Microsoft Defender for Endpoint vs. Microsoft Intune

Overview
ProductRatingMost Used ByProduct SummaryStarting Price
Microsoft Defender for Endpoint
Score 8.9 out of 10
N/A
Microsoft Defender for Endpoint (formerly Microsoft Defender ATP) is a holistic, cloud delivered endpoint security solution that includes risk-based vulnerability management and assessment, attack surface reduction, behavioral based and cloud-powered next generation protection, endpoint detection and response (EDR), automatic investigation and remediation, managed hunting services, rich APIs, and unified security management.
$2.50
per user/per month
Microsoft Intune
Score 8.2 out of 10
N/A
Microsoft Intune (formerly Microsoft Endpoint Manager), combining the capabilities of the former Microsoft System Center Configuration Manager, SCCM or ConfigMgr, is presented as a unified endpoint management option. Microsoft Intune is an endpoint management solution for mobile devices, an MDM solution that allows the user to securely manage iOS, Android, Windows, and macOS devices with a single endpoint management solution. The component Endpoint Configuration Manager (the…
$5
per user/per month
Pricing
Microsoft Defender for EndpointMicrosoft Intune
Editions & Modules
Academic
$2.50
per user/per month
Standalone
$5.20
per user/per month
Microsoft 365 Business Basic
$5
per user/per month
Microsoft 365 For Individuals
$6.99
per month
Microsoft 365 Apps
$8.25
per user/per month
Microsoft 365 For Families
$9.99
per month
Microsoft 365 Business Standard
$12.50
per user/per month
Microsoft 365 Business Premium
$15
per user/per month
Offerings
Pricing Offerings
Microsoft Defender for EndpointMicrosoft Intune
Free Trial
YesNo
Free/Freemium Version
NoNo
Premium Consulting/Integration Services
NoNo
Entry-level Setup FeeNo setup feeNo setup fee
Additional Details
More Pricing Information
Community Pulse
Microsoft Defender for EndpointMicrosoft Intune
Considered Both Products
Microsoft Defender for Endpoint
Chose Microsoft Defender for Endpoint
Defender is far easier to deploy and manage than Sophos and tends to work without as many issues. The threat assessment portal provides an in-depth view of the organization's security posture, whereas Sophos only shows the patching status of the PCs. We did need Intune to get …
Chose Microsoft Defender for Endpoint
Microsoft Defender for Endpoint is the most cost effective solution considering our Microsoft 365 licensing status. While many 3rd party solutions are great and have been used over the years, in the non-profit world, cost is a huge driving factor of items. Coupled with …
Chose Microsoft Defender for Endpoint
We started onboarding macOS devices on jamf and started managing it. Because Defender for Endpoint is not working as expected for and compared to price and functionality we are switching from it.
Chose Microsoft Defender for Endpoint
As we are using 90% of Windows devices and laptops in our organisation we figured out that Microsoft Defender for Endpoint is a better solution for us as compared to above solutions mentioned. It is very easy and convenient to use this solution with Windows devices. The …
Chose Microsoft Defender for Endpoint
It has more functionality overall and then again, reporting is much better. The ability to prioritize and define our own criticalities, so I think that's a lot better.
Chose Microsoft Defender for Endpoint
Microsoft Defender gels very well with the rest of the M365 suite of products. The security Dashboard gives one view for Email Security and Endpoint Security. The security events can be generated while getting integrated with SIEM solution or can use its own SIEM offering.
