No more typing reviews! Try our Samantha, our new voice AI agent.

Microsoft Defender for Identity vs Sweet Security comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.3
Qualys TotalCloud enhances efficiency and automation, achieving up to 40% cost savings and over 50% improved asset scanning.
Sentiment score
4.8
Microsoft Defender for Identity enhances threat detection, reduces efforts, minimizes risks, and optimizes costs despite varied ROI assessments.
Sentiment score
5.6
Sweet Security enhances threat response, resource efficiency, and ROI by improving risk prioritization and visibility across multi-cloud environments.
We are able to scan all our assets with less human intervention and achieve overall effective outcomes.
Dns architect at a tech consulting company with 1,001-5,000 employees
It has saved about 90% of our time.
Senior Consultant at a consultancy with 10,001+ employees
TotalCloud has generated overall savings of 30 to 40 percent across various departments.
Security Manager at a consultancy with 10,001+ employees
The ROI is that we are not waiting for a breach but being proactive rather than reactive.
Partner Account Manager at a wholesaler/distributor with 51-200 employees
 

Customer Service

Sentiment score
6.7
Qualys TotalCloud's customer service is praised for responsiveness despite occasional delays, with ratings from seven to ten.
Sentiment score
6.4
Microsoft Defender for Identity offers knowledgeable support, yet response times can vary, especially with complex issues or initial contacts.
Sentiment score
7.9
Sweet Security offers exceptional customer support, featuring quick issue resolution, accessible account managers, and high user satisfaction.
They are helpful, respond to my queries, and can answer any question.
Developer at a consultancy with 10,001+ employees
Qualys's tech support is highly responsive, providing multiple ways to interact with them.
Service Manager, Security Operations at CDA IT SOLUTIONS
Qualys' customer service provides quality answers, but the response time is long, even though it is within the SLA.
Works at a consultancy with 10,001+ employees
Generally, the support is more effective than other providers like Oracle.
Owner at Alopex ONE UG
The quality of support is very good, but troubleshooting can take time due to complex setups and the need to provide many logs.
Cloud Security & Governance at a financial services firm with 10,001+ employees
The people I normally use for support are very knowledgeable, especially when they help remote in and get to where I need to go and show me much faster and help me understand what I should be doing.
Technology Coordinator at a educational organization with 501-1,000 employees
They are there immediately, providing us with the best technical people, solving any issue we had.
Director of Security Operations at a tech vendor with 501-1,000 employees
They gave me a trial period, did multiple follow-ups, and were reviewing themselves the findings to actually understand how their product is performing.
Infrastructure & Dev Ops Lead at Babylon Labs
I would rate customer support a nine out of ten because they maintain a competitive price, offer trial periods, provide follow-up, are very responsive, and are effectively hands-on in assisting and offering prompt service and support.
Partner Account Manager at a wholesaler/distributor with 51-200 employees
 

Scalability Issues

Sentiment score
7.4
Qualys TotalCloud is highly scalable and adaptable, efficiently supporting varied environments and large-scale deployments with robust performance.
Sentiment score
7.2
Microsoft Defender for Identity is highly scalable and adaptable, excelling in large enterprises with efficient cloud-based processing.
Sentiment score
7.2
Sweet Security is ideal for small to medium businesses in multi-cloud environments, though large enterprises may face interface issues.
We started our organization about nine months back. We started with about 30 users, and we now have more than 100 users.
CIO at a venture capital & private equity firm with 11-50 employees
Our organization currently uses it to manage over 1200 web applications.
Analyst, Information Security at Infosys
It is absolutely scalable, and I would rate its scalability as nine out of ten.
retired at a consultancy with 10,001+ employees
In a Microsoft-centric organization, especially with Azure infrastructure and Office 365, Microsoft Defender for Identity is scalable.
Cloud Security & Governance at a financial services firm with 10,001+ employees
We don't need to scale it since it's all SaaS.
Cloud and compute team leader at a manufacturing company with 1,001-5,000 employees
We are a robust enterprise with thousands of assets in the cloud or tens of thousands.
Director of Security Operations at a tech vendor with 501-1,000 employees
The user interface that I see doesn't make me very confident that I will be able to extract information in case I had hundreds or thousands of Kubernetes clusters or hundreds or thousands of hosts.
Infrastructure & Dev Ops Lead at Babylon Labs
 

