Try our new research platform with insights from 80,000+ expert users

Cortex XDR by Palo Alto Networks vs Microsoft Defender for Cloud comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 12, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.6
Cortex XDR by Palo Alto Networks offers ROI with fewer breaches, reduced incidents, enhanced security, and compliance benefits within 16 months.
Sentiment score
7.2
Microsoft Defender for Cloud enhances security, reduces costs, and improves efficiency, offering proactive vulnerability identification and significant benefits.
They appreciate the rich telemetry data from the solution, as it provides in-depth threat identification.
Defender proactively indexes and analyzes documents, identifying potential threats even when inactive, enhancing preventative security.
Identifying potential vulnerabilities has helped us avoid costly data losses.
The biggest return on investment is the rapid improvement of security posture.
 

Customer Service

Sentiment score
6.5
Cortex XDR customer service receives mixed reviews, citing regional differences in responsiveness, communication, and expertise quality.
Sentiment score
6.6
Microsoft Defender for Cloud support varies in quality; enterprise users report better experiences, while others face inconsistencies and delays.
Every vendor has similar support; it depends on how the case is handled and raised.
Since security is critical, we prefer a quicker response time.
The support team was very responsive to queries.
They understand their product, but much like us, they struggle with the finer details, especially with new features.
 

Scalability Issues

Sentiment score
7.6
Cortex XDR by Palo Alto Networks efficiently scales for medium to large businesses, supporting numerous users and endpoints seamlessly.
Sentiment score
7.8
Microsoft Defender for Cloud is scalable and flexible, integrates easily, but may have scalability and cost concerns at large scales.
We are using infrastructure as a code, so we do not have any scalability issues with Microsoft Defender for Cloud implementation because our cloud automatically does it.
Defender won't replace our endpoint XDR, but it will likely adapt and support any growth in the Microsoft Cloud space.
There might be scalability issues as you scale up to large enterprises.
 

Stability Issues

Sentiment score
8.1
Cortex XDR is highly stable and reliable, with user satisfaction scores between eight and ten out of ten.
Sentiment score
7.7
Microsoft Defender for Cloud is reliable with minor downtime and occasional portal or connectivity issues, praised for overall performance.
Cortex XDR is stable, offering high quality and reliable performance.
Defender's stability has been flawless for us.
Microsoft Defender for Cloud is very stable.
Microsoft sometimes changes settings or configurations without transparency.
 

Room For Improvement

Cortex XDR requires improved functionality, user interface, integration, and pricing, while addressing performance, false positives, and compatibility issues.
Microsoft Defender for Cloud users seek enhanced customization, better integration, improved dashboards, automation, and clearer pricing and documentation.
Cortex XDR could improve its sales support team, including better commission structures and referral programs.
Microsoft, in general, could significantly improve its communication and support.
The artificial intelligence features could be expanded to allow the system to autonomously manage security issues without needing intervention from admins.
I've heard there might be issues with scalability for larger enterprises.
 

Setup Cost

Cortex XDR offers flexible but costly licensing, accommodating varying business sizes with yearly or monthly payment options.
Microsoft Defender for Cloud provides customizable pricing options, with debated cost-effectiveness, especially for extensive or regional deployments.
Cortex XDR is perceived as expensive by some customers, yet offers dynamic pricing.
Every time we consider expanding usage, we carefully evaluate the necessity due to cost concerns.
We appreciate the licensing approach based on employee count rather than a big enterprise license.
Microsoft Defender for Cloud is pricey, especially for Kubernetes clusters.
 

