• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • No categories available

      Browse All Categories

      Select a category to view markets

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. Microsoft Defender for Endpoint
Logo of Microsoft Defender for Endpoint

Microsoft Defender for Endpoint

byMicrosoft
in
4.4
Market Presence: Endpoint Protection Platforms (Transitioning to Endpoint Protection), Mobile Threat Defense (Transitioning to Workspace Security Platforms)

Overview

Review Summary
AI Generated Using Real User Reviews

See a synthesized overview of the key takeaways from verified reviews of Microsoft Defender for Endpoint.

Product Information on Microsoft Defender for Endpoint

Updated 14th October 2025

What is Microsoft Defender for Endpoint?

Microsoft Defender for Endpoint is an endpoint security software designed to detect, investigate, and respond to advanced threats across devices within an organization. The software provides protection against malware, ransomware, and other malicious activities by leveraging behavioral sensors, threat intelligence, and cloud-based analytics. It supports automated response and remediation actions, secures data through attack surface reduction, and integrates with other security solutions for centralized management. Microsoft Defender for Endpoint addresses business challenges related to protecting endpoints from evolving cyber threats, managing vulnerabilities, and maintaining compliance with organizational security policies.

Microsoft Defender for Endpoint Pricing

Microsoft Defender for Endpoint software uses a subscription-based pricing model, with multiple licensing tiers available depending on features and organizational needs. Pricing is typically calculated per user or device on a monthly or annual basis, and may be included as part of broader enterprise subscription packages.

Overall experience with Microsoft Defender for Endpoint

Business Analyst
<50M USD, Real Estate
FAVORABLE

“Secure every property, protect every endpoint with the intelligent security for modern real estate operations ”

5.0
Jun 16, 2026
This text serves as a placeholder and does not reflect the user’s review responses or opinions. This text serves as a placeholder and does not reflect the user’s review responses or opinions. This text serves as a placeholder and does not reflect the user’s review responses or opinions.
It Associate
10B - 30B USD, Telecommunication
CRITICAL

“Early Stage Product Offers Intune Connectivity But Lacks Comprehensive Capabilities”

3.0
Jan 22, 2026
This text serves as a placeholder and does not reflect the user’s review responses or opinions. This text serves as a placeholder and does not reflect the user’s review responses or opinions. This text serves as a placeholder and does not reflect the user’s review responses or opinions.

About Company

Company Description

Updated 11th August 2023

Microsoft enables digital transformation for the era of an intelligent cloud and an intelligent edge. Its mission is to empower every person and every organization on the planet to achieve more. Microsoft is dedicated to advancing human and organizational achievement. Microsoft Security helps protect people and data against cyberthreats to give peace of mind.

Company Details

Updated 25th March 2024
Company type
Public
Year Founded
1975
Head office location
Redmond, Washington, United States
Number of employees
10000+
Annual Revenue
30B+ USD
Website
https://microsoft.com

Do You Manage Peer Insights at Microsoft?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

Top Microsoft Defender for Endpoint Alternatives

Logo of CrowdStrike Falcon
1. CrowdStrike Falcon
4.7
(3164 Ratings)
Logo of SentinelOne Singularity Endpoint
2. SentinelOne Singularity Endpoint
4.7
(2875 Ratings)
Logo of Sophos Endpoint
3. Sophos Endpoint
4.8
(2062 Ratings)
View All Alternatives

Peer Discussions

Microsoft Defender for Endpoint Reviews and Ratings

4.4

(1986 Ratings)

Rating Distribution

5 Star
46%
4 Star
45%
3 Star
9%
2 Star
1%
1 Star
0%
Why ratings and reviews count differ?
  • Business Analyst
    <50M USD
    Real Estate
    Review Source

    Secure every property, protect every endpoint with the intelligent security for modern real estate operations

    5.0
    Jun 16, 2026
    As our real estate operations continue to become more digital, connected and collaborative, MDE has become a key part of how we protect the business while maintaining seamless access into business-critical information. Across property management, development, leasing and business operations, the platform protects our endpoints without disrupting productivity. MDE has improved visibility across endpoints through centralized monitoring and realtime security insights, giving out IT team clearer understanding of device health and exposure across the environment. Detection and response capabilities have accelerated how quickly potential threats are identified and investigates, improving operational resilience and reducing blindspots. The platform has also strengthened compliance reporting and governance through centralized audit visibility, policy monitoring and improved evidence collection. It consolidates multiple endpoint security function in a unified platform which has reduced complexity and contributed to lower administrative cost. Automation and AI assisted investigations have further reduced the burden on our IT and security team, allowing them to focus on proactive improvements instead of repetitive monitoring and manual responses.
  • Business Analyst
    <50M USD
    Real Estate
    Review Source

    Secure every property, protect every endpoint with the intelligent security for modern real estate operations

