Try our new research platform with insights from 80,000+ expert users

Darktrace vs Microsoft Defender for Office 365 comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Dec 28, 2025

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cloudflare One
Sponsored
Ranking in Email Security
20th
Average Rating
8.8
Reviews Sentiment
6.7
Number of Reviews
22
Ranking in other categories
Secure Web Gateways (SWG) (15th), Data Loss Prevention (DLP) (21st), Cloud Access Security Brokers (CASB) (11th), Distributed Denial-of-Service (DDoS) Protection (7th), Software Defined WAN (SD-WAN) Solutions (13th), Access Management (12th), Bot Management (3rd), ZTNA as a Service (8th), ZTNA (3rd), Secure Access Service Edge (SASE) (10th), Remote Browser Isolation (RBI) (3rd)
Darktrace
Ranking in Email Security
8th
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
84
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (2nd), Network Traffic Analysis (NTA) (1st), Network Detection and Response (NDR) (1st), Extended Detection and Response (XDR) (7th), Cloud Security Posture Management (CSPM) (11th), Cloud-Native Application Protection Platforms (CNAPP) (9th), Attack Surface Management (ASM) (4th), AI-Powered Cybersecurity Platforms (4th), AI Observability (9th)
Microsoft Defender for Offi...
Ranking in Email Security
2nd
Average Rating
8.4
Reviews Sentiment
6.8
Number of Reviews
60
Ranking in other categories
Email Archiving (1st), Advanced Threat Protection (ATP) (2nd), Microsoft Security Suite (9th), Secure Email Gateway (SEG) (1st)
 

Mindshare comparison

As of March 2026, in the Email Security category, the mindshare of Cloudflare One is 1.5%, down from 1.8% compared to the previous year. The mindshare of Darktrace is 2.1%, down from 3.0% compared to the previous year. The mindshare of Microsoft Defender for Office 365 is 8.8%, down from 13.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Email Security Mindshare Distribution
ProductMindshare (%)
Microsoft Defender for Office 3658.8%
Darktrace2.1%
Cloudflare One1.5%
Other87.6%
Email Security
 

Featured Reviews

CV
Network Architect at IP Dimension
Cloud security has improved remote access and has reduced costs for smaller client sites
I have used Cloudflare One's Identity-Aware Proxy, and it is quite straightforward from what I have seen so far. The app registration on the Azure side integrates fully into Cloudflare, and I am very satisfied with that part because it is easy to set up. The integration of Cloudflare One's Secure Web Gateway and Zero Trust Network Access works without any issues. That part is pretty automatic, and if you complete the rest of the setup, it comes together by itself with no issues from my side. What makes it nice is that we can actually start replacing on-site firewalls at this stage for the smaller clients because it does not matter if they go to a coffee shop or work from home; they are still secured by the same connection. The hops get shorter and you get better latency. We have done testing to see if it is better. One thing that we did notice with our proof of concept with our current client is that they have people connecting from the UK. When they used their previous VPN solution, uploading CAD drawings and other files to the server took a long time. They mentioned that it is much quicker on Cloudflare One's solution. I definitely believe that is part of the improved performance, and I am satisfied with that as well. What is nice about Cloudflare One is that it makes the setup easier and also easier to train technicians to maintain it. Compared to legacy systems, we do not need to get fancy firewalls in place that are costly. That is definitely also a cost-saver with Cloudflare One.
AM
Technical Consultant - Unix Platform Services at BITS AND BYTE IT CONSULTING PVT LTD
Consistent threat hunting and anomaly detection deliver valuable insights for network security management
In terms of improvement for Darktrace, pricing is the main concern. Pricing bothers me and this is one of the major factors when choosing a solution. When we get feedback from customers, that's the only felt need. When we factor in Darktrace, we do it only limited. We put it on where the perimeters and connections are, but still, some gray areas are left out, especially if we have multiple branches. We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.
Emeka Ndulu - PeerSpot reviewer
Cloud Solutions Architect at a tech services company with 201-500 employees
Improves threat visibility and response while reducing manual tasks and training users against phishing
I appreciate the attack simulation feature whereby I get to train users and educate them on how to identify phishing emails and spam emails, as well as the anti-spam protection. It gives me visibility into my threat environment and threat landscape to ensure that I am one step ahead of any likelihood of threats within my environment. I get to detect it and respond, so the threat intelligence is very effective. Microsoft security solutions save my time. It saves money because once I protect my environment, I don't lose money. It has decreased my detection time and my time to respond.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"This solution is easy to understand and easy to configure."
"Using Cloudflare One makes my work quite easy because for DDoS protection, all I need to do is understand the OSI model and click; it makes it easier than trying to write a command line or use a Linux command."
"Cloudflare Access is part of the Zero Trust philosophy."
"It's the endpoint exposition. We don't need to expose our VPN server to the internet and need a zero-test solution. I can apply some conditional access to the endpoint that's connecting to our network to check their security policies or the security condition of their workstation. Once the workstation is trying to connect to my internal network, then I would like to check the discrete condition of these endpoints that are trying to access my internal network. We created some conditional access. We have CrowdStrike, to check if the CrowdStrike is installed, to check if it's updated, and to check for Windows updates. We created some conditional policies to check it."
"It will take the blow rather than our applications should an attack occur."
"The blocking feature is very good."
"Cloudflare is simple to use."
"Cloudflare, in my opinion, was easy to implement."
"Regarding the autonomous response feature, I appreciate how it functions within the platform."
"The most valuable feature is the solution's ability to trim out the false positives and point your attention to the real important stuff."
"The technical support from Darktrace is very good, including support from their resellers."
"I like the dashboards, which are cool. They are more user-friendly, in my experience. Its learning capabilities are really good."
"We are able to detect a lot of things, actually, and see what is happening in our network."
"It provides a comprehensive, detailed view of network activity and whatever is happening inside it."
"The platform has many modules, and each module examines a different situation in the behavior."
"Darktrace is very flexible."
"Microsoft Defender for Office 365 has improved my organization's security. It makes it easier to manage the infrastructure without the help of third-party applications."
"Defender is a SaaS platform, so it offers more flexibility. Managing the permissions is easier. The solution's automated detection and response features are scalable."
"It gives me visibility into my threat environment and threat landscape to ensure that I am one step ahead of any likelihood of threats within my environment."
"Microsoft Defender for Office 365 is a stable solution."
"The product's scalability is good."
"Microsoft Defender for Office 365 saves me time; it does save a lot of time, especially with the automation."
"We use Microsoft Defender for its ability to integrate with existing business technologies, which is beneficial for protecting business areas."
"Threat Explorer is an invaluable tool for me, and it plays a crucial role in helping me discern the origins of various email campaigns, pinpointing where they emanate from, and identifying the individuals within our organization who are affected."
 

