We had multiple use cases at my previous company. I changed companies during their implementation stages of this solution. From what I saw, the solution has a good use case for SIEM.
Managing Partner at Digitaiken
We saved money by consolidating into a single solution
Pros and Cons
- "We saw improvement from a regulatory compliance perspective due to having a single dashboard."
- "The solution helped out management a lot, reducing about 50% of the time needed to spend on this after implementation and saving the organization money by consolidating into one solution instead of two or three."
- "I felt that there was disconnection in terms of understanding the UI. The communication for moving from the old UI to the new UI could be improved. It was a bit awkward."
What is our primary use case?
How has it helped my organization?
It helped improve my previous organization's security posture. Their previous solution was running separately in each region. That has now been centralized by moving to the cloud. This was a huge change for their operations because they used to have multiple vendors managing their SIEM. Now, that has been consolidated under a single vendor. This consolidation has improved response times.
What is most valuable?
We saw improvement from a regulatory compliance perspective due to having a single dashboard.
What needs improvement?
I felt that there was disconnection in terms of understanding the UI. The communication for moving from the old UI to the new UI could be improved. It was a bit awkward.
Buyer's Guide
Microsoft Defender for Cloud
August 2026
Learn what your peers think about Microsoft Defender for Cloud. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
912,517 professionals have used our research since 2012.
For how long have I used the solution?
I have been using Azure Security Center for five to six years. I was using it as my previous organization up until six months ago.
What do I think about the stability of the solution?
The stability was good.
What do I think about the scalability of the solution?
The solution was very much scalable.
Overall, there were around 150,000 users beginning to use it at the organization.
How are customer service and support?
We didn't use technical support directly from Microsoft. We used the third-parties' support.
Which solution did I use previously and why did I switch?
We were previously using multiple solutions that integrated with SAP. For example, one region would be running QRadar and another region would be using Symantec. Each region of the company was just running it in silo mode off their internal Exchange. As part of centralizing a global solution, we chose to go with Azure Security Center, because our on-prem solution was not really working for us. This is why we started using Azure Security Center.
How was the initial setup?
The initial setup was easy; it was not complex.
The deployment took a month.
The transition went well. I didn't see any challenges.
What about the implementation team?
The setup was done by a third-party vendor, Fujitsu, who was very good. There was also another vendor, Microland, who had good knowledge and helped us with building it.
Not too many people were needed for the transition between solutions. I am unsure of the number of people needed because multiple activities were being run during the process, e.g., SharePoint migration.
What was our ROI?
The solution helped out management a lot. It reduced about 50% of the time needed to spend on this after implementation.
The organization saved money by consolidating into one solution instead of two or three.
What's my experience with pricing, setup cost, and licensing?
Microsoft's licensing and pricing are sometimes complicated. If someone is new to Microsoft's licensing, they might have difficulty with it.
Which other solutions did I evaluate?
We might have looked at other competitors. However, Azure Security Center was attractive because of its licensing, which was packaged with the Office 365 licensing, as well as the fact that it is a single solution.
What other advice do I have?
I liked the centralization that it offered. However, I am cautious about the licensing part because I am unsure how you would manage the solution if it wasn't bundled.
When we started, our team didn't make a clear roadmap, which slowed us down. I recommend that you clearly define your roadmap before getting started.
The solution is very good. I would rate it as eight out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager at a tech services company with 10,001+ employees
Its incident alerts have reduced our manual work for a lot of things
Pros and Cons
- "One important security feature is the incident alerts. Now, with all these cyberattacks, there are a lot of incident alerts that get triggered. It is very difficult to keep monitoring everything automatically, instead our organization is utilizing the automated use case that we get from Microsoft. That has helped bring down the manual work for a lot of things."
- "For organizations who have an on-prem environment and are planning to move to a cloud-based solution, Azure Security Center is definitely one of the best tools that they can use."
- "Most of the time, when we log into the support, we don't get a chance to interact with Microsoft employees directly, except having it go to outsource employees of Microsoft. The initial interaction has not been that great because outsourced companies cannot provide the kind of quality or technical expertise that we look for. We have a technical manager from Microsoft, but they are kind of average unless we make noise and ask them to escalate. We then can get the right people and the right solution, but it definitely takes time."
- "Most of the time, when we log into the support, we don't get a chance to interact with Microsoft employees directly, except having it go to outsource employees of Microsoft."
What is our primary use case?
I work as a SOC manager. We use it for incident security, incident monitoring, threat analysis, and looking at remediation or suppression.
What is most valuable?
Most use cases that come from Microsoft are all automated. Even before any manual effort, the tool is designed in such a way that it just does the threat analysis. It gives us exactly what the incident alert is all about:
- The priority
- The threat
- The impact
- The risk
- How it can be mitigated.
Those are the key features of this particular tool.
The solution has features that have definitely helped improve our security posture.
One important security feature is the incident alerts. Now, with all these cyberattacks, there are a lot of incident alerts that get triggered. It is very difficult to keep monitoring everything automatically, instead our organization is utilizing the automated use case that we get from Microsoft. That has helped bring down the manual work for a lot of things. The automation tool does the following (when human interaction is needed):
- Identifies what kind of an alert is it.
- Whether we have to dismiss it.
- When we need to take any action so the team can do it appropriately.
This is one of its key benefits.
It is easy to use based on my experience. If a newcomer comes in, it is just a matter of time to just learn it because it is not that difficult.
What needs improvement?
Most of the time, we are looking for more automation, e.g., looking to ensure that the real-time risk, threat, and impact are being identified by Microsoft. With the Signature Edition, there is an awareness of the real risks and threats. However, there are a lot of things where we need to go back to Microsoft, and say, "Are you noticing these kinds of alerts as well? Do we have any kind of solution for this?" This is where I find that Microsoft could be more proactive.