Valuable Features

Cortex XDR provides advanced threat detection, integration, and ease of use, excelling in real-time prevention and incident investigation.
Microsoft Defender for Cloud provides enhanced security, AI-driven insights, multi-cloud support, and integrates with Sentinel for proactive threat management.
It incorporates AI for normal behavior detection, distinguishing unusual operations.
The most valuable feature for me is the variety of APIs available.
This feature significantly aids in threat detection and enhances the user experience by streamlining security management.
The most valuable feature is the recommendations provided on how to improve security.
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
91
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Extended Detection and Response (XDR) (7th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (4th)
Microsoft Defender for Cloud
Average Rating
8.0
Reviews Sentiment
7.0
Number of Reviews
74
Ranking in other categories
Vulnerability Management (7th), Container Management (8th), Container Security (4th), Cloud Workload Protection Platforms (CWPP) (3rd), Cloud Security Posture Management (CSPM) (3rd), Cloud-Native Application Protection Platforms (CNAPP) (4th), Data Security Posture Management (DSPM) (3rd), Microsoft Security Suite (3rd), Compliance Management (2nd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Cortex XDR by Palo Alto Networks is designed for Endpoint Protection Platform (EPP) and holds a mindshare of 4.2%, down 5.4% compared to last year.
Microsoft Defender for Cloud, on the other hand, focuses on Cloud Workload Protection Platforms (CWPP), holds 14.2% mindshare, down 15.7% since last year.
Endpoint Protection Platform (EPP)
Cloud Workload Protection Platforms (CWPP)
 

Featured Reviews

Mohammad Qaw - PeerSpot reviewer
Perfect correlation and XDR capabilities for network traffic plus endpoint security
The solution should force customers to integrate with network traffic to see the full benefits of XDR. If you are not integrating it or feeding in your network traffic, then you are just buying a normal antivirus which doesn't make any sense. You are paying double the price to use the antivirus feature or to say you have XDR, but in reality you are not using it. The solution should include an on-premises option because some customers want only on-premises. It would be hard, but good to do if possible. Open XDR would be beneficial in the future. Right now, the solution is Closed XDR so cannot communicate with the few new vendors in the Open XDR market.
Vibhor Goel - PeerSpot reviewer
A single tool for complete visibility and addressing security gaps
Currently, issues are structured in Microsoft Defender for Cloud at severity levels of high, critical, or warning, but these severity levels are not always right. For example, Microsoft might consider a port being open as critical, but that might not be the case for our company. Similarly, it might suggest closing some management ports, but you might need them to be able to log in, so the severity levels for certain things can be improved. Even though Microsoft Defender for Cloud provides a way to temporarily disable certain alerts or notifications without affecting our security score, it would be better to have more granularized control over these recommendations. Currently, we cannot even disable certain alerts or notifications. There should be an automated mechanism to design Azure policies based on the recommendations, possibly with AI integration. Instead of an engineer having to write a policy to fix security gaps, which is very time-consuming, there should be an inbuilt capability to auto-remediate everything and have proper control in place. Additionally, enabling Defender for Cloud at the resource group level, rather than only at the subscription level, would be beneficial.
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
831,683 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
9%
Government
8%
Manufacturing Company
7%
Computer Software Company
15%
Financial Services Firm
13%
Manufacturing Company
9%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. The ability to reverse damage caused by ransomware with minimal interruptions to...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions that are very scalable, secure, and user-friendly. Cortex XDR by Palo Alto offers ...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface, applies behavioral-based endpoint protection and response, and includes risk-ba...
How is Prisma Cloud vs Azure Security Center for security?
Azure Security Center is very easy to use, integrates well, and gives very good visibility on what is happening across your ecosystem. It also has great remote workforce capabilities and supports a...
What do you like most about Microsoft Defender for Cloud?
The entire Defender Suite is tightly coupled, integrated, and collaborative.
What is your experience regarding pricing and costs for Microsoft Defender for Cloud?
The licensing is straightforward but can become expensive if you cover everything. You must balance the cost against the importance of what needs covering.
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Microsoft Azure Security Center, Azure Security Center, Microsoft ASC, Azure Defender
 

Interactive Demo

Demo not available
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Microsoft Defender for Cloud is trusted by companies such as ASOS, Vatenfall, SWC Technology Partners, and more.
Find out what your peers are saying about Cortex XDR by Palo Alto Networks vs. Microsoft Defender for Cloud and other solutions. Updated: September 2023.
831,683 professionals have used our research since 2012.