Try our new research platform with insights from 80,000+ expert users

Azure Key Vault vs Microsoft Defender for Cloud Apps comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.1
Azure Key Vault delivers ROI through cost-efficiency, enhanced security, compliance, and centralized management, improving organizational security and access control.
Sentiment score
7.0
Microsoft Defender for Cloud Apps enhances security and efficiency, offering significant ROI with up to 60% savings and streamlined operations.
The biggest return on investment so far has been visibility, knowing what we have in our environment.
Cloud and data protection engineer at a university with 10,001+ employees
As a small team, Microsoft Defender for Cloud Apps allowed us to manage systems with just one or two people.
Manager, Information Technology Security Compliance at a manufacturing company with 201-500 employees
We have at least saved the costs we had from the Netskope solution this year.
Security and Continuity Manager at Rolinco NV
 

Customer Service

Sentiment score
6.9
Azure Key Vault support is praised for responsiveness and knowledge, though some experience communication issues and delays reaching experts.
Sentiment score
6.4
Microsoft Defender for Cloud Apps support is praised for its responsiveness, though some users experience delays and resource access challenges.
Technical support from Azure responds as quickly as possible without any delay.
Security Engineer at a computer software company with 1,001-5,000 employees
I have a strong relationship with Microsoft since we are one of their best clients in Spain.
Software Architect at RedesCDM
The skill level of the support staff is also questionable.
IT Director at Infosys
Their customer service is pretty good, but it's frustrating to go through three or four channels before reaching the right person.
Cloud and data protection engineer at a university with 10,001+ employees
The support is excellent, and the speed of response is commendable.
Solutions Architect at a university with 51-200 employees
There were instances where the engineers were knowledgeable and helpful, but at other times it felt like a ping pong game, with unnecessary transfers until the right person was found.
Manager, Information Technology Security Compliance at a manufacturing company with 201-500 employees
 

Scalability Issues

Sentiment score
7.2
Azure Key Vault is scalable, cloud-based, suitable for enterprises, but requires improved integration; users rate scalability highly.
Sentiment score
7.4
Microsoft Defender for Cloud Apps offers scalable, seamless integration, and reliable management for organizations of all sizes and environments.
For what I know about the log collector and how much data it can take in, it is super scalable and capable of handling high workloads.
Cloud and data protection engineer at a university with 10,001+ employees
Microsoft Defender for Cloud Apps is very scalable, provided you have the right subscription.
Solutions Architect at a university with 51-200 employees
In my experience, Microsoft Defender for Cloud Apps is good enough for small to medium businesses.
Manager, Information Technology Security Compliance at a manufacturing company with 201-500 employees
 

Stability Issues

Sentiment score
8.1
Azure Key Vault is highly reliable, rated 8-10, with minor performance issues as usage increases, outperforming competitors in stability.
Sentiment score
8.0
Microsoft Defender for Cloud Apps is highly stable, reliable, and maintains performance with minor, swiftly resolved incidents.
I would rate it a ten because I have not experienced any stability issues so far with Defender for Cloud Apps.
Head of Security Operations at a computer software company with 51-200 employees
I would assess the stability and reliability of Microsoft Defender for Cloud Apps as stable
Network Engineer at Apexon
My impression on the stability and reliability of Microsoft Defender for Cloud Apps is that it is very stable.
Security and Continuity Manager at Rolinco NV
 

Room For Improvement

Azure Key Vault needs an intuitive interface, improved integration, enhanced security, optimized pricing, and better support and accessibility.
Microsoft Defender for Cloud Apps seeks enhanced pricing, integration, user interface, automation, and multi-cloud support, while improving insights and management.
My security area wants to rotate passwords every day, every week, or every month, depending on the services.
Software Architect at RedesCDM
One of our certificates was not getting deployed, and during that time, the support team was unsure and had to connect with the back-end team for assistance.
Senior Infrastructure Engineer at MIC Global
The skill level of the support staff is also questionable.
IT Director at Infosys
For data loss prevention, it would be useful to be able to drill down into the kind of data being transferred over CloudApp.
Head of Security Operations at a computer software company with 51-200 employees
Defender typically connects to Entra ID, but we have local users on the cloud for database access, SSH, or RDS, and there is nothing produced by Defender regarding those local IAM users.
Network Engineer at Apexon
Microsoft Defender for Cloud Apps would benefit if Microsoft allows users to fine-tune false positives, enabling us to dismiss alerts or make adjustments so that such things don't trigger multiple times in the future.
Security delivery analyst at a tech vendor with 10,001+ employees
 