For how long have I used the solution?
I have been using it for more than nine years.
What do I think about the stability of the solution?
We have not had issues with tool usage or any hiccups.
There are certain glitches, which are areas of improvement, thus we continuously keep working with Microsoft. Microsoft does acknowledge this, because it's a learning experience for Microsoft as well. They always expect feedback and improvements on their tools, as it is a collaboration effort between Microsoft and the client.
What do I think about the scalability of the solution?
I work for an organization with more than 50,000 users. Under security alone, we have 5,000-plus users. On my team, we have around 400 people who are looking at it.
There are different roles in the company: project management, security operations (the red and blue teams), and pen testing. I lead a security operations center team, where we have L1, L2, L3, and L4 capabilities. All these come under the same umbrella of the security operations center, and they are all rolled up to the Chief Information Security Officer as part of security.
How are customer service and technical support?
An ongoing improvement for both Microsoft as well as for my organization: We need to work together. Sometimes, the solution doesn't work so we reach out to Microsoft Enterprise support for any help or assistance. If there is any feedback or improvement, then we work together, but they definitely have helped most of the time.
There are certain gray areas. We constantly work with Microsoft to notice whether there is something that only we, as a client, face. Or, if there are other clients who have the same kind of situation, issues, or scenarios where they need help.
I would rate Azure Security Center anywhere between five to six out of 10. Most of the time, when we log into the support, we don't get a chance to interact with Microsoft employees directly, except having it go to outsource employees of Microsoft. The initial interaction has not been that great because outsourced companies cannot provide the kind of quality or technical expertise that we look for. We have a technical manager from Microsoft, but they are kind of average unless we make noise and ask them to escalate. We then can get the right people and the right solution, but it definitely takes time.
Which solution did I use previously and why did I switch?
We use Microsoft Defender and Splunk. We primarily went with Azure Security Center because of client requirements.
How was the initial setup?
The initial setup is pretty easy and straightforward.
To deploy just Azure Security Center, it took three to four hours. However, there are a lot of things that it depends on.
Different clients have different requirements. If the client says, "We are using Azure Security Center. We want to use Microsoft technology or products." We will go with that. There are clients who are using Cisco products as well.
What about the implementation team?
The solution architect usually designs it, taking into consideration the initial setup guide, playbook, and documentation.
We don't use consultants for the deployment.
What's my experience with pricing, setup cost, and licensing?
It has global licensing. It comes with multiple licenses since there are around 50,000 people (in our organization) who look at it.
What other advice do I have?
For organizations who have an on-prem environment and are planning to move to a cloud-based solution, Azure Security Center is definitely one of the best tools that they can use. Year-over-year, I can see a lot of differences and improvements that Microsoft has definitely implemented, in terms of risk analysis, threat impact, and risk impact.
Most of the time, for any action that is performed within an organization or environment, if there is a risk or threat analysis, it is the security operation center who gets to know about it. The end user doesn't get affected at any cost unless there is a ransomware or cyberattack.
I wouldn't say that this is the only tool or product that has helped us out. There are a lot of technologies that Microsoft has come up with, which all together have made a difference. From a score of one to 10 for overall security, I would rate Azure Security Center somewhere between a seven to eight. This is not the only tool that my team depends on. There are other tools, but in terms of threat analysis and threat impact, this particular tool has definitely helped us.
We use a lot of Microsoft technologies, not only Azure Security Center. Apart from Azure Security Center, we use the playbook. We are also moving forward with Azure IoT Central and Log Analytics, which is a SIEM tool. So, I have Azure Security Center, Azure Advanced Threat Protection, Windows Defender, Log Analytics, and Azure IoT Central.
Using Azure Security Center, there are a lot of things that get automated. So, I am not dependent completely on Azure Security Center. It is a collaboration of different tools and technologies to achieve the end result. That is why I am saying seven to eight out of 10, because I am not dependent on a particular tool. It is also one of the tools that is definitely helpful for checking risk analysis, but there are other tools as well.
I would rate Azure Security Center as seven to eight of 10. If you talk about Microsoft products, I would rate it anywhere between eight to nine out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Microsoft Defender for Cloud
August 2026
Learn what your peers think about Microsoft Defender for Cloud. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
912,517 professionals have used our research since 2012.
Senior Architect at a tech services company with 10,001+ employees
A ready-made service that reports security threats and vulnerabilities
Pros and Cons
- "This is a platform as a service provided by Azure. We don't need to install or maintain Azure Security Center. It is a ready-made service available in Azure. This is one of the main things that we like. If you look at similar tools, we have to install, maintain, and update services. Whereas, Azure Security Center manages what we are using. This is a good feature that has helped us a lot."
- "The features that Azure Security Center provides from a security point of view are amazing."
- "One of the main challenges that we have been facing with Azure Security Center is the cost. The costs are really a complex calculation, e.g., to calculate the monthly costs. Azure is calculating on an hourly basis for use of the resource. Because of this, we found it really complex to promote what will be our costs for the next couple of months. I think if Azure could reduce the complex calculation and come up with straightforward cost mapping that would be very useful from a product point of view."
- "One of the main challenges that we have been facing with Azure Security Center is the cost."
What is our primary use case?
We are working for a major client in the UK. So, we are moving all the products of clients from their on-premises environment to the cloud. One of the biggest challenges we face, “Once the infrastructure is created in the cloud, how can we make sure that the infrastructure is secure enough?” For that purpose, we are using Azure Security Center, which gives us all the security loopholes and vulnerabilities for our infrastructure. That has been helpful for us.
How has it helped my organization?
We use the Azure Security Center to scan the entire infrastructure from a security point of view. It gives us all the vulnerabilities, observations, etc. It reports most of the critical issues.
