Microsoft Defender for Cloud Apps and SentinelOne Singularity Identity are key players in cloud security solutions. Microsoft Defender appears to have an upper hand in integration with Microsoft ecosystems, while SentinelOne is noted for its AI capabilities and user-friendly interface.
Features: Microsoft Defender for Cloud Apps offers comprehensive visibility, robust integration with Microsoft products, and advanced threat detection and alert systems. SentinelOne Singularity Identity provides behavioral-based threat detection, deep network visibility, and a user-friendly management console.
Room for Improvement: Microsoft Defender users seek enhanced third-party integration, faster response times for sensitive data, and improved macOS compatibility. SentinelOne could improve endpoint management, extend visibility, and reduce server strain from agents.
Ease of Deployment and Customer Service: Microsoft Defender offers hybrid and public cloud deployment, though customer service experiences vary, with some reporting delays. SentinelOne is flexible for public and on-premises deployments and is praised for its knowledgeable support.
Pricing and ROI: Microsoft Defender is competitively priced within Microsoft ecosystems through bundling in E3 and E5 licenses, delivering ROI via security improvements and downtime reduction. SentinelOne is cost-effective for the features provided, but users note annual pricing increases. Both solutions offer tangible ROI, with Microsoft's bundled approach potentially offering more comprehensive value.
As a small team, Microsoft Defender for Cloud Apps allowed us to manage systems with just one or two people.
The biggest return on investment so far has been visibility, knowing what we have in our environment.
Their customer service is pretty good, but it's frustrating to go through three or four channels before reaching the right person.
The support is excellent, and the speed of response is commendable.
There were instances where the engineers were knowledgeable and helpful, but at other times it felt like a ping pong game, with unnecessary transfers until the right person was found.
They have been responsive to our needs as integrators and those of the client.
Microsoft Defender for Cloud Apps is very scalable, provided you have the right subscription.
The scalability may require additional resources for larger business operations.
For what I know about the log collector and how much data it can take in, it is super scalable and capable of handling high workloads.
I would rate it a ten because I have not experienced any stability issues so far with Defender for Cloud Apps.
The current stability of Microsoft Defender for Cloud Apps is quite good.
Like any other Microsoft product, the uptime is good.
For data loss prevention, it would be useful to be able to drill down into the kind of data being transferred over CloudApp.
A significant improvement I would like to see is the integration into a single pane of glass.
Specifically, integration with CASB for on-premise and cloud did not work as anticipated back in 2019.
There is a clear roadmap for improvements, including enhancing capabilities with AI and seamless functionality in an MSP model for deeper visibility across multiple agencies.
It's not the cheapest, but also not the most expensive, placing it in the mid-level range.
If a product is of high quality, it justifies the expense.
My organization is currently revisiting pricing, but previously, the cost was a bit expensive, yet comparable to other solutions with similar functionalities and features.
The integration within the entire Defender suite is highly valuable because it allows for communication between different components and offers pretty decent correlations.
Microsoft Defender for Cloud Apps is very comprehensive, providing a complete 360-degree view of applications within an organization.
The most valuable features of Microsoft Defender for Cloud Apps include live, up-to-date information, which provided real-time alerts.
With visibility into endpoint telemetry, SentinelOne does provide useful information to find threat actors and empowers those who are in the business of threat hunting.
Microsoft Defender for Cloud Apps is a comprehensive security solution that provides protection for cloud-based applications and services. It offers real-time threat detection and response, as well as advanced analytics and reporting capabilities. With Defender for Cloud Apps, organizations can ensure the security of their cloud environments and safeguard against cyber threats. Whether you're running SaaS applications, IaaS workloads, or PaaS services, Microsoft Defender for Cloud Apps can help you secure your cloud environment and protect your business from cyber threats.
Reviews from Real Users
Ram-Krish, Cloud Security & Governance at a financial services firm, says that Microsoft Defender for Cloud Apps "Integrates well and helps us in protecting sensitive information, but takes time to scan and apply the policies and cannot detect everything we need".
PeerSpot user, Senior Cloud & Security Consultant at a tech services, writes that Microsoft Defender for Cloud Apps "Great for monitoring user activity and protecting data while integrating well with other applications".
Simon Burgess,Infrastructure Engineer at SBITSC, states that Microsoft Defender for Cloud Apps is "A fluid, intelligent product for great visibility, centralized management, and increased uptime".
Singularity Identity, a component of the Singularity platform, provides threat detection & response (ITDR) capabilities to defend Active Directory and domain-joined endpoints in real-time from adversaries aiming to gain persistent, elevated privilege and move covertly. Singularity Identity provides actionable, high-fidelity insight as attacks emerge from managed and unmanaged devices. It detects identity misuse and reconnaissance activity happening within endpoint processes targeting critical domain servers, service accounts, local credentials, local data, network data, and cloud data. On-agent cloaking and deception techniques slow the adversary down while providing situational awareness and halting adversarial attempts at lateral movement. Singularity Identity helps you detect and respond to identity-based attacks, providing early warning while misdirecting them away from production assets.
Singularity Identity’s primary use case is to protect credential data and disrupt identity-based attacks. The most valuable function of Singularity Identity is its ability to misdirect attackers by providing deceptive data to identity-based recon attacks. Additionally, it can hide and deny access to locally stored credentials or identity data on Active Directory domain controllers.
Singularity Identity also provides rapid detection and respond to identity attacks, capturing attack activity and feeding it directly to the Singularity platform’s Security DataLake for enterprise-wide analysis and response.
By implementing Singularity Identity, organizations benefit from enhanced security, reduced credential-related risks, and improved user productivity. It detects and responds to identity-based attacks, ensuring only authorized individuals can access critical identity data. With its cloaking capabilities to hide identity stored locally on endpoints or in the identity infrastructure and it’s ability to provide decoy results to identity-based attacks, organizations can effectively secure their sensitive or privileged identities, resulting in improved overall identity security.
We monitor all Advanced Threat Protection (ATP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.