TrustRadius: an HG Insights company

Microsoft Defender for Endpoint

Score8.8 out of 10

330 Reviews and Ratings

What is Microsoft Defender for Endpoint?

Microsoft Defender for Endpoint (formerly Microsoft Defender ATP) is a holistic, cloud delivered endpoint security solution that includes risk-based vulnerability management and assessment, attack surface reduction, behavioral based and cloud-powered next generation protection, endpoint detection and response (EDR), automatic investigation and remediation, managed hunting services, rich APIs, and unified security management.

Read more details.

Categories & Use Cases

Media

Screenshot of blocked activities
Screenshot of Detects & responds
Screenshot of discovers vulnerability
Screenshot of Eliminates blind spots
Screenshot of Risk management

1 / 5

Screenshot of blocked activities

Top Performing Features

  • Malware Detection

    Detection and blocking of zero-day file and fileless malware.

    Category average: 9.1

  • Endpoint Detection and Response (EDR)

    Continuous monitoring and response to advanced internet threats by endpoint agents.

    Category average: 9.2

  • Anti-Exploit Technology

    In-memory and application layer attack blocking (e.g. ransomeware)

    Category average: 8.8

Areas for Improvement

  • Centralized Management

    Centralized management supporting multi-factor authentication, customized views, and role-based access control.

    Category average: 8.7

  • Vulnerability Management

    Vulnerability prioritization for fixes.

    Category average: 8.6

  • Hybrid Deployment Support

    Administrators should be able to choose endpoint security on-premise, cloud, or hybrid.

    Category average: 7.9

Who Buys & Uses Microsoft Defender for Endpoint

Pros

  • Advanced threat detection and automated response capabilities
  • Seamless integration within the broader Microsoft ecosystem
  • Cost-effectiveness through existing Microsoft 365 licensing

Cons

  • Complex and non-intuitive management interface with scattered information
  • High volume of false positives leading to alert fatigue
  • Limited native reporting and analytics capabilities

Microsoft Defender for Endpoint

Use Cases and Deployment Scope

Scope of use case is the title, link file, RNK, and file. Malware

Pros

  • I get a good rest. Static file Detections of malware are updated quite often and are also quite effective. And overall has more.

Cons

  • So far, it has not been detecting the link. File. Malware for changes that we are facing where you buy separately from simple anti, let the link file malware problem.

Return on Investment

  • It's malware detection, so it didn't apply any objectively; it didn't really apply any bit objectively is anti-slideshare.

Usability

Microsoft Defender for Endpoint Review

Use Cases and Deployment Scope

So Microsoft Defender for Endpoint manages the scope of all of our endpoints, including servers, desktops, laptops, and so forth. It is our EDR and XDR product for our enterprise. So it monitors all activity on the laptop for viruses, ransomware, any type of activity, anomalous activity, or anything associated with those types of threats.

Pros

  • So I think it went well. It's a great question. It does a lot of things well, but it's tied into some other products that we use. So I would say that it identifies threats and risks. And we also use another product that manages that risk. And then we—so, just to be clear, we use Purview and DLP associated with the Microsoft Defender for Endpoint product, and we use their SIEM product to manage what we do when an event or an alert becomes active.

Cons

  • I mean, I think there's a lot of things, and that's just the nature of the beast. So there's a lot of change in the industry, and they tend to keep up with the change. Nobody can keep up with the same pace as the changes itself. But one of the areas I think that we have the most challenges with is when the alert comes in, it takes a while before we get alerted. And that creates somewhat of an issue. So if it's 10, 15, 20 minutes, then we have 15, 20 minutes of a bad actor being in our environment and we don't know about it. So we can't act upon it, and we're not in a position to act immediately. And I guess that's part of the problem on the Microsoft Defender for Endpoint reporting side of what we've been told.

Return on Investment

  • Again, it's embedded into our license model. So our ROI is kind of hard to figure out with it because of the embedded cost. But as we go through our annual checks, it checks our boxes, and we have not been in the news. So I would say it's pretty successful.

Usability

Microsoft Defender for Endpoint review

Use Cases and Deployment Scope

We use it to currently help manage our endpoints as well as our servers, but that's not the endpoint version; that's the defender for our server portion, I guess. But endpoints, yes. Our current desktop environment, things like that.

Pros

  • It allows us to triangulate with the Microsoft cloud to be able to deal with incoming threats

Cons

  • General training and functionality, maybe. Make it a little bit more simple. A little bit simpler, if they can, from a detailed administration standpoint

Return on Investment

  • It helped us with a malware event. A malware and ransomware event that we had. So it was one of the three products that was able to protect us

Microsoft Defender for Endpoint

Use Cases and Deployment Scope

It's used for monitoring our endpoints across the US. It has a backend for cloud, which is very helpful and detects and allows for incident response to go much faster. Paired with Sentinel, it's fantastic.

Pros

  • Malware detection and different issues that come in with it, like if someone's hacking an end user or they click a malicious link, it will detect that, alert our guys, and then they can jump in and see what was going on. It has the ability to reach in and review malicious code and tell you how it started and see the attack chain.

Cons

  • AI agent integration. It's not quite there yet, but working on it.

Return on Investment

  • Positive. With it being integrated into the operating system, it reduces the amount of agent load that we get on the endpoints.

Usability

Alternatives Considered

CrowdStrike Falcon and SentinelOne Vigilance

Other Software Used

Datadog

Offers Solid Protection Against Attacks at the Endpoints.

Use Cases and Deployment Scope

We use the Microsoft Defender for Endpoint to protect data at the endpoints. Helps to keep employees laptop, desktops, phones and other devices secure and protect against cyber threats. Offers a strong encryption scheme that helps to protect data organizational data from getting in wrong hands in-case of lost of a device.

Pros

  • Protects devices from cyber attacks ( Malware and Spyware)
  • Responding to threats in real-time.
  • Automates cyber threat protection and response.
  • Seamless integration with Microsoft ecosystem.
  • Offers reliable security monitoring.

Cons

  • Learning curve for advanced features.
  • False positive in occasional instances.

Return on Investment

  • Enhances security at the endpoints.
  • Helps to boast productivity by elimination of interruptions.
  • Enhances compliance and disaster recovery.

Usability

Other Software Used

Barracuda Backup, Microsoft 365