🌐
Microsoft
microsoft.com › en-us › security › business › endpoint-security › microsoft-defender-endpoint
Microsoft Defender for Endpoint | Microsoft Security
Help secure endpoints with industry-leading, multiplatform detection and response. ... Stop cyberattacks and protect endpoints at speed and scale with industry-transforming AI that amplifies your security team’s strengths.
🌐
Microsoft Learn
learn.microsoft.com › en-us › defender-endpoint › microsoft-defender-endpoint
Microsoft Defender for Endpoint - Microsoft Defender for Endpoint | Microsoft Learn
November 6, 2025 - Microsoft Defender for Endpoint is an enterprise endpoint security platform designed to help enterprises prevent, detect, investigate, and respond to advanced threats on their endpoints.
Discussions

What do you think Microsoft Defender for Endpoint?
Currently work at a company that is 95% Windows. Defender for Endpoint has been surprisingly good at detecting threats on Windows. Seen lots of false positives on our Linux systems though. Their UI has its positives and negatives. The timeline doesnt show everything their Advanced Hunting logs show and vice versa. But their investigation UI is crap compared to Crowdstrike and Sentinel One. If you see a suspicious process in Defender, you cant find out network connections and files dropped by the process easily in the UI. You have to go to the Advanced Hunting logs. Their alert/incident views are okay, but not as useful as Crowdstrike's. It also seems to require other Microsoft solutions like SCCM or Intune to deploy, which isnt the case for Crowdstrike. If you're using the rest of the Microsoft infrastructure for e-mail, identity, etc then Defender makes a lot of sense. If not, then its adequate but not best in class, like most of Microsoft's products. I'd look around in your case since you're 70% Linux/Mac. More on reddit.com
🌐 r/AskNetsec
21
28
March 11, 2023
Microsoft Forefront Endpoint Protection - End of Life - July 9th 2019
I had no idea. That was quiet. This is specifically for FEP 2010, and not SCEP, I'm assuming? More on reddit.com
🌐 r/sysadmin
2
11
March 21, 2019
Windows Defender vs. Symantec Endpoint Protection
For home use defender is fine. More on reddit.com
🌐 r/windows
13
3
June 26, 2019
Microsoft ATP Endpoint Protection

I haven't used it personally, but I've heard that Defender ATP is worlds away from the stock Defender that comes with Windows, so it may actually be good.

