

Find out in this report how the two Microsoft Security Suite solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
We can quarantine and isolate a device within minutes.
Microsoft Defender XDR has saved me at least 50% of my time.
It helped stop multiple intrusion points where we would have had millions in lost revenue if the attackers got in.
Purview can do a quick scan, and it doesn't use human resources, so it gets time to do things that we need humans to focus on.
The E5 license comes with different solutions like data discovery classification, CASB, DLP solutions, and Defender for Cloud.
The cost of data loss and your data going to a competitor is potentially massive.
You get stuck in low-level support for way longer than you should, instead of them escalating the issue up the chain.
It's critical to escalate SEV B issues immediately to a domestic engineer.
Once issues are escalated to the second or third layer, the support is much better.
Sometimes, I get a fast and knowledgeable response, while other times, I've experienced delays and received no resolution.
It's hard to be an ambassador for a product when you know it will be hard to get support.
After our issues are reported, it takes a long time to find a resolution.
My concern is about the scale of events and alerts being generated, and the product is doing a very good job of only surfacing the important items for us.
It has a very good integration system that integrates with all Azure services, all threat intelligence data models, and integrates very well with other systems such as Palo Alto.
Microsoft Defender XDR shows tremendous scalability, much more so than on-premises solutions.
It can be scaled across different departments organization-wide very quickly and easily.
It can handle large collections of data without issues.
Scalability can be improved by reducing these intervals.
The service has remained consistently online, with any issues isolated to specific components, suggesting a well-designed and modular architecture.
The services within our ecosystem have been reliable, meeting their SLAs.
It provides high-fidelity signals.
Once implemented, I haven't had issues with its consistency.
The product is stable, and whatever it does, it does better than any other thing.
Since identity is where everything is based, if that goes down, you're screwed.
The licensing process needs improvement and clarification.
Improvements are needed in automated response capabilities.
If you have a central location where you perform one isolation method, all other potentially affected systems that have been touched may also be isolated simultaneously.
Effectiveness in Microsoft Purview Information Protection means enforcing the policy and making sure it works consistently across non-Microsoft products as well.
A lot of functionality in Microsoft Purview Information Protection is not exposed in an API officially yet, which has made a lot of implementation work difficult because we have to do click ops instead of DevOps.
Having a roadmap or updates about new releases would be helpful for demonstrating to clients.
There are certainly savings when using Microsoft Defender XDR, which can range from 30%, 40%, and even up to 50%.
Otherwise, combining multiple Microsoft Defender components can get expensive.
I would rate the pricing as eight out of ten, indicating it is a reasonable cost for the product.
I talked to people who had compared it to other products on the market, and they're spending five figures to get started.
The E5 license covers most of the solutions for different technologies, so that way, it is good and more affordable compared to any other solution.
Our focus is on helping customers maximize their software investment.
With Microsoft threat intelligence information, it detects various types of threats, including insider attacks, malicious content, and data exfiltration.
This allows us to secure our systems in advance and proactively improve security, rather than waiting for incidents to occur.
Once we have it on the security dashboard, we can see a real-time storyline.
Microsoft Copilot is an advantage because it's enterprise-grade AI.
It's paramount to have a single solution for information protection.
Regardless of the education, the employee might share the information anyway, so the AI shouldn't be the first point of failure. It should be a human making good decisions.
| Product | Mindshare (%) |
|---|---|
| Microsoft Defender XDR | 5.5% |
| Microsoft Purview Information Protection | 2.3% |
| Other | 92.2% |


| Company Size | Count |
|---|---|
| Small Business | 46 |
| Midsize Enterprise | 27 |
| Large Enterprise | 40 |
| Company Size | Count |
|---|---|
| Small Business | 5 |
| Midsize Enterprise | 4 |
| Large Enterprise | 14 |
Microsoft Defender XDR is a comprehensive security solution designed to protect against threats in the Microsoft 365 environment.
It offers robust security measures, comprehensive threat detection capabilities, and an efficient incident response system. With seamless integration with other Microsoft products and a user-friendly interface, it simplifies security management tasks.
Users have found it effective in detecting and preventing various types of attacks, such as phishing attempts, malware infections, and data breaches.
Watch the Microsoft demo video here: Microsoft Defender XDR demo video.
Microsoft Purview Information Protection offers sensitivity labels, automated classification, and encryption to protect data across platforms while integrating with M365, Azure, and AWS to prevent unauthorized access and enhance data governance.
Microsoft Purview Information Protection supports compliance with regulatory standards through features like data loss prevention and intuitive DLP rules. It integrates with multiple platforms such as M365, Azure, and AWS for extensive data protection. The platform helps manage sensitive data through automated labeling and effective policy deployment. While there are areas needing improvement like third-party integration, API support, and policy enforcement consistency, Purview remains a powerful tool for businesses to assess data usage and reduce unauthorized access.
What are the key features of Microsoft Purview Information Protection?Companies across various industries implement Microsoft Purview Information Protection to apply sensitivity labels to emails and cloud content like OneDrive and SharePoint. It's utilized for data classification, loss prevention, and governance. Microsoft partners use it for SAP integration and compliance assessments, while consultants focus on protecting and managing data efficiently for clients centered around Microsoft solutions.
We monitor all Microsoft Security Suite reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.