No more typing reviews! Try our Samantha, our new voice AI agent.
IT Architect at a real estate/law firm with 10,001+ employees
Real User
Dec 4, 2023
Provides multi-cloud capability, is plug-and-play, and improves our security posture
Pros and Cons
  • "Defender for Cloud is a plug-and-play solution that provides continuous posture management once enabled."
  • "The remediation process could be improved."

What is our primary use case?

We have deployed Microsoft Defender for Cloud to identify vulnerabilities across various log sources for our client.

We implemented Defender to improve the security posture of our client's landscape.

How has it helped my organization?

The single pane of glass that Microsoft offers is highly crucial for several reasons. First, aggregating multiple log sources into a single pane of glass is not achievable without Microsoft Defender for Cloud. Second, we also interact with other cloud environments.

We use Defender's free CSPM functionality for the Microsoft Cloud security benchmark. The benchmark recommendations show all the vulnerabilities that help us to create a remediation plan and to take action.

It is a necessity for us that the free CSPM functionality provides multi-cloud monitoring and posture management because most of our workloads are spread across multi-clouds.

The comprehensive range of workloads protected by Defender for Cloud is sufficient for our needs, as it encompasses all essential security pillars.

We have enabled Defender for Cloud's native support for GCP. A key requirement for us before selecting Defender for Cloud was that it supported other clouds.

Defender for Cloud has aided in reducing the number of vulnerabilities and expediting the resolution process, thanks to its helpful suggestions. Consequently, we have achieved remarkable time savings of approximately 30 to 40 percent each week in comprehending and addressing vulnerabilities.

By integrating Defender for Cloud with the firewall and Defender for Endpoints, we have gained comprehensive security insights through these Microsoft integrations. This unified approach provides a single pane of glass for viewing all security information, eliminating the need to navigate between multiple portals.

Defender for Cloud has improved our security posture.

The unified monitoring has saved us around 30 percent of our time.

Defender for Cloud has increased our security team's efficiency by 30 percent.

What is most valuable?

Defender for Cloud is a plug-and-play solution that provides continuous posture management once enabled.

The multi-cloud capability is an important feature of Microsoft Defender for Cloud.

What needs improvement?

The remediation process could be improved. I have seen that Google has a similar Security Center, where they not only identify vulnerabilities but also provide the steps to fix them. If Microsoft Defender for Cloud could provide remediation steps for all vulnerabilities, it would be a significant enhancement. Currently, only some vulnerabilities have remediation steps available.

Buyer's Guide
Microsoft Defender for Cloud
August 2026
Learn what your peers think about Microsoft Defender for Cloud. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,422 professionals have used our research since 2012.

For how long have I used the solution?

I have been using Microsoft Defender for Cloud for three years.

What do I think about the stability of the solution?

Microsoft Defender for Cloud is stable. We have not encountered any downtime.

What do I think about the scalability of the solution?

Microsoft Defender for Cloud is scalable.

How are customer service and support?

The technical support is good. We can raise tickets without any issues.

Which solution did I use previously and why did I switch?

We previously utilized Google's Security Center. However, we transitioned to Microsoft Defender for Cloud following the client's preference for a native solution, as they are a Microsoft-centric organization. Additionally, Microsoft Defender for Cloud's multi-cloud capabilities, including its ability to integrate information from Google Cloud, were compelling factors in our decision.

What was our ROI?

We have achieved a return on investment in terms of time and efficiency, which translates to monetary savings. For instance, we have gained 30 percent more efficiency in remediation tasks. This means that what previously took ten days can now be completed in seven days, saving us time and, consequently, money.

What's my experience with pricing, setup cost, and licensing?

I am not involved much with the pricing but the bundle offering is good.

Which other solutions did I evaluate?

We considered Prisma Cloud before ultimately selecting Microsoft Defender for Cloud. The fact that Defender for Cloud was a native solution for our client significantly simplified the integration process.

What other advice do I have?

I would rate Microsoft Defender for Cloud nine out of ten.

We have Microsoft Defender for Cloud deployed across 2,000 locations and over 3,000 endpoints.

No maintenance is required from our end.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Microsoft Azure
Disclosure: My company has a business relationship with this vendor other than being a customer.
PeerSpot user
Roel Van Der Ouderaa - PeerSpot reviewer
Senior Technical Consultant at Simac ICT
Real User
Top 20
Dec 17, 2024
Enhanced our security process by providing insights and critical alerts
Pros and Cons
  • "Defender for Cloud provides a complete DevOps security package for cloud services."
  • "The scalability of Microsoft Defender for Cloud is very good."
  • "While we are satisfied with Defender for Cloud's features, an AI enhancement could potentially provide better advice and adapt more effectively to our environment."

