Skip to main content
TrustRadius
Microsoft Defender XDR

Microsoft Defender XDR
Formerly Microsoft 365 Defender

Overview

What is Microsoft Defender XDR?

Microsoft 365 Defender combines SIEM and XDR capabilities for Microsoft 365 environments, encompassing threat detection, post-breach detection, automated investigation, and response for endpoints. Additionally, it protects cloud apps, emails and documents, and employee identities.

Read more
Recent Reviews

Microsoft Defender XDR

10 out of 10
February 06, 2024
Microsoft Defender XDR is mainly responsible for the detection and handling of Phishing related emails. Microsoft Defender XDR is also …
Continue reading
Read all reviews

Awards

Products that are considered exceptional by their customers based on a variety of criteria win TrustRadius awards. Learn more about the types of TrustRadius awards to make the best purchase decision. More about TrustRadius Awards

Reviewer Pros & Cons

View all pros & cons
Return to navigation

Pricing

View all pricing
N/A
Unavailable

What is Microsoft Defender XDR?

Microsoft 365 Defender combines SIEM and XDR capabilities for Microsoft 365 environments, encompassing threat detection, post-breach detection, automated investigation, and response for endpoints. Additionally, it protects cloud apps, emails and documents, and employee identities.

Entry-level set up fee?

  • No setup fee
For the latest information on pricing, visithttps://www.microsoft.com/en…

Offerings

  • Free Trial
  • Free/Freemium Version
  • Premium Consulting/Integration Services

Would you like us to let the vendor know that you want pricing?

24 people also want pricing

Alternatives Pricing

What is Kaspersky EDR Expert?

Kaspersky Endpoint Detection and Response (EDR) Expert provides endpoint protection, advanced detection, threat hunting and investigation capabilities and multiple response options in a single package. It is an EDR solution for IT security teams with more mature incident response processes,…

Return to navigation

Product Demos

Getting started with Microsoft 365 Defender

YouTube
Return to navigation

Product Details

What is Microsoft Defender XDR?

For SecOps, XDR with incident-level visibility across the kill chain for automatic disruption of sophisticated attacks and accelerated response across endpoints, identities, email, collaboration tools, cloud applications, and data.


Endpoints: Discovers and secures endpoint and network devices across a multiplatform enterprise.

Identities: Manages and secures hybrid identities and simplifies employee, partner, and customer access.

Cloud apps: Visibility, control, and threat detection across cloud services and apps.

Email and collaboration tools: Protects email and collaboration tools from advanced threats, such as phishing and business email compromise.

Microsoft Defender XDR (formerly Microsoft 365 Defender) combines SIEM and XDR capabilities for Microsoft 365 environments, encompassing threat detection, post-breach detection, automated investigation, and response for endpoints. Additionally, it protects cloud apps, emails and documents, and employee identities.

Microsoft Defender XDR Features

  • Supported: Endpoints: Discovers and secures endpoint and network devices across a multiplatform enterprise.
  • Supported: Identities: Manages and secures hybrid identities and simplifies employee, partner, and customer access.
  • Supported: Cloud Apps: Offers visibility, controls data, and detects threats across cloud services and apps.
  • Supported: Email & Collaboration tools: Protects email and collaboration tools from advanced threats, such as phishing and business email compromise.

Microsoft Defender XDR Screenshots

Screenshot of AH Advanced ModeScreenshot of AH Guided modeScreenshot of CD exampleScreenshot of CD Supported actions

Microsoft Defender XDR Technical Details

Operating SystemsUnspecified
Mobile ApplicationNo

Frequently Asked Questions

Microsoft 365 Defender combines SIEM and XDR capabilities for Microsoft 365 environments, encompassing threat detection, post-breach detection, automated investigation, and response for endpoints. Additionally, it protects cloud apps, emails and documents, and employee identities.

CrowdStrike Falcon, Sophos Intercept X, and Symantec Endpoint Security are common alternatives for Microsoft Defender XDR.

Reviewers rate Usability highest, with a score of 8.

The most common users of Microsoft Defender XDR are from Mid-sized Companies (51-1,000 employees).
Return to navigation

Comparisons

View all alternatives
Return to navigation

Reviews and Ratings

(137)

