Try our new research platform with insights from 80,000+ expert users

Azure Key Vault vs Microsoft Defender External Attack Surface Management comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Azure Key Vault
Ranking in Microsoft Security Suite
15th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
52
Ranking in other categories
Enterprise Password Managers (1st), Certificate Management Software (1st), Secrets Management Tools (2nd)
Microsoft Defender External...
Ranking in Microsoft Security Suite
33rd
Average Rating
7.6
Reviews Sentiment
6.0
Number of Reviews
2
Ranking in other categories
Attack Surface Management (ASM) (14th)
 

Mindshare comparison

As of January 2026, in the Microsoft Security Suite category, the mindshare of Azure Key Vault is 1.5%, up from 1.1% compared to the previous year. The mindshare of Microsoft Defender External Attack Surface Management is 0.8%, up from 0.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Microsoft Security Suite Market Share Distribution
ProductMarket Share (%)
Azure Key Vault1.5%
Microsoft Defender External Attack Surface Management0.8%
Other97.7%
Microsoft Security Suite
 

Featured Reviews

Rajthilak BS - PeerSpot reviewer
Associate Vice President (Data Security & Protection - Confidential AI) at Standard Chartered Bank
Have addressed compliance challenges but still struggle with seamless integration of certificate issuance between environments
In terms of Azure Key Vault improvements, we have to compare the competitor. If we consider AWS, our bank has Microsoft PKI, which is a Microsoft product, for the entire digital certificate infrastructure. Even in the cloud, when it is AWS, the internal certificates are MS PKI. When we had a problem, users had to come to on-premise to get a certificate and import it to AWS Certificate Manager and assign it. We wondered why we could not issue the certificate directly from the cloud for cloud users. There was a simple way in AWS. They have a Private Certificate Authority (PCA) and Amazon Certificate Manager. Private Certificate Authority issues certificates to Amazon services. They also provide Amazon Certificate Manager to store and deploy certificates. These are two neat components - one is an issuer and another is storage and deployment solutions for certificates. With PCA, I can directly enable it and get certificates from AWS itself. AWS can issue SSL/TLS certificates if you enable it directly. If you consider Azure, it is not very clear. Even the naming convention, Key Vault, might not suggest that this is a PKI or certificate manager. You cannot issue certificates directly. They have app certificates and did not have a clear-cut certificate management solution in the cloud when I worked at that time. I am not sure whether they have updated Azure Key Vault as a full-fledged PKI solution now. From what I saw, it was not a full-fledged PKI solution. We are not majorly using Azure Key Vault because it is only for storing secrets. If some solutions can provide guidance on how we can maximize leverage, we can immediately look forward to doing that. We already have some business problems we want to solve. While our primary focus is AWS, many of the services such as ADO are running on Azure, and the secondary services are growing bigger.
AndyChan3 - PeerSpot reviewer
General manager at a tech services company with 201-500 employees
Enhanced visibility and exposes vulnerabilities but needs more integration
I am currently in the pilot stage of implementing Microsoft External Attack Surface Management (EASM). My organization is transitioning to a comprehensive track of Microsoft solutions, and we will move to full-scale production in another year, maybe Microsoft External Attack Surface Management…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"With Azure Key Vault, we can generate our own keys and then import them inside the system, which provides a higher level of security than provider-managed keys."
"There is advanced data protection available. We're working in a highly regulated environment, and this is essential to us."
"The access policy feature helps secure content and resources."
"It allows me to run applications using these certificates without directly installing them."
"The product's integration capabilities are good."
"The best feature is the integrity of the .NET applications in our company."
"The integration with other Azure services is one of the standout features for me. It allows us to use secrets from the Azure Key Vault seamlessly without direct interaction.Additionally, the ability to easily mark secrets for expiration and receive notifications is invaluable."
"We use Azure Key Vault for securing secret connection streams, like API secrets, Azure services Secret Key, and AD Client Secret."
"It seems to be better at protecting from cyberattacks."
"Microsoft External Attack Surface Management helps improve the visibility of my exposed vulnerabilities and provides an overview of my security posture across the globe."
"Microsoft External Attack Surface Management helps improve the visibility of my exposed vulnerabilities and provides an overview of my security posture across the globe."
 

Cons

"There are additional charges for data transfers. However, the pricing is mostly reasonable for the licensing overall."
"The voucher access policy can be improved by configuring it based on groups, rather than just applications or users."
"They should add a key vault feature for the databases temporarily integrated into hybrid clouds."
"The initial setup could be less complex for first-time users."
"Currently, our company has to add the secrets manually, one by one, in Azure Key Vault, which is a tedious process."
"While it is reliable, enhancing security and protection should always be the priority."
"The solution's usage can be a little better from the user interface point of view."
"I would suggest making the user interface a bit more friendly."
"The integration is not as seamless compared to competitors like Palo Alto."
"Further integration across different Microsoft products would be an improvement."
"With Microsoft, support is always crazy, it's not easy to get support."
 

Pricing and Cost Advice

"Pricing is quite reasonable and support is included, although premium support is available for an additional fee."
"The pricing is decent. It has a pretty low price. It is a straightforward cost based on usage."
"The product has good pricing."
"Azure Key Vault is expensive."
"I rate the solution's pricing a four out of ten."
"The product costs much less compared to other vendors."
"Currently, the solution's pricing is based on the number of transactions, which is very high in some cases."
"The price of the solution is reasonable for what we are using it for."
Information not available
report
Use our free recommendation engine to learn which Microsoft Security Suite solutions are best for your needs.
881,082 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Computer Software Company
12%
Manufacturing Company
10%
Government
7%
Computer Software Company
17%
Financial Services Firm
10%
Outsourcing Company
6%
Energy/Utilities Company
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise11
Large Enterprise27
No data available
 

Questions from the Community

Which is better - Azure Key Vault or AWS Secrets Manager?
Azure Key Vault is a SaaS solution. You can easily store passwords and secrets securely and encrypt them. Azure Key Vault is a great solution to ensure you are compliant with security and governanc...
What do you like most about Microsoft Azure Key Vault?
With Azure Key Vault, we can generate our own keys and then import them inside the system, which provides a higher level of security than provider-managed keys.
What needs improvement with Microsoft Defender External Attack Surface Management?
Further integration across different Microsoft products would be an improvement. Introduction of more AI automation into the products would also be beneficial. The integration is not as seamless co...
What is your primary use case for Microsoft Defender External Attack Surface Management?
I am currently in the pilot stage of implementing Microsoft External Attack Surface Management (EASM). My organization is transitioning to a comprehensive track of Microsoft solutions, and we will ...
 

Also Known As

Microsoft Azure Key Vault, MS Azure Key Vault
No data available
 

Overview

 

Sample Customers

Adobe, DriveTime, Johnson Controls, HP, InterContinental Hotels Group, ASOS
Information Not Available
Find out what your peers are saying about Azure Key Vault vs. Microsoft Defender External Attack Surface Management and other solutions. Updated: December 2025.
881,082 professionals have used our research since 2012.