Stability Issues

Sentiment score
8.4
Qualys TotalCloud is stable and reliable, offering 99.9% uptime with quick support for minor issues and transparent maintenance updates.
Sentiment score
7.1
Microsoft Defender for Identity is highly stable, reliable, with minimal downtime; occasional issues require support for agent redeployment.
Sentiment score
8.9
Sweet Security offers high stability and user satisfaction with minimal issues, reliable operations, and seamless cloud-native performance.
Overall, the support provided has been excellent.
Analyst, Information Security at Infosys
It has a lot of scanning mechanisms, which are agentless APIs, eBPF, and cloud agents, that are highly reliable.
Sr Security Engineer at a tech vendor with 5,001-10,000 employees
It is a stable solution, which is why we chose it.
CIO at a venture capital & private equity firm with 11-50 employees
Microsoft Defender for Identity is quite robust and built on Azure hyperscale infrastructure, with a 99% availability.
Cloud Security & Governance at a financial services firm with 10,001+ employees
We do not see any issues with the stability of Microsoft Defender for Identity.
Deputy Manager at Servion Global Solutions
Having recently started using it, reliability is affirmed, but manual investigation is often performed to verify if alerts identified by auto-remediation are accurate.
Instrumentation Engineer at Toyo Engineering Corp
Sweet Security delivers cloud-native service updates seamlessly and requires very minimal operational effort.
SOC L2 Analyst at a tech services company with 51-200 employees
I would rate the stability of Sweet Security a ten out of ten.
Works at a tech services company with 201-500 employees
We have never had any issues with stability.
Director of Security Operations at a tech vendor with 501-1,000 employees
 

Room For Improvement

Qualys TotalCloud requires UI improvements, better cloud integration, enhanced support, and optimized reporting, onboarding, and vulnerability detection.
Microsoft Defender for Identity needs improvements in alert accuracy, UI/UX, asset integration, automation, anomaly detection, and third-party integration.
Sweet Security needs real-time blocking, third-party integration, detailed documentation, and customization in alerts, UI, reporting, and playbooks.
Ideally, the scanner should automatically detect and scan all subdomains, even if not explicitly defined, ensuring comprehensive vulnerability assessment.
Analyst, Information Security at Infosys
Ideally, updates should be more immediate, enabling quicker implementation of solutions.
Project Lead at Persistent Systems
Our goal is to integrate all these functions into Qualys, creating a single dashboard for comprehensive security monitoring and management.
Senior Information Security Engineer at a consultancy with 10,001+ employees
If Microsoft could develop a feature that indicates when impossible travel is caused by VPN connections, it would prevent unnecessary password resets and session disruptions, especially for VIP users in organizations.
CyberSecurity Engineer | Information Security Management at Self Employed
One improvement I would recommend is the integration of an admin application within Teams, allowing easy access to attack information on a mobile platform.
Owner at Alopex ONE UG
Reducing false positives is something we've been working on with Microsoft.
Cloud Security & Governance at a financial services firm with 10,001+ employees
The next great thing that Sweet Security can do is to turn toward IAC, how it is handled and enforced, to tackle potential breaches of policy before they really happen.
Director of Security Operations at a tech vendor with 501-1,000 employees
Maybe they can just show the actual signal and not show that there is a lot of vulnerabilities, but indicate which are important.
Infrastructure & Dev Ops Lead at Babylon Labs
The main areas for improvement are related to how Sweet Security needs to be customized.
Works at a tech services company with 201-500 employees
 

Setup Cost

Qualys TotalCloud is costly but justified for large companies due to features, flexibility, and VMware integration efficiencies.
Microsoft Defender for Identity pricing aligns with E5 licenses, offering value in hybrid setups but can be costly at scale.
Sweet Security provides strong ROI, valued for visibility, threat detection, and responsive support, appealing to large enterprises.
Qualys TotalCloud's pricing is currently acceptable, it is becoming increasingly expensive.
Senior Manager at a financial services firm with 10,001+ employees
Pricing is managed by our finance team; however, Qualys TotalCloud offers cost-effective licensing flexibility.
IT Manager at a consultancy with 10,001+ employees
Qualys TotalCloud is expensive, but it offers a premier solution with no headaches.
Vice President at Inspira Enterprise
If they can reduce the costs, organizations will be happy, and it will compensate for using the Azure environment, which is more expensive on the infrastructure as a service side.
CyberSecurity Engineer | Information Security Management at Self Employed
Ensuring a fair price according to market standards.
Owner at Alopex ONE UG
From an organization perspective, using E5 licenses is value for money, especially if Azure and Office 365 are already in use.
Cloud Security & Governance at a financial services firm with 10,001+ employees
They're not cheap, but they're not as expensive compared to other companies.
Works at a tech services company with 201-500 employees
Sweet Security contains very similar features at a much better pricing.
Infrastructure & Dev Ops Lead at Babylon Labs
Sweet Security's pricing is quite fair and cost-effective by many users.
Partner Account Manager at a wholesaler/distributor with 51-200 employees
 

