Skip to main content
TrustRadius
Microsoft Defender XDR

Microsoft Defender XDR
Formerly Microsoft 365 Defender

Overview

What is Microsoft Defender XDR?

Microsoft 365 Defender combines SIEM and XDR capabilities for Microsoft 365 environments, encompassing threat detection, post-breach detection, automated investigation, and response for endpoints. Additionally, it protects cloud apps, emails and documents, and employee identities.

Read more
Recent Reviews

Microsoft Defender XDR

10 out of 10
February 06, 2024
Microsoft Defender XDR is mainly responsible for the detection and handling of Phishing related emails. Microsoft Defender XDR is also …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Reviewer Pros & Cons

View all pros & cons
Return to navigation

Pricing

View all pricing
N/A
Unavailable

What is Microsoft Defender XDR?

Microsoft 365 Defender combines SIEM and XDR capabilities for Microsoft 365 environments, encompassing threat detection, post-breach detection, automated investigation, and response for endpoints. Additionally, it protects cloud apps, emails and documents, and employee identities.

Entry-level set up fee?

  • No setup fee
For the latest information on pricing, visithttps://www.microsoft.com/en…

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Would you like us to let the vendor know that you want pricing?

26 people also want pricing

Alternatives Pricing

What is Kaspersky EDR Expert?

Kaspersky Endpoint Detection and Response (EDR) Expert provides endpoint protection, advanced detection, threat hunting and investigation capabilities and multiple response options in a single package. It is an EDR solution for IT security teams with more mature incident response processes,…

Return to navigation

Product Demos

Getting started with Microsoft 365 Defender

YouTube
Return to navigation

Product Details

What is Microsoft Defender XDR?

For SecOps, XDR with incident-level visibility across the kill chain for automatic disruption of sophisticated attacks and accelerated response across endpoints, identities, email, collaboration tools, cloud applications, and data.


Endpoints: Discovers and secures endpoint and network devices across a multiplatform enterprise.

Identities: Manages and secures hybrid identities and simplifies employee, partner, and customer access.

Cloud apps: Visibility, control, and threat detection across cloud services and apps.

Email and collaboration tools: Protects email and collaboration tools from advanced threats, such as phishing and business email compromise.

Microsoft Defender XDR (formerly Microsoft 365 Defender) combines SIEM and XDR capabilities for Microsoft 365 environments, encompassing threat detection, post-breach detection, automated investigation, and response for endpoints. Additionally, it protects cloud apps, emails and documents, and employee identities.

Microsoft Defender XDR Features

  • Supported: Endpoints: Discovers and secures endpoint and network devices across a multiplatform enterprise.
  • Supported: Identities: Manages and secures hybrid identities and simplifies employee, partner, and customer access.
  • Supported: Cloud Apps: Offers visibility, controls data, and detects threats across cloud services and apps.
  • Supported: Email & Collaboration tools: Protects email and collaboration tools from advanced threats, such as phishing and business email compromise.

Microsoft Defender XDR Screenshots

Screenshot of AH Advanced ModeScreenshot of AH Guided modeScreenshot of CD exampleScreenshot of CD Supported actions

Microsoft Defender XDR Technical Details

Operating SystemsUnspecified
Mobile ApplicationNo

Frequently Asked Questions

Microsoft 365 Defender combines SIEM and XDR capabilities for Microsoft 365 environments, encompassing threat detection, post-breach detection, automated investigation, and response for endpoints. Additionally, it protects cloud apps, emails and documents, and employee identities.

CrowdStrike Falcon, Sophos Intercept X, and Symantec Endpoint Security are common alternatives for Microsoft Defender XDR.

Reviewers rate Usability highest, with a score of 8.

The most common users of Microsoft Defender XDR are from Mid-sized Companies (51-1,000 employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(137)

