Try our new research platform with insights from 80,000+ expert users

CyberArk Endpoint Privilege Manager vs Microsoft Defender for Business comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.9
CyberArk Endpoint Privilege Manager enhances security and reduces costs, despite challenges in quantifying precise ROI, with immediate benefits.
Sentiment score
8.2
Microsoft Defender for Business boosts ROI with increased productivity, cost savings, improved security, and enhanced business opportunities.
Deploying CyberArk Endpoint Privilege Manager has secured the infrastructure, which saves money, time, and resources.
Using Microsoft Defender for Business results in cost reductions as it consolidates various features under one product, saving around 20% to 30% of the budget.
It is pretty good because it offers various features such as Exchange, OfficeSuite, OneDrive, and SharePoint.
The value I see in Microsoft Defender for Business is in its ability to track and respond to application usage and security threats through its CASB and automation features, which are cost-beneficial.
 

Customer Service

Sentiment score
6.7
CyberArk Endpoint Privilege Manager support varies; effectiveness depends on user experience, with inconsistent response times and complex contact methods.
Sentiment score
5.4
Microsoft Defender for Business offers prompt support but lacks efficiency, with slower resolutions and mixed user satisfaction ratings.
They respond immediately to our inquiries, resolve issues promptly, and provide valuable guidance, especially in critical situations.
We engage them when needed and receive prompt responses that typically resolve our issues.
Earlier, we received support for normal tickets within a day, but now it takes one or two days to resolve issues.
It is rated ten out of ten for its quality and assistance.
The onboarding support is exceptional, ensuring seamless integration and implementation.
Faster support is needed for endpoint security solutions.
 

Scalability Issues

Sentiment score
7.7
CyberArk Endpoint Privilege Manager scales efficiently for small to massive deployments, supporting cloud and on-premise solutions with ease.
Sentiment score
8.1
Microsoft Defender for Business is praised for scalability, with high ratings, despite configuration challenges across sectors like IT and government.
We can set permissions per team or department, allowing some teams to elevate specific applications while others have different permissions.
CyberArk Endpoint Privilege Manager is quite scalable.
The available reports and other security tools assist in scaling it according to my organization's needs.
The cloud-based nature of the solution ensures high scalability.
The scalability of Microsoft Defender for Business is rated as ten, indicating it is very scalable.
In terms of scalability, I find Microsoft Defender for Business to be good and reliable.
 

Stability Issues

Sentiment score
8.2
CyberArk Endpoint Privilege Manager is stable with high performance but occasionally experiences downtime during upgrades, especially on non-Windows systems.
Sentiment score
7.8
Microsoft Defender for Business is stable and reliable, with minimal downtime and occasional bugs, maintaining user satisfaction.
It is a robust solution that has effectively supported our environment without major issues.
Since implementing it, we have not experienced any outages or stability issues.
CyberArk Endpoint Privilege Manager offers multiple options for creating and stopping policies.
No customer complaints about its functionality or reliability.
Although it generally works, there are occasional issues and errors that sometimes require a complete system format to rectify.
Threat detection capabilities could be improved.
 

Room For Improvement

CyberArk Endpoint Privilege Manager needs user-friendly enhancements, better integration, faster support, pricing adjustments, and improved threat detection tools.
Microsoft Defender for Business needs enhancements in reporting, integration, support efficiency, and pricing, with user-friendliness and communication issues.
CyberArk Endpoint Privilege Manager could be improved by simplifying the administration process, specifically when setting up policies and applications.
Currently, no user-based policy option is available inside the EPM console.
Some features provided in the self-hosted version of EPM are not supported in the software as a service version, like connection to some analysis applied by Palo Alto.
Microsoft should provide batch management solutions with the application, integrating pass management with roles.
Features related to Advanced Persistent Threat detection vectors and cyber kill chain integrations are not available out-of-the-box.
There can be improvements in the user interface to make it more intuitive.
 

Setup Cost

CyberArk Endpoint Privilege Manager is costly, especially for small businesses, with potential discounts for large enterprises.
Microsoft Defender for Business offers cost-effective pricing within Office 365 Premium, valued for features and nonprofit discounts, despite some competitors.
CyberArk Endpoint Privilege Manager is slightly expensive, but costs can be negotiated to become more competitive.
CyberArk Endpoint Privilege Manager is costly compared to other solutions.
Single-year pricing remains good.
The pricing is quite affordable at the enterprise level with no extra expenses noted.
The package with Business Premium is good for what you get for the price.
 

