

Microsoft Defender for Cloud Apps and Anomali are competing in the cybersecurity space, focusing on threat detection and cloud app security. While Anomali excels in specialized threat intelligence, Microsoft Defender for Cloud Apps is more cost-effective and integrates seamlessly with Microsoft services, offering strong pricing and support.
Features:Microsoft Defender for Cloud Apps offers comprehensive app discovery, data protection, and smooth threat detection. It integrates seamlessly with Microsoft services, providing a robust solution for organizations using Microsoft. Anomali excels in threat intelligence, predictive analytics, and integration with existing security infrastructures, offering an edge in proactive threat management.
Room for Improvement:Microsoft Defender for Cloud Apps could benefit from improvements in threat intelligence analysis and predictive analytics to better compete with Anomali. Additionally, enhancing proactive threat management capabilities would make it even more competitive. Anomali, on the other hand, could improve integration with cloud services and expand documentation to facilitate easier deployment. Streamlining customer experiences with tighter cloud integration could also be beneficial.
Ease of Deployment and Customer Service:Microsoft Defender for Cloud Apps is known for its smooth deployment and extensive documentation, making integration with Microsoft ecosystems straightforward. Anomali offers flexible deployment options and dedicated support services, though Microsoft's integration with its ecosystem gives it an advantage for organizations already using Microsoft solutions.
Pricing and ROI:Microsoft Defender for Cloud Apps is praised for competitive pricing within Microsoft 365 environments, offering considerable ROI by maximizing existing investments. Anomali, while having a higher initial cost, provides significant returns through its advanced threat intelligence capabilities, justifying its pricing for those needing specialized threat management.
Analyst productivity has improved significantly, with hours saved because of automation and AI-driven work that Anomali performs.
Anomali provides us with a very cost-effective value compared to the market, and I would rate it ten out of ten for return on investment metrics.
There is a return on investment concerning time and effort saved by 40% after implementing Anomali.
The biggest return on investment so far has been visibility, knowing what we have in our environment.
As a small team, Microsoft Defender for Cloud Apps allowed us to manage systems with just one or two people.
We have at least saved the costs we had from the Netskope solution this year.
They have strong onboarding and deployment assistance, provide a dedicated technical account manager for large customers, and engage in regular product updates and customer interaction.
The technical support at Anomali is excellent.
It doesn't seem very professional how they're handling support anymore.
Their customer service is pretty good, but it's frustrating to go through three or four channels before reaching the right person.
The support is excellent, and the speed of response is commendable.
There were instances where the engineers were knowledgeable and helpful, but at other times it felt like a ping pong game, with unnecessary transfers until the right person was found.
The scalability is massive, allowing us to store millions of indicators.
I believe Anomali's scalability is good; whether it is an organization for ten people or one hundred thousand people, the job a threat intel platform has to do will be the same.
Anomali's scalability is impressive as a mature platform capable of processing large amounts of threat intelligence and indicators of compromise data.
For what I know about the log collector and how much data it can take in, it is super scalable and capable of handling high workloads.
Microsoft Defender for Cloud Apps is very scalable, provided you have the right subscription.
In my experience, Microsoft Defender for Cloud Apps is good enough for small to medium businesses.
From a reliability perspective, Anomali consistently injects threat feeds, works on automation, performs reliable API integrations, and supports enterprise scale globally.
For example, while Microsoft allows ample time for users to adapt to deprecated features, Anomali only gave us three weeks before switching, so they need to be more cognizant of customer use cases from their engineering side.
The good thing is that they have a health check page, and if any issues arise, they notify us.
I would rate it a ten because I have not experienced any stability issues so far with Defender for Cloud Apps.
I would assess the stability and reliability of Microsoft Defender for Cloud Apps as stable
My impression on the stability and reliability of Microsoft Defender for Cloud Apps is that it is very stable.
Combining all aliases into a coherent solution would be beneficial, as we had to review each individual source ourselves.
Anomali should increase their capability to fetch details from various dark web solutions where threat actors post compromised credentials.
Anomali's ability to correlate and integrate different Threat Intel platforms, such as Mandiant and PolySwarm, is another valuable feature, removing duplicacy and enabling the application of specific IOCs across various security controls.