Cons

"Feedback could be enhanced. While I work efficiently with Clover as a partner in Mexico City, sometimes the information and requests are easier to manage with more concrete solutions."
"Our customers no longer use Cloudflare because its service is subpar."
"Cloudflare Zero Trust Platform needs to improve its documentation. It took time to do the implementation."
"The tool should provide on-premise versions. Currently, all versions are cloud-based."
"When there are any dynamic changes in complex applications, the tool takes a lot of time, making its analytics-related area a major matter of concern where improvements are needed."
"The pricing is an area that can be improved. Pricing, as far as I recall, was the source of our problems."
"The software has automated alerts, but the automated alerts are not available in the mobile app."
"Cloudflare DDoS has poor technical support."
"I did not use the AI features because they should make it more user-friendly which would be a benefit. Additionally, the solution could integrate with more SIEM or SOAR tools."
"Upper management wasn't sold on the value proposition."
"One thing that I would like to look at going forward is to have a fully automated network infrastructure that is monitored automatically real-time, and that gives me this kind of capability where I would be able to look at my network at any given time and see the state of my network. With Darktrace, at the moment, I have to almost put in a date and tell them that want you to give me data from this date to this date. I don't want that. I want a fast solution in which it doesn't matter when I log into the application. Whenever I log in, I must be able to see my network and run a report. In other words, if I go in now and I say, "Give me a full report of what happened today, it must be able to give me that. It mustn't just be limited to a seven-day period, for argument's sake. It must be able to give me real-time and day-to-day tracking of what has happened within my network."
"I would like to see more protection in the endpoint. Especially because we have a lot of people using VPNs. If they would improve end point security, it would give more control there."
"In the next version, I'd like to see penetration testing."
"As of now, I feel Darktrace can be improved to better detect end device activities, such as laptops or desktops, to bind it with our network."
"Pricing bothers me and this is one of the major factors when choosing a solution."
"In a shared environment, it doesn't work, and there are still some integration issues."
"Microsoft needs to broaden its global support presence by establishing teams of subject-matter experts in all regions."
"The only thing they should improve is the licensing model. They should stop changing it. A year ago, the five features I mentioned were included in one product. Now, three of them are bundled into one product, and you have to pay extra for the other two. I don't mind paying extra, but I don't want them to change it every year or every six months. I need to know what I'm looking at and not worry about it next year."
"I'd like some additional features any product can give me to protect our environment in a better way."
"This product's effectiveness could be improved, in terms of detecting unwanted spam or even malware between the emails, compared to other products."
"Microsoft Defender for Office 365 must improve the overall management style, including the GUI. It also needs to change the filters so that it is easy to whitelist and blacklist data."
"Microsoft Defender for Office 365 is not up to the mark in comparison with Wiz or Palo Alto."
"The changes to customer service, specifically the new model for support agreements, are not favorable."
"Microsoft security solutions work as expected. They are constantly updating the solutions to make them better. At the same time, the changes can impact a customer's environment, and we need to adjust settings. Sometimes we aren't aware of the changes, and nothing is pushed from the backend automatically."
 

