Try our new research platform with insights from 80,000+ expert users

Microsoft Purview eDiscovery vs Microsoft Sentinel comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Room For Improvement

Sentiment score
5.5
Microsoft Purview eDiscovery faces tagging issues, slow search, workflow disruptions, and limited compatibility compared to specialized legal tools.
Sentiment score
5.0
Microsoft Sentinel users want better integration, more tools, improved UI, clearer documentation, reduced costs, and enhanced alert system.
Adding more features, as Microsoft continues to expand their cloud offerings, would be beneficial.
 

Setup Cost

No sentiment score available
Microsoft Purview eDiscovery is costly for users, with E5 licenses offering benefits but standard editions and compliance challenges persist.
Sentiment score
5.2
Microsoft Sentinel offers value through integration but requires careful cost management due to its complex, consumption-based pricing model.
With CSP or MCE-style agreements with Microsoft, the process is streamlined since we have reps from both Microsoft and CDW working together.
 

Valuable Features

Sentiment score
8.3
Microsoft Purview eDiscovery offers comprehensive data search, compliance, and protection across platforms, supporting legal and international enterprise needs.
Sentiment score
8.5
Microsoft Sentinel offers seamless integration, automation, AI capabilities, and scalable threat detection, enhancing security with cost-effectiveness and efficient monitoring.
The most valuable feature of Microsoft Purview eDiscovery is its ability to search across various platforms, including Exchange, SharePoint, Teams, and OneDrive.
 

Customer Service

No sentiment score available
Sentiment score
7.3
Microsoft Sentinel support is generally positive, with mixed reviews on responsiveness and the necessity for premium support tiers.
 

Scalability Issues

No sentiment score available
Sentiment score
8.1
Microsoft Sentinel offers scalable, automatic resource adjustments, multi-region support, and extensive data integration, adapting to diverse organizational needs.
It scales with us seamlessly.
 

Stability Issues

No sentiment score available
Sentiment score
8.4
Microsoft Sentinel is highly stable and reliable, with 99.9% availability, despite some integration and log ingestion issues.
Microsoft Purview eDiscovery is highly reliable.
 

Categories and Ranking

Microsoft Purview eDiscovery
Ranking in Microsoft Security Suite
26th
Average Rating
7.6
Reviews Sentiment
7.5
Number of Reviews
4
Ranking in other categories
eDiscovery (3rd)
Microsoft Sentinel
Ranking in Microsoft Security Suite
5th
Average Rating
8.2
Reviews Sentiment
7.4
Number of Reviews
89
Ranking in other categories
Security Information and Event Management (SIEM) (2nd), Security Orchestration Automation and Response (SOAR) (1st)
 

Mindshare comparison

As of November 2024, in the Microsoft Security Suite category, the mindshare of Microsoft Purview eDiscovery is 0.7%, down from 0.9% compared to the previous year. The mindshare of Microsoft Sentinel is 5.6%, down from 6.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Microsoft Security Suite
 

Featured Reviews

Mike McBride - PeerSpot reviewer
It has improved visibility and simplified data review, but it lacks many features found in specialized tools
I see two significant challenges with many of my clients. One is that there are some functionality gaps compared to specialized tools in the legal industry, like a legal hold tool or a document review tool. They have features that Purview eDiscovery lacks. Those gaps create a situation where I almost have to do things twice. I need to collect all my data in eDiscovery and ship it to another platform to complete the review. For example, you can't date stamp documents. I have to put them in another tool to do that. It has legal hold notifications and various decent features, but other tools have more functionality. Those are some minor challenges and gaps, but I wouldn't want to solve the larger issues myself. The other problem is that it's changing all the time. Microsoft has an excellent platform, and they're constantly updating 365. It creates an issue for eDiscovery users when Microsoft makes those changes behind the scenes, and you're unaware. I've experienced this. We were getting ready to have a training session with a customer, and the interface differed when we logged in the next day. It's a general issue with SaaS and cloud-native products, not just Microsoft. With an on-prem solution, I can see that I'm at version 10.0.1, and here are all the new features in the release notes. However, in 365, I'm wherever Microsoft tells me I am, and I never know when new features will hit. I can't stop them from being implemented. I wake up one day to see that everything has changed, and now I need to figure out how it will impact my workflow. It might not even be a change to an eDiscovery feature. You'd be talking about something like loops or any new product. How do I collect this? How does it work with eDiscovery? It's almost a full-time job keeping track of these changes.
Nitin Arora - PeerSpot reviewer
Gives us one place to investigate and respond to threats, and automation eliminates manual work
They can work on the EDR side of things. It is already really superb, because of the kinds of features we get with the EDR solution. It's not a standard EDR and they have recently enhanced things. But the problem is with onboarding devices. I have different OS flavors, including a large number of Linux, Windows, macOS, and some on-prem machines as well. Every time we need to onboard these kinds of machines into the EDR, we need to do it with the help of Intune, to sync up the devices, and do the configuration. I'm looking for something on the EDR side that will reduce this kind of work. They can eliminate having to do manual configuration for the machines, and check the different types of configurations for each OS. In some cases, it does not support some OSs. If they could reduce this type of work, that would be really amazing.
report
Use our free recommendation engine to learn which Microsoft Security Suite solutions are best for your needs.
816,562 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Government
12%
Computer Software Company
11%
University
6%
Computer Software Company
16%
Financial Services Firm
10%
Government
8%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Microsoft Purview eDiscovery?
The tool has been beneficial. Some of our previous users left the organization without sharing the information they had at a personal level. This information was related to the organization, and th...
What is your experience regarding pricing and costs for Microsoft Purview eDiscovery?
Microsoft Purview eDiscovery comes as part of Microsoft 365 licenses.
What needs improvement with Microsoft Purview eDiscovery?
Microsoft Purview eDiscovery should be cheaper.
Is there a common threat intelligence tool that aggregates multiple threat intelligence sources?
Yes, Azure Sentinel is a SIEM on the Cloud. Multiple data sources can be uploaded and analyzed with Azure Sentinel and its Threat Hunting functionality with AI available as templates or customized ...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
Which is better - Azure Sentinel or AWS Security Hub?
We like that Azure Sentinel does not require as much maintenance as legacy SIEMs that are on-premises. Azure Sentinel is auto-scaling - you will not have to worry about performance impact, you will...
 

Also Known As

No data available
Azure Sentinel
 

Overview

 

Sample Customers

Information Not Available
Microsoft Sentinel is trusted by companies of all sizes including ABM, ASOS, Uniper, First West Credit Union, Avanade, and more.
Find out what your peers are saying about Microsoft Purview eDiscovery vs. Microsoft Sentinel and other solutions. Updated: October 2024.
816,562 professionals have used our research since 2012.