Try our new research platform with insights from 80,000+ expert users

Abnormal Security vs Microsoft Defender for Office 365 comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 3, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Abnormal Security
Ranking in Email Security
4th
Ranking in Secure Email Gateway (SEG)
3rd
Average Rating
9.4
Reviews Sentiment
7.5
Number of Reviews
11
Ranking in other categories
No ranking in other categories
Microsoft Defender for Offi...
Ranking in Email Security
1st
Ranking in Secure Email Gateway (SEG)
1st
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
60
Ranking in other categories
Email Archiving (1st), Advanced Threat Protection (ATP) (2nd), Microsoft Security Suite (10th)
 

Mindshare comparison

As of January 2026, in the Email Security category, the mindshare of Abnormal Security is 5.9%, down from 6.5% compared to the previous year. The mindshare of Microsoft Defender for Office 365 is 9.6%, down from 13.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Email Security Market Share Distribution
ProductMarket Share (%)
Microsoft Defender for Office 3659.6%
Abnormal Security5.9%
Other84.5%
Email Security
 

Featured Reviews

William Schellhaas - PeerSpot reviewer
Senior Director of IT at Crunch Fitness West Florida and Atlanta (CR Fitness)
Provides comprehensive email security management, effective in detecting a wide range of email threats
The ideal scenario would be for Abnormal Security to work in tandem with Microsoft to analyze incoming emails. This means Abnormal Security would assess emails before they reach my inbox, even if it happens slightly after Microsoft's initial scan. Currently, the process isn't seamless. Microsoft analyzes emails and delivers legitimate ones to my inbox. Abnormal Security then scans these delivered emails, and if flagged as malicious, they disappear. This creates a problem for our ticketing system mailbox, which is a third-party service. Emails sent to the ticketing system address are automatically forwarded by Microsoft. However, if these emails are malicious, Abnormal Security only cleans them from my Outlook mailbox after they've been forwarded. Since we primarily rely on the ticketing system and not the Outlook mailbox, these malicious emails still reach the ticketing system.
Emeka Ndulu - PeerSpot reviewer
Cloud Solutions Architect at a tech services company with 201-500 employees
Improves threat visibility and response while reducing manual tasks and training users against phishing
I appreciate the attack simulation feature whereby I get to train users and educate them on how to identify phishing emails and spam emails, as well as the anti-spam protection. It gives me visibility into my threat environment and threat landscape to ensure that I am one step ahead of any likelihood of threats within my environment. I get to detect it and respond, so the threat intelligence is very effective. Microsoft security solutions save my time. It saves money because once I protect my environment, I don't lose money. It has decreased my detection time and my time to respond.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"I like Abnormal's threat protection with auto-remediation, but I also love its abuse mailbox feature, which automatically responds to the end user. That feature has a super-valuable security component and helps improve the user experience."
"It does some really cool stuff that other tools aren't doing. We found it to be really effective, and the AI/ML functionality is really what differentiates them."
"I would recommend Abnormal Security."
"The features that appeal to me most are the combination of auto-remediation and Detection 360."
"Their ability to take things out of the mailbox and catch things much faster than users is excellent."
"Initial auto-remediation allows us to auto-remediate before the email lands in the end user's inbox for a split second."
"I have never encountered any stability issues with Abnormal."
"Abnormal Security's AI capabilities are what we like most, as they can categorize and classify the emails, and based on the context of the email, understand if it's a graymail, a bulk mail, or a phish."
"The most valuable feature of Microsoft Defender for Office 365 is its spam filter."
"I like its investigation capabilities, as that is what is most important to me. It is fairly simple with a user-friendly interface."
"I appreciate the attack simulation feature whereby I get to train users and educate them on how to identify phishing emails and spam emails, as well as the anti-spam protection."
"The good part is that you don't have to configure it, which is very convenient."
"It also gives the vulnerability status according to the versions you have selected. Let's say you have Google Chrome. It mentions the versions it has, and it updates. Within two hours of an update, it is reflected in the dashboard. That's really nice to have."
"It has significantly decreased my time to detection and response."
"One of the best features of the tool is its capability to aggregate insights from different workloads, basically from the Office 365 and endpoints part."
"The email protection is excellent, especially in terms of anti-phishing policies."
 

