• HOME
  • CATEGORIES

    • CATEGORIES

    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

    • No categories available

      Browse All Categories

      Select a category to view markets

  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. Microsoft Defender for Identity
Logo of Microsoft Defender for Identity

Microsoft Defender for Identity

byMicrosoft
in
4.4
Market Presence: Identity Threat Detection and Response (ITDR), Insider Risk Management Solutions

Overview

Product Information on Microsoft Defender for Identity

Updated 14th October 2025

What is Microsoft Defender for Identity?

Microsoft Defender for Identity is a software designed to help organizations detect and investigate advanced identity-related threats within on-premises Active Directory environments. It provides real-time monitoring and analysis of user activities, behaviors, and permissions to identify potential security risks such as compromised accounts, lateral movement, and reconnaissance efforts. The software uses data from Active Directory signals and network traffic to pinpoint suspicious actions and provide actionable insights for security operations teams. Its integration with broader security platforms allows streamlined incident response and supports investigations by enabling visibility into identity-based attacks targeting businesses.

Microsoft Defender for Identity Pricing

Microsoft Defender for Identity software adopts a subscription-based pricing model, typically offered per user per month. The pricing structure may vary depending on features, deployment size, and the integration with other Microsoft security solutions. Licenses are generally available as part of Microsoft 365 security packages or can be purchased separately with different tiers based on organizational requirements.

Overall experience with Microsoft Defender for Identity

Operations Manager
<50M USD, Real Estate
FAVORABLE

“Effective real-time threat detection, but overwhelming alert volumes hinder workflow”

5.0
May 31, 2026
Based on our experience, what has worked well in using this product is since our common arrangement in outsourcing is we access records from multiple locations. This product is valuable to us as it is able to detect suspicious activity, credential theft and unauthorized access attempts. What hasn't worked well for us so far is the volume of security alerts we receive, as we have high employee turnover resulting in new login activities, we also have volume of alerts that are unnecessary to review.
It Security & Risk Management Associate
<50M USD, Energy and Utilities
CRITICAL

“Integrated Threat Detection in Defender for Identity for Microsoft-centric environments.”

3.0
Feb 24, 2026
The overall experience for admins in Microsoft Defender for Identity (MDI) is streamlined, intelligent and very well integrated, especially for Microsoft-centric environments. Administrators are now able to access this through the unified security portal, making it very easy to administer, review alerts and customise. This interface is very much designed with SOC users in mind, well done Microsoft!

About Company

Company Description

Updated 11th August 2023

Microsoft enables digital transformation for the era of an intelligent cloud and an intelligent edge. Its mission is to empower every person and every organization on the planet to achieve more. Microsoft is dedicated to advancing human and organizational achievement. Microsoft Security helps protect people and data against cyberthreats to give peace of mind.

Company Details

Updated 25th March 2024
Company type
Public
Year Founded
1975
Head office location
Redmond, Washington, United States
Number of employees
10000+
Annual Revenue
30B+ USD
Website
https://microsoft.com

Do You Manage Peer Insights at Microsoft?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

Top Microsoft Defender for Identity Alternatives

Logo of Varonis Unified Data Security Platform
1. Varonis Unified Data Security Platform
4.7
(260 Ratings)
Logo of Falcon Next-Gen Identity Security
2. Falcon Next-Gen Identity Security
4.6
(206 Ratings)
Logo of Proofpoint Insider Threat Management
3. Proofpoint Insider Threat Management
4.6
(115 Ratings)
View All Alternatives

Peer Discussions

Microsoft Defender for Identity Reviews and Ratings

4.4

(247 Ratings)

Rating Distribution

5 Star
44%
4 Star
49%
3 Star
6%
2 Star
0%
1 Star
0%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.2

Integration & Deployment

4.5

Service & Support

4.2

Product Capabilities

4.5

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • It Security & Risk Management Associate
    <50M USD
    Energy and Utilities
    Review Source

    Integrated Threat Detection in Defender for Identity for Microsoft-centric environments.

    3.0
    Feb 24, 2026
    The overall experience for admins in Microsoft Defender for Identity (MDI) is streamlined, intelligent and very well integrated, especially for Microsoft-centric environments. Administrators are now able to access this through the unified security portal, making it very easy to administer, review alerts and customise. This interface is very much designed with SOC users in mind, well done Microsoft!
  • Operations Manager
    <50M USD
    Real Estate
    Review Source

    Effective real-time threat detection, but overwhelming alert volumes hinder workflow

    5.0
    May 30, 2026
    Based on our experience, what has worked well in using this product is since our common arrangement in outsourcing is we access records from multiple locations. This product is valuable to us as it is able to detect suspicious activity, credential theft and unauthorized access attempts. What hasn't worked well for us so far is the volume of security alerts we receive, as we have high employee turnover resulting in new login activities, we also have volume of alerts that are unnecessary to review.
  • Software Developer
    <50M USD
    Software
    Review Source

