Try our new research platform with insights from 80,000+ expert users
Enterprise Architect at NTT New Zealand Ltd.
Real User
Stable, integrates with other Defender components, and effectively measures identity security
Pros and Cons
  • "Defender for Identity has not affected the end-user experience."
  • "The solution could be better at using group-managed access and they could replace it with broad-based access controls."

What is our primary use case?

The solution provides alerts when malicious actors are active and that's something most companies are missing. Quite often, malicious actors do reconnaissance for weeks, months, and on their checkout. They get a sense of the whole environment before they execute a ransomware attack. This sensor will alert users if something like that happens and it gives you time to mitigate the issues or block the attacker.

How has it helped my organization?

It gives companies a lot of insights that they didn't have before. It has increased the security posture significantly.

What is most valuable?

The feature that I most like is that it integrates with the other Defender components. Defender Identity is part of Microsoft 365, and there is Defender for Office 365, Defender for endpoints, and cloud edge security. These tools integrate really well together. The integration with the other tools makes it a comprehensive tool that I would recommend to any company.

It measures your identity security. For example, let's say a lot of companies don't have a proper decommissioning process for global admins or domain admins. And so, when an administrator who has built many privileges leaves the company, the account gets disabled and it still has members of domain admin groups or sensitive groups. This will highlight them and alert users to say, in a sense, "hey, these users or to these user accounts of sensitive privileges, but haven't been used for a long period of time". The few times I've created this report and showed this to customers, they're shocked due to the fact that it's an easy entry for malicious actors that they weren't aware of. That's one of the cool features.

Defender for Identity has not affected the end-user experience.

What needs improvement?

The solution could be better at using group-managed access and they could replace it with broad-based access controls.

Buyer's Guide
Microsoft Defender for Identity
January 2025
Learn what your peers think about Microsoft Defender for Identity. Get advice and tips from experienced pros sharing their opinions. Updated: January 2025.
831,265 professionals have used our research since 2012.

For how long have I used the solution?

I've worked with the solution since June of last year. I've worked with it across three organizations so far.

What do I think about the stability of the solution?

I have never seen any issues. The solution appears to be stable. 

What do I think about the scalability of the solution?

Scalability is not applicable in this case.

In terms of users, there will be cloud engineers or security analysts, security engineers, and those types of people.

How are customer service and support?

Normally the tech support is pretty responsive and they understand the tool.

Which solution did I use previously and why did I switch?

Our organization did not previously use a different solution.

How was the initial setup?

I've used the solution within three organizations. Two I have implemented myself and the third was implemented by someone else entirely.

The initial setup is straightforward, however, because it needs to communicate between the domain controller and Microsoft cloud, which can cause issues if there are firewalls. Normally, domain controllers don't have access to the internet, or at least, that's what's recommended. Installing the tool itself is not hard, however, the firewalls make the process harder.

There are a bunch of URLs that you have to whitelist on the firewalls and you could set up a transparent proxy.

Installing one takes five minutes at a maximum and you need to times that by the number of domain controllers you have. I recall that, in our case, some domain controllers were not up to speed. Their memory CPU utilization was not big enough to handle the load of the network traffic scanning. Therefore, before you install it on the domain controller, the recommendation is to run a tool to see if your domain controllers are capable to handle the sensors. That's something to note for other users considering an installation.

I didn't create an implementation strategy. It's a pretty straightforward tool. You just install it on all the main controllers and then integrate it with all the other Defender components. It's not really a strategy. The only thing to note is if you deal with a security team, they always say that there's already an endpoint protection solution on the domain controller. However, this is different, and this works side-by-side with whatever already exists. Other than that, there's not really a strategy.

For deployment and maintenance, one person would be enough and they would not even have to be full-time as it's a cloud solution. Microsoft does all the maintenance of the backend of the infrastructure and the only thing you have to make sure of is that the sensors are healthy on the domain controllers. That's the only thing you have to do. It's not too much effort.