Attribute Ratings

Reviews

(1-25 of 41)
Companies can't remove reviews or game the system. Here's why
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We used the MS XDR as this is a bundle that we bought when we subscribed to the M365 platform, so having it was a bonus as we stated earlier, but due to limitation on licenses in Sentinelone, having this is just a blessing for us, so we can reduce around 200 licenses and can utilize it for other users
Yash Mudaliar | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
The on-boarding and initial deployment is very much automated and has less technical overheads in comparison to the above products as per my experience. Apart from that, once organizations decide to move towards even one of the Microsoft security products, it will make more sense for them to employ Microsoft 365 Defender rather than any other XDR in the market.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
The Microsoft 365 Defender is a product that has a lot of advantages over other similar products. This is because Microsoft 365 Defender integrates seamlessly with both Microsoft 365 services, is capable of detecting threats in real time, and has the capability of automating incident response. This cybersecurity solution has unique features and a user-friendly design that organizations prefer.
Abdrhman Arar . | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
For the Identity Protection, Microsoft 365 Defender helps me to have fewer headaches from resetting passwords and securing the hacked account, it forces the security layers that help to achieve this solution.For the Endpoint, I have bought too many apps to secure endpoints but Microsoft 365 Defender for endpoint helps me to secure all endpoints while I'm sitting in my office with monitoring everything and fixing all issues with it.For the Data Loss Prevention, it helps me to achieve the best practices of securing confidential information and data and emails internal and external the enterprise For Cloud apps and Cloud Integration, I use it to secure all cloud app in Azure and AWS and Gcloud, it makes everything in one platform which make it easy for me to secure and investigete every issue.
Rudy Fulmer | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We use sophos endpoint protection and xg firewalls in conjunction with microsoft 365 defender. We dont believe defender is robust enough to be our only security solution but it works well as another line of defense from threats to our organization especially our ever growing microsoft 365 enviroments list of applications.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
beats cylance protect, crowstrike is solid but at a costly product
cannot use kapersky due to embargo
norton not good enough now
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We have used and find great value with competitors to Microsoft 365 Defender. Many of these services were utilized before customers began the total cloud shift that has been seen with certain industries. It is difficult to compare these products apples to apples. What I will say is that Microsoft has a steeper learning curve, and suffers from frequent enough rebranding and renaming of services, but it is often included in licensing that many companies need or wind up purchasing. Third party competitors come at an additional cost, but can remediate the burden of learning as they are typically user friendly in comparison.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
As already stated, the main advantage of Defender is being able to use a single console to manage it and all the other 365 applications. I can state that it provides a more effective protection than Bitdefender MDR and Trend Micro Apex One while I consider CrowdStrike on the same level.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We use Microsoft products and have a large group of users. It works easily with our system. There is a great deal of knowledge base out there, often a little overwhelming. But we feel it's the best tool for our network to use parallel to the rest of our back-end.
September 22, 2023

Security Measures

Score 8 out of 10
Vetted Review
Verified User
Incentivized
Firstly Microsoft 365 Defender offers effortless integration with other Microsoft solutions over the products evaluated. Compared to Microsoft 365 Defender the evaluated products should improve the integration and its web interfaces.
Few challenges were encountered when contacting support during the evaluation and service or support is considered to be the most important factor for any product to be procured.
Pricings of Kaspersky and ESET XDR solutions were much more higher compared to Microsoft 365 Defender.
One point where Microsoft needs to be improved is to improve their system learning capabilities, interface and support documentation.
September 22, 2023

Must buy to protect systems

Score 7 out of 10
Vetted Review
Verified User
Incentivized
Microsoft is a known leader in the cyber security space and the trust microsoft has is greater than any other product. The pricing though bit on the higher side , but it ensures a proper support with using the product which makes it more preferred in our organisation.it is fairly having a better documentation
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We selected the Microsoft 365 Defender as we using Microsoft environment and integration with Microsoft 365 Services. Also its provide single dashboard from where we can manage and monitor security across different services, Which streamlines our security operations and enhances visibility.
Score 10 out of 10
Vetted Review
Verified User
Incentivized
As compare to the FortiAuthenticator and FortiSIEM the Microsoft 365 Defender has been standout performer while handling, detecting the preventing the attacks. The Microsoft 365 Defender is very good in analyzing the critical event and detecting the attacks and it's scope before it happens. Also the remediation steps performed by the Microsoft 365 Defender is far more better than expected.
Itumeleng Thekiso | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
First and foremost using a like for like product linked to its vendor is always going to be a smooth process i.e. Office 365 and Microsoft 365 Defender it will always work in tandem because of its integration, stacking up Mimecast Integrated Cloud Email Security with Microsoft 365 Defender is a tough one as both these tools are good in their own regard but I will always choose Microsoft 365 Defender because it really does provide an integrated system to Office 365.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
365 Defender works with all 365 applications to protect the user while using them from any potential threats. This is one of the main reasons why Microsoft is a business standard. They provide everything a business needs in one place, one license.
We chose 365 Defender because our organisation uses all 365 applications, it made sense to use their security platform because it would work best with the applications they built.
Return to navigation