Try our new research platform with insights from 80,000+ expert users

Microsoft Defender for Identity vs NetMon comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Microsoft Defender for Iden...
Ranking in Identity Threat Detection and Response (ITDR)
3rd
Average Rating
8.8
Reviews Sentiment
7.0
Number of Reviews
25
Ranking in other categories
Advanced Threat Protection (ATP) (6th), Microsoft Security Suite (3rd)
NetMon
Ranking in Identity Threat Detection and Response (ITDR)
14th
Average Rating
7.6
Reviews Sentiment
7.7
Number of Reviews
11
Ranking in other categories
Network Monitoring Software (58th)
 

Mindshare comparison

As of August 2025, in the Identity Threat Detection and Response (ITDR) category, the mindshare of Microsoft Defender for Identity is 15.9%, down from 24.5% compared to the previous year. The mindshare of NetMon is 0.0%. It is calculated based on PeerSpot user engagement data.
Identity Threat Detection and Response (ITDR)
 

Featured Reviews

ROBERT-CHRISTIAN - PeerSpot reviewer
Integration within the ecosystem enhances collaboration and automates functionalities
The integration into the Microsoft Defender ecosystem is the most valuable feature of Microsoft Defender for Identity. It fits very nicely with all the other Defender tools, allowing for excellent collaboration among them. It also fits seamlessly into Microsoft Sentinel SIEM. Furthermore, Microsoft security solutions can save time as they allow the automation of numerous functionalities, and the reporting inside the Microsoft ecosystem is commendable.
AshishDubey - PeerSpot reviewer
A stable and scalable tool useful for network behavior analysis, DPA, and network forensic services
I have not worked much on LogRhythm NetMon to be able to comment on what needs improvement in the product since there is another team in our company that is working on the solution presently. LogRhythm NetMon's pricing model is an area of concern that should be made a little bit cheaper in comparison to the other players in the market currently. With players like IBM QRadar that propose QNI or Darktrace in the market, LogRhythm NetMon needs to consider a reduction in its pricing model.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"It automates routine testing and helps automate the finding of high-value alerts."
"The advanced threat protection is one of the strengths of Microsoft Defender for Identity, as it utilizes user and entity analytics and can detect indicative attacks."
"The best feature is security monitoring, which detects and investigates suspicious user activities. It can easily detect advanced attacks based on the behavior. The credentials are securely stored, so it reduces the risk of compromise. It will monitor user behavior based on artificial intelligence to protect the identities in your organization. It will even help secure the on-premise Active Directory. It syncs from the cloud to on-premise, and on-premise modifications will be reflected in the cloud."
"The basic security monitoring at its core feature is the most valuable aspect. But also the investigative parts, the historical logging of events over the network are extremely interesting because it gives an in-depth insight into the history of account activity that is really easy to read, easy to follow, and easy to export."
"The most valuable feature is its hybrid artificial intelligence, which gathers forensic data to track and counteract security threats, much like the CSI series in effect."
"Auto-remediation is a valuable feature applied to Microsoft Defender for Identity, reducing the burden of investigating false positives."
"I would rate Microsoft Defender for Identity at nine out of ten."
"The integration into the Microsoft Defender ecosystem is the most valuable feature of Microsoft Defender for Identity."
"Visibility is a valuable feature, the ability to see even if the traffic is not going into the firewall"
"The initial setup is straightforward because we can deploy an open server."
"The analytics feature is the most valuable feature."
"LogRhythm NetMon's most impressive feature is that it's a bundled package, so you're not just relying on monthly data; you get a six-month view for more comprehensive indicators of compromise. This dual approach is precious. We implement LogRhythm NetMon in our cybersecurity strategy mainly for compliance and correlation of network, user, and decision activities, particularly for network firewalls and access control."
"It is a stable solution...It is a scalable solution."
"NetMon's best feature is traffic analysis."
"The most valuable feature is the log, which can be analyzed by our SIEM solution."
"The protocols with which you see the traffic for a particular website that a client has in their environment, for example, are valuable. We can monitor whether the traffic is up to the mark or whether they need to add more bandwidth. Also, we can see if we're able to get real-time environment data as well. The customization dashboard is really good. LogRhythm NetMon has its own in-built dashboards which are helpful in guiding customization."
 

