No more typing reviews! Try our Samantha, our new voice AI agent.

Kandji vs Morphisec comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Detection and Response (EDR)
5th
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
118
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Extended Detection and Response (XDR) (3rd), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
Kandji
Ranking in Endpoint Detection and Response (EDR)
12th
Average Rating
8.8
Reviews Sentiment
6.4
Number of Reviews
20
Ranking in other categories
Vulnerability Management (20th), Mobile Device Management (MDM) (3rd), Enterprise Mobility Management (EMM) (3rd)
Morphisec
Ranking in Endpoint Detection and Response (EDR)
60th
Average Rating
9.2
Reviews Sentiment
7.4
Number of Reviews
21
Ranking in other categories
Vulnerability Management (56th), Endpoint Protection Platform (EPP) (44th), Advanced Threat Protection (ATP) (29th), Cloud Workload Protection Platforms (CWPP) (34th), Threat Deception Platforms (13th)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
CD
SysAdmin at a recreational facilities/services company with 11-50 employees
Strong security structure has supported fast Mac and iOS administration with minimal IT effort
One area for improvement for Kandji would be having a bigger suite of applications. I noticed that some of the niche apps our data software firm needs were not in the regular library. We were able to use the custom app feature to create those apps ourselves, but I would love it if Kandji could expand the library. I also wish Kandji could lock down different ports on MacBooks based on which ones we wanted to shut down, and I hope there is an easier way to sandbox people's bring your own device devices because when we're doing SOC 2, it really wants us to sandbox things so that if someone were to take a device that is not ours, we could delete just our data off there and not theirs. An improvement needed for Kandji would be the ability to remote into devices. I would appreciate something that is really reliable for that without having to buy third-party software.
Rick Schibler - PeerSpot reviewer
VP of Information Technology at Kentucky Trailer
Offers in-memory protection at a lower price than competitors
Morphisec's in-memory protection is probably the most valuable feature because it stops malicious activity from occurring. If something tries to install or act as a sleeper agent, Morphisec will detect and stop it. Morphisec's Moving Target Defense is critical to hardening our attack surface. If it detects something, it indicates whether it's valid. That means you've got a breach requiring investigation. It detects anomalies but doesn't necessarily point to what caused them. You still need to do that work. The solution is reasonably easy to administer. They made some changes last year, adding a cloud-based monitoring solution that makes deploying and monitoring our endpoints easy.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Cortex XDR by Palo Alto Networks has accelerated the response time for my security team, so we have been able to resolve issues faster than usual."
"The best feature of Cortex XDR by Palo Alto Networks is that it collects logs from different sections such as the endpoint, the network, and the cloud, making it easy to investigate alerts, collect some of the investigation packages related to the infected machines, and provide live response."
"Stability is one of the features we like the most."
"If you are looking for security, mainly for advanced threat prevention from ransomware and malware attacks, I would recommend Cortex."
"The most valuable feature of Cortex XDR by Palo Alto Networks is its machine-learning capabilities. Additionally, there is full integration with other solutions."
"The initial setup is pretty easy."
"Automation and playbooks have helped me significantly, as Cortex Xnor's playbooks predefine the workflow of the automation, such as response processes, alert triggering, and enriching the context, efficiently detecting and blocking malicious attacks with firewalls while eliminating workload and speeding responses for next-generation operations."
"Cortex is a very good total solution on the endpoints."
"I highly recommend Kandji to others looking into using it since I have not seen any game-breaking issues; it is highly reliable, scalable, improves security, and reduces the time individuals need to spend on system configuration for security updates."
"Kandji has positively impacted my organization by simplifying the management of the Apple fleet."
"Kandji has positively impacted my organization by allowing us to better assist and it allows for a better user experience, a better kind of fleet management."
"I have seen a return on investment with Kandji, as I save time."
"The customer support is the best I have ever seen."
"Kandji has positively impacted my organization because it was very easy to implement and manage all of our devices, especially when we manage with the ISO and SOC 2 certifications that we need for our organization."
"Kandji has positively impacted my organization because it is very user-friendly, and among the multiple MDM solutions I have used, such as JumpCloud and Intune, Kandji stands out as one of the best for Mac devices."
"After deploying Kandji, I see a return on investment because the IT workload is reduced due to automated and faster employee onboarding, and we also have fewer support tickets because we do not have to manually install the software as employees can use Kandji Self Service and install the software on their own."
"Morphisec makes it super easy for our IT team to prevent breaches of critical systems; it is a one-click install, then it takes care of the rest."
"Morphisec makes it very easy for IT teams of any size to prevent breaches of critical systems because of the design of their tool. When we evaluated Morphisec, the CIO and I sat and listened. What attracted us to them is the fact that it stops activity at the point of detection. That saves a lot of time because now we are not investigating and trying to trace down what to turn off. We have already prevented it, which makes it very much safer and more secure."
"Morphisec is quite an important tool for us in terms of security and InfoSec because of the malware protection."
"Morphisec has absolutely helped save money on our security stack. The ransomware at the end of the day can cost organizations millions upon millions of dollars. Investing in tools like Morphisec is a great reduction in that cost. If I can spend $10,000 in a year to protect assets that could be ransomed for $20,000,000, that's definitely a bet that one should pursue. Morphisec absolutely it's worth the investment."
"Morphisec stops attacks without needing to know what type of threat it is, just that it is foreign. It is based on injections, so it would know when a software launches. If a software launches and something else also launches, then it would count that as anomalous and block it. Because the software looks at the code, and if it executes something else that is not related, then Morphisec would block it. That is how it works."
"With Morphisec, at least when it does happen, I feel confident that we have in place solutions that will not only prevent it, but also let us know when something has happened."
"Morphisec gives me even more than Microsoft can give me, even if I were to pay."
"Morphisec makes it very easy for IT teams of any size to prevent breaches of critical systems because of the design of their tool."
 

