Microsoft Defender for Identity vs Microsoft Purview Compliance Manager comparison

 

Comparison Buyer's Guide

Executive Summary
 

Categories and Ranking

Microsoft Defender for Iden...
Ranking in Microsoft Security Suite
8th
Average Rating
9.0
Number of Reviews
13
Ranking in other categories
Advanced Threat Protection (ATP) (6th), Identity Threat Detection and Response (ITDR) (1st)
Microsoft Purview Complianc...
Ranking in Microsoft Security Suite
21st
Average Rating
9.4
Number of Reviews
3
Ranking in other categories
Data Governance (11th)
 

Mindshare comparison

As of July 2024, in the Microsoft Security Suite category, the mindshare of Microsoft Defender for Identity is 5.5%, up from 3.3% compared to the previous year. The mindshare of Microsoft Purview Compliance Manager is 1.6%, up from 1.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Microsoft Security Suite
Unique Categories:
Advanced Threat Protection (ATP)
8.8%
Identity Threat Detection and Response (ITDR)
27.7%
Data Governance
2.5%
 

Featured Reviews

Iñaki Martinez Urricelqui - PeerSpot reviewer
Apr 17, 2023
Without some of the alerts we get, it would be very difficult to know what is happening
It gives us control over all our users and everything they are working on. Defender for Identity is good to have because there are some types of alerts that, without them, it would be very difficult to know what is happening. All the integration it has with different Microsoft packages, like Teams and Office, is good. When there are potentially risky users, the solution automatically blocks them. That helps prevent security incidents, and it's also good because we don't have to block them manually. It also helps us be prepared for threats before they hit. And it has decreased our time to respond because the analytics make it easier.
Sachin Vinay - PeerSpot reviewer
Dec 2, 2022
Really good encryption mechanism prevents man-in-the-middle and other types of attacks
It helps you configure the system and even offers ideas on how to resolve important security concerns in an organization. It lists out all the issues that happen when we move data from the cloud to on-premises. It gives you a detailed view of the known issues and helps with industry standards so that the cloud features completely align with on-premises. We can see whether our data security is matching the industry standards. It even offers prompts and ideas on items that you may not even have been aware of. It provides us with ideas on how to improve our proficiency in handling data in the cloud. And you can add notes for others in the reporting feature, so if there are any issues, others can refer to them. The fact that Purview delivers data protection across multi-cloud and multi-platform environments is also important to us. We have most of our data on Microsoft but part of our data, our university websites, for example, is on Amazon AWS. We move data between clouds and also from on-premises to the cloud. There is no other mechanism to check if this data is moving according to industry standards for such things as * security * bandwidth * SSL encryption mechanism. We would not be able to see these metrics without Microsoft Purview Compliance Manager. It gives you a dashboard on how to improve your setup on the Microsoft cloud or even AWS. And it gives us the same information if we push data from on-premises to cloud. Also, our users have a mix of operating systems. Most use Windows but there are also people who use macOS and Linux. With Purview, we can easily find the issues in Linux or more complex operating systems like macOS. We are notified of all issues with the help of Purview Compliance Manager.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"This solution has advanced a lot over the last few years."
"It is easy to set up. Based on the number of devices you would like to set up, you can use scripts, Group Policy, etc. It takes five minutes to set up."
"Microsoft Defender for Identity provides excellent visibility into threats by leveraging real-time analytics and data intelligence."
"The best feature is security monitoring, which detects and investigates suspicious user activities. It can easily detect advanced attacks based on the behavior. The credentials are securely stored, so it reduces the risk of compromise. It will monitor user behavior based on artificial intelligence to protect the identities in your organization. It will even help secure the on-premise Active Directory. It syncs from the cloud to on-premise, and on-premise modifications will be reflected in the cloud."
"The most valuable aspect is its connection to Microsoft Sentinel and Defender for Endpoint, and giving exact timelines for incidents and when certain events occured during an incident."
"Defender for Identity has not affected the end-user experience."
"The solution offers excellent visibility into threats."
"The basic security monitoring at its core feature is the most valuable aspect. But also the investigative parts, the historical logging of events over the network are extremely interesting because it gives an in-depth insight into the history of account activity that is really easy to read, easy to follow, and easy to export."
"Purview delivers data protection across multi-cloud and multi-platform environments."
"We have more visibility of data and how it is being shared."
"We move data between clouds and also from on-premises to the cloud. There is no other mechanism to check if this data is moving according to industry standards for such things as security, bandwidth, and SSL encryption mechanism. We would not be able to see these metrics without Microsoft Purview Compliance Manager."
 

