Verified User in Manufacturing
AM
Enterprise (> 1000 emp.)
"Deep Microsoft Ecosystem Integration with Powerful Automated Investigation"
4.5/5
What do you like best about Microsoft Defender for Endpoint?

What I like best about Microsoft Defender for Endpoint is the depth of integration with the Microsoft security ecosystem. It gives strong visibility across endpoints, ties alerts into Microsoft Sentinel and Defender XDR, and makes investigation much easier by correlating device, user, identity, and email-related signals. The automated investigation and response features are also valuable because they help reduce manual triage effort and speed up containment. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Defender for Endpoint?

What I dislike about Microsoft Defender for Endpoint is that it can be complex to configure and tune properly, especially in larger or more mature environments. Some alerts can require careful suppression or tuning to avoid noise, and the portal experience can feel fragmented because related information is sometimes spread across multiple Microsoft security areas. Reporting and advanced hunting are powerful, but they can take time to learn and use effectively. Review collected by and hosted on G2.com.

See what 303 reviewers think of Microsoft Defender for Endpoint

4.4 out of 5 · Verified reviews from real users

Read all reviews