Skip to content
Notifications
Clear all

Switched from CB to Defender for Endpoint. Here's the productivity hit we took.

2 Posts
2 Users
0 Reactions
3 Views
(@carlosr)
Estimable Member
Joined: 1 week ago
Posts: 116
Topic starter   [#10375]

Just migrated our 500-server AWS workload from Carbon Black to Microsoft Defender for Endpoint. The security team is happy, but our devs and SREs are not.

The biggest hit was in investigation speed. With CB, we had granular process lineage and instant remote shell. Defender's portal feels slower, and the query language has a steeper learning curve. Our mean time to triage alerts increased by about 40% in the first month.

Key friction points:
* Custom IOCs are harder to deploy at scale compared to CB's feeds.
* API feels more restrictive for automated response workflows.
* Container runtime defense seems less integrated than CB's sensor.

Has anyone else made this switch and found ways to close the productivity gap? Specifically around automation and evidence collection. What's the actual ROI after you factor in the increased investigation time?

—CR


Ask me about hidden egress costs.


   
Quote
(@jackm)
Trusted Member
Joined: 1 week ago
Posts: 46
 

I'm an SRE at a 120-person SaaS shop. We're all-in on Azure and I've managed our Defender for Endpoint rollout across about 200 endpoints, mostly developer workstations and a few dozen servers.

**Deployment/integration effort**: In an Azure/AAD shop, it's nearly zero for onboarding. The real 2-3 week effort was building new automations in Logic Apps because the API, while powerful, is more regimented than CB's.
**Where it clearly wins**: The cost. Bundled into our existing E5 licenses, it was effectively free vs. CB's ~$70/endpoint/year. The signal integration with Azure Sentinel is also a real win; we close cloud alerts faster.
**Where it breaks**: Custom detection and IOCs. Deploying a new custom IOC at scale took my team a full day to script via PowerShell. In CB, we just updated a feed. The portal is also slower; our drill-down time for an alert increased from ~30 sec to over 2 minutes.
**Support/vendor responsiveness**: Microsoft support is ticket-based and slow for technical deep dives. You rely on the community and your own TAM. CB's support was more hands-on and engineering-led in my experience.

I'd pick Defender if you're already on Microsoft 365 E5 and your top constraint is budget. If your team's speed is the highest priority and you have the budget, CB still seems better. To make a clean call, tell us what your team spends more time on: building new detections, or investigating known threats?



   
ReplyQuote