Setup Cost

Azure Key Vault pricing varies by usage, seen as cost-effective versus competitors, though some find it expensive.
Microsoft Defender for Cloud Apps is seen as cost-effective for enterprises within Microsoft ecosystems, despite standalone pricing concerns.
I would classify it as low priced.
Enterprise Architect at a computer software company with 1,001-5,000 employees
The pricing of Azure Key Vault is nominal, not that expensive.
Associate Vice President (Data Security & Protection - Confidential AI) at Standard Chartered Bank
We are planning to buy protection for Entra.
IT Director at Infosys
The pricing for Microsoft Defender for Cloud Apps is acceptable.
Solutions Architect at a university with 51-200 employees
My organization is currently revisiting pricing, but previously, the cost was a bit expensive, yet comparable to other solutions with similar functionalities and features.
Manager, Information Technology Security Compliance at a manufacturing company with 201-500 employees
It's not the cheapest, but also not the most expensive, placing it in the mid-level range.
IT Architect at a logistics company with 10,001+ employees
 

Valuable Features

Azure Key Vault offers secure, scalable secret management with easy integration, featuring advanced protection, role-based access, and DevOps support.
Microsoft Defender for Cloud Apps integrates well, offering threat detection, management ease, shadow IT discovery, and robust security enhancements.
All secrets are in the Key Vault, and access is managed by the integrated management in ITT, which Azure provides to the services.
Software Architect at RedesCDM
It also helps me increase my security posture and assists with regulatory and compliance requirements.
Enterprise Architect at a computer software company with 1,001-5,000 employees
Since implementing Azure Key Vault, I have observed that instead of storing plain values, we can store them securely as and when required.
Software Engineer at Synoptek
It provides excellent suggestions and options for configuration; for example, it can track suspicious files getting uploaded to cloud resources on Azure based on their signatures, generating alerts for those files.
Security delivery analyst at a tech vendor with 10,001+ employees
The product recommends things that need to be blocked and allows for dynamic configuration, which cuts down on potential issues that might arise from going through lists and understanding what needs to be blocked.
Partner & Chief Executive Officer at a consultancy with 51-200 employees
The ability to sanction unsanctioned apps using Secure Score benchmarking, included in Cloud, is also beneficial.
Head of Security Operations at a computer software company with 51-200 employees
 

Categories and Ranking

Azure Key Vault
Ranking in Microsoft Security Suite
15th
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
52
Ranking in other categories
Enterprise Password Managers (1st), Certificate Management Software (1st), Secrets Management Tools (2nd)
Microsoft Defender for Clou...
Ranking in Microsoft Security Suite
12th
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
42
Ranking in other categories
Cloud Access Security Brokers (CASB) (4th), Advanced Threat Protection (ATP) (14th)
 

Mindshare comparison

As of January 2026, in the Microsoft Security Suite category, the mindshare of Azure Key Vault is 1.5%, up from 1.1% compared to the previous year. The mindshare of Microsoft Defender for Cloud Apps is 3.1%, up from 2.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Microsoft Security Suite Market Share Distribution
ProductMarket Share (%)
Microsoft Defender for Cloud Apps3.1%
Azure Key Vault1.5%
Other95.4%
Microsoft Security Suite
 