From an organization or security audit point of view, there are few tools available in the market. The output or score of Azure Security Center has really helped the organization from a business point of view by showing that we are secure enough with all our data, networks, or infrastructure in Azure. This helps the organization from a business point of view to promote the score, e.g., we are secure enough because this is our score in Azure Security Center.
We are using it from a security point of view. If there is a threat or vulnerability, the solution will immediately scan, report, or alert us to those issues.
What is most valuable?
We are using most of the good services in Azure:
- The load balancing options
- Firewall
- Application Gateway
- Azure AD.
I value Azure Security Center the most from a security point of view. Everybody is concerned about moving data or infrastructure to the cloud. This solution proves that we are secure enough for that infrastructure, which is why I really value the Azure Security Center. We are secure in our infrastructure.
This is a platform as a service provided by Azure. We don't need to install or maintain Azure Security Center. It is a ready-made service available in Azure. This is one of the main things that we like. If you look at similar tools, we have to install, maintain, and update services. Whereas, Azure Security Center manages what we are using. This is a good feature that has helped us a lot.
What needs improvement?
From a business point of view, the only drawback is that Azure or Microsoft need to come up with flexible pricing/licensing. Then, I would rate it 10 out of 10.
For how long have I used the solution?
We have been using it in production for the last three years. I have been part of the cloud migration team for Azure Cloud for the last two years.
What do I think about the stability of the solution?
We started using Azure Cloud from the initial version. Every week or month, there are updates in Azure. For the last three years, we have been using the latest version.
What do I think about the scalability of the solution?
Whenever we increase the number of our resources, Azure Security Center easily copes with it. Since this is a ready-made service, it will automatically scale.
We are working with around 100 to 150 major clients in the UK. Each client has 200 to 500 users.
From an overall infrastructure point of view, we have a five member team.
How are customer service and technical support?
We are getting adequate support and documentation from Microsoft. We are a Premium customer of Microsoft, so we are getting support in terms of documentation and manual support.
Which solution did I use previously and why did I switch?
We were using this service from the onset.
How was the initial setup?
This is a PaaS service. It is a ready-made service available in Azure Cloud. It is very easy to use and set up because you are using the platform. We don't want to maintain this service from our end.
There are different models when it comes to the cloud:
- Infrastructure as a service
- Platform as a service
- Software as a service.
We are using sort of a hybrid, both infrastructure as a service and platform as a service.
What about the implementation team?
We are using our own team for the deployment.
We consume or subscribe to the service. Azure takes care of the maintenance and deployment, and we don't need to worry about it.
What was our ROI?
We are securing our customers' infrastructure using Azure Security Center. That internally helps their overall organization meet their goal/score on security.
So far, the feedback from the customer and our team have been really positive. We are very happy and getting return on investment from this product.
What's my experience with pricing, setup cost, and licensing?
Its pricing is a little bit high in terms of Azure Security Center, but the good thing is that we don't need to maintain and deploy it. So, while the pricing is high, it is native to Azure which is why we prefer using this tool.
One of the main challenges that we have been facing with Azure Security Center is the cost. The costs are really a complex calculation, e.g., to calculate the monthly costs. Azure is calculating on an hourly basis for use of the resource. Because of this, we found it really complex to promote what will be our costs for the next couple of months. I think if Azure could reduce the complex calculation and come up with straightforward cost mapping that would be very useful from a product point of view.
Which other solutions did I evaluate?
Other than Azure Security Center, we did not find a single tool which could analyze all our infrastructure or resources in Azure Cloud.
We were mainly looking for products or tools native to Azure. The other tools that we evaluated were not native to Azure. Azure Security Center is natively attached to Azure. Because other tools were not natively supporting Azure, then we would have to maintain and deploy them separately.
What other advice do I have?
So far, we have received very positive feedback from the team and customers. Because it is a single tool where we list all the problems or vulnerabilities, we are happy as a team. The customer is also happy.
End users are not interacting with Azure Security Center. This is a back-end service that evaluates security.
There are no other good tools in Azure, other than Azure Security Center, which will evaluate and alert you to security vulnerabilities and threats. So, if somebody is really concerned about the security of their infrastructure in Azure, I suggest you use Azure Security Center. The features that it provides from a security point of view are amazing.
I would rate the product as a seven or eight (out of 10) because it is really helping us to improve our security standards.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
CTO at a tech services company with 11-50 employees
Enhanced threat detection with machine learning and advanced sandboxing
Pros and Cons
- "Some of the most valuable features of Microsoft Defender for Cloud include its effectiveness in threat detection through unsupervised machine learning, CTI, and advanced sandboxing."
- "Integration into other third-party products, particularly those from tier three vendors like ManageEngine and Hexcode, has proven difficult."
What is our primary use case?
Our primary use case is for cloud endpoint IoT security and overall cybersecurity implementations. We handle aspects from presales, installation, post-sales, and ongoing consulting to optimize customer security.
How has it helped my organization?
Implementing Microsoft Defender for Cloud has helped our organization in terms of providing robust cloud workload protection with minimal false positives. It also allows us to integrate with other tools like Splunk for observability and Qualys for vulnerability assessments, ensuring comprehensive security for our clients.
What is most valuable?
Some of the most valuable features of Microsoft Defender for Cloud include its effectiveness in threat detection through unsupervised machine learning, CTI, and advanced sandboxing. These features have consistently minimized false positives. The rich history of signature-based technology from Microsoft also adds to its reliability.
What needs improvement?
Integration into other third-party products, particularly those from tier three vendors like ManageEngine and Hexcode, has proven difficult. While there is ample documentation from Microsoft, the company needs to improve on making their integrations less challenging.
For how long have I used the solution?
I have been working with Microsoft products for six to seven years.
Which solution did I use previously and why did I switch?