What is our primary use case?

We are a managed service provider. We use Microsoft Defender for Cloud to provide services to our customers.

What is most valuable?

Defender for Cloud provides a complete DevOps security package for cloud services. Defender covers a broad range of workloads. It helps us prioritize because it identifies critical alerts that we work to resolve. 

Microsoft Defender for Cloud has enhanced our security process by providing insights and critical alerts. We use it on our own managed platform. It has helped us gain some insights and realize areas for improvement. We have worked to resolve the issues highlighted by the alerts, improving our overall security posture.

What needs improvement?

While we are satisfied with Defender for Cloud's features, an AI enhancement could potentially provide better advice and adapt more effectively to our environment.

For how long have I used the solution?

I have been using Defender for Cloud for about three or four months.

What do I think about the stability of the solution?

I haven't observed any outages with Microsoft Defender for Cloud. The stability is excellent.

What do I think about the scalability of the solution?

The scalability of Microsoft Defender for Cloud is very good. I haven't experienced any issues.

How are customer service and support?

I rate Microsoft support eight out of 10. Technical support is generally satisfactory, though call response times can occasionally be slow.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup was straightforward and easy.

What about the implementation team?

We acted as the integrator, being a managed service provider. We haven't yet developed a strategy for implementing it in other companies.

What was our ROI?

Defender for Cloud provides an invaluable return on investment by preventing potential security breaches. The peace of mind it offers is difficult to quantify.

What's my experience with pricing, setup cost, and licensing?

Pricing is a consideration, but we strive to keep costs low by enabling only necessary services.

Which other solutions did I evaluate?

We evaluated other products but focused on adopting a more cloud-native approach with Microsoft's platform.

What other advice do I have?

I rate Microsoft Defender for Cloud nine out of 10. It's progressing well, although perfection takes time.

Which deployment model are you using for this solution?

Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Csp
PeerSpot user
Buyer's Guide
Microsoft Defender for Cloud
August 2026
Learn what your peers think about Microsoft Defender for Cloud. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,422 professionals have used our research since 2012.
reviewer2564271 - PeerSpot reviewer
Programme Manager- Cyber Fusion- Group CISO at a financial services firm with 10,001+ employees
Real User
Top 10
Nov 13, 2024
Valuable API variety and enhanced security but expanding legacy asset scope is recommended
Pros and Cons
  • "The most valuable feature for me is the variety of APIs available."
  • "I recommend that they extend the scope for legacy infra assets."

What is our primary use case?

We are using the tool for checking for vulnerabilities over my website for my own personal purpose and within my corporate role. This is also a tool that we have deployed. In terms of usage, it's much more related to reporting and vulnerability management rather than setting up from an organizational perspective.

How has it helped my organization?

From an efficiency perspective, it has helped with reporting and the self-service availability of security postures.

What is most valuable?

The most valuable feature for me is the variety of APIs available. Additionally, the suggestions I get from Defender for security levels and recommendations on how to upgrade my security level are very appreciated.

What needs improvement?

I recommend that they extend the scope for legacy infra assets.

For how long have I used the solution?

I have been working with it for more than a year now.

What do I think about the stability of the solution?

I rate the stability an eight out of ten.

What do I think about the scalability of the solution?

There are no complaints about scalability, and I rate it an eight out of ten.

How are customer service and support?

I rate customer support a nine out of ten. The support team was very responsive to queries.

How would you rate customer service and support?

Positive

How was the initial setup?

Rating the setup, I would give it a six out of ten. The setup process took about two to three days due to waiting on support replies.

What about the implementation team?

I had a support team to help with some of the setup aspects, and they were very responsive.

What was our ROI?

It's difficult to say because the volume of vulnerabilities and threats has increased, making it tough to compare efficiency between usage before and after implementation.

What's my experience with pricing, setup cost, and licensing?

I don't have visibility into the specific costs, but it seems to be a significant concern for our organization. Every time we consider expanding usage, we carefully evaluate the necessity due to cost concerns.

Which other solutions did I evaluate?

I am familiar with Dataiku and Databricks, and we use SailPoint in conjunction.

What other advice do I have?

Users must first understand the list of assets they have and whether there is out-of-the-box connectivity with them.

I'd rate the solution seven out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
reviewer2595948 - PeerSpot reviewer
Engineer at a computer software company with 201-500 employees
Real User
Top 20
Dec 16, 2024
It's really easy to search through with KQL queries to find the security breaches and incidents
Pros and Cons
  • "I find Microsoft Defender for Cloud's KQL very flexible and powerful. It's really easy to search through with KQL queries to find the security breaches and incidents and to track down the breach itself."
  • "I would rate Microsoft Defender for Cloud a ten."

