Cortex XDR by Palo Alto Networks and Microsoft Defender XDR compete in the extended detection and response (XDR) category. Microsoft Defender XDR seems to have the upper hand due to its seamless integration with Microsoft products and extensive analytics features.
Features: Cortex XDR boasts robust threat detection capabilities with advanced machine learning, behavior-based detection, and integration with firewalls providing comprehensive security for endpoint protection. Microsoft Defender XDR emphasizes its integration with Microsoft products, advanced threat hunting, and automated response, supported by seamless integration with cloud services and extensive analytics.
Room for Improvement: Cortex XDR needs to reduce false positives, improve user experience with better reporting, and provide on-premises solutions for data residency requirements. It could also enhance its automation and integration options. Microsoft Defender XDR could improve third-party integration, speed up support response, and enhance the usability of its interface, especially for threat detection and automation.
Ease of Deployment and Customer Service: Both solutions offer various deployment options, including public, private, and hybrid cloud environments. Cortex XDR's customer service gets mixed reviews regarding responsiveness, while Microsoft's support is praised for strong integration assistance but could be more responsive in resolving technical issues.
Pricing and ROI: Cortex XDR is perceived as expensive compared to competitors but valued for its security features and operational savings for large enterprises. Microsoft's pricing, bundled with its services, is considered manageable with good ROI, though some users find it complex and variable by region. Both products are recognized for significant ROI in operational security improvements and reduced threat management workload.
They appreciate the rich telemetry data from the solution, as it provides in-depth threat identification.
Ever since we turned on the M5 feature set back in June, we have seen a reduced number of potentially malicious clicks and faster alerting when incidents occur.
Every vendor has similar support; it depends on how the case is handled and raised.
It's critical to escalate SEV B issues immediately to a domestic engineer.
You get stuck in low-level support for way longer than you should, instead of them escalating the issue up the chain.
The technical support from Microsoft Defender XDR has been disappointingly slow.
Microsoft Defender XDR shows tremendous scalability, much more so than on-premises solutions.
It is suitable for enterprise-level deployment but has room for improvement.
Cortex XDR is stable, offering high quality and reliable performance.
The service has remained consistently online, with any issues isolated to specific components, suggesting a well-designed and modular architecture.
The services within our ecosystem have been reliable, meeting their SLAs.
Cortex XDR could improve its sales support team, including better commission structures and referral programs.
The licensing process needs improvement and clarification.
Improvements are needed in automated response capabilities.
It would be better if much of that information were immediately visible, especially when looking at endpoints or users.
Cortex XDR is perceived as expensive by some customers, yet offers dynamic pricing.
I would rate the pricing as eight out of ten, indicating it is a reasonable cost for the product.
Microsoft purposefully obfuscates this through marketing ploys to hide costs.
Licensing is somewhat confusing, particularly when presenting our pitch decks to stakeholders and leveraging key features in premium SKUs, but we managed with some assistance from Microsoft.
It incorporates AI for normal behavior detection, distinguishing unusual operations.
With Microsoft threat intelligence information, it detects various types of threats, including insider attacks, malicious content, and data exfiltration.
The Email Explorer feature has proven invaluable, offering a broader perspective than automated alerts and incidents alone.
The email protection feature is the most valuable because our risks primarily lie there, and it seems to be the most popular target.
Cortex XDR by Palo Alto Networks is the first threat detection and response software to combine both visibility across all types of data as well as autonomous machine learning analytics. Threat detection very often requires analysts to divide their attention among many different data streams. This platform unifies a vast variety of data flows, which allows analysts to assess threats from a single location. Users can now maintain a level of visibility that other threat detection programs simply cannot offer. This level of transparency lends itself to both quick identification of problems that arise and the equally quick development of a potential solution.
Cortex XDR’s machine learning works on many different levels to detect and prevent threats. It is constantly scanning for threats and vulnerabilities. The solution can scan up to 5.4 billion IP addresses in three-quarters of an hour. This allows it to spot weak points in the system and notify administrators long before hackers can take advantage of vulnerabilities. Once the Artificial Intelligence (AI) discovers an issue or an area where an issue could potentially take place the system creates a log of the information and subsequently sends an alert to system administrators. The AI takes the information that it has gathered and uses it to assign threat levels to the issues that it detects. Following this, a human analyst will be assigned to manually assess the issue and deal with it accordingly. You can set it to automatically respond to the threat by isolating the issue while analysts investigate it.
Benefits of Cortex XDR
Some of Cortex XDR’s benefits include:
Reviews from Real Users
Cortex XDR by Palo Alto Networks software stands out among its competitors for a number of reasons. Two major ones are its ability to isolate threats while enabling them to be studied and the way that the software combines all of the data that it gathers into a single, more complete picture than other solutions offer.
PeerSpot users note the effectiveness of these features. A network designer at a computer software company wrote, “The solution has a very helpful isolation feature. If any system gets compromised, with one click I can access the system and isolate it from other networks, and then go into further forensic investigation of the current threat without compromising anything else.”
Jeff W., Vice President/CTO at Sinnott Wolach Technology Group, noted, “The ability to kind of stitch everything together and see the actual complete picture is very useful. I guess you'd call it a playbook. Some people call it the forensics analysis of what was happening on particular endpoints when they detected some malicious behavior, and what transpired before that to cause that. It is also very user friendly.”
Microsoft Defender XDR is a comprehensive security solution designed to protect against threats in the Microsoft 365 environment.
It offers robust security measures, comprehensive threat detection capabilities, and an efficient incident response system. With seamless integration with other Microsoft products and a user-friendly interface, it simplifies security management tasks.
Users have found it effective in detecting and preventing various types of attacks, such as phishing attempts, malware infections, and data breaches.
Watch the Microsoft demo video here: Microsoft Defender XDR demo video.
We monitor all Extended Detection and Response (XDR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.