Try our new research platform with insights from 80,000+ expert users

Microsoft Defender Threat Intelligence vs Palo Alto Networks AutoFocus comparison

 

Comparison Buyer's Guide

Executive SummaryUpdated on Aug 11, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Microsoft Defender Threat I...
Ranking in Threat Intelligence Platforms
4th
Average Rating
8.4
Reviews Sentiment
7.4
Number of Reviews
32
Ranking in other categories
Advanced Threat Protection (ATP) (10th), Microsoft Security Suite (15th)
Palo Alto Networks AutoFocus
Ranking in Threat Intelligence Platforms
27th
Average Rating
7.8
Reviews Sentiment
7.7
Number of Reviews
6
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of July 2025, in the Threat Intelligence Platforms category, the mindshare of Microsoft Defender Threat Intelligence is 2.8%, up from 1.9% compared to the previous year. The mindshare of Palo Alto Networks AutoFocus is 1.2%, down from 1.6% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Threat Intelligence Platforms
 

Featured Reviews

TapabrataSamanta - PeerSpot reviewer
A cost-effective solution for monitoring and security but lacks supports for non-Microsoft products
There are weaknesses, and Microsoft is working on addressing them. Over the past three to four years, the ATP and other components have improved significantly, and the integration has also advanced. We are using third-party services. While we have Microsoft Threat Intelligence, which leverages Microsoft's facilities, we also utilize additional third-party threat intelligence. As of today, we don't completely rely on Microsoft for certain regions. This is an area where Microsoft needs to improve. Consequently, we use Anomali, a third-party threat intelligence provider. We integrate our product's intelligence with Anomali, from which we obtain threat insights. Microsoft products offer significant advantages, especially in the realm of threat intelligence. It works very well with Microsoft products. However, you might need additional services if you have non-Microsoft products in your environment. For instance, if you use Apple or Linux, Microsoft's solutions alone might not be sufficient. If they can work more effectively, especially with zero-day attack speed and other sophisticated threats, it will help us provide our customers with timely newsletters about new attacks.
RichPhillips - PeerSpot reviewer
Offers a centralized dashboard for reporting threats and anomalies
The tool along with other suite of products provides us with threat and alert information.  The solution has provided us with a centralized dashboard for reporting threats and anomalies.  I am impressed with the tool's integration of Palo Alto products which serves as a platform for security.  I…

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable feature of the solution stems from the insight it provides."
"They have a very transparent roadmap for the product."
"The product is useful when the end user downloads malware files."
"The technical support services are excellent."
"It helps to monitor by providing the best 24/7 monitoring integrated with Sentinel and IBM systems."
"One of the best features is that it provides a certain level of customization, allowing us to set our spam confidence levels."
"Microsoft's integration into the security stack works quite well."
"You can use it to monitor third parties and ensure they are not under threat attacks. It is beneficial in the GRC model."
"I would rate Palo Alto Networks AutoFocus a ten out of ten."
"It integrates well with other solutions and provides good threat intelligence in terms of external threats."
"The logs play a crucial role as they contribute to blocking unwanted Internet traffic."
"The most valuable feature is alerting."
"I am impressed with the tool's integration of Palo Alto products which serves as a platform for security."
"The feature that I like best is the dashboard."
 

Cons

"The software is expensive."
"It takes time for the support team to understand the issue, and they then respond with a delay at times, which causes a lot of trouble."
"The solution could be more stable and precise because, at times, the threats detected are not legitimate."
"I would like to see more AI features and capabilities."
"Microsoft Defender Threat Intelligence is evolving and needs to fix and enhance numerous issues like stability and licensing. The continuous rebranding and licensing changes are confusing."
"The price point is something they can improve slightly for those who don't have an M 365 E5."
"One area that can be improved is reducing false positives."
"Having up-to-date documentation and real-time reflections in all portals would be beneficial to keep users informed about any changes. Additionally, the frequent changes in Microsoft's UI and the movement of features between different products in the set pose difficulties."
"I would like to have more technical documentation that contains greater detail on the types of threats that are occurring."
"I would like the tool to see more integration with Cortex XDR. There is no real reason to keep them separate."
"It would be helpful to have better documentation for configuring and installing the solution."
"It would be better if they used the threat intelligence feeds directly from their side and changing the verdict instead of us requesting it."
"It is a completely cloud-based product at present."
 

Pricing and Cost Advice

"There is a need to make yearly payments towards the licensing charges attached to the product."
"The pricing of the solution is good."
"The solution's pricing is reasonable and not very expensive."
"It is an expensive product."
"The product has multiple subscription models."
"The product is a part of my Microsoft 365 subscription, so there is no additional cost. It is cost-effective."
"Microsoft's pricing structure involves annual fees."
"It's reasonably priced, though there's room for further improvement."
"It is expensive."
"The solution is reasonably priced."
report
Use our free recommendation engine to learn which Threat Intelligence Platforms solutions are best for your needs.
860,592 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
16%
Financial Services Firm
13%
Educational Organization
12%
Manufacturing Company
8%
Computer Software Company
10%
Insurance Company
10%
Financial Services Firm
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Microsoft Defender Threat Intelligence?
It just runs in the background. I don't have to worry about, making sure it's Intelligence. So, you know, this kind of makes it very easy, have to worry about installing. It is easy to use.
What needs improvement with Microsoft Defender Threat Intelligence?
From the telemetry data standpoint, I would prefer Defender data to be more open in future updates.
What is your primary use case for Microsoft Defender Threat Intelligence?
We have tried Microsoft Defender Threat Intelligence. I have expertise with Microsoft Defender products. I am not familiar with Microsoft Defender for IoT because we did not use that in our environ...
What needs improvement with Palo Alto Networks AutoFocus?
While Palo Alto Networks AutoFocus is effective, I always prefer to have a second source of threat intelligence feed to ensure coverage for zero-day vulnerabilities that might be missed. This is mo...
What is your primary use case for Palo Alto Networks AutoFocus?
I use Palo Alto Networks AutoFocus ( /products/palo-alto-networks-autofocus-reviews ) for threat intelligence. Palo Alto Networks has its own threat intelligence team, Unit 42, which analyzes submi...
What advice do you have for others considering Palo Alto Networks AutoFocus?
I would rate Palo Alto Networks AutoFocus a ten out of ten. I always activate it when purchasing Palo Alto Networks products because it's simple to deploy and beneficial. However, for non-Palo Alto...
 

Also Known As

No data available
Palo Alto Threat Intelligence Management
 

Overview

 

Sample Customers

Information Not Available
Telkom Indonesia
Find out what your peers are saying about Microsoft Defender Threat Intelligence vs. Palo Alto Networks AutoFocus and other solutions. Updated: June 2025.
860,592 professionals have used our research since 2012.