What I like best about Microsoft Defender for Endpoint is the depth of integration with the Microsoft security ecosystem. It gives strong visibility across endpoints, ties alerts into Microsoft Sentinel and Defender XDR, and makes investigation much easier by correlating device, user, identity, and email-related signals. The automated investigation and response features are also valuable because they help reduce manual triage effort and speed up containment. Review collected by and hosted on G2.com.
What I dislike about Microsoft Defender for Endpoint is that it can be complex to configure and tune properly, especially in larger or more mature environments. Some alerts can require careful suppression or tuning to avoid noise, and the portal experience can feel fragmented because related information is sometimes spread across multiple Microsoft security areas. Reporting and advanced hunting are powerful, but they can take time to learn and use effectively. Review collected by and hosted on G2.com.