Valuable Features

Qualys TotalCloud offers efficient asset discovery, security posture management, and vulnerability management with excellent integration and threat intelligence features.
Microsoft Defender for Identity enhances threat detection and security integration, offering streamlined investigation with automated alerts and behavioral analytics.
Sweet Security enhances runtime monitoring and threat detection with seamless CI/CD integration, reducing false positives and alert fatigue.
This view of risk helps reduce the work we would have to do to combine multiple sources to prioritize risk.
Works at a consultancy with 10,001+ employees
It will help cybersecurity professionals monitor the cloud and find vulnerabilities.
Developer at a consultancy with 10,001+ employees
We are enjoying the new feature, FlexScan, which is valuable for Internet-facing VMs.
Senior Consultant at a consultancy with 10,001+ employees
We receive an advance report of risky users, allowing us to take preemptive action before an attack causes damage to organization details.
Instrumentation Engineer at Toyo Engineering Corp
The most valuable feature is its hybrid artificial intelligence, which gathers forensic data to track and counteract security threats, much like the CSI series in effect.
Owner at Alopex ONE UG
The advanced threat protection is one of the strengths of Microsoft Defender for Identity, as it utilizes user and entity analytics and can detect indicative attacks.
Cloud Security & Governance at a financial services firm with 10,001+ employees
Sweet Security's reporting tools enhance our insights into potential vulnerabilities and threats as they serve as our eyes and ears inside AWS, telling us what we are doing wrong so we can fix it.
Cloud and compute team leader at a manufacturing company with 1,001-5,000 employees
Sweet Security enabled teams to see each detection of activity upon every request made from the application level towards the infrastructure, making it much easier and reducing the time for an analyst to understand what is really happening.
Partner Account Manager at a wholesaler/distributor with 51-200 employees
Sweet Security is well-scalable throughout multi-cloud environments and Kubernetes clusters because it relies on lightweight runtime telemetry and cloud native architecture, allowing it to support growing cloud infrastructure of any size.
SOC L2 Analyst at a tech services company with 51-200 employees
 

Categories and Ranking

Qualys TotalCloud
Sponsored
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
46
Ranking in other categories
Vulnerability Management (11th), Container Security (11th), Cloud Workload Protection Platforms (CWPP) (8th), Cloud Security Posture Management (CSPM) (8th), SaaS Security Posture Management (SSPM) (2nd), Cloud-Native Application Protection Platforms (CNAPP) (7th)
Microsoft Defender for Iden...
Average Rating
8.8
Reviews Sentiment
6.8
Number of Reviews
28
Ranking in other categories
Advanced Threat Protection (ATP) (7th), Microsoft Security Suite (6th), Identity Threat Detection and Response (ITDR) (1st)
Sweet Security
Average Rating
8.6
Reviews Sentiment
7.1
Number of Reviews
7
Ranking in other categories
Vulnerability Management (32nd), Cloud Workload Protection Platforms (CWPP) (15th), Cloud Security Posture Management (CSPM) (18th), Cloud-Native Application Protection Platforms (CNAPP) (14th), Identity Threat Detection and Response (ITDR) (7th), Cloud Detection and Response (CDR) (6th), AI Security (27th)
 

