Try our new research platform with insights from 80,000+ expert users
Works at a consumer goods company with 10,001+ employees
User
Top 10
Mar 18, 2025
Prioritize security by managing vulnerabilities and improving attack surface protection
Pros and Cons
  • "I have not experienced any difficulties or issues with the stability of Microsoft Defender for Cloud."
  • "There needs to be improvement in the security recommendations, particularly in attack path mapping. Sometimes, it misleads users about the real exposure of external-facing assets."

What is our primary use case?

We use Microsoft Defender for Cloud primarily for security reasons, particularly focusing on cyber threats. It is utilized in the manufacturing industry.

What is most valuable?

The most valuable features of Microsoft Defender for Cloud include vulnerability management and threat intelligence. Additionally, security recommendations and attack surface reduction (ASR) rules are significant. ASR rules play a crucial role in attack surface reduction, where they ensure that asset devices are well-protected and streamlined for enhanced security.

What needs improvement?

There needs to be improvement in the security recommendations, particularly in attack path mapping. Sometimes, it misleads users about the real exposure of external-facing assets. It would be beneficial to streamline recommendations to avoid unnecessary alerts and to refine the severity of alerts based on specific environments or environmental attributes.

For how long have I used the solution?

I have been using the solution for three years.
Buyer's Guide
Microsoft Defender for Cloud
January 2026
Learn what your peers think about Microsoft Defender for Cloud. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,455 professionals have used our research since 2012.

What do I think about the stability of the solution?

I have not experienced any difficulties or issues with the stability of Microsoft Defender for Cloud.

What do I think about the scalability of the solution?

I would rate the scalability of Microsoft Defender for Cloud between eight and nine out of ten for our company.

How are customer service and support?

I would rate Microsoft's technical support around seven to eight out of ten. They are supportive but sometimes slow, especially regarding new feature additions and managing their backlog.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I have not evaluated other solutions in this company before using Microsoft Defender for Cloud.

How was the initial setup?

The setup is generally easy, particularly for Windows native operating systems. On a scale of one to ten, I would rate the setup an eight for Windows and a seven to eight for Linux devices.

What's my experience with pricing, setup cost, and licensing?

Initially, the cost was reasonable, but additional services from Microsoft sometimes incur extra expenses that seem higher than expected.

What other advice do I have?

Microsoft Defender for Cloud is compatible with the Microsoft ecosystem and provides decent integration with third-party tools. Overall, I would rate the solution an eight out of ten for its effectiveness and support.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Systems & Software Engineer at a financial services firm with 10,001+ employees
Real User
Top 10
Nov 20, 2025
Lacks granular control and causes interference but supports basic scanning needs
Pros and Cons
  • "Our main use cases for Microsoft Defender for Cloud involve scanning PCs."
  • "I don't appreciate Microsoft Defender for Cloud because it seems to interfere with many things. That's the problem I've been experiencing with it."

What is our primary use case?

Our main use cases for Microsoft Defender for Cloud involve scanning PCs.

What is most valuable?

I doubt that we are using the unified AI-powered security feature offered by Microsoft Defender for Cloud.

Microsoft Defender for Cloud's integrated XDR feature is not being used.

The GenAI threat protection features for Microsoft Defender for Cloud are not being utilized.

What needs improvement?

I don't appreciate Microsoft Defender for Cloud because it seems to interfere with many things. That's the problem I've been experiencing with it. Before Defender, we had McAfee, which was much better at granular exceptions and changing what it does. Microsoft Defender for Cloud doesn't have that granularity. I can't tell it to leave certain items alone while scanning others. Microsoft Defender for Cloud doesn't really provide that capability, which is a significant problem. It's been causing far more issues than McAfee did.