What about the implementation team?

This tool I install for customers as I am a consultant. When I say, I've got experience, it's not purely for our company as we are an IT company and we consult with customers. I didn't use a third party. I'll typically do it with one of my colleagues.

What was our ROI?

We have not looked at the ROI of Defender.

What's my experience with pricing, setup cost, and licensing?

In terms of the pricing, I don't know off the top of my head the cost, however, it's part of Microsoft 365. It is an EMS-5, an Enterprise Mobility and Security Suite.

It's my understanding that there are no extra costs beyond the standard licensing fee.

Which other solutions did I evaluate?

I do not recall looking at other options before implementing Defender. 

What other advice do I have?

I'm an integrator and consultant.

With the current versions I'm working on, I clarified today that it was up to date. Whatever the latest version is, is the one I am working on. I don't keep track of the version numbers.

It's a cloud-based solution. No on-premise components are required.

I'd rate the solution at a nine out of ten.

I'd advise new users to check their firewalls and make sure they whitelist them, alongside the appropriate URLs. Make sure to enlist a tool to measure if the center can run on your domain controller as well.

Any company should have this tool or a similar tool to it. It's very important to understand if there is a malicious actor in the environment. You can't live without this tool like this in this day and age.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
PeerSpot user
reviewer1687521 - PeerSpot reviewer
Senior Infrastructure Security Engineer at a tech services company with 51-200 employees
Real User
It gives you a holistic view of everything happening in your organization
Pros and Cons
  • "It is easy to set up. Based on the number of devices you would like to set up, you can use scripts, Group Policy, etc. It takes five minutes to set up."
  • "I would like to be able to do remediation from the platform because it is just a scanner right now. If you onboard a device, it shows you what is happening, but you can't use it to fix things. You need to go into the system to fix it instead."

What is our primary use case?

Our use case is endpoint detection and response (EDR). 

You can integrate Microsoft Defender with other solutions. 

How has it helped my organization?

It gives you a holistic view of everything happening in your organization.

You can use it to do a lot of monitoring.

What is most valuable?

The most valuable features are ETL, lab, and monitoring.

What needs improvement?

I would like to be able to do remediation from the platform because it is just a scanner right now. If you onboard a device, it shows you what is happening, but you can't use it to fix things. You need to go into the system to fix it instead.

For how long have I used the solution?

I have been using it for three years.

What do I think about the stability of the solution?

It is quite stable. There are incidents from time to time, which can affect any platform. This affects in different regions or locations within Canada or even Africa. Sometimes users complain and we get a service request that we check to determine if there is an incident. 

How are customer service and support?

When there are issues, sometimes the issue is clear by itself, and other times, I contact Microsoft technical support. Most times, the technical support provides a workaround. My experience with their technical support has been excellent.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We also use Kaspersky and other solutions, but all these solutions integrate with Azure, Microsoft Defender, or Microsoft 365. They don't really work on their own.

How was the initial setup?

It is easy to set up. Based on the number of devices you would like to set up, you can use scripts, Group Policy, etc.

It takes five minutes to set up.

What's my experience with pricing, setup cost, and licensing?

You won't be able to change your tenants from where you deploy them. For example, if you select Canada, they will charge you based on Canadian pricing. If you are also in London, when you deploy in Canada, the pound is higher than Canadian dollars, but your platform resources are billable in Canadian dollars. Using your pounds to pay for any of these things will be cheaper. Or, if you deploy in London, they will charge you based on your local currency.

The package has a lot of features. We just want email and calendar only. This is the standard plan. However, if you want something which extends the product's features, you can get Microsoft business.

What other advice do I have?

I would rate the solution as nine out of 10.

Disclosure: I am a real user, and this review is based on my own experience and opinions.
PeerSpot user
Buyer's Guide
Download our free Microsoft Defender for Identity Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2025
Buyer's Guide
Download our free Microsoft Defender for Identity Report and get advice and tips from experienced pros sharing their opinions.