We used to resell CyberX before it was acquired. The switch was made to enhance our security offerings with more comprehensive solutions.
How was the initial setup?
The initial setup of Microsoft Defender for Cloud is manageable. Our team handles the presales, installation, and post-sales, ensuring the customer achieves a level of compliance with their security and regulatory needs.
What about the implementation team?
We perform the presales, installation, and post-sales for clients. For compliance and consultancy, a dedicated consulting team works with the customers.
What's my experience with pricing, setup cost, and licensing?
The pricing of Microsoft Defender for Cloud is very expensive. Although it is overpriced, many of our enterprise customers have a Microsoft ELA, making it the solution of choice.
Which other solutions did I evaluate?
Our customers also use products like CrowdStrike, Cyber Reason, TrendMicro, and AllGuard. Many are on Microsoft Azure, while some also use OCI and AWS.
What other advice do I have?
The primary piece of advice would be to improve third-party integrations, especially with products from tier-three vendors. This would make the overall solution more versatile and easier to manage for diverse customer needs.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Student at a educational organization with 1,001-5,000 employees
Seamlessly integrated and improves security but should be more tailored to micro-segmentation
Pros and Cons
- "It works seamlessly on the Azure platform because it's a Microsoft app. Its setup is similar, so if you already have a Microsoft account, it just flows into it."
- "It improves the transparency and visibility of the traffic in and out of the network of each workload on my system."
- "From my own perspective, they just need a product that is tailored to micro-segmentation so I can configure rules for multiple systems at once and manage it."
- "As a micro-segmentation product, it's not so great, especially if you have a lot of systems."
What is our primary use case?
I work on micro-segmentation for my master's thesis, and I was looking for ways to implement micro-segmentation using Defender. I work on the assumption that small businesses can't implement expensive virtualization solutions, so I'm looking for alternatives to implement micro-segmentation for their network security.
I use the latest version of the solution.
It's a test deployment. I created the entire network. It's more like a laboratory setup.
How has it helped my organization?
The solution does what I want it to do. If you're already on Microsoft, this solution comes bundled with it. It's seamlessly integrated, and it improves security because I can determine who can access what applications and who or what my applications communicate with. It improves the transparency and visibility of the traffic in and out of the network of each workload on my system.
The benefits were realized almost immediately.
Compared to other products, it hasn't helped save SOC time or increase efficiency. I'm focused on micro-segmentation, so compared to other products, it wasn't built for that, but it can be adapted to it.
I'm not sure that the effect on my overall time for detection can be measured, but for non-threats, it's almost effective. The notification system is effective too. It lets me know as soon as there's a problem.
What is most valuable?
I use this solution to natively support Azure. It works seamlessly on the Azure platform because it's a Microsoft app. Its setup is similar, so if you already have a Microsoft account, it just flows into it.
It's very important to me that the solution has the ability to protect hybrid and multi-cloud environments.
I'm looking to implement the solution in SMEs that might use different environments. Most SMEs don't have the resources to own their infrastructure entirely, so I can't really predict what environment they will be used in, therefore, I need a solution that is flexible enough to work in multiple environments, both online and offline. The only limiting factor is that I can not this solution use on platforms that aren't Microsoft.
The single pane of glass view is very important for me. It's great to be able to see everything at once and go where I need to very quickly. It's also easy to use if you've used any Microsoft product before. It allows me to see everything I want at a glance. I didn't think it was important until I started to use it, and then I realized how convenient it was.
For micro-segmentation, the unified portal has had an effect on my cloud security posture, but it's a lot of work because I have to configure the rules individually. It's difficult to compare this solution to a product like NSX or any other specialized micro-segmentation product, but because I'm trying to get a solution for small businesses that have about 10 PCs or 10 systems at the most.
It effectively defends against known threats. It also updates regularly, so the threat signatures are updated regularly, but I don't know how often the database is updated on Microsoft, so I can't really quantify its effectiveness against either zero-day threats or new threats.
I've only tried it on Azure cloud and it's effective. I've only used it on a single-cloud structure.
Right now, I'm setting rules for incoming and outgoing traffic for different applications.
What needs improvement?
From my own perspective, they just need a product that is tailored to micro-segmentation so I can configure rules for multiple systems at once and manage it. Instead of having to set up individual rules for individual applications, there should be a system that can allow me to set up multiple rules at once and can automatically update the rules as the infrastructure changes.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
In general, the scalability is good. It wasn't built for my use case, which is micro-segmentation. If I had 100 systems, it would be a lot of work for me.
How are customer service and support?
I have not had to call or get in touch with them, but there's a lot of documentation online. I've found a lot of what I need without having to contact anyone.
The documentation is excellent. There's a lot from Microsoft and other providers. I think it's a fairly popular system.
How was the initial setup?
It was straightforward. I was the only person that deployed and tested the solution.
Initial deployment took a day, but the initial configuration rule setting took a while because it was my first time using the system.
The first step was to set up the cloud, install some test applications that I needed to protect, and then configure rules for traffic between the applications, and then between the application and external networks.
The solution doesn't really require any maintenance. It's fairly automatic. Once it's up and running, it pretty much works.
What's my experience with pricing, setup cost, and licensing?
The cost is fair. There aren't any costs in addition to the standard licensing fee.
Which other solutions did I evaluate?
I didn't evaluate other options because I use this solution for thesis research. I researched which solution was the most used cloud and picked Azure.
What other advice do I have?
I would rate this solution six out of ten.
As a perimeter defense system, I would rate the solution a seven. As a micro-segmentation system or application, I would rate it a four.
As a perimeter defense solution, it's excellent. As a micro-segmentation product, it's not so great, especially if you have a lot of systems. It's not the product's fault because I don't think that's what it was built for.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cyber Security Specialist at a tech services company with 1,001-5,000 employees
Helps enforce best practices when new virtual machine, app gateway, or functional service comes online
Pros and Cons
- "The most valuable features of the solution are the insights, meaning the remediation suggestions, as well as the incident alerts."
