Skip to content
Microsoft Defender ...
 
Notifications
Clear all

Microsoft Defender ATP detection latency seems high - anyone measured this?

1 Posts
1 Users
0 Reactions
2 Views
(@martech_maverick_42)
Trusted Member
Joined: 2 months ago
Posts: 35
Topic starter   [#4615]

Been doing a stack audit for a client who's all-in on the Microsoft security suite. The promise is obvious: native integration, single pane of glass, etc. But when we started looking at actual telemetry and comparing timestamps, the detection latency from Defender for Endpoint was... concerning.

We're talking alerts firing **15-20 minutes** after the initial malicious process execution, even for known-bad hashes and straightforward behavioral stuff. In a world where dwell time is measured in minutes, that's an eternity. My old, supposedly "bloated" multi-vendor setup had that down to under 5.

Before I go down the rabbit hole of tuning AV/ASR policies (which feels like trying to start a fire with wet wood), I wanted to see if others have actually measured this.

* Are you seeing similar delays, or is my tenant just uniquely unlucky?
* Is this the trade-off for the "integrated" approach—more streamlined management, but slower actual protection?
* What's your baseline? Are sub-5-minute detections even possible with ATP in a real-world deployment, or is that just marketing slideware?

The sales engineers are, predictably, talking about "cloud-powered AI" and "cross-signal correlation," but I'm looking at a clock. Would love some unfiltered data points.



   
Quote