Try our new research platform with insights from 80,000+ expert users

Microsoft Defender for Identity vs Sweet Security comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

SentinelOne Singularity Clo...
Sponsored
Average Rating
8.6
Reviews Sentiment
7.5
Number of Reviews
118
Ranking in other categories
Vulnerability Management (4th), Cloud and Data Center Security (3rd), Container Security (3rd), Cloud Workload Protection Platforms (CWPP) (4th), Cloud Security Posture Management (CSPM) (3rd), Cloud-Native Application Protection Platforms (CNAPP) (3rd), Compliance Management (2nd), AI Software Development (1st), AI Observability (2nd)
Microsoft Defender for Iden...
Average Rating
8.8
Reviews Sentiment
6.8
Number of Reviews
28
Ranking in other categories
Advanced Threat Protection (ATP) (8th), Microsoft Security Suite (4th), Identity Threat Detection and Response (ITDR) (3rd)
Sweet Security
Average Rating
9.0
Reviews Sentiment
8.0
Number of Reviews
3
Ranking in other categories
Vulnerability Management (38th), Cloud Workload Protection Platforms (CWPP) (17th), Cloud Security Posture Management (CSPM) (25th), Cloud-Native Application Protection Platforms (CNAPP) (17th), Identity Threat Detection and Response (ITDR) (12th), Cloud Detection and Response (CDR) (8th)
 

Featured Reviews

SC
Information Security Engineer at DataVigilant Infotech
Enables us to prioritize and effectively address critical security issues
Evidence-based reporting helps us to prioritize and solve critical security issues. The new visualization feature demonstrates how an attacker can enter the system, highlighting the potential path that can be exploited and outlining all the steps the attacker could take. With that visibility, we can ensure the perimeter is strong and attackers cannot enter, thus reducing the risk. It has helped us prioritize issues. The visibility into how an attack could happen is valuable. For example, it highlights the system vulnerability and outlines where an attack could propagate. The visualization helps me to prioritize remediation, and if I don't know where to start, I can check to see the score that enables me to prioritize issues. I am using infrastructure-as-code scanning, and it's one of the useful features. In pre-production, it identifies embedded secrets and misconfigurations, including issues with Kubernetes or some privileged containers. This feature allows us to pass the audit and secure IaC code so that it isn't easily exploitable by attackers. We can more proactively work to identify and resolve vulnerabilities by using the dashboard and the alerting system that SentinelOne provides. It helps us with audits and compliance. We can show the compliance in percentage. We can confidently say that our company or infrastructure is very secure. It has improved our security posture by 30% to 35%. It has reduced our false positives by 30%. It has helped teams collaborate better. The security team manages SentinelOne Singularity Cloud Security, and when it flags vulnerabilities, they are forwarded to DevOps for remediation. Previously, we needed to identify and report the issues, but there would be lapses in communication. Now, there is a centralized dashboard that anyone can look at and see the open issues and work on them.
RK
Cloud Security & Governance at a financial services firm with 10,001+ employees
Protect on-premises and hybrid environments with advanced threat detection and seamless integration
Our Active Directory implementation is a hybrid one. The advanced threat protection is one of the strengths of Microsoft Defender for Identity, as it utilizes user and entity analytics and can detect indicative attacks. It identifies lateral movements, privilege escalations, and alerts on potential attacks. The tool is also used for security posture assessment. The seamless integration with other Microsoft solutions within our Microsoft-centric environment is also a major advantage.
reviewer2761083 - PeerSpot reviewer
Director of Security Operations at a tech vendor with 501-1,000 employees
Has reduced investigation time by correlating application and infrastructure events
Sweet Security has room for improvement in two areas. One is for robust integration with automations and playbooks. We have our internally developed platform that operates around security incident playbooks, so the connection between those two systems would be great. The option to run specific playbooks through the Sweet Security platform would help us a lot, but these must be fully customizable. We prefer not to block the business from progressing unless we are fully sure that it is an incident. Most of the actions I would take would revolve around containment or notification on a specific platform and not via email or similar communications. The second area is around the code perspective. I know it's just the start of a long journey that Sweet Security is going to go through to become a platform that also handles code, but I would expect options for a complete analysis and writing policies for infrastructure as code. The next great thing that Sweet Security can do is to turn toward IAC, how it is handled and enforced, to tackle potential breaches of policy before they really happen.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"Its performance impact on the systems is low, which means there is a minimal impact on system performance compared to traditional antivirus solutions."
"The visibility is the best part of the solution."
"It is pretty easy to integrate with this platform. When properly integrated, it monitors end-to-end."
"SentinelOne Singularity Cloud Security provides email alerts and ranks issues based on severity, such as high, critical, etc., that help us prioritize issues."
"When creating cloud infrastructure, Cloud Native Security evaluates the cloud security parameters and how they will impact the organization's risk. It lets us know whether our security parameter conforms to international industry standards. It alerts us about anything that increases our risk, so we can address those vulnerabilities and prevent attacks."
"Cloud Native Security's best feature is its ability to identify hard-coded secrets during pull request reviews."
"SentinelOne stands out with its responsiveness to feature requests for Singularity Cloud Security."
"My favorite feature is Storyline."
"I recommend Microsoft Defender for Identity because it is easy to implement."
"The most valuable feature is its hybrid artificial intelligence, which gathers forensic data to track and counteract security threats, much like the CSI series in effect."
"In the security portfolio that we manage, Microsoft Defender for Identity is very important because it is the professional service that we sell the most."
"The solution offers excellent visibility into threats."
"The most valuable features of Microsoft Defender for Identity are the simulations; whenever something happens, it provides complete step-by-step process details, including the hierarchy, how it happens in the environment, and the lateral movement, which is amazing."
"I would rate Microsoft Defender for Identity at nine out of ten."
"The advanced threat protection is one of the strengths of Microsoft Defender for Identity, as it utilizes user and entity analytics and can detect indicative attacks."
"All the integration it has with different Microsoft packages, like Teams and Office, is good."
"The value of having real-time visibility in our cloud environment with Sweet Security changes everything because it differentiates between identifying and reacting to something that is not really a risk and something that is truly a risk that needs to be treated."
"Before we had Sweet Security, upon any type of detection of activity, we needed to conduct lots of investigations in different platforms and logs until we could build the larger picture, but once we inserted Sweet Security, we are able to actually see each and every request being made from the application level towards the infrastructure, making it much easier and reducing the time for an analyst to understand what's really happening."
"The value we see from having real-time visibility into our cloud environment is significant, as Sweet Security serves as our eyes and ears inside AWS, telling us what we are doing wrong so we can fix it."
 

