Skip to main content
TrustRadius
Microsoft Defender XDR

Microsoft Defender XDR
Formerly Microsoft 365 Defender

Overview

What is Microsoft Defender XDR?

Microsoft 365 Defender combines SIEM and XDR capabilities for Microsoft 365 environments, encompassing threat detection, post-breach detection, automated investigation, and response for endpoints. Additionally, it protects cloud apps, emails and documents, and employee identities.

Read more
Recent Reviews

Microsoft Defender XDR

10 out of 10
February 06, 2024
Microsoft Defender XDR is mainly responsible for the detection and handling of Phishing related emails. Microsoft Defender XDR is also …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Reviewer Pros & Cons

View all pros & cons
Return to navigation

Pricing

View all pricing
N/A
Unavailable

What is Microsoft Defender XDR?

Microsoft 365 Defender combines SIEM and XDR capabilities for Microsoft 365 environments, encompassing threat detection, post-breach detection, automated investigation, and response for endpoints. Additionally, it protects cloud apps, emails and documents, and employee identities.

Entry-level set up fee?

  • No setup fee
For the latest information on pricing, visithttps://www.microsoft.com/en…

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Would you like us to let the vendor know that you want pricing?

24 people also want pricing

Alternatives Pricing

What is Kaspersky EDR Expert?

Kaspersky Endpoint Detection and Response (EDR) Expert provides endpoint protection, advanced detection, threat hunting and investigation capabilities and multiple response options in a single package. It is an EDR solution for IT security teams with more mature incident response processes,…

Return to navigation

Product Demos

Getting started with Microsoft 365 Defender

YouTube
Return to navigation

Product Details

What is Microsoft Defender XDR?

For SecOps, XDR with incident-level visibility across the kill chain for automatic disruption of sophisticated attacks and accelerated response across endpoints, identities, email, collaboration tools, cloud applications, and data.


Endpoints: Discovers and secures endpoint and network devices across a multiplatform enterprise.

Identities: Manages and secures hybrid identities and simplifies employee, partner, and customer access.

Cloud apps: Visibility, control, and threat detection across cloud services and apps.

Email and collaboration tools: Protects email and collaboration tools from advanced threats, such as phishing and business email compromise.

Microsoft Defender XDR (formerly Microsoft 365 Defender) combines SIEM and XDR capabilities for Microsoft 365 environments, encompassing threat detection, post-breach detection, automated investigation, and response for endpoints. Additionally, it protects cloud apps, emails and documents, and employee identities.

Microsoft Defender XDR Features

  • Supported: Endpoints: Discovers and secures endpoint and network devices across a multiplatform enterprise.
  • Supported: Identities: Manages and secures hybrid identities and simplifies employee, partner, and customer access.
  • Supported: Cloud Apps: Offers visibility, controls data, and detects threats across cloud services and apps.
  • Supported: Email & Collaboration tools: Protects email and collaboration tools from advanced threats, such as phishing and business email compromise.

Microsoft Defender XDR Screenshots

Screenshot of AH Advanced ModeScreenshot of AH Guided modeScreenshot of CD exampleScreenshot of CD Supported actions

Microsoft Defender XDR Technical Details

Operating SystemsUnspecified
Mobile ApplicationNo

Frequently Asked Questions

Microsoft 365 Defender combines SIEM and XDR capabilities for Microsoft 365 environments, encompassing threat detection, post-breach detection, automated investigation, and response for endpoints. Additionally, it protects cloud apps, emails and documents, and employee identities.

CrowdStrike Falcon, Sophos Intercept X, and Symantec Endpoint Security are common alternatives for Microsoft Defender XDR.

Reviewers rate Usability highest, with a score of 8.

The most common users of Microsoft Defender XDR are from Mid-sized Companies (51-1,000 employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(137)

Attribute Ratings

Reviews

(1-1 of 1)
Companies can't remove reviews or game the system. Here's why
Abdrhman Arar . | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Microsoft 365 Defender is helpful in investigating and detecting issues and malicious in our endpoints, office 365 emails, identity, cloud apps, and all the environment. I use it with the best practices to achieve the main and big goal of securing all Office 365 emails, endpoints, identity, cloud apps, DLP.
  • Securing Emails
  • Secure and detect malicious in Endpoints
  • help force/enforce access and the Identity Protection
  • securing our Cloud Apps
  • it's amazing for the Data Loss Prevention (DLP)
  • Amazing XDR
  • Good integuration with all cloud proveders and secure the servers and resources
Microsoft 365 Defender is the best for securing your Office 365 emails and policies and it's better than any anti-virus app for the endpoints, also for Cloud apps you can secure all the apps, and the most I like most is the Identity Protection which makes you feel better with less headache from securing all of your employee's identity, also the Data loss protection with the labeling feature that's the best feature for secure your confidential data and emails that send internal and external your enterprise.
  • For the Identity Protection, Microsoft 365 Defender helps me to have fewer headaches from resetting passwords and securing the hacked account, it forces the security layers that help to achieve this solution.
  • For the Endpoint, I have bought too many apps to secure endpoints but Microsoft 365 Defender for endpoint helps me to secure all endpoints while I'm sitting in my office with monitoring everything and fixing all issues with it.
  • For the Data Loss Prevention, it helps me to achieve the best practices of securing confidential information and data and emails internal and external the enterprise
  • For Cloud apps and Cloud Integration, I use it to secure all cloud app in Azure and AWS and Gcloud, it makes everything in one platform which make it easy for me to secure and investigete every issue.
In the Office 365 emails, there are too many emails malicious, phishing, and malware that come to all employee's mailboxes and collaboration tools (Sharepoint, Onedrive) some employees send files and make folders with public permission for everyone For endpoints, the anti-virus apps keep close apps and stop files and make the endpoint resource so heavy to load
In the Office 365 emails, it help me to fix the emails malicious, phishing and malware by the Threat policies with the anti-malware/phishing/anti-spam/safe attachments/safe links For the collaboration tools (Sharepoint, Onedrive) it helps me to prevent any unauthorized users to access anything in the platform For Endpoint it helps me to secure the endpoint with less resource usage and in silently mode wich make it easy to investigate and remediate every thing in the endpoint.
It is amazing when you get an issue on anything and have a way to fix it with Microsoft 365 Defender
it is easy to configure, you just need to be patient and read everything before you make any selection, just to make it will from the first time.
For the Identity Protection, Microsoft 365 Defender helps me to have fewer headaches from resetting passwords and securing the hacked account, it forces the security layers that help to achieve this solution.For the Endpoint, I have bought too many apps to secure endpoints but Microsoft 365 Defender for endpoint helps me to secure all endpoints while I'm sitting in my office with monitoring everything and fixing all issues with it.For the Data Loss Prevention, it helps me to achieve the best practices of securing confidential information and data and emails internal and external the enterprise For Cloud apps and Cloud Integration, I use it to secure all cloud app in Azure and AWS and Gcloud, it makes everything in one platform which make it easy for me to secure and investigete every issue.
  • Online Training
  • In-Person Training
  • No Training
Good and hard to find someonme who can explain everything for you beside Microsoft they provide you everything you need.
Microsoft Provides a good training for the Microsoft 365 Defender and has a good learning paths to learn and take the exams and get your Certifications.
The platform itself is easy.
Microsoft Support is really good in calls and uptime availability and they are helpful in understanding and fixing issues and reporting the bugs, also the first line support is amazing in fixing bugs and releasing the new patches.
I did before and I get a 24h support calls
No
Yes they did, sometimes the support agent keep email me and calling me with all updates in my issue and care to fix it.
Return to navigation