Hey everyone. Just made the jump back to Microsoft Defender for Endpoint after a 6-month trial with Cisco Secure Endpoint (formerly AMP). Our team is small, and the switch was eye-opening.
Cisco's detection was solid, but the admin overhead killed us. The console felt clunky, and we spent hours tuning policies. MDE just snaps into our existing Microsoft 365 tenant. The automated investigation scripts are a lifesaver for our limited staff.
Biggest win: the unified security graph in the Microsoft 365 Defender portal. Seeing alerts from email, identity, and endpoints in one place is huge. With Cisco, everything was siloed.
Here's a snippet of the KQL we use now for hunting—couldn't do this as easily before:
```kql
DeviceProcessEvents
| where Timestamp > ago(1h)
| where ProcessCommandLine contains "powershell"
| project Timestamp, DeviceName, InitiatingProcessFileName, ProcessCommandLine
```
The cost was also a factor. With our E5 licenses, MDE felt like a no-brainer. Anyone else made a similar round-trip?
I'm the solo sysadmin for a 60-person tech consultancy running on Microsoft 365 E3, so managing everything with minimal overhead is my main goal.
1. **True cost comparison**: With our existing E5 licenses, MDE is essentially free. Adding Cisco Secure Endpoint started at around $6-8/user/month, which was a new line item our budget didn't have.
2. **Deployment time and effort**: MDE onboarding took maybe an hour with Intune. The Cisco deployment required a separate VM for the management console and a full week of testing policy rollouts.
3. **Admin console usability**: The Cisco console felt like a legacy dashboard with too many nested menus. For a quick threat check, the Microsoft 365 Defender portal shows me endpoint, email, and identity alerts on one screen.
4. **Automation for small teams**: MDE's automated investigation and remediation handles common alerts without me. With Cisco, I was writing more custom rules and spending time on false positives.
For any shop already paying for Microsoft 365, especially E5, I'd pick MDE. It's the simpler, integrated choice. If you weren't using Microsoft at all and had a dedicated security team, tell us your endpoint count and if you have a SOC to handle the extra tuning.