Try our new research platform with insights from 80,000+ expert users

Azure Bastion vs Microsoft Defender for Cloud Apps comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Azure Bastion
Ranking in Microsoft Security Suite
17th
Average Rating
8.6
Number of Reviews
9
Ranking in other categories
Network Monitoring Software (28th), Remote Monitoring and Management (RMM) (7th)
Microsoft Defender for Clou...
Ranking in Microsoft Security Suite
11th
Average Rating
8.4
Number of Reviews
32
Ranking in other categories
Cloud Access Security Brokers (CASB) (4th), Advanced Threat Protection (ATP) (12th)
 

Mindshare comparison

As of November 2024, in the Microsoft Security Suite category, the mindshare of Azure Bastion is 1.5%, up from 1.4% compared to the previous year. The mindshare of Microsoft Defender for Cloud Apps is 2.0%, up from 1.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Microsoft Security Suite
 

Featured Reviews

Aladin Steiner - PeerSpot reviewer
Nov 28, 2023
Has good scalability and provides secure access to the virtual machines
Our customers use the product to connect to Azure virtual machines. It is a perfect solution that they can easily connect to the browser and experience the VM services Azure Bastion makes it easy to provide quick virtual machine access to our customers. We don’t have to build complex SSL VPN…
Anthony Alvarico - PeerSpot reviewer
Jul 9, 2024
Provides discovery, data exfiltration, and sensitive data exposure at low cost
The deployment process is quick, taking two to three days. The implementation and customization require more time. We need to adjust the setup to fit the client's needs, which involves fine-tuning notifications and alerts to avoid overwhelming them. First, you need the appropriate licensing. Once you have that, go to security.microsoft.com and integrate with Defender for Endpoints to receive information. While you can ingest logs from different firewalls, such as Palo Alto or Cisco, we usually implement them with Defender for Endpoints. Once a laptop or desktop is set up in Defender for Endpoints, integrating Cloud Apps with the endpoints allows us to collect the data easily. I rate the initial setup a nine out of ten, where one is difficult and ten is easy.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"As an Azure consultant, for me, it is the best way to give the administrator access as you can manage the permission - including who can access Bastion."
"It provides all the security to us. Without getting on the internet, we can access our servers. We can access our desktop through our web browser. We don't need to run the mstsc command and login to the VM. All those things are not required."
"The product's setup is easy."
"The connection to virtual machines is very useful."
"The ability to operate the product with scripting is excellent."
"The interface is available in the edit portal."
"The most significant advantage lies in its runbook features, particularly beneficial for our infrastructure team."
"Azure Bastion makes it easy to provide quick virtual machine access to our customers."
"There are a lot of features with benefits, including discovery, investigation, and putting controls around things. You can't say that you like the investigation part but not the discovery. Everything is correlated; that's how the tool works."
"If your business requirements are relatively simple, it can get the job done."
"Better logging allows us to find problems and take appropriate steps to lock them out."
"The most valuable feature of Microsoft Defender for Cloud Apps is to stop shadow IT."
"Threat detection is its key feature, and that's why we use this tool. It gives an alert if a PC is attacked or there is any kind of anomaly, such as there is a spike in sending emails or we see an unauthorized website being accessed. So, it keeps us on our toes. We get to know that there is something wrong, and we can isolate the user and find any issues with it. So, threat detection is very robust in this tool."
"Defender's integration with our identity solutions is critical in our current setup."
"We have become more aware of what services our users are using, how often they are using them, and what data is being sent out of the organization and to which services. So, it is really a lot about visibility and helping us make decisions based on that. It drives some of our policy decisions for adding extra security controls."
"The most effective features for data protection are data loss prevention (DLP) and data classification."
 

