Try our new research platform with insights from 80,000+ expert users

Pros & Cons summary

Buyer's Guide

Get pricing advice, tips, use cases and valuable features from real users of this product.
Get the report

Prominent pros & cons

PROS

Microsoft Defender for Identity has evolved significantly, offering advanced threat protection through user and entity analytics to detect and investigate suspicious activities efficiently.
Its easy setup process, requiring only a few minutes, utilizes scripts and Group Policy for seamless deployment across devices.
The integration with Microsoft packages like Teams and Office, along with customized detection rules, enhances its adaptability to business needs.
The tool provides comprehensive visibility into threats with features like entity tags and honeytoken entities, enhancing the identification and management of sensitive accounts.
Real-time analytics and hybrid artificial intelligence ensure effective monitoring and protection of identities, with reliable auto-remediation and excellent stability.

CONS

When data leaves the cloud, there are security issues, and improvements are needed in enhancing group-managed access with broad-based access controls.
Microsoft Defender for Identity solely functions as a scanner with a lack of options for direct remediation or alert resolution from the console, causing heavy reliance on other Microsoft products.
Technical support needs enhancement, particularly in providing guides or walkthroughs to address minor issues, which could help reduce ticket numbers and pressure on the support team.
Microsoft Defender for Identity generates excessive false positives, misidentifying legitimate activities such as screen locking and failing to recognize internal IP addresses correctly, leading to difficulty in incident management.
Integration of Microsoft Defender for Identity with non-Microsoft applications and systems is lacking, and associated costs when integrated into Sentinel are high, which requires improvement.
 

Microsoft Defender for Identity Pros review quotes

reviewer1043151 - PeerSpot reviewer
Cyber Security BA/BSA at a insurance company with 10,001+ employees
Mar 13, 2021
This solution has advanced a lot over the last few years.
DS
Enterprise Architect at NTT New Zealand Ltd.
Sep 9, 2021
Defender for Identity has not affected the end-user experience.
reviewer1687521 - PeerSpot reviewer
Senior Infrastructure Security Engineer at a tech services company with 51-200 employees
Oct 5, 2021
It is easy to set up. Based on the number of devices you would like to set up, you can use scripts, Group Policy, etc. It takes five minutes to set up.
Learn what your peers think about Microsoft Defender for Identity. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
reviewer1688547 - PeerSpot reviewer
Security specialist at a manufacturing company with 10,001+ employees
Oct 6, 2021
The basic security monitoring at its core feature is the most valuable aspect. But also the investigative parts, the historical logging of events over the network are extremely interesting because it gives an in-depth insight into the history of account activity that is really easy to read, easy to follow, and easy to export.
Sachin Vinay - PeerSpot reviewer
Assistant Manager-Networks at a university with 1,001-5,000 employees
Dec 3, 2022
The best feature is security monitoring, which detects and investigates suspicious user activities. It can easily detect advanced attacks based on the behavior. The credentials are securely stored, so it reduces the risk of compromise. It will monitor user behavior based on artificial intelligence to protect the identities in your organization. It will even help secure the on-premise Active Directory. It syncs from the cloud to on-premise, and on-premise modifications will be reflected in the cloud.
BK
IT Manager at vTech4U
Mar 31, 2023
The solution offers excellent visibility into threats.
BS
Lead Security Analyst at a tech vendor with 10,001+ employees
Apr 13, 2023
The feature I like most is that you can create your own customized detection rules. It has a lot of default alerts and rules, but you can customize them according to your business needs.
Iñaki Martinez Urricelqui - PeerSpot reviewer
Threat Analysis Technology Risk & Cybersecurity Analyst II at a consultancy with 5,001-10,000 employees
Apr 17, 2023
All the integration it has with different Microsoft packages, like Teams and Office, is good.
Emeka Ndulu - PeerSpot reviewer
Cloud Solutions Architect at a tech services company with 201-500 employees
Apr 18, 2023
The feature I like the most about Defender for Identity is the entity tags. They give you the ability to identify sensitive accounts, devices, and groups. You also have honeytoken entities, which are devices that are identified as "bait" for fraudulent actors.
Matthew Bouwer - PeerSpot reviewer
Cyber Security Analyst at a tech services company with 1,001-5,000 employees
Apr 20, 2023
The most valuable aspect is its connection to Microsoft Sentinel and Defender for Endpoint, and giving exact timelines for incidents and when certain events occured during an incident.
 

Microsoft Defender for Identity Cons review quotes

reviewer1043151 - PeerSpot reviewer
Cyber Security BA/BSA at a insurance company with 10,001+ employees
Mar 13, 2021
When the data leaves the cloud, there are security issues.
DS
Enterprise Architect at NTT New Zealand Ltd.
Sep 9, 2021
The solution could be better at using group-managed access and they could replace it with broad-based access controls.
reviewer1687521 - PeerSpot reviewer
Senior Infrastructure Security Engineer at a tech services company with 51-200 employees
Oct 5, 2021
I would like to be able to do remediation from the platform because it is just a scanner right now. If you onboard a device, it shows you what is happening, but you can't use it to fix things. You need to go into the system to fix it instead.
Learn what your peers think about Microsoft Defender for Identity. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
reviewer1688547 - PeerSpot reviewer
Security specialist at a manufacturing company with 10,001+ employees
Oct 6, 2021
The impact of the sensors on the domain controllers can be quite high depending on your loads. I don't know if there's any room for improvement there, but that's one of the things that might be improved.
Sachin Vinay - PeerSpot reviewer
Assistant Manager-Networks at a university with 1,001-5,000 employees
Dec 3, 2022
There is no option to remedy an issue directly from the console. If we see an alert, we can't fix it from the console. Instead, we must depend on other Microsoft products, such as MDE. That is a significant drawback. It simply works as a scanner, which can sometimes put enough load on the sensors. Immediate actions should be possible from the dashboard because. It can prevent issues from spreading further.
BK
IT Manager at vTech4U
Mar 31, 2023
The technical support needs significant improvement. Documentation for more minor issues in the form of guides or walkthroughs could help to resolve this issue. The number of tickets raised would decrease, removing some pressure from the support team and making it easier to clear the remaining tickets.
BS
Lead Security Analyst at a tech vendor with 10,001+ employees
Apr 13, 2023
We observe a lot of false positives. Sometimes, when we go for a coffee break, we lock our screens. Locking the screen has a separate Windows event ID and sometimes I see it is detected as a failed login.
Iñaki Martinez Urricelqui - PeerSpot reviewer
Threat Analysis Technology Risk & Cybersecurity Analyst II at a consultancy with 5,001-10,000 employees
Apr 17, 2023
And when you are working in a priority IP address, Identity is not able to know that those IPs are from the company. It sees that the IPs are from Taiwan or from Hong Kong or from India, even though they are internal IPs, resulting in a lot of false positives.
Emeka Ndulu - PeerSpot reviewer
Cloud Solutions Architect at a tech services company with 201-500 employees
Apr 18, 2023
An area for improvement is the administrative interface. It's basic compared to other administrative centers. They could make it more user-friendly and easier to navigate.
Matthew Bouwer - PeerSpot reviewer
Cyber Security Analyst at a tech services company with 1,001-5,000 employees
Apr 20, 2023
Defender for Identity gives us visibility, but we often get false positives from Azure that take us down the garden path. We go through 30 incidents each day and most of those are false positives or benign positive alerts. Occasionally, we get true positive alerts.