Try our new research platform with insights from 80,000+ expert users

Change Auditor for Active Directory vs CrowdStrike Falcon comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Change Auditor for Active D...
Average Rating
9.0
Reviews Sentiment
6.9
Number of Reviews
2
Ranking in other categories
Active Directory Management (7th)
CrowdStrike Falcon
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
137
Ranking in other categories
Security Information and Event Management (SIEM) (6th), Endpoint Protection Platform (EPP) (1st), Threat Intelligence Platforms (TIP) (1st), Endpoint Detection and Response (EDR) (1st), Extended Detection and Response (XDR) (1st), Attack Surface Management (ASM) (1st), Identity Threat Detection and Response (ITDR) (1st), AI-Powered Cybersecurity Platforms (1st)
 

Mindshare comparison

While both are Security Software solutions, they serve different purposes. Change Auditor for Active Directory is designed for Active Directory Management and holds a mindshare of 6.8%, down 7.6% compared to last year.
CrowdStrike Falcon, on the other hand, focuses on Extended Detection and Response (XDR), holds 10.5% mindshare, down 17.8% since last year.
Active Directory Management Market Share Distribution
ProductMarket Share (%)
Change Auditor for Active Directory6.8%
ManageEngine ADManager Plus12.6%
One Identity Active Roles10.8%
Other69.8%
Active Directory Management
Extended Detection and Response (XDR) Market Share Distribution
ProductMarket Share (%)
CrowdStrike Falcon10.5%
Wazuh7.9%
Darktrace6.1%
Other75.5%
Extended Detection and Response (XDR)
 

Featured Reviews

reviewer2794194 - PeerSpot reviewer
Sr Mgr Cyber Defense at a manufacturing company with 10,001+ employees
Auditing changes has become faster and now uncovers misconfigurations within minutes
The best features Change Auditor for Active Directory offers are that it's lightweight and easy to understand. You don't have to memorize event IDs since it's in English. What makes Change Auditor for Active Directory lightweight and easy to understand in my experience is that it doesn't require the events to record to the domain controllers. Therefore, I can focus just on the event types without having to turn up detailed logging on my DCs. Change Auditor for Active Directory has positively impacted my organization by helping us respond to audits very quickly to show that we had evidence of who was making the changes and match them up to the ticket request and who approved it. After implementing Change Auditor for Active Directory, it has allowed us to answer questions literally in minutes, whereas it would have taken us half a day to a day before.
Waleed Omar - PeerSpot reviewer
Information Security Specialist at Arab Open University
Provides effective real-time threat detection with potential for cost optimization
Some features such as device control, firewall management, and file analysis are standalone products that we need to purchase separately. If these features came out of the box within the product, it would be much more beneficial for us. Other providers such as SentinelOne include these features in their base product. We attended a CrowdStrike Falcon event where they discussed some shallow AI features, but we cannot see these in our panel yet. We work with different solutions such as Darktrace and SocRadar, where AI features are automatically displayed in our dashboards after release. However, for CrowdStrike Falcon, we cannot see these features.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Change Auditor for Active Directory has positively impacted my organization by helping us respond to audits very quickly to show that we had evidence of who was making the changes and match them up to the ticket request and who approved it."
"The most valuable features are the ability to protect Active Directory accounts and groups, and the real-time notifications that help manage Active Directory more effectively."
"The ability to execute real-time response, or, that you can connect to the agent and see exactly what processes are operating, is the most important feature of this solution."
"It helps to prevent unauthorized access or identity theft from external sites. If your identity is stolen, you can ban it."
"Falcon has the capacity to identify potential problems quickly. The administrator can deploy the agent, and the users cannot change it. This assures you that the agent remains on this device. Also, the agent can act preemptively to provide alerts about potential problems."
"CrowdStrike Falcon is a very light solution. It does not use too much processor or RAM."
"The most valuable aspects of CrowdStrike Falcon for me are its device observability, identification, and software and OS recognition."
"CrowdStrike Falcon has done an excellent job at detecting breaches. It has allowed us to stay in business and keep our systems up."
"This solution has made the lives of the IT staff much easier, compared to the previous one."
"The CS falcon agent is a lightweight agent compared with other agents of EDR products."
 

