Try our new research platform with insights from 80,000+ expert users

Darktrace vs Microsoft Defender XDR comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 8, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.3
Darktrace users experience substantial returns through threat prevention and reduced downtime, despite deployment challenges and difficulty measuring returns.
Sentiment score
7.1
Microsoft Defender XDR provides high ROI by consolidating security tools, streamlining operations, and enhancing security, despite licensing costs.
Other NDR solutions provide virtual appliances that can be deployed on virtualization servers to get up and running quickly.
Technical Consultant - Unix Platform Services at BITS AND BYTE IT CONSULTING PVT LTD
Using this solution provides financial benefits by securing from server attacks, which offers indirect savings.
Systems Specialist/ Administrator at ALFA International Company Limited.
We can quarantine and isolate a device within minutes.
Information Security Analyst at a educational organization with 10,001+ employees
Microsoft Defender XDR has saved me at least 50% of my time.
House security operator at Cypress Creek Renewables
It helped stop multiple intrusion points where we would have had millions in lost revenue if the attackers got in.
Network Technician at T. Baker Smith, LLC
 

Customer Service

Sentiment score
7.6
Darktrace's customer service is praised for responsiveness and efficiency, though some suggest improvements for complex issues.
Sentiment score
6.1
Microsoft Defender XDR's support is timely and responsive, yet smaller organizations experience slower, less effective assistance than larger ones.
The technical support from Darktrace is of high quality.
Network & Security Section Head/Digital Transformation at City Edge
Darktrace provides excellent technical support with a monthly meeting to review platform incidents, ensuring the system functions as expected.
Head of Technology Operations at Pobl Group
The challenge lies in waiting for a response after logging a ticket.
Group Cybersecurity Administrator at Tharisa
You get stuck in low-level support for way longer than you should, instead of them escalating the issue up the chain.
Enterprise Application Engineer at a legal firm with 1,001-5,000 employees
It's critical to escalate SEV B issues immediately to a domestic engineer.
Infrastructure engineer at Cetera Financial Group
Once issues are escalated to the second or third layer, the support is much better.
Cyber Security Engineer at a financial services firm with 1-10 employees
 

Scalability Issues

Sentiment score
7.6
Darktrace is praised for its scalability, supporting diverse user bases and integrating well with existing infrastructures.
Sentiment score
6.9
Microsoft Defender XDR scales well for various organizations, efficiently supporting growth and flexibility despite some network deployment challenges.
Darktrace has high scalability, and I would rate it a nine out of ten.
Network & Security Section Head/Digital Transformation at City Edge
Since it's cloud-based, it expands easily.
Head of Technology Operations at Pobl Group
There is still a gap in terms of storage, and we are trying to figure out how to increase that capacity for regulated environments, which require data retention for 5 to 6 years.
Technical Consultant - Unix Platform Services at BITS AND BYTE IT CONSULTING PVT LTD
My concern is about the scale of events and alerts being generated, and the product is doing a very good job of only surfacing the important items for us.
Vice President, Information Technology at a construction company with 201-500 employees
Microsoft Defender XDR shows tremendous scalability, much more so than on-premises solutions.
Infrastructure engineer at Cetera Financial Group
Microsoft Defender XDR scales pretty well.
Information Security Analyst at a educational organization with 10,001+ employees
 

Stability Issues

Sentiment score
8.5
Darktrace is highly rated for stability and reliability, with effective monitoring and an intuitive interface despite occasional traffic impacts.
Sentiment score
8.1
Microsoft Defender XDR is praised for high stability, reliable performance, minimal issues, frequent updates, and prompt issue resolution.
The stability of Darktrace is excellent, rated ten out of ten.
Head of Technology Operations at Pobl Group
The appliance itself has never let me down.
Group Cybersecurity Administrator at Tharisa
For stability, I would rate Darktrace an eight out of ten.
Security Analyst at a healthcare company with 10,001+ employees
The service has remained consistently online, with any issues isolated to specific components, suggesting a well-designed and modular architecture.
Senior System Engineer at a sports company with 5,001-10,000 employees
The services within our ecosystem have been reliable, meeting their SLAs.
Infrastructure engineer at Cetera Financial Group
It provides high-fidelity signals.
Information Security Analyst at a educational organization with 10,001+ employees
 

