Microsoft Defender XDR has been fantastic for phishing and account compromise scenarios, Endpoint Security, Automated threat detection and response and just generally giving a great overview through their dashboard, meaning the IT team doesn't need to switch between multiple tools to understand the full scope of an incident. In mostly remote organization like ours, it really helps to keep on top of any potential threats that we don't have the opportunity to spot in person. While it works great for us in a mostly Microsoft 365 environment, I can see how it would be less appropriate in an organization that is less integrated in the Microsoft ecosystem or uses a large number of third party tools.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
One of the greatest strength of Microsoft Defender XDR has the ability to convey alert and signal in the closing point, email, identity and cloud applications in an event. Instead of obtaining isolated alert from each tool, Microsoft Defender XDR consolidates them in a full attack story, which helps the security teams to understand the scope and impact of a danger very fast.
If a user clicks on the fishing link, Microsoft Defender XDR automatically can associate malicious emails with lateral movement efforts, suspected sine-in, and endpoint activity-to protect against hours of manual probes.
The defender uses AI-powered automation for investigating and treatment of Microsoft Defender XDR events. It can separate the infected closing points, can cancel the compromised tokens, or remove malicious email - without the need for human intervention.
When malware is detected on a device, the defender can separate the device, kill malicious processes, and automatically flag the same files throughout the environment, which can spread.
Because it is integrated deeply with Microsoft 365 defender, Entra ID (Azure Ad), Intune, and PurView, the defender provides native safety in the XDR Microsoft Stack. It simplifies deployment and maintenance, offering deep visibility in user activity and cloud data.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
They have conflicting scheduling paradigms. When scheduling patching for clients, the 1st Friday is interpreted as the very first Friday of the month, even if this is the 1st of the month. For scripting, the 1st Friday of the month is interpreted as the 1st Friday of the 1st FULL WEEK of the month. This makes no sense to have two different interpretations, and makes it unreliable to schedule recurring scripts to fall when recurring maintenance does. The scripts need to be done manually because of this.
There is no way to dictate reboot orders for patch policies. This tied directly in with my first point. We have some clients that require reboot orders. This is not possible without having different patch policies for each server and specifying a time this way. But, there aren't small enough increments of time to make this reliable, plus patching duration might vary. Excluding reboots with patching and scheduling reboot scripts fixes this. However, this can't be done once on a recurring schedule due to the different scheduling paradigms already discussed. We have to schedule these manually each month.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Improved algorithms to minimize false positives in threat detection, reducing the impact on security teams and preventing unnecessary investigations into non-threatening incidents.
Advanced User-Friendly Interface:
Streamlined and intuitive user interface for the centralized dashboard, making it more accessible for security professionals with varying levels of expertise.
Greater Third-Party Integration:
Increased compatibility and integration capabilities with a broader range of third-party security tools
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
The primary reason for this rating is that ConnectWise Automate is currently so integral to our operations that moving away would involve more man hours than we would realistically have to invest. However, ConnectWise Automate is also completely capable of meeting all of our business needs and customizable to the point where if something is not meeting those needs out of the box, it can be modified to do what we want. From only installing software on machines if a different software package exists, to push a new version of that software is available, to check if credentials for user/machine have been updated to our new standards and then updating them if they have not, ConnectWise Automate is capable of doing everything we ask of it.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
We are pleased with the product and have no plans to look for alternatives. We are deeply invested in Microsoft ecosystem and Defender XDR provides seamless integration to other Microsoft products. For academic institution pricing is also quite affordable. In the contrary, we hope to extend the scope of the product for our entire environment.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. TR verified that a representative sample of customers was invited. More Info
Basic use of the product is fairly easy. Information about the machines you manage can be found in customizable dashboards, which can be unique for each user, and, therefore, properly suited to the users' needs/job function. This is not a 10 because some of the interfaces are very clunky (Patch Management), and some features are not intuitive and not well documented (reporting). Scripting and Patch Management have a fairly steep learning curve (For structure in patch management and syntax in scripting), but once learned, they work well.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Once configured, it's very usable for any security team or IT Analyst. It'll give you everything you need to know in a single consolidated dashboard, and while you can certainly dive deeper with a very feature rich platform, generally it's very usable. I gave it an 8 as some of the advanced features do have a very strong learning curve, while routine tasks are quite straightforward, some of the features such as threat hunting, custom detections and automated response workflows do have a bit of a learning curve and will require some research and experience to get to grips with