    What is our primary use case?

    The primary use case for Microsoft Defender for Cloud in our organization is investigating breach or security incidents.

    How has it helped my organization?

    Defender for Cloud has improved our security posture by 20 to 30 percent. With everybody moving to hybrid, it's challenging to maintain a good security posture with so many people working from home. I'm impressed with the solution's coordinated detection and responses across devices, identities, apps, emails, data, and cloud workloads. That's why we're considering using Defender in more areas and integrating it more.

    What is most valuable?

    I find Microsoft Defender for Cloud's KQL very flexible and powerful. It's really easy to search through with KQL queries to find the security breaches and incidents and to track down the breach itself. Microsoft Defender for Cloud presents a prioritized list of remediation for security issues, giving us a starting point to begin locking things down and tightening security.

    What needs improvement?

    I can't think of anything that needs improvement. It's a pretty good product.

    For how long have I used the solution?

    I have been using Microsoft Defender for Cloud for the last year.

    What do I think about the stability of the solution?

    Defender's stability has been flawless for us. I haven't noticed any issues.

    What do I think about the scalability of the solution?

    It's great. It seems perfectly scalable.

    How are customer service and support?

    I would rate Microsoft customer service and technical support 10 out of 10. They seem quick to respond and get us the answers we need, taking a hands-off approach to helping us integrate.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I previously used other antivirus products like Kaspersky. Microsoft Defender for Cloud is preferred because it offers cloud ability and is a more trusted partner in the industry.

    What about the implementation team?

    We used a consultant for the implementation, and the experience was good. No complaints.

    What was our ROI?

    Our return on investment is seen through increased productivity. I'm able to get more done with less time.

    Which other solutions did I evaluate?

    I evaluated other antivirus products like Kaspersky before switching.

    What other advice do I have?

    I would rate Microsoft Defender for Cloud a ten. Having this solution alleviates the need to worry about other antivirus products, offering a one-stop solution.

    Which deployment model are you using for this solution?

    Hybrid Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Sales Manager at Voit Digital
    Reseller
    Top 20
    Oct 15, 2024
    Comprehensive and centralized device management with room for licensing clarity
    Pros and Cons
    • "The valuable features include the ability to manage devices and the fact that Defender can replace other security tools like SCCM."
    • "There are challenges with the licensing policies, which are quite complicated."

    What is our primary use case?

    For example, the customer wants to restrict USB connections or any output device, or they want to verify any link they open before opening it in their real environment. Mostly, they replace the current security tool they are using, such as Kaspersky, with Defender for Cloud because it integrates well with Office 365.

    How has it helped my organization?

    The biggest advantage is it centralizes management. Customers do not have to manage different vendor products. They feel confident using Microsoft because of the long-recognized technology and detailed technical documentation available online.

    What is most valuable?

    The valuable features include the ability to manage devices and the fact that Defender can replace other security tools like SCCM. Since they use Office 365, they need tools that work better in their organization, such as M365 Defender for Cloud.

    What needs improvement?

    There are challenges with the licensing policies, which are quite complicated. The documentation is difficult to understand and resellers need proper training to support customers effectively. Microsoft should provide better training for resellers.

    For how long have I used the solution?

    I have been working with Defender for Cloud for more than five years.

    What do I think about the stability of the solution?

    It is quite stable. It doesn’t have significant stability issues. I would rate it an eight for stability.

    What do I think about the scalability of the solution?

    I am not the one using it directly yet I haven't heard any complaints, so I would rate it a five.

    How are customer service and support?

    Working with Microsoft technical support can be challenging. The problem-solving process can be delayed, and not all issues get resolved promptly. If there are ten tickets, maybe only five or six get resolved satisfactorily.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    Customers are replacing security tools like Kaspersky, Symantec, or Broadcom to use Defender for Cloud because it integrates seamlessly with Office 365.

    How was the initial setup?

    The initial setup is not very easy yet it is manageable. It is not too difficult for those familiar with the product. It is a medium-complexity setup.

    What about the implementation team?

    The implementation should be handled by the reseller. Resellers need proper training from Microsoft as the documentation is complicated.

    What was our ROI?

    In Vietnam, the cost structure makes it expensive. The licensing is priced publicly on the Microsoft website and it adds up based on the number of users.

    What's my experience with pricing, setup cost, and licensing?

    The cost is expensive for the Vietnamese market. It is publicly available on the Microsoft website, and the pricing depends on the number of users.