Cons

"The areas of Microsoft Defender for Identity that can be improved include its cost, which is quite expensive when integrated into Sentinel. Additionally, there is room for improvement in its integration with non-Microsoft applications and systems."
"I would like to be able to do remediation from the platform because it is just a scanner right now. If you onboard a device, it shows you what is happening, but you can't use it to fix things. You need to go into the system to fix it instead."
"There is no option to remedy an issue directly from the console. If we see an alert, we can't fix it from the console. Instead, we must depend on other Microsoft products, such as MDE. That is a significant drawback. It simply works as a scanner, which can sometimes put enough load on the sensors. Immediate actions should be possible from the dashboard because. It can prevent issues from spreading further."
"The solution could be better at using group-managed access and they could replace it with broad-based access controls."
"The tracking instance needs to be configured appropriately."
"The solution could improve how it handles on-premises Android-related attacks."
"Defender for Identity gives us visibility, but we often get false positives from Azure that take us down the garden path. We go through 30 incidents each day and most of those are false positives or benign positive alerts. Occasionally, we get true positive alerts."
"Microsoft should look at what competing vendors like CrowdStrike and Broadcom are doing and incorporate those features into Sentinel and Defender. At the same time, I think the intelligence inside the product is improving fast. They should incorporate more zero-trust and hybrid trust approaches. They need to build up threat intelligence based on threats and methods used in attacks on other companies."
"Sometimes it's hard to find the network devices' self-audit logs."
"Could use a topology diagram which would help get an exact visual."
"LogRhythm NetMon's pricing model is an area of concern that should be made a little bit cheaper in comparison to the other players in the market currently."
"Some of the automated tasks we can perform on QRadar cannot be performed on LogRhythm because the solution has limitations."
"The platform's integration features often need to be improved."
"The training for this product is not very good and needs to be improved."
"There is an issue with tunneling in relation to how the connectivity is established between the end devices and where NetMon is installed. On the console, I often observe that there's a difference of a few seconds or maybe a minute, and this lag time should not be there."
"I would like to see better integration with multiple products. Integration is not something that is readily available for most of the products."
 

Pricing and Cost Advice

"Defender for Identity is a little more expensive than other Microsoft products. Identity and Microsoft Defender for Cloud are both a bit costly."
"It is very affordable considering that other SIEM solutions are much more expensive and have many more licensing restrictions and fees."
"The product is costly, and we had multiple discussions with accounting to receive a discounted rate. However, on the open market, the tool is expensive."
"Microsoft Defender for Identity comes as part of the Microsoft E5 licensing stack."
"You won't be able to change your tenants from where you deploy them. For example, if you select Canada, they will charge you based on Canadian pricing. If you are also in London, when you deploy in Canada, the pound is higher than Canadian dollars, but your platform resources are billable in Canadian dollars. Using your pounds to pay for any of these things will be cheaper. Or, if you deploy in London, they will charge you based on your local currency."
"The product is expensive for smaller companies."
"The price of this solution is too high, so it should be made more practical and more valuable for the customer."
"Pricing is okay. There were some competitors that were extremely expensive and there were some which were really inexpensive but LogRhythm stayed in the middle of them."
"I don't have visibility into the pricing of LogRhythm NetMon as it's handled through our commercial partnerships."
"NetMon's licensing costs about $85k per year, with some extra costs for support."
"LogRhythm's licensing part is something that depends on the license you want since they offer it on a perpetual and subscription basis."
report
Use our free recommendation engine to learn which Identity Threat Detection and Response (ITDR) solutions are best for your needs.
865,384 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
15%
Financial Services Firm
13%
Government
7%
Manufacturing Company
7%
No data available
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Microsoft Defender for Identity?
Microsoft Defender for Identity provides excellent visibility into threats by leveraging real-time analytics and data intelligence.
What needs improvement with Microsoft Defender for Identity?
Microsoft can improve Microsoft Defender for Identity by ensuring that installation prerequisites are included in the setup process. Installing the solution presents challenges as numerous logs and...
What is your primary use case for Microsoft Defender for Identity?
My personal use case for Microsoft Defender for Identity is that it is amazing. It provides very good and deep analytics about whatever is happening in the on-premises Active Directory. The sensors...
What do you like most about LogRhythm NetMon?
It has a very strong artificial intelligence engine.
What is your experience regarding pricing and costs for LogRhythm NetMon?
I don't have visibility into the pricing of LogRhythm NetMon as it's handled through our commercial partnerships.
What needs improvement with LogRhythm NetMon?
The main concern is that LogRhythm has not improved NetMon but instead introduced a separate product, which many customers, including us, would prefer to be integrated into a single platform for ea...
 

Also Known As

Azure Advanced Threat Protection, Azure ATP, MS Defender for Identity
LogRhythm Network Monitor
 

Overview

 

Sample Customers

Microsoft Defender for Identity is trusted by companies such as St. Luke’s University Health Network, Ansell, and more.
Sera-Brynn
Find out what your peers are saying about Microsoft Defender for Identity vs. NetMon and other solutions. Updated: July 2025.
865,384 professionals have used our research since 2012.