8 min

How to choose antivirus for 500 computers

A practical comparison of antivirus for 500 computers, covering management, audit reports, endpoint load, and three-year Kaspersky and Microsoft costs.

How to choose antivirus for 500 computers

There is no free choice between Kaspersky and Microsoft Defender for a fleet of 500 computers. Windows already has an antivirus engine, but an organization also needs policies, enforcement monitoring, an activity log, alert investigation, and evidence for audits. This management layer usually changes the final cost and workload more than the difference between the endpoint agents.

If all 500 machines run a supported version of Windows, are already managed through Microsoft Intune or Configuration Manager, and the required Microsoft licenses were bought for other purposes, Defender often has a lower total cost of ownership. If the fleet is mixed, some computers rarely connect to the corporate network, reports must remain under the company's direct control, and the team is used to running protection from one dedicated console, Kaspersky is often more predictable. Make the decision on equal protection scope over three years, not on a lab detection percentage or the price of one license.

The word "Defender" hides three different offers

The comparison makes sense only after the buyer names the exact editions and functions. Microsoft Defender Antivirus is built into Windows 10 and Windows 11 and can receive settings through Group Policy, PowerShell, Configuration Manager, Intune, or Defender for Endpoint security settings management. It is an antivirus component, not an automatically complete security service for 500 endpoints.

Microsoft Defender for Endpoint adds a cloud portal, endpoint detection and response, device information, and centralized investigation. Its plans contain different sets of capabilities. Microsoft Defender for Business usually does not qualify for a project of this size because Microsoft documentation limits it to organizations with up to 300 users. Defender for Endpoint Plan 1 and Plan 2 licenses do not include servers either. Microsoft requires separate entitlement such as Defender for Endpoint Server or one of the Defender for Servers plans.

On the Kaspersky side, the comparable offer is not a consumer antivirus product. It is a business license for Kaspersky Endpoint Security together with Kaspersky Security Center and the additional functions that are actually included in the chosen edition. Security Center distributes group policies, runs tasks, collects events, and creates reports. The specification must state the license contents because basic protection, EDR, device control, encryption, and vulnerability management must not silently be treated as one package.

Decide separately what the organization means by protection. Antivirus stops known and suspicious objects when they are accessed. EDR stores broader activity context, connects events, and gives an operator investigation and response tools. Vulnerability management identifies weak versions and configurations, but it does not automatically install every update without a separate process. Vendors package these functions differently, so comparing edition names proves nothing.

Do not put functions that nobody will use into the mandatory scope. If the company has no on-call team capable of reviewing behavioral alerts, expensive EDR telemetry can easily become an unread queue. A contract with an external monitoring service or dedicated internal hours then belongs to the option as directly as the license does. Conversely, an organization with a SOC should not compare full EDR with a local antivirus merely because both block a test file.

In the procurement worksheet, separate four layers:

  • antivirus and threat prevention on the endpoint;
  • centralized configuration and status control;
  • investigation and response after an alert;
  • event retention and production of audit evidence.

If a supplier checks "available" beside centralized management, ask for the license, console, and data source behind the report. Group Policy can configure Defender, but on its own it does not provide an operational incident queue. The local Kaspersky console on a computer does not replace Security Center either. A product class error creates an attractive but useless price difference.

Test centralized management with exceptions

A good console does more than create a policy. It shows the effective state of every machine and the source of each deviation. Across 500 devices there will inevitably be laptops outside the network, old departmental GPOs, test groups, temporary exclusions for a demanding application, and computers that have not sent telemetry for weeks. Central configuration works only when these exceptions are visible.

Kaspersky Security Center organizes management around groups, policies, and policy profiles. According to Kaspersky documentation, one active policy applies to each managed application in a group, while child groups inherit settings. A separate profile can activate under a condition, for example when a laptop leaves the corporate network. This model is clear to an administrator who wants one hierarchy and needs to prevent local changes to selected settings.