More on reddit.com
🌐 r/sysadmin
16
7
June 19, 2016
🌐
Microsoft Learn
learn.microsoft.com › en-us › intune › configmgr › protect › deploy-use › endpoint-protection
Endpoint Protection - Configuration Manager | Microsoft Learn
When you use Endpoint Protection with Configuration Manager, you have the following benefits: Configure antimalware policies, Windows Defender Firewall settings, and manage Microsoft Defender for Endpoint to selected groups of computers.
🌐
Microsoft Learn
learn.microsoft.com › en-us › intune › intune-service › protect › endpoint-security
Manage endpoint security in Microsoft Intune - Microsoft Intune | Microsoft Learn
Security baselines in Intune are preconfigured groups of Windows device configuration settings that are pre-configured with defaults that set the best practice recommendations from the relevant Microsoft security teams. Intune supports security baselines for Windows device settings, Microsoft Edge, Microsoft Defender for Endpoint Protection, and more.
🌐
BlueVoyant
bluevoyant.com › home › microsoft defender for endpoint: architecture, features, and plans
Microsoft Defender for Endpoint: Architecture, Features & Plans
December 1, 2022 - Supports distribution of updates through Windows Server Update Service (WSUS), Microsoft Endpoint Configuration Manager, or the regular methods you use to deploy Microsoft updates to endpoints. ... Next-generation protection is able to detect and block advanced and unknown threats, protecting against malware and exploits that cannot be detected by legacy antivirus.
Price   $
Address   335 Madison Ave, Suite 5G, 10017, New York
🌐
Microsoft Learn
learn.microsoft.com › en-us › intune › intune-service › protect › microsoft-defender-with-intune
Use Microsoft Defender for Endpoint in Microsoft Intune - Microsoft Intune | Microsoft Learn
October 22, 2025 - When you integrate Microsoft Defender for Endpoint with Microsoft Intune you can use Intune to enforce device compliance, configure devices to help prevent security breaches, and limit the impact of threats from devices that run Defender for ...
🌐
Steeves
steeves.net › home › is microsoft defender for endpoint worth all the hype?
Is Microsoft Defender for Endpoint Worth All the Hype? — Steeves and Associates
December 22, 2021 - Defender for Endpoint is an enterprise endpoint security product that supports Mac, Linux, and Windows operating systems, along with Android and iOS The platform has been curated to help enterprise networks prevent, detect, investigate as well as respond to threats for end-user devices such ...
Find elsewhere
🌐
Finchloom
finchloom.com › blog › microsoft-defender-for-endpoint
Microsoft Defender for Endpoint Protection | Finchloom
Every day, Defender downloads an update from Microsoft that looks for new types of malware, viruses, files, pictures, etc. that might match a pattern from the daily downloaded file. If Defender does find a match, it blocks the file in question. This is the traditional endpoint protection that we ...
🌐
NeweggBusiness
neweggbusiness.com › product › product.aspx
NeweggBusiness - Microsoft Defender For Endpoint Annual
Buy Microsoft Defender For Endpoint Annual with fast shipping and top-rated customer service. Once you know, you Newegg!
🌐
Microsoft Learn
learn.microsoft.com › en-us › defender-endpoint
Microsoft Defender for Endpoint documentation - Microsoft Defender for Endpoint | Microsoft Learn
Microsoft Defender for Endpoint delivers preventative protection, post-breach detection, automated investigation, and response.
🌐
Nerdio
getnerdio.com › home › glossary › microsoft defender for endpoint
Defender for Endpoint: Features and Comparisons
May 5, 2025 - Microsoft Defender for Endpoint employs a multi-layered approach to protect your organization from cyberattacks. By combining advanced threat detection, prevention, and response capabilities, it helps you stay ahead of evolving threats and safeguard ...
🌐
Microsoft
microsoft.com › en-us › security › business › security-101 › what-is-an-endpoint
What Is an Endpoint? | Microsoft Security
Endpoint security, or endpoint protection, helps protect endpoints from malicious actors and exploits. Cybercriminals target endpoints because they are doorways to corporate data and by nature vulnerable to attack. They are outside network security and dependent on users to put security measures ...
🌐
Microsoft
microsoft.com › en-us › security › business › microsoft-intune
Microsoft Intune: Endpoint Management | Microsoft Security
Maximize productivity and simplify administration without compromising endpoint management and security. Manage and protect cloud-connected endpoints across Windows, Android, macOS, iOS, and Linux operating systems.
🌐
Microsoft 365
m365maps.com › files › Microsoft-Defender-for-Endpoint.htm
Microsoft Defender for Endpoint License Diagram
Microsoft Defender for Endpoint licensing diagram from the m365maps.com collection by Aaron Dinnage
🌐
Reddit
reddit.com › r/asknetsec › what do you think microsoft defender for endpoint?
r/AskNetsec on Reddit: What do you think Microsoft Defender for Endpoint?
March 11, 2023 -

Hi there!

  1. Have you used Microsoft Defender for Endpoint? What has been your experience with it?

  2. In your opinion, what are the benefits of using Microsoft Defender for Endpoint over other endpoint protection solutions?

  3. What are the potential drawbacks or limitations of using Microsoft Defender for Endpoint?

  4. How effective do you think Microsoft Defender for Endpoint is at detecting and mitigating threats?

  5. How does Microsoft Defender for Endpoint compare to other endpoint protection solutions in terms of ease of use and manageability?

Also, I'm not very well familiar with Microsoft licenses and products, but I'm not sure I understand what is Microsoft Defender for Endpoint.

It is an additional sensor/add-on that upgrade default Microsoft Defender Antivirus or is it a separate, self-contained product?

We have around 6000 endpoints (Windows 30%, Linux 69% and MacOS 1%).

How much would it cost and are there any discounts? Who has dealt with this?