Cons

"I would like to be able to do remediation from the platform because it is just a scanner right now. If you onboard a device, it shows you what is happening, but you can't use it to fix things. You need to go into the system to fix it instead."
"The technical support needs significant improvement. Documentation for more minor issues in the form of guides or walkthroughs could help to resolve this issue. The number of tickets raised would decrease, removing some pressure from the support team and making it easier to clear the remaining tickets."
"An area for improvement is the administrative interface. It's basic compared to other administrative centers. They could make it more user-friendly and easier to navigate."
"When the data leaves the cloud, there are security issues."
"The impact of the sensors on the domain controllers can be quite high depending on your loads. I don't know if there's any room for improvement there, but that's one of the things that might be improved."
"The solution could be better at using group-managed access and they could replace it with broad-based access controls."
"Microsoft should look at what competing vendors like CrowdStrike and Broadcom are doing and incorporate those features into Sentinel and Defender. At the same time, I think the intelligence inside the product is improving fast. They should incorporate more zero-trust and hybrid trust approaches. They need to build up threat intelligence based on threats and methods used in attacks on other companies."
"We observe a lot of false positives. Sometimes, when we go for a coffee break, we lock our screens. Locking the screen has a separate Windows event ID and sometimes I see it is detected as a failed login."
"One area for improvement is the technical support for Purview. With all the other solutions from Microsoft we get really good technical support, but with Purview we had a compliance error and we couldn't find the solution. Purview would not point us to the correct solution, it just indicated the error. We had to troubleshoot it and find out what led to this error. We contacted technical support but it took them one week to identify the root cause of the error."
"We've had issues with data connectors for Teams."
"We'd like to see the solution expanded to include firewalls and endpoints."
 

Pricing and Cost Advice

"It is very affordable considering that other SIEM solutions are much more expensive and have many more licensing restrictions and fees."
"The product is costly, and we had multiple discussions with accounting to receive a discounted rate. However, on the open market, the tool is expensive."
"You won't be able to change your tenants from where you deploy them. For example, if you select Canada, they will charge you based on Canadian pricing. If you are also in London, when you deploy in Canada, the pound is higher than Canadian dollars, but your platform resources are billable in Canadian dollars. Using your pounds to pay for any of these things will be cheaper. Or, if you deploy in London, they will charge you based on your local currency."
"Defender for Identity is a little more expensive than other Microsoft products. Identity and Microsoft Defender for Cloud are both a bit costly."
"The pricing and licensing are moderate because we have other licenses for Microsoft services. The pricing is in line with that."
report
Use our free recommendation engine to learn which Microsoft Security Suite solutions are best for your needs.
793,295 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
14%
Government
9%
Manufacturing Company
7%
Computer Software Company
15%
Financial Services Firm
14%
Government
8%
Manufacturing Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
 

Questions from the Community

What do you like most about Microsoft Defender for Identity?
Microsoft Defender for Identity provides excellent visibility into threats by leveraging real-time analytics and data intelligence.
What needs improvement with Microsoft Defender for Identity?
One potential area for improvement could be exploring flexibility in the installation of Microsoft Defender for Identity agents. Currently, it is mandatory to install the agent on the on-premises e...
What is your primary use case for Microsoft Defender for Identity?
Microsoft Defender for Identity is like a personal security guard for our organization's identity. It keeps a close eye on how we use our identities across both on-premises and Azure Active Directo...
What do you like most about Microsoft Purview Compliance Manager?
We have more visibility of data and how it is being shared.
What is your experience regarding pricing and costs for Microsoft Purview Compliance Manager?
I'm not sure of the exact pricing of the solution. It's cheaper than our previous option. The cost is not much of an issue at the moment.
 

Also Known As

Azure Advanced Threat Protection, Azure ATP, MS Defender for Identity
Microsoft Compliance Manager
 

Overview

 

Sample Customers

Microsoft Defender for Identity is trusted by companies such as St. Luke’s University Health Network, Ansell, and more.
Information Not Available
Find out what your peers are saying about Microsoft Defender for Identity vs. Microsoft Purview Compliance Manager and other solutions. Updated: May 2024.
793,295 professionals have used our research since 2012.