Try our new research platform with insights from 80,000+ expert users

Microsoft Defender Vulnerability Management vs Tenable Nessus comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Oct 9, 2024

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Zafran Security
Sponsored
Ranking in Vulnerability Management
17th
Average Rating
9.6
Reviews Sentiment
7.8
Number of Reviews
6
Ranking in other categories
Continuous Threat Exposure Management (CTEM) (1st)
Microsoft Defender Vulnerab...
Ranking in Vulnerability Management
12th
Average Rating
8.0
Reviews Sentiment
6.7
Number of Reviews
16
Ranking in other categories
Advanced Threat Protection (ATP) (16th), Microsoft Security Suite (20th), Risk-Based Vulnerability Management (5th)
Tenable Nessus
Ranking in Vulnerability Management
1st
Average Rating
8.4
Reviews Sentiment
6.0
Number of Reviews
87
Ranking in other categories
No ranking in other categories
 

Mindshare comparison

As of October 2025, in the Vulnerability Management category, the mindshare of Zafran Security is 1.0%, up from 0.1% compared to the previous year. The mindshare of Microsoft Defender Vulnerability Management is 2.7%, down from 2.8% compared to the previous year. The mindshare of Tenable Nessus is 7.3%, down from 11.3% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Vulnerability Management Market Share Distribution
ProductMarket Share (%)
Tenable Nessus7.3%
Microsoft Defender Vulnerability Management2.7%
Zafran Security1.0%
Other89.0%
Vulnerability Management
 

Featured Reviews

Israel Cavazos Landini - PeerSpot reviewer
Weekly insights and risk analysis facilitate informed security decisions
I appreciate the weekly insights Zafran provides, which include critical topics for networks and IT security, allowing us to evaluate which insights apply to our environment. The organization score feature is valuable to keep the leadership team updated on how our infrastructure fares security-wise. The applicable risk level versus base risk level feature is beneficial because prior to Zafran, we only used the base risk level, but now understand that risk depends on the asset itself. Zafran is an excellent tool.
Krishna R - PeerSpot reviewer
Achieve comprehensive endpoint and identity protection with continuous real-time monitoring
I have not thought about improvements for Microsoft Defender Vulnerability Management as of now, but this is typically an operational maintenance process. The operational maintenance process refers to these products being part of day-to-day operations. Threats keep coming almost daily, and we need to run it, prioritize the risk, and apply the patches. I am not able to think of many features for improvement at this point in time. There should be risk scoring added to Microsoft Defender Vulnerability Management; specifically, they call it quantification of the risk. If they can provide peer site reviews or risk scoring, such as how my organization in the healthcare industry fares against my peers on average, it would be valuable information. This scoring should be for specific industries as well. If I belong to the healthcare industry using Microsoft Defender Vulnerability Management, it should provide me with a risk score and show how I fare against the risk score of my industry. If there are guidelines or insights on this, it will compel customers to reduce risk levels or improve their risk scores. The application block capabilities in Microsoft Defender Vulnerability Management are effective and up to the standards, as everybody is looking at open OSINT and open-source security packages. I think on CV scoring, they are aligned with the industry.
MohammedJaffir - PeerSpot reviewer
Has enabled me to reduce false positives and perform deep credential auditing with seamless integrations
I mostly use the configuration audit feature for the audit configuration as a scan policy, and I will use it for credential audit, which helps me scan credentials access such as local administrator or root access, performing a deeper and more accurate check of local configuration settings and file systems, making it a highly recommended feature. Regarding integration capabilities, we can integrate Tenable Nessus with SIM tools such as Splunk, IBM QRadar, and Azure Sentinel, as well as with ticketing systems such as ServiceNow, Jira, and Slack. There is no complexity as it is very easy to integrate everything. In terms of the reporting feature, while vulnerability scanning can throw some false positives, Tenable Nessus has very few, achieving a reduction of 75% to 80% false positives with manual analysis needed. We can generate standard Nessus reports that typically include host summaries and vulnerabilities by host and plugin, alongside solutions and remediation recommendations. The main benefits I get from Tenable Nessus are complete asset inventory and comprehensive attack surface management, allowing us to prioritize vulnerabilities based on risk, focusing on true risk and threat path analysis.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Overall, we have seen about eighty-seven percent reduction of the number of vulnerabilities that require urgency to remediate, specifically the number of criticals."
"Zafran has become an indispensable tool in our cybersecurity arsenal."
"Zafran is an excellent tool."
"We are able to see the real risk of a vulnerability on our environment with our security tools."
"We saw benefits from Zafran Security almost immediately after deploying it."
"A valuable feature is the ease of management and integration with Microsoft products."
"Overall, I would rate Microsoft Defender Vulnerability Management a nine out of ten."
"Microsoft Defender Vulnerability Management has streamlined our threat management processes and provided region-specific customization for our healthcare operations."
"One valuable feature is the Microsoft Security Scorecard."
"The product’s most valuable features are compliance, recommendations, and inventories."
"A valuable feature is the ease of management and integration with Microsoft products."
"Microsoft Defender Vulnerability Management is a good product, and I believe it deserves a positive recommendation."
"The most valuable aspect is the kind of assessment results I get, and the recommendations provided in Microsoft products really help in taking care of the resources."
"The most valuable features of Tenable Nessus are the scanning option. Advanced scanning is highly useful. The offline config audits and application assessments are useful."
"A valuable feature of the solution is that it is easy to understand."
"With the Tenable Nessus enterprise edition, you have unlimited licenses to scan the device."
"Nessus gives me a good preview of vulnerabilities and good suggestions for remediation. It's easy to find a description of a given vulnerability and solutions for it."
"The features of Tenable Nessus that I have found most valuable are its reliability and its ability to collate a dependable output, where we are able to get the same vulnerability when we test manually. The output is quite reliable."
"The solution can scale well."
"Scanners and reports using CIS templates ("de-facto" standard, easy to fix and to locate correction tips at documentation), tests against cloud providers, database profiles, several types of telecom devices, and others highly customizable scans."
"It gives a holistic view of your entire environment."
 

