Try our new research platform with insights from 80,000+ expert users

Microsoft Purview eDiscovery vs Microsoft Sentinel comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.7
Microsoft Purview eDiscovery boosts ROI by improving data efficiency, compliance, risk management, and reducing legal and IT workloads.
Sentiment score
7.3
Microsoft Sentinel enhances ROI with improved security, cost savings, automation, and faster threat detection, benefiting organizations efficiently.
We have seen a 100% return on investment.
The ease of accessing necessary information promptly is the biggest return on investment.
It's hard to quantify the ROI in a dollar amount, but we realize value by doing more tasks in less time than we did before.
If a customer is already using Microsoft’s ecosystem, the ROI can be positive due to seamless integration.
We attribute our growth to Sentinel.
From a risk perspective, it's about mitigating risk, and as mentioned earlier, we haven't missed many things since we've had the offering in market—only a couple of minor incidents.
 

Customer Service

Sentiment score
7.6
Microsoft Purview eDiscovery is praised for responsive support, despite some mixed experiences with wait times and outcomes.
Sentiment score
6.7
Microsoft Sentinel support is responsive and helpful, though basic support can be slow, with some preferring community resources.
I would rate Microsoft Purview eDiscovery's customer service and technical support a ten.
Their solutions' integration simplifies resolving issues compared to those caused by third-party products.
Working with a Sentinel engineer helped us tune settings effectively.
When my team needs to escalate issues to Microsoft, especially for Microsoft Sentinel, the response is fast through their French entity.
 

Scalability Issues

Sentiment score
7.9
Microsoft Purview eDiscovery is scalable and efficient, seamlessly integrating with cloud infrastructures but lacks some search functions.
Sentiment score
8.0
Microsoft Sentinel offers scalable, adaptable security solutions using Azure, ideal for various organizations with its flexible and updated features.
It scales with us seamlessly.
With the E3 licensing, I would rate the scalability of Microsoft Purview eDiscovery as a six because it lacks certain critical search functionalities.
Office 365 and Exchange are running on it, covering about 35,000 users efficiently.
As our organization uses Microsoft Azure and Defender, everything grows together, and we can integrate various features seamlessly.
Being a SaaS solution, the scalability of Microsoft Sentinel is robust.
 

Stability Issues

Sentiment score
8.6
Microsoft Purview eDiscovery is generally stable, with minor slowdowns, but users seek more transparency on performance issues.
Sentiment score
7.8
Microsoft Sentinel is highly reliable, with 99.9%+ availability and occasional minor issues, maintaining stability across diverse environments.
For us, it has been one hundred percent reliable.
Microsoft Purview eDiscovery is highly reliable.
So far, we have not experienced any issues, and it has been stable from the beginning.
In the past two years, our team hasn't encountered any issues with the stability of Microsoft Sentinel from an operations perspective.
I need to be aware of deprecated connectors as they may disconnect, but the data continues to be sent with a need for quick adaptation.
 

Room For Improvement

Microsoft Purview eDiscovery needs faster, more efficient features, better integration, NLP for queries, and affordable pricing for users.
Microsoft Sentinel users seek better integration, user-friendliness, documentation, AI capabilities, and customizable features with improved performance and pricing.
Adding more features, as Microsoft continues to expand their cloud offerings, would be beneficial.
Defining what constitutes a credit card because that is where I get the most false positives.
We find that many critical functions are available only to E5 license holders.
We have some tools, such as our off-site Meraki firewalls, that have not fully integrated with Sentinel.
Currently, we are happy to have a way in the middle with not so much cost, but it would be nice to have the ability to enhance the automation of workflows based on learned incidents.
There are complexities in calculating the right pricing tier for different customers, which makes it difficult for me as a consultant during upfront pricing.
 

Setup Cost

Microsoft Purview eDiscovery pricing is complex, with E5 costly yet beneficial, while E3 is cheaper but limited.
Microsoft Sentinel's usage-based pricing offers strong value with extensive integration, but cost unpredictability concerns some users.
With CSP or MCE-style agreements with Microsoft, the process is streamlined since we have reps from both Microsoft and CDW working together.
As an M3, I find the Purview pricing of 1250 per user worthwhile.
The pricing and licensing with Microsoft can be complex, and licensing is known to be a challenge because it changes frequently.
Microsoft Sentinel offers more capabilities than Bastion, with a more intuitive experience.
Setting up the right cost model for customers is intricate, requiring careful consideration of various components and licensing tiers.
The ingestion costs for the data analytics is usually the highest cost.
 