- "The solution has also simplified management of endpoints and servers and gives us visibility in a single pane of glass."
- "I would like to see better automation when it comes to pushing out security features to the recommendations, and better documentation on the step-by-step procedures for enabling certain features."
What is our primary use case?
We use it to keep our Azure infrastructure up to date with the security best practices that Microsoft suggests. We also use it to have better visibility into changes in our databases.
How has it helped my organization?
It helps me know if a new virtual machine or an app gateway or a functional service has come online that doesn't have the best security practices enforced on them. The impact we've had is a better security posture being enforced throughout our Azure environment.
The solution has also simplified management of endpoints and servers and gives us visibility in a single pane of glass. And it's easy to identify security corrections in the environment.
It has helped save us SOC time and increased their efficiency. While we haven't measured by how much, we see it in their day-to-day activities. And it has likely improved our time to detection, but we just haven't had anything to detect.
What is most valuable?
The most valuable features of the solution are the insights, meaning the remediation suggestions, as well as the incident alerts.
We have also integrated Microsoft 365 and Microsoft Defender for Cloud with Microsoft Sentinel and the integration was easy.
In addition, it's good at helping us proactively discover unknowns and defend against threats.
What needs improvement?
I would like to see better automation when it comes to pushing out security features to the recommendations, and better documentation on the step-by-step procedures for enabling certain features.
For how long have I used the solution?
I have been using Microsoft Defender for Cloud on a day-to-day basis for about a year.
What do I think about the stability of the solution?
It's quite stable. We don't have many problems.
What do I think about the scalability of the solution?
The scalability is very good.
We have 100 internal users and we are deployed across multiple sites. It's 100 percent cloud and our infrastructure handles API responses for our clients.
How are customer service and support?
For the cloud infrastructure, their technical support is good.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
In my previous company, I used the native portal, which is pretty much what Defender does, on AWS.
What other advice do I have?
The intelligent threat hunting provided by Microsoft 365 and Microsoft Sentinel based on the alerts, incidents, and logs passed along by Microsoft Defender for Cloud is moderate.
The ability of Microsoft solutions to work natively together to deliver integrated protection as well as coordinated detection and responses across the environment is improving a lot, but it still has a ways to go.
Overall, if you are worried about security, you should have Microsoft Defender for Cloud. It's the minimum you should have.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cloud Solution Architect at Tech Mahindra Limited
Good log analysis and threat prevention but can be a bit complex
Pros and Cons
- "Technical support is helpful."
- "No doubt it is useful as per the log analysis and threat protection analysis."
- "The product was a bit complex to set up earlier, however, it is a bit streamlined now."
What is most valuable?
The log analysis and threat prevention analysis are good.
Technical support is helpful.
What needs improvement?
We haven't really received any customer feedback yet. Once we have some, we'll be able to better discuss areas of improvement.
The solution needs to keep improving its log analysis and threat mechanisms.
The product was a bit complex to set up earlier, however, it is a bit streamlined now.
Basically, we are looking at unique specimens. Linux works best with ONELAB. With Linux, we have a lot of Metasploit, however, it is undetectable sometimes. We want to improve that particular aspect of the Defender.
For how long have I used the solution?
We've been using the solution for the last four and a half years.
What do I think about the scalability of the solution?
While, right now, the solution, in terms of size, is fine, one year or two years down the line, we will need to scale up and we will need to check that particular scale-up process then. As of now, we haven't done so.
How are customer service and support?
Technical support has been good.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup was hard at first. It's gotten easier. It gets simpler with time.
In terms of maintenance, we are in a hybrid culture. There are data center staff, as well as cloud-centric staff which defaults as per the client requirement. We as a service company, need to rigorously go through cloud solutions, even with the clients and their compliance. We have to honor that compliance.
What about the implementation team?
We have a channel partner with Microsoft. They have consulted with some other third-party people from their end.
What's my experience with pricing, setup cost, and licensing?
The solution has a license renewal on a yearly basis.
The licensing part is not my area of interest. It is a different team that looks after that.
What other advice do I have?
We are channel partners for Microsoft. We are a gold partner and a channel partner.
We earlier were using the on-premises deployment. Then we moved to the cloud for the last two-and-a-half years. It's a hybrid cloud.
I'd advise new users that they can implement it, however, it is complex in nature. No doubt it is useful as per the log analysis and threat protection analysis.
I would rate the solution a seven out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Cybersecurity Student at a university with 1,001-5,000 employees
Simple to set up, easy to use, and requires zero maintenance
Pros and Cons
- "It's got a lot of great features."
- "It is very scalable, the product has been very easy to use and simple to set up, the maintenance and updating are part of the service so that brings great value, it's a stable product, technical support is helpful, and it's got a lot of great features."
- "They could always work to make the pricing a bit lower."
What is our primary use case?
I primarily use the solution just for the networking of virtual machines.
What is most valuable?
It is very scalable.
The product has been very easy to use and simple set up.
The maintenance and updating are part of the service, so that brings great value.
It's a stable product.
Technical support is helpful.
It's got a lot of great features.
What needs improvement?
I can't speak to any features that are missing. I need time to get a little bit more into it before making any kinds of suggestions.
They could always work to make the pricing a bit lower.
For how long have I used the solution?
I've been using the solution for a few months.
What do I think about the stability of the solution?
The stability is great. There are no bugs or glitches. It doesn't crash or freeze. It's reliable and the performance has been quite good in general.
What do I think about the scalability of the solution?
Its ability to scale is impressive. It's one of the main selling points. If a company needs to expand it, it can do so. It's not a problem.