Cons

"While using Cortex, I noticed some aspects that could be improved, such as increasing the synchronization speed between XDR and Xnor."
"The solution should enhance the ADR and reporting."
"I would like to see some additional features related to email protection included."
"I feel that it should not be a licensed activity because a feature should allow us to see applications running on end devices."
"I have run into some detection issues with Cortex XDR. It needs to be better at detection of internal attacks."
"There are some third-party solutions that are difficult to integrate with, which is something that can be improved."
"The price could be a little lower."
"The GUI could be improved."
"Kandji should give open customization."
"There are certain limitations with blueprints where each machine can only have one or must have a blueprint, which is frustrating since certain machines may not need to have a blueprint straight away for testing."
"One thing I think could be improved is what happens when a user gets locked out."
"I think Kandji could be improved with a better UI."
"One thing I have noticed is that Kandji is mainly for Mac devices."
"Kandji can definitely be improved by the complexity. I feel we cannot necessarily tweak the Blueprints in the ways that we need to or there are just complex one-off situations where we need more customization and more ability to run custom scripts."
"I believe Kandji can be improved by having more self-service options, as users can complete a few steps before reaching out to IT support, which will give us more context on the issue."
"The Windows part needs a lot of work."
"If anything, tech support might be their weakest link."
"The only area that really needs improvement is the reporting functionality."
"We have discovered some bugs in the new releases that they've had to fix, so I would like to see more testing and QA on their side before they release."
"Those are some of the features that I was looking for on my on-prem platform that they've already instituted in the cloud and that I'm sure will be instituting on their on-prem platform as well. Having to have an on-prem server required a lot of administration. Being able to push that to the cloud and have it managed up there for us is a real nice addition."
"It would be useful for them if they had some kind of network discovery."
"Having to have an on-prem server required a lot of administration."
"I haven't been able to get the cloud deployment to work."
"Sometimes it generates false positive alerts. They need to continue working on that. They have provided solutions for it and have fixed issues with updated versions. The service is quite good but they need to work on it more so that there are no false positive alerts."
 

Pricing and Cost Advice

"The tool's price is moderate."
"Its pricing is kind of in line with its competitors and everybody else out there."
"The solution is expensive. It's pricing is on a yearly-basis."
"The price is on the higher side, but it's okay."
"It has reasonable pricing for the use cases it provides to the company."
"It is present, but when compared to other competitive products, I would say it is not less expensive; however, when all of the other added values are considered, the price is reasonable."
"Every customer has to pay for a license because it doesn't work with what you get from a managed services provider."
"The price of the solution could be reduced. I have customers that have voiced that the solution is good for the value but if I want to sell more of the solution the price reduction would help."
"Users have to pay a yearly licensing fee for Kandji, which is expensive."
"It does not have multi-tenants. If South Africa wants to show only the machines that they have, they need their own cloud incidence. It is not possible to have that in a single cloud incidence with multiple tenants in it, instead you need to have multiple cloud incidences. Then, if you have that, it will be more expensive. However, they are going to change that, which is good."
"Compared to their competitors, the price of Morphisec is not that high. You can easily deploy it on a large-scale or small-scale network."
"Morphisec is reasonably priced because our parent company's other subsidiaries use different products like CrowdStrike. CrowdStrike is four or five times more expensive than Morphisec. The competitive pricing saves us money in our overall security stack."
"The pricing is definitely fair for what it does."
"Our licensing is tied into our contract. Because we have a long-term contract, our pricing is a little bit lower. It is per year, so we don't get charged per endpoint, but we do have a cap. Our cap is 80 endpoints. If we were to go over 80, when we renewed our contract, which is not until three years are over. Then, they would reevaluate, and say, "Well, you have more than 80 devices active right now. This is going to be the price change." They know that we are installing and replacing computers, so the numbers will be all over the place depending on whether you archive or don't archive, which is the reason why we just have to keep up on that stuff."
"It is a little bit more expensive than other security products that we use, but it does provide us good protection. So, it is a trade-off."
"Price-wise, it's on the higher side. A traditional antivirus solution is cheaper, but in terms of security and manageability, its ROI is better than a traditional antivirus. I would recommend it to anybody evaluating or considering an antivirus solution. If your system gets compromised, the cost of ransom would be a lot more. This way, it saves a lot of cost."
"Licenses are per endpoint, and that's true for the cloud version as well. The only difference is that there is a little extra charge for the cloud version."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
915,341 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Manufacturing Company
10%
Comms Service Provider
14%
Outsourcing Company
12%
Financial Services Firm
10%
Construction Company
7%
Outsourcing Company
15%
Manufacturing Company
13%
Construction Company
13%
Comms Service Provider
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise55
By reviewers
Company SizeCount
Small Business6
Midsize Enterprise5
Large Enterprise7
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise8
Large Enterprise8
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What is your experience regarding pricing and costs for Kandji?
My experience with pricing, setup cost, and licensing is that we are using nearly 100 machines in Kandji, which comes...
What needs improvement with Kandji?
One thing I have noticed is that Kandji is mainly for Mac devices. We cannot manage Windows devices on Kandji. This i...
What is your primary use case for Kandji?
Kandji, which is now called Hero, is used for mobile device management. We use it to manage Mac devices, Apple device...
Ask a question
Earn 20 points
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
No data available
Morphisec, Morphisec Moving Target Defense
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Information Not Available
Lenovo/Motorola, TruGreen, Covenant Health, Citizens Medical Center
Find out what your peers are saying about Kandji vs. Morphisec and other solutions. Updated: September 2026.
915,341 professionals have used our research since 2012.