Microsoft offers several equal channels for managing Defender Antivirus. Microsoft documentation lists Group Policy, Configuration Manager, Intune, Defender for Endpoint security settings management, PowerShell, WMI, and MpCmdRun. This provides choice but also creates conflict risk. Microsoft explicitly recommends using one management method when possible and documents the precedence of sources. A setting applied locally through PowerShell can lose to an Intune policy or GPO, while an engineer searches for a "broken Defender" instead of the second system that restored the old value.

Before choosing a product, take ten machines from different departments and test one awkward setting, such as an exclusion for an accounting system directory. The administrator must be able to say who created the exclusion, which devices receive it, whether it took effect, whether a local administrator can add another one, and when the setting changed. If the answer requires visiting computers or manually comparing three consoles, that debt will multiply across 500 endpoints.

The second awkward test involves a missing machine. Disconnect a pilot laptop for several days, change a policy, and then connect it through an ordinary home internet connection. Measure when the console notices its return, whether it receives the latest configuration, and whether it requires a corporate VPN. In a distributed fleet, management channel quality matters more than the number of switches in the interface.

Defender has an advantage when the company already maintains devices in Intune or Configuration Manager, keeps Microsoft Entra groups and administrator roles in order, and runs security operations in the Microsoft Defender portal. A new antivirus policy then fits the existing model. If those processes do not exist, the built-in agent saves an installation but does not create management out of nothing.

Kaspersky wins on the clarity of responsibility when the organization is prepared to assign Security Center, a network agent, a database, backups, and a service owner. These are extra components, but the team knows where to find policies and events. The choice between one new dedicated console and an already funded Microsoft environment is an operations question, not an antivirus engine quality question.

Updates are part of management too. Test phased distribution of new agent versions and databases, bandwidth limits for a branch, restart windows, and the ability to stop a bad release. Across 500 machines, one package downloaded through a narrow link at the same time can disrupt a branch even if threat detection is perfect. The budget must include distribution points, proxies, or other resources if the chosen architecture needs them.

An auditor needs a trail, not a screenshot

A green circle on the home page is not enough for an audit. The organization needs a reproducible evidence set: a list of covered devices, protection status on a selected date, database or platform freshness, detected threats and the response to them, the active policy, its change history, and administrator accounts. The report must explain exceptions instead of hiding them in one overall percentage.

Kaspersky Security Center has standard report categories for protection status, deployment, updates, and threat statistics. Kaspersky documentation allows administrators to create templates, export results to a file, and schedule report delivery. Policies have revision history. A small revision can be viewed as HTML and a larger one can be saved as JSON. That is useful during an audit because the team can show both the current setting and the moment it changed.

Event retention in Kaspersky is configurable. It is not free infinity. The vendor warns that a longer retention period fills the Administration Server database faster. The service owner therefore has to decide in advance which events are needed for one or three years, size the database, configure backups, and test recovery. Local storage gives the organization control, but it also gives the organization all responsibility for preservation.

Intune provides operational reports for unhealthy endpoints and active malware, organizational reports for antivirus agent status and detected malware, filtering, and export. The Intune audit log records object creation, modification, deletion, and assignment, and Microsoft documentation states that those events are retained for two years. Defender for Endpoint data remains visible in the portal for up to 180 days, while advanced hunting over raw events generally covers 30 days. For a longer investigation period Microsoft proposes streaming data to external storage such as Microsoft Sentinel, which adds configuration and ingestion costs.

Do not confuse a compliance report with investigation material. The first says how many machines are protected and received a policy. The second shows a sequence of actions on one device. An auditor may accept the first, but a response team cannot operate without the second. State the period, detail level, export format, and archive owner in the technical requirements. Otherwise both suppliers will show their best screens, and after implementation the team may find that the required events have already expired.

During acceptance, request a report for an arbitrary past date rather than only the current state. Choose a device that was offline for a week, one with a temporary exclusion, and one test detection. The system must preserve their different states and the operator's actions. This test separates centralized reporting from centralized presentation.