I think it's too new to have major concerns regarding security when deploying AI applications, at least from my perspective. Regarding scanning a PC, I'm uncertain about the concerns. The actions it takes on those scans might be part of it, but they already have defined policies. For example, if Microsoft Defender for Cloud thinks a piece of software is malicious, it deletes it. I don't believe that's necessarily the best approach. I would prefer it to quarantine the software instead. I think the option for quarantine might exist, but I'm uncertain if it could be modified for that. It probably depends on the threat level or what Microsoft Defender for Cloud perceives as a threat level.

Microsoft Defender for Cloud can be improved with more granular control. They need to examine what McAfee can do.

For how long have I used the solution?

I think we've been using Microsoft Defender for Cloud for about four years now.

What do I think about the stability of the solution?

I've experienced performance issues with Microsoft Defender for Cloud.

What do I think about the scalability of the solution?

In my opinion, Microsoft Defender for Cloud doesn't scale well with the growing needs of the organization. But again, it's just my experience.

How are customer service and support?

Since I don't talk directly to Microsoft support for Defender, we just talk to our internal people who are supposedly the experts in it at the bank. I couldn't give an opinion on Microsoft's support.

I would prefer to bypass our internal people and actually go to Microsoft to get answers, but they won't allow us to do that.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

Prior to adopting Microsoft Defender for Cloud, we were using McAfee. Money is always a factor.

How was the initial setup?

I didn't deploy Microsoft Defender for Cloud.

What about the implementation team?

Agentless scanning for the cloud environment has not been enabled with Microsoft Defender for Cloud.

What was our ROI?

I don't know if I've seen a return on investment with Microsoft Defender for Cloud.

What's my experience with pricing, setup cost, and licensing?

I have no idea about the pricing, setup cost, and licensing because I don't handle that.

Which other solutions did I evaluate?

I don't think anything else was considered before choosing Microsoft Defender for Cloud.

What other advice do I have?

I would advise another organization that's considering Microsoft Defender for Cloud to shop around and make sure it's the best solution. This review has a rating of 5.

Which deployment model are you using for this solution?

Information regarding the deployment model is not provided in the review.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Information regarding the cloud provider is not provided in the review.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Nov 20, 2025
Flag as inappropriate
PeerSpot user
Buyer's Guide
Microsoft Defender for Cloud
January 2026
Learn what your peers think about Microsoft Defender for Cloud. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,455 professionals have used our research since 2012.
Efren Torres - PeerSpot reviewer
System Administrator at a engineering company with 201-500 employees
Real User
Top 10
Nov 19, 2025
Switching to a lighter agent has improved visibility and reduced client-side impact
Pros and Cons
  • "The feature of Microsoft Defender for Cloud that I appreciate most is the ability to view logs of applications, as I find it much clearer to understand what is running."
  • "Microsoft Defender for Cloud can be improved because many of the functions involve multiple places to accomplish the same task, which can make it convoluted."

What is our primary use case?

My main use cases for Microsoft Defender for Cloud are client-end, as we are replacing our Sophos agents on our client computers with Microsoft Defender.

What is most valuable?

The feature of Microsoft Defender for Cloud that I appreciate most is the ability to view logs of applications, as I find it much clearer to understand what is running.

That feature benefits my company because we are a small company. Previously, we were running a Sophos agent that ran heavily on our computers, and switching over to Defender has made it lighter for us.

Microsoft Defender for Cloud has helped me manage and secure my multi-cloud environments, as we are hybrid-joined, and the insights it has provided are significant. For instance, we were able to identify sub-hosted IPs that were not even part of our segment from another client that our managed service provider was handling.

What needs improvement?

Microsoft Defender for Cloud can be improved because many of the functions involve multiple places to accomplish the same task, which can make it convoluted. It performs the same functions, but you have to navigate to different areas for different tasks, making it confusing at times.

For how long have I used the solution?

I have been using Microsoft Defender for Cloud for approximately one year.

What do I think about the stability of the solution?

As for the stability and reliability of the platform, everything has been going well. I have no complaints and would rate it about an eight.

What do I think about the scalability of the solution?

I would rate Microsoft Defender for Cloud's scalability with the growing needs of my company as approximately an eight.

