Microsoft Defender for Endpoint Review
April 27, 2022

Microsoft Defender for Endpoint Review

Ali Marandi | TrustRadius Reviewer
Score 9 out of 10
Vetted Review
Verified User

Overall Satisfaction with Microsoft Defender for Endpoint (formerly Microsoft Defender ATP)

My company utilizes Defender for Endpoint across all end point devices, including Windows and Linux servers. For me, Defender's capabilities are above any other AV tool I previously used. Some of the main benefits for us are:
  • Cloud Console
  • Cloud based updates
  • Live protection
Additionally, we use the EDR capability extensively. It has made life easer for our SOC team.
  • AV/Malware protection
  • Vulnerability Management
  • End Point Detection and Response (EDR)
  • Onboarding devices
  • Device configuration can be challenging
  • In order to use this product to its full capabilities, Intune will be required
  • EDR
  • Vulnerability Management
  • AV/Malware protection
  • Savings over previous vendor
  • ease of administration
  • increased SOC SLA
Defender works better for my org. This may depend on your ecosystem, however for me, Defender is a clear winner. I like Defender's ability to utilize multiple sensors and data points to detect possible breaches. I like the built-in EDR functionality. I do not need to purchase a separate EDR software anymore. I really like the vulnerability management. it has enabled our SOC team to view multiple security-related sensors from a single portal.

Do you think Microsoft Defender for Endpoint delivers good value for the price?

Yes

Are you happy with Microsoft Defender for Endpoint's feature set?

Yes

Did Microsoft Defender for Endpoint live up to sales and marketing promises?

Yes

Did implementation of Microsoft Defender for Endpoint go as expected?

Yes

Would you buy Microsoft Defender for Endpoint again?

Yes

Tenable.io, Microsoft Sentinel (formerly Azure Sentinel), Microsoft Defender for Identity (formerly Azure ATP)
Live Protection works well, it almost renders scheduled scans pointless.
Vulnerability management is a nice feature. It allows for vulnerabilities to be factored in for an overall exposure score.
Secure Score .
We utilize EDR as well. It makes easier for our Incident Response team to built a timeline. We're using Defender more when it comes to IR.

Microsoft Defender for Endpoint Feature Ratings

Anti-Exploit Technology
9
Endpoint Detection and Response (EDR)
9
Centralized Management
9
Hybrid Deployment Support
9
Infection Remediation
9
Vulnerability Management
9
Malware Detection
9