Build one permanent evidence package and issue it on a schedule. Include the source export, a readable copy for the auditor, a description of filters, the file checksum, and a record of who approved the exclusions. A checksum does not prove that the source data was true, but it shows that the stored file did not change after issue. Apply role-based access to the archive and separate it from the right to change policies.

Export format matters. A PDF is easy to read but difficult to compare automatically with an asset inventory. CSV or JSON works well for completeness checks, but an auditor may misread a status without a field description. Request both forms and reconcile records by a unique device identifier, not just the computer name, which can be reused after reinstallation.

Measure endpoint load on your own applications

Nobody can honestly declare one agent "lighter" for all 500 machines. Load depends on processor age, memory, storage type, file profile, network directories, full scan timing, and conflicts with business applications. An antivirus that disappears into the background in an office editor may delay a software build, archive extraction, a large database launch, or batch processing of medical images.

Defender has a deployment advantage because the component is already present in a supported Windows installation, so the main antivirus package does not have to be delivered to each workstation. That does not mean zero load. Real-time protection still processes file activity, while cloud protection and EDR send and process telemetry. Kaspersky installs a management agent and a protection component. The Kaspersky Endpoint Security requirements list 2 GB of memory and 2 GB of free space as minimums for a 64-bit workstation, but a vendor minimum does not predict business application delay.

For the pilot, choose computers from the bottom quarter of the fleet rather than the newest machines, and select two or three demanding work operations. For each product compare sign-in time, application launch, opening a file set, peak processor load, occupied storage, and the number of user calls. Run full scans on the same schedule with identical treatment of archives and network paths. Otherwise the test measures different policies.

Microsoft provides a useful measurement tool directly in PowerShell:

New-MpPerformanceRecording -RecordTo C:\Temp\defender.etl
Get-MpPerformanceReport -Path C:\Temp\defender.etl -TopFiles 10 -TopProcesses 10
Get-MpComputerStatus | Select-Object AMRunningMode,AntivirusEnabled,RealTimeProtectionEnabled,AntivirusSignatureLastUpdated

The first command records scan events until the user stops the recording, the second identifies the files and processes with the highest scan cost, and the third confirms the protection mode and state. A typical Performance Analyzer report shows paths, processes, scan counts, and elapsed time. Microsoft separately warns that the analyzer does not produce a ready exclusion list. An exclusion reduces protection, so an engineer must justify it and target only the required device group.

Apply the same principle to Kaspersky with operating system measurements and task statistics in Security Center. Compare the median and the worst machines rather than one average result. If a product needs an exclusion for an entire directory containing executables or for a critical system process, that is not a performance win. It moves risk from processor usage into security.

Measure network cost as well. Initial installation, the first database download, a platform update, and ordinary synchronization have different traffic profiles. Run a separate test in a small branch and on a laptop using a mobile connection. Average monthly consumption will not reveal a short peak that occupies the entire link on Monday morning.

False positives contribute to load in more ways than user irritation. One blocked internal module creates a support call, diagnosis, exclusion approval, policy change, and a repeat test. Record the time for that entire chain during the pilot. A product with slightly more processor use can cost less if its policy fits the application set more accurately and the operator can explain an event faster.

Three-year cost begins after the license price

Design one management perimeter
GSE's vendor neutral approach helps select an architecture without one ecosystem deciding the outcome.
Discuss the project

Total cost of ownership includes all cash payments and labor that differ between options. A per-endpoint price is necessary, but in a mature environment it rarely decides the competition. Part of Defender's cost may already sit in Microsoft 365, while another part appears in Intune, Defender for Endpoint, server licenses, Sentinel, and cloud administration work. With Kaspersky, the separate subscription, management server, database, backups, and agent updates are more visible.

