Try our new research platform with insights from 80,000+ expert users

Change Auditor for Active Directory vs CrowdStrike Falcon comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Change Auditor for Active D...
Average Rating
9.0
Reviews Sentiment
6.9
Number of Reviews
2
Ranking in other categories
Active Directory Management (7th)
CrowdStrike Falcon
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
136
Ranking in other categories
Security Information and Event Management (SIEM) (6th), Endpoint Protection Platform (EPP) (1st), Threat Intelligence Platforms (TIP) (1st), Endpoint Detection and Response (EDR) (1st), Extended Detection and Response (XDR) (1st), Attack Surface Management (ASM) (1st), Identity Threat Detection and Response (ITDR) (1st), AI-Powered Cybersecurity Platforms (1st)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Change Auditor for Active Directory is designed for Active Directory Management and holds a mindshare of 6.8%, down 7.6% compared to last year.
CrowdStrike Falcon, on the other hand, focuses on Extended Detection and Response (XDR), holds 10.5% mindshare, down 17.8% since last year.
Active Directory Management Market Share Distribution
ProductMarket Share (%)
Change Auditor for Active Directory6.8%
ManageEngine ADManager Plus12.6%
One Identity Active Roles10.8%
Other69.8%
Active Directory Management
Extended Detection and Response (XDR) Market Share Distribution
ProductMarket Share (%)
CrowdStrike Falcon10.5%
Wazuh7.9%
Darktrace6.1%
Other75.5%
Extended Detection and Response (XDR)
 

Featured Reviews

reviewer2794194 - PeerSpot reviewer
Sr Mgr Cyber Defense at a manufacturing company with 10,001+ employees
Auditing changes has become faster and now uncovers misconfigurations within minutes
The best features Change Auditor for Active Directory offers are that it's lightweight and easy to understand. You don't have to memorize event IDs since it's in English. What makes Change Auditor for Active Directory lightweight and easy to understand in my experience is that it doesn't require the events to record to the domain controllers. Therefore, I can focus just on the event types without having to turn up detailed logging on my DCs. Change Auditor for Active Directory has positively impacted my organization by helping us respond to audits very quickly to show that we had evidence of who was making the changes and match them up to the ticket request and who approved it. After implementing Change Auditor for Active Directory, it has allowed us to answer questions literally in minutes, whereas it would have taken us half a day to a day before.
Waleed Omar - PeerSpot reviewer
Information Security Specialist at Arab Open University
Provides effective real-time threat detection with potential for cost optimization
Some features such as device control, firewall management, and file analysis are standalone products that we need to purchase separately. If these features came out of the box within the product, it would be much more beneficial for us. Other providers such as SentinelOne include these features in their base product. We attended a CrowdStrike Falcon event where they discussed some shallow AI features, but we cannot see these in our panel yet. We work with different solutions such as Darktrace and SocRadar, where AI features are automatically displayed in our dashboards after release. However, for CrowdStrike Falcon, we cannot see these features.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features are the ability to protect Active Directory accounts and groups, and the real-time notifications that help manage Active Directory more effectively."
"Change Auditor for Active Directory has positively impacted my organization by helping us respond to audits very quickly to show that we had evidence of who was making the changes and match them up to the ticket request and who approved it."
"CrowdStrike Falcon has helped my customers predict and prevent potential breaches because of its proactive approach."
"CrowdStrike is deployed on every workstation, so policy changes can be enforced on all of them. It lowers the manual work on each of the workstations. It has helped us manage device usage in our environment."
"We are happy with CloudStrike's ease of use and touch notification."
"We haven't had any infections or down time."
"CrowdStrike Falcon helps with endpoint protection by having very low memory utilization and processor usage, so it doesn't impact the computer system performance, and the computer system works very fast compared to all other endpoint protection solutions."
"The CS falcon agent is a lightweight agent compared with other agents of EDR products."
"Among CrowdStrike Falcon's most valuable capabilities are its UEBA and SOAR functionalities, along with its seamless integration with any other SIEM solution."
"The real-time analytics aspect of CrowdStrike performs well because we get all logs in real-time, with no delay, allowing us to take action immediately."
 