Room For Improvement

Darktrace needs improved integration, automation, usability, pricing, support, and clarity, plus better endpoint protection and third-party tool integration.
Microsoft Defender XDR requires enhancements in speed, integration, automation, AI, ease-of-use, and industry-specific threat intelligence.
There is no dedicated salesperson in Egypt, and having one would help to improve focus on this market.
Solution Architect at a tech services company with 51-200 employees
They say they can integrate with most firewalls, but when we did an integration with Meraki MX firewalls, that integration didn't work and still doesn't work to this day.
Security Analyst at a healthcare company with 10,001+ employees
We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.
Technical Consultant - Unix Platform Services at BITS AND BYTE IT CONSULTING PVT LTD
The licensing process needs improvement and clarification.
Owner at a consultancy with 11-50 employees
Improvements are needed in automated response capabilities.
Security manager at a consultancy with 10,001+ employees
Some inconsistencies exist between blades, which could be improved for a more seamless user and UI experience.
Infrastructure engineer at Cetera Financial Group
 

Setup Cost

Darktrace is costly yet valued for advanced features, offering flexible module selection with negotiable discounts and yearly contracts.
Microsoft Defender XDR pricing is seen as complex but fair, with high costs alleviated in bundled Microsoft 365 packages.
The product is considered expensive compared to others.
Solution Architect at a tech services company with 51-200 employees
The pricing is costly in USD, and they charge based on device counts.
Group Cybersecurity Administrator at Tharisa
The licensing cost is approximately eight dollars a year.
Security Information & Incident Analyst at a financial services firm with 1,001-5,000 employees
There are certainly savings when using Microsoft Defender XDR, which can range from 30%, 40%, and even up to 50%.
Director, Sales at a tech vendor with 201-500 employees
I would rate the pricing as eight out of ten, indicating it is a reasonable cost for the product.
Security manager at a consultancy with 10,001+ employees
Microsoft purposefully obfuscates this through marketing ploys to hide costs.
Senior System Engineer at a sports company with 5,001-10,000 employees
 

Valuable Features

Darktrace offers AI-driven threat detection, real-time monitoring, and autonomous response with scalability and ease of integration for enhanced security.
Microsoft Defender XDR integrates tools for comprehensive security, offering threat detection, automation, identity protection, and enhanced efficiency.
It is capable of responding to lateral movement and ransomware deployment within environments where there is data exfiltration.
Group Cybersecurity Administrator at Tharisa
I do not need to manually process incidents as Darktrace provides an incident summary, potential detection paths, and other details, all exportable with just a click.
Security Information & Incident Analyst at a financial services firm with 1,001-5,000 employees
If I am in a data center where I don't have layer two, it becomes an issue because the autonomous response is reliant on sending spoofed TCP resets to my core switch to block traffic, which is a major issue.
Security Analyst at a healthcare company with 10,001+ employees
With Microsoft threat intelligence information, it detects various types of threats, including insider attacks, malicious content, and data exfiltration.
Security manager at a consultancy with 10,001+ employees
This allows us to secure our systems in advance and proactively improve security, rather than waiting for incidents to occur.
Works at Hometrack
Once we have it on the security dashboard, we can see a real-time storyline.
Information Security Analyst at a educational organization with 10,001+ employees
 