    What other advice do I have?

    Organizations should ensure resellers are well-trained to support the new technologies. Proper documentation and support are crucial.

    I'd rate the solution seven out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company has a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2544105 - PeerSpot reviewer
    Assistant General Manager at a tech services company with 51-200 employees
    Real User
    Top 10
    Oct 8, 2024
    Enhanced vulnerability management with efficient updates and actionable recommendations
    Pros and Cons
    • "The pricing is good."
    • "The vulnerabilities are duplicated many times."

    What is our primary use case?

    Mostly, it's related to the vulnerability management.

    How has it helped my organization?

    Earlier, we used to do the vulnerability assessment manually, scheduling it based on our timeline, maybe every six months or once a year. Now, it helps us a lot because we can get the vulnerabilities updated and get recommendations.

    What is most valuable?

    The MDVM part is very good. While we were doing the POC, Microsoft Defender was using Qualys for the vulnerability. Now, they have switched to their own MDVM, which is Microsoft Defender Vulnerability Management.

    What needs improvement?

    The vulnerabilities are duplicated many times. If it reports that the findings are around 30 or 40, or let's say, 100, it is not the exact number as it is possible that there are multiple findings which are duplicated in nature, and actually, the number is only 62 or 67. 

    Another issue after Microsoft Defender upgraded and left Qualys is that whenever the load for the report data is too high, we cannot export the report in one go, so we have to do it in batches.

    For how long have I used the solution?

    I have been using the solution for two years.

    What do I think about the stability of the solution?

    The quality of the MDVM feature, one of the keys which we are getting, is many times duplicated with the same IDs.

    How are customer service and support?

    I have contacted Microsoft for the quality issue, and they are working with us.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I did work with something similar, however, not in the same organization. In my earlier organization, I was working with Check Point and Tenable.

    What's my experience with pricing, setup cost, and licensing?

    The pricing is good. It is license-based, and we are not utilizing all of the features, like API and other functionalities, so the cost is not that high.

    What other advice do I have?

    I would definitely recommend Microsoft Defender for Cloud, provided they make some improvements in the MDVM part.

    I'd rate the solution eight out of ten. 

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    CEO at Wood IT Security
    Real User
    Sep 7, 2023
    Gives insight into potential avenues for attack paths, but it is expensive, and the user interface must be improved
    Pros and Cons
    • "The product has given us more insight into potential avenues for attack paths."
    • "The product must improve its UI."

    What is our primary use case?

    I use the solution for threat hunting. We've installed it on a lot of devices. I look for specific version numbers or threats within the environment.

    How has it helped my organization?

    The product has given us more insight into potential avenues for attack paths.

    What is most valuable?

    I like that the solution shows me recent log-ins for certain servers and devices. It's pretty helpful to track down activities and identify or tie them to specific users.

    What needs improvement?

    The product must improve its UI. Looking at multiple devices for the same issue or vulnerability is very cumbersome.

    The solution should provide built-in features related to trending and graphing over time. If it’s already present, we haven’t found it. It doesn't seem intuitive to find it quite as easily as some other tools with ready-to-go dashboards.

    For how long have I used the solution?

    I have been using the solution for two years.

    What do I think about the stability of the solution?

    The tool’s stability seems to be pretty good. I'm sure Microsoft takes care of its backend structure since it is a cloud solution.

    What do I think about the scalability of the solution?

    Scalability, in general, is fine. We can deploy it on as many devices as we want. However, getting meaningful results and data out of that is not easy, especially when some of the things you're looking for might be across your entire enterprise. For example, if we want to know whether a DLL version is installed on any device, trying to get that information by going one by one through the devices is ridiculously cumbersome.

    Which solution did I use previously and why did I switch?

    We used LogRhythm for a little bit. We switched to Microsoft Defender for Cloud because we wanted to do a cloud homogenization. We wanted to bring things away from on-premise and into the cloud because we had cloud assets. It just made more sense to have a cloud solution to manage the tools instead of pulling back into our network and opening the tunnel paths to our on-premise LogRhythm server.

    How was the initial setup?

    The solution is deployed on-premise as well as on the public cloud. Our cloud providers are Azure and AWS. We also have some GCP assets. We have around 20,000 total devices. They don’t always correspond to an end user. Of those, maybe 12,000 to 13,000 are enrolled in Microsoft Defender for Cloud.

    Other devices we have are either outdated Linux or outdated Windows. We’re trying to migrate all the ones we can, and then some of them will be those narrow use-case devices where it wouldn't really make sense or be feasible for them to have a definitive cloud. They're limited processing power devices, like iPads and tablets.