Top answer
1 of 11
25
Currently work at a company that is 95% Windows. Defender for Endpoint has been surprisingly good at detecting threats on Windows. Seen lots of false positives on our Linux systems though. Their UI has its positives and negatives. The timeline doesnt show everything their Advanced Hunting logs show and vice versa. But their investigation UI is crap compared to Crowdstrike and Sentinel One. If you see a suspicious process in Defender, you cant find out network connections and files dropped by the process easily in the UI. You have to go to the Advanced Hunting logs. Their alert/incident views are okay, but not as useful as Crowdstrike's. It also seems to require other Microsoft solutions like SCCM or Intune to deploy, which isnt the case for Crowdstrike. If you're using the rest of the Microsoft infrastructure for e-mail, identity, etc then Defender makes a lot of sense. If not, then its adequate but not best in class, like most of Microsoft's products. I'd look around in your case since you're 70% Linux/Mac.
2 of 11
9
I work in a place that just cut 6k+ windows workstations over to it and an additional 7k+ servers. We manage workstations with Intunes and policy management there is pretty simple. For servers we use MECM as tenant attached and all policy is done in Intunes via MECM Server Collections. For detecting threats, I think it’s pretty great but I’m in a full Defender XDR shop. So email, endpoint, MCAS, Identity, Cloud, etc. everything except IoT. My biggest drawback right now is towards servers. Sometimes it feels that defender isn’t honoring the path exclusions I give it and then MsSense is locking up our files and those files exclusions are managed by the Defender product team. Not even support has access to it. Neither do the admins of the tenant which is BS. We onboarded all of our windows servers using Azure ARC with defender for cloud servers P1. This will auto install the MDE agent for you. The sticker price is $5/server/month but with our E5 agreement, we got it at $2.50. But again, we are all defender xdr and sentinel siem. For detecting threats, I was reviewing a pentest recommendations and thought it was kinda BS because of the previous EPP we had (Cb). So I proved to some people at work that the remediation doesn’t matter now. I copy/pasted malicious powershell into my notepad and defender immediately quarantined the file. It wasn’t even saved yet. That was pretty cool to demonstrate. There are a lot of bells and whistles to it so I would say make sure you understand all of it. And speak to your msft reps to speak with a product owner. Not the sales specialist. The product owners will give you the real meat and potatoes of the solution and the sales folks are contoso demo monkies. For Linux servers, use Ansible to manage the policies via the managed.json file. Also for licensing, I think it’s just P1 or P2 through defender for cloud. This is where combining Azure ARC + Defender for Cloud
🌐
Kocho
kocho.co.uk › home › blog › what is microsoft defender for endpoint?
What is Microsoft Defender for Endpoint? | Kocho Blog
September 4, 2024 - Defender for Endpoint Plan 2 (P2): Offers comprehensive endpoint security features, including all the capabilities of P1 plus advanced threat hunting, detection, and response tools, automated investigation and remediation, and in-depth threat ...
🌐
Atech Cloud
atech.cloud › home › resources › endpoint security with microsoft defender
Endpoint Security with Microsoft Defender - Atech Cloud
January 10, 2023 - Microsoft Defender for Endpoint is there to make sure that when a breach does occur, it can be quickly isolated and dealt with before it has a chance to cause any damage or manifest itself within your network.
Price   $$$
Address   Jubilee House, Globe Park , Third Avenue, SL7 1EY, Marlow
🌐
ITProMentor
itpromentor.com › home › shop › courses › ecourses
Microsoft Defender for Endpoint (Business) - ITProMentor
Microsoft Defender for Endpoint (Business)
Replace your third-party endpoint security solutions with Microsoft Defender for Business (a.k.a. Microsoft Defender for Endpoint) Buy Now
Price   $97.00
🌐
Lumifi Cybersecurity
lumificyber.com › home › blog › what is microsoft defender for endpoint and how does it work?
What is Microsoft Defender for Endpoint? | Advanced Threat Protection | Lumifi Cybersecurity
May 29, 2024 - Microsoft Defender for Endpoint, formerly known as Microsoft Defender Advanced Threat Protection, provides enterprise-level protection to endpoints to prevent, detect, investigate, and respond to advanced threats.
🌐
Microsoft Learn
learn.microsoft.com › en-us › intune › intune-service › protect › microsoft-defender-integrate
Onboard and Configure Devices with Microsoft Defender for Endpoint via Microsoft Intune - Microsoft Intune | Microsoft Learn
October 22, 2025 - Microsoft Defender for Endpoint reports on the risk level of devices. Devices that exceed the allowed risk level are identified as noncompliant. Use Conditional Access policy to block users from accessing corporate resources while using a device that is identified as noncompliant. Use app protection ...