Cons

"Change Auditor for Active Directory could be improved if the client were more flexible when installed, so if I upgrade the server, I wouldn't have to replace the clients at the same time."
"Areas that could be improved include having more management capabilities with command-line scripts and more flexibility in general."
"For further improvements, I can only think of one example because this is very important for us; they could reduce the price. Then it would deserve a rating of seven."
"One thing that is not yet available is attack simulation."
"Falcon could include more integrative features."
"The KDR solution is immature. They do not have much preemption in ITDR. Threat prevention should be their first priority, and false positive reductions are needed."
"On the firewall management side, there should be more granularity. There should also be more granularity for device control. Everything else is brilliant."
"It would be nice if they did have some sort of Active Directory tie-in, whether that be Azure or on-prem. Sometimes, it is difficult for us to determine if we are missing any endpoints or servers in CrowdStrike. We honestly don't have a great inventory, but it would be nice if CrowdStrike had a way to say this is everything in your environment, Active Directory-wise, and this is what doesn't have sensors. They try to do that now with a function that they have built-in, but I have been unsuccessful in having it help us identify what needs a sensor. So, better visibility of what doesn't have a sensor in our environment would be helpful."
"Basically, they don't cover legacy OS or applications. That's the only issue we're concerned about"
"CrowdStrike should provide better visibility in its reporting. There should be more forensic details about detected threats."
 

Pricing and Cost Advice

Information not available
"We pay between $30-50 per user for a yearly license, which is more expensive than SentinelOne or Bitdefender. However, CrowdStrike gives better value for money."
"The price of CrowdStrike Falcon is expensive and should be reduced."
"There are three to four licensing models available to choose from for CrowdStrike Falcon. The price of CrowdStrike Falcon depends on the distributor and the reseller partner. The price we received was good."
"Our licensing fees were between $50,000 and $60,000 per year, which was pretty expensive for a small business."
"Our company pays approximately US$ 65,000 annually for 900 machines."
"The solution isn't very costly; it's affordable."
"Crowdstrike Falcon is relatively cheap."
"The price of CrowdStrike Falcon could be better. It is very expensive, we pay approximately $900 per month for the licenses. There are not any additional fees."
report
Use our free recommendation engine to learn which Active Directory Management solutions are best for your needs.
879,986 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
13%
Computer Software Company
11%
Manufacturing Company
9%
Insurance Company
8%
Computer Software Company
13%
Financial Services Firm
10%
Manufacturing Company
9%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise34
Large Enterprise62
 

Questions from the Community

What is your experience regarding pricing and costs for Quest Change Auditor for Active Directory?
The price can vary based on the components purchased and the needs and budget of the organization. It is considered a bit pricey, especially for smaller companies.
What needs improvement with Quest Change Auditor for Active Directory?
Areas that could be improved include having more management capabilities with command-line scripts and more flexibility in general. Often this type of tool could benefit from better scripting capab...
What is your primary use case for Quest Change Auditor for Active Directory?
The primary use case is to manage human errors, like protecting identities from being modified by the software, and to audit security. This includes monitoring high-privilege accounts and having th...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions that are very scalable, secure, and user-friendly. Cortex XDR by Palo Alto offers ...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never push your machine hardware to "test", you don't have the usual "scan now" feature ...
 

Also Known As

No data available
CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface, CrowdStrike Falcon Platform
 

Overview

 

Sample Customers

American Airlines, Bank of America, BARCLAYS, ebay, Ford, intel, MARS, MERCK, Microsoft, UBER, VISA
Information Not Available
Find out what your peers are saying about One Identity, Microsoft, Netwrix and others in Active Directory Management. Updated: December 2025.
879,986 professionals have used our research since 2012.