We have about 25 or so people using the solution. Some of them are new.
How are customer service and support?
From my experience, technical support is good. They're quick to respond and knowledgeable. I haven't seen a need for improvement in any aspect of their support services. We are quite satisfied with them.
Which solution did I use previously and why did I switch?
We did use other solutions, however, they were more for training or educational purposes.
How was the initial setup?
The setup is extremely straightforward and simple. It's not a complex or difficult process. You can get as involved as you want in it, or you can keep it simple.
The maintenance is also part of their service, which means we don't have to worry about it at all. They take care of everything. It doesn't require personnel watching over it.
What's my experience with pricing, setup cost, and licensing?
The pricing is mid to high. It's not the cheapest or least expensive option.
What other advice do I have?
It's a good solution for, I'd say, small to medium business startups. It's also viable for enterprise solutions.
I'd rate the solution at a ten out of ten. We have been very happy with its capabilities.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Associate Principal - Cloud Solutions at Apexon
Provides good recommendations and makes policy administration easy
Pros and Cons
- "It is very intuitive when it comes to policy administration, alerts and notifications, and ease of setting up roles at different hierarchies. It has also been good in terms of the network technology maps. It provides a good overview, but it also depends on the complexity of your network."
- "Azure Security Center helped us in recovering from our mistake."
- "For Kubernetes, I was using Azure Kubernetes Service (AKS). To see that whatever is getting deployed into AKS goes through the correct checks and balances in terms of affinities and other similar aspects and follows all the policies, we had to use a product called Stackrox. At a granular level, the built-in policies were good for Kubernetes, but to protect our containers from a coding point of view, we had to use a few other products. For example, from a programming point of view, we were using Checkmarx for static code analysis. For CIS compliance, there are no CIS benchmarks for AKS. So, we had to use other plugins to see that the CIS benchmarks are compliant. There are CIS benchmarks for Kubernetes on AWS and GCP, but there are no CIS benchmarks for AKS. So, Azure Security Center fell short from the regulatory compliance point of view, and we had to use one more product. We ended up with two different dashboards. We had Azure Security Center, and we had Stackrox that had its own dashboard. The operations team and the security team had to look at two dashboards, and they couldn't get an integrated piece. That's a drawback of Azure Security Center. Azure Security Center should provide APIs so that we can integrate its dashboard within other enterprise dashboards, such as the PowerBI dashboard. We couldn't get through these aspects, and we ended up giving Reader security permission to too many people, which was okay to some extent, but when we had to administer the users for the Stackrox portal and Azure Security Center, it became painful."
- "So, Azure Security Center fell short from the regulatory compliance point of view, and we had to use one more product."
What is our primary use case?
We are primarily using Azure Security Center to bring a level of security into the environment. Before I started to work with this solution, I was a Kubernetes and Azure Cloud architect. I was working for a service provider where I did not get the opportunity to look at how do they secure the resources, but in the last one and a half years, I had to get into those aspects because the organization I was working for wanted to introduce Kubernetes into the ecosystem, and the main concern was regarding all the hacking that was going on. For introducing Kubernetes as a platform, all business managers wanted to know if it was secure or how to make it secure. We started to look at Azure Security Center and its capabilities because Azure was their main solution. We also used AWS and GCP to some extent, but predominantly, we had Azure. So, we first took Azure Security Center and started to leverage its features.
How has it helped my organization?
Azure gives access to a lot of policies and allows you to group those policies into initiatives. There were about 170 subscriptions spread across sandbox, dev, test, non-prod, and prod environments, which were spread across India, Canada, and the USA. Each geography had its own data resiliency requirements, so these policies had to be applied stringently. For example, if somebody created a virtual machine, it had to be in a specific region, or if someone was storing the data in a database, it had to be only in that region. It could not cross the border. So, we had to first enforce policies at the level where we had to identify where the storage resources were, which network could talk to which network, and who could do what, and then it went on to all levels. Azure provided very good, robust, and built-in policies for each resource, and we had to set some to audit and some to enforce.
While setting policies for about 170 subscriptions, we needed to ensure consistency. We needed to apply them consistently across all subscriptions. Azure Security Center helped us in ensuring that we audit certain policies, and we also enforce certain policies. We had set some policies to audit because we wanted to see what's going on, and we had set some policies to enforce because of regulatory purposes or because of the way the entire network and all the systems were designed. We used Azure Security Center as our central place to administer policies. We had to group all the subscriptions into management groups, and there was a hierarchy of groups. We could apply the policies at one specific level, and any subscription that we would create under that group would have the same set of policies. It helped us in getting a bird's-eye view through dashboards. We could see what was happening across the enterprise.
We started using it for Kubernetes, but it expanded into a wider initiative of more stringent policies across the board. In terms of lift and shift, a lot of people get tempted to go to GCP because it is cheaper, but we were primarily using Microsoft products. So, we started adopting Azure, and we did not pay attention to Azure Security Center at the beginning. When we looked at Azure Security Center for the first time, it had already been three years, and we had done almost 100% lift and shift, but we could recover from any aspect of security. Azure Security Center helped us in recovering from our mistake. If we had worked with it at the start of our journey, it would have been easier, and even though we were looking at it halfway through our journey, it still helped us. I consider it halfway because lift and shift is only one part of the process. You are saving a lot of money, but you are still not cloud-based. The real power of the cloud comes when you start using the platform services, and before starting to use them, we were able to get into a secured environment. Kubernetes was the first platform that we were looking at, and when we were able to secure it, everything else was pretty simple. That's because, with Kubernetes, there is a shared responsibility model where the cloud provider takes care of some of the aspects, and you have to take care of a lot of things. Azure Security Center helps in ensuring that you have taken care of and secured everything.
What is most valuable?
