Try our new research platform with insights from 80,000+ expert users

CyberArk Endpoint Privilege Manager vs Microsoft Defender for Business comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.0
CyberArk Endpoint Privilege Manager boosts security, saves resources, and enhances confidence, offering a perceived positive ROI despite quantification challenges.
Sentiment score
7.5
Microsoft Defender boosts productivity and security, integrating seamlessly with Office tools for significant budget savings despite ROI challenges.
Deploying CyberArk Endpoint Privilege Manager has secured the infrastructure, which saves money, time, and resources.
I consider CyberArk Endpoint Privilege Manager's return on investment to be good since it effectively accomplishes the goals expected from privilege access management solutions.
Using Microsoft Defender for Business results in cost reductions as it consolidates various features under one product, saving around 20% to 30% of the budget.
It is pretty good because it offers various features such as Exchange, OfficeSuite, OneDrive, and SharePoint.
The value I see in Microsoft Defender for Business is in its ability to track and respond to application usage and security threats through its CASB and automation features, which are cost-beneficial.
 

Customer Service

Sentiment score
6.6
CyberArk Endpoint Privilege Manager support is generally rated high, with quick resolutions but concerns about response times and accessibility.
Sentiment score
5.2
Users have mixed reviews of Microsoft Defender's support, noting contact difficulties and inconsistent technical assistance despite good onboarding.
They respond immediately to our inquiries, resolve issues promptly, and provide valuable guidance, especially in critical situations.
We engage them when needed and receive prompt responses that typically resolve our issues.
Earlier, we received support for normal tickets within a day, but now it takes one or two days to resolve issues.
It is rated ten out of ten for its quality and assistance.
The onboarding support is exceptional, ensuring seamless integration and implementation.
Faster support is needed for endpoint security solutions.
 

Scalability Issues

Sentiment score
7.7
CyberArk Endpoint Privilege Manager efficiently scales for varied environments, supporting small to large enterprises with a distributed cloud-based architecture.
Sentiment score
8.2
Microsoft Defender for Business is scalable and effective across diverse environments, though special configurations might impact growth speed.
We can set permissions per team or department, allowing some teams to elevate specific applications while others have different permissions.
CyberArk Endpoint Privilege Manager is quite scalable.
The available reports and other security tools assist in scaling it according to my organization's needs.
The cloud-based nature of the solution ensures high scalability.
The scalability of Microsoft Defender for Business is rated as ten, indicating it is very scalable.
In terms of scalability, I would rate Microsoft Defender for Business a ten.
 

Stability Issues

Sentiment score
8.2
CyberArk Endpoint Privilege Manager is stable and reliable, maintaining 99.99% uptime with rare issues and smooth offline adaptation.
Sentiment score
7.3
Microsoft Defender for Business is stable and reliable, with minimal crashes, but some report occasional bugs impacting stability.
It is a robust solution that has effectively supported our environment without major issues.
Since implementing it, we have not experienced any outages or stability issues.
CyberArk Endpoint Privilege Manager offers multiple options for creating and stopping policies.
No customer complaints about its functionality or reliability.
Although it generally works, there are occasional issues and errors that sometimes require a complete system format to rectify.
I would rate the stability of Microsoft Defender for Business with a three out of ten, where one is very bad.
 

Room For Improvement

CyberArk Endpoint Privilege Manager requires improvements in UI, integration, performance, support, threat detection, customization, pricing flexibility, and automation.
Microsoft Defender for Business needs better reporting, integration, simplified interface, and enhanced features to address various limitations and concerns.
CyberArk Endpoint Privilege Manager could be improved by simplifying the administration process, specifically when setting up policies and applications.
Currently, no user-based policy option is available inside the EPM console.
Some features provided in the self-hosted version of EPM are not supported in the software as a service version, like connection to some analysis applied by Palo Alto.
Microsoft should provide batch management solutions with the application, integrating pass management with roles.
Features related to Advanced Persistent Threat detection vectors and cyber kill chain integrations are not available out-of-the-box.
There can be improvements in the user interface to make it more intuitive.
 

Setup Cost

CyberArk Endpoint Privilege Manager is costly but considered reasonable for its features, with significant discounts for large enterprises.
Microsoft Defender for Business offers competitive pricing with enterprise value, though some users find costs high compared to competitors.
CyberArk Endpoint Privilege Manager is slightly expensive, but costs can be negotiated to become more competitive.
CyberArk Endpoint Privilege Manager is costly compared to other solutions.
I've received feedback that the pricing is high, however, for me, the value it brings is worth the cost.
Single-year pricing remains good.
The pricing is quite affordable at the enterprise level with no extra expenses noted.
The package with Business Premium is good for what you get for the price.
 