Featured Reviews

reviewer2859021 - PeerSpot reviewer
Sr Security Engineer at a tech vendor with 5,001-10,000 employees
Risk-based triage has transformed container security and now prioritizes high-impact threats
The best features Qualys TotalCloud offers currently include managing cloud infrastructure and container security while facing major challenges such as alert fatigue. Traditional vulnerability scanners flag hundreds of CVEs on short-lived Kubernetes containers, some of which have no internet exposure or are gone before we can even triage them. I leverage Qualys TotalCloud to move beyond static CVSS. I use it to implement runtime exposure, correlation risk reprioritization, and shift-left integration. This notifies developers to fix a base image upstream rather than patching live ephemeral instances. In my work with cloud and container security, the biggest operational hurdle was alert fatigue. I use Qualys to shift left from static CVSS severity to context-aware risk prioritization. I correlated raw vulnerability data with real-time risk factors such as public network exposure, active runtime execution, or overly permissive IAM roles. This allows us to immediately drop the priority of isolated containers and escalate lower-severity CVEs that sit on an exposed, high-risk path. We can map these findings directly back to our CI/CD pipelines so developers can patch the root base images upstream. We have drastically cut down the signal-to-noise ratio, saved a lot of manual hours doing triage work, and ensured engineering effort goes directly towards high-impact risk reduction.
CM
Technology Coordinator at a educational organization with 501-1,000 employees
Helps detect threats faster and prioritize critical security tasks with increased visibility
The feature I value most about Microsoft Defender for Identity is the ability to see where people are attempting to log in from. Microsoft Defender for Identity helps me automate routine tasks and find alerts that I set up to receive, so it helps me get where I'm trying to go easier and faster. I can see where everything is at. Microsoft Defender for Identity helps me prioritize important tasks. If I get an alert for a user who downloaded an application that is not sanctioned, I normally go straight to that user's computer device to find the device name and the user. Now I can get to them much faster. Microsoft Defender for Identity saves me time overall. I can quantify the time saved by Microsoft Defender for Identity as maybe 25 minutes, or if expressed as a percentage, maybe 20 to 25%. Some of the learning curve and actually learning what these products do takes time to figure out. Microsoft Defender for Identity definitely helps decrease the time of detection and response.
reviewer2805510 - PeerSpot reviewer
Partner Account Manager at a wholesaler/distributor with 51-200 employees
Runtime-first security has transformed real-time threat detection and reduced alert fatigue
Sweet Security can be improved in terms of product maturity and ecosystem. It has a smaller market presence, so we do not have as many large enterprise deployments. Sweet Security is less mature than competitors such as Wiz or Palo Alto Networks. Some competitors provide better integrations and workflow tooling. Additionally, as a new vendor, there is a new market perception and higher perceived risk, which relates to trust of the product. Some competitors are seen as safer and more established choices. Since Sweet Security operates in the production live environment, there have been a couple of problems reported where issues occurred in production environments. However, these have been resolved within about an hour or two. Having that risk is always going to be a negative. As a cloud-native platform solution, Sweet Security is really good overall. There are only a couple of areas for improvement, such as not being fully 100% production safe, and the reality that its competitors are global, well-known companies such as Palo Alto and Wiz.
report
Use our free recommendation engine to learn which Identity Threat Detection and Response (ITDR) solutions are best for your needs.
913,806 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Comms Service Provider
16%
Outsourcing Company
12%
Manufacturing Company
11%
Financial Services Firm
10%
Financial Services Firm
12%
Manufacturing Company
10%
Computer Software Company
9%
Comms Service Provider
7%
Financial Services Firm
10%
Outsourcing Company
9%
Healthcare Company
9%
Wellness & Fitness Company
9%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business14
Midsize Enterprise5
Large Enterprise34
By reviewers
Company SizeCount
Small Business9
Midsize Enterprise5
Large Enterprise15
By reviewers
Company SizeCount
Small Business7
Midsize Enterprise3
Large Enterprise10
 

Questions from the Community

What needs improvement with Qualys TotalCloud?
In terms of improvement, remediation still belongs to the cloud team, which is one of the issues we faced with Qualys...
What is your primary use case for Qualys TotalCloud?
My main use case for Qualys TotalCloud is regarding the cloud visibility that we were not having previously. Previous...
What needs improvement with Microsoft Defender for Identity?
I really would have to sit down to think about how Microsoft Defender for Identity can be improved. I didn't take sto...
What is your primary use case for Microsoft Defender for Identity?
My main use cases for Microsoft Defender for Identity include Conditional Access, checking risky users, remediating r...
What advice do you have for others considering Microsoft Defender for Identity?
I don't really use Microsoft Defender for Identity a lot because my new role doesn't allow me to take time to do so. ...
What is your experience regarding pricing and costs for Sweet Security?
My experience with pricing, setup cost, and licensing has been that Sweet Security's pricing is quite fair and cost-e...
What needs improvement with Sweet Security?
In terms of improvements, I do not belong to the security team, but most of it is handled by me. I could see that clu...
What is your primary use case for Sweet Security?
I have been using Sweet Security for approximately one and a half years. For our organization, Sweet Security blocks ...
 

Also Known As

Qualys TotalCloud with FlexScan
Azure Advanced Threat Protection, Azure ATP, MS Defender for Identity
No data available
 

Overview

 

Sample Customers

Information Not Available
Microsoft Defender for Identity is trusted by companies such as St. Luke’s University Health Network, Ansell, and more.
Information Not Available
Find out what your peers are saying about Microsoft Defender for Identity vs. Sweet Security and other solutions. Updated: August 2026.
913,806 professionals have used our research since 2012.