No more typing reviews! Try our Samantha, our new voice AI agent.

Change Auditor for Active Directory vs CrowdStrike Falcon comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Change Auditor for Active D...
Average Rating
9.0
Reviews Sentiment
6.9
Number of Reviews
2
Ranking in other categories
Active Directory Management (7th)
CrowdStrike Falcon
Average Rating
8.8
Reviews Sentiment
7.2
Number of Reviews
173
Ranking in other categories
Endpoint Protection Platform (EPP) (3rd), Endpoint Detection and Response (EDR) (2nd)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Change Auditor for Active Directory is designed for Active Directory Management and holds a mindshare of 5.2%, down 7.9% compared to last year.
CrowdStrike Falcon, on the other hand, focuses on Endpoint Protection Platform (EPP), holds 5.7% mindshare, down 8.2% since last year.
Active Directory Management Mindshare Distribution
ProductMindshare (%)
Change Auditor for Active Directory5.2%
Active Roles by One Identity11.7%
Netwrix Auditor10.1%
Other73.0%
Active Directory Management
Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
CrowdStrike Falcon5.7%
Microsoft Defender for Endpoint6.5%
SentinelOne Singularity Endpoint4.5%
Other83.3%
Endpoint Protection Platform (EPP)
 

Featured Reviews

reviewer2794194 - PeerSpot reviewer
Sr Mgr Cyber Defense at a manufacturing company with 10,001+ employees
Auditing changes has become faster and now uncovers misconfigurations within minutes
The best features Change Auditor for Active Directory offers are that it's lightweight and easy to understand. You don't have to memorize event IDs since it's in English. What makes Change Auditor for Active Directory lightweight and easy to understand in my experience is that it doesn't require the events to record to the domain controllers. Therefore, I can focus just on the event types without having to turn up detailed logging on my DCs. Change Auditor for Active Directory has positively impacted my organization by helping us respond to audits very quickly to show that we had evidence of who was making the changes and match them up to the ticket request and who approved it. After implementing Change Auditor for Active Directory, it has allowed us to answer questions literally in minutes, whereas it would have taken us half a day to a day before.
JW
Senior Security Engineer at a financial services firm with 10,001+ employees
Centralized endpoint protection has strengthened compliance and accelerated incident response
There are a number of areas that I only touch a handful of times, but when I get in there, I realize why I don't do that. The main area would be within the support area. The support bot is not really as smart as you would expect it, especially in this day and age of LLM and other capabilities that I know CrowdStrike Falcon is already capable of doing. Additionally, I would appreciate a little bit more easy to read insights of some of the dashboards or maybe manipulation of the dashboards. It is still a little cumbersome to build custom dashboards and it's not as intuitive as you would think. Documentation is abysmal and needs to be improved dramatically. I know that there's a big effort to do this, however, even the new effort is honestly worse than it was before. Those are definitely major areas of improvement, just more in the usability of the features.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Change Auditor for Active Directory has positively impacted my organization by helping us respond to audits very quickly to show that we had evidence of who was making the changes and match them up to the ticket request and who approved it."
"The most valuable features are the ability to protect Active Directory accounts and groups, and the real-time notifications that help manage Active Directory more effectively."
"There are two things which customers really like about CrowdStrike. If they buy managed services from CrowdStrike, it offers them detection of security issues in one minute. If you buy their professional services, they offer insurance where you can claim up to $5 million if there's a breach. This is a huge upsell for customers."
"CrowdStrike provides a lot of visibility in their tool."
"The OverWatch is the most valuable feature to me. It's a 24x7 monitoring service, and when they see anything suspicious in my environment, they will investigate."
"Falcon has decreased the load on our analyst team because they don't have to manually contact the system owners to stop that particular event from happening as Falcon detects threats and quarantines the machines itself."
"CrowdStrike is deployed on every workstation, so policy changes can be enforced on all of them. It lowers the manual work on each of the workstations. It has helped us manage device usage in our environment."
"The benefits I've seen from having multiple security capabilities on a single platform include a single pane of glass, the ability to contain and eradicate threats easier, and the value I've seen from having endpoint, identity, cloud, and other security telemetry in the same CrowdStrike Falcon platform makes it easy to use one path to focus on specific threats and be able to correlate them together, especially with advanced search and using the graph."
"CrowdStrike enables the infrastructure managers to visualize all the events and get information about the network."
"The stability is good; we haven't experienced any glitches or bugs."
 

