No more typing reviews! Try our Samantha, our new voice AI agent.

Microsoft Defender for Identity vs Sweet Security comparison

Sponsored
 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
6.3
SentinelOne Singularity Cloud enhances security, efficiency, and ROI by reducing incident times, costs, and resource needs while improving compliance.
Sentiment score
4.8
Microsoft Defender for Identity enhances threat detection, reduces efforts, minimizes risks, and optimizes costs despite varied ROI assessments.
Sentiment score
6.1
Sweet Security boosts incident response and reduces alert fatigue with improved visibility, prioritizing threats for informed tool investments.
After implementing SentinelOne, it takes about five to seven minutes.
Cloud engineer at a construction company with 5,001-10,000 employees
Our ability to get in and review our vulnerability stance, whether daily, monthly, weekly, or whatever it might be, has drastically improved over our prior provider.
IT Support Specialist at a non-tech company with 201-500 employees
It has saved us more than 50% of our time.
Sr security engineer at Halodoc
The ROI is that we are not waiting for a breach but being proactive rather than reactive.
Partner Account Manager at a wholesaler/distributor with 51-200 employees
 

Customer Service

Sentiment score
7.8
SentinelOne Singularity Cloud Security is praised for responsive support, though recent acquisition slightly impacted personalized service.
Sentiment score
6.4
Microsoft Defender for Identity offers knowledgeable support, yet response times can vary, especially with complex issues or initial contacts.
Sentiment score
9.0
Sweet Security provides exceptional customer service and technical support, with quick issue resolution and strong customer relationships.
Having a reliable team ready and willing to assist with any issues is essential.
Director, DevOps at Relay Network
Throughout the migration, they remained available for several hours without complaint, providing assistance at every step.
Mobile Application Developer at a retailer with 1-10 employees
In my experience, I have never encountered a junior person or someone without knowledge coming into support from SentinelOne.
Senior Technical Engineer at Safezone Secure Solutions Private Limited
Generally, the support is more effective than other providers like Oracle.
Owner at Alopex ONE UG
The quality of support is very good, but troubleshooting can take time due to complex setups and the need to provide many logs.
Cloud Security & Governance at a financial services firm with 10,001+ employees
The people I normally use for support are very knowledgeable, especially when they help remote in and get to where I need to go and show me much faster and help me understand what I should be doing.
Technology Coordinator at a educational organization with 501-1,000 employees
They are there immediately, providing us with the best technical people, solving any issue we had.
Director of Security Operations at a tech vendor with 501-1,000 employees
They gave me a trial period, did multiple follow-ups, and were reviewing themselves the findings to actually understand how their product is performing.
Infrastructure & Dev Ops Lead at Babylon Labs
I would rate customer support a nine out of ten because they maintain a competitive price, offer trial periods, provide follow-up, are very responsive, and are effectively hands-on in assisting and offering prompt service and support.
Partner Account Manager at a wholesaler/distributor with 51-200 employees
 

Scalability Issues

Sentiment score
8.1
SentinelOne Singularity Cloud Security offers highly rated scalability, easily integrating across environments and accommodating growth despite some configuration challenges.
Sentiment score
7.2
Microsoft Defender for Identity is highly scalable and adaptable, excelling in large enterprises with efficient cloud-based processing.
Sentiment score
7.3
Sweet Security scales well for small to medium businesses but faces mixed reviews for large enterprise scalability and performance.
The SentinelOne Singularity Cloud exhibits high scalability.
Security Analyst at Intersistemi Italia s.p.a.
We've automated in our MDM so any device that we start in our MDM automatically installs SentinelOne.
IT Support Specialist at a non-tech company with 201-500 employees
It is scalable. I would rate it a ten out of ten for scalability.
Sr security engineer at Halodoc
In a Microsoft-centric organization, especially with Azure infrastructure and Office 365, Microsoft Defender for Identity is scalable.
Cloud Security & Governance at a financial services firm with 10,001+ employees
We don't need to scale it since it's all SaaS.
Cloud and compute team leader at a manufacturing company with 1,001-5,000 employees
We are a robust enterprise with thousands of assets in the cloud or tens of thousands.
Director of Security Operations at a tech vendor with 501-1,000 employees
The user interface that I see doesn't make me very confident that I will be able to extract information in case I had hundreds or thousands of Kubernetes clusters or hundreds or thousands of hosts.
Infrastructure & Dev Ops Lead at Babylon Labs
 