Build the model in tenge without invented price lists. Request a fixed commercial quote from both suppliers for the same term and scope, then apply the organization's fully loaded hourly rate. Put direct and infrastructure expenses in the first part of the calculation:

  • licenses for 500 endpoints with the required functions;
  • separate entitlement for servers and other operating systems;
  • virtual resources, operating systems, a database, and backups for local components;
  • ingestion and storage of events beyond the product's standard window.

Do not leave a row blank because a resource already exists. Enter zero cash cost and record the constraint beside it, such as available database capacity or the current contract term. This prevents one option from using infrastructure for free when another service already depends on it.

In the second part, calculate labor and user impact:

  • implementation, migration, and training;
  • monthly administration and report production;
  • support, investigation, and false positive handling;
  • measured slowdown of work operations.

The formula is simple: TCO = external payments + internal hours multiplied by the fully loaded hourly rate + infrastructure cost + measured productivity loss. Do not include the salary of the entire IT department. Include only the difference in hours between the options: creating an audit report, resolving a policy conflict, updating a management server, maintaining a connector, or handling a false alert.

Two manipulations appear often. The first calls Defender free but adds full administration cost to Kaspersky. The second assigns the whole Microsoft 365 contract to Defender even though the company would still buy it for email and office applications. For an existing subscription, the correct amount is the incremental price caused by the selected protection level plus operations. If the license is already paid, its decision cost may be zero, but the required specialists and storage are not.

Test sensitivity against at least two uncertain inputs: event volume growth and administrator time. Across 500 machines, an extra 15 minutes of manual work per device per quarter becomes 125 hours each quarter. This is not an industry statistic. It is arithmetic in your model. Replace the assumption with the pilot result and give the finance director a range rather than one falsely precise amount.

Add a payment calendar. A three-year agreement, annual subscription, and cloud consumption may have the same nominal total but respond differently to a changing machine count and exchange rate. Record the rules for adding and removing licenses, the renewal date, support cost after the first year, and the right to transfer a license when a computer is replaced. Take these conditions from the supplier's offer, not a marketing page.

Exit cost differs too. For a local product, the team must export required reports, preserve keys, and remove agents correctly. For a cloud service, it must export events before access expires, revoke roles, and stop data transmission. Budgeting several days of work to close the contract is more honest than assuming the next product will appear by itself.

Microsoft wins in an established Microsoft environment

Choose Defender when the organization already manages supported Windows devices through Intune or Configuration Manager, uses Microsoft Entra for groups and roles, and has specialists who review incidents in Microsoft Defender every day. In that situation, the built-in antivirus shortens the separate agent delivery chain, while endpoint telemetry connects to signals from other Microsoft services the company has purchased.

The strong scenario is ordinary: devices are enrolled, one policy source is defined, obsolete GPOs have been removed, licenses are assigned automatically, and export beyond the standard event window already works. The new product then needs no separate database, backup routine, or management server updates. The team uses its existing roles, groups, and response procedure.

The word "already" does most of the work. If the company has only local Active Directory and a Windows license, moving to full cloud endpoint management becomes a separate project. It has to prepare device identity, roles, network access, retention rules, training, and support. Buying that change only to replace antivirus can make sense, but it cannot hide in a row that says "Defender is included with Windows."

Pay special attention to the source of settings. Microsoft documentation shows that management channels have precedence, while some parameters do not follow the general order. Before the pilot, export existing GPOs, Configuration Manager profiles, Intune settings, and local PowerShell scripts. Give each parameter one owner, or an innocent edit to an old GPO may reverse the new cloud policy during the next refresh.

In a multi-OS environment, verify functions separately for every platform. Defender for Endpoint supports Windows, macOS, Linux, Android, and iOS, but one product name does not guarantee identical prevention, configuration, and remote response tools. Servers also require separate licensing. Build the device list from the inventory, not an assumption that all 500 objects are alike.

Microsoft has another advantage when a real SOC uses advanced hunting and event correlation. If the organization only plans to run an antivirus report once a month, it will pay for capabilities that nobody operates. An EDR license without a person who reviews the queue and knows how to isolate a device does not provide incident response.

