

Microsoft Defender for Identity and SentinelOne Singularity Identity both compete in the threat detection and identity protection domain. While Microsoft's Defender benefits from its extensive integration across Microsoft's ecosystem, SentinelOne shines with its robust AI-driven detection capabilities and user-friendly management console.
Features: Microsoft Defender for Identity includes integration capabilities across Microsoft's ecosystem, effective threat detection and identity protection, and seamless sync between on-premises and cloud environments. SentinelOne Singularity Identity offers advanced behavioral analysis, dynamic threat detection, and a user-friendly management console that provides a unified view of potential threats.
Room for Improvement: Microsoft Defender for Identity needs improvement in sensor impact on domain controllers, integration between Azure ID and on-premises, and direct issue remediation from the console. SentinelOne Singularity Identity would benefit from enhanced endpoint management, better support structures, and additional features for precise control over web filtering and settings.
Ease of Deployment and Customer Service: Both Microsoft Defender for Identity and SentinelOne Singularity Identity support cloud and on-premises deployment options. Microsoft receives praise for knowledgeable staff but faces challenges with delayed responses, whereas SentinelOne excels in platform integration but could improve in first-level support and performance issue handling.
Pricing and ROI: Microsoft Defender for Identity is costly unless bundled yet offers significant ROI through reduced security costs and time savings. SentinelOne Singularity Identity, though seen as pricey due to cost increments, presents competitive pricing with significant ROI through its advanced detection capabilities and reduced resolution time.
I have reduced the identity threat detection time from hours to ten to fifteen minutes, which directly lowers my risk exposure.
Generally, the support is more effective than other providers like Oracle.
The quality of support is very good, but troubleshooting can take time due to complex setups and the need to provide many logs.
The people I normally use for support are very knowledgeable, especially when they help remote in and get to where I need to go and show me much faster and help me understand what I should be doing.
They have been responsive to our needs as integrators and those of the client.
The scalability of Microsoft Defender for Identity has been strong for me because it scales easily across large Active Directory environments since the sensors sit on domain controllers and processing is cloud-side.
In a Microsoft-centric organization, especially with Azure infrastructure and Office 365, Microsoft Defender for Identity is scalable.
Microsoft Defender for Identity is quite robust and built on Azure hyperscale infrastructure, with a 99% availability.
We do not see any issues with the stability of Microsoft Defender for Identity.
Having recently started using it, reliability is affirmed, but manual investigation is often performed to verify if alerts identified by auto-remediation are accurate.
If Microsoft could develop a feature that indicates when impossible travel is caused by VPN connections, it would prevent unnecessary password resets and session disruptions, especially for VIP users in organizations.
One improvement I would recommend is the integration of an admin application within Teams, allowing easy access to attack information on a mobile platform.
Reducing false positives is something we've been working on with Microsoft.
There is a clear roadmap for improvements, including enhancing capabilities with AI and seamless functionality in an MSP model for deeper visibility across multiple agencies.
If they can reduce the costs, organizations will be happy, and it will compensate for using the Azure environment, which is more expensive on the infrastructure as a service side.
Ensuring a fair price according to market standards.
From an organization perspective, using E5 licenses is value for money, especially if Azure and Office 365 are already in use.
We receive an advance report of risky users, allowing us to take preemptive action before an attack causes damage to organization details.
Microsoft Defender for Identity offers advanced identity threat detection because it is strong at catching Kerberos abuse, pass the hash, DC Sync abuse, and lateral movement using behavioral analytics.
The most valuable feature is its hybrid artificial intelligence, which gathers forensic data to track and counteract security threats, much like the CSI series in effect.
With visibility into endpoint telemetry, SentinelOne does provide useful information to find threat actors and empowers those who are in the business of threat hunting.
| Product | Mindshare (%) |
|---|---|
| Microsoft Defender for Identity | 3.6% |
| SentinelOne Singularity Identity | 2.0% |
| Other | 94.4% |


| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 5 |
| Large Enterprise | 14 |
| Company Size | Count |
|---|---|
| Small Business | 4 |
| Midsize Enterprise | 5 |
| Large Enterprise | 13 |
Microsoft Defender for Identity offers real-time threat detection and protection for hybrid Active Directory environments. It integrates with Microsoft 365 components for seamless security and monitors advanced behaviors, enhancing identity protection across cloud and on-premises environments.
Microsoft Defender for Identity provides detailed threat insights and user behavior analytics to detect unauthorized access and notify anomalies. It allows setting custom detection rules, enhancing threat response automation. While it needs improvements in cloud security, SIEM integration, and access controls, users leverage its ability to mitigate identity threats like suspicious logins and ransomware. Enhanced integration with Microsoft security products ensures a coordinated threat response for identity control and privilege management.
What are the key features of Microsoft Defender for Identity?In specific industries, organizations implement Microsoft Defender for Identity to secure on-premises and hybrid Active Directory environments through user and entity behavior analytics, malicious activity detection, and integration with Microsoft security tools. This approach enhances security posture assessment and helps mitigate identity threats like identity harvesting and unauthorized access.
SentinelOne Singularity Identity offers AI-driven detection, prevention, and cloud protection, providing real-time coverage and streamlined security management through its unified console and customizable interface.
Singularity Identity enhances threat detection with dynamic capabilities, facilitating real-time protection and easy user workflows. Its management console offers a unified view for deeper risk analysis, boosting operational security. Through behavioral analysis and adaptable interfaces, threat response becomes efficient. Key elements include identity guarding and quick incident mitigation. Automated remediation options and rollback features are impactful, ensuring decreased response times. Challenges include improving user accessibility, especially for non-IT individuals, and enhancing customer support with faster solutions and robust reporting. Performance issues like CPU usage demand solutions, while endpoint management and agent updates could benefit from automation. Adding network response features and lowering costs may enhance engagement.
What are the most important features?Industries leverage SentinelOne Singularity Identity for comprehensive threat monitoring across networks. It ensures cloud and endpoint security, plus control over identity and data breaches. By replacing outdated antivirus systems, organizations emphasize proactive defense, visibility, incident response, and detecting lateral movements. Implementing this solution supports strong network and endpoint security, enhances cloud management, and maintains a robust security framework.
We monitor all Advanced Threat Protection (ATP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.