How are customer service and support?

I have not had to reach out much regarding customer service and technical support, so my thoughts are limited.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

The main differences between Microsoft Defender for Cloud and the other platform I was using involve deployment. Microsoft Defender for Cloud is not on the client-end, so it is not noticeable and not as taxing on system performance.

How was the initial setup?

My experience with the deployment of Microsoft Defender for Cloud has been straightforward, as it went smoothly.

What was our ROI?

The biggest return on investment for me when using Microsoft Defender for Cloud is seen with end-users, as they do not reach out to us regarding issues where the underlying cause was our Sophos agent.

What's my experience with pricing, setup cost, and licensing?

Regarding the pricing, setup cost, and licensing of the platform, what we have paid for is still to be determined, as we are about to renew our licensing at the end of this year.

So far, it has been affordable. In comparison to Sophos that we were running, we have found that it will wind up being approximately the same amount of cost.

Which other solutions did I evaluate?

I am currently considering Windows Defender.

What other advice do I have?

I am not using the unified AI-powered security feature offered by Microsoft Defender for Cloud at this time.

I am not using Microsoft Defender for Cloud's integrated XDR features at this time.

I am not utilizing the enhanced AI threat protection features of Microsoft Defender for Cloud, as there are many AI features we have not explored yet.

I have enabled agentless scanning in my cloud environment.

It has been with Microsoft Defender for Cloud.

I assess the impact on my workload protection without the need for installing agents as really good, considering that it is running smoothly on the client machines without lag or any performance impact.

My advice to other companies considering Microsoft Defender for Cloud is to be aware that there is a lot involved and a lot of what it can do, meaning that you will need to conduct a lot of research and study training material. I rate my overall experience with Microsoft Defender for Cloud an eight.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Nov 19, 2025
Flag as inappropriate
PeerSpot user
Jordi Costa - PeerSpot reviewer
Enterprise Deployments Lead at a tech services company with 1,001-5,000 employees
Real User
Top 10
Nov 19, 2025
Improves multi-cloud security and reduces operational concerns during off-hours
Pros and Cons
  • "Microsoft Defender for Cloud has benefited my organization by reducing the overall cost of the Azure package and providing greater peace of mind during off-hours to prevent problems."
  • "Comparing Microsoft Defender for Cloud to other solutions on the market, Microsoft needs to push a little bit to improve it."

What is our primary use case?

My main use cases for Microsoft Defender for Cloud cover several Azure solutions.

What is most valuable?

Microsoft Defender for Cloud is integrated with the entire Microsoft suite and does not require purchasing extra add-ons or additional applications.

Microsoft Defender for Cloud has benefited my organization by reducing the overall cost of the Azure package and providing greater peace of mind during off-hours to prevent problems.

Microsoft Defender for Cloud has helped me manage and secure my multi-cloud environment.

Microsoft Defender for Cloud has helped keep our environment secure.

What needs improvement?

Comparing Microsoft Defender for Cloud to other solutions on the market, Microsoft needs to push a little bit to improve it. It works and does what it needs to do, but other companies are offering more.

For how long have I used the solution?

I have been using Microsoft Defender for Cloud for approximately two and a half years.

What do I think about the stability of the solution?

Microsoft Defender for Cloud is reliable and stable.

I have not experienced any malfunctions with Microsoft Defender for Cloud. We have never had issues. At the beginning, about three years ago, there were several issues, but currently we do not have any.

Which solution did I use previously and why did I switch?

Before we started using Microsoft Defender for Cloud, we had been using other applications from third-party companies.

How was the initial setup?

The experience of deploying Microsoft Defender for Cloud is very easy. It is basically only a matter of enabling it and specifying where you want to apply it. There is a basic customization option on the left side for focusing on what you want.

What other advice do I have?

We are not using the unified AI-powered security posture feature.

We are using the XDR, but only for a specific solution due to the cost. If it is needed, we evaluate whether the cost benefits justify enabling and using the XDR.