Cons

"I think the ability to have some enhanced reporting capabilities is something they can improve on, as they have good reports but we have asked for some specific reporting enhancements."
"Initially, we were somewhat concerned about the scalability of Zafran due to our large asset count and the substantial amount of information we needed to process."
"The dashboarding and reporting functionality of Zafran Security is an area that definitely could use some improvements."
"There should be risk scoring added to Microsoft Defender Vulnerability Management; specifically, they call it quantification of the risk."
"The documentation from Microsoft needs significant improvement. The documents are disorganized, with one document linking to another, making the steps unclear and difficult to follow."
"Sometimes the stability of the agents could be improved."
"The automated remediations can be more specific."
"Integration can be improved."
"It is expensive."
"Regarding Microsoft's technical support, I would rate it a three out of ten; they could be more responsive and knowledgeable."
"It is challenging to extract and customize reports from the system."
"We use credentialed scans. They need more permissions and more changes or settings on Windows and Linux."
"We have had some false positives in the past, which we hope can improve in the future."
"Tenable Nessus could improve reporting and information sharing. It would be helpful if we could share the reports and have a little bit better flexibility in the reporting of the data."
"We'd like to see the solution embrace more user-friendliness."
"Lacks some penetration testing-related services."
"I would like to see more on the automation side."
"The reporting feature needs to be improved."
"I would like to have a management option after the network scanning."
 

Pricing and Cost Advice

Information not available
"I rate the product's price a three on a scale of one to ten, where one is a low price, and ten is a high price."
"The licensing model follows a per-user per-month structure."
"The product’s pricing is medium."
"The licensing costs are reasonable."
"The tool is a bit costly."
"Its pricing is great and can't be improved. It is very cheap. It is less than 2,000 pounds a license, and you can't really ask for more. It has unlimited IPs and unlimited scans. There are no particular pricing constraints. The only additional cost is the inherent cost of the people to actually review the actual scans."
"Nessus Manager is not an expensive product. It has its limitations, but the pricing reflects that. We have a yearly subscription."
"The price of the solution is reasonable."
"The solution is worth the cost. It's a good investment."
"We incurred a single cost for a perpetual license, although I cannot comment on the price as this is above my management level."
"Nowadays, your vulnerability applications are going to be kind of pricey because lots of them, including Rapid7, are based upon a base price, but then they add in the nodes. That's where they get you. If you're a big network, obviously, you need to scan everything. Therefore, it's going to be costly. The risk and insurance money associated with having ransomware on my networks is going to cost me more money, time, and marketing than the price of the tool. That's why I'm speaking only as an information security officer to security operations. This is the tool that is there in my toolbox to say whether we vulnerable or not. At this point, I don't care about how much it costs my company to have it because if I wasn't able to report it and we got ransomware, then who cares? I'm probably going to be out of business because it happened. That's why I don't care about the price. I have it, and I could use it effectively and do my report. At the end of the day, even if we get ransomware, as long as I reported it, followed my protocol, and put in the change, irrespective of whether it was ignored or denied, I did my job."
"The price is high for the solution. There are free tools with similar functionality available. The solution cost approximately $3,500."
"Cost-wise, it's an affordable tool."
report
Use our free recommendation engine to learn which Vulnerability Management solutions are best for your needs.
872,655 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
11%
Computer Software Company
9%
Manufacturing Company
8%
Government
5%
Financial Services Firm
12%
Computer Software Company
11%
Government
8%
Manufacturing Company
7%
Computer Software Company
12%
Financial Services Firm
11%
Government
10%
Manufacturing Company
10%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise2
Large Enterprise5
By reviewers
Company SizeCount
Small Business39
Midsize Enterprise19
Large Enterprise35
 

Questions from the Community

What is your experience regarding pricing and costs for Zafran Security?
Since we stood Zafran Security up in our private cloud, we handle the maintenance on our side. As we opted not to use...
What needs improvement with Zafran Security?
In terms of areas for improvement, Zafran Security is doing a really great job as a new and emerging company. Oftenti...
What is your primary use case for Zafran Security?
My use cases for Zafran Security revolve around two primary areas. One is around vulnerability management and priorit...
What is your experience regarding pricing and costs for Microsoft Defender Vulnerability Management?
I would rate the price as a three for us due to the partnership discounts. For non-partners, however, the cost could ...
What needs improvement with Microsoft Defender Vulnerability Management?
I have not thought about improvements for Microsoft Defender Vulnerability Management as of now, but this is typicall...
How would you choose between Rapid7 InsightVM and Tenable Nessus?
You have full visibility across cloud, network, virtual, and containerized infrastructures with Rapid7 Insight VM. Yo...
What's the difference between Tenable Nessus and Tenable.io Vulnerability Management?
Tenable Nessus is a vulnerability assessment solution that is both easy to deploy and easy to manage. The design of ...
What do you like most about Tenable Nessus?
We have around 500 virtual machines. Therefore, we conduct monthly scans and open tickets for our developers to addre...
 

Overview

 

Sample Customers

Information Not Available
Information Not Available
Bitbrains, Tesla, Just Eat, Crosskey Banking Solutions, Covenant Health, Youngstown State University
Find out what your peers are saying about Microsoft Defender Vulnerability Management vs. Tenable Nessus and other solutions. Updated: September 2025.
872,655 professionals have used our research since 2012.