TrustRadius: an HG Insights company

Microsoft Defender for Identity vs. Splunk User Behavior Analytics

Save this comparison

Save this comparison

Add Product

Recommended Comparisons

    Overview
    ProductRatingMost Used ByProduct SummaryStarting Price

    Microsoft Defender for Identity

    Score7.7 out of 10
    N/AMicrosoft Defender for Identity (formerly Azure Advanced Threat Protection, also known as Azure ATP) is a cloud-based security solution that leverages on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions directed at the organization.N/A

    Splunk User Behavior Analytics

    Score5.9 out of 10
    N/ASplunk supplies security analytics as a standalone solution or priced as an add-on for users of its popular SIEM products, to protect enterprises against unknown threats and malicious behavior, via the Splunk User Behavior Analytics application.N/A
    Pricing
    Microsoft Defender for IdentitySplunk User Behavior Analytics
    Editions & Modules
    No answers on this topic
    No answers on this topic
    Offerings
    Pricing Offerings
    Microsoft Defender for IdentitySplunk User Behavior Analytics
    Free Trial
    NoNo
    Free/Freemium Version
    NoNo
    Premium Consulting/Integration Services
    NoNo
    Entry-level Setup FeeNo setup feeNo setup fee
    Additional Details
    More Pricing Information
    User Ratings
    Microsoft Defender for IdentitySplunk User Behavior Analytics
    Likelihood to Recommend
    7.0
    (1 ratings)
    10.0
    (2 ratings)
    Support Rating
    -
    (0 ratings)
    9.0
    (1 ratings)
    User Testimonials
    Microsoft Defender for IdentitySplunk User Behavior Analytics
    Likelihood to Recommend
    Microsoft
    Microsoft Defender for Identity is a great solution for each company that has an Active Directory. It fills in the blanks for Identity related incidents that are being missed in the XDR platform. To get a full view on identity risks it is an essential component
    Read full review
    Cisco
    Splunk User Behavior Analytics application is necessary when any company wants to capture the threat based on user behavior instead of just counting the number of occurrences of particular event. With Splunk UBA, we can analyse number of anomalies captured and which in turn creating threats which are nearly true positive.
    Incentivized
    Read full review
    Pros
    Microsoft
    • detect threats and suspicious activities
    • pro-active measurements on possible breaches
    • identity security posture
    Read full review
    Cisco
    • Monitor and troubleshoot for any system errors.
    • Get the insights on application data sets and do some predictive analysis.
    Incentivized
    Read full review
    Cons
    Microsoft
    • setup can be complicated, with AD complexity
    • Sometimes the load on DCs is pretty high, leading to performance issues
    • Better tuning options for preventing false-positive/bening alerts
    Read full review
    Cisco
    • Performance-wise, it can be improved. Queries take a long time.
    • Dataset exploration - More data visualization charts can be added.
    Incentivized
    Read full review
    Alternatives Considered
    Microsoft
    Microsoft Defender for Identity is more specialized on the Identity platform, it is a single solution compared to a multi-solution. The integration is better when using the XDR suite in combination with Sentinel. Microsoft Defender for Identity gives a better overview of the security posture
    Read full review
    Cisco
    Easier we were using Splunk Enterprise on heavy forwarder on which all the add-on were installed and were using Splunk Cloud with respect to search head and indexers stack. And with Splunk Enterprise Security premium app, we were relying on correlation rules which were throwing more number of false positive but after implementing Splunk UBA, we are now getting real-time true positive threat or incidents.
    Incentivized
    Read full review
    Return on Investment
    Microsoft
    • Cost impact was pretty high
    • Learning curve, needed time (money) for training
    • Greatly improved detections and gives more insights
    Read full review
    Cisco
    • Fewer team members to work on real threats.
    • Less time required to deal with real incidents.
    • Easy to implement across the network.
    Incentivized
    Read full review
    ScreenShots