Try our new research platform with insights from 80,000+ expert users

AWS GuardDuty vs Microsoft Defender for Cloud comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 19, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.6
SentinelOne Singularity Cloud boosts efficiency and saves costs by automating tasks, reducing vulnerabilities, and improving security compliance.
Sentiment score
1.0
Amazon GuardDuty enhances threat detection and response times, improving security, operational efficiency, and customer trust for businesses.
Sentiment score
6.9
Microsoft Defender for Cloud boosts security and efficiency, integrates with Azure, reduces costs, prevents breaches, and offers proactive defense.
The detailed information PingSafe gives about how to fix vulnerabilities reduces the time spent on remediation by about 70 to 80 percent.
Security and Compliance Manager at Bidgely
After implementing SentinelOne, it takes about five to seven minutes.
Cloud engineer at a construction company with 5,001-10,000 employees
Our ability to get in and review our vulnerability stance, whether daily, monthly, weekly, or whatever it might be, has drastically improved over our prior provider.
IT Support Specialist at a non-tech company with 201-500 employees
Defender proactively indexes and analyzes documents, identifying potential threats even when inactive, enhancing preventative security.
Endpoint management at a government with 10,001+ employees
Identifying potential vulnerabilities has helped us avoid costly data losses.
Manager at CBTS
Compared to not having Microsoft Defender for Cloud in place, we definitely saw an advantage by not having downtime due to a security threat.
Principal Microsoft Consultant at MicroAge
 

Customer Service

Sentiment score
7.8
SentinelOne Singularity Cloud Security's service is praised for support, insights, and staff, though response times and knowledge vary.
Sentiment score
9.2
AWS GuardDuty support is praised for responsiveness and knowledgeability, though some variability in quality and wait times exists.
Sentiment score
6.3
Microsoft Defender for Cloud support is responsive at higher levels, but experiences vary with mixed satisfaction due to delays.
When we send an email, they respond quickly and proactively provide solutions.
Security and Compliance Manager at Bidgely
They took direct responsibility for the system and could solve queries quickly.
Senior DevOps Engineer at a tech services company with 501-1,000 employees
Having a reliable team ready and willing to assist with any issues is essential.
Director, DevOps at Relay Network
I rate technical support for AWS GuardDuty as ten out of ten; AWS has very good security support overall.
Senior IT Auditor at Ernst & Young
I appreciate the support for AWS; it is relatively fast, and their SLAs meet my needs.
Senior Security Analyst (AppSec) at ELETROBRAS
Since security is critical, we prefer a quicker response time.
Manager at CBTS
The support team was very responsive to queries.
Programme Manager- Cyber Fusion- Group CISO at a financial services firm with 10,001+ employees
They understand their product, but much like us, they struggle with the finer details, especially with new features.
Endpoint management at a government with 10,001+ employees
 

Scalability Issues

Sentiment score
8.2
SentinelOne Singularity Cloud Security is scalable, user-friendly, effective, and integrates well, though improvements in manual processes are needed.
Sentiment score
7.8
Amazon GuardDuty excels in scalable threat management, integrating seamlessly with AWS resources to support diverse organizational needs effectively.
Sentiment score
7.4
Microsoft Defender for Cloud is scalable, integrating across environments effortlessly, suitable for all enterprise sizes with flexible performance.
I would rate it a 10 out of 10 for scalability.
IT Engineer at a venture capital & private equity firm with 1,001-5,000 employees
Scalability is no longer a concern because Cloud Native Security is a fully cloud-based resource.
CISO at a computer software company with 201-500 employees
I would rate the scalability of PingSafe 10 out of 10.
Sr DevOps Engineer at a media company with 51-200 employees
It is designed to scale based on usage, which makes it very adaptable for varying demands.
AWS Cloud Engineer at Standard Telephones and Cables
As we have reduced our on-premises infrastructure, it is about how we can migrate workloads to the cloud to make it easier, and then having everything fully encompassed and secured within that area makes it much easier for us to scale as needed and grow.
Principal Microsoft Consultant at MicroAge
We are using infrastructure as a code, so we do not have any scalability issues with Microsoft Defender for Cloud implementation because our cloud automatically does it.
Senior Cloud Platform Engineer at Deutsche Börse
It has multiple licenses and features, covering infrastructures from a hundred to five hundred virtual machines, without any issues.
Snr. Infrastructure Architect (Data Centre) at LogicEra
 