    What about the implementation team?

    The product certainly requires maintenance.

    What was our ROI?

    Just based on costs, I do not see an ROI. However, evaluating a return on investment for something that provides insight into risks and vulnerabilities is not my area of expertise. In my opinion, a lot of it can't be quantified.

    What's my experience with pricing, setup cost, and licensing?

    We have the full E5 license. The tool is pretty expensive.

    Which other solutions did I evaluate?

    We evaluated Splunk. Splunk's really expensive. It would also have been an on-premise solution. We needed a cloud solution.

    What other advice do I have?

    We use Microsoft Defender for Cloud to support Azure natively. The solution’s ability to protect hybrid and multi-cloud environments is pretty important for us. Just as much as anyone else.

    The unified portal for managing and providing visibility across hybrid and multi-cloud environments could be better with some of the ways things are displayed. Overall, it’s all right.

    We have had the solution since we started cloud. I cannot provide a comparison for it. I don't pay too much attention to Microsoft Secure Score. However, I’m sure the product has affected it. We use the product to track down vulnerabilities and missing patches. When those get passed, I'm sure that it changes the score.

    We have integrated Microsoft 365 and Microsoft Defender for Cloud with Microsoft Sentinel. However, I don't deal with it specifically. The tool’s UI could be better. As it is right now, we can only view information from one device at a time. It is extremely limiting.

    The solution is pretty good at keeping our multi-cloud infrastructure and cloud resources secure. We use AWS, and we also have some Windows devices in AWS. We have Microsoft Defender on those.

    Microsoft Defender for Cloud has helped save some of our SOC time. The reporting features, being able to search multiple devices for a specific vulnerability or incident and tying it back, are very difficult to do in the UI. There's some scripting that can be done, but that doesn't make it easier for a lot of people.

    We have set up alerts in the tool. That, combined with other industry scanners like Tenable Nessus, Invicti, and a couple of others that we utilize in our environment, sends updates and alerts to us so that we can quickly respond to issues. We were not measuring TTR. So, the effect on the overall TTR is negligible.

    It is hard to quantify whether the product has saved us money. We haven't seen any attacks from ransomware gangs. Possibly, those are being prevented, and we don't get alerts for some of these attacks. It has not saved us money. It's expensive. However, it is not expensive compared to all our computers being locked up, and someone demanded two million dollars.

    People evaluating the product must look at other options to determine what works best for their environment and organization. It may not necessarily be the best option, but it might be. It certainly works well in a wholly Microsoft Windows environment, especially with other Microsoft software as a primary. If they’re using OfficeSuite, like Microsoft Word and Microsoft Excel, it works well. If they have other things within their environment, they must do their homework and research to see if it works.

    Overall, I rate the tool a seven out of ten.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Microsoft Azure
    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
    PeerSpot user
    Nicolo-De Jesus - PeerSpot reviewer
    Senior Information Security Manager at a recruiting/HR firm with 1,001-5,000 employees
    Real User
    Oct 3, 2023
    The solution's unified portal is essential for managing and providing visibility across our hybrid and multi-cloud environments
    Pros and Cons
    • "DSPM is the most valuable feature."
    • "I would like to have the ability to customize executive reporting."

    What is our primary use case?

    We use Microsoft Defender for Cloud to manage our cloud security posture. We also use Container Protection, which provides additional security for our containerized workloads. This gives us the visibility we need to ensure that our cloud resources are secure.

    How has it helped my organization?

    We use Microsoft Defender for Cloud to natively support Azure Cloud.

    Microsoft Defender for Cloud's ability to protect our hybrid environments is definitely critical because we are on the journey of transitioning from hybrid to the cloud. In order to do that, we need a platform that can help us through the transition.

    The solution's unified portal is essential for managing and providing visibility across our hybrid and multi-cloud environments. Visibility is something that every security operation needs and it gives us leverage to improve our security posture. This is great.

    The single pane of glass view is critical for our organization. This is because we previously used a different platform, so we are all familiar with its features and how to improve upon them. Our heavy investment in Microsoft products made Defender for Cloud a natural choice.

    Our goal is to increase our secure score. As we take steps to mitigate risk, our secure score will increase, giving us the feeling that our cloud resources are secure.

    Microsoft Defender for Cloud significantly improves security operations. Instead of having to look at multiple windows or portals, it provides a single pane of glass for the investigation and remediation of cloud resource risks.

    Microsoft Defender for Cloud helps us proactively discover unknown threats and defend against known threats. It also helps us improve our security posture and defend our cloud resources. We do not normally have external Internet-facing resources, but when we do, Microsoft Defender for Cloud helps us meet compliance requirements.