When we enable the feature, we enable it to perform an analysis. It can provide you with a background check.

We are concerned about the information that the application can provide when deploying AI applications. We worry about any information the solution may give that it cannot usually provide in a correct way.

I would rate this product an 8 overall.

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Nov 19, 2025
Flag as inappropriate
PeerSpot user
CEO at a tech vendor with 1-10 employees
Real User
Top 10
May 5, 2025
Alerts provide value for security-conscious customers while menu overlap requires refinement
Pros and Cons
  • "The UX and UI are very good. Users have more of a taste for Microsoft UI."
  • "The feature of Microsoft Defender for Cloud that I have found most valuable is the alerts, which are pretty standard for security."
  • "An area where Microsoft Defender for Cloud could be improved is in getting away from having multiple menus that do the same thing, which seems imposing when looking at it."
  • "An area where Microsoft Defender for Cloud could be improved is in getting away from having multiple menus that do the same thing, which seems imposing when looking at it."

What is our primary use case?

My current use case for Microsoft Defender for Cloud is that we use it primarily for policy. In terms of migrating to Azure, our organization hasn't migrated fully. It has increased the attack surface, so our main use for Microsoft Defender for Cloud is specifically for policy.

What is most valuable?

The feature of Microsoft Defender for Cloud that I have found most valuable is the alerts, which are pretty standard for security. Microsoft Defender has this built in, so more people are coming to it. It's a very recognized brand and more people are coming through it.

We have a large number of customers in Azure, and using Defender means having less variable solutions.

It helps manage attack surface and security posture.

The UX and UI leave something to be desired. Users have more of a taste for Microsoft UI.

The value of Microsoft Defender for Cloud for our organization is notable, especially for our customers that are very security-conscious, as it's beneficial to have it there.

Microsoft Defender for Cloud's CSPM capability has helped our organization assess and manage security posture. The UX and UI is typical Microsoft, the access control takes some time getting used to, and now we just use it on those platforms.

What needs improvement?

An area where Microsoft Defender for Cloud could be improved is in getting away from having multiple menus that do the same thing, which seems imposing when looking at it. It has its upsides and downsides.

For how long have I used the solution?

I have been using Microsoft Defender for Cloud for just over a year.

How are customer service and support?

I've never directly dealt with technical support. 

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

We did not use other solutions.

How was the initial setup?

The setup is okay. In terms of ease, it's maybe the best out of the major three. 

What was our ROI?

I have seen a return on investment with Microsoft Defender for Cloud, as our posture is intact. While it may be somewhat confusing, it has decent feature parity among the major three providers, and businesses have been gradually discovering its potential.

What's my experience with pricing, setup cost, and licensing?

The pricing is pretty standard. 

Which other solutions did I evaluate?

We use the stock option on a given cloud platform.

What other advice do I have?

We use it just for customers on Azure. 

On a scale of one to ten, I rate Microsoft Defender for Cloud a seven.

Which deployment model are you using for this solution?

Hybrid Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: May 5, 2025
Flag as inappropriate
PeerSpot user
Roel Van Der Ouderaa - PeerSpot reviewer
Senior Technical Consultant at a computer software company with 501-1,000 employees
Consultant
Top 20
Dec 17, 2024
Enhanced our security process by providing insights and critical alerts
Pros and Cons
  • "Defender for Cloud provides a complete DevOps security package for cloud services."
  • "The scalability of Microsoft Defender for Cloud is very good."
  • "While we are satisfied with Defender for Cloud's features, an AI enhancement could potentially provide better advice and adapt more effectively to our environment."

What is our primary use case?

We are a managed service provider. We use Microsoft Defender for Cloud to provide services to our customers.

What is most valuable?

Defender for Cloud provides a complete DevOps security package for cloud services. Defender covers a broad range of workloads. It helps us prioritize because it identifies critical alerts that we work to resolve. 