Cons

"Areas that could be improved include having more management capabilities with command-line scripts and more flexibility in general."
"Change Auditor for Active Directory could be improved if the client were more flexible when installed, so if I upgrade the server, I wouldn't have to replace the clients at the same time."
"CrowdStrike Falcon can be improved by continuing to keep everything on the cutting edge."
"Improving CrowdStrike Falcon could involve slowing down the release of sensor updates and prevention policies, as I appreciate how they release them, but if they could slow down the release, that would help us catch up."
"They need to strengthen the forensic capabilities of this product, for e-discovery."
"The price is too high. When we are reaching a new renewal, management always asks what's going on in the market."
"I would also like to see the endpoint firewall component produce some level of logging and feedback."
"They offered a white glove service that was extremely costly. When we got into it, we saw it was relatively easy. If I was being nitpicky, I'd say that I don't like being sold something that's unnecessary. That's the only downside I've seen to the solution."
"Technical support could be better than what is currently offered."
"The management of the solution could improve."
 

Pricing and Cost Advice

Information not available
"Our company pays approximately US$ 65,000 annually for 900 machines."
"As I'm part of the technical team, not the budgeting team, I don't have information on CrowdStrike Falcon pricing."
"The other administrator and I can log in to check the exact details of what happened, what was running, and what caused the detection. We know exactly what was happening on the end users PC and we can tell if it's something that we actually need or something that's malicious."
"The price of CrowdStrike Falcon is expensive and should be reduced."
"The price is high in comparison to similar brands."
"It's an expensive solution but you get a very good product for the price. Compared to other products, SentinelOne is definitely cheaper and the Microsoft E5 package is probably more expensive. Not many companies are willing to purchase CrowdStrike Falcon in Turkey due to the cost, but the market is changing."
"We bought a very small number of licenses, then ran it for a year. We bought a 100 licenses for a year, so we didn't actually do a proof of concept. We just bought them. Then, the next year, we bought 10,000 licenses."
"The price of CrowdStrike Falcon is reasonable."
report
Use our free recommendation engine to learn which Active Directory Management solutions are best for your needs.
913,806 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Manufacturing Company
9%
Insurance Company
9%
Healthcare Company
8%
Financial Services Firm
10%
Outsourcing Company
9%
Manufacturing Company
9%
Computer Software Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business58
Midsize Enterprise46
Large Enterprise83
 

Questions from the Community

What is your experience regarding pricing and costs for Quest Change Auditor for Active Directory?
My experience with pricing, setup cost, and licensing was pretty straightforward. Actually, we bundled it with some other services offered from Quest to get a volume discount.
What needs improvement with Quest Change Auditor for Active Directory?
Change Auditor for Active Directory could be improved if the client were more flexible when installed, so if I upgrade the server, I wouldn't have to replace the clients at the same time. I think g...
What is your primary use case for Quest Change Auditor for Active Directory?
My main use case for Change Auditor for Active Directory is auditing changes, finding changes to undo, and break-fix solving issues. For example, I could give you a quick specific example of how I'...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions that are very scalable, secure, and user-friendly. Cortex XDR by Palo Alto offers ...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never push your machine hardware to "test", you don't have the usual "scan now" feature ...
 

Also Known As

No data available
CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface, CrowdStrike Falcon Platform
 

Overview

 

Sample Customers

American Airlines, Bank of America, BARCLAYS, ebay, Ford, intel, MARS, MERCK, Microsoft, UBER, VISA
Information Not Available
Find out what your peers are saying about One Identity, Microsoft, Netwrix and others in Active Directory Management. Updated: August 2026.
913,806 professionals have used our research since 2012.