Microsoft Defender for Endpoint-Best EDR Solution
September 25, 2023

Microsoft Defender for Endpoint-Best EDR Solution

Bhuwan Chandra | TrustRadius Reviewer
Score 8 out of 10
Vetted Review
Verified User

Overall Satisfaction with Microsoft Defender for Endpoint

Microsoft Defender for Endpoint gives us unique opportunity to more tightly integrate into the OS . Cloud Based Light-weight agent, powered by behavioral sensors. We were looking Intelligence Security Graph to integrate detection with other Microsoft products, to track back the response the attack. Microsoft threat hunting service is integrate with Microsoft Defender for Endpoint product. Microsoft also provide a separate per user service where customers can directly interact with threat hunting experts.
  • Microsoft Defender for Endpoint helps customers to more tightly integrate into the OS
  • ATP integrate with their cloud based sandbox for malware analysis
  • Microsoft Defender for Endpoint Antivirus provide ML based scanning
  • Mac & Linux EDR visibility is weak spot for Microsoft Defender for Endpoint
  • ATP does not have malware search functionality
  • ATP includes dashboards for specific threats but not actor attributions
  • Microsoft Defender for Endpoint gives opportunity to more tightly integrate with the OS , Like Windows 10, Mac & Linux
  • I think pricing is confusing & ATP is expensive specially for Customers who are not completely brought into the Microsoft Ecosystems, standalone Defender ATP is 60$ per year
  • In my experience, Microsoft conflate paid & free features which confuses the customers and their bundles structure causes the customers to buy unwanted products & features.
  • Cloud Solutions
  • Integration with Other Systems
  • Ease of Use
Microsoft Defender for Endpoint provide IT hygiene , Gives visibility into enabled products on endpoints & also provide strong remote remediation .

Microsoft Defender for Endpoint assist the customer in Full endpoint event collection & collects log for further analysis for ATP & Sandbox. According Gartner magic Quadrant for EPP Microsoft Defender for Endpoint score high in ability to execute & forward learning organizations.
Microsoft Defender for Endpoint-Microsoft's EPP and EDR offering primarily built into Windows 10 but has been ported to other operating systems such as Mac & Linux , For Mac they use Bitdefender as OEM & Linux for AV engine. We also use Threat experts for Microsoft's threat hunting services, which included in Microsoft Defender for Endpoint cost, while Threat expert on demand is paid service.
we were using 100 enable endpoints for Microsoft Defender for Endpoint .Mac os was 6, & Linux were 21 .
CrowdStrike Falcon EDR is one the Best solution available in Market ,However, I think they are lack in Threat visibility and Vulnerability assessment& Management for application versions & configurations .

Do you think Microsoft Defender for Endpoint delivers good value for the price?

Yes

Are you happy with Microsoft Defender for Endpoint's feature set?

Yes

Did Microsoft Defender for Endpoint live up to sales and marketing promises?

Yes

Did implementation of Microsoft Defender for Endpoint go as expected?

Yes

Would you buy Microsoft Defender for Endpoint again?

Yes

Microsoft Defender for Endpoint provide Threats & Vulnerability management analyzes risk for applications versions & configurations . Lives response provides strong remediation and also uses their Intelligent Security graph for ATP data. Threats Service mostly uses Hunter Trained AI .
Microsoft Defender for Endpoint gives visibility on enable devices on endpoints but lacks visibility of unmanaged devices in the network. Customers can configure device controls via Intune but it is limited to windows 10 only.

Microsoft Defender for Endpoint Feature Ratings

Anti-Exploit Technology
7
Endpoint Detection and Response (EDR)
8
Centralized Management
5
Infection Remediation
8
Vulnerability Management
9
Malware Detection
9