Skip to main content
TrustRadius
Microsoft Defender for Endpoint

Microsoft Defender for Endpoint
Formerly Microsoft Defender ATP

Overview

What is Microsoft Defender for Endpoint?

Microsoft Defender for Endpoint (formerly Microsoft Defender ATP) is a holistic, cloud delivered endpoint security solution that includes risk-based vulnerability management and assessment, attack surface reduction, behavioral based and cloud-powered next generation protection, endpoint detection and response (EDR), automatic investigation…

Read more
Recent Reviews

Secure workstations with MDE

8 out of 10
November 03, 2023
Microsoft Defender for Endpoint offers exceptional threat insight and protection. Its KQL powered Advanced Hunting provides deep analysis. …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Popular Features

View all 7 features
  • Malware Detection (53)
    8.5
    85%
  • Infection Remediation (52)
    8.2
    82%
  • Anti-Exploit Technology (51)
    8.0
    80%
  • Centralized Management (52)
    7.9
    79%

Reviewer Pros & Cons

View all pros & cons
Return to navigation

Pricing

View all pricing

Academic

$2.50

On Premise
per user/per month

Standalone

$5.20

On Premise
per user/per month

Entry-level set up fee?

  • No setup fee

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services
Return to navigation

Product Demos

Microsoft Defender for Endpoint Overview

YouTube
Return to navigation

Features

Endpoint Security

Endpoint security software protects enterprise connected devices from malware and cyber attacks.

8.2
Avg 8.5
Return to navigation

Product Details

What is Microsoft Defender for Endpoint?

Presented as an epicenter for comprehensive endpoint security, Microsoft Defender for Endpoint helps users rapidly stop attacks, scale security resources, and evolve defenses across operating systems and network devices.

Rapidly stops threats: Protects against sophisticated threats such as ransomware and nation-state attacks.

Scales security: Puts time back in the hands of defenders to prioritize risks and elevate the organization's security posture.

Evolves the organization's defenses: Goes beyond endpoint silos and mature the organization's security based on a foundation for extended detection and response (XDR) and Zero Trust.

Microsoft Defender for Endpoint Features

Endpoint Security Features

  • Supported: Anti-Exploit Technology
  • Supported: Endpoint Detection and Response (EDR)
  • Supported: Centralized Management
  • Supported: Infection Remediation
  • Supported: Vulnerability Management
  • Supported: Malware Detection

Microsoft Defender for Endpoint Screenshots

Screenshot of blocked activitiesScreenshot of Detects & respondsScreenshot of discovers vulnerabilityScreenshot of Eliminates blind spotsScreenshot of Risk management

Microsoft Defender for Endpoint Video

Microsoft Defender for Endpoint

Microsoft Defender for Endpoint Competitors

Microsoft Defender for Endpoint Technical Details

Deployment TypesOn-premise
Operating SystemsWindows
Mobile ApplicationNo

Frequently Asked Questions

Microsoft Defender for Endpoint (formerly Microsoft Defender ATP) is a holistic, cloud delivered endpoint security solution that includes risk-based vulnerability management and assessment, attack surface reduction, behavioral based and cloud-powered next generation protection, endpoint detection and response (EDR), automatic investigation and remediation, managed hunting services, rich APIs, and unified security management.

CrowdStrike Falcon, Symantec Endpoint Security, and Sophos Intercept X are common alternatives for Microsoft Defender for Endpoint.

Reviewers rate Endpoint Detection and Response (EDR) and Malware Detection highest, with a score of 8.5.

The most common users of Microsoft Defender for Endpoint are from Enterprises (1,001+ employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(175)

Attribute Ratings

Reviews

(1-25 of 65)
Companies can't remove reviews or game the system. Here's why
Conrad Nyamache | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
  • Cloud Solutions
  • Scalability
  • Integration with Other Systems
  • Ease of Use
  • Other
It's ease of implementation especially in the initial setting up process and the awesome customer support we got from the technical team really made it stand out from others.
Score 7 out of 10
Vetted Review
Verified User
Incentivized
  • Cloud Solutions
  • Scalability
  • Integration with Other Systems
Before we chose to move forward with Microsoft Defender for Endpoint, we had three different platforms that were performing the tasks of vulnerability scanning, antivirus/antimalware and SIEM. Now, with Microsoft Defender for Endpoint, we've been able to integrate these into one platform and seamlessly integrate with other Microsoft security applications for even greater insight.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
  • Integration with Other Systems
Our biggest influence was selecting a product that works well with our current product portfolio and the ease of implementation. It has also been fairly easy to manage after getting past some of the initial setup tasks. Overall, this has been a lot easier to setup and use than any other endpoint protection software.
Yash Mudaliar | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
  • Cloud Solutions
  • Integration with Other Systems
  • Ease of Use
The depth and quality of logs provided by Microsoft Defender for Endpoint (especially for Windows endpoints) is exceptional and arguably the best in market. Due to this we have been getting very detailed activity timeline in incidents and an accurate software inventory in vulnerability management. While the onboarding process is a little complex, but it completely makes up for the fact that there are a wide array of actions that can be taken directly form the portal on the onboarded devices.
Score 7 out of 10
Vetted Review
Verified User
Incentivized
  • Cloud Solutions
  • Scalability
  • Integration with Other Systems
This is part of the M365 offerings that we bought, so it comes by default, as this can be an additional protection layers for us with no additional cost, it is something that we will consider in the future from economic stand point

