CrowdStrike Falcon and Microsoft Defender for Cloud are competitors in the cybersecurity solutions category. CrowdStrike Falcon seems to have an edge in endpoint detection with its robust EDR capabilities and cloud-native architecture, while Microsoft Defender for Cloud stands out for its threat intelligence and integration within the Azure ecosystem, appealing more to users seeking comprehensive cloud workload protection.
Features: CrowdStrike Falcon provides robust EDR capabilities, comprehensive endpoint visibility, and remote connectivity for manual analysis. Its cloud-native architecture is particularly valued by users. Microsoft Defender for Cloud is noted for threat intelligence, seamless Azure integration, and compliance management, which enhance security for cloud workloads.
Room for Improvement: CrowdStrike Falcon could benefit from better integration with other security systems and enhancements in reporting and dashboard functionality. Microsoft Defender for Cloud needs to improve user interfaces, documentation, pricing transparency, and false-positive reduction for a better user experience.
Ease of Deployment and Customer Service: CrowdStrike Falcon's deployment is straightforward across cloud environments, supported by responsive customer service. However, improvements in response times are needed. Microsoft Defender for Cloud integrates well within Azure but can cause confusion due to its ecosystem's complexity, indicating a need for clearer communication and support.
Pricing and ROI: CrowdStrike Falcon is a premium product offering a strong ROI, despite higher costs, through its effective threat management and flexible pricing. Microsoft Defender for Cloud offers competitive pricing for Azure users, but its complex pricing model still provides good integration value. Both solutions deliver significant ROI, with CrowdStrike focused on endpoint protection and Microsoft on cloud integration.
Defender proactively indexes and analyzes documents, identifying potential threats even when inactive, enhancing preventative security.
Identifying potential vulnerabilities has helped us avoid costly data losses.
The biggest return on investment is the rapid improvement of security posture.
The CrowdStrike team is very efficient; I would rate them ten out of ten.
Since security is critical, we prefer a quicker response time.
The support team was very responsive to queries.
They understand their product, but much like us, they struggle with the finer details, especially with new features.
It has adequate coverage and is easy to deploy.
When it comes to scalability, it is entirely based on premium models according to demand.
We are using infrastructure as a code, so we do not have any scalability issues with Microsoft Defender for Cloud implementation because our cloud automatically does it.
It has multiple licenses and features, covering infrastructures from a hundred to five hundred virtual machines, without any issues.
Defender won't replace our endpoint XDR, but it will likely adapt and support any growth in the Microsoft Cloud space.
I have never seen instability in the CrowdStrike tool.
We are following N-1 versions across our environment, which is stable.
Defender's stability has been flawless for us.
Microsoft Defender for Cloud is very stable.
Microsoft sometimes changes settings or configurations without transparency.
Simplifying the querying process, such as using double quote queries or directly obtaining logs based on IP addresses or usernames, would be beneficial.
Another concern is CrowdStrike's GUI. It changes annually, making it hard to work and find options.
Threat prevention should be their first priority.
Microsoft, in general, could significantly improve its communication and support.
It would be beneficial to streamline recommendations to avoid unnecessary alerts and to refine the severity of alerts based on specific environments or environmental attributes.
The artificial intelligence features could be expanded to allow the system to autonomously manage security issues without needing intervention from admins.
It is expensive compared to SentinelOne, but as the market leader, it is worth it.
Every time we consider expanding usage, we carefully evaluate the necessity due to cost concerns.
We appreciate the licensing approach based on employee count rather than a big enterprise license.
Microsoft Defender for Cloud is pricey, especially for Kubernetes clusters.
I can investigate by accessing the customer's host based on the RTR environment and utilize host search to know details for the past seven days, including logins, processes, file installations, malicious processes, and network connections.
The machine learning behavior for anomaly detection is a valuable feature.
Real-time response (RTR) is a feature of EDR.
The most valuable feature for me is the variety of APIs available.
This feature significantly aids in threat detection and enhances the user experience by streamlining security management.
The most valuable feature is the recommendations provided on how to improve security.
CrowdStrike Falcon provides endpoint protection and threat intelligence using a cloud-based platform for real-time detection and response. Its minimal impact on system performance and ease of deployment are key benefits along with advanced logging and reporting for compliance and forensic analysis.
CrowdStrike Falcon is known for its efficacy in identifying malware, ransomware, and sophisticated cyber threats. The platform's cloud-native architecture and advanced AI capabilities ensure comprehensive endpoint visibility and rapid response times. Users appreciate the lightweight agent and seamless deployment process, along with detailed reporting features. Integration with security tools and efficient customer support are essential features, although some users highlight high pricing, occasional detection delays, and challenges with integration. Frequent alerts and the mobile app's performance are areas for improvement.
What are the key features of CrowdStrike Falcon?
What are the benefits or ROI of CrowdStrike Falcon?
In industries like finance, healthcare, and retail, CrowdStrike Falcon is often used for critical security due to its robust threat detection capabilities. Financial firms value its rapid response and detailed reporting for compliance, while healthcare providers appreciate the minimal system performance impact. Retailers benefit from its comprehensive endpoint visibility and integration with other security tools.
Microsoft Defender for Cloud is a comprehensive security solution that provides advanced threat protection for cloud workloads. It offers real-time visibility into the security posture of cloud environments, enabling organizations to quickly identify and respond to potential threats. With its advanced machine learning capabilities, Microsoft Defender for Cloud can detect and block sophisticated attacks, including zero-day exploits and fileless malware.
The solution also provides automated remediation capabilities, allowing security teams to quickly and easily respond to security incidents. With Microsoft Defender for Cloud, organizations can ensure the security and compliance of their cloud workloads, while reducing the burden on their security teams.
We monitor all Extended Detection and Response (XDR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.