

Microsoft Defender for Identity and Huntress Managed EDR are significant contenders in the cybersecurity domain, particularly focusing on identity security and endpoint detection. Based on the gathered data, Huntress Managed EDR seems to have an edge for smaller to medium businesses due to its ease of deployment, low false positives, and superior customer support.
Features: Microsoft Defender for Identity is known for its seamless integration within the Microsoft ecosystem, providing comprehensive threat detection capabilities and holistic views through tools like Azure AD Identity Protection. It also excels in advanced identity security features and offers integrated security monitoring across on-premises and cloud environments. Huntress Managed EDR is renowned for its ease of deployment and robust threat-hunting expertise, providing low false positives and automated remediation. It integrates well with existing systems, making it an efficient solution for endpoint protection in SMBs.
Room For Improvement: Microsoft Defender for Identity could enhance its handling of false positives and improve threat intelligence data. Refining alert management and aligning Azure ID with on-premises functions are also suggested improvements. Huntress Managed EDR would benefit from better report customization, more third-party solution integrations, and increased alert detail transparency. Expanding coverage for various platforms and stronger antivirus tool integrations are also recommended.
Ease of Deployment and Customer Service: Both solutions offer flexible deployment across cloud and on-premises environments. Microsoft Defender for Identity supports multiple setups but faces occasional customer service challenges, with discrepancies in response quality. Huntress Managed EDR is preferred for its simplicity in deployment and highly responsive technical support, ensuring an overall positive customer experience.
Pricing and ROI: Microsoft Defender for Identity is typically bundled within Microsoft 365 suites like E3 and E5. It is considered cost-effective when integrated with Microsoft services, though some users find it costly as an add-on to E3 licenses. Huntress Managed EDR offers competitive pricing, especially beneficial for SMBs, delivering good value and cost-effectiveness compared to pricier alternatives.
We have to provide endpoint security as a core part of our service as an MSP and using Huntress Managed EDR has saved us approximately a thousand dollars a month over using other more expensive, less effective solutions.
My advice to others looking into using Huntress Managed EDR is that if they're looking for an easy-to-use and manage solution, Huntress Managed EDR is a good fit for a small to medium company.
I have seen a return on investment mainly through time savings, as we know all the endpoints are protected 24/7, and we understand the value of the SOC team, with the human SOC team being very valuable.
I felt it was important to raise awareness about this new technique where attackers use legitimate applications to gain remote access and control of computers.
They are thorough and ensure the problem is addressed without pushing responsibilities onto me unnecessarily.
For technical support, I would rate Huntress a ten out of ten, and in truth, they are better than that.
Generally, the support is more effective than other providers like Oracle.
The quality of support is very good, but troubleshooting can take time due to complex setups and the need to provide many logs.
The people I normally use for support are very knowledgeable, especially when they help remote in and get to where I need to go and show me much faster and help me understand what I should be doing.
I know other techs with thousands deployed, so scalability isn't an issue.
Scaling Huntress is simple; I can manage up to a thousand devices without issue.
I can easily scale from one machine to thousands without any fuss.
In a Microsoft-centric organization, especially with Azure infrastructure and Office 365, Microsoft Defender for Identity is scalable.
About stability, we have not seen any lagging, crashing, downtime, or any sort of instability with Huntress Managed EDR.
We have not experienced any issues with lagging, crashing, or downtime.
I never experienced issues, but once there was an instance with false positives with their Rio service, which was quickly resolved by customer service.
Microsoft Defender for Identity is quite robust and built on Azure hyperscale infrastructure, with a 99% availability.
We do not see any issues with the stability of Microsoft Defender for Identity.
Having recently started using it, reliability is affirmed, but manual investigation is often performed to verify if alerts identified by auto-remediation are accurate.
A more transparent way for the support team at Huntress and our IT team to collaborate to make it faster and easier would be beneficial.
Huntress Managed EDR indicated this is a normal behavior, but I would prefer to be alerted whenever there is any incident involving Windows Defender on any machines, regardless of the status of the incident.
Since we support customers in different countries, expanding the language options for their training would be beneficial.
If Microsoft could develop a feature that indicates when impossible travel is caused by VPN connections, it would prevent unnecessary password resets and session disruptions, especially for VIP users in organizations.
