Try our new research platform with insights from 80,000+ expert users

ArcSight Analytics vs Microsoft Defender for Identity comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

ArcSight Analytics
Average Rating
6.8
Reviews Sentiment
6.7
Number of Reviews
15
Ranking in other categories
User Entity Behavior Analytics (UEBA) (13th)
Microsoft Defender for Iden...
Average Rating
8.8
Reviews Sentiment
6.9
Number of Reviews
26
Ranking in other categories
Advanced Threat Protection (ATP) (5th), Microsoft Security Suite (3rd), Identity Threat Detection and Response (ITDR) (3rd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. ArcSight Analytics is designed for User Entity Behavior Analytics (UEBA) and holds a mindshare of 1.3%, up 1.2% compared to last year.
Microsoft Defender for Identity, on the other hand, focuses on Identity Threat Detection and Response (ITDR), holds 15.4% mindshare, down 23.9% since last year.
User Entity Behavior Analytics (UEBA) Market Share Distribution
ProductMarket Share (%)
ArcSight Analytics1.3%
Exabeam9.6%
IBM Security QRadar9.3%
Other79.8%
User Entity Behavior Analytics (UEBA)
Identity Threat Detection and Response (ITDR) Market Share Distribution
ProductMarket Share (%)
Microsoft Defender for Identity15.4%
CrowdStrike Falcon15.6%
Microsoft Entra ID Protection12.2%
Other56.8%
Identity Threat Detection and Response (ITDR)
 

Featured Reviews

Subhadip Pakrashi - PeerSpot reviewer
A scalable solution that provides a deeper insight and threat analysis about the network
ArcSight Analytics is used to get a deeper insight and threat analysis about the network. The solution's threat analysis gives a good view of the network. We can then compare those vulnerabilities and CVS scores worldwide and get a good understanding of how likely the network is to be hit. The kind of report ArcSight Analytics gives is really good. ArcSight Analytics is a very scalable solution that is easy to deploy.
Peter Arabomen - PeerSpot reviewer
Has supported hybrid identity management while integrating well with cloud directory services
The only challenge I have with Microsoft Defender for Identity is the latency. I may not put that entirely on Microsoft, because latency could be network related. At times when trying to authenticate, the prompt is delayed. We tried implementing passwordless authentication, especially for on-premises workloads, but we haven't been able to achieve that. Passwordless authentication is part of the identity functionalities, particularly when it comes to enforcing passwordless for on-premises workloads. In terms of improvements, you can't create OUs on Azure AD. Regarding giving users privileges on what they can do across different OUs, I haven't seen that feature on Microsoft Defender for Identity. Microsoft Defender for Identity needs to be able to plug into third-party applications that are not Microsoft. For instance, with a human resource application used to manage users and leave requests, when staff leaves the organization, they are first exited from that application before AD. Integration between Azure AD and third-party applications would allow automatic syncing when removing staff. The initial setup of Microsoft Defender for Identity is not hard. However, setup is one thing, and getting value from the application end-to-end is another. It can be set up and running from the first day but not functioning optimally. Initially, when we did the setup, it wasn't optimal. Over time, with continuous improvement, which we're still doing, we've gotten to a comfortable level, but there's still room for improvement.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features are that you get lots of connectors, which make it easy to log in to my ASM, and lots of prebuilt roles from the company."
"ArcSight Analytics is used to get a deeper insight and threat analysis about the network."
"This solution allows us to identify connections for all users."
"The ability to correlate different logs is the solution's most valuable feature."
"Less resource consumption in terms of memory and processing."
"One of the most valuable features is the alerts."
"Allows multiple integrations with multiple systems in a stable and flexible fashion."
"The two most valuable features of this solution are its stability and scalability."
"This solution has advanced a lot over the last few years."
"The feature I like the most about Defender for Identity is the entity tags. They give you the ability to identify sensitive accounts, devices, and groups. You also have honeytoken entities, which are devices that are identified as "bait" for fraudulent actors."
"All the integration it has with different Microsoft packages, like Teams and Office, is good."
"Microsoft Defender for Identity provides excellent visibility into threats by leveraging real-time analytics and data intelligence."
"It automates routine testing and helps automate the finding of high-value alerts."
"The basic security monitoring at its core feature is the most valuable aspect. But also the investigative parts, the historical logging of events over the network are extremely interesting because it gives an in-depth insight into the history of account activity that is really easy to read, easy to follow, and easy to export."
"The feature I like most is that you can create your own customized detection rules. It has a lot of default alerts and rules, but you can customize them according to your business needs."
"The solution’s alerting is fairly efficient."
 