Kaspersky is simpler for a locally managed perimeter

Compare options without vendor bias
GSE works with Microsoft and other major developers while preserving freedom of choice.
Discuss the project

Choose Kaspersky when operations needs a separate, clear system for managing protection, a significant part of the fleet works in a local perimeter, and the company wants direct control over policy and event storage. Security Center fits the classic model well: an administration server, device groups, a network agent, policies, tasks, and reports.

This option is often simpler for a geographically distributed organization whose departments have different levels of management maturity. The central team locks mandatory settings, assigns a profile to mobile users, and sees devices that have not synchronized for a long time. The dedicated console does not depend on whether the company has completed a wider move to cloud endpoint management.

The price of that clarity is owned infrastructure. The server and database need updates, monitoring, event capacity, backups, and tested recovery. The network agent also needs updates. If these duties are simply added to an overloaded system administrator, reports will lose completeness over time and the database will become a failure point.

Place the management server with network failures between sites in mind. A branch should receive databases and policy without repeatedly moving the same package across the central link, while a mobile machine should securely reach the server from an external network or use a vendor-supported gateway. The exact design depends on the selected version and topology, so include it in the project and test instead of drawing it after licenses are purchased.

Check cross-platform coverage as strictly as with Microsoft. Request a function matrix for the actual Windows, Linux, and server versions in use, not a generic supported operating systems list. Record which capabilities are included in the proposed edition. Business package names change, but the contract must protect the required outcome.

Reputation or regulatory requirements cannot be replaced by a technical argument. If an internal policy, industry rule, or customer term forbids cloud processing of certain telemetry or excludes a specific vendor, state it first as a mandatory criterion. Comparing scan speed for an eliminated option is pointless after that filter. Lawyers and the data owner should confirm that the condition applies to this organization instead of citing somebody else's procurement.

Migration is riskier than steady operation

Prepare the fleet for migration
GSE controls the equipment path from production through delivery and ongoing support.
Choose a solution

Most serious disruption happens during the week of change, not after the selection. Two active antivirus engines can intercept the same file operations, duplicate scans, block each other's files, and produce unpredictable load. A machine without active protection appears when the old agent is already removed but the new one fails to activate because of a policy, damaged registration, or lost connection.

Microsoft describes Defender Antivirus modes as active, passive, and disabled. On client Windows, Defender generally stops acting as the primary protection when a current third-party antivirus is installed. Server behavior differs, and passive mode while onboarded to Defender for Endpoint has separate conditions. The team must check the actual AMRunningMode value rather than judging by the Windows Security application icon.

A safe migration moves in rings. The lab first reproduces installation, removal, and rollback. A small IT group then checks policies and work applications. Representatives of demanding profiles and remote laptops follow. Broad deployment begins only when the console shows the expected mode, events arrive, and support staff know how to restore protection.

Define stop conditions for every ring in advance: the share of devices without current signatures, increased sign-in time, application conflicts, event delivery delay, and machines with two active engines. The numbers must come from the organization's risk tolerance. The rollback plan has to restore the old agent and its policy, not merely remove the new product.

A test detection confirms the operational channel, not overall product quality. A safe test file or built-in simulation should create an event, deliver it to the console, trigger the expected action, and appear in a report. Record the time for each stage. If the file is blocked but the analyst cannot see the event, the endpoint is only partly protected from an operations perspective.

Test a machine after removal of the old product and after a failed installation of the new one. It must automatically enter a remediation queue, and support staff must have a prepared recovery command or package. That rehearsal feels unnecessary until the first broad failure leaves dozens of remote laptops disconnected from the console.

Do not buy both products for three years in the name of "double protection." Passive Defender for Endpoint beside third-party antivirus can preserve selected EDR capabilities, but that is a deliberate architecture with licenses, exclusions, and a clear owner. Two invoices and two alert queues without a coordinated response model increase noise.

