No more typing reviews! Try our Samantha, our new voice AI agent.

Darktrace vs Microsoft Defender for Cloud comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jan 25, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.3
SentinelOne Singularity Cloud enhances security, efficiency, and ROI by reducing incident times, costs, and resource needs while improving compliance.
Sentiment score
6.3
Darktrace users experience substantial returns through threat prevention and reduced downtime, despite deployment challenges and difficulty measuring returns.
Sentiment score
7.1
Microsoft Defender for Cloud boosts efficiency, cuts remediation time, improves security, and reduces overhead despite varied cost perceptions.
After implementing SentinelOne, it takes about five to seven minutes.
Cloud engineer at a construction company with 5,001-10,000 employees
Our ability to get in and review our vulnerability stance, whether daily, monthly, weekly, or whatever it might be, has drastically improved over our prior provider.
IT Support Specialist at a non-tech company with 201-500 employees
It has saved us more than 50% of our time.
Sr security engineer at Halodoc
Other NDR solutions provide virtual appliances that can be deployed on virtualization servers to get up and running quickly.
Technical Consultant - Unix Platform Services at BITS AND BYTE IT CONSULTING PVT LTD
Using this solution provides financial benefits by securing from server attacks, which offers indirect savings.
Systems Specialist/ Administrator at ALFA International Company Limited.
Defender proactively indexes and analyzes documents, identifying potential threats even when inactive, enhancing preventative security.
Endpoint management at a government with 10,001+ employees
Identifying potential vulnerabilities has helped us avoid costly data losses.
Manager at CBTS
Compared to not having Microsoft Defender for Cloud in place, we definitely saw an advantage by not having downtime due to a security threat.
Principal Microsoft Consultant at MicroAge
 

Customer Service

Sentiment score
7.8
SentinelOne Singularity Cloud Security is praised for responsive support, though recent acquisition slightly impacted personalized service.
Sentiment score
7.6
Darktrace's customer service is praised for responsiveness and efficiency, though some suggest improvements for complex issues.
Sentiment score
6.3
Microsoft Defender for Cloud support receives mixed reviews, with praise for documentation but issues with response times and escalation.
Having a reliable team ready and willing to assist with any issues is essential.
Director, DevOps at Relay Network
Throughout the migration, they remained available for several hours without complaint, providing assistance at every step.
Mobile Application Developer at a retailer with 1-10 employees
In my experience, I have never encountered a junior person or someone without knowledge coming into support from SentinelOne.
Senior Technical Engineer at Safezone Secure Solutions Private Limited
The technical support from Darktrace is of high quality.
Network & Security Section Head/Digital Transformation at a government with 201-500 employees
Darktrace provides excellent technical support with a monthly meeting to review platform incidents, ensuring the system functions as expected.
Head of Technology Operations at Pobl Group
The challenge lies in waiting for a response after logging a ticket.
Group Cybersecurity Administrator at Tharisa
Since security is critical, we prefer a quicker response time.
Manager at CBTS
The support team was very responsive to queries.
Programme Manager- Cyber Fusion- Group CISO at a financial services firm with 10,001+ employees
They understand their product, but much like us, they struggle with the finer details, especially with new features.
Endpoint management at a government with 10,001+ employees
 

Scalability Issues

Sentiment score
8.1
SentinelOne Singularity Cloud Security offers highly rated scalability, easily integrating across environments and accommodating growth despite some configuration challenges.
Sentiment score
7.6
Darktrace is praised for its scalability, supporting diverse user bases and integrating well with existing infrastructures.
Sentiment score
7.5
Microsoft Defender for Cloud is scalable, easily deployable, integrates well, and adapts to growth but may incur higher costs.
The SentinelOne Singularity Cloud exhibits high scalability.
Security Analyst at Intersistemi Italia s.p.a.
We've automated in our MDM so any device that we start in our MDM automatically installs SentinelOne.
IT Support Specialist at a non-tech company with 201-500 employees
It is scalable. I would rate it a ten out of ten for scalability.
Sr security engineer at Halodoc
Darktrace has high scalability, and I would rate it a nine out of ten.
Network & Security Section Head/Digital Transformation at a government with 201-500 employees
Since it's cloud-based, it expands easily.
Head of Technology Operations at Pobl Group
There is still a gap in terms of storage, and we are trying to figure out how to increase that capacity for regulated environments, which require data retention for 5 to 6 years.
Technical Consultant - Unix Platform Services at BITS AND BYTE IT CONSULTING PVT LTD
As we have reduced our on-premises infrastructure, it is about how we can migrate workloads to the cloud to make it easier, and then having everything fully encompassed and secured within that area makes it much easier for us to scale as needed and grow.
Principal Microsoft Consultant at MicroAge
We are using infrastructure as a code, so we do not have any scalability issues with Microsoft Defender for Cloud implementation because our cloud automatically does it.
Senior Cloud Platform Engineer at Deutsche Börse
It has multiple licenses and features, covering infrastructures from a hundred to five hundred virtual machines, without any issues.
Snr. Infrastructure Architect (Data Centre) at LogicEra
 

