

Find out in this report how the two Microsoft Security Suite solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
It has led to cost savings as well as time savings because I can use a single solution for all applications.
Companies can leverage it for setting up external identities without needing to develop their own solutions.
In terms of return on investment, prior to using this product, our company managed our own mail server with all internal authentication happening on premises, resulting in a ROI in the thousands every year.
If a customer is already using Microsoft’s ecosystem, the ROI can be positive due to seamless integration.
Our MTTR, mean time to response, improved by forty to fifty percent. Earlier, medium-severity incidents took two to three hours to resolve. Now, after Microsoft Sentinel, it is forty to fifty-five minutes.
For example, time saving on incidents is 40 to 50%, and previously, incident analysis took two to three hours, whereas now it takes 30 to 60 minutes.
Companies without a Microsoft license for Entra ID or Azure portal cannot add Azure AD B2C, creating logistical issues for some of my clients who are unable to evaluate the platform.
The support for business applications, infrastructure support, and Entra has been mostly positive with highly skilled technicians.
The documentation is very thorough, reducing the need for support.
Microsoft invests significantly in support, which is crucial for companies.
I believe Microsoft could improve by keeping customer service within the US for Microsoft Sentinel customers who are within state and federal government sectors.
Working with a Sentinel engineer helped us tune settings effectively.
This is one of EID's weak points compared to Azure AD B2C, which offers customizable authentication options, including attribute and password combinations.
End-user workloads experience increased latency in a cloud environment compared to on-premises resources.
Microsoft Entra External ID is quite scalable, and I would rate its scalability between eight and nine out of ten.
There is no need to add hardware or redesign infrastructure because it is cloud-native.
As our organization uses Microsoft Azure and Defender, everything grows together, and we can integrate various features seamlessly.
Being a SaaS solution, the scalability of Microsoft Sentinel is robust.
I'd rate the stability of the Microsoft Entra External ID as a 10.
The stability of this solution is very good.
I have not encountered any stability issues with Microsoft Entra External ID.
I have never experienced any downtime, crashes, or performance issues with Microsoft Sentinel because it is SOC as a Service, so it maintains 100% uptime and scaling.
In the past two years, our team hasn't encountered any issues with the stability of Microsoft Sentinel from an operations perspective.
I need to be aware of deprecated connectors as they may disconnect, but the data continues to be sent with a need for quick adaptation.
This is particularly challenging during enterprise agreement renewals, as it's difficult for customers to review costs leading to lengthy negotiations.
Enhanced customizable login options and the ability to use attribute password logins are critical features that are required for Microsoft Entra External ID to gain dominance in the authentication market.
I would like to see a more detailed alert system that provides a summary of why alerts are generated, who is generating them, and the reasons behind it.
Log ingestion and retention costs can grow quickly, and understanding which data source is driving cost is not always straightforward.
We have some tools, such as our off-site Meraki firewalls, that have not fully integrated with Sentinel.
There are complexities in calculating the right pricing tier for different customers, which makes it difficult for me as a consultant during upfront pricing.
Regarding pricing, the cost seems high for single sign-on, especially for external applications like Oracle.
Microsoft's pricing is complex and difficult to fathom due to a range of different licensing options.
The cost can be a factor for Microsoft Entra External ID, but in general, it offers a scalable and efficient solution compared to deploying individual solutions.
It has been beneficial that Microsoft Sentinel is included as part of the Microsoft package, making it more cost-effective.
Microsoft Sentinel is not a low-cost SIEM.
Microsoft Sentinel is provided at no cost, so we didn't have any issues with the cost.
It is crucial for hybrid environments, especially for integrating existing on-site infrastructures with cloud-based Active Directory, such as in Office 365 implementations.
EID unifies workforce users with external business partners, which is a very strong feature.
The detailed monitoring and reporting in Microsoft Entra External ID support compliance efforts effectively.
Microsoft Sentinel's ability to correlate data from multiple sources and its detection capabilities are essential.
Microsoft Sentinel has improved cost efficiency, which is one of the key areas we're able to win business against the ability to have threat intelligence.
Microsoft Sentinel's ability to correlate data from multiple sources enhances our threat detection capabilities beyond what is a simple data lake solution by filtering out the noise and consolidating the signal down to a meaningful level that is easier to investigate and see.
| Product | Mindshare (%) |
|---|---|
| Microsoft Sentinel | 4.8% |
| Microsoft Entra External ID | 1.8% |
| Other | 93.4% |

| Company Size | Count |
|---|---|
| Small Business | 9 |
| Midsize Enterprise | 2 |
| Large Enterprise | 6 |
| Company Size | Count |
|---|---|
| Small Business | 44 |
| Midsize Enterprise | 23 |
| Large Enterprise | 46 |
Microsoft Entra External ID provides streamlined identity management with features like Active Directory integration, multi-factor authentication, and centralized user management, supporting both B2C and B2E needs. It's designed to enhance security while simplifying access management across applications.
Microsoft Entra External ID enhances identity management by offering easy setup, robust monitoring, and centralized user management. It supports compliance with comprehensive reporting and integrates seamlessly with Azure. While it facilitates cross-company collaboration, user lifecycle management, and B2B guest access, users note the need for improved technical support, faster synchronization speeds, and more customizable interfaces. Integration with open-source software, legacy tools, and ERP systems is advised along with a more predictable pricing model and improved federated login security. Current licensing complexity and the need for more user-friendly interfaces are areas for development.
What are the most important features?In sectors like IT, finance, and healthcare, Microsoft Entra External ID is utilized for managing complex access needs and compliance requirements, supporting projects involving Active Directory, Microsoft Teams, and cloud-based infrastructures. These industries leverage its capabilities for managing identities and improving secure collaboration while ensuring alignment with existing on-premises systems.
Microsoft Sentinel offers cloud-native SIEM and SOAR capabilities with AI-powered threat detection, automated responses, and integration with Microsoft products. It is designed for comprehensive threat management with flexible deployment and scalability.
Microsoft Sentinel provides centralized management of cloud-based security monitoring and incident detection. Leveraging AI capabilities, it enhances threat intelligence and automation, allowing users to streamline security operations across cloud and on-premises systems. Microsoft Sentinel efficiently aggregates logs, correlates security events from multiple sources, and integrates seamlessly with Microsoft security offerings such as Defender. While its flexible deployment options and robust automation through playbooks are advantageous, users may encounter challenges with integration outside of Microsoft products, potential log ingestion delays, and a complex query language. The platform would benefit from enhanced speed, a simplified interface, improved query performance, and stronger documentation support.
What are the most important features of Microsoft Sentinel?In specific industries, Microsoft Sentinel is utilized for its capability to monitor cloud-based workloads and detect incidents effectively. Users in healthcare, finance, and retail adopt it for its strong AI-driven threat detection and its ability to integrate with existing Microsoft solutions, ensuring high-level security operations and compliance with industry standards.
We monitor all Microsoft Security Suite reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.