Pricing and Cost Advice

"My company has to make yearly payments towards the licensing costs attached to the solution. There are no hidden charges apart from the licensing costs of the solution."
"The solution's pricing lacks transparency."
"The price tag is no longer $200,000, but rather $300,000 to $400,000. It's twice."
"Cloudflare Zero Trust Platform's pricing is good."
"The pricing is somewhere in the middle. I would rate the pricing a seven out of ten."
"The solution is not that expensive."
"The pricing of the solution is cheap. The licensing cost is also very low. I rate the cost and pricing a three out of ten."
"The prices are slightly expensive."
"It is expensive. I don't have the price for other competitors."
"The pricing is quite high, estimated at around $350,000 per year."
"When it comes to large installations, it can be expensive, but for small accounts it's fine."
"The price of Darktrace is high and could be reduced. We pay approximately $30,000 to $54,000 annually."
"The cost is moderate."
"The pricing is subscription-based and it is high."
"I'm unfamiliar with the exact cost, but we have a yearly license and had to pay for Darktrace's services before the deployment. The product is very expensive, so some organizations can't afford to pay the total amount directly, meaning they often seek a partner or pay in installments, which increases the price more."
"It is inexpensive considering what it can do and the competition."
"Defender for 365 comes in various plans and licenses, along with other Microsoft security solutions. Purchasing this kind of package or security bundle gives good value for money, and that's what I recommend."
"The solution could be better by simplifying the business model of their licensing. It was hard to figure out how to get the licensing done for the environment, initially."
"The product is very expensive."
"I was working in the government and it was too expensive for us to use our Microsoft products."
"Defender is a little bit more expensive as compared to others. We are in the manufacturing environment. So, we don't have a high budget for all of our endpoint devices. Its cost is a major concern for us."
"The pricing has become expensive."
"Compared to other brands, Microsoft Defender for Office 365's pricing is competitive."
"The pricing is normal. Considering its popularity, it's not overpriced."
report
Use our free recommendation engine to learn which Email Security solutions are best for your needs.
884,192 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
10%
Computer Software Company
10%
Financial Services Firm
9%
Manufacturing Company
7%
Computer Software Company
10%
Manufacturing Company
9%
Financial Services Firm
8%
Government
7%
Computer Software Company
13%
Financial Services Firm
8%
Manufacturing Company
8%
Comms Service Provider
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business10
Midsize Enterprise2
Large Enterprise10
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise19
Large Enterprise29
By reviewers
Company SizeCount
Small Business23
Midsize Enterprise10
Large Enterprise31
 

Questions from the Community

What needs improvement with Cloudflare Access?
Cloudflare Access has strong integration with Microsoft, among other platforms. However, when it comes to Kaspersky, ...
What is your primary use case for Cloudflare Access?
Cloudflare Access provides secure access to internal applications for employees, external members of the organization...
What advice do you have for others considering Cloudflare Access?
Cloudflare Access is one of the best integrations available. While about two hundred vendors offer similar services, ...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing u...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is ...
What is your experience regarding pricing and costs for Darktrace?
Concerning pricing for the product, I would say it is somewhat expensive.
What needs improvement with Microsoft Defender for Office 365?
The inbuilt analysis of false positives can be faster. It's not slow, but it can be faster.
What is your primary use case for Microsoft Defender for Office 365?
My use case for Microsoft Defender for Office 365 is for email protection, safe links, protection of links, documents...
 

Also Known As

Cloudflare Area 1 Email Security, Cloudflare Bot Management, Cloudflare Gateway, Cloudflare Zero Trust Platform, Cloudflare DDoS, Cloudflare SASE & SSE Platform
No data available
MS Defender for Office 365
 

Overview

 

Sample Customers

23andMe
Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
Microsoft Defender for Office 365 is trusted by companies such as Ithaca College.
Find out what your peers are saying about Darktrace vs. Microsoft Defender for Office 365 and other solutions. Updated: March 2026.
884,192 professionals have used our research since 2012.