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
In our experience there has been very little downtime for Microsot Defender XDR. For us there hasn’t been any single incident where we needed the product and it was not available.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. TR verified that a representative sample of customers was invited. More Info
It used to be great, but then they broke reporting, speed and responsiveness with version 11 and the new Patch Manager. It's really bad and their support people are way behind on fixing so many bugs. They have really gone downhill. If they don't get it together soon, we'll start looking around.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Most of the time the product is as responsive as you might expect from cloud product. Occasionly the product is little slugish, this has been at most a slight irritation. Reports generate quickly ennough for our needs. We also not have found that Defender XDR slows down systems that it is integrated with
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. TR verified that a representative sample of customers was invited. More Info
ConnectWise Automate lets you manage more endpoints, with enhanced productivity and improved service, all without increasing expenses. It can manage patches and updates across thousands of computers. We also use it for customized monitoring and alerting on workstations and servers. Monitoring is really robust and granular. It does a great job of gathering a TON of data about the network, and that data is searchable. There are a bunch of different reports built in. Integrates with Manage, Control, and other applications. It does a ton of stuff out of the box, and has endless customization options.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Their support throughout our onboarding of the product was fabulous. They not only took the time to carefully explain to teams not as well equipped with the lingo but explained to the tech team how to teach the other teams to be successful. They never once seemed impatient or annoyed with basic questions and didn’t pretend to know something when they needed to research an answer
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. TR verified that a representative sample of customers was invited. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
The Online training has been re-done and needs a lot more work. When you look at training in different roles, it shows a lot of the same topics but no explanation to what is different about them. Several times that topics are the exact same, but they make you re-take the same information for a different topic, instead of marking that you have already completed that portion of training.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Microsoft Provides a good training for the Microsoft 365 Defender and has a good learning paths to learn and take the exams and get your Certifications.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Start small and learn the in's and out's before making policies and rolling things out company wide. Ask the questions of why if you don't agree with something or your company does things a different way. Usually they are done a certain way for a reason. Start simple with roll out and slowly enable or add on the functionality that is needed.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
seemless and almost transparent. can be deployed by script if needed so every endpoint on our system get's it. if you have intune it gets dumped on the the endpoint by policy so nothing escapes it
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. TR verified that a representative sample of customers was invited. More Info
I believe the monitoring and alerts in Continuum command is better, but [ConnectWise Automate (formerly LabTech)] does have stronger scripting, and perhaps a better interface. N-Central is inferior on all fronts to both. I did not make the purchasing decision. I would myself likely pick Continuum if I had to make a on the spot choice.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Our product in that area, for instance as a security platform and for us it is for the moment really bad point. We started to move in that direction that there is that disconnect from the client management. So if there is some action that needs to be executed detected by security team, there is not an easy way to make that available to the team that is responsible for managing the identities as users, as the devices
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info
Azure cloud provides techical power to scale the product for whole organization. From organizational point of view scaling Defender XDR for various IT teams needs good collaboration and clear norms that all teams must agree to and follow.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. TR verified that a representative sample of customers was invited. More Info
We found we were able to provide good monitoring of our customers sites which was an objective. However, that came at a significant time investment that never seemed to be finished.
We were able to negotiate a price that worked for us for an up-front purchase which was nice.
We found the pricing to be very competitive.
Bottom line for us was despite the pros of the product, we found other RMM solutions to be a better overall "value" due to not having to dedicate technicians to maintaining the product.
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. TR verified that a representative sample of customers was invited. More Info
A de minimis incentive was given to thank the reviewer for their time. The incentive was not used to bias or drive a particular response, nor was the incentive contingent on a positive endorsement. More Info