Stability Issues

Sentiment score
8.3
SentinelOne Singularity Cloud Security is highly stable, reliable, and rated 9/10, with only minor UI and communication issues.
Sentiment score
8.5
Darktrace is highly rated for stability and reliability, with effective monitoring and an intuitive interface despite occasional traffic impacts.
Sentiment score
7.6
Microsoft Defender for Cloud is stable and reliable, with minor issues quickly resolved, earning high user ratings.
SentinelOne Singularity Cloud is incredibly reliable.
Security Analyst at Intersistemi Italia s.p.a.
The only downtime we had was when switching from V1 to V2 but it was smooth.
Cloud Security Specialist at a insurance company with 10,001+ employees
I would rate it a ten out of ten for stability.
Sr security engineer at Halodoc
The stability of Darktrace is excellent, rated ten out of ten.
Head of Technology Operations at Pobl Group
The appliance itself has never let me down.
Group Cybersecurity Administrator at Tharisa
For stability, I would rate Darktrace an eight out of ten.
Security Analyst at a healthcare company with 10,001+ employees
Defender's stability has been flawless for us.
Engineer at a computer software company with 201-500 employees
I have not experienced any crashes or downtime.
Head Of IT at Cirrus Response
Microsoft Defender for Cloud is very stable.
Cloud architect at a tech vendor with 1,001-5,000 employees
 

Room For Improvement

Users desire improved integration, interface, automation, detection accuracy, documentation, reporting, security, and customization to address existing concerns.
Darktrace needs improved integration, automation, usability, pricing, support, and clarity, plus better endpoint protection and third-party tool integration.
Microsoft Defender for Cloud needs enhanced customization, integration, automation, scalability, support, pricing, and user experience for better efficiency.
If notifications are available, then it will be more helpful, easy, and time-saving.
Sr Security Analyst at a computer software company with 201-500 employees
Alerts should be directly tied to compliance standards and have a clear role in the overall compliance process.
Cloud Security & Architecture Specialist at a insurance company with 10,001+ employees
The Infrastructure as Code service available in PingSafe and the services available in AWS cloud security can be merged so that we can get the security data directly from AWS cloud in PingSafe.
Cloud Engineer at a tech services company with 201-500 employees
There is no dedicated salesperson in Egypt, and having one would help to improve focus on this market.
Solution Architect at a tech services company with 51-200 employees
They say they can integrate with most firewalls, but when we did an integration with Meraki MX firewalls, that integration didn't work and still doesn't work to this day.
Security Analyst at a healthcare company with 10,001+ employees
We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.
Technical Consultant - Unix Platform Services at BITS AND BYTE IT CONSULTING PVT LTD
Microsoft, in general, could significantly improve its communication and support.
Endpoint management at a government with 10,001+ employees
It would be beneficial to streamline recommendations to avoid unnecessary alerts and to refine the severity of alerts based on specific environments or environmental attributes.
Works at Coca-Cola HBC
The artificial intelligence features could be expanded to allow the system to autonomously manage security issues without needing intervention from admins.
Cloud Consultant at i-Community AG
 

Setup Cost

SentinelOne offers competitive, flexible pricing with good value, though some find it high for large deployments.
Darktrace is costly yet valued for advanced features, offering flexible module selection with negotiable discounts and yearly contracts.
Microsoft Defender for Cloud pricing varies by workload and region, with some finding value and others noting hidden costs.
With very little negotiation involved, we just let them know what we could pay and they were willing to meet us at slightly above what we paid with Sophos, which was still very fair for what we were looking at.
IT Support Specialist at a non-tech company with 201-500 employees
If you want to buy just EDR, the price is less. XDR is a little bit more expensive.
IT Security Specialist at Tailor Security Tech
It should not be based on subscription. It should be based on the number of servers that I am scanning.
AVP DevOps and Product Support at a recruiting/HR firm with 1,001-5,000 employees
The product is considered expensive compared to others.
Solution Architect at a tech services company with 51-200 employees
The pricing is costly in USD, and they charge based on device counts.
Group Cybersecurity Administrator at Tharisa
The licensing cost is approximately eight dollars a year.
Security Information & Incident Analyst at a financial services firm with 1,001-5,000 employees
Security has essentially no cost when compared to the cost of a breach.
Director, Cloud and Modern Workplace at Informanix Technology Group
Every time we consider expanding usage, we carefully evaluate the necessity due to cost concerns.
Programme Manager- Cyber Fusion- Group CISO at a financial services firm with 10,001+ employees
We appreciate the licensing approach based on employee count rather than a big enterprise license.
Manager, Microsoft Technology Alliance at Silverfort
 