Its recommendations are really good. Most of the time, they are appropriate. Azure comes with a lot of default policies that are set to audit only. As the enterprise grew and we started adopting the cloud, initially, we didn't pay much attention to Azure Security Center. For us, Azure Security Center was like an afterthought; it was not planned from day one. In our enterprise journey, when we started looking at it halfway through, we realized that there were so many violations. We started with auditing. We found policies that nobody was using, and then we started enforcing them. It was really good in terms of built-in policies, recommendations, and then applying them across the board with a minimal set of actions.
It is very intuitive when it comes to policy administration, alerts and notifications, and ease of setting up roles at different hierarchies. It has also been good in terms of the network technology maps. It provides a good overview, but it also depends on the complexity of your network.
What needs improvement?
For Kubernetes, I was using Azure Kubernetes Service (AKS). To see that whatever is getting deployed into AKS goes through the correct checks and balances in terms of affinities and other similar aspects and follows all the policies, we had to use a product called Stackrox. At a granular level, the built-in policies were good for Kubernetes, but to protect our containers from a coding point of view, we had to use a few other products. For example, from a programming point of view, we were using Checkmarx for static code analysis. For CIS compliance, there are no CIS benchmarks for AKS. So, we had to use other plugins to see that the CIS benchmarks are compliant. There are CIS benchmarks for Kubernetes on AWS and GCP, but there are no CIS benchmarks for AKS. So, Azure Security Center fell short from the regulatory compliance point of view, and we had to use one more product. We ended up with two different dashboards. We had Azure Security Center, and we had Stackrox that had its own dashboard. The operations team and the security team had to look at two dashboards, and they couldn't get an integrated piece. That's a drawback of Azure Security Center. Azure Security Center should provide APIs so that we can integrate its dashboard within other enterprise dashboards, such as the PowerBI dashboard. We couldn't get through these aspects, and we ended up giving Reader security permission to too many people, which was okay to some extent, but when we had to administer the users for the Stackrox portal and Azure Security Center, it became painful.
We were also using it for just-in-time access for developer VMs. Many a time, developers need certain administrative privileges to perform some actions, and that's where we had to use just-in-time privileges. Administering them out of Azure Security Center is good, but it also means that you have to give those permissions to lots of people, which is very cumbersome. So, I ended up giving permissions to the entire Ops team, which defeats the purpose and is also not acceptable at a lot of places.
These were the two use cases where I felt that I really had to get into the depth of Azure Security Center to figure out how I can use it much better.
For how long have I used the solution?
I have been working with this solution for the last one and a half years.
What do I think about the stability of the solution?
I didn't find any issues with its stability. When you start using Azure Security Center to look at your on-prem application or resources, you might have issues with monitoring these on-prem resources, but it is not related to the stability or reliability of Azure Security Center. It has nothing to do with Azure Security Center; it is related to how you have configured, what kind of resources you have, and what permissions you have given.
Sometimes, the network operations team and security operations team are not in tandem with each other. We had done lift and shift for most of the resources, but there were still some resources that were on-prem. For on-prem resources, people are comfortable with Dynatrace and other similar tools, but they are not really security tools; they come under the observation and monitoring tools. It can be very hard to sell Azure Security Center for something that is on-prem, and because of the corporate silos, someone might not give you access to an on-prem resource. For example, your Oracle Database is still on-prem, and you are systematically strangulating the application and moving it to Cosmos DB or SQL Server on the cloud, but you are not allowed to monitor it. In such situations, Azure Security Center can only report one part of the application, which makes it tough to tell business managers
why this application is down, what went wrong, why there is latency, what is the problem, etc. So, more than the product, it has to do with ensuring that the SOC team works with the NOC team and ensures that they have the required access so that they can also observe on-prem resources from the security aspect. Otherwise, you won't know what's happening. You won't know if any hacking is going on, or if somebody is doing SQL injections to the on-prem Oracle Database. You wouldn't have a clue.
How are customer service and support?
I'm an architect. I don't deal with the regular operations aspects.
How was the initial setup?
There is nothing in terms of the setup. It comes by default. It is only about paying attention to the Azure Security Center in terms of giving correct roles to subscription owners, security administrators, etc. It is only about properly setting up those roles.
It only required going through the documentation in detail and having a couple of brainstorming sessions. We didn't have to hire any special consultants. We could do it ourselves. We spent a week properly going through the documentation. Having a word with the product managers also helped. Many times, such implementations have more to do with the way organizations are structured in terms of departmental silos. So, it helps to get everybody on board and ensure that everybody has the same understanding. It is related to an organization's culture; it has nothing to do with the product. It is more related to outsiders and insiders and different levels of knowledge and backgrounds, but the product itself is pretty simple to start with.
What about the implementation team?
We did it ourselves.
What's my experience with pricing, setup cost, and licensing?
It is bundled with our enterprise subscription, which makes it easy to go for it. It is available by default, and there is no extra cost for using the standard features.
Which other solutions did I evaluate?
I don't know if any other solution was evaluated. Most probably, we didn't because Azure Security Center is available by default, and there is no extra charge for using the standard features.
What other advice do I have?
When you're using such platform services, you've got to be a little bit careful because the products are always getting updated. You need to keep an eye on the product roadmap in terms of what's coming up so that you are not duplicating. That's what we had to do with Stackrox. We discussed with Microsoft's technical support team, and we got a confirmation that they're not going to take care of CIS benchmarks in the near future. It was a little bit disheartening, but at least, we knew upfront that Microsoft is not going to look into this area. They were open and candid about what they were going to do and what they were not going to do. So, we started looking at other products. Microsoft keeps on updating its products to keep them relevant. So, you need to know what they are implementing in the next three months or six months so that you can at least tell the security teams that a certain feature is coming up.
