Microsoft Defender XDR vs Microsoft Purview eDiscovery comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Microsoft Defender XDR
Ranking in Microsoft Security Suite
1st
Average Rating
8.4
Number of Reviews
85
Ranking in other categories
Endpoint Detection and Response (EDR) (7th), Extended Detection and Response (XDR) (5th)
Microsoft Purview eDiscovery
Ranking in Microsoft Security Suite
26th
Average Rating
7.0
Number of Reviews
3
Ranking in other categories
eDiscovery (3rd)
 

Mindshare comparison

As of June 2024, in the Microsoft Security Suite category, the mindshare of Microsoft Defender XDR is 4.9%, down from 10.4% compared to the previous year. The mindshare of Microsoft Purview eDiscovery is 0.4%, down from 0.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Microsoft Security Suite
Unique Categories:
Endpoint Detection and Response (EDR)
8.4%
Extended Detection and Response (XDR)
23.3%
eDiscovery
31.6%
 

Featured Reviews

Brian Mulambuzi - PeerSpot reviewer
May 14, 2024
Helps improve our visibility, our security posture, and defends against advanced threats
Microsoft Defender XDR provides a unified identity and access management platform. It does a good job with identity protection. Including identity and access management within Defender XDR is valuable because it streamlines our organization's security by consolidating multiple tools into one. This eliminates the need to manage and pay for separate solutions and licenses, simplifying our security posture. Microsoft Defender XDR has improved our visibility, making us more efficient by providing threat details and remediation steps as well as improving our security posture. It safeguards our organization by preventing advanced threats like ransomware and business email compromise, along with stopping lateral movement within our network that could enable attackers to spread and gain wider access. It includes the ability to stop attacks and adapt to evolving threats. This is an important feature for us. We have been enabled to discontinue using Microsoft Sentinel. Microsoft Defender XDR helps save costs through the licensing for businesses which is around $20 each and helps save time for our security team.
Deepesh Mehtani - PeerSpot reviewer
Nov 30, 2023
Helps to collect data from SharePoint and comes with good search and data connectivity features
The tool's search options and data connectivity are good. Microsoft Purview eDiscovery is valuable for collecting information. It makes it easier for us to provide information when a user is looking for specific data from another user. For instance, it's very convenient if a user needs data from their email but doesn't want to navigate through ten years of logs (since we've migrated everything to Office 365). The old emails and data in SharePoint are easily searchable. So, I can quickly go there, retrieve the necessary information, such as a PSD card or a data file, and grant access to the users.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The integration, visibility, vulnerability management, and device identification are valuable."
"Microsoft XDR's system of analysis and investigation is super convenient for our customers. It integrates with other Microsoft solutions like Defender for 365 to protect email traffic from malicious external web links and phishing."
"The common and advanced security policies for threat hunting and blocking attacks are valuable."
"Its most significant advantage lies in its affordability."
"The unified view of the threat landscape on a central dashboard is the most valuable feature."
"There is also one dashboard that shows us the status of many controls at once and the details I can get... It gives a great overview of many areas, such as files, emails, chats, and links. Even with the apps, it gives you a great overview. In one place you can see where you should look into things more deeply..."
"Microsoft Defender's most critical component is its CASB solution. It has many built-in policies that can improve your organization's cloud security posture. It's effective regardless of where your users are, which is critical because most users are working from home. It's cloud-based, so nothing is on-premise."
"I like that it's stable. It's been stable for a long time, and Microsoft Defender has done a good job there."
"I think eDiscovery Premium has made dealing with data from Teams much more accessible than any other platform."
"The tool has been beneficial. Some of our previous users left the organization without sharing the information they had at a personal level. This information was related to the organization, and they didn't disclose it. Thanks to the product, it's easy for me to search and find out what communication a specific user has done, whether it's from SharePoint or any other platform. With Microsoft Purview eDiscovery, we can easily retrieve and restore this data."
"The machine learning wasn't half bad. I really like that part. I thought it was novel. It pretty much automated it, once you trained the model."
 