    What is most valuable?

    DSPM is the most valuable feature. It integrates with standard frameworks, so we can easily see if there are any gaps in our compliance with NIST standards. This allows us to identify areas for improvement and ensure that we are meeting all applicable requirements.

    What needs improvement?

    I would like to have the ability to customize executive reporting.

    For how long have I used the solution?

    I have been using Microsoft Defender for Cloud for five months.

    What do I think about the stability of the solution?

    In the short time we have been using Microsoft Defender for Cloud it has been stable.

    What do I think about the scalability of the solution?

    Microsoft Defender for Cloud is scalable, and we have not yet needed to scale it up.

    Which solution did I use previously and why did I switch?

    We previously used Prisma Cloud, but we switched to Microsoft Defender for Cloud due to internal business decisions. We have since merged with a company that also uses Microsoft Defender for Cloud. We want to leverage the licenses from the merged company and also cut costs in our security portfolio.

    What about the implementation team?

    The implementation was completed in-house. The solution's maintenance is easy.

    What other advice do I have?

    I give Microsoft Defender for Cloud an eight out of ten. We have not used all the modules yet.

    The time to detection has remained relatively the same.

    Our time to respond has remained the same because we previously used Prisma Cloud. Prisma Cloud is what we were using before, so we already have an established service level for handling incidents. We are remediating some of the configuration and cloud issues.

    The primary users of the solution in our organization are the automation team and the software engineering team. We have also migrated some of our ERP systems to the solution.

    I recommend Microsoft Defender for Cloud because it is a mature product that can meet most businesses' security requirements and budgets.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Srikanth Matsa - PeerSpot reviewer
    Senior DevOps Engineer at a tech services company with 501-1,000 employees
    Real User
    Jan 5, 2023
    Offers a security posture score that indicates how well our environment is protected but should offer better pricing options
    Pros and Cons
    • "Microsoft Defender has a lot of features including regulatory compliance and attaching workbooks but the most valuable is the recommendations it provides for each and every resource when we open Microsoft Defender."
    • "Microsoft can improve the pricing by offering a plan that is more cost-effective for small and medium organizations."

    What is our primary use case?

    Our company policy is to onboard all the resources, which are supported by Microsoft Defender because it gives us a good amount of recommendations regarding security and vulnerability issues. We have a lot of new users that are not familiar with security protocols and the solution helps protect our systems. Some people don't have experience with security measures like enabling HTTPS, and FTPS security, setting up encryption on virtual machines, or they don't know how to set up private endpoints. For someone who is new, or doesn't have a lot of experience in this field, it is difficult to monitor everything. Microsoft Defender provides recommendations based on severity. High-severity recommendations are more important, while low-severity recommendations may not be as critical. Security reviewers can review all recommendations to make sure they are appropriate. Microsoft Defender is important for a whole variety of reasons, one of which is that it can help improve the security posture of our environment. This is important for organizations of all sizes but is particularly critical for businesses that are delivering services to customers.

    How has it helped my organization?

    Before Microsoft Defender our external team would give us updates on which ports are opening and which vulnerabilities are being attacked. Now with the recommendations of Microsoft Defender, we can find these vulnerabilities sooner and fix them. Before onboarding those respected resources into Microsoft Defender, we faced a few issues. Once we onboarded those resources, we received prompt recommendations that helped us make the organization's resources more secure. If resources are not secured, it can impact the reputation of the organization. The solution helped identify a lot of the issues, at a high priority that we could resolve.

    Microsoft Defender helps any organization that needs to follow security baseline recommendations in order to improve its environment. Regarding threats, I recommend Microsoft Sentinel for detecting and hunting the threats. I can identify what exactly happened at that particular time or particular resource with the help of Microsoft Sentinel.

    The solution has significantly reduced the overall time it takes us to detect issues. Most of the resources are scanned every 30 minutes, so it doesn't take much time for the solution to give us the respected recommendations.

    Depending on the issue, Microsoft Defender for Cloud has helped reduce our overall time to respond. There are a few recommendations that we can fix immediately by just clicking using the UI. However, the overall time to respond to issues depends upon that respected recommendation list. There are a few things that we need to consider when it comes to the security settings of our virtual machines which can take a long time to identify and fix. 

    What is most valuable?

    Microsoft Defender has a lot of features including regulatory compliance and attaching workbooks but the most valuable is the recommendations it provides for each and every resource when we open Microsoft Defender.

    The solution provides a security posture score, which indicates how well our environment is protected and what our rating is. It also displays the current percentage of our work that is protected. 

