TrustRadius: an HG Insights company

Microsoft Defender for Endpoint

Score8.9 out of 10

286 Reviews and Ratings

What is Microsoft Defender for Endpoint?

Microsoft Defender for Endpoint (formerly Microsoft Defender ATP) is a holistic, cloud delivered endpoint security solution that includes risk-based vulnerability management and assessment, attack surface reduction, behavioral based and cloud-powered next generation protection, endpoint detection and response (EDR), automatic investigation and remediation, managed hunting services, rich APIs, and unified security management.

Read more details.

Categories & Use Cases

Media

Screenshot of blocked activities
Screenshot of Detects & responds
Screenshot of discovers vulnerability
Screenshot of Eliminates blind spots
Screenshot of Risk management

1 / 5

Screenshot of blocked activities

Top Performing Features

  • Malware Detection

    Detection and blocking of zero-day file and fileless malware.

    Category average: 9.1

  • Endpoint Detection and Response (EDR)

    Continuous monitoring and response to advanced internet threats by endpoint agents.

    Category average: 9.2

  • Infection Remediation

    Capability to quarantine infected endpoint and terminate malicious processes.

    Category average: 8.6

Areas for Improvement

  • Vulnerability Management

    Vulnerability prioritization for fixes.

    Category average: 8.6

  • Centralized Management

    Centralized management supporting multi-factor authentication, customized views, and role-based access control.

    Category average: 8.6

  • Hybrid Deployment Support

    Administrators should be able to choose endpoint security on-premise, cloud, or hybrid.

    Category average: 8

Who Buys & Uses Microsoft Defender for Endpoint

Pros

  • Robust threat detection and rapid response capabilities, including advanced machine learning for malware.
  • Seamless integration within the broader Microsoft ecosystem (e.g., Microsoft 365, Sentinel, Intune).
  • Significant cost savings by consolidating or replacing third-party antivirus and EDR solutions.

Cons

  • Management interface is perceived as cumbersome, difficult to navigate, and prone to frequent changes.
  • High volume of false positives and alerts, leading to operational overhead for security teams.
  • Limited out-of-the-box reporting and analytics, often requiring custom solutions or external tools.

Microsoft Defender for Endpoint

Use Cases and Deployment Scope

Scope of use case is the title, link file, RNK, and file. Malware

Pros

  • I get a good rest. Static file Detections of malware are updated quite often and are also quite effective. And overall has more.

Cons

  • So far, it has not been detecting the link. File. Malware for changes that we are facing where you buy separately from simple anti, let the link file malware problem.

Return on Investment

  • It's malware detection, so it didn't apply any objectively; it didn't really apply any bit objectively is anti-slideshare.

Usability

Offers Solid Protection Against Attacks at the Endpoints.

Use Cases and Deployment Scope

We use the Microsoft Defender for Endpoint to protect data at the endpoints. Helps to keep employees laptop, desktops, phones and other devices secure and protect against cyber threats. Offers a strong encryption scheme that helps to protect data organizational data from getting in wrong hands in-case of lost of a device.

Pros

  • Protects devices from cyber attacks ( Malware and Spyware)
  • Responding to threats in real-time.
  • Automates cyber threat protection and response.
  • Seamless integration with Microsoft ecosystem.
  • Offers reliable security monitoring.

Cons

  • Learning curve for advanced features.
  • False positive in occasional instances.

Return on Investment

  • Enhances security at the endpoints.
  • Helps to boast productivity by elimination of interruptions.
  • Enhances compliance and disaster recovery.

Usability

Other Software Used

Barracuda Backup, Microsoft 365

Microsoft Defender for Endpoint Review

Use Cases and Deployment Scope

We use it to monitor alerts and incidents, respond to them, gather data, and threat hunt.

Pros

  • Particularly well. It gives a clear picture when alerts come in. We’re able to dig deep into the process or file that’s generating the alert, so that’s very helpful.

Cons

  • Room for improvement: better whitelisting capabilities. That’s the number one thing I would love to have.

Return on Investment

  • Mostly poisitive.

Return on Investment

2000, we're supporting Windows.

Microsoft Defender for Endpoint

Use Cases and Deployment Scope

What I can divulge now is that we went from a 60,000 to a 100,000 employee environment, and as part of the acquisition of the new company, we were very worried about insider threats and what disgruntled employees could do. Therefore, it was something that we had to really up the ante in terms of its deployment to oversee internal and the enterprise security posture of the firm.

Pros

  • I think from a scalability perspective, it’s incredible. It fits very well with our Azure stack, and we’re constantly adopting more and more different Microsoft products. But I think the key thing is ease of use. Its scalability, and it’s just that, enterprise-wise and in terms of control, we can actually centralize it as well.

Cons

  • I think we’re quite satisfied with it at the moment in terms of its deployment. I can’t think of any enhancements. We’ll run an assessment soon, but no, nothing at the moment.

Return on Investment

  • Return on investment, we’re still yet to evaluate. I could honestly say it makes the board of directors sleep at night because it is a great tool, and the way we’ve explained it from a monetary perspective—it’s too early to say at the moment.

Usability

Return on Investment

So Windows, definitely, and Solaris installations, which is Linux as well. How many? We’re talking about maybe 60,000.

Microsoft Defender for Endpoint

Use Cases and Deployment Scope

We basically have it on every machine and every server. The business problem it addresses is scanning our network for detectable threats, outdated software, software exploits, and vulnerabilities, and then telling us we need to get them remediated.

Pros

  • I do like the alert system, how it's picking up on things and alerting us about it, and then giving us the recommendations on remediating that particular issue.

Cons

  • The only thing is sometimes, because Microsoft has so many platforms, it gets a little confusing, like am I in the security platform? Am I in Purview? Where am I at right now? Because there's so many sites that are kind of doing a lot of the same thing, and so that does get a little confusing from time to time, but outside of that, it's a pretty good product.

Return on Investment

  • We're a young company in the field of security, not a young company, but in this area, we are young, and it's been a good starting point for us to get our security system as a whole in place.

Usability

Return on Investment

It's about 130. Windows server.