Microsoft Defender for Cloud has enhanced our security process by providing insights and critical alerts. We use it on our own managed platform. It has helped us gain some insights and realize areas for improvement. We have worked to resolve the issues highlighted by the alerts, improving our overall security posture.

What needs improvement?

While we are satisfied with Defender for Cloud's features, an AI enhancement could potentially provide better advice and adapt more effectively to our environment.

For how long have I used the solution?

I have been using Defender for Cloud for about three or four months.

What do I think about the stability of the solution?

I haven't observed any outages with Microsoft Defender for Cloud. The stability is excellent.

What do I think about the scalability of the solution?

The scalability of Microsoft Defender for Cloud is very good. I haven't experienced any issues.

How are customer service and support?

I rate Microsoft support eight out of 10. Technical support is generally satisfactory, though call response times can occasionally be slow.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup was straightforward and easy.

What about the implementation team?

We acted as the integrator, being a managed service provider. We haven't yet developed a strategy for implementing it in other companies.

What was our ROI?

Defender for Cloud provides an invaluable return on investment by preventing potential security breaches. The peace of mind it offers is difficult to quantify.

What's my experience with pricing, setup cost, and licensing?

Pricing is a consideration, but we strive to keep costs low by enabling only necessary services.

Which other solutions did I evaluate?

We evaluated other products but focused on adopting a more cloud-native approach with Microsoft's platform.

What other advice do I have?

I rate Microsoft Defender for Cloud nine out of 10. It's progressing well, although perfection takes time.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Csp
PeerSpot user
reviewer2596320 - PeerSpot reviewer
IT Administrator at a university with 10,001+ employees
Real User
Top 20
Nov 30, 2024
Lists the criticality that is the most insecure for our environment
Pros and Cons
  • "The most valuable features are the security recommendations provided by Defender for Cloud."
  • "Defender for Cloud has improved our security posture."
  • "If they had an easier way to display all the vulnerabilities of the machines affected and remediation steps on one screen rather than having to dive deep into each of them, that would be a lot easier."

What is our primary use case?

We are using Defender for Cloud to check in on security and vulnerability management.

How has it helped my organization?

When we were switching from on-prem to the cloud, we did not have the vulnerability management tool to give us alerts on that. We were using Tenable Security Center on-prem. When we moved to the cloud, we needed a solution and chose Defender for Cloud. Now, when we do our vulnerability management meetings, we refer to Defender for Cloud recommendations. We can assign them to technicians or security personnel in case we need to change policies or make exceptions. It is set up to ensure only security personnel can dismiss a recommendation.

It lists the criticality that is the most insecure for our environment and the criticality score for it. This is helpful for us to know what we need to deal with first.

Defender for Cloud has improved our security posture. 

What is most valuable?

The most valuable features are the security recommendations provided by Defender for Cloud.

What needs improvement?

Tenable Security Center has a list of all of our vulnerabilities. I can sort it by vulnerability or by machine. Defender for Cloud does do that, but it is just not as clean and easy to get to. It sometimes gets too deep in the weeds, and I do not know how I got to that point. If they had an easier way to display all the vulnerabilities of the machines affected and remediation steps on one screen rather than having to dive deep into each of them, that would be a lot easier.

There can be an easier-to-read dashboard. It would be nice to be able to see the top ten vulnerabilities that we have specific to a system on the dashboard. We can view the security score currently, but a cleaner and simpler display would be good.

For how long have I used the solution?

I have been using Defender for Cloud for three years.

What do I think about the stability of the solution?

It is pretty stable and feels solid.

How are customer service and support?

We have struggled with Microsoft customer service quite a bit. While experts are a ten, the overall experience is not always positive and we have had to make a complaint. When we are able to get to a call with their experts, it is great, but it can take time to get to that level. We have had to raise a ticket for the same thing about three times.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We were using Tenable Security Center on-prem. We switched because we were moving to a Microsoft-centric cloud solution.

How was the initial setup?

It was easy. The setup was handled by a technician who did not report any significant issues.

What about the implementation team?

We did not use any third party for deployment.