Cons

"When you have a boot issue on Windows, you cannot use Azure Bastion to fix it. You have to use the Azure console or the VM console, and it is very limited."
"While general support is valuable, having a detailed breakdown of the specific issues would contribute to a more streamlined and efficient resolution process."
"The solution breaks down sometimes."
"Speaking of AI, having Microsoft Copilot in Azure Bastion would be good."
"There are some challenges because Bastion is more compatible with Edge but not with the other browsers. As an organization, it doesn't make sense that we have to use only Edge. We should be able to access Bastion over Chrome, Mozilla, or Opera. It should be our choice."
"We are not able to copy and paste files directly into the server over the patch host. We have to transfer files over to Azure Storage."
"The protocol speed could be faster."
"You are charged for retrieving your own data."
"The integration with macOS operating systems needs to be better."
"I believe it's only set to be integrated with Microsoft Defender for identity and identity protection. I would like to see it available for use with something like Office 365 Defender. I don't think it's integrated with that yet."
"It doesn't actually decrease the time to respond. This has been an issue with Microsoft recently. Sometimes, there is a delay when it comes to getting an alert policy email... Sometimes it takes two or three hours for that email to be sent."
"I would like to see them include more features in the older licenses. There are some features that are not available, such as preventing or analyzing cloud attacks."
"Defender for Cloud Apps could come with more configured policies out of the box. Also, integration could be easier. Integration is moderately difficult because Microsoft hasn't developed a solution that unifies device onboarding and management. You have to use Intune to manage devices and Defender for Endpoint to enforce policies. They need to fix their integration, but I believe they will straighten it out by the end of the year."
"Sometimes, we'll get false positive alarms. For example, when a SharePoint path has no file sharing, but there is an external user, it will trigger an alarm that the file has been shared with an external user... the alerting mechanism should be more precise when giving you an alert about what activity has been done with the file..."
"We sometimes get errors when we create policies, which is somewhat annoying because some policies stop working due to misconfigurations. We find this challenging because it limits our options for troubleshooting an issue."
"I would like for it to be available on Mac and for it to support all of the features of Microsoft financing products. It is really for Windows."
 

Pricing and Cost Advice

"Azure Bastion's pricing is good."
"The tool is cheaply priced. I would say that the product is free to use."
"It does not save money for us."
"The pricing is a lower decision point than high-quality security for our organization. Better security comes at a cost, but it's worth it, and that's what we tell our customers."
"It has pretty good pricing."
"Where we are right now, this is an acceptable pricing. I would like to see more transparency given to the end user. The end user given to us is via the cloud service provider. There are different programs and license models. Some include this, and some include that. It is all over the place. There can be a little more consistency or simplification in the pricing so that your parts list is not ten pages long, and you are not trying to determine, "If I have an E3, does this cover that?", or "Do I need to pay separately for the license?" Simplification would probably be better."
"This product is not expensive."
"The cost could be improved when you need to pay for anything. For example, refreshing files takes time to load, though it may be my Internet. To improve the refresh time, Microsoft says that we need to pay for a Premium license, and I don't like paying for things that help make a solution better."
"We utilize the Microsoft E5 licensing, which encompasses the entire Microsoft suite; however, it is costly."
"It has fair pricing. You pay for what you get. As far as I know, there are no costs in addition to the standard licensing fee."
"We are an MST and we do not pay for the solution. However, the price of the solution could be better."
"The product's pricing seems fair."
report
Use our free recommendation engine to learn which Microsoft Security Suite solutions are best for your needs.
814,763 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
18%
Manufacturing Company
10%
Government
7%
Financial Services Firm
7%
Computer Software Company
17%
Financial Services Firm
12%
Manufacturing Company
9%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Azure Bastion?
Azure Bastion makes it easy to provide quick virtual machine access to our customers.
What is your experience regarding pricing and costs for Azure Bastion?
The tool is cheaply priced. I would say that the product is free to use.
What needs improvement with Azure Bastion?
I think the tool is pretty good. It is like having a tool that just works. If there are better tools that Azure comes up with, then that is a separate thing. In the current scenario, Azure Bastion ...
Which is the better security solution - Cisco Umbrella or Microsoft Cloud App Security?
Cisco Umbrella is an integral component of the Cisco SASE architecture. It integrates security in a single, cloud-native solution, unifying multiple features like DNS-layer security, threat intelli...
What do you like most about Microsoft Cloud App Security?
It does a great job of monitoring and maintaining a security baseline. For us, that is a key element. The notifications are pretty good.
What is your experience regarding pricing and costs for Microsoft Cloud App Security?
It's relatively low-cost, especially since it's often bundled with Microsoft 365.
 

Also Known As

No data available
MS Cloud App Security, Microsoft Cloud App Security
 

Overview

 

Sample Customers

Information Not Available
Customers for Microsoft Defender for Cloud Apps include Accenture, St. Luke’s University Health Network, Ansell, and Nakilat.
Find out what your peers are saying about Azure Bastion vs. Microsoft Defender for Cloud Apps and other solutions. Updated: October 2024.
814,763 professionals have used our research since 2012.