Cons

"One potential drawback is the cost of SentinelOne Singularity Cloud Security, which may be prohibitive for smaller businesses or startups, particularly those in regions with lower average incomes, such as India."
"The cloud-based operations might pose challenges in areas with limited or unavailable internet connectivity. Desktop features might be useful for smaller organizations with less complex security needs."
"One potential drawback is the cost of SentinelOne Singularity Cloud Security, which may be prohibitive for smaller businesses or startups, particularly those in regions with lower average incomes, such as India."
"I believe the UI/UX updates for SentinelOne Singularity Cloud Security have room for improvement."
"SentinelOne Singularity Cloud Security can improve by eliminating 100 percent of the false positives."
"SentinelOne Singularity Cloud Security is an excellent CSPM tool, but its CWPP features need improvement, and there is scope for more application security posture management features."
"They need more experienced support personnel."
"The documentation could be better."
"The documentation provided by Microsoft is often seen as a waste of time."
"When the data leaves the cloud, there are security issues."
"The areas of Microsoft Defender for Identity that can be improved include its cost, which is quite expensive when integrated into Sentinel. Additionally, there is room for improvement in its integration with non-Microsoft applications and systems."
"I can't say that I've seen a return on investment since we have Microsoft Defender for Identity because we also have another security solution in place."
"There is no option to remedy an issue directly from the console. If we see an alert, we can't fix it from the console. Instead, we must depend on other Microsoft products, such as MDE. That is a significant drawback. It simply works as a scanner, which can sometimes put enough load on the sensors. Immediate actions should be possible from the dashboard because. It can prevent issues from spreading further."
"The solution could improve how it handles on-premises Android-related attacks."
"And when you are working in a priority IP address, Identity is not able to know that those IPs are from the company. It sees that the IPs are from Taiwan or from Hong Kong or from India, even though they are internal IPs, resulting in a lot of false positives."
"Fixing the solution isn't very seamless."
"One area for improvement could be the alerts, as we have an issue with the alert time, the time it takes for the system to send the alert, but besides that, there is nothing special."
"There was something a year ago that caused a production issue in my company, but they fixed it within an hour."
"The option to run specific playbooks through Sweet Security platform would help us a lot, but these must be fully customizable."
 