Featured Reviews

Rajthilak BS - PeerSpot reviewer
Associate Vice President (Data Security & Protection - Confidential AI) at Standard Chartered Bank
Have addressed compliance challenges but still struggle with seamless integration of certificate issuance between environments
In terms of Azure Key Vault improvements, we have to compare the competitor. If we consider AWS, our bank has Microsoft PKI, which is a Microsoft product, for the entire digital certificate infrastructure. Even in the cloud, when it is AWS, the internal certificates are MS PKI. When we had a problem, users had to come to on-premise to get a certificate and import it to AWS Certificate Manager and assign it. We wondered why we could not issue the certificate directly from the cloud for cloud users. There was a simple way in AWS. They have a Private Certificate Authority (PCA) and Amazon Certificate Manager. Private Certificate Authority issues certificates to Amazon services. They also provide Amazon Certificate Manager to store and deploy certificates. These are two neat components - one is an issuer and another is storage and deployment solutions for certificates. With PCA, I can directly enable it and get certificates from AWS itself. AWS can issue SSL/TLS certificates if you enable it directly. If you consider Azure, it is not very clear. Even the naming convention, Key Vault, might not suggest that this is a PKI or certificate manager. You cannot issue certificates directly. They have app certificates and did not have a clear-cut certificate management solution in the cloud when I worked at that time. I am not sure whether they have updated Azure Key Vault as a full-fledged PKI solution now. From what I saw, it was not a full-fledged PKI solution. We are not majorly using Azure Key Vault because it is only for storing secrets. If some solutions can provide guidance on how we can maximize leverage, we can immediately look forward to doing that. We already have some business problems we want to solve. While our primary focus is AWS, many of the services such as ADO are running on Azure, and the secondary services are growing bigger.
FV
Security and Continuity Manager at Rolinco NV
Deployment has been seamless with insightful data categorization and enhanced control
The features of Microsoft Defender for Cloud Apps that I have found most valuable include the overall portal view, with bubble graphs which give us insight into what goes where in the categorization, nowadays with Generative AI but all kinds of categorization, collaboration, etc. That central view of the portal is very useful for us. The impact of Microsoft Defender for Cloud Apps on our organization's ability to assess and manage app related risks has been significant because we have more visibility. Therefore, we can add more control, and we have already done so. This was not possible in the old solution, in the old CASB solution with Netskope. We now can see on the spot, and we do that almost weekly, what the end users are utilizing, which cloud providers or cloud apps they're using. The visibility into OAuth apps provided by Microsoft Defender for Cloud Apps is very good. The visibility into risk and risk management of our organization's Generative AI apps is very nice, as you can choose the category Generative AI and then see exactly what traffic has been going to and from Generative AI in the cloud. This makes us very insightful on what is used within the company. We have some policies on blocking specific Generative AI, and we use within our company one particular AI part, which is CoPilot of Microsoft. In this way, we can see what the end users are using other than CoPilot, and that makes us more in control. The effectiveness of the integration of Microsoft Defender for Cloud Apps with Defender XDR and defending against SaaS attacks is very intuitive. It works immediately if we create a new policy or in Purview or in Microsoft Defender for Cloud Apps, or when we make an app unsanctioned by blocking it, then it is almost immediately, or at least within a couple of hours, effective on all the endpoints where the EDR is running. This gives us much better control over things than before.
report
Use our free recommendation engine to learn which Microsoft Security Suite solutions are best for your needs.
881,082 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Computer Software Company
12%
Manufacturing Company
10%
Government
7%
Financial Services Firm
11%
Computer Software Company
11%
Manufacturing Company
8%
Government
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise11
Large Enterprise27
By reviewers
Company SizeCount
Small Business15
Midsize Enterprise10
Large Enterprise19
 

Questions from the Community

Which is better - Azure Key Vault or AWS Secrets Manager?
Azure Key Vault is a SaaS solution. You can easily store passwords and secrets securely and encrypt them. Azure Key Vault is a great solution to ensure you are compliant with security and governanc...
What do you like most about Microsoft Azure Key Vault?
With Azure Key Vault, we can generate our own keys and then import them inside the system, which provides a higher level of security than provider-managed keys.
Which is the better security solution - Cisco Umbrella or Microsoft Cloud App Security?
Cisco Umbrella is an integral component of the Cisco SASE architecture. It integrates security in a single, cloud-native solution, unifying multiple features like DNS-layer security, threat intelli...
What is your experience regarding pricing and costs for Microsoft Cloud App Security?
At the time of implementation, when the size of our organization was small, it was a more affordable product. Since all our productivity applications were on O365, Microsoft Defender for Cloud Apps...
What needs improvement with Microsoft Cloud App Security?
The fidelity of the signal in Microsoft Defender for Cloud Apps has been a challenge in some areas. There have been instances where the alerts generated have been false positives. A lot of work has...
 

Also Known As

Microsoft Azure Key Vault, MS Azure Key Vault
MS Cloud App Security, Microsoft Cloud App Security
 

Overview

 

Sample Customers

Adobe, DriveTime, Johnson Controls, HP, InterContinental Hotels Group, ASOS
Customers for Microsoft Defender for Cloud Apps include Accenture, St. Luke’s University Health Network, Ansell, and Nakilat.
Find out what your peers are saying about Azure Key Vault vs. Microsoft Defender for Cloud Apps and other solutions. Updated: December 2025.
881,082 professionals have used our research since 2012.