Cons

"[There is] complexity in maintaining it and managing it. It's not easy to use. It requires a lot of training."
"The interactive dashboard is complicated and you need to have training in order to use it, so I think that it could be made easier to use."
"Currently, there are no compatible connectors for this solution, which means we have to depend on FlexConnectors."
"The customer service could be improved, and additional integrations with other APIs could be added."
"ArcSight is not a user-friendly solution and the interface needs to be improved."
"I faced stability issues with Windows Operating System. The installed connectors hang if they remain idle for a long period of time."
"It needs more user analytics and aggregation user queries. And it's slow. When you query over ArcSight, it is very slow."
"I would like to see orchestration."
"There is no option to remedy an issue directly from the console. If we see an alert, we can't fix it from the console. Instead, we must depend on other Microsoft products, such as MDE. That is a significant drawback. It simply works as a scanner, which can sometimes put enough load on the sensors. Immediate actions should be possible from the dashboard because. It can prevent issues from spreading further."
"One potential area for improvement could be exploring flexibility in the installation of Microsoft Defender for Identity agents."
"When the data leaves the cloud, there are security issues."
"We observe a lot of false positives. Sometimes, when we go for a coffee break, we lock our screens. Locking the screen has a separate Windows event ID and sometimes I see it is detected as a failed login."
"An area for improvement is the administrative interface. It's basic compared to other administrative centers. They could make it more user-friendly and easier to navigate."
"They should improve the automation for impossible travel detection. When connected to Wi-Fi and then to VPN, the system sometimes interprets the IP address change as impossible travel."
"The areas of Microsoft Defender for Identity that can be improved include its cost, which is quite expensive when integrated into Sentinel. Additionally, there is room for improvement in its integration with non-Microsoft applications and systems."
"One improvement I would recommend is the integration of an admin application within Teams, allowing easy access to attack information on a mobile platform to promptly alert affected users and their friends."
 

Pricing and Cost Advice

"It can range between $30,000 and $40,000 USD, and can go up to $500,000 and $600,000 USD."
"The monthly licensing fee is around $20,000. There aren't any costs in addition to the standard licensing fee."
"This solution is expensive."
"ArcSight Analytics is a bit expensive compared with other tools in terms of licensing costs, training, hardware implementation, and support."
"My customers pay a yearly licensing fee for ArcSight Analytics."
"In addition to the costs of standard licensing fees, there is the cost of labor for maintenance."
"Defender for Identity is a little more expensive than other Microsoft products. Identity and Microsoft Defender for Cloud are both a bit costly."
"It is very affordable considering that other SIEM solutions are much more expensive and have many more licensing restrictions and fees."
"Microsoft Defender for Identity comes as part of the Microsoft E5 licensing stack."
"The product is costly, and we had multiple discussions with accounting to receive a discounted rate. However, on the open market, the tool is expensive."
"You won't be able to change your tenants from where you deploy them. For example, if you select Canada, they will charge you based on Canadian pricing. If you are also in London, when you deploy in Canada, the pound is higher than Canadian dollars, but your platform resources are billable in Canadian dollars. Using your pounds to pay for any of these things will be cheaper. Or, if you deploy in London, they will charge you based on your local currency."
report
Use our free recommendation engine to learn which User Entity Behavior Analytics (UEBA) solutions are best for your needs.
867,370 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
No data available
Computer Software Company
15%
Financial Services Firm
13%
Manufacturing Company
7%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business4
Midsize Enterprise4
Large Enterprise7
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise3
Large Enterprise14
 

Questions from the Community

What SOC product do you recommend?
For tools I’d recommend: -SIEM- LogRhythm -SOAR- Palo Alto XSOAR Doing commercial w/o both (or at least an XDR) is asking to miss details that are critical, and ending up a statistic. Also, rememb...
What do you like most about ArcSight Analytics?
ArcSight Analytics is used to get a deeper insight and threat analysis about the network.
What is your experience regarding pricing and costs for ArcSight Analytics?
My customers pay a yearly licensing fee for ArcSight Analytics.
What do you like most about Microsoft Defender for Identity?
Microsoft Defender for Identity provides excellent visibility into threats by leveraging real-time analytics and data intelligence.
What needs improvement with Microsoft Defender for Identity?
Microsoft can improve Microsoft Defender for Identity by ensuring that installation prerequisites are included in the setup process. Installing the solution presents challenges as numerous logs and...
What is your primary use case for Microsoft Defender for Identity?
My personal use case for Microsoft Defender for Identity is that it is amazing. It provides very good and deep analytics about whatever is happening in the on-premises Active Directory. The sensors...
 

Also Known As

ArcSight User Behavior Analytics, ArcSight UBA
Azure Advanced Threat Protection, Azure ATP, MS Defender for Identity
 

Overview

 

Sample Customers

Information Not Available
Microsoft Defender for Identity is trusted by companies such as St. Luke’s University Health Network, Ansell, and more.
Find out what your peers are saying about ArcSight Analytics vs. Microsoft Defender for Identity and other solutions. Updated: July 2023.
867,370 professionals have used our research since 2012.