Attribute Ratings

Reviews

(1-25 of 59)
Companies can't remove reviews or game the system. Here's why
Score 9 out of 10
Vetted Review
Verified User
It offers secure monitoring and very quick response and alarm gateway which helps us protect our office 365 and azure cloud. And the AI driven threat detection algorithm allows for customized automated reaction and action capabilities so we don't need to supervise it anymore. It also includes very useful and powerful features such as email screening, malware detection and url filtering which altogether makes it a very powerful security solution that offers comprehensive protection and is easy to use.
Score 9 out of 10
Vetted Review
Verified User
Microsoft Defender XDR protects us from several threats like zero day attacks and our overall system, our emails and apps. And all of this is possible due to it's threat intelligence and real time scanning in the background using. Also after scanning, all the information is showed on the dashboard and you can also set custom alerts to notify you instantly if any threat is detected. Overall it's a great security solution for your cloud infrastructure and on premise devices and it is highly recommended by me.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
Microsoft Defender XDR helps us to swiftly detect incoming messages for phishing and make sure attachments are virus or malware free and it analyses them and reports any threats to our system. Also software implementation and integration is easy with its simple installation and thorough documentation plus their good support. Finally it protects our domains and both local and cloud identities.
John Drebin | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
This most reliable security system prevents organizations from malware practices that can negatively affect confidential data. It detects viruses contained in URLs and email attachments. It has blocked many targeted attacks on private data in the enterprise. It has saved costs on security deployments and enhanced safe collaboration among teams.
Abdul Ayub | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
Incentivized
Microsoft Defender XDR integrated with Microsoft 365 offers comprehensive solution for online cyber attacks and network security. With the real time monitoring and evaluation of security level our data is more secure while dealing with multiple software and clients. With the expansion of services across all sub apps like Teams, Microsoft Excel and word data can be shared without any worry and risk.
February 06, 2024