The decision for 500 machines should fit on one page

For a typical organization with 500 supported Windows computers, Intune, and Defender for Endpoint already licensed, I would choose Microsoft after a successful pilot. Kaspersky in that environment must prove that its reports, local control, or lower labor justify another system. For local Active Directory without mature cloud management, a requirement to retain events inside the perimeter, and a small generalist IT team, I would more often choose Kaspersky Security Center with properly sized infrastructure.

One failed mandatory criterion changes the decision. If the product does not support a working operating system, lacks the required retention period, does not license servers, cannot produce policy history, or breaks a critical application in the pilot, it fails regardless of price. Compare the remaining offers with the three-year model.

On the final page, record editions and license counts, operating system and server coverage, the single policy authority, event location and retention, measured load, operating hours, migration plan, and the response owner. State the model assumptions beside them. A year later this page will be more useful than the supplier's presentation because it explains why actual cost differed from the estimate.

Give every mandatory criterion a simple pass or fail result, and compare price only among the options that pass. A weighted score in which a low price can offset a missing mandatory report or unsupported operating system is dangerous. Weighted points work for interface convenience and implementation time, but not for requirements whose absence leaves the fleet without control.

GSE can assemble either option for the customer as a systems integrator. The company sells and integrates Microsoft software and software from other major developers, and states that its approach is vendor neutral. This is appropriate when the customer wants one party responsible for workstation, server infrastructure, deployment, and support compatibility, but the selection criteria must still belong to the customer.

Do not ask the winner to "show the best protection." Give both candidates the same machines, policies, demanding operations, test detection, and auditor request. The better option is the one your team can use three years later to explain the state of any of the 500 computers quickly and account for the price of that knowledge.

FAQ

Is Microsoft Defender really free for a company?

The antivirus component is included in supported Windows editions, but central management, EDR, event retention, and server protection may require other products and licenses. Calculate the incremental cost over existing entitlements and the team's work, not only the agent price.

Does Microsoft Defender for Business support 500 computers?

Usually not. Microsoft positions Defender for Business for organizations with up to 300 users. A 500-machine environment should consider enterprise Defender for Endpoint plans and verify server entitlement separately.

Can built-in Defender be managed only with Group Policy?

Group Policy can distribute many settings, but it does not replace a complete incident queue, cloud investigation, or convenient effective-state reporting. If audit and response are requirements, specify the additional management services.

Which is better for an audit, Kaspersky Security Center or Intune?

Both can produce useful reports when configured correctly. Compare a report for a past date, policy change history, inactive device lists, export format, and evidence of the response to a threat rather than their home screens.

Which antivirus puts less load on old computers?

There is no universal answer because policy and work files determine load. Run the same pilot on slow machines, measure real operations, and reject performance gains achieved through broad exclusions.

Should Defender be disabled when Kaspersky is installed?

On client Windows, the primary mode usually changes automatically when a third-party antivirus is registered correctly, but servers and Defender for Endpoint onboarding have separate rules. Check AMRunningMode and protection state for every group, especially during migration.

Can Kaspersky and Defender remain on a machine together?

You can design an arrangement with third-party antivirus and selected Defender for Endpoint capabilities, but it is not free double protection. It needs compatible modes, exclusions, licenses, and one procedure for handling two event sources.

What belongs in a three-year antivirus ownership cost?

Include endpoint and server licenses, management, event storage, infrastructure, implementation, updates, support, and the difference in internal labor. Add measured productivity loss if the pilot shows a meaningful delay.

How long do Defender and Kaspersky keep events?

The period depends on the data type and architecture. Defender for Endpoint keeps portal data longer than raw advanced hunting data remains queryable, while Kaspersky allows retention settings in a database that the organization must operate.

How many computers are enough for a pre-purchase pilot?

Representation matters more than the number alone. Include old and new machines, remote laptops, demanding applications, several departments, and at least one server scenario if servers are in scope.