Valuable Features

CyberArk Endpoint Privilege Manager ensures security and compliance through admin control, ransomware protection, and advanced credential analytics.
Microsoft Defender for Business provides scalable, cost-effective security with AI-powered threat detection, easy integration, and user-friendly features.
CyberArk Endpoint Privilege Manager effectively reduces malicious content in applications by allowing us to identify and block dangerous applications.
CyberArk Endpoint Privilege Manager enhances computer security by providing minimal access, effectively preventing ransomware attacks.
The most valuable feature is the ability to control users with admin rights.
The threat detection capabilities are robust, with a dedicated research team and a continuously updated threat feed.
Its vulnerability management is regarded as one of the best in the industry.
The most effective features of Microsoft Defender for Business include its threat detection and response capabilities in managing vulnerabilities and ransomware attacks.
 

Categories and Ranking

CyberArk Endpoint Privilege...
Average Rating
8.2
Reviews Sentiment
6.8
Number of Reviews
35
Ranking in other categories
Endpoint Compliance (4th), Privileged Access Management (PAM) (3rd), Anti-Malware Tools (5th), Application Control (5th), Ransomware Protection (7th)
Microsoft Defender for Busi...
Average Rating
7.8
Reviews Sentiment
7.1
Number of Reviews
17
Ranking in other categories
Endpoint Protection Platform (EPP) (25th), Microsoft Security Suite (15th)
 

Mindshare comparison

While both are Endpoint Security solutions, they serve different purposes. CyberArk Endpoint Privilege Manager is designed for Privileged Access Management (PAM) and holds a mindshare of 3.5%, down 3.6% compared to last year.
Microsoft Defender for Business, on the other hand, focuses on Endpoint Protection Platform (EPP), holds 1.9% mindshare, up 1.2% since last year.
Privileged Access Management (PAM)
Endpoint Protection Platform (EPP)
 

Featured Reviews

Sumit Chavan - PeerSpot reviewer
Helps secure the infrastructure and control users with admin rights
There are many features that are currently missing. A customization option is required for certain policies. For instance, if we need to stop PowerShell scripting, we have to create a different policy for that. Being able to create a sub-level policy within a top-level policy would be good. Currently, no user-based policy option is available inside the EPM console. We can only create computer-based policies. The database is available, but there is a drawback in not being able to create local groups on the EPM console. We only have to depend on Active Directory. This limits infrastructure security as we depend on the Active Directory team to manage user groups. If they remove any users, we lose control. If we could create groups locally and block them or set specific policies, we would have more control. Local endpoint management is missing from the EPM site. Moreover, there is an issue with policies not running as expected when we make enhancements. We have to find multiple ways to whitelist applications or enhance policies.
Syed Abid  - PeerSpot reviewer
Advanced threat protection secures diverse workloads with cost-effective deployment
If I need logs and don't have local storage bundled with Defender, I need to add workspace and log analytics, which is costly for storing logs of 2 GB, 5 GB, 10 GB. A default storage of 5 GB for logs should be included with Defender. There are limitations in whitelisting folders and files, and the whitelisting feature for Defender threat protection was deprecated. A straightforward feature for this should be added.
report
Use our free recommendation engine to learn which Privileged Access Management (PAM) solutions are best for your needs.
845,485 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Computer Software Company
14%
Manufacturing Company
11%
Government
8%
Computer Software Company
19%
Comms Service Provider
7%
Retailer
6%
Government
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Looking for recommendations and a pros/cons template for software to detect insider threats
This is an inside-out --- outside-in --- inside-in question, as an insider can be an outsider as well. There is no short answer other than a blend of a PAM tool with Behavioral Analytics and Endpo...
What do you like most about CyberArk Endpoint Privilege Manager?
The most valuable feature of the solution is its performance.
What is your experience regarding pricing and costs for CyberArk Endpoint Privilege Manager?
CyberArk Endpoint Privilege Manager is slightly expensive, but costs can be negotiated to become more competitive.
What do you like most about Microsoft Defender for Business?
A few things are valuable. One is the alerting we see when any kind of intrusion is happening, any kind of malware is being deployed across the endpoints, or any kind of suspicious activity is goin...
What is your experience regarding pricing and costs for Microsoft Defender for Business?
Microsoft Defender for Business offers the best pricing option in the market and is very cost-effective.
What needs improvement with Microsoft Defender for Business?
The areas where Microsoft Defender for Business could improve include the support, installation process, and wiki. I should be able to find solutions to issues quickly without having to delve too d...
 

Also Known As

Viewfinity
No data available
 

Overview

Find out what your peers are saying about CyberArk, Delinea, One Identity and others in Privileged Access Management (PAM). Updated: March 2025.
845,485 professionals have used our research since 2012.