Microsoft Defender XDR

Score 10 out of 10
Vetted Review
Verified User
Microsoft Defender XDR is mainly responsible for the detection and handling of Phishing related emails. Microsoft Defender XDR is also responsible for the detection of anomalous user logins. We basically use this tool for the monitoring of user activities. It is also useful in identifying registered devices for a user and is a big help during our investigations.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
My money is on Microsoft Defender XDR when it comes to recommending it to others. It stays up to date because to the compatibility with other Microsoft products and the regular upgrades. Naturally there may be specialized materials required for optimal functioning as is the case with anything. Moreover firms seeking contemporary threat security should find it to be a great choice.
Shubham Jurail | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
Incentivized
We are using Microsoft Defender XDR to secure our infrastructure services and system from various viruses, malware, and various cyber-attacks. It has unique features, it is very simple to use in comparison to other security tools, and it can easily integrate with other products. As this is cloud, there is no issue for scaling, deploying, and other aspects of administration.
Mario Urrutia | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Microsoft Defender XDR is a crucial part of your overall enterprise instance-wide proactive security and defense strategy. The multiple integrated options add layers of protection that prevent many potential problems with the integrity of assets, accounts and, above all, the valuable data managed within the resources that Microsoft Defender XDR protects. We are still in the learning and integration process, including it in more licensing.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
Personally, I recommend Microsoft Defender XDR. Microsoft Defender XDR had exceptional threat detection and response. Defender XDR leads the security simplification movement with its powerful AI, ability to integrate with other Microsoft security systems, and automation of routine tasks. Real-time functions are simple. Because it prevents viruses so well, you won't notice it running in the background. Nearly all risks are gone.
Score 8 out of 10
Vetted Review
ResellerIncentivized
we as a businesses leverage Microsoft Defender XDR (Extended Detection and Response) as a pivotal component of their cybersecurity strategy. This comprehensive platform plays a crucial role in fortifying defenses against a myriad of cyber threats. Employing cutting-edge technologies like advanced analytics and machine learning, Defender XDR actively monitors and analyzes activities across endpoints, networks, and cloud environments.Its primary function is early threat detection, identifying anomalies, malware, and advanced persistent threats that may pose risks to organizational security. The system ensures a proactive stance, enabling rapid responses to potential incidents. This is particularly significant in the context of British businesses adhering to stringent data protection regulations such as the General Data Protection Regulation (GDPR). Defender XDR assists in maintaining compliance by securing sensitive data and providing tools for effective incident response.The centralized dashboard serves as a command center, offering real-time insights into security incidents. This feature aids security professionals in conducting efficient investigations, thereby reducing the dwell time of threats within the network. Integration with other Microsoft security tools creates a cohesive defense, enhancing the overall cybersecurity posture of British businesses. Ultimately, Microsoft Defender XDR stands as a vital ally in the dynamic landscape of cybersecurity, enabling organizations to stay ahead of evolving threats and safeguard their digital assets.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
As a young start up, our end users are not the most advanced in term of Security and since we bought 200 Licenses for O365, getting the defender is just something we have to do, as it provides layers of protection for our users from the popular phishing attempts, Protecting the other tools within our suite like one drive etc, not to mention the scary malware attacks. For other organization this might seems to be small, but for a start up where every dollar counts, this is a big matter for us, combining it with Hybrid working mode and a not too advanced users in term of security, this is just a must for us
Apeksha Jain | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User
In today's world, everything is on the internet and every data we record goes to our system in the form of digital information. In our hospital too we are flooded with information like patient biodata, medicine prescriptions, treatment procedures, doctors, and nurses, and every small piece of information is being recorded as digital information. So we have so much information it needs security and Microsoft 365 Defender is a robust security protection system for our digital information. It helps in blocking various malicious emails, which can corrupt our system, and data breaches can occur. It helps prevent sensitive information keeping us safe from Phishing. It's a very robust and useful tool for security in an organization.
Yash Mudaliar | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We are not only managing Microsoft 365 Defender for our clients but also using it for our organization as an XDR (eXtended Detection and Response) tool for all our users. It does a fantastic job of correlating identities, network, endpoints, applications across the organization to present relevant information in incidents and reports. It very much acts as a single pane of glass providing a holistic view of security insights across the various domains.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
Microsoft 365 Defender assists developers in finding and addressing coding vulnerabilities, a vulnerability scanner built into Microsoft Defender for endpoint search code sources and find known vulnerabilities. prior ro Microsoft 365 Defender for cloud Apps can also be used to check it. It gives developers access o threat intelligence, which they may use to comprehend the most recent defenses against them. I have utilized Microsoft 365 Defender, for stopping known phishing URLs from appearing in the applications. Before deploying code to a cloud environment , me and my team utilizes it o check it for vulnerabilities , by doing this we are sure that our code is safe before releasing I on the internet.
Score 8 out of 10
Vetted Review
Verified User
Microsoft 365 Defender is the complete solution for our cloud infrastructure. It is used as a multi-layered security solution that protects our mail platform, identities, applications, and data all in one platform. The zero-trust approach is built upon this solution in combination with conditional access policies. The Defender portal is the main portal for security, research, and mitigation of incidents.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
I use Microsoft 365 Defender to boost cybersecurity in our company. This software helps protect sensitive financial data, spot threats in real-time, and take proactive steps to manage incidents. The easy-to-use interface allows me to investigate security incidents, adhere to security policies, and safeguard against data loss. Microsoft 365 Defender works well with other tools to create a strong security system that meets our needs.
Abdrhman Arar . | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
Microsoft 365 Defender is helpful in investigating and detecting issues and malicious in our endpoints, office 365 emails, identity, cloud apps, and all the environment. I use it with the best practices to achieve the main and big goal of securing all Office 365 emails, endpoints, identity, cloud apps, DLP.
Rudy Fulmer | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We use it for threat detection within our microsoft 365 enviroment to help secure our email, sharepoint data, teams etc. It is very useful in that reguard as it gives us realtime alerts on end users devices that may have been compromised. It is nice to be able to lock down various parts of 365 as well.
Score 9 out of 10
Vetted Review
Verified User
Incentivized
we use this as the front line of defense and then use Huntress as the add on to get the optimal settings and config and reporting to give better insight into what is going on and how to remediate the issues. Microsoft 365 Defender has come a long way and certainly at this point a great firstline
Score 9 out of 10
Vetted Review
Verified User
Incentivized
365 Defender has come to mean much more than traditional Microsoft Defender did when it was a pseudo antivirus. As an IT provider, we leverage Defender for the any Office 365 cyber security customer to prevent, detect, and remediate threats to their cloud email platform. Defender folds into our MSSP offering as a layer of both proactive and reactive approaches. It is intelligent and always shifting, which can be both an asset and a challenge.
Score 8 out of 10
Vetted Review
Verified User
Incentivized
We currently use Microsoft 365 to protect all the clients deployed across our company. Since we use lots of Microsot products, having also the security features integrated into the 365 portal is very convenient cause we don't need to access various independent consoles to manage our infrastructure.
In addition, since Defender is obviously fully integrated with the OS, it provides unique funcionalities that aren't available in other third-party products.
Anirudh Srinivas | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User
Incentivized
With varying tools across different vendors and on systems that utilize the Windows operating system , often its difficult to patch them separately always and also manage them with different consoles. The tool choice was to have a unified platform that supports both the OS and other updates.
Jordan Dotson | TrustRadius Reviewer
Score 10 out of 10
Vetted Review
Verified User
Incentivized
This is the most efficient enterprise prevention suite that protects confidential data from leaking. It sends security alerts to the IT team when there are potential threats that can affect workflows. It has powerful data detection system that can detect ransomware attacks that can destroy data. The platform has customizable endpoint security models that can be integrated easily with other applications.
September 23, 2023

Good for small environment.

Score 9 out of 10
Vetted Review
Verified User
Incentivized
We use Microsoft 365 Defender for mobile devices, like laptops and Home-Office users.
It's using a centralized configuration and management platform, so we can protect all devices.

We can manage BOD from our coworkers, that no infected or unprotected devices can connect to our network.
Return to navigation