Stability Issues

Sentiment score
8.2
SentinelOne Singularity Cloud Security is stable with occasional minor UI glitches, seamlessly integrates with AWS, and is highly rated.
Sentiment score
8.6
AWS GuardDuty is praised for stability, reliability, and integration, with high user ratings and effective multiple account management.
Sentiment score
7.5
Microsoft Defender for Cloud is stable and reliable, with minimal issues mainly during updates, ensuring strong user satisfaction.
SentinelOne Singularity Cloud is incredibly reliable.
Security Analyst at Intersistemi Italia s.p.a.
We contacted Cloud Native Security, and they addressed it in a day.
DevSecOps Engineer at a tech company with 1,001-5,000 employees
The only downtime we had was when switching from V1 to V2 but it was smooth.
Cloud Security Specialist at a insurance company with 10,001+ employees
The stability of GuardDuty is extremely reliable.
DevOps Engineer at a consultancy with 10,001+ employees
It is backed by machine learning, and AWS has strong machine learning models and the capacity to support this with advanced computing power.
AWS Cloud Engineer at Standard Telephones and Cables
Defender's stability has been flawless for us.
Engineer at a computer software company with 201-500 employees
Microsoft Defender for Cloud is very stable.
Cloud architect at a tech vendor with 1,001-5,000 employees
Microsoft sometimes changes settings or configurations without transparency.
Senior Cloud Platform Engineer at Deutsche Börse
 

Room For Improvement

SentinelOne Singularity Cloud needs improvements in search, cost, integration, user experience, and security features to enhance usability.
AWS GuardDuty users seek mobile access, better integration, improved dashboards, cost clarity, and enhanced threat intelligence and detection accuracy.
Microsoft Defender for Cloud users seek better automation, clarity, integration, AI features, and comprehensive analytics for improved security management.
If they can merge Kubernetes Security with other modules related to Kubernetes, that would help us to get more modules in the current subscription.
IT Engineer at a venture capital & private equity firm with 1,001-5,000 employees
As organizations move to the cloud, a cloud posture management tool that offers complete cloud visibility becomes crucial for maintaining compliance.
CISO at a computer software company with 201-500 employees
I would also like to see Cloud Native Security offer APIs that allow us to directly build dashboards within the platform.
Senior Cybersecurity Engineer at a computer software company with 11-50 employees
A unified dashboard that aggregates findings across all regions without requiring manual aggregation could enhance convenience for users.
AWS Cloud Engineer at Standard Telephones and Cables
Further integration with services like API Gateway would be beneficial.
DevOps Engineer at a consultancy with 10,001+ employees
Comparing AWS GuardDuty to similar products from Microsoft, Microsoft has a product called Sentinel, which is a completely integrated solution that basically does everything from vulnerability management to managing log analytics.
Senior IT Auditor at Ernst & Young
Microsoft, in general, could significantly improve its communication and support.
Endpoint management at a government with 10,001+ employees
It would be beneficial to streamline recommendations to avoid unnecessary alerts and to refine the severity of alerts based on specific environments or environmental attributes.
Works at Coca-Cola HBC
The artificial intelligence features could be expanded to allow the system to autonomously manage security issues without needing intervention from admins.
Cloud Consultant at i-Community AG
 

Setup Cost

SentinelOne Singularity Cloud Security offers flexible, modular pricing, deemed fair and competitive, with discounts enhancing affordability and value.
AWS GuardDuty offers flexible, scalable pay-as-you-go pricing, making it cost-effective for enterprises without upfront investments.
Microsoft Defender for Cloud is scalable, offering free and paid versions with costs averaging $15 monthly per server.
With very little negotiation involved, we just let them know what we could pay and they were willing to meet us at slightly above what we paid with Sophos, which was still very fair for what we were looking at.
IT Support Specialist at a non-tech company with 201-500 employees
There are some tools that are double the cost of Cloud Native Security.
IT Engineer at a venture capital & private equity firm with 1,001-5,000 employees
I recall Cloud Native Security charging a slightly higher premium previously.
Senior Cybersecurity Engineer at a computer software company with 11-50 employees
GuardDuty is very cheap and operates on a pay-as-you-go basis.
AWS Cloud Engineer at Standard Telephones and Cables
The pricing of this tool is cheaper compared to other tools from other vendors, which are more expensive.
Senior Security Analyst (AppSec) at ELETROBRAS
AWS GuardDuty is an expensive feature
Senior IT Auditor at Ernst & Young
Security has essentially no cost when compared to the cost of a breach.
Director, Cloud and Modern Workplace at Informanix Technology Group
Every time we consider expanding usage, we carefully evaluate the necessity due to cost concerns.
Programme Manager- Cyber Fusion- Group CISO at a financial services firm with 10,001+ employees
We appreciate the licensing approach based on employee count rather than a big enterprise license.
Manager, Microsoft Technology Alliance at Silverfort
 