Chose Microsoft Defender for Endpoint
Very reliable with accuracy
Does not become a resource hog
Chose Microsoft Defender for Endpoint
As compared to some of the other products we have used in our organization over the years, Windows Defender has been a lot better at not using a lot of system resources when running on the clients. A lot of other commercial threat protection products on the market today, tend …
Microsoft Intune
Chose Microsoft Intune
Microsoft Intune is more robust as far as fine-tuning security controls. It also allows for software installs, folder access controls, updating PCs, and other features simply not found in previous products we have used. Because it is rolled into MS 365 it's very cost …
Features
Microsoft Defender for EndpointMicrosoft Intune
Endpoint Security
Comparison of Endpoint Security features of Product A and Product B
Microsoft Defender for Endpoint
8.7
77 Ratings
3% above category average
Microsoft Intune
-
Ratings
Anti-Exploit Technology8.874 Ratings00 Ratings
Endpoint Detection and Response (EDR)9.176 Ratings00 Ratings
Centralized Management8.876 Ratings00 Ratings
Hybrid Deployment Support7.210 Ratings00 Ratings
Infection Remediation9.074 Ratings00 Ratings
Vulnerability Management8.671 Ratings00 Ratings
Malware Detection9.175 Ratings00 Ratings
Best Alternatives
Microsoft Defender for EndpointMicrosoft Intune
Small Businesses
ThreatLocker
ThreatLocker
Score 9.4 out of 10
Avast CloudCare
Avast CloudCare
Score 10.0 out of 10
Medium-sized Companies
BlackBerry Protect (CylancePROTECT)
BlackBerry Protect (CylancePROTECT)
Score 9.1 out of 10
KACE Systems Management Appliance
KACE Systems Management Appliance
Score 8.6 out of 10
Enterprises
BeyondTrust Endpoint Privilege Management
BeyondTrust Endpoint Privilege Management
Score 9.9 out of 10
KACE Systems Management Appliance
KACE Systems Management Appliance
Score 8.6 out of 10
All AlternativesView all alternativesView all alternatives
User Ratings
Microsoft Defender for EndpointMicrosoft Intune
Likelihood to Recommend
8.9
(136 ratings)
9.1
(53 ratings)
Likelihood to Renew
8.4
(10 ratings)
9.9
(2 ratings)
Usability
8.7
(11 ratings)
8.2
(12 ratings)
Availability
9.1
(1 ratings)
-
(0 ratings)
Performance
9.1
(1 ratings)
6.9
(14 ratings)
Support Rating
9.0
(7 ratings)
10.0
(10 ratings)
Implementation Rating
7.3
(1 ratings)
8.9
(2 ratings)
Configurability
8.2
(1 ratings)
-
(0 ratings)
Ease of integration
-
(0 ratings)
7.6
(14 ratings)
Product Scalability
9.1
(1 ratings)
-
(0 ratings)
User Testimonials
Microsoft Defender for EndpointMicrosoft Intune
Likelihood to Recommend
Microsoft
It is well integrated with the Microsoft Admin center providing a quick way to find everything you're looking for. However, if there is a problem that needs addressed, you may have to click through a few more pages to find the solution. It will definitely let you know what's going on in your environment.
Read full review
Microsoft
Microsoft Intune is well suited for the larger end of the small business segment to the enterprise. The ability to configure and remotely deploy computer configurations, control mobile devices, and fine tune security controls of each device or device group is a major win for this product. Smaller and mid-sized businesses may balk at having to increase their license level to unlock the better updating features.
Read full review
Pros
Microsoft
  • One, it's crazy lightweight, so compared to some of the competitors that we also have used with our security services, it's really lightweight and so I don't have a lot of overhead on the system that it's running on.
  • It does really fantastic PowerShell integration.
Read full review
Microsoft
  • [Microsoft Endpoint Manager (Microsoft Intune + SCCM)] helps to speed up the deployment of patches/software throughout our environment. I can easily build a package and then deploy across all endpoints.
  • The ability to supercede software is also quite handy. This automates the removal of old versions and replacing them with newer versions.
  • The Intune Autopilot option is very useful if you want to deploy software to devices straight out of the box. You can configure them to download software when a user opens a new PC and turns it on for the first time.
Read full review
Cons
Microsoft
  • So the fact that Defender for Endpoint still works with signatures is actually, I don't know, a little difficult for us because, I mean, since Microsoft trusts those signatures, you can easily inject code. And we've done it many times. To show that you can inject code through vulnerabilities like CV 2013, 99, and 33 but still keep the signature. So because of the trust of those signatures, the malware just kind of slides into the environment without Defender knowing. That's the first part. The second part is that the behavioral analysis is not precisely its Prime. It's not Defender's best capability for endpoints. So, Defender does not identify all behaviors considered by other EDRs in the market.
Read full review
Microsoft
  • Deploying more apps besides Microsoft Edge and Microsoft Office 365 app
  • Microsoft needs to make it easier to deploy exe, pkg, and msi apps without having to go through the manual process of re-packaging these apps using tools from github like intuneapputil
  • Add a feature to push out software updates for 3rd party apps
Read full review
Likelihood to Renew
Microsoft
Cost add-ons for Security features is nickel and diming the process to keep pace with cybercrime. Limited Education budgets require us to be more pro-active in finding cost-effective measures to protect our devices, staff and students. Defender is a strong, well-featured product that is pricing itself out of the education market
Read full review
Microsoft
Mascom Wireless is a Microsoft shop and SCCM has proved to be helpful in keeping our Microsoft products up to date every month without fail. We also have a Microsoft Enterprise Agreement which we renewed for three years ending 2022. The remote access utility works wonders for the organisation and have saved travel bills including subsistance allowance. We have been able to fulfill security audits both internal and external. We have been able to keep a robust inventory of our computer assets and nothing falls of the cracks
Read full review
Usability
Microsoft
It offers multiple security features and integrates well with Microsoft ecosystems. A workflow for threat detection, investigation, automated remediation, and a centralized dashboard is an added advantage. This application is mainly designed for experienced users; new users may feel challenged.