Cons

"Areas that could be improved include having more management capabilities with command-line scripts and more flexibility in general."
"Change Auditor for Active Directory could be improved if the client were more flexible when installed, so if I upgrade the server, I wouldn't have to replace the clients at the same time."
"CS Falcon sensing capabilities for non-domain machines should be enhanced since the agent doesn't detect the neighbor's IP Address and/or any anomaly which was identified in the network for the non-domain machine."
"Whenever there is a feature release (upgrade) where we push to all the endpoints, it causes something to be blocked without us knowing."
"They don't really have anything when it comes to scanning attachments."
"The portal can be clunky to navigate at times and has room for improvement."
"Tighter integration around XDR could be included."
"Sometimes CrowdStrike changes the GUI, and they need to be better at informing us and providing guidance concerning that."
"CrowdStrike Falcon needs to improve their host management system."
"It would be nice if they did have some sort of Active Directory tie-in, whether that be Azure or on-prem. Sometimes, it is difficult for us to determine if we are missing any endpoints or servers in CrowdStrike. We honestly don't have a great inventory, but it would be nice if CrowdStrike had a way to say this is everything in your environment, Active Directory-wise, and this is what doesn't have sensors. They try to do that now with a function that they have built-in, but I have been unsuccessful in having it help us identify what needs a sensor. So, better visibility of what doesn't have a sensor in our environment would be helpful."
 

Pricing and Cost Advice

Information not available
"Purchasing the product through the AWS Marketplace is just a click away. Since we were using the on-premise version of the product, we continued on the cloud by purchasing it through the AWS Marketplace."
"CrowdStrike is a reasonably priced tool."
"With respect to pricing, my suggestion to others is to evaluate the environment and purchase what you need."
"This solution has a very competitive price."
"We pay 40,000 dirhams per 100 users."
"All I can say about the licensing cost is that it's negotiable."
"Pricing and licensing seem to be in line with what they offer. We are a smaller organization, so pricing is important. Obviously, we would make a business case if it is something we really needed or felt that we needed. So, the pricing is in line with what we are getting from a product standpoint."
"It is expensive compared to SentinelOne, but as the market leader, it is worth it."
report
Use our free recommendation engine to learn which Active Directory Management solutions are best for your needs.
881,082 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Computer Software Company
11%
Insurance Company
9%
Manufacturing Company
9%
Computer Software Company
11%
Financial Services Firm
10%
Manufacturing Company
9%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
No data available
By reviewers
Company SizeCount
Small Business46
Midsize Enterprise34
Large Enterprise62
 

Questions from the Community

What is your experience regarding pricing and costs for Quest Change Auditor for Active Directory?
The price can vary based on the components purchased and the needs and budget of the organization. It is considered a bit pricey, especially for smaller companies.
What needs improvement with Quest Change Auditor for Active Directory?
Areas that could be improved include having more management capabilities with command-line scripts and more flexibility in general. Often this type of tool could benefit from better scripting capab...
What is your primary use case for Quest Change Auditor for Active Directory?
The primary use case is to manage human errors, like protecting identities from being modified by the software, and to audit security. This includes monitoring high-privilege accounts and having th...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions that are very scalable, secure, and user-friendly. Cortex XDR by Palo Alto offers ...
How does Crowdstrike Falcon compare with Darktrace?
Both of these products perform similarly and have many outstanding attributes. CrowdStrike Falcon offers an amazing user interface that makes setup easy and seamless. CrowdStrike Falcon offers a cl...
How does Microsoft Defender for Endpoint compare with Crowdstrike Falcon?
The CrowdStrike solution delivers a lot of information about incidents. It has a very light sensor that will never push your machine hardware to "test", you don't have the usual "scan now" feature ...
 

Also Known As

No data available
CrowdStrike Falcon XDR, CrowdStrike Falcon Threat Intelligence, CrowdStrike Identity Protection, CrowdStrike Falcon Surface, CrowdStrike Falcon Platform
 

Overview

 

Sample Customers

American Airlines, Bank of America, BARCLAYS, ebay, Ford, intel, MARS, MERCK, Microsoft, UBER, VISA
Information Not Available
Find out what your peers are saying about One Identity, Microsoft, Netwrix and others in Active Directory Management. Updated: December 2025.
881,082 professionals have used our research since 2012.