Microsoft Defender for Cloud Apps and Microsoft Defender for Identity are both contenders in the cloud security market. Defender for Cloud Apps has the upper hand in application threat visibility, while Defender for Identity excels in identity and posture management.
Features: Microsoft Defender for Cloud Apps integrates across various clouds, prioritizing user management and threat detection with extensive application discovery to monitor user activities. Its threat visibility across applications is exceptional. Microsoft Defender for Identity focuses on identity security, providing insights into Active Directory and protecting both on-premises and cloud identities through robust threat detection and AI-driven insights.
Room for Improvement: Microsoft Defender for Cloud Apps struggles with macOS integration and could improve false positive rates and reporting features. Simplified pricing and better third-party tool integration are also desirable. Microsoft Defender for Identity's anomaly detection and data correlation need enhancement, as well as alert precision and administrative usability. Both would benefit from stronger third-party integrations and reporting.
Ease of Deployment and Customer Service: Microsoft Defender for Cloud Apps is versatile, deployed in Hybrid and Public Cloud environments, yet suffers from inconsistent support experiences. Microsoft Defender for Identity is mainly deployed in Public Cloud and on-premises environments. While technical support is competent, reaching the right level remains challenging for both, requiring improved responsiveness and streamlined support.
Pricing and ROI: Microsoft Defender for Cloud Apps is bundled into packages like Microsoft 365 E3 and E5, offering cost benefits within the Microsoft ecosystem. However, standalone pricing is less appealing. It demonstrates strong ROI through better security and reduced costs. Microsoft Defender for Identity integrates into Microsoft E5, noted for its premium pricing. Its comprehensive security features yield high ROI, especially within a broader Microsoft license.
The biggest return on investment so far has been visibility, knowing what we have in our environment.
Their customer service is pretty good, but it's frustrating to go through three or four channels before reaching the right person.
Generally, the support is more effective than other providers like Oracle.
For what I know about the log collector and how much data it can take in, it is super scalable and capable of handling high workloads.
Like any other Microsoft product, the uptime is good.
We are having trouble with our continuous reporting configuration and struggling with configuring the collector properly with our log parsing.
One improvement I would recommend is the integration of an admin application within Teams, allowing easy access to attack information on a mobile platform.
Ensuring a fair price according to market standards.
We have also locked down our consent apps, so users can no longer consent on their own behalf to create apps in our environment.
The most valuable feature is its hybrid artificial intelligence, which gathers forensic data to track and counteract security threats, much like the CSI series in effect.
Microsoft Defender for Cloud Apps is a comprehensive security solution that provides protection for cloud-based applications and services. It offers real-time threat detection and response, as well as advanced analytics and reporting capabilities. With Defender for Cloud Apps, organizations can ensure the security of their cloud environments and safeguard against cyber threats. Whether you're running SaaS applications, IaaS workloads, or PaaS services, Microsoft Defender for Cloud Apps can help you secure your cloud environment and protect your business from cyber threats.
Reviews from Real Users
Ram-Krish, Cloud Security & Governance at a financial services firm, says that Microsoft Defender for Cloud Apps "Integrates well and helps us in protecting sensitive information, but takes time to scan and apply the policies and cannot detect everything we need".
PeerSpot user, Senior Cloud & Security Consultant at a tech services, writes that Microsoft Defender for Cloud Apps "Great for monitoring user activity and protecting data while integrating well with other applications".
Simon Burgess,Infrastructure Engineer at SBITSC, states that Microsoft Defender for Cloud Apps is "A fluid, intelligent product for great visibility, centralized management, and increased uptime".
Microsoft Defender for Identity integrates with Microsoft tools to monitor user activity, providing advanced threat detection and analysis using AI. It enhances proactive threat response and security visibility, making it essential for securing on-premises and cloud environments like Active Directory.
Microsoft Defender for Identity offers comprehensive monitoring and AI-driven user behavior analysis. It detects threats through real-time alerts and identifies lateral movements and entity tagging, ensuring robust security management. With excellent visibility via its dashboard, it supports customized detection rules and seamlessly integrates with SIEM platforms. While SecureScore and SecureScan provide robust environment security, there is room for improvement in cloud security, on-premises application integration, and remediation capabilities. Azure integration is limited, and the administrative interface could be more user-friendly. Users experience frequent false positives, affecting threat detection efficiency.
What key features stand out in Microsoft Defender for Identity?In specific industries such as education and finance, Microsoft Defender for Identity is crucial for securing on-premises Active Directory and Azure Active Directory environments. It effectively detects suspicious activities and manages conditional access policies, offering user and entity behavior analytics, endpoint detection and response capabilities. This helps prevent unauthorized access and strengthens overall security, making it an invaluable asset for organizations aiming to safeguard their digital infrastructure.
We monitor all Advanced Threat Protection (ATP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.