One improvement I would recommend is the integration of an admin application within Teams, allowing easy access to attack information on a mobile platform.
Reducing false positives is something we've been working on with Microsoft.
The savings from utilizing the included Windows Defender offset the cost of Huntress Managed EDR, making it an affordable solution overall.
It is not too expensive or too cheap. It is just right.
It can get expensive for small to medium businesses if large license quantities are not purchased.
If they can reduce the costs, organizations will be happy, and it will compensate for using the Azure environment, which is more expensive on the infrastructure as a service side.
Ensuring a fair price according to market standards.
From an organization perspective, using E5 licenses is value for money, especially if Azure and Office 365 are already in use.
What stands out most is their human element: when faced with an unknown threat, real people, not just automated processes, are investigating it, and they're people we trust.
They provide detailed remediation steps, explaining why an issue is a problem and what steps to take.
Previously, I could not modify it unless I had special Microsoft licensing, so it was beneficial to control Windows Defender through a central console to add policies and things like that.
We receive an advance report of risky users, allowing us to take preemptive action before an attack causes damage to organization details.
The most valuable feature is its hybrid artificial intelligence, which gathers forensic data to track and counteract security threats, much like the CSI series in effect.
The advanced threat protection is one of the strengths of Microsoft Defender for Identity, as it utilizes user and entity analytics and can detect indicative attacks.
| Product | Mindshare (%) |
|---|---|
| Huntress Managed EDR | 6.6% |
| CrowdStrike Falcon Complete MDR | 6.9% |
| SentinelOne Vigilance | 6.3% |
| Other | 80.2% |
| Product | Mindshare (%) |
|---|---|
| Microsoft Defender for Identity | 11.4% |
| CrowdStrike Falcon | 14.0% |
| Microsoft Entra ID Protection | 7.1% |
| Other | 67.5% |

| Company Size | Count |
|---|---|
| Small Business | 55 |
| Midsize Enterprise | 4 |
| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 4 |
| Large Enterprise | 14 |
Huntress Managed EDR provides round-the-clock threat detection, incident response, and remediation services. It offers a cost-effective security solution tailored for small to medium businesses, integrating seamlessly with Microsoft Defender to bolster cybersecurity without needing extensive security personnel.
Huntress Managed EDR specializes in comprehensive threat-hunting and proactive defense, designed to operate alongside existing antivirus tools like Microsoft Defender. It delivers continuous monitoring and advanced threat detection to protect endpoints from threats beyond traditional antivirus capabilities. The platform features a user-oriented interface enabling efficient endpoint management and security. While valued for its 24/7 security operations and threat response, Huntress faces certain challenges such as enhancing reporting capabilities, expanding integration with third-party systems, and advancing its XDR functionalities. Users seek improved API capabilities, streamlined report generation, and broader Macintosh support to elevate their experience with the tool.
What are the key features?Industries leverage Huntress Managed EDR to enhance security frameworks and integrate with existing security measures, like Microsoft Defender. Its deployment spans financial, healthcare, and SMB sectors, where the need for robust endpoint protection and threat-hunting capabilities is paramount. Organizations benefit from its flexible deployment options, adapting Huntress to their specific cybersecurity strategies.
Microsoft Defender for Identity offers real-time threat detection and protection for hybrid Active Directory environments. It integrates with Microsoft 365 components for seamless security and monitors advanced behaviors, enhancing identity protection across cloud and on-premises environments.
Microsoft Defender for Identity provides detailed threat insights and user behavior analytics to detect unauthorized access and notify anomalies. It allows setting custom detection rules, enhancing threat response automation. While it needs improvements in cloud security, SIEM integration, and access controls, users leverage its ability to mitigate identity threats like suspicious logins and ransomware. Enhanced integration with Microsoft security products ensures a coordinated threat response for identity control and privilege management.
What are the key features of Microsoft Defender for Identity?In specific industries, organizations implement Microsoft Defender for Identity to secure on-premises and hybrid Active Directory environments through user and entity behavior analytics, malicious activity detection, and integration with Microsoft security tools. This approach enhances security posture assessment and helps mitigate identity threats like identity harvesting and unauthorized access.
We monitor all Managed Detection and Response (MDR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.