Valuable Features

CyberArk Endpoint Privilege Manager enhances security by managing privileges, reducing admin needs, and improving operational efficiency and data protection.
Microsoft Defender for Business integrates seamlessly with Microsoft products, offering comprehensive security, scalability, and user-friendly features for effective threat management.
CyberArk Endpoint Privilege Manager effectively reduces malicious content in applications by allowing us to identify and block dangerous applications.
It allows them to granularly manage controls to prevent some malicious activities on the endpoint machine.
CyberArk Endpoint Privilege Manager enhances computer security by providing minimal access, effectively preventing ransomware attacks.
The threat detection capabilities are robust, with a dedicated research team and a continuously updated threat feed.
Its vulnerability management is regarded as one of the best in the industry.
The most effective features of Microsoft Defender for Business include its threat detection and response capabilities in managing vulnerabilities and ransomware attacks.
 

Categories and Ranking

CyberArk Endpoint Privilege...
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
38
Ranking in other categories
Endpoint Compliance (5th), Privileged Access Management (PAM) (4th), Anti-Malware Tools (5th), Application Control (5th), Ransomware Protection (6th)
Microsoft Defender for Busi...
Average Rating
7.8
Reviews Sentiment
7.0
Number of Reviews
19
Ranking in other categories
Endpoint Protection Platform (EPP) (23rd), Microsoft Security Suite (16th)
 

Mindshare comparison

While both are Endpoint Security solutions, they serve different purposes. CyberArk Endpoint Privilege Manager is designed for Privileged Access Management (PAM) and holds a mindshare of 3.4%, down 3.8% compared to last year.
Microsoft Defender for Business, on the other hand, focuses on Endpoint Protection Platform (EPP), holds 2.0% mindshare, up 1.3% since last year.
Privileged Access Management (PAM)
Endpoint Protection Platform (EPP)
 

Featured Reviews

Sumit Chavan - PeerSpot reviewer
Helps secure the infrastructure and control users with admin rights
There are many features that are currently missing. A customization option is required for certain policies. For instance, if we need to stop PowerShell scripting, we have to create a different policy for that. Being able to create a sub-level policy within a top-level policy would be good. Currently, no user-based policy option is available inside the EPM console. We can only create computer-based policies. The database is available, but there is a drawback in not being able to create local groups on the EPM console. We only have to depend on Active Directory. This limits infrastructure security as we depend on the Active Directory team to manage user groups. If they remove any users, we lose control. If we could create groups locally and block them or set specific policies, we would have more control. Local endpoint management is missing from the EPM site. Moreover, there is an issue with policies not running as expected when we make enhancements. We have to find multiple ways to whitelist applications or enhance policies.
Syed Abid  - PeerSpot reviewer
Advanced threat protection secures diverse workloads with cost-effective deployment
If I need logs and don't have local storage bundled with Defender, I need to add workspace and log analytics, which is costly for storing logs of 2 GB, 5 GB, 10 GB. A default storage of 5 GB for logs should be included with Defender. There are limitations in whitelisting folders and files, and the whitelisting feature for Defender threat protection was deprecated. A straightforward feature for this should be added.
report
Use our free recommendation engine to learn which Privileged Access Management (PAM) solutions are best for your needs.
856,873 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Computer Software Company
15%
Manufacturing Company
11%
Government
9%
Computer Software Company
19%
Comms Service Provider
8%
Retailer
7%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Looking for recommendations and a pros/cons template for software to detect insider threats
This is an inside-out --- outside-in --- inside-in question, as an insider can be an outsider as well. There is no short answer other than a blend of a PAM tool with Behavioral Analytics and Endpo...
What do you like most about CyberArk Endpoint Privilege Manager?
The most valuable feature of the solution is its performance.
What is your experience regarding pricing and costs for CyberArk Endpoint Privilege Manager?
I've received feedback that the pricing is high, however, for me, the value it brings is worth the cost. It's really one of the best solutions.
What do you like most about Microsoft Defender for Business?
A few things are valuable. One is the alerting we see when any kind of intrusion is happening, any kind of malware is being deployed across the endpoints, or any kind of suspicious activity is goin...
What is your experience regarding pricing and costs for Microsoft Defender for Business?
Microsoft Defender for Business offers the best pricing option in the market and is very cost-effective.
What needs improvement with Microsoft Defender for Business?
The areas where Microsoft Defender for Business could improve include the support, installation process, and wiki. I should be able to find solutions to issues quickly without having to delve too d...
 

Also Known As

Viewfinity
No data available
 

Overview

Find out what your peers are saying about CyberArk, Delinea, One Identity and others in Privileged Access Management (PAM). Updated: June 2025.
856,873 professionals have used our research since 2012.