    Unified Identity Visibility Enhances Detection Yet Remains Tied to Microsoft Ecosystem

    4.0
    Apr 21, 2026
    The overall experience with this piece of software has been strong, especially as part of a broader Microsoft security stack. It's not a standalone ITDR tool, but rather a deeply integrated solution that brings identity signals into a unified security ecosystem. What stands out is the visibility - it correlates identity activity across on-prem, cloud and even third-party identity providers, giving a much clearer picture of what's happening across the environment.
  • IT Security & Risk Management Associate
    10B+ USD
    Banking
    Review Source

    Effective identity threat detection with seamless hybrid environment integration

    5.0
    Jun 2, 2026
    Microsoft ITDR across Entra ID and on-premises AD has been working well for us. Anomaly detection is effective at catching identity-based threats, and real-time alerting means we get notified quickly when something looks suspicious. Automated response capabilities like account lockdown and MFA enforcement are reliable. Integration between Entra ID and our on-prem AD has been smooth, and both are feeding threat intelligence to our deteciton pipleline without issues.
  • Communications Manager
    50M-1B USD
    Consumer Goods
    Review Source

    It facilitates identity monitoring, but requires adaptation to alerts.

    5.0
    Jun 1, 2026
    We've had a good experience with Microsoft Defender for Identity. We implemented it primarily to gain more visibility into what's happening in Active Directory and to detect suspicious behavior that's difficult to identify. It has helped us detect risks related to users, credentials, and network activity.
    Automated Translation from Spanish
...
Showing Result 1-5 of 301

Recommended Gartner Insights

Powered by Google TranslateThis service may contain translations provided by Google. Google disclaims all warranties related to the translations, express or implied, including any warranties of accuracy, reliability, and any implied warranties of merchantability, fitness for a particular purpose and noninfringement. Gartner's use of this provider is for operational purposes and does not constitute an endorsement of its products or services.

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.

User Sentiment About Microsoft Defender for Identity
Reviewer Insights for: Microsoft Defender for Identity
Deciding Factors: Microsoft Defender for Identity Vs. Market Average

Microsoft Defender for Identity Likes & Dislikes

Like

The standout features of this product are the following: - It is able to identify the threat in real time before it leads to a serious breach. - It protects employee and client accounts from credential theft - It secures hybrid and remote work locations for our employees and clients

Like

The best feature is the strong identity-based threat detection. The behavioral analytics engine does an excellent job of detecting attacks such as Pass-the-Hash, Golden Ticket attacks, as well as identifying suspicious lateral movement. The attack timeline and entity mapping make it very easy to understand how an incident unfolded and can significantly speed up investigations. Another positive for MDI is its seamless integration with the Microsoft Security Ecosystem, embedded within Defender XDR, a truly unified experience can be achieved across endpoints, email, cloud apps and identities. Finally, its very low maintenance once setup. From an admin perspective, its heavily reliant on simple sensor deployment on domain controllers with minimal infrastructure maintenance and updates.

Like

Between the things that I like the most are the holistic identity visibility. One of the biggest strengths is the unified identity view. It correlates identities across multiple systems, so security teams can see a single, consolidated profile of a user, including privileges and risk signals. Defender for Identity is particularly good at detecting classic identity-based attacks, such as lateral movement, credential theft, and privilege escalation. It monitors behavior patterns and flash anomalies early in the attack chain. The automated response capabilities is also very helpful. It can trigger automated actions like blocking access, enforcing conditional access, or escalating incidents - helping SOC teams respond faster without manual intervention.

Dislike

The main issues we encounter for this product are the following: - It gives the volume number of login and authentication alerts - It requires skilled personnel who will be able to understand which alerts should be investigated - It may be a cost concern for us as a growing company as there could be a cost increase for a need of additional added security

Dislike

One of the biggest drawbacks is the lack of use outside of Microsoft environments. While this is great within our Microsoft stack, we are left looking at other vendors for Identity protection among many of our other platforms. Also, during setup and onboarding, the platform can become very noisy with a lot of false-positive alerts. You will find that a lot of time needs to be allocated to tuning alerts in the early days to make best use of your analysts time. Finally, the flexibility and granular controls you would expect from a Microsoft solution are not present here. This is very much an off-the-shelf product with little room to customise if your environment has a particular niche.

Dislike

The fact that the best value is only inside the Microsoft Ecosystem. Defender for Identity works best if you're already heavily invested in Microsoft. Outside that ecosystem, it can feel limited compared to more vendor-agnostic ITDR tools. Compared to some newer ITDR platforms, customization and tuning options can feel restricted. You often rely on Microsoft's built-in detections rather than crafting your own logic. Also, it is powerful, but it's really just one component of a broader Defender suite. If you're looking for a single, independent ITDR product, this may feel incomplete without the rest of the stack.