    What needs improvement?

    When there is a recommendation by Microsoft Defender that suggests using the Azure Logic App, the remediation step when a user takes action should be created automatically.

    Microsoft can improve the pricing by offering a plan that is more cost-effective for small and medium organizations.

    For how long have I used the solution?

    I have been using the solution for almost two years.

    What do I think about the stability of the solution?

    I give the stability of Microsoft Defender for Cloud an eight out of ten.

    What do I think about the scalability of the solution?

    Microsoft Defender for Cloud is a tool that is designed to scan our resources regardless of the volume every 30 minutes.

    How are customer service and support?

    We have the standard support plan. If we need any help, we just raise a support ticket.

    How would you rate customer service and support?

    Neutral

    How was the initial setup?

    The initial setup is easy. To enable the solution, we simply need to access Microsoft Defender and enable the on button.

    What's my experience with pricing, setup cost, and licensing?

    Currently, Microsoft offers only one plan at the enterprise level which is $15 per machine. This plan can be very costly for small and medium businesses and in some parts of the world, it is cheaper for an organization to hire a full-time security engineer instead.

    What other advice do I have?

    I give the solution a seven out of ten.

    Compared to Microsoft Defender, Microsoft Sentinel is a more mature solution. We can connect to Active Directory from Sentinel to identify risky users which is information that we can't get from Defender. If we could establish the connections to Azure Active Directory and Azure Active Threat Production plan, we could define our flow, which would be connected with the workspace. Microsoft Sentinel is more flexible and is ideal for more complex security scenarios.

    The solution is applied for resources in the subscription. It does not differentiate the environment. If we select the app services, it will secure all the app services in all the environments. If it's not segregated as per the environment, it can create security issues. We have three different environments: production, QA, and dev and we can only deploy the resources in two regions, which are supported by the geo in India.

    We have virtual machines that need to be patched. But the patching analysis isn't done by Defender. Our solutions provide patching recommendations that have to be completed manually.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Microsoft Azure
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Pratik_Savla - PeerSpot reviewer
    Security and Compliance Architect at a manufacturing company with 1,001-5,000 employees
    Real User
    Top 5
    Sep 19, 2022
    It gave us more substantial visibility into our security, helping us increase our overall security posture and manage risks throughout the entire organization
    Pros and Cons
    • "The vulnerability reporting is helpful. When we initially deployed Defender, it reported many more threats than we currently see. It gave us insight into areas we had not previously considered, so we knew where we needed to act."
    • "Defender gave us more substantial visibility into our security, helping us increase our overall security posture and manage risks throughout the entire organization."
    • "Microsoft sources most of their threat intelligence internally, but I think they should open themselves up to bodies that provide feel intelligence to build a better engine. There may be threats out there that they don't report because their team is not doing anything on that and they don't have arrangements with another party that is involved in that research."

    What is our primary use case?

    Defender acts as a CSPM solution, a post-share management solution for cloud security. We use it to find weak spots in our cloud configuration and strengthen the overall security posture of our cloud environment. With this particular tool, we seek to protect workloads across various environments. We have about 3,000 endpoints and 100 users in the United States alone. 

    How has it helped my organization?

    Defender gave us more substantial visibility into our security, helping us increase our overall security posture and manage risks throughout the entire organization. It helps us make decisions about specific kinds of risks. If we see a glaring vulnerability, we can determine whether this is an acceptable risk or something that requires urgent action. The risk level determines our investment and budgeting, and the amount of work needed to remedy that. It provides a lot of valuable information for informing our comprehensive risk management strategy.

    The solution does a pretty good job of finding previously unknown threats. It helps keep us aware of the kinds of threats that are out there and how we could potentially be impacted. Defender gives us a high level of information about unknown or zero-day threats. It's sometimes hard to gauge whether everything is there because the report is customized based on our infrastructure and what might be pertinent to us.

    They've always notified us when there was a zero-day threat. I think there have been a few instances where they altered us about a new threat before it was publicized, which is a good sign that they value us as a customer. They've warned us about something before releasing it to the wider public.

    Defender improved our SOC efficiency and saved us from having to add more personnel on the SOC side. It definitely improved that whole area, giving us the bandwidth to work on other things. Defender reduced our detection time because they are proactive about notifying us. I haven't seen too much of a time lag. There were a few instances, but it was never something critical where we had to call them out and ask if this was an issue or something. 

    Time-to-response has also gone down. The sooner we get the notification, the quicker we can jump on something. It helped us respond to any potential breach or attack faster. 