Valuable Features

SentinelOne Singularity Cloud offers easy usability, automation, and integrations, enhancing security with real-time detection and response capabilities.
AWS GuardDuty provides scalable, cost-effective security through threat detection, automated response, and seamless integration with AWS and third-party tools.
Microsoft Defender for Cloud enhances security with AI-based threat detection, multi-cloud support, and a unified portal for comprehensive management.
This helps visualize potential attack paths and even suggests attack paths a malicious actor might take.
Security Engineer-DevSecOps at a computer software company with 51-200 employees
The infrastructure-as-code feature is helpful for discovering open ports in some of the modules.
DevSecOps Engineer at a tech company with 1,001-5,000 employees
This tool has been helpful for us. It allows us to search for vulnerabilities and provides evidence directly on the screen.
Cloud Security Specialist at a insurance company with 10,001+ employees
It notifies you immediately when something goes wrong, allowing quick response to threats.
DevOps Engineer at a consultancy with 10,001+ employees
Enabling GuardDuty with a single click allows it to start analyzing data for threats without requiring additional software deployment or updates.
AWS Cloud Engineer at Standard Telephones and Cables
The great benefits of using AWS GuardDuty are that it is connected to all ecosystems from the AWS environment, and I can detect threats faster and locate all the information in a single tool.
Senior Security Analyst (AppSec) at ELETROBRAS
The most valuable feature for me is the variety of APIs available.
Programme Manager- Cyber Fusion- Group CISO at a financial services firm with 10,001+ employees
This feature significantly aids in threat detection and enhances the user experience by streamlining security management.
Cloud Consultant at i-Community AG
The most valuable feature is the recommendations provided on how to improve security.
Cloud architect at a tech vendor with 1,001-5,000 employees
 

Categories and Ranking

SentinelOne Singularity Clo...
Sponsored
Ranking in Cloud Workload Protection Platforms (CWPP)
4th
Average Rating
8.6
Reviews Sentiment
7.7
Number of Reviews
114
Ranking in other categories
Vulnerability Management (4th), Cloud and Data Center Security (3rd), Container Security (3rd), Cloud Security Posture Management (CSPM) (3rd), Cloud-Native Application Protection Platforms (CNAPP) (3rd), Compliance Management (2nd), AI Software Development (1st), AI Observability (2nd)
AWS GuardDuty
Ranking in Cloud Workload Protection Platforms (CWPP)
2nd
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
25
Ranking in other categories
No ranking in other categories
Microsoft Defender for Cloud
Ranking in Cloud Workload Protection Platforms (CWPP)
1st
Average Rating
8.0
Reviews Sentiment
6.8
Number of Reviews
87
Ranking in other categories
Vulnerability Management (6th), Container Management (7th), Container Security (7th), Cloud Security Posture Management (CSPM) (4th), Cloud-Native Application Protection Platforms (CNAPP) (4th), Data Security Posture Management (DSPM) (5th), Microsoft Security Suite (7th), Compliance Management (4th), Cloud Detection and Response (CDR) (2nd)
 

Mindshare comparison

As of January 2026, in the Cloud Workload Protection Platforms (CWPP) category, the mindshare of SentinelOne Singularity Cloud Security is 3.8%, up from 2.2% compared to the previous year. The mindshare of AWS GuardDuty is 14.8%, up from 12.4% compared to the previous year. The mindshare of Microsoft Defender for Cloud is 16.7%, up from 14.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cloud Workload Protection Platforms (CWPP) Market Share Distribution
ProductMarket Share (%)
Microsoft Defender for Cloud16.7%
AWS GuardDuty14.8%
SentinelOne Singularity Cloud Security3.8%
Other64.7%
Cloud Workload Protection Platforms (CWPP)
 

