Jump to content

Recommended Posts

Posted

Hi all

 

Our ISP is going to be moving us from Sophos to Windows Defender. For all its critics, Sophos is quite straight forward in that I can view what updates each device it can have, easily find reports, see if there's any issues, easy to install etc.

 

I have rolled out Windows Defender endpoint to a test device and I have to say feelings are mixed. It all just seems all over the place. Reports seem to include enrolled devices that are not included in the AV ring, which is skewing the figures. Also the configuration, although granular, seems a bit bonkers.

 

Does anyone use Windows Defender as their main AV and think its great once you get your head round it? Any tips?

 

Thanks

Posted (edited)

Watching this thread with interest as I've had the same notice. I've never used Defender in a large/education environment and Sophos has always done a great job on the 13 primary schools I manage. 

Edited by Patrick
Posted

I think it will depend on what licensing they are giving you.  If the basic level, then it will do what is necessary, but you won't get a lot of reporting.  If you have the higher level you will get more insight.

 

The biggest question is what information do you actually want or need? To me, the updates available isn't helpful, I want to know what device is not on the latest definition and what errors or warnings are being generated.  Intune does that.

 

To be honest, I just let it do its thing, it is set up and any notifications we deal with.

Posted (edited)

 

On 12/09/2025 at 14:01, TechMonkey said:

I think it will depend on what licensing they are giving you.  If the basic level, then it will do what is necessary, but you won't get a lot of reporting.  If you have the higher level you will get more insight.

 

The biggest question is what information do you actually want or need? To me, the updates available isn't helpful, I want to know what device is not on the latest definition and what errors or warnings are being generated.  Intune does that.

 

To be honest, I just let it do its thing, it is set up and any notifications we deal with.

 

I'm on the same thought pattern as you really. I don't need bombarding with info, just need to know any machines that have fallen behind or have been infected or need attention. As long as I've got that, and defender actually does its job as well as Sophos, I'll be happy. 

Edited by Patrick
  • 3 months later...
Posted

HI All,

 

Just giving this thread a nudge, apologies for jumping on the bandwagon but this is quite worrying for us! 

 

How are you all getting on with moving from Sophos to Microsoft Defender.

We are still quite confused here as to why LCC EDS decided to make the decision without consulting schools first. (Other than apparently saving schools money.)

 

Our take on it here is that if we could stay with Sophos, we would. (Sophos just works and is a trusted AV along with being simple to use)

 

Microsoft Defender on the other hand, if set up correctly...with appropriate licencing to give you anywhere near what you get with Sophos, is very complicated, all over the place, requires many hours of training, the list goes on. Basically this move has caused us to loose many hours of work on researching/ testing to see if we can get to grips with it.

 

Our findings point towards us needing a minimum of A3 licencing with Microsoft Defender for Endpoint (Plan 2) Licencing. (I am still waiting for pricing for this but it does look like it will work out dearer than Sophos)

 

Please can you all pass on your opinions on this... so that we can all make an educated decision in whether to stay with Sophos are make the leap and move to Microsoft Defender

 

For me Sophos is a no brainer for the following reasons: -

  • It just works
  • Support is brilliant
  • It looks like it actually cheaper than Microsoft Defender. (If correct licencing for Defender is purchased) 
  • Sophos meets all DFE guidelines out of the box.

We have not really used Microsoft Defender so we cannot comment on this although by the looks of it we will need to spend may hours in training and many hours is setting it up.

We cant imagine not having some kind of Console were we can actively manage and monitor all threats and update failures. (Console access is a DFE requirement although not specifically by using the Defender console, but it would make a lot of sense to use this for full integration like you get with Sophos)

(Which by the looks of it is only possible if you have at a minimum of A3 licencing with Microsoft Defender for Endpoint (Plan 2))

 

Any opinions or advice on this will be greatly received.

 

Kind regards

 

 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...