As it is being offered as SaaS, there is no cost for deployment and it offers a great scalability for our organization
Score 8 out of 10
Vetted Review
Verified User
Incentivized
  • Cloud Solutions
  • Scalability
  • Integration with Other Systems
Our IT environment is basically based on Microsoft products. Hence, it was beneficial to use Microsoft Defender for Endpoint as the product for endpoint protection. It can easily get integrated with Microsoft Intune which was a big plus for us. Furthermore, being cloud based helped us in covering the remote devices also.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
  • Cloud Solutions
  • Scalability
Many security features, such as advanced threat detection, real-time response, vulnerability management, and compliance capabilities, are available with Microsoft Defender for Endpoint. It might be appealing to businesses looking for a complete endpoint security solution. My organizations already using Microsoft products, the familiarity of the interface and tools can make the transition to Microsoft Defender for Endpoint smoother. IT teams and end-users may find it easier to adapt to a solution that aligns with their existing knowledge.
Score 8 out of 10
Vetted Review
Verified User
  • Scalability
  • Integration with Other Systems
Microsoft Defender for Endpoint is a service that scales very well, be it in size or in different locations. The integration part is the biggest driver for choosing Defender for Endpoint, especially since the M365 platform is in use.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
  • Cloud Solutions
  • Scalability
  • Integration with Other Systems
Primarily, it's a cloud-native solution, leveraging the inherent Microsoft Defender within the Windows operating system. The process of connecting a device to the MDE portal is straightforward and uncomplicated. Additionally, unlike on-premises EDR solutions, it doesn't require a separate server to host the entire solution.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
  • Integration with Other Systems
  • Ease of Use
The seamless integration of Microsoft Defender for Endpoint with other Microsoft security products, such as Azure Defender and Microsoft Defender for 365, was a primary consideration. This integration created a unified security experience, enabling us to manage our security operations efficiently and cohesively. The ease of use also played a role in choosing it.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
  • Scalability
  • Integration with Other Systems
  • Ease of Use
Defender for Endpoint's capabilities in endpoint detection and response deliver exceptionally advanced, almost real-time attack detection, enabling swift and effective action. Security analysts can promptly prioritize alerts, gain a thorough understanding of the breach's extent, and take immediate actions to mitigate threats. Upon identifying a threat, the system generates alerts for analysts to assess. Alerts sharing common attack techniques or linked to the same attacker are amalgamated into a single entity known as an "incident." This amalgamation of alerts simplifies and streamlines the investigative and remediation process for analysts as they collaborate to tackle these threats.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
  • Cloud Solutions
  • Scalability
  • Integration with Other Systems
  • Ease of Use
We are a Microsoft house so it was not a hard decision. But, because we are so ingrained with Microsoft 365 it just made sense when we started talking about what we could do to improve our overall security stance and protect the organization as a whole.
Score 5 out of 10
Vetted Review
Verified User
Incentivized
  • Cloud Solutions
  • Scalability
  • Integration with Other Systems
  • Ease of Use
Reduction in Security Incidents: By effectively detecting and mitigating security threats, Microsoft Defender for Endpoint can lead to a reduction in security incidents, which can translate into cost savings associated with incident response, recovery, and potential legal consequences. Preventing Data Breaches: Avoiding data breaches can result in significant financial savings, as the costs of data breach notification, forensic investigations, regulatory fines, and damage to an organization's reputation can be substantial.Improved Productivity: Enhanced security can lead to increased employee productivity by reducing the downtime and disruptions caused by malware infections or other security incidents.
Bhuwan Chandra | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
  • Cloud Solutions
  • Integration with Other Systems
  • Ease of Use
Microsoft Defender for Endpoint provide IT hygiene , Gives visibility into enabled products on endpoints & also provide strong remote remediation .

Microsoft Defender for Endpoint assist the customer in Full endpoint event collection & collects log for further analysis for ATP & Sandbox. According Gartner magic Quadrant for EPP Microsoft Defender for Endpoint score high in ability to execute & forward learning organizations.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
  • Cloud Solutions
  • Scalability
  • Integration with Other Systems
  • Ease of Use
Seems like a repetition, but for me, the very plus of this solution and what influenced me to change and adopt this solution was the "one subscription for all the service I need." All the integration, the simplicity, one point of contact, and of course, some money less than other solutions.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
  • Cloud Solutions
  • Ease of Use
Two main factors:
  1. it is a Microsoft solution (it was an important factor considering other solutions that were part of the project).
  2. We made a pilot to better understand how it would be to deploy and manage the solution, and it did run very well. It gave us confidence to choose this solution.
Score 6 out of 10
Vetted Review
ResellerIncentivized
  • Cloud Solutions
  • Scalability
  • Integration with Other Systems
  • Ease of Use
Device Threat Analysis and Score: Microsoft Defender antivirus software collects underlying system data used for threat analysis and the device's Microsoft Security Score. This will provide your organization's security team with more meaningful information, such as recommendations and opportunities to improve your organization's security posture.
Return to navigation