Featured Reviews

SC
Information Security Engineer at DataVigilant Infotech
Enables us to prioritize and effectively address critical security issues
Evidence-based reporting helps us to prioritize and solve critical security issues. The new visualization feature demonstrates how an attacker can enter the system, highlighting the potential path that can be exploited and outlining all the steps the attacker could take. With that visibility, we can ensure the perimeter is strong and attackers cannot enter, thus reducing the risk. It has helped us prioritize issues. The visibility into how an attack could happen is valuable. For example, it highlights the system vulnerability and outlines where an attack could propagate. The visualization helps me to prioritize remediation, and if I don't know where to start, I can check to see the score that enables me to prioritize issues. I am using infrastructure-as-code scanning, and it's one of the useful features. In pre-production, it identifies embedded secrets and misconfigurations, including issues with Kubernetes or some privileged containers. This feature allows us to pass the audit and secure IaC code so that it isn't easily exploitable by attackers. We can more proactively work to identify and resolve vulnerabilities by using the dashboard and the alerting system that SentinelOne provides. It helps us with audits and compliance. We can show the compliance in percentage. We can confidently say that our company or infrastructure is very secure. It has improved our security posture by 30% to 35%. It has reduced our false positives by 30%. It has helped teams collaborate better. The security team manages SentinelOne Singularity Cloud Security, and when it flags vulnerabilities, they are forwarded to DevOps for remediation. Previously, we needed to identify and report the issues, but there would be lapses in communication. Now, there is a centralized dashboard that anyone can look at and see the open issues and work on them.
SK
Senior IT Auditor at Ernst & Young
Has provided automated threat detection and daily malicious activity insights while supporting seamless orchestration with existing dashboards
I would assess the integration of AWS GuardDuty with Threat Intelligence as majorly positive; no threat intelligence is 100% accurate, and there are a few false positives, but as a security engineer, this must be accepted, and overall, the response and service is good for us. We do not directly use AWS GuardDuty dashboard by itself, as we have our own integrated security dashboard; AWS GuardDuty gives the feed to that dashboard, and it's giving us a satisfactory view of how the security landscape looks. We use metrics such as zero-day threats, any malicious traffic, and any traffic which originates from OFAC countries to measure its effectiveness, as we are majorly into a financial institution, as any traffic that is from a malicious IP or a rogue device. I don't see any significant negative points regarding AWS GuardDuty; it's a good product to have if you're a cloud consumer. I rate AWS GuardDuty nine out of ten overall.
David Birhange - PeerSpot reviewer
Director, Cloud and Modern Workplace at Informanix Technology Group
Brings together cloud security insights through a unified view and supports agentless protection for virtual machines
Copilot and similar features are already being used, though not necessarily for Microsoft Defender for Cloud specifically. We are trying to get more experience before rolling out most of Microsoft Defender for Cloud's AI capabilities. This is definitely on our to-do list, and the priority is urgent as we seek to learn more about these capabilities. The GenAI threat protection from Microsoft Defender for Cloud has not been enabled yet. There are many unknowns with AI applications. AI agents will operate while you're not present, whether you are sleeping or awake, and it's unclear whether there would be any exfiltration of data or how data is being managed. Microsoft Purview is being used extensively, and there is significant development going on with DSPM that will be rolled out to address security concerns. Data labeling and proper demarcation for sensitivity of data before it is received are being actively pursued.
report
Use our free recommendation engine to learn which Cloud Workload Protection Platforms (CWPP) solutions are best for your needs.
879,672 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
14%
Manufacturing Company
10%
Government
5%
Financial Services Firm
15%
Computer Software Company
12%
Manufacturing Company
9%
Government
6%
Financial Services Firm
13%
Computer Software Company
12%
Manufacturing Company
9%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise20
Large Enterprise53
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise3
Large Enterprise15
By reviewers
Company SizeCount
Small Business27
Midsize Enterprise10
Large Enterprise49
 

Questions from the Community

What do you like most about PingSafe?
The dashboard gives me an overview of all the things happening in the product, making it one of the tool's best featu...
What is your experience regarding pricing and costs for PingSafe?
I think the pricing of SentinelOne Singularity Cloud Security is a bit high.
What needs improvement with PingSafe?
We did not try to use the threat investigations feature from SentinelOne Singularity Cloud Security.Drift detection w...
What do you like most about Amazon GuardDuty?
With anomaly detection, active threat monitoring, and set correlation, GuardDuty alerts me to any unusual user behavi...
What is your experience regarding pricing and costs for Amazon GuardDuty?
AWS GuardDuty is an expensive feature, and while you can't expect the price to be low, it can be lower because it's p...
What needs improvement with Amazon GuardDuty?
AWS GuardDuty is a good product; it's doing its job right now, and I don't see any additional improvements needed. Co...
How is Prisma Cloud vs Azure Security Center for security?
Azure Security Center is very easy to use, integrates well, and gives very good visibility on what is happening acros...
What is your experience regarding pricing and costs for Microsoft Defender for Cloud?
My experience with pricing, setup cost, and licensing for Microsoft Defender for Cloud was pretty straightforward. We...
What needs improvement with Microsoft Defender for Cloud?
Microsoft Defender for Cloud can be improved. An additional feature that should be included in the next release is Ze...
 

Also Known As

PingSafe
No data available
Microsoft Azure Security Center, Azure Security Center, Microsoft ASC, Azure Defender
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

Information Not Available
autodesk, mapbox, fico, webroot
Microsoft Defender for Cloud is trusted by companies such as ASOS, Vatenfall, SWC Technology Partners, and more.
Find out what your peers are saying about AWS GuardDuty vs. Microsoft Defender for Cloud and other solutions. Updated: December 2025.
879,672 professionals have used our research since 2012.