Stability Issues

Sentiment score
8.3
SentinelOne Singularity Cloud Security is highly stable, reliable, and rated 9/10, with only minor UI and communication issues.
Sentiment score
7.1
Microsoft Defender for Identity is highly stable, reliable, with minimal downtime; occasional issues require support for agent redeployment.
Sentiment score
8.5
Sweet Security is highly stable, with users rating it 9-10/10 for reliability and quick issue resolution.
SentinelOne Singularity Cloud is incredibly reliable.
Security Analyst at Intersistemi Italia s.p.a.
The only downtime we had was when switching from V1 to V2 but it was smooth.
Cloud Security Specialist at a insurance company with 10,001+ employees
I would rate it a ten out of ten for stability.
Sr security engineer at Halodoc
Microsoft Defender for Identity is quite robust and built on Azure hyperscale infrastructure, with a 99% availability.
Cloud Security & Governance at a financial services firm with 10,001+ employees
We do not see any issues with the stability of Microsoft Defender for Identity.
Deputy Manager at Servion Global Solutions
Having recently started using it, reliability is affirmed, but manual investigation is often performed to verify if alerts identified by auto-remediation are accurate.
Instrumentation Engineer at Toyo Engineering Corp
I would rate the stability of Sweet Security a ten out of ten.
Works at a tech services company with 201-500 employees
We have never had any issues with stability.
Director of Security Operations at a tech vendor with 501-1,000 employees
Sweet Security is stable, as I find that user experience does not tend to reveal many production problems, and when they do occur, they are resolved quickly.
Partner Account Manager at a wholesaler/distributor with 51-200 employees
 

Room For Improvement

Users desire improved integration, interface, automation, detection accuracy, documentation, reporting, security, and customization to address existing concerns.
Microsoft Defender for Identity needs improvements in alert accuracy, UI/UX, asset integration, automation, anomaly detection, and third-party integration.
Sweet Security needs improved integration, UI, and automation, with concerns over complexity, customization, and market position risks.
If notifications are available, then it will be more helpful, easy, and time-saving.
Sr Security Analyst at a computer software company with 201-500 employees
Alerts should be directly tied to compliance standards and have a clear role in the overall compliance process.
Cloud Security & Architecture Specialist at a insurance company with 10,001+ employees
The Infrastructure as Code service available in PingSafe and the services available in AWS cloud security can be merged so that we can get the security data directly from AWS cloud in PingSafe.
Cloud Engineer at a tech services company with 201-500 employees
If Microsoft could develop a feature that indicates when impossible travel is caused by VPN connections, it would prevent unnecessary password resets and session disruptions, especially for VIP users in organizations.
CyberSecurity Engineer | Information Security Management at Self Employed
One improvement I would recommend is the integration of an admin application within Teams, allowing easy access to attack information on a mobile platform.
Owner at Alopex ONE UG
Reducing false positives is something we've been working on with Microsoft.
Cloud Security & Governance at a financial services firm with 10,001+ employees
The next great thing that Sweet Security can do is to turn toward IAC, how it is handled and enforced, to tackle potential breaches of policy before they really happen.
Director of Security Operations at a tech vendor with 501-1,000 employees
Maybe they can just show the actual signal and not show that there is a lot of vulnerabilities, but indicate which are important.
Infrastructure & Dev Ops Lead at Babylon Labs
The main areas for improvement are related to how Sweet Security needs to be customized.
Works at a tech services company with 201-500 employees
 

Setup Cost

SentinelOne offers competitive, flexible pricing with good value, though some find it high for large deployments.
Microsoft Defender for Identity pricing aligns with E5 licenses, offering value in hybrid setups but can be costly at scale.
Sweet Security offers cost-effective pricing with fair value, integration benefits, and excellent support, ideal for enterprise-level businesses.
With very little negotiation involved, we just let them know what we could pay and they were willing to meet us at slightly above what we paid with Sophos, which was still very fair for what we were looking at.
IT Support Specialist at a non-tech company with 201-500 employees
If you want to buy just EDR, the price is less. XDR is a little bit more expensive.
IT Security Specialist at Tailor Security Tech
It should not be based on subscription. It should be based on the number of servers that I am scanning.
AVP DevOps and Product Support at a recruiting/HR firm with 1,001-5,000 employees
If they can reduce the costs, organizations will be happy, and it will compensate for using the Azure environment, which is more expensive on the infrastructure as a service side.
CyberSecurity Engineer | Information Security Management at Self Employed
Ensuring a fair price according to market standards.
Owner at Alopex ONE UG
From an organization perspective, using E5 licenses is value for money, especially if Azure and Office 365 are already in use.
Cloud Security & Governance at a financial services firm with 10,001+ employees
They're not cheap, but they're not as expensive compared to other companies.
Works at a tech services company with 201-500 employees
Sweet Security contains very similar features at a much better pricing.
Infrastructure & Dev Ops Lead at Babylon Labs
Sweet Security's pricing is quite fair and cost-effective by many users.
Partner Account Manager at a wholesaler/distributor with 51-200 employees
 

