No more typing reviews! Try our Samantha, our new voice AI agent.

DefectDojo vs Microsoft Defender Vulnerability Management comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

DefectDojo
Ranking in Vulnerability Management
44th
Average Rating
8.0
Reviews Sentiment
6.6
Number of Reviews
1
Ranking in other categories
DevSecOps (12th)
Microsoft Defender Vulnerab...
Ranking in Vulnerability Management
13th
Average Rating
8.2
Reviews Sentiment
6.4
Number of Reviews
18
Ranking in other categories
Advanced Threat Protection (ATP) (18th), Microsoft Security Suite (18th), Risk-Based Vulnerability Management (6th)
 

Mindshare comparison

As of May 2026, in the Vulnerability Management category, the mindshare of DefectDojo is 0.9%, up from 0.5% compared to the previous year. The mindshare of Microsoft Defender Vulnerability Management is 1.8%, down from 3.2% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Vulnerability Management Mindshare Distribution
ProductMindshare (%)
Microsoft Defender Vulnerability Management1.8%
DefectDojo0.9%
Other97.3%
Vulnerability Management
 

Featured Reviews

reviewer2267097 - PeerSpot reviewer
Integration and Solution Architect at a government with 501-1,000 employees
Easy to use with efficient vulnerability reporting and team collaboration
Use case, so all the reports from GitLeaks, DefectDojo, GitLeaks or dependency check or Trivy, they make reports, and we send this report to DefectDojo to have CVMs, Central Vulnerability Management. DefectDojo is Central Vulnerability Management. If you have a dashboard to set, we have…
OB
Microsoft Solutions Manager at Self-Employed
Ensures strong threat and vulnerability management with continuous risk assessment
The major priority is identity, which is crucial; we have lots of companies in manufacturing, energy, or various sectors, and it varies from one to another. I assess Microsoft Defender Vulnerability Management as very effective in continuously assessing vulnerabilities without requiring scans. We use automatic investigation and remediation features, safe attachments, safe links, and real-time reports, which are also very effective. For Active Directory, Defender has threat intelligence, and we are using that. The risk-based prioritization within Vulnerability Management affects my ability to manage vulnerabilities, particularly in relation to the Zero Trust Model utilized by our customers. The end-users often do as they please in their systems.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"With the pipeline of detection and DefectDojo, we are able to see the real vulnerabilities, and we fix them."
"The solution is highly scalable."
"The integration with Sentinel has been one of the most valuable features for my organization."
"Microsoft Defender Vulnerability Management is a good product, and I believe it deserves a positive recommendation."
"Microsoft Defender Vulnerability Management provides several valuable features that I utilize, as I use it to control security configuration, for example, the apps that I use or the many connections from my router, and with this configuration, I can filter content and malware."
"The solution helps identify threats and vulnerabilities."
"Microsoft Defender Vulnerability Management provides regular advisories and recommendations that help improve our security posture."
"The integration with Sentinel has been one of the most valuable features for my organization."
"Microsoft Defender Vulnerability Management is versatile and assesses vulnerabilities, providing detailed information on CVEs, their categories, and exploit statuses."
 

Cons

"We need something to notify the team responsible for a product when vulnerabilities are found."
"They may need to improve the portal refresh rate for Microsoft Defender Vulnerability Management because it takes time for recommendations to disappear after mitigation; sometimes, it takes one week, when it should ideally take only one to two hours."
"It is challenging to extract and customize reports from the system."
"The product is not stable; it is very resource-intensive, consuming a lot of memory and CPU, which makes it slow."
"Probably my only criticism would be the cost. It is expensive."
"Regarding Microsoft's technical support, I would rate it a three out of ten; they could be more responsive and knowledgeable."
"The constant changes in the product configuration or the console setup can sometimes be challenging."
"We have experienced some logging issues, including a few hours of downtime initially. Despite this, I would rate the overall stability as an eight."
"Configuration of Microsoft Defender Vulnerability Management is something that needs improvement."
 

Pricing and Cost Advice

Information not available
"The tool is a bit costly."
"I rate the product's price a three on a scale of one to ten, where one is a low price, and ten is a high price."
"The product’s pricing is medium."
"The licensing model follows a per-user per-month structure."
"The licensing costs are reasonable."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
893,244 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
13%
Financial Services Firm
12%
Computer Software Company
10%
Construction Company
8%
Financial Services Firm
12%
Manufacturing Company
8%
Government
7%
Computer Software Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise2
Large Enterprise8
 

Questions from the Community

What is your experience regarding pricing and costs for DefectDojo?
The pricing is great. It is much cheaper compared to other solutions. We don't want to pay for things we are able to do on our own.
What needs improvement with DefectDojo?
We need something to notify the team responsible for a product when vulnerabilities are found. We are able to attach a team or a manager for a product, however, we are not able to send them a notif...
What is your primary use case for DefectDojo?
Use case, so all the reports from GitLeaks, DefectDojo, GitLeaks or dependency check or Trivy, they make reports, and we send this report to DefectDojo to have CVMs, Central Vulnerability Managemen...
What needs improvement with Microsoft Defender Vulnerability Management?
When I create rules, it gave me problems and I did not know where the problem was located. A small pop-up notification indicating how a rule should be configured would be helpful, rather than the p...
What is your primary use case for Microsoft Defender Vulnerability Management?
I do not use Microsoft Defender Vulnerability Management at work. However, I am currently not working, but I do use Microsoft Defender Vulnerability Management on my personal computer.
 

Overview

Find out what your peers are saying about Wiz, Tenable, Qualys and others in Vulnerability Management. Updated: May 2026.
893,244 professionals have used our research since 2012.