For data loss prevention, it would be useful to be able to drill down into the kind of data being transferred over CloudApp.
Defender typically connects to Entra ID, but we have local users on the cloud for database access, SSH, or RDS, and there is nothing produced by Defender regarding those local IAM users.
Microsoft Defender for Cloud Apps would benefit if Microsoft allows users to fine-tune false positives, enabling us to dismiss alerts or make adjustments so that such things don't trigger multiple times in the future.
Pricing and licensing are good, but the costs for purchasing threat feeds are somewhat complicated and a bit on the higher side.
My experience with pricing, setup cost, and licensing is that there are not many follow-ups, but once we interacted with the product team or the leadership of Anomali, they managed a lot with us, and it all paid off to reach a conclusion that we would continue with this product.
The pricing for Microsoft Defender for Cloud Apps is acceptable.
My organization is currently revisiting pricing, but previously, the cost was a bit expensive, yet comparable to other solutions with similar functionalities and features.
It's not the cheapest, but also not the most expensive, placing it in the mid-level range.
Regarding integration, Anomali has capabilities to integrate with different downstream applications such as Palo Alto, allowing us to create playbooks to block domains, URLs, or IPs directly within the firewall.
Correlating IOCs with the telemetry data we are ingesting from our data sources allows us to pull monthly reports identifying how many assets and users interacted with malicious content, giving insight into whether communications failed or users accessed restricted content, providing complete visibility of the IOCs traveling throughout our environment.
It aggregates intelligence from hundreds of sources, automatically de-duplicates, applies risk scoring, applies context, and reduces much manual effort.
It provides excellent suggestions and options for configuration; for example, it can track suspicious files getting uploaded to cloud resources on Azure based on their signatures, generating alerts for those files.
The product recommends things that need to be blocked and allows for dynamic configuration, which cuts down on potential issues that might arise from going through lists and understanding what needs to be blocked.
The ability to sanction unsanctioned apps using Secure Score benchmarking, included in Cloud, is also beneficial.
| Product | Mindshare (%) |
|---|---|
| Microsoft Defender for Cloud Apps | 2.0% |
| Anomali | 3.4% |
| Other | 94.6% |


| Company Size | Count |
|---|---|
| Small Business | 2 |
| Midsize Enterprise | 1 |
| Large Enterprise | 14 |
| Company Size | Count |
|---|---|
| Small Business | 15 |
| Midsize Enterprise | 13 |
| Large Enterprise | 19 |
Anomali delivers user-friendly cyber threat intelligence, offering concise insights with robust capabilities for evolving scenarios.
Anomali offers a powerful platform for cyber threat intelligence, allowing organizations to efficiently stream and analyze threat feeds. It excels in threat modeling, prioritizing intelligence, and supporting large-scale automation through its API, fostering a proactive security approach.
What are Anomali's Key Features?Anomali serves as a crucial tool for threat intelligence in industries ranging from finance to healthcare. Organizations stream threat feeds into Anomali to correlate and aggregate data, enhancing security measures and facilitating thorough threat investigations. Its adaptability makes it suitable across different sectors.
Microsoft Defender for Cloud Apps is a robust tool for shadow IT detection, cloud integration, and threat detection, enhancing security management with capabilities in auditing and data protection.
Microsoft Defender for Cloud Apps strengthens cloud security by providing comprehensive insights into user activities, seamlessly integrating with Microsoft security products and platforms like SharePoint, Teams, and OneDrive. Its investigative capabilities enhance threat detection, while real-time alerts and policy applications improve security posture. Organizations benefit from its monitoring, auditing, and privileged identity management features that contribute to enhanced security management and data protection.
What are the key features of Microsoft Defender for Cloud Apps?Microsoft Defender for Cloud Apps implementation varies across industries, crucial for sectors needing stringent data protection and compliance, like finance and healthcare. Firms use it to monitor user activity, enforce data loss prevention policies, and ensure security across multi-cloud environments while integrating with Azure services for comprehensive threat management. These implementations are particularly beneficial in improving compliance efforts and protecting sensitive data.
We monitor all Advanced Threat Protection (ATP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.