Valuable Features

Microsoft Purview eDiscovery ensures efficient data retrieval with multi-platform integration, automation, compliance visibility, and adherence to global data privacy laws.
Microsoft Sentinel provides AI-driven automation, robust threat detection, scalability, and seamless integration for comprehensive security operations within the Microsoft ecosystem.
The most valuable feature of Microsoft Purview eDiscovery is its ability to search across various platforms, including Exchange, SharePoint, Teams, and OneDrive.
Purview can connect to iOS, Mac, Android, and SaaS apps, which is critical for capturing SMS and MMS text message data.
Purview's inclusion of global regulations is critical because we're heavily regulated by FERC, Sarbanes-Oxley, and the SEC.
Microsoft Sentinel's ability to correlate data from multiple sources and its detection capabilities are essential.
Microsoft Sentinel has improved cost efficiency, which is one of the key areas we're able to win business against the ability to have threat intelligence.
Microsoft Sentinel's ability to correlate data from multiple sources enhances our threat detection capabilities beyond what is a simple data lake solution by filtering out the noise and consolidating the signal down to a meaningful level that is easier to investigate and see.
 

Categories and Ranking

Microsoft Purview eDiscovery
Ranking in Microsoft Security Suite
25th
Average Rating
7.6
Reviews Sentiment
7.5
Number of Reviews
8
Ranking in other categories
eDiscovery (2nd)
Microsoft Sentinel
Ranking in Microsoft Security Suite
4th
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
97
Ranking in other categories
Security Information and Event Management (SIEM) (3rd), Security Orchestration Automation and Response (SOAR) (1st), AI-Powered Cybersecurity Platforms (5th)
 

Mindshare comparison

As of June 2025, in the Microsoft Security Suite category, the mindshare of Microsoft Purview eDiscovery is 0.7%, down from 0.9% compared to the previous year. The mindshare of Microsoft Sentinel is 5.0%, down from 6.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Microsoft Security Suite
 

Featured Reviews

Frank Radeck - PeerSpot reviewer
Tasks that took an entire day before we implemented the solution now take just 30 minutes.
The most valuable feature of Microsoft Purview eDiscovery is its ability to search across various platforms, including Exchange, SharePoint, Teams, and OneDrive. It enables a streamlined, unified process for searching across these platforms. It is critical for Purview to be able to connect to iOS, Mac, and Android devices and data in other SaaS apps. From a support perspective, I can do things while I'm eating lunch or something else. It's more dynamic and responsive. I think everybody appreciates it. We're not tied to one device. Purview's multi-cloud capabilities are also essential for the same reasons. Keeping everything under one umbrella further increases the time savings. Purview accounts for critical regulations from around the world. This is crucial because we hold ourselves accountable to standards and need to align with them. Working at a law firm, we have clients who dictate to us what standards they expect. The visibility is excellent. As we move more things into the cloud, more opportunities exist to put everything under one umbrella.
Ivan Angelov - PeerSpot reviewer
Threat detection and response capabilities enhance investigation processes
My security team has been using Microsoft Sentinel for around two years. We also have Bastion and SolarWinds as part of our monitoring tools. We use a three-way tool, alongside Microsoft Sentinel, in our environment The most valuable features for us include threat collection, threat detection,…
report
Use our free recommendation engine to learn which Microsoft Security Suite solutions are best for your needs.
856,873 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Government
13%
Financial Services Firm
13%
Computer Software Company
10%
University
6%
Computer Software Company
16%
Financial Services Firm
11%
Manufacturing Company
8%
Government
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

What do you like most about Microsoft Purview eDiscovery?
The tool has been beneficial. Some of our previous users left the organization without sharing the information they had at a personal level. This information was related to the organization, and th...
What is your experience regarding pricing and costs for Microsoft Purview eDiscovery?
The setup process was very straightforward. We acquired pricing through our reseller in NASDAQ, eliminating the need to search for prices ourselves.
What needs improvement with Microsoft Purview eDiscovery?
The query language can be time-consuming to figure out if you don't know it initially. While there are options with dropdowns to select criteria, having a natural language feature would be benefici...
Is there a common threat intelligence tool that aggregates multiple threat intelligence sources?
Yes, Azure Sentinel is a SIEM on the Cloud. Multiple data sources can be uploaded and analyzed with Azure Sentinel and its Threat Hunting functionality with AI available as templates or customized ...
What is a better choice, Splunk or Azure Sentinel?
It would really depend on (1) which logs you need to ingest and (2) what are your use cases Splunk is easy for ingestion of anything, but the charge per GB/Day Indexed and it gets expensive as log ...
Which is better - Azure Sentinel or AWS Security Hub?
We like that Azure Sentinel does not require as much maintenance as legacy SIEMs that are on-premises. Azure Sentinel is auto-scaling - you will not have to worry about performance impact, you will...
 

Also Known As

No data available
Azure Sentinel
 

Overview

 

Sample Customers

Information Not Available
Microsoft Sentinel is trusted by companies of all sizes including ABM, ASOS, Uniper, First West Credit Union, Avanade, and more.
Find out what your peers are saying about Microsoft Purview eDiscovery vs. Microsoft Sentinel and other solutions. Updated: April 2025.
856,873 professionals have used our research since 2012.