What was our ROI?

We have seen a return on investment, but I cannot quantify it.

Which other solutions did I evaluate?

We did not evaluate other solutions because we were only looking for a Microsoft-centric solution.

What other advice do I have?

I would rate Defender for Cloud an eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Vibhor Goel - PeerSpot reviewer
Senior Cloud Platform Engineer at a financial services firm with 5,001-10,000 employees
Real User
Top 20
Nov 20, 2024
A single tool for complete visibility and addressing security gaps
Pros and Cons
  • "Microsoft Defender for Cloud helps in improving our overall security posture. We have a nice overview of what is missing where and what can be improved."
  • "The solution is quite good and addresses many security gaps."
  • "There should be an automated mechanism to design Azure policies based on the recommendations, possibly with AI integration. Instead of an engineer having to write a policy to fix security gaps, which is very time-consuming, there should be an inbuilt capability to auto-remediate everything and have proper control in place."
  • "Customer service and support from Microsoft are very poor. Even for high-severity cases, response or resolution time can extend to three or four weeks."

What is our primary use case?

I am closely dealing with alerts related to cloud workloads. We are integrating the alerts that pop up for different services to analyze the gaps in our Azure landscape. We then assess what we need to close and what makes sense for our environment because not everything is applicable. It depends on our company's requirements as well. We plan the strategy for how to close those gaps. There are different mechanisms for how you deal with those security alerts.

How has it helped my organization?

We are using the Microsoft Azure Security Benchmark along with the CIS Benchmark. We rely quite heavily on these benchmarks, and I would rate the CSPM functionality a nine out of ten. Most recommendations are focused on generic security gaps, but overall, those recommendations are very good from the security aspect, irrespective of the industry.

It is pretty good in terms of the range of workloads covered. It covers most of the IaaS infrastructure that Azure offers and most of the PaaS services that we are using. I cannot recall any service that we are using for which Microsoft Defender for Cloud does not have recommendations.

We have integrated the alerts that we are getting from Microsoft Defender for Cloud with our on-premises Splunk solution. We capture those alerts. They are integrated via Microsoft Events Hub. It acts like a queue and pulls those alerts from Microsoft Defender for Cloud and then sends them to Splunk. This integration helps our global security team to figure out which alerts are critical. They can then reach out to the owner of an asset.

Microsoft Defender for Cloud helps in improving our overall security posture. We have a nice overview of what is missing where and what can be improved.

Without Microsoft Defender for Cloud, we will not have any visibility into our security posture. The way on-premises things work in our company is complex. We have ten different tools for ten different categories. We have one tool for vulnerability assessment and one for patch fixing. Microsoft Defender for Cloud is a single integrated tool. It gives me a holistic overview of my whole security posture.

What is most valuable?

The most valuable features are the different plans it offers and the visibility within them, such as the Defender for Servers plan includes capabilities for vulnerability findings on machines and configurations at the OS level. They have different plans for different things. We are utilizing all of them, and they are equally good. 

What needs improvement?

Currently, issues are structured in Microsoft Defender for Cloud at severity levels of high, critical, or warning, but these severity levels are not always right. For example, Microsoft might consider a port being open as critical, but that might not be the case for our company. Similarly, it might suggest closing some management ports, but you might need them to be able to log in, so the severity levels for certain things can be improved. Even though Microsoft Defender for Cloud provides a way to temporarily disable certain alerts or notifications without affecting our security score, it would be better to have more granularized control over these recommendations. Currently, we cannot even disable certain alerts or notifications.

There should be an automated mechanism to design Azure policies based on the recommendations, possibly with AI integration. Instead of an engineer having to write a policy to fix security gaps, which is very time-consuming, there should be an inbuilt capability to auto-remediate everything and have proper control in place.

Additionally, enabling Defender for Cloud at the resource group level, rather than only at the subscription level, would be beneficial.

For how long have I used the solution?

I have been using Microsoft Defender for Cloud for five years.