Read full review
Microsoft
The console is not intuitive and does not work well often. Due to the complexity of the product, documentation can be confusing. When properly configured, routine tasks like OS deployment, remote control, and software deployment are easy to do. Troubleshooting of System Center Configuration Manager issues is hard, as there are various logs, and their content can be hard to understand.
Read full review
Reliability and Availability
Microsoft
Microsoft Defender for Endpoint chugs along just fine no matter what we throw at it and what systems it's running on. It doesn't take up a lot of resources either, so that's welcomed.
Read full review
Microsoft
No answers on this topic
Performance
Microsoft
Microsoft Defender for Endpoint is easy on memory and resources on clients.
Read full review
Microsoft
It's a 'heavy' system, which demands a lot of resources form the datacenter perspective. So, make sure you followed the requirements to avoid frustration in the future. From the 'client' perspective, it's fine. I've never had any issue with that.
Read full review
Support Rating
Microsoft
The first time I tried to onboard my macOS endpoints to MDE I struggled for quite a bit. I had to reach out to Microsoft's MDE support team. The tech was very helpful in walking me through the steps during a screen share session
Read full review
Microsoft
We have not needed to seek support for this product in the time that we have used it thus far. It's been working really well, and have not had any major issues. Being that it's a Microsoft product, it goes without saying that there will be many support options available if needed. This includes phone, web, forums, KB articles, etc. There is even comprehensive documentation that is available on the web through Microsoft's website for use of the product.
Read full review
Implementation Rating
Microsoft
Deployment was handled by our team here and everything went pretty smoothly. We did have a few hiccups in our test group, but that only took a bit to get ironed out.
Read full review
Microsoft
Work with a "test group" of users who you have a good relationship with so that when things don't work properly they understand! Work with your partner nicely without forcing things especially timelines as you are bound to make mistakes and create oversights in the project Management can also interfere with the implementation (which can cause delays) if you make too many mistakes which takes me back to having a "test group" where you have good relations
Read full review
Alternatives Considered
Microsoft
Defender is far easier to deploy and manage than Sophos and tends to work without as many issues. The threat assessment portal provides an in-depth view of the organization's security posture, whereas Sophos only shows the patching status of the PCs. We did need Intune to get many of the control features (disabling USB drives) that Sophos offered out of the box.
Read full review
Microsoft
We did not evaluate or use other products like Microsoft Endpoint Manager (Microsoft Intune + SCCM). The main reason we did not evaluate or use other products is because Microsoft Endpoint Manager (Microsoft Intune + SCCM) integrates seamlessly with Microsoft 365 and Windows PCs. Expenses would have increased as well if we had purchased another similar product.
Read full review
Scalability
Microsoft
Microsoft Defender for Endpoint is easily scaled from small orgs to giant enterprises.
Read full review
Microsoft
No answers on this topic
Return on Investment
Microsoft
  • Reduced incidents of security breaches lead to lower remediation costs and avoid potential financial losses and reputational damage.
  • Reduces the need for additional third-party security solutions and training, thereby lowering overall security management costs.
  • Increased efficiency and productivity of IT staff lead to better allocation of resources and cost savings.
  • Reduces the risk of fines and sanctions associated with non-compliance, ensuring business continuity and protecting revenue.
Read full review
Microsoft
  • In our current environment, this System Center Configuration Manager had replaced several standalone solutions for patching, imaging, remote assistance, reporting, etc. That saved a lot of time and resulted in money to manage the IT infrastructure.
  • Once SCCM is deployed and fully configured, all agents are deployed and it is easy to automate a lot of processes and just control them from time to time to make sure that everything is working as supposed to be.
  • SCCM + Windows 10: great built-in endpoint protection solution. As a result, there is no need to buy additional software for that purpose.
  • The imaging process is better compared to WDS because you can modify deployment packages and apply patches to a newly imaged machine. This saves tons of time for new employees deployment.
Read full review
ScreenShots

Microsoft Defender for Endpoint Screenshots

Screenshot of blocked activitiesScreenshot of Detects & respondsScreenshot of discovers vulnerabilityScreenshot of Eliminates blind spotsScreenshot of Risk management