

Red Canary and Microsoft Defender for Identity are competitive cybersecurity products. While Red Canary has an edge in pricing and customer support satisfaction, Microsoft Defender for Identity is preferred for its comprehensive features, appealing to organizations that prioritize functionality over cost.
Features: Red Canary is known for efficient threat detection, real-time alerting, and strong response capabilities. It integrates seamlessly with security infrastructure and provides compliance solutions for industries like banking and healthcare. Microsoft Defender for Identity provides real-time identity protection, advanced identity threat detection using behavioral analytics, and integrates efficiently with Microsoft's tools to give a deep insight into identity-based threats.
Room for Improvement: Red Canary could expand its feature set to compete with more multifunctional suites. Its threat detection is strong, but there is room for enhancing automation and predictive analytics. Microsoft Defender for Identity can improve its ease of deployment, making it more accessible without requiring extensive resources, simplify its integration processes, and enhance its user interface to further improve usability.
Ease of Deployment and Customer Service: Red Canary supports easy deployment with comprehensive integration and responsive customer service. Microsoft Defender for Identity also integrates with the Microsoft suite but might require additional resources for deployment due to its complexity, although Microsoft's customer support is robust in addressing deployment challenges.
Pricing and ROI: Red Canary offers cost-effective pricing models that emphasize ROI with lower entry costs. Microsoft Defender for Identity involves higher setup costs due to its extensive features, but the ROI is justified through its comprehensive identity security offerings, making it valuable for organizations seeking long-term benefits.
Any missed detection will definitely be triggered by Red Canary.
We have probably spent maybe 15% of the time that we were spending on incident investigation and system monitoring, demonstrating a return on investment.
Generally, the support is more effective than other providers like Oracle.
The quality of support is very good, but troubleshooting can take time due to complex setups and the need to provide many logs.
The people I normally use for support are very knowledgeable, especially when they help remote in and get to where I need to go and show me much faster and help me understand what I should be doing.
In emergencies, there is an on-call person available to resolve issues immediately.
Their customer support is excellent.
If I need more details about any incident, there is a contact us option to reach an agent.
In a Microsoft-centric organization, especially with Azure infrastructure and Office 365, Microsoft Defender for Identity is scalable.
We've been able to connect and throw all of the data that we have access to over to their systems to parse, process, and monitor without issue.
Microsoft Defender for Identity is quite robust and built on Azure hyperscale infrastructure, with a 99% availability.
We do not see any issues with the stability of Microsoft Defender for Identity.
Having recently started using it, reliability is affirmed, but manual investigation is often performed to verify if alerts identified by auto-remediation are accurate.
If Microsoft could develop a feature that indicates when impossible travel is caused by VPN connections, it would prevent unnecessary password resets and session disruptions, especially for VIP users in organizations.
One improvement I would recommend is the integration of an admin application within Teams, allowing easy access to attack information on a mobile platform.
Reducing false positives is something we've been working on with Microsoft.
Red Canary can be improved by continuing to add new features and capabilities.
I wish Red Canary could have a graph that shows the endpoint, user, and how it spreads, providing a visual representation to easily identify what happened.
Red Canary's pricing spectrum may not be ideal for smaller financial institutions.
If they can reduce the costs, organizations will be happy, and it will compensate for using the Azure environment, which is more expensive on the infrastructure as a service side.
Ensuring a fair price according to market standards.
From an organization perspective, using E5 licenses is value for money, especially if Azure and Office 365 are already in use.
The services are higher priced.
We receive an advance report of risky users, allowing us to take preemptive action before an attack causes damage to organization details.
The most valuable feature is its hybrid artificial intelligence, which gathers forensic data to track and counteract security threats, much like the CSI series in effect.
The advanced threat protection is one of the strengths of Microsoft Defender for Identity, as it utilizes user and entity analytics and can detect indicative attacks.
Red Canary has impacted my organization positively because we treat any ticket triggered by them as high priority due to the fact that 99 percent of the time it is a true positive.
Red Canary detects threats and attack patterns, allowing us to assess any significant damage caused to the banking environment, particularly if protected data has been damaged or corrupted.
In my experience, the best features Red Canary offers are their team, their monitoring team, their expertise at incident investigation, and a focus on suspicious or actual indicators of compromise to ensure that we're not spending time just reviewing logs, but that we're actually looking at things that may indicate we have broader issues.
| Product | Mindshare (%) |
|---|---|
| Microsoft Defender for Identity | 3.6% |
| Red Canary | 1.9% |
| Other | 94.5% |

| Company Size | Count |
|---|---|
| Small Business | 8 |
| Midsize Enterprise | 5 |
| Large Enterprise | 15 |
| Company Size | Count |
|---|---|
| Small Business | 6 |
| Large Enterprise | 2 |
Microsoft Defender for Identity offers real-time threat detection and protection for hybrid Active Directory environments. It integrates with Microsoft 365 components for seamless security and monitors advanced behaviors, enhancing identity protection across cloud and on-premises environments.
Microsoft Defender for Identity provides detailed threat insights and user behavior analytics to detect unauthorized access and notify anomalies. It allows setting custom detection rules, enhancing threat response automation. While it needs improvements in cloud security, SIEM integration, and access controls, users leverage its ability to mitigate identity threats like suspicious logins and ransomware. Enhanced integration with Microsoft security products ensures a coordinated threat response for identity control and privilege management.
What are the key features of Microsoft Defender for Identity?In specific industries, organizations implement Microsoft Defender for Identity to secure on-premises and hybrid Active Directory environments through user and entity behavior analytics, malicious activity detection, and integration with Microsoft security tools. This approach enhances security posture assessment and helps mitigate identity threats like identity harvesting and unauthorized access.
Red Canary Managed Detection and Response (MDR) offers robust threat detection, rapid response capabilities, continuous security monitoring, and seamless integration with existing tools. Valued for its actionable reporting and proactive threat intelligence, it streamlines operations and enhances organizational efficiency and security.
We monitor all Advanced Threat Protection (ATP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.