    It also saved us money because we don't need to deploy a second product to get some additional coverage. It also saved us from adding more security staff. Overall, it has had a positive financial impact on the company. 

    What is most valuable?

    The vulnerability reporting is helpful. When we initially deployed Defender, it reported many more threats than we currently see. It gave us insight into areas we had not previously considered, so we knew where we needed to act.

    Defender's ability to protect multi-cloud environments is essential for us. Our company's offerings are based on tasks, and these cloud service providers are critical infrastructure for us. If anything bad happens, it compromises our services. We need to understand and improve our posture.

    It also seamlessly integrates with Sentinel. It was fairly easy because we already leveraged Microsoft 365 earlier, so adding the Sentinel piece was pretty quick. It took a day to figure out and go ahead with the actual deployment. This integration with 365 and Sentinel provided timely intelligence over time. It becomes a problem if we don't get a threat notification in time. They are highly proactive about delivering that information in the initial alert and backing it up with more details as the situation develops.

    Microsoft has a relatively sizeable threat-hunting group constantly digging up many things. That helps because it gives us confidence if we face some threats that not many other players are exploring. With this particular product, we're confident they'll let us know where we stand. 

    What needs improvement?

    Microsoft sources most of their threat intelligence internally, but I think they should open themselves up to bodies that provide feel intelligence to build a better engine. There may be threats out there that they don't report because their team is not doing anything on that and they don't have arrangements with another party that is involved in that research. 

    Opening up to more collaboration with different entities in the private or public sector would help them feed more information to the customers and improve their security posture. More partnerships with other players who can feed them intelligence will help them develop the engine powering this product, ultimately benefiting every customer who uses it. 

    For how long have I used the solution?

    I have been using Defender for Cloud for about a year and a half. 

    What do I think about the stability of the solution?

    We've had a positive experience overall with Defender's unified portal. We seldom see any bugs. Sometimes, there is a lag in the reporting and some inconsistencies with our searches, but it's rare. There were some periods when their service was not running properly.

    While there hasn't been a significant outage, we've experienced some performance degradation where Microsoft notified us that they were having a problem. They informed us ahead of time when there are issues, but I've never had a complete outage thus far. 

    What do I think about the scalability of the solution?

    Defender for Cloud is scalable, given the licensing model. The performance doesn't suffer under a heavy workload. Many organizations I know have a massive workload, and they're still leveraging Defender without any issues. I rate Defender an eight out of ten for scalability.

    How are customer service and support?

    I rate Microsoft support an eight out of ten. Their support is great, so we have no complaints. They were responsive when we had issues.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We used SentinelOne only for endpoint threat detection. That's probably the closest competitor. We haven't used any other solutions besides that. 

    How was the initial setup?

    Setting up Defender for Cloud was relatively straightforward. We worked with a person assigned from Microsoft, who gave us a walkthrough of the steps we needed to take.

    Defender doesn't require much maintenance after deployment other than a few pieces of infrastructure we have internally. We need to monitor the solutions to check alerts and security advisories, but we've never had to deal with any maintenance.

    What about the implementation team?

    We ended up using a reseller. They were good. I used them for other vendors, and we've had a productive relationship working on multiple initiatives. This one was nothing new. 

    What's my experience with pricing, setup cost, and licensing?

    They have a free version, but the license for this one isn't too high. It's free to start with, and you're charged for using it beyond 30 days. Some other pieces of Defender are charged based on usage, so you will be charged more for a high volume of transactions. I believe Defender for Cloud is a daily charge based on Azure's App Service Pricing. 

    It's a negligible cost if your usage isn't that high, like a few cents. It's appealing for people to try it. If you don't plan to use it much, you won't have a high bill.

    Which other solutions did I evaluate?

    Other options were considered, but it came down to the level of value we would get from a holistic vulnerability intelligence product like Defender for Cloud. Also, Microsoft products are pervasive, with a much broader customer base. That was a deciding factor. We saw much more potential from Defender compared to the alternatives. Even though the competition solutions may have functioned better in terms of providing more intelligence, other factors weighed in favor of Microsoft Defender.

    What other advice do I have?

    I rate Microsoft Defender for Cloud an eight out of ten. I recommend doing a PoC. You shouldn't implement something after only reviewing the documentation and marketing materials. Put it through a PoC for a month at least to get a feel for how it functions and whether it satisfies your requirements. 

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Microsoft Azure
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free Microsoft Defender for Cloud Report and get advice and tips from experienced pros sharing their opinions.
    Updated: August 2026
    Buyer's Guide
    Download our free Microsoft Defender for Cloud Report and get advice and tips from experienced pros sharing their opinions.