Categories and Ranking

Darktrace
Ranking in Extended Detection and Response (XDR)
6th
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
84
Ranking in other categories
Email Security (9th), Intrusion Detection and Prevention Software (IDPS) (2nd), Network Traffic Analysis (NTA) (1st), Network Detection and Response (NDR) (1st), Cloud Security Posture Management (CSPM) (13th), Cloud-Native Application Protection Platforms (CNAPP) (11th), Attack Surface Management (ASM) (4th), AI-Powered Cybersecurity Platforms (4th), AI Observability (8th)
Microsoft Defender XDR
Ranking in Extended Detection and Response (XDR)
3rd
Average Rating
8.4
Reviews Sentiment
7.1
Number of Reviews
106
Ranking in other categories
Endpoint Detection and Response (EDR) (7th), Microsoft Security Suite (5th)
 

Mindshare comparison

As of January 2026, in the Extended Detection and Response (XDR) category, the mindshare of Darktrace is 6.1%, down from 9.1% compared to the previous year. The mindshare of Microsoft Defender XDR is 4.9%, down from 6.8% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR) Market Share Distribution
ProductMarket Share (%)
Microsoft Defender XDR4.9%
Darktrace6.1%
Other89.0%
Extended Detection and Response (XDR)
 

Featured Reviews

AM
Technical Consultant - Unix Platform Services at BITS AND BYTE IT CONSULTING PVT LTD
Consistent threat hunting and anomaly detection deliver valuable insights for network security management
In terms of improvement for Darktrace, pricing is the main concern. Pricing bothers me and this is one of the major factors when choosing a solution. When we get feedback from customers, that's the only felt need. When we factor in Darktrace, we do it only limited. We put it on where the perimeters and connections are, but still, some gray areas are left out, especially if we have multiple branches. We need Darktrace on each branch to get the data out, and I suggest having some kind of a centralized product that gets data from multiple sources to aggregate and provide the data.
KO
House security operator at Cypress Creek Renewables
Advanced threat hunting saves significant time in tracking and responding to incidents
Microsoft Defender XDR could be improved with a lower price. My main suggestion would essentially be what Copilot is providing, which is a single pane of glass, so I don't have to go to different windows. That's just a workflow consideration for me. It would be great to have all the information centralized into one particular data app. If I need to open up extra ones, I can, however, I would appreciate a future where everything I need is right there on one single pane of glass. Beyond that, there's really nothing else I see that I would want Microsoft to improve.
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
881,114 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Manufacturing Company
9%
Financial Services Firm
8%
Government
7%
Computer Software Company
13%
Financial Services Firm
9%
Manufacturing Company
8%
Comms Service Provider
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business45
Midsize Enterprise19
Large Enterprise29
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise25
Large Enterprise38
 

Questions from the Community

How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is meant for smaller to medium-sized businesses. It is also a good option for organ...
What do you like most about Darktrace?
A very useful feature in Darktrace for real-time threat analysis is the packet inspection that analyzes the packet traffic in real time.
What do you like most about Microsoft 365 Defender?
Microsoft Defender XDR provides strong identity protection with comprehensive insights into risky user behavior and potential indicators of compromise.
What is your experience regarding pricing and costs for Microsoft 365 Defender?
My experience with pricing, setup, costs, and licensing of Microsoft Defender XDR is tied to our E5 subscription, which is very straightforward for us. We also purchase the uplift for our mobile us...
What needs improvement with Microsoft 365 Defender?
I am not aware of a mobile app that would be available for my team. With a single analyst, if she is ever away, it would be beneficial to have easier access. While she can use the web portal, the e...
 

Also Known As

No data available
Microsoft 365 Defender, Microsoft Threat Protection, MS 365 Defender
 

Overview

 

Sample Customers

Irwin Mitchell, Open Energi, Wellcome Trust, FirstGroup plc, Virgin Trains, Drax, QUI! Group, DNK, CreaCard, Macrosynergy, Sisley, William Hill plc, Toyota Canada, Royal British Legion, Vitol, Allianz, KKR, AIRBUS, dpd, Billabong, Mclaren Group.
Accenture, Deloitte, ExxonMobil, General Electric, IBM, Johnson & Johnson and many others.
Find out what your peers are saying about Darktrace vs. Microsoft Defender XDR and other solutions. Updated: December 2025.
881,114 professionals have used our research since 2012.