

Anomali and Microsoft Defender for Office 365 are competitors in the cybersecurity space. Microsoft Defender for Office 365 is seen as superior due to its advanced protection features and integration within the Microsoft ecosystem.
Features: Anomali is valued for its advanced threat intelligence, analytics, and threat modeling capabilities. It also excels in integration via its API. Microsoft Defender for Office 365 offers built-in protection against phishing, safe links, and safe attachments. It provides seamless integration with Microsoft tools, robust information protection, and anti-phishing features.
Room for Improvement: Anomali could enhance ease of deployment and reduce technical setup demands. Its data set might be expanded to match competitors. Microsoft Defender for Office 365 would benefit from improved user interface intuitiveness and refined anti-phishing accuracy, and enhancements in machine learning functionalities.
Ease of Deployment and Customer Service: Microsoft Defender for Office 365 provides streamlined deployment and centralized management within the Microsoft ecosystem. Anomali requires more technical involvement during setup but offers dedicated support for its platform.
Pricing and ROI: Anomali involves higher initial setup costs but offers significant ROI through its threat intelligence capabilities. Microsoft Defender for Office 365 is cost-effective within its ecosystem, balancing pricing with integration benefits to enhance ROI by reducing threat exposure.
Analyst productivity has improved significantly, with hours saved because of automation and AI-driven work that Anomali performs.
Anomali provides us with a very cost-effective value compared to the market, and I would rate it ten out of ten for return on investment metrics.
There is a return on investment concerning time and effort saved by 40% after implementing Anomali.
It has also decreased our time to detection and response by about 15 to 20 percent.
Overall, cost of owning and operating our system goes down.
It's hard to quantify the return on investment we've seen from Microsoft Defender for Office 365.
They have strong onboarding and deployment assistance, provide a dedicated technical account manager for large customers, and engage in regular product updates and customer interaction.
The technical support at Anomali is excellent.
It doesn't seem very professional how they're handling support anymore.
Over the past two years, there have been no critical problems.
we opened tickets, and they typically resolve them quickly.
With a subscription for Microsoft Defender for Office 365, it is an eight. Without it, it is a six.
The scalability is massive, allowing us to store millions of indicators.
I believe Anomali's scalability is good; whether it is an organization for ten people or one hundred thousand people, the job a threat intel platform has to do will be the same.
Anomali's scalability is impressive as a mature platform capable of processing large amounts of threat intelligence and indicators of compromise data.
We have never faced scalability problems, and Microsoft manages it effectively.
Microsoft Defender for Office 365 scales transparently for us, as we grew from 1,000 users to 3,000 users, and we didn't notice much difference.
Microsoft Defender for Office 365 scales with the growing needs of my company well.
From a reliability perspective, Anomali consistently injects threat feeds, works on automation, performs reliable API integrations, and supports enterprise scale globally.
For example, while Microsoft allows ample time for users to adapt to deprecated features, Anomali only gave us three weeks before switching, so they need to be more cognizant of customer use cases from their engineering side.
The good thing is that they have a health check page, and if any issues arise, they notify us.
I would rate the stability of Microsoft Defender for Office 365 as 10 over 10 because it's highly available, it works, and it does the job it is meant to do.
I have not experienced any downtime, crashes, or performance issues because of Defender.
The solution is stable, as we have been using it for the past two years.
Combining all aliases into a coherent solution would be beneficial, as we had to review each individual source ourselves.
Anomali should increase their capability to fetch details from various dark web solutions where threat actors post compromised credentials.
Anomali's ability to correlate and integrate different Threat Intel platforms, such as Mandiant and PolySwarm, is another valuable feature, removing duplicacy and enabling the application of specific IOCs across various security controls.
The main area for improvement is simplifying the implementation and rollout process.
Microsoft could improve by offering recommendations for domain spoofing attacks, especially scenarios where DNS records like SPF, DKIM, and DMARC are not properly published.
There is a different console for different things; I just want one consolidated console.
Pricing and licensing are good, but the costs for purchasing threat feeds are somewhat complicated and a bit on the higher side.
My experience with pricing, setup cost, and licensing is that there are not many follow-ups, but once we interacted with the product team or the leadership of Anomali, they managed a lot with us, and it all paid off to reach a conclusion that we would continue with this product.
We've likely saved 30% of costs.
Money-wise, it is a part of the Office 365 suite, making it slightly more expensive compared to Trend Micro.
Microsoft is quite affordable with a lot of features available for any size organization.
Regarding integration, Anomali has capabilities to integrate with different downstream applications such as Palo Alto, allowing us to create playbooks to block domains, URLs, or IPs directly within the firewall.
Correlating IOCs with the telemetry data we are ingesting from our data sources allows us to pull monthly reports identifying how many assets and users interacted with malicious content, giving insight into whether communications failed or users accessed restricted content, providing complete visibility of the IOCs traveling throughout our environment.
It aggregates intelligence from hundreds of sources, automatically de-duplicates, applies risk scoring, applies context, and reduces much manual effort.
It ranks the threats and allows us to prioritize those hitting us the hardest, such as email threats.
It provides end-to-end visibility on email threats such as phishing, extending beyond Exchange Online Protection.
The value of the DLP feature is significant to us because we have internal data, sometimes sensitive, and the users may not always be aware of security and privacy, which might lead them to send out information mistakenly to external parties.
| Product | Mindshare (%) |
|---|---|
| Microsoft Defender for Office 365 | 6.5% |
| Anomali | 3.4% |
| Other | 90.1% |


| Company Size | Count |
|---|---|
| Small Business | 3 |
| Midsize Enterprise | 1 |
| Large Enterprise | 14 |
| Company Size | Count |
|---|---|
| Small Business | 24 |
| Midsize Enterprise | 11 |
| Large Enterprise | 32 |
Anomali delivers user-friendly cyber threat intelligence, offering concise insights with robust capabilities for evolving scenarios.
Anomali offers a powerful platform for cyber threat intelligence, allowing organizations to efficiently stream and analyze threat feeds. It excels in threat modeling, prioritizing intelligence, and supporting large-scale automation through its API, fostering a proactive security approach.
What are Anomali's Key Features?Anomali serves as a crucial tool for threat intelligence in industries ranging from finance to healthcare. Organizations stream threat feeds into Anomali to correlate and aggregate data, enhancing security measures and facilitating thorough threat investigations. Its adaptability makes it suitable across different sectors.
Microsoft Defender for Office 365 offers real-time email security, enhancing threat detection through integration within the Microsoft ecosystem. Its user-friendly interface and central management streamline operations, providing robust protection against phishing, ransomware, and malware.
Defender for Office 365 is focused on efficiently securing email communication by safeguarding against phishing, malware, and spam threats. With its strong integration with other Microsoft services, it is tailored to improve endpoint security and identity protection. Its centralized management tools simplify threat prioritization, while the automated threat response capabilities ensure swift actions against potential risks. Organizations leverage its capabilities to efficiently manage their cybersecurity efforts, particularly in remote work environments, while maintaining a secure system across Office 365 applications and Azure-hosted services.
What are the key features?Implementations of Defender for Office 365 vary across industries, optimizing email security for sectors such as finance, healthcare, and education. In finance, it aids in protecting sensitive financial data from phishing and fraud. Healthcare benefits from secure communications, ensuring patient data privacy. Educational institutions use it to maintain secure virtual learning environments against cyber threats.
We monitor all Advanced Threat Protection (ATP) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.