    5.0
    Jun 16, 2026
    As our real estate operations continue to become more digital, connected and collaborative, MDE has become a key part of how we protect the business while maintaining seamless access into business-critical information. Across property management, development, leasing and business operations, the platform protects our endpoints without disrupting productivity. MDE has improved visibility across endpoints through centralized monitoring and realtime security insights, giving out IT team clearer understanding of device health and exposure across the environment. Detection and response capabilities have accelerated how quickly potential threats are identified and investigates, improving operational resilience and reducing blindspots. The platform has also strengthened compliance reporting and governance through centralized audit visibility, policy monitoring and improved evidence collection. It consolidates multiple endpoint security function in a unified platform which has reduced complexity and contributed to lower administrative cost. Automation and AI assisted investigations have further reduced the burden on our IT and security team, allowing them to focus on proactive improvements instead of repetitive monitoring and manual responses.
  • Read All 2,223 Reviews

    Get unlimited access to verified peer reviews and insights

    Read unlimited Gartner-vetted product reviews
    View and share valuable product insights
    Download full product profiles
    Review products you use today

Recommended Gartner Insights

  • Critical Capabilities for Endpoint Protection Platforms (Transitioning to Endpoint Protection)
  • Magic Quadrant for Endpoint Protection Platforms (Transitioning to Endpoint Protection)
Powered by Google TranslateThis service may contain translations provided by Google. Google disclaims all warranties related to the translations, express or implied, including any warranties of accuracy, reliability, and any implied warranties of merchantability, fitness for a particular purpose and noninfringement. Gartner's use of this provider is for operational purposes and does not constitute an endorsement of its products or services.

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.

User Sentiment About Microsoft Defender for Endpoint
Reviewer Insights for: Microsoft Defender for Endpoint
Deciding Factors: Microsoft Defender for Endpoint Vs. Market Average
Performance of Microsoft Defender for Endpoint Across Market Features

Microsoft Defender for Endpoint Likes & Dislikes

Like

MDE standout due to its centralized endpoint management capabilities, which have made it easier to maintain consistent security control across our distributed environment. Having visibility, policy management, security monitoring and operational oversight in a single platform had simplified administration while keeping our devices protected regardless of where users are working. What has been particularly valuable is the depth of protection delivered across the endpoint layers features such as device control help enforce policies around removable media and reduce the risk of unauthorized data movement. MDE also continuously safeguard out devices against known and emerging threats and also provide stronger network level control that help limit unnecessary exposure across our endpoints. Additionally, attack surface reductio rules have strengthened our security posture by minimizing opportunities for malicious execution and restricting behaviors commonly exploited by attackers. Another area where defender performs strongly is its advanced behavior analysis and AI-driven threat detection. It analyzes activity patterns to identify suspicious behavior and surface meaningful alaerts in realtime. this has improved investigative accuracy and help us to respond faster .

Like

MDE standout due to its centralized endpoint management capabilities, which have made it easier to maintain consistent security control across our distributed environment. Having visibility, policy management, security monitoring and operational oversight in a single platform had simplified administration while keeping our devices protected regardless of where users are working. What has been particularly valuable is the depth of protection delivered across the endpoint layers features such as device control help enforce policies around removable media and reduce the risk of unauthorized data movement. MDE also continuously safeguard out devices against known and emerging threats and also provide stronger network level control that help limit unnecessary exposure across our endpoints. Additionally, attack surface reductio rules have strengthened our security posture by minimizing opportunities for malicious execution and restricting behaviors commonly exploited by attackers. Another area where defender performs strongly is its advanced behavior analysis and AI-driven threat detection. It analyzes activity patterns to identify suspicious behavior and surface meaningful alaerts in realtime. this has improved investigative accuracy and help us to respond faster .

Like

MDE standout due to its centralized endpoint management capabilities, which have made it easier to maintain consistent security control across our distributed environment. Having visibility, policy management, security monitoring and operational oversight in a single platform had simplified administration while keeping our devices protected regardless of where users are working. What has been particularly valuable is the depth of protection delivered across the endpoint layers features such as device control help enforce policies around removable media and reduce the risk of unauthorized data movement. MDE also continuously safeguard out devices against known and emerging threats and also provide stronger network level control that help limit unnecessary exposure across our endpoints. Additionally, attack surface reductio rules have strengthened our security posture by minimizing opportunities for malicious execution and restricting behaviors commonly exploited by attackers. Another area where defender performs strongly is its advanced behavior analysis and AI-driven threat detection. It analyzes activity patterns to identify suspicious behavior and surface meaningful alaerts in realtime. this has improved investigative accuracy and help us to respond faster .

Dislike

The lack of features that we have found with other MTD vendors.

Dislike

The lack of features that we have found with other MTD vendors.

Dislike

The lack of features that we have found with other MTD vendors.