TrustRadius: an HG Insights company

Microsoft Defender XDR

Score8.7 out of 10

185 Reviews and Ratings

What is Microsoft Defender XDR?

Microsoft 365 Defender combines SIEM and XDR capabilities for Microsoft 365 environments, encompassing threat detection, post-breach detection, automated investigation, and response for endpoints. Additionally, it protects cloud apps, emails and documents, and employee identities.

Read more details.

Media

Screenshot of AH Advanced Mode
Screenshot of AH Guided mode
Screenshot of CD example
Screenshot of CD Supported actions

1 / 4

Screenshot of AH Advanced Mode

Who Buys & Uses Microsoft Defender XDR

Pros

  • Unified platform for comprehensive threat protection across endpoints, identities, email, and cloud applications.
  • Seamless integration with the broader Microsoft ecosystem for simplified security management.
  • Robust automated response and remediation capabilities for rapid incident handling.

Cons

  • Complex user interface and navigation, particularly for new users and multi-tenant management.
  • Limited integration and support for non-Microsoft ecosystems and third-party tools.
  • High volume of low-essential alerts, contributing to alert noise and clutter.

Microsoft Defender XDR

Use Cases and Deployment Scope

We use Microsoft Defender XDR to provide centralized threat detection and response across endpoints, identities, email and Microsoft 365 services. It helps us protect against phishing, malware, ransomware, account compromise and other similar threats. It's been very effective for monitoring and securing corporate endpoints, user accounts, mailboxes and cloud services.

Our IT team use it for continuous threat detection, incident investigation and remediation primarily.

Pros

  • Phishing and email threat protection - It gives us good visibility into who received a message, who interacted with it, and allows us to remove malicious emails from mailboxes quickly if needed.
  • Endpoint Security and investigation - we can see what processes are running, investigate suspicious activity, and quickly determine whether a device has been impacted by malware or other threats.
  • Identity Protection - by identifying unusual sign-in activity and other behavior that could indicate an account has been compromised, it makes it far easier to spot and isolate before it becomes a bigger issue.

Cons

  • Feature Distribution - Microsoft has been consolidating their security tools, but features are often accessed through different admin portals which can be frustrating as an administrator.
  • Licensing Complexity - Understanding which license is needed for specific security features can be challenging, particularly for organizations like ours with mixed licensing models.
  • False Positives - Initial tuning is often required to reduce the number of false positives, which can initially overshadow genuine threats that the security team need to be aware of.

Return on Investment

  • Faster threat detection and response
  • Improved operational efficiency (by consolidating multiple security functions into one platform and automating tasks)
  • Reduced investigation time

Usability

Other Software Used

Microsoft 365, Bitdefender GravityZone, Microsoft Purview eDiscovery, Microsoft Defender for Identity, Microsoft Defender for Cloud Apps, Exclaimer, WordPress

Microsoft Defender XDR Review

Use Cases and Deployment Scope

It helps us manage each device, be able to detect malicious activity before it happens, and prevent it. We could create rules to stop things from happening beforehand.

Pros

  • Good at reporting when it needs to.

Cons

  • There's a lot of false positives here and there. Maybe an easier way to suppress false alerts. Much easier.

Return on Investment

  • Instead of paying for two products for XDR, paying for one, just pay a Microsoft E5 license for security, and that's it.
  • It has reduced investigation time significantly. Before, it was all a manual process, whereas this one is giving you the alerts instantly.

Usability

Microsoft Defender XDR Review

Use Cases and Deployment Scope

It's part of our security suite to help with our compliance and detect threats. It's part of our IT security solution.

Pros

  • It integrates well with all the other Microsoft tools, as we use Outlook. It integrates really well.

Cons

  • Maybe just some UI improvements and not having to use Microsoft Graph for information. If we can do that through Houli, that would be nice.

Return on Investment

  • It catches threats, which is great. And it has a lot of true positives.

Usability

Alternatives Considered

CrowdStrike Falcon

Defender XDR our go to choice to secure Microsoft ecosystem

Use Cases and Deployment Scope

Our organization utilizes Microsoft Defender XDR to enhance security of our cloud and onpremises environments. The product secures our endpoints, identeties, productivity products like Exchange, Teams and Sharepoint and also other cloud applications. Product is one of the most important layers of security for out IT team. The product is deployed on all of our several hundred endoints and it secure several thousand identities.

Pros

  • Unified visibility in one tool
  • Automated attack distribution
  • Threat intelligence

Cons

  • For non-Windows devices features are more limited and would need some work
  • Sometimes there is alert noise
  • UI is somewhat complex as the products scope is large

Return on Investment

  • Defender has improved our response times against security threats
  • Defender has improved our insights to our enviroment and allowed us to proactively improve our security posture
  • Automatic response to threats has made our enviroment more secure

Usability

Alternatives Considered

Symantec Endpoint Security

Other Software Used

Microsoft 365 Copilot, ChatGPT

Microsoft Defender XDR Unified Security automated response and ROI in action.

Use Cases and Deployment Scope

We use Microsoft Defender XDR to monitor for cyber threats, increase our response time to cyber events and tie into Microsoft Purview for insider risk management and data loss prevention. We can investigate and remediate threats from a single portal and Microsoft Defender XDR integrates perfectly with Purrview for insider risk and adaptive DLP policies.

Pros

  • Anti-phishing workflows
  • Threat and vulnerability scanning and detection
  • Insider risk detection and policy enforcement

Cons

  • The security portal is busy and can be difficult to navigate
  • Licensing is spread across multiple plans.
  • Struggles with non-Microsoft ecosystems like Linux or other SIEM tools besides Sentinel

Return on Investment

  • Automated remediation reduced manual workloads and accelerated our response time by 80%
  • Lowered our breach likelihood by 20%
  • Lowered downtime by 50%

Usability

Alternatives Considered

CrowdStrike Falcon and Cortex Xpanse by Palo Alto Networks

Other Software Used

CrowdStrike Falcon, Microsoft Sentinel, Microsoft 365 Copilot, Microsoft Security Copilot