CrowdStrike Falcon and Microsoft Sentinel are competitors in the cybersecurity solutions market. CrowdStrike Falcon seems to have the upper hand in ease of deployment and user experience, while Microsoft Sentinel stands out in integration and automation features.
Features: CrowdStrike Falcon shines with its robust EDR capabilities, real-time response, and threat intelligence that provides endpoint protection and remediation remotely. It offers valuable features like forensics and network isolation. Microsoft Sentinel is known for its comprehensive threat intelligence, user behavior analytics, and built-in SOAR capabilities, which support automated incident response and advanced threat detection, making it a powerhouse in security operations.
Room for Improvement: CrowdStrike Falcon has room to improve in reporting and integrations with other technologies, and better support for non-domain machines would enhance its utility. It lacks a DLP feature and the GUI speed along with false positive rates could be optimized. Microsoft Sentinel's complexity in pricing and log ingestion costs could be simplified, and more out-of-the-box analytics rules and enhanced AI and automation features are needed. Better integration options and documentation are also suggested areas for improvement.
Ease of Deployment and Customer Service: CrowdStrike Falcon is praised for its straightforward deployment and user-friendly interface, though its technical support may need quicker response times. Microsoft Sentinel, integrated well with the Azure ecosystem, is highly rated for ease of use despite its complex configurations, and provides solid customer support as part of Microsoft's service offering.
Pricing and ROI: CrowdStrike Falcon is considered expensive but valued for its security benefits, potentially justifying the cost for large enterprises, though the pricing might be a barrier for smaller businesses. Its ROI is reflected in resource savings and enhanced security measures. Microsoft Sentinel's pay-as-you-go model based on data ingestion might be costly but offers value through advanced features, especially when data ingestion is carefully managed, making both solutions valuable investments in threat mitigation.
Their solutions' integration simplifies resolving issues compared to those caused by third-party products.
Working with a Sentinel engineer helped us tune settings effectively.
Office 365 and Exchange are running on it, covering about 35,000 users efficiently.
As our organization uses Microsoft Azure and Defender, everything grows together, and we can integrate various features seamlessly.
So far, we have not experienced any issues, and it has been stable from the beginning.
Sentinel's stability is great.
We have some tools, such as our off-site Meraki firewalls, that have not fully integrated with Sentinel.
Currently, we are happy to have a way in the middle with not so much cost, but it would be nice to have the ability to enhance the automation of workflows based on learned incidents.
We already had the necessary licensing for Sentinel, so we didn't need to spend extra money.
Custom workbooks are valuable. It is one of the crucial points in dealing with potential security threats in an automated way without requiring too much manpower.
CrowdStrike Falcon provides endpoint protection and threat intelligence using a cloud-based platform for real-time detection and response. Its minimal impact on system performance and ease of deployment are key benefits along with advanced logging and reporting for compliance and forensic analysis.
CrowdStrike Falcon is known for its efficacy in identifying malware, ransomware, and sophisticated cyber threats. The platform's cloud-native architecture and advanced AI capabilities ensure comprehensive endpoint visibility and rapid response times. Users appreciate the lightweight agent and seamless deployment process, along with detailed reporting features. Integration with security tools and efficient customer support are essential features, although some users highlight high pricing, occasional detection delays, and challenges with integration. Frequent alerts and the mobile app's performance are areas for improvement.
What are the key features of CrowdStrike Falcon?
What are the benefits or ROI of CrowdStrike Falcon?
In industries like finance, healthcare, and retail, CrowdStrike Falcon is often used for critical security due to its robust threat detection capabilities. Financial firms value its rapid response and detailed reporting for compliance, while healthcare providers appreciate the minimal system performance impact. Retailers benefit from its comprehensive endpoint visibility and integration with other security tools.
Microsoft Sentinel is a scalable, cloud-native, security information event management (SIEM) and security orchestration automated response (SOAR) solution that lets you see and stop threats before they cause harm. Microsoft Sentinel delivers intelligent security analytics and threat intelligence across the enterprise, providing a single solution for alert detection, threat visibility, proactive hunting, and threat response. Eliminate security infrastructure setup and maintenance, and elastically scale to meet your security needs—while reducing IT costs. With Microsoft Sentinel, you can:
- Collect data at cloud scale—across all users, devices, applications, and infrastructure, both on-premises and in multiple clouds
- Detect previously uncovered threats and minimize false positives using analytics and unparalleled threat intelligence from Microsoft
- Investigate threats with AI and hunt suspicious activities at scale, tapping into decades of cybersecurity work at Microsoft
- Respond to incidents rapidly with built-in orchestration and automation of common tasks
To learn more about our solution, ask questions, and share feedback, join our Microsoft Security, Compliance and Identity Community.
We monitor all Security Information and Event Management (SIEM) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.