Cons

"There could be more selectable options and more granular selections available."
"I would like to have the ability to customize the auto-remediation feature."
"I, as such, do not have anything that I do not like or would like to add, but you could argue that because they are doing it API-based, there is a chance that something could slip through temporarily before they are able to pull it out. In theory, it could happen just because of the nature of the system. They are not in line with the delivery of the mail. They are kind of asynchronous, which is a pro as well as a con. If it is synchronous, then I know it would always stop them, but because it is asynchronous, things could get through temporarily or because of some system issues on the Microsoft side or their side. It is the nature of the beast, but it is a little bit of a con."
"There could be more selectable options and more granular selections available."
"When we're working on something as engineers, and we find an idea or a method of doing something that would be greatly improved by doing it another way, there should be an ability for me to click the ideas button, type in an idea that I have, and submit it to a product review team or developers to have them think through the process a little bit more."
"For Abnormal Security as a product, I would say probably somewhere around a seven, as there are some other areas where they can improve to achieve a higher rating."
"One feature I'd love to see is outbound scanning."
"Abnormal should add more automatic reports. I have an open request to our account team for more notification and report types that can be sent automatically. For example, they have an awesome report that gets sent weekly, and I also want them monthly, so I don't need to do so much adding up when my director wants numbers over time."
"The phishing and spam filters could use some improvement."
"Microsoft wants its well-paying customers to finish testing some of its half-baked products, find bugs, and report bugs back to Microsoft's team, which is a little frustrating for those who have to manage it and roll it up to thousands of people across the organization."
"One area for improvement is support, in terms of being able to reach them and, especially, technical support for configuration."
"The visibility for the weaknesses in the system and unauthorized access can be improved."
"Microsoft Defender for Office 365's Mac functionality requires improvement to deliver the same level of protection found on Windows devices."
"Microsoft Defender for Office 365 should improve the troubleshooting tools. It's unclear whether the device is blocked at the firewall level or at the device itself. The granularity needed for troubleshooting is currently lacking. From my perspective, Microsoft should address this issue to benefit many users who likely share the same sentiment."
"In some situations, it has not been able to pick impersonated emails having no attachments. Technical support definitely has a scope for improvement."
"I'd like some additional features any product can give me to protect our environment in a better way."
 

Pricing and Cost Advice

"The license is based on the user count, so the number of users that have an email address in the organization."
"Abnormal Security, on the other hand, provides the same level of functionality for just over $60,000 – that's half the price!"
"Overall, we'd certainly prefer lower pricing, but Abnormal Security doesn't seem unreasonable compared to similar offerings in the market."
"The pricing appears fair, and they demonstrate a genuine willingness to work with us on it."
"It's a user-base subscription."
"Defender is a little bit more expensive as compared to others. We are in the manufacturing environment. So, we don't have a high budget for all of our endpoint devices. Its cost is a major concern for us."
"From the pricing point of view, like any other product in the market, there is scope for negotiation."
"The product is expensive."
"The pricing is normal. Considering its popularity, it's not overpriced."
"The product is very expensive."
"It is much more expensive than using another solution because we have had to include some options and upgrade our license."
"Microsoft Defender for Office 365 is an add-on to the Office license. Many customers are purchasing this solution."
report
Use our free recommendation engine to learn which Email Security solutions are best for your needs.
881,114 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
12%
Financial Services Firm
10%
Manufacturing Company
8%
Government
7%
Computer Software Company
14%
Financial Services Firm
8%
Manufacturing Company
8%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business1
Midsize Enterprise2
Large Enterprise8
By reviewers
Company SizeCount
Small Business23
Midsize Enterprise10
Large Enterprise31
 

Questions from the Community

What do you like most about Abnormal Security?
The features that appeal to me most are the combination of auto-remediation and Detection 360.
What is your experience regarding pricing and costs for Abnormal Security?
I find the pricing to be favorable, but I did not disclose the exact cost.
What needs improvement with Abnormal Security?
Ease of use is important, and Abnormal Security's responsiveness and ability to deliver solutions when issues arise are crucial. However, there is always room for improvement, as achieving a perfec...
What needs improvement with Microsoft Defender for Office 365?
The inbuilt analysis of false positives can be faster. It's not slow, but it can be faster.
What is your primary use case for Microsoft Defender for Office 365?
My use case for Microsoft Defender for Office 365 is for email protection, safe links, protection of links, documents, protecting my documents, and protecting attachments. I also use it to conduct ...
 

Also Known As

No data available
MS Defender for Office 365
 

Overview

 

Sample Customers

Foot Lcoker, Xerox, Liberty Mutual, Mattel, Boston Scientific
Microsoft Defender for Office 365 is trusted by companies such as Ithaca College.
Find out what your peers are saying about Abnormal Security vs. Microsoft Defender for Office 365 and other solutions. Updated: January 2026.
881,114 professionals have used our research since 2012.