Valuable Features

SentinelOne Singularity Cloud Security provides scalable AI-driven cloud protection with automated remediation, deep visibility, and seamless third-party integration.
Microsoft Defender for Identity enhances threat detection and security integration, offering streamlined investigation with automated alerts and behavioral analytics.
Sweet Security offers deep runtime visibility, unifying security with real-time insights, threat detection, and customizable dashboards for APIs.
This tool has been helpful for us. It allows us to search for vulnerabilities and provides evidence directly on the screen.
Cloud Security Specialist at a insurance company with 10,001+ employees
The cloud misconfiguration feature gave us almost zero false positives.
Sr security engineer at Halodoc
PingSafe has sped up the process by 80% to 90%.
Sr Security Analyst at a computer software company with 201-500 employees
We receive an advance report of risky users, allowing us to take preemptive action before an attack causes damage to organization details.
Instrumentation Engineer at Toyo Engineering Corp
The most valuable feature is its hybrid artificial intelligence, which gathers forensic data to track and counteract security threats, much like the CSI series in effect.
Owner at Alopex ONE UG
The advanced threat protection is one of the strengths of Microsoft Defender for Identity, as it utilizes user and entity analytics and can detect indicative attacks.
Cloud Security & Governance at a financial services firm with 10,001+ employees
Sweet Security's reporting tools enhance our insights into potential vulnerabilities and threats as they serve as our eyes and ears inside AWS, telling us what we are doing wrong so we can fix it.
Cloud and compute team leader at a manufacturing company with 1,001-5,000 employees
Sweet Security enabled teams to see each detection of activity upon every request made from the application level towards the infrastructure, making it much easier and reducing the time for an analyst to understand what is really happening.
Partner Account Manager at a wholesaler/distributor with 51-200 employees
I really love the feature within Sweet Security platform that allows you to visualize the specific packages or functions that are being loaded to the memory and are actually being executed by the operational system.
Director of Security Operations at a tech vendor with 501-1,000 employees
 

Categories and Ranking

SentinelOne Singularity Clo...
Sponsored
Average Rating
8.8
Reviews Sentiment
7.3
Number of Reviews
124
Ranking in other categories
Vulnerability Management (4th), Cloud and Data Center Security (5th), Container Security (3rd), Cloud Workload Protection Platforms (CWPP) (4th), Cloud Security Posture Management (CSPM) (3rd), Cloud-Native Application Protection Platforms (CNAPP) (3rd), Compliance Management (1st), AI Observability (3rd)
Microsoft Defender for Iden...
Average Rating
8.8
Reviews Sentiment
6.8
Number of Reviews
28
Ranking in other categories
Advanced Threat Protection (ATP) (8th), Microsoft Security Suite (5th), Identity Threat Detection and Response (ITDR) (3rd)
Sweet Security
Average Rating
8.6
Reviews Sentiment
7.6
Number of Reviews
5
Ranking in other categories
Vulnerability Management (31st), Cloud Workload Protection Platforms (CWPP) (15th), Cloud Security Posture Management (CSPM) (19th), Cloud-Native Application Protection Platforms (CNAPP) (14th), Identity Threat Detection and Response (ITDR) (9th), Cloud Detection and Response (CDR) (4th)
 