Pricing and Cost Advice

"The cost for PingSafe is average when compared to other CSPM tools."
"PingSafe is priced reasonably for our workload."
"The pricing for PingSafe in India was more reasonable than other competitors."
"I am not involved in the pricing, but it is cost-effective."
"It is a little expensive. I would rate it a four out of ten for pricing."
"Pricing is based on modules, which was ideal for us."
"I wasn't sure what to expect from the pricing, but I was pleasantly surprised to find that it was a little less than I thought."
"While SentinelOne Singularity Cloud Security offers robust protection, its high cost may be prohibitive for small and medium-sized businesses."
"You won't be able to change your tenants from where you deploy them. For example, if you select Canada, they will charge you based on Canadian pricing. If you are also in London, when you deploy in Canada, the pound is higher than Canadian dollars, but your platform resources are billable in Canadian dollars. Using your pounds to pay for any of these things will be cheaper. Or, if you deploy in London, they will charge you based on your local currency."
"It is very affordable considering that other SIEM solutions are much more expensive and have many more licensing restrictions and fees."
"Defender for Identity is a little more expensive than other Microsoft products. Identity and Microsoft Defender for Cloud are both a bit costly."
"Microsoft Defender for Identity comes as part of the Microsoft E5 licensing stack."
"The product is costly, and we had multiple discussions with accounting to receive a discounted rate. However, on the open market, the tool is expensive."
Information not available
report
Use our free recommendation engine to learn which Identity Threat Detection and Response (ITDR) solutions are best for your needs.
881,665 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Computer Software Company
12%
Manufacturing Company
10%
Government
6%
Financial Services Firm
13%
Computer Software Company
12%
Manufacturing Company
8%
Comms Service Provider
7%
Wellness & Fitness Company
14%
Healthcare Company
10%
Financial Services Firm
9%
Non Profit
6%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business48
Midsize Enterprise22
Large Enterprise54
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise4
Large Enterprise14
No data available
 

Questions from the Community

What do you like most about PingSafe?
The dashboard gives me an overview of all the things happening in the product, making it one of the tool's best featu...
What is your experience regarding pricing and costs for PingSafe?
Regarding the pricing for SentinelOne Singularity Cloud Security, I do not think it is something I can compare.
What needs improvement with PingSafe?
Regarding the downsides of cloud security, I do not have much negative to discuss about cloud security, because it is...
What needs improvement with Microsoft Defender for Identity?
I really would have to sit down to think about how Microsoft Defender for Identity can be improved. I didn't take sto...
What is your primary use case for Microsoft Defender for Identity?
My main use cases for Microsoft Defender for Identity include Conditional Access, checking risky users, remediating r...
What advice do you have for others considering Microsoft Defender for Identity?
I don't really use Microsoft Defender for Identity a lot because my new role doesn't allow me to take time to do so. ...
What is your experience regarding pricing and costs for Sweet Security?
I'm not really into the specifics of the pricing, but as far as I know, it is cost-effective.
What needs improvement with Sweet Security?
Sweet Security has room for improvement in two areas. One is for robust integration with automations and playbooks. W...
What is your primary use case for Sweet Security?
We are cloud native and are using Sweet Security for call runtime protection. It is much bigger than just runtime pro...
 

Also Known As

PingSafe
Azure Advanced Threat Protection, Azure ATP, MS Defender for Identity
No data available
 

Overview

 

Sample Customers

Information Not Available
Microsoft Defender for Identity is trusted by companies such as St. Luke’s University Health Network, Ansell, and more.
Information Not Available
Find out what your peers are saying about Microsoft Defender for Identity vs. Sweet Security and other solutions. Updated: December 2025.
881,665 professionals have used our research since 2012.