Everfox Data Guard, formerly from Forcepoint, enables highly complex, bi-directional, automated data and file transfers between physically separated networks.
N/A
Microsoft Defender for Endpoint
Score 8.8 out of 10
N/A
Microsoft Defender for Endpoint (formerly Microsoft Defender ATP) is a holistic, cloud delivered endpoint security solution that includes risk-based vulnerability management and assessment, attack surface reduction, behavioral based and cloud-powered next generation protection, endpoint detection and response (EDR), automatic investigation and remediation, managed hunting services, rich APIs, and unified security management.
Scenarios where this solution suits well - 1) Zero Trust Network - wherever client wants a perfect ZTN enabled network + Compliant with standards like NIST 2) Huge Data / VIDEO transfer with cloud/AWS solutions like CDN and CloudFront - Able to connect easily 3) Hybrid networks - connect with various security policies 4) Secure data transfer which has UDP needs for traffic like syslog/UDP VoIP ports need
I think Microsoft Defender for Endpoint is very good in the federal space that I work in because when you deal with these highly regulated environments, anything that you have outside of the Microsoft ecosystem, you have the justified documented company. There's a lot of work and a high level of effort involved in that. So what it's really good at is that it's all encompassed into Microsoft. It's built in, it works really well together. So that's why it's my recommendation whenever we deal with customers that are in my field.
I think from a scalability perspective, it’s incredible. It fits very well with our Azure stack, and we’re constantly adopting more and more different Microsoft products. But I think the key thing is ease of use. Its scalability, and it’s just that, enterprise-wise and in terms of control, we can actually centralize it as well.
I feel like the vulnerability management side of things is really great. I would like maybe more custom risk scores from that. It gives us our highs and criticals. Proof of concept exploits would be great so we can really assess the risk. It already does a lot of that, though. It gives us that tag. But maybe making it more GUI-friendly, more visibly friendly, could be something I feel like they could work on. The portal, too, I find, is a little hard to navigate sometimes. There seem to be hidden webpages within webpages. One thing off the top of my head is the IPs. They have the IP pages, but you have to click through four or five different subpages to get there. So I feel like maybe redoing the navigation in the portal would be very helpful.
Cost add-ons for Security features is nickel and diming the process to keep pace with cybercrime. Limited Education budgets require us to be more pro-active in finding cost-effective measures to protect our devices, staff and students. Defender is a strong, well-featured product that is pricing itself out of the education market
It's good, but as I said, it does get a little confusing sometimes when you're trying to remediate, when you're trying to put all your alerts together, and trying to get everything in the same place. It's a little, I guess, what we call alert fatigue. There are a lot of alerts on it as well.
Microsoft Defender for Endpoint chugs along just fine no matter what we throw at it and what systems it's running on. It doesn't take up a lot of resources either, so that's welcomed.
The first time I tried to onboard my macOS endpoints to MDE I struggled for quite a bit. I had to reach out to Microsoft's MDE support team. The tech was very helpful in walking me through the steps during a screen share session
Deployment was handled by our team here and everything went pretty smoothly. We did have a few hiccups in our test group, but that only took a bit to get ironed out.
1) Good satisfactory overall support 2) Relatively straight forward installation 3) Data Security 4) Cloud support which is big plus / multi cloud as well. Most of the clients are also very intelligent since they refer Gartner and other reports for statistical data. They do their homework well in advance hence we have to make sure we know the product well
Previously, we've used Sophos. We've used, way back when, McAfee, Norton, Symantec, all those. And we finally settled on Microsoft Defender for Endpoint. We're a Microsoft technology stack shop. So obviously it was natural. It's built into Windows, so we're not adding additional agents. Some of the other vendors and their agents, for a while, would compete with CPU usage. And so it actually slowed down the machines. Because Microsoft Defender for Endpoint is built into the Windows product, Microsoft is going to ensure that it does not affect the other productivity tools that a user may use.
Since we are from cyber security, we are engaged in a multi-year relationship with clients that are interested in deploying ForcePoint.
We have been strong pipeline in our current PoVs for European clients that are interested in this solution. They just want extended support to deploy it end-to-end
Less costly training mandates, good training material available on the net
Another positive impact is that Microsoft Defender for Endpoint is built into the Windows OS. So naturally, it is much easier to load it out and manage it, rather than acquiring it through party ER, deploying it, and managing it separately. So that's definitely on the positive side that we observe there's a byproduct of changing Microsoft Defender for Endpoint.