Cons

"The logs could be better."
"There are still some components, such as vulnerability management within the vendor product, where improved integration would be beneficial."
"There are a few technical issues with Defender XDR that can be improved. Sometimes, the endpoint devices are not reporting properly to the Defender 365 portal. When you're getting all the information from the Microsoft portal, the devices are sometimes not in sync. We have hundreds of endpoint devices, some needing to be onboarded again."
"The documentation on their website is somewhat outdated and doesn't show properly. I wanted to try a query in Microsoft Defender 365. When I opened the related documentation from the security blog on the Microsoft website, the figures were not showing. It was difficult to understand the article without having the figures. The figures were there in the article, but they were not getting loaded, which made the article obsolete."
"Microsoft frequently changes the names of its products, sometimes even renaming entire portals or features."
"Intrusion detection and prevention would be great to have with 365 Defender."
"The only problem I find is that the use cases are built-in. There is no template available that you can modify according to your organization's standards. What they give is very generic, the market standard, but that might not be applicable to every organization."
"The patching capability should be there. Patching is something that you cannot do even though you see the vulnerabilities present in your environment. For patching, you have to depend on another solution."
"I see two significant challenges with many of my clients. One is that there are some functionality gaps compared to specialized tools in the legal industry, like a legal hold tool or a document review tool. They have features that Purview eDiscovery lacks. Those gaps create a situation where I almost have to do things twice. I need to collect all my data in eDiscovery and ship it to another platform to complete the review."
"Microsoft Purview eDiscovery should be cheaper."
"Purview eDiscovery works, but it's not entirely perfect. There were times when search results would get hung up or error codes would be presented and we'd have to contact Microsoft to get that sorted out."
 

Pricing and Cost Advice

"For Defender, they have Endpoint Plan 1 and Endpoint Plan 2, but I don't know on what basis they have classified Endpoint Plan 1 and Plan 2, but it has given me enough pain to pick and design Endpoint Plan 1 or Endpoint Plan 2 for my organization. In fact, we are still struggling with it. Too many SKUs are confusing. There should not be too many SKUs, and they shouldn't charge for every new feature."
"With the little idea I have about the costs, I can say that XDR tools tend to be a bit expensive. If you are using Microsoft Defender XDR, then you need to go for a subscription-based pricing model."
"The price of the solution is high compared to others and we have lost some customers because of it."
"The most valuable licensing option is expensive, so pricing could be improved. Licensing options for this solution also need to be consolidated, because they frequently change."
"Microsoft Defender XDR is included in our license."
"Microsoft purposely makes its license combinations complex and includes combinations like Microsoft 365 E3 and Microsoft 365 E5, Office 365 E3, Office 365 E5, and Office 365 E1, so you get confused. Microsoft tries to sell you a bundle of a lot of things together."
"Microsoft should provide lower-level licensing options. They should do it in such a way that even an individual could purchase a license, and it should be entirely flexible."
"On average, we pay around 55 euros per user for the services and features we receive."
"Microsoft Purview eDiscovery comes as part of Microsoft 365 licenses."
"In the positions that I've had through contracting over the years, I've heard talk of it being overpriced and underperforming compared to its competitors."
report
Use our free recommendation engine to learn which Microsoft Security Suite solutions are best for your needs.
787,779 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
17%
Financial Services Firm
10%
Government
8%
Manufacturing Company
8%
Computer Software Company
14%
Government
13%
Financial Services Firm
13%
Manufacturing Company
5%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about Microsoft 365 Defender?
Microsoft Defender XDR provides strong identity protection with comprehensive insights into risky user behavior and potential indicators of compromise.
What is your experience regarding pricing and costs for Microsoft 365 Defender?
Microsoft Defender XDR is expensive, especially for the full suite functionality. However, when compared to buying multiple-point solutions separately, it may be comparable in price. Overall, it is...
What needs improvement with Microsoft 365 Defender?
Improving scalability, especially for very large tenants, could be beneficial for Microsoft Defender XDR. Additionally, enhancing the privilege access management capability would make it a better s...
What do you like most about Microsoft Purview eDiscovery?
The tool has been beneficial. Some of our previous users left the organization without sharing the information they had at a personal level. This information was related to the organization, and th...
What is your experience regarding pricing and costs for Microsoft Purview eDiscovery?
Microsoft Purview eDiscovery comes as part of Microsoft 365 licenses.
What needs improvement with Microsoft Purview eDiscovery?
Microsoft Purview eDiscovery should be cheaper.
 

Also Known As

Microsoft 365 Defender, Microsoft Threat Protection, MS 365 Defender
No data available
 

Overview

 

Sample Customers

Accenture, Deloitte, ExxonMobil, General Electric, IBM, Johnson & Johnson and many others.
Information Not Available
Find out what your peers are saying about Microsoft Defender XDR vs. Microsoft Purview eDiscovery and other solutions. Updated: May 2024.
787,779 professionals have used our research since 2012.