We didn't have to do it for Azure Security Center, but for Azure Firewall, we had to request certain features, and there are a lot of features that are still pending. For example, if I use Azure Firewall, just-in-time permissions do not work. If VMs are behind Azure Firewall, then through Azure Security Center, I can't give permissions, but if I use the Palo Alto firewall, I can do the same. So, we had to set up our VMs by using the Palo Alto firewall. Sometimes, Microsoft does strange things, and they don't talk to the Azure Firewall team. After one and a half years of asking for that feature, it is still a no-go. We want to use Azure Firewall because it is not VM-based. With the Palo Alto firewall, I have to provide one more VM in between and start administering it. So, I have one extra resource that needs to be administered, and it is non-Azure or non-Microsoft.
When you start enforcing policies across multiple subscriptions, you need to be very careful. You need to pay attention to the notifications that come out. The notification details were where we had to do some customization. We had to prioritize the notifications and then put them into a group mailbox so that instead of one person, a group of teams gets notified. We could write an Azure function around it to integrate with Microsoft Teams. We could push them to the Microsoft Teams channel. It took some amount of effort. It took about a week of tinkering, but we were able to notify the entire development team. As we started auditing and enforcing from our sandbox to the development environment, we started discovering a lot more things. We got formal requests on why we had to disable some policies. We got more specific feedback. When we are able to catch such things early in the life cycle, it becomes easier to protect the higher-level environments properly. It was very good in terms of the dashboard, converting from non-compliance to audit, or enforcing policies across multiple subscriptions. We had to customize the notifications, and it would've been nice if there was a more intuitive way of customizing the notification, but it might also be because of our knowledge level at that time. We could have also integrated it with Slack because it supports integration with Slack, but we predominantly use Microsoft Teams.
I would advise others to start playing with it. They can start with a sandbox environment. If an enterprise has multiple resources, such as VMs, databases, they should put all of them in different resource groups in a subscription and categorize their resources properly. All resources should be structured properly. Otherwise, it is really difficult to administer policies at the resource level. They have to group them properly so that they are managing resource groups or subscriptions rather than individual resources. So, structuring of the resources is the key to the administration of policies. It took quite some time for us. It was not an easy task. We create Terraform scripts for setting the entire infrastructure. So, we had to reorganize our Terraform scripts to ensure that the resources were created in appropriate resource groups and communication can happen across resource groups. We had to set up the NSGs properly from the network point of view so that they all were accessible. It took us quite some time, but organizing the resources pays very well when it comes to spinning the higher-level environments and ensuring that they're compliant or they work.
I would rate it an eight out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
CEO at RevealRx LLC
Comprehensive, cost-effective, and helpful in identifying the gaps
Pros and Cons
- "It helps you to identify the gaps in your solution and remediate them, and it produces a compliance checklist against known standards such as ISO 27001, HIPAA, iTrust, etc."
- "Customizing some of the compliance requirements based on individual needs seems like the biggest area of improvement. There should be an option to turn specific controls on and off based on how your solution is configured."
What is our primary use case?
We use it to manage the overall compliance of our products.
What is most valuable?
It helps you to identify the gaps in your solution and remediate them. It produces a compliance checklist against known standards such as ISO 27001, HIPAA, iTrust, etc.
What needs improvement?
Customizing some of the compliance requirements based on individual needs seems like the biggest area of improvement. There should be an option to turn specific controls on and off based on how your solution is configured.
For how long have I used the solution?
I have been using this solution for five or six years. We have been working with it pretty much since it came out.
What do I think about the stability of the solution?
It is a great product. The new security features that emerge in Microsoft products can sometimes be difficult to track. It automatically flags when you don't have what you probably should have.
What do I think about the scalability of the solution?
It is very scalable. We are a small organization with less than 10 people, and at least half of those people are in the solution at any given point in time.
How are customer service and technical support?
Microsoft's tech support is decent. I would rate them a four out of five. We're currently dealing with a ticket mostly on the billing side, and it has been open for over a month, so I'm not going to give them a stellar rating. I feel they should have figured this out a long time ago, but they've resolved technical issues relatively quickly.
How was the initial setup?
It was very easy. It was there by default. It basically turned itself on, and then they gave you a default thing.
In terms of maintenance, typically, there is one person in there, probably per week, looking at the compliance and things that they can do to improve the bar.
Which other solutions did I evaluate?
It was included with the product. We looked at other solutions, but this was the most comprehensive and cost-effective one.
What other advice do I have?
I would rate Azure Security Center a nine out of 10.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Microsoft Defender for Cloud Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Product Categories
Cloud Workload Protection Platforms (CWPP) Vulnerability Management Container Management Container Security Cloud Security Posture Management (CSPM) Cloud-Native Application Protection Platforms (CNAPP) Data Security Posture Management (DSPM) Microsoft Security Suite Compliance Management Cloud Detection and Response (CDR)Popular Comparisons
Microsoft Intune
Microsoft Defender for Endpoint
Microsoft Entra ID
SentinelOne Singularity Cloud Security
Qualys TotalCloud
Checkmarx One
Prisma Cloud by Palo Alto Networks
Check Point Cloud Firewall (formerly CloudGuard Network Security)
Varonis Platform
Buyer's Guide
Download our free Microsoft Defender for Cloud Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- How is Prisma Cloud vs Azure Security Center for security?
- What tools provide the best container environment security?
- When evaluating Cloud Workload Security, what aspect do you think is the most important to look for?
- Can we customize the dashboard in Threat Stack Cloud Security Platform? Any recommendations for an alternative solution supporting dashboards?
- What are the best cloud workload security software solutions?
- Why use cloud workload security software?
- Why are Cloud Workload Protection Platforms (CWPP) important for companies?
- Why is CWPP (Cloud Workload Protection Platforms) important for companies?

