Valuable Features

SentinelOne Singularity Cloud Security provides scalable AI-driven cloud protection with automated remediation, deep visibility, and seamless third-party integration.
Darktrace offers AI-driven threat detection, real-time monitoring, and autonomous response with scalability and ease of integration for enhanced security.
Microsoft Defender for Cloud provides comprehensive security with CSPM and CWPP, enhancing threat detection, compliance, and automation across multi-cloud environments.
This tool has been helpful for us. It allows us to search for vulnerabilities and provides evidence directly on the screen.
Cloud Security Specialist at a insurance company with 10,001+ employees
The cloud misconfiguration feature gave us almost zero false positives.
Sr security engineer at Halodoc
PingSafe has sped up the process by 80% to 90%.
Sr Security Analyst at a computer software company with 201-500 employees
It is capable of responding to lateral movement and ransomware deployment within environments where there is data exfiltration.
Group Cybersecurity Administrator at Tharisa
I do not need to manually process incidents as Darktrace provides an incident summary, potential detection paths, and other details, all exportable with just a click.
Security Information & Incident Analyst at a financial services firm with 1,001-5,000 employees
If I am in a data center where I don't have layer two, it becomes an issue because the autonomous response is reliant on sending spoofed TCP resets to my core switch to block traffic, which is a major issue.
Security Analyst at a healthcare company with 10,001+ employees
The most valuable feature for me is the variety of APIs available.
Programme Manager- Cyber Fusion- Group CISO at a financial services firm with 10,001+ employees
This feature significantly aids in threat detection and enhances the user experience by streamlining security management.
Cloud Consultant at i-Community AG
The most valuable feature is the recommendations provided on how to improve security.
Cloud architect at a tech vendor with 1,001-5,000 employees
 

Categories and Ranking

SentinelOne Singularity Clo...
Sponsored
Ranking in Cloud Security Posture Management (CSPM)
3rd
Ranking in Cloud-Native Application Protection Platforms (CNAPP)
3rd
Average Rating
8.8
Reviews Sentiment
7.3
Number of Reviews
124
Ranking in other categories
Vulnerability Management (4th), Cloud and Data Center Security (5th), Container Security (3rd), Cloud Workload Protection Platforms (CWPP) (4th), Compliance Management (1st), AI Observability (3rd)
Darktrace
Ranking in Cloud Security Posture Management (CSPM)
10th
Ranking in Cloud-Native Application Protection Platforms (CNAPP)
9th
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
84
Ranking in other categories
Email Security (9th), Intrusion Detection and Prevention Software (IDPS) (2nd), Network Traffic Analysis (NTA) (1st), Network Detection and Response (NDR) (1st), Extended Detection and Response (XDR) (7th), Attack Surface Management (ASM) (4th), AI-Powered Cybersecurity Platforms (5th), AI Observability (6th)
Microsoft Defender for Cloud
Ranking in Cloud Security Posture Management (CSPM)
4th
Ranking in Cloud-Native Application Protection Platforms (CNAPP)
4th
Average Rating
8.0
Reviews Sentiment
6.9
Number of Reviews
89
Ranking in other categories
Vulnerability Management (5th), Container Management (6th), Container Security (5th), Cloud Workload Protection Platforms (CWPP) (1st), Data Security Posture Management (DSPM) (5th), Microsoft Security Suite (7th), Compliance Management (4th), Cloud Detection and Response (CDR) (3rd)
 

Mindshare comparison

As of May 2026, in the Cloud Security Posture Management (CSPM) category, the mindshare of SentinelOne Singularity Cloud Security is 4.9%, up from 2.8% compared to the previous year. The mindshare of Darktrace is 2.5%, up from 1.4% compared to the previous year. The mindshare of Microsoft Defender for Cloud is 6.3%, down from 10.1% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Cloud Security Posture Management (CSPM) Mindshare Distribution
ProductMindshare (%)
SentinelOne Singularity Cloud Security4.9%
Microsoft Defender for Cloud6.3%
Darktrace2.5%
Other86.3%
Cloud Security Posture Management (CSPM)
 