What do I think about the stability of the solution?

Overall, stability is good. However, Microsoft sometimes changes settings or configurations without transparency. These changes, detected as drift by our infrastructure as a code tool, require unnecessary work. I suggest Microsoft maintain default settings as per the existing configurations during updates to save us from having to do unnecessary work.

What do I think about the scalability of the solution?

Scalability is generally good, but it also depends on the customer's implementation. We are using infrastructure as a code, so we do not have any scalability issues with Microsoft Defender for Cloud implementation because our cloud automatically does it.

If a new subscription is created manually, the configuration is manual too. An automatic toggle for new subscriptions would ease scalable deployment.

From a scalable perspective, if your company has hundreds or thousands of subscriptions, there should be some toggle to automatically scan your new subscription and turn different plans on. This is something they can take into consideration.

How are customer service and support?

Customer service and support from Microsoft are very poor. Even for high-severity cases, response or resolution time can extend to three or four weeks. Often, cases are transferred between teams with no resolution, resulting in a negative experience. We end up closing the case or resolving it on our own. I cannot recall any instance where they managed to quickly resolve any issue. 

I even suggested to my top management to give me one percent of what they are paying for Microsoft's enterprise-level support because I anyway end up resolving the issues on my own. Our case just gets transferred from one engineer to another. We have to explain the same thing from scratch. Nobody is checking case details. Nobody is handing over properly on Microsoft's side. The support experience is very bad.

How would you rate customer service and support?

Negative

Which solution did I use previously and why did I switch?

I did not use any other solutions. Because we use Azure, we prefer to use Microsoft's native, built-in capabilities. That is why we have been using Microsoft Defender for Cloud from the beginning.

How was the initial setup?

The initial setup was simple and straightforward. From a configuration perspective, it is not so complicated. It involves enabling the service at the subscription level, which requires turning on basic toggles.

What about the implementation team?

My team implements these solutions. All new requirements pass through our team.

What's my experience with pricing, setup cost, and licensing?

The pricing model for most plans is generally good, but the cost of the new Defender for Storage plan is high and should be revisited, as it could lead to disabling desirable security features due to cost.

They have introduced a new Defender for Storage plan which they are going to mandate for new workloads. They might already have done that, but it is very costly for users needing additional capabilities. The licensing cost is per storage account irrespective of whether it is enabled or not. Previously, the model for the same service was based on transactions. If you had one million transactions, you were charged according to that. If you had only 10,000, you were charged according to that. Making the new storage plan mandatory is not a good idea from a customer perspective. We did our analysis and compared the new storage plan with the old one. We found that the cost with the new plan is 3.5 times higher. Why would I opt for that as a customer? If it becomes mandatory, we might even disable the plan altogether. We will end up losing certain security alerts that we want to have because of the cost aspect. This new plan should not be enforced, and the customers should have the flexibility to decide.

Another thing is that Microsoft Defender for Cloud is always enabled at the subscription levels. When it is enabled at the subscription level, everybody is charged for it. In the future, there should be more granularity so that under the same subscription, different teams can put their resources. Whoever wants to utilize these capabilities can enable them in their resource group. This will help save costs. Teams will be happy because they will be able to utilize these tools as per their requirements. 

What other advice do I have?

I would rate Microsoft Defender for Cloud an eight out of ten. The solution is quite good and addresses many security gaps. It is the starting point to improve the security of your Azure platform. You can introduce other solutions such as Microsoft Sentinel later. If you start with just Microsoft Defender for Cloud, about 75% of your security gaps will be addressed. After that, you can think of some advanced solutions.

In my experience of working with Azure, teams are not utilizing this solution to its fullest capability. It has so many plans and recommendations to offer, but most of the people do not understand it.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
Download our free Microsoft Defender for Cloud Report and get advice and tips from experienced pros sharing their opinions.
Updated: January 2026
Buyer's Guide
Download our free Microsoft Defender for Cloud Report and get advice and tips from experienced pros sharing their opinions.