Featured Reviews

Sreeraj Mohandas - PeerSpot reviewer
Security Engineer at HashXpert
Consolidated cloud security has reduced manual work and has automated vulnerability remediation
I elaborate on my rating of SentinelOne support by mentioning that there was some time where the troubleshooting took a longer time. In fact, there were many meetings going on. The availability of the document on the internet is on a lesser side because as an engineer, I would want to know about the troubleshooting aspects of this particular tool. When I am facing a customer, I do not prefer to bring the vendor to every call and try to resolve it, as it takes months and months. It would be better to have a training session with the engineer on site to explain and train properly. This is not the case with SentinelOne, so this is the only thing I have a complaint about. I do not have any other room for improvement to suggest within SentinelOne itself. However, I would really want the AI assistant for the threat hunting part to be more accessible. They have it, but they are making it licensed, so it is a bit on the higher end.
OA
CyberSecurity Engineer | Information Security Management at Self Employed
Automation and threat intelligence streamline threat response and user management
In Microsoft Defender for Identity, I would appreciate improvements in providing information on conditional access. They have added more control that can be put in place, which was not present years ago. They have also integrated Azure Information Protection where policies can be configured. The Self-Service Password Reset (SSPR) allows users to reset their passwords, which is a valuable tool for remote workers. They have added more features into conditional access that integrate with other components, including SSPR and Identity Information Protection, trusted IPs, and locations. These configurations in trusted IP addresses are integrated into conditional access and control the applications I want to secure. Regarding impossible travel scenarios, I can either block the user or grant access while requesting multi-factor authentication. They should improve the automation for impossible travel detection. When connected to Wi-Fi and then to VPN, the system sometimes interprets the IP address change as impossible travel. If Microsoft could develop a feature that indicates when impossible travel is caused by VPN connections, it would prevent unnecessary password resets and session disruptions, especially for VIP users in organizations.
reviewer2805510 - PeerSpot reviewer
Partner Account Manager at a wholesaler/distributor with 51-200 employees
Runtime-first security has transformed real-time threat detection and reduced alert fatigue
Sweet Security can be improved in terms of product maturity and ecosystem. It has a smaller market presence, so we do not have as many large enterprise deployments. Sweet Security is less mature than competitors such as Wiz or Palo Alto Networks. Some competitors provide better integrations and workflow tooling. Additionally, as a new vendor, there is a new market perception and higher perceived risk, which relates to trust of the product. Some competitors are seen as safer and more established choices. Since Sweet Security operates in the production live environment, there have been a couple of problems reported where issues occurred in production environments. However, these have been resolved within about an hour or two. Having that risk is always going to be a negative. As a cloud-native platform solution, Sweet Security is really good overall. There are only a couple of areas for improvement, such as not being fully 100% production safe, and the reality that its competitors are global, well-known companies such as Palo Alto and Wiz.
report
Use our free recommendation engine to learn which Identity Threat Detection and Response (ITDR) solutions are best for your needs.
893,221 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
14%
Computer Software Company
11%
Manufacturing Company
9%
Government
5%
Financial Services Firm
13%
Computer Software Company
11%
Manufacturing Company
9%
Comms Service Provider
7%
Wellness & Fitness Company
10%
Healthcare Company
10%
Manufacturing Company
8%
Financial Services Firm
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business52
Midsize Enterprise23
Large Enterprise58
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise5
Large Enterprise14
By reviewers
Company SizeCount
Small Business3
Midsize Enterprise3
Large Enterprise3
 

Questions from the Community

What do you like most about PingSafe?
The dashboard gives me an overview of all the things happening in the product, making it one of the tool's best featu...
What is your experience regarding pricing and costs for PingSafe?
My experience with the pricing, setup costs, and licensing of SentinelOne Singularity Cloud Security is that the pric...
What needs improvement with PingSafe?
Integration could be improved because not all solutions can be integrated with SentinelOne Singularity Cloud Security...
What needs improvement with Microsoft Defender for Identity?
I really would have to sit down to think about how Microsoft Defender for Identity can be improved. I didn't take sto...
What is your primary use case for Microsoft Defender for Identity?
My main use cases for Microsoft Defender for Identity include Conditional Access, checking risky users, remediating r...
What advice do you have for others considering Microsoft Defender for Identity?
I don't really use Microsoft Defender for Identity a lot because my new role doesn't allow me to take time to do so. ...
What is your experience regarding pricing and costs for Sweet Security?
My experience with pricing, setup cost, and licensing has been that Sweet Security's pricing is quite fair and cost-e...
What needs improvement with Sweet Security?
Sweet Security can be improved in terms of product maturity and ecosystem. It has a smaller market presence, so we do...
What is your primary use case for Sweet Security?
My main use case for Sweet Security as a distributor is to distribute to our partners within the UK channel, and they...
 

Also Known As

PingSafe
Azure Advanced Threat Protection, Azure ATP, MS Defender for Identity
No data available
 

Overview

 

Sample Customers

Information Not Available
Microsoft Defender for Identity is trusted by companies such as St. Luke’s University Health Network, Ansell, and more.
Information Not Available
Find out what your peers are saying about Microsoft Defender for Identity vs. Sweet Security and other solutions. Updated: April 2026.
893,221 professionals have used our research since 2012.