Featured Reviews

Sreeraj Mohandas - PeerSpot reviewer
Security Engineer at HashXpert
Consolidated cloud security has reduced manual work and has automated vulnerability remediation
I elaborate on my rating of SentinelOne support by mentioning that there was some time where the troubleshooting took a longer time. In fact, there were many meetings going on. The availability of the document on the internet is on a lesser side because as an engineer, I would want to know about the troubleshooting aspects of this particular tool. When I am facing a customer, I do not prefer to bring the vendor to every call and try to resolve it, as it takes months and months. It would be better to have a training session with the engineer on site to explain and train properly. This is not the case with SentinelOne, so this is the only thing I have a complaint about. I do not have any other room for improvement to suggest within SentinelOne itself. However, I would really want the AI assistant for the threat hunting part to be more accessible. They have it, but they are making it licensed, so it is a bit on the higher end.
AM
Technical Consultant - Unix Platform Services at BITS AND BYTE IT CONSULTING PVT LTD
Consistent threat hunting and anomaly detection deliver valuable insights for network security management
In terms of improvement for Darktrace, pricing is the main concern. Pricing bothers me and this is one of the major factors when choosing a solution. When we get feedback from customers, that's the only felt need. When we factor in Darktrace, we do it only limited. We put it on where the perimeters and connections are, but still, some gray areas are left out, especially if we have multiple branches. We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.
RW
Head Of IT at Cirrus Response
Cloud security has cut investigation time and now reveals threats faster but needs simpler oversight
When deploying AI applications, my key security concerns with Microsoft Defender for Cloud are data loss, leakage of data, and guardrails around the actual AI, and I am hoping that this is going to help me put those guardrails in place and identify data exfiltration. Microsoft Defender for Cloud has not helped me manage and secure multi-cloud environments, as we are 100 percent Microsoft and have not really got it in any other environment at all. I am not yet using the unified AI-powered security feature offered by Microsoft Defender for Cloud, but that is coming. I am not yet using the integrated XDR feature of Microsoft Defender for Cloud, but that is coming. I am not yet utilizing the GenAI threat protection features of Microsoft Defender for Cloud. That is also coming and a lot of that will come from learning it here. I have enabled the agentless scanning in my cloud environment with Microsoft Defender for Cloud. Assessing the impact on my workload protection without needing to install agents with Microsoft Defender for Cloud makes it a lot easier, but it also identifies a lot more, which puts more load on me sometimes. I would advise another organization considering Microsoft Defender for Cloud that it is the most logical route to follow if their whole ecosystem is Microsoft. It is easy to implement and it is very self-explanatory when doing it, making sense to just follow the steps as it is too simple, really. I would rate this review a 7.5 out of 10.
report
Use our free recommendation engine to learn which Cloud Security Posture Management (CSPM) solutions are best for your needs.
893,221 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Computer Software Company
11%
Manufacturing Company
9%
Government
5%
Manufacturing Company
9%
Computer Software Company
9%
Financial Services Firm
9%
Government
7%
Financial Services Firm
12%
Computer Software Company
10%
Manufacturing Company
9%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business52
Midsize Enterprise23
Large Enterprise58
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise19
Large Enterprise29
By reviewers
Company SizeCount
Small Business30
Midsize Enterprise12
Large Enterprise49
 

Questions from the Community

What do you like most about PingSafe?
The dashboard gives me an overview of all the things happening in the product, making it one of the tool's best featu...
What is your experience regarding pricing and costs for PingSafe?
My experience with the pricing, setup costs, and licensing of SentinelOne Singularity Cloud Security is that the pric...
What needs improvement with PingSafe?
Integration could be improved because not all solutions can be integrated with SentinelOne Singularity Cloud Security...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is ...
What is your experience regarding pricing and costs for Darktrace?
Concerning pricing for the product, I would say it is somewhat expensive.
How is Prisma Cloud vs Azure Security Center for security?
Azure Security Center is very easy to use, integrates well, and gives very good visibility on what is happening acros...
What is your experience regarding pricing and costs for Microsoft Defender for Cloud?
My experience with pricing, setup costs, and licensing was that the license cost was the only consideration. Setup an...
What needs improvement with Microsoft Defender for Cloud?
To improve Microsoft Defender for Cloud, I think pricing-wise, the license price is a little bit higher from an inges...
 

Also Known As

PingSafe
No data available
Microsoft Azure Security Center, Azure Security Center, Microsoft ASC, Azure Defender
 

Interactive Demo

Demo not available
Demo not available
 

Overview

 

Sample Customers

Information Not Available
Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
Microsoft Defender for Cloud is trusted by companies such as ASOS, Vatenfall, SWC Technology Partners, and more.
Find out what your peers are saying about Darktrace vs. Microsoft Defender for Cloud and other solutions. Updated: April 2026.
893,221 professionals have used our research since 2012.