• HOME
  • CATEGORIES

    • CATEGORIES

    • Application Development

      • Observability Platforms
      • Integrated Development Environment (IDE) Software
      • Enterprise Agile Planning Tools
      • Integration Platform as a Service
      • AI-Augmented Software Testing Tools
      • View All
    • Artificial Intelligence

      • AI Code Assistants (Transitioning to AI Coding Agents)
      • Generative AI Knowledge Management Apps/General Productivity
      • AI Application Development Platforms
      • Artificial Intelligence Applications in IT Service Management (Transitioning to AI Applications in IT Service Management)
      • Conversational AI Platforms
      • View All
    • Cloud Computing

      • Backup and Data Protection Platforms
      • Cloud Database Management Systems
      • Strategic Cloud Platform Services
      • Server Virtualization (Transitioning to Server Virtualization Platforms)
      • Hybrid Cloud Storage
      • View All
    • Customer Relationship Management

      • Contact Center as a Service
      • CRM Customer Engagement Center
      • Digital Experience Platforms
      • Web Content Management
      • Field Service Management
      • View All
    • Data and Analytics

      • Analytics and Business Intelligence Platforms
      • Data Science and Machine Learning Platforms (Transitioning to AI Platforms For Data Science and Machine Learning)
      • Data Integration Tools
      • Process Mining Platforms (Transitioning to Process Intelligence Platforms)
      • Augmented Data Quality Solutions
      • View All
    • Education

      • Manager and Leadership Training
      • Corporate Learning Technologies
      • eLearning Authoring Tools
      • Higher Education Student Information System Software as a Service (Transitioning to Higher Education SaaS Student Information Systems)
      • Digital Learning Content Providers
      • View All
    • Enterprise Networking and Communications

      • Unified Communications as a Service
      • Global WAN Services
      • Intranet Packaged Solutions
      • SD-WAN
      • Edge Distribution Platforms
      • View All
    • Finance

      • Expense Management Software
      • Financial Planning Software
      • Financial Close and Consolidation Solutions
      • Cloud Financial Management Tools
      • Accounts Payable Applications
      • View All
    • Healthcare and Life Sciences

      • Medical Device Security Solutions (Transitioning to Medical Device Risk Management Platforms)
      • Health Navigation Solutions
      • Claim Editor Software
      • Revenue Cycle Management Software (Transitioning to Revenue Cycle Management Solutions)
      • Digital Health Platforms (Transitioning to Healthcare Provider Industry Cloud Platforms)
      • View All
    • Human Resources

      • Employee Recognition and Reward Systems
      • Workforce Management Applications (Transitioning to Workforce Management (WFM) Technology)
      • Digital Employee Experience Management Tools
      • Talent Acquisition (Recruiting) Suites
      • Cloud HCM Suites for Regional and/or Sub-1,000 Employee Enterprises
      • View All
    • IT Infrastructure and IoT

      • Enterprise Wired and Wireless LAN Infrastructure (Transitioning to Enterprise Wired and Wireless LAN)
      • Endpoint Management Tools
      • IT Service Management Platforms
      • Container Management
      • Infrastructure Monitoring Tools
      • View All
    • IT Security

      • Endpoint Protection Platforms
      • Email Security
      • Managed Detection and Response
      • Security Information and Event Management
      • Security Awareness Computer-Based Training
      • View All
    • Legal

      • Contract Life Cycle Management
      • Electronic Signature
      • Governance, Risk and Compliance Tools, Assurance Leaders
      • Compliance Monitoring Solutions
      • Corporate Governance Services
      • View All
    • Manufacturing

      • Enterprise Asset Management Software
      • Manufacturing Execution Systems
      • Global Industrial IoT Platforms
      • PLM Software in Discrete Manufacturing Industries
      • Computer-Aided Design (CAD) Software
      • View All
    • Marketing

      • Video Editing Software
      • Email Marketing
      • Multichannel Marketing Hubs
      • Customer Data Platforms
      • Event Marketing and Management Platforms
      • View All
    • Productivity and Collaboration

      • Document Management
      • Collaborative Work Management
      • Visual Collaboration Applications
      • Knowledge Management (KM) Software
      • Meeting Solutions
      • View All
    • Public Sector and Government

      • Government Budgeting and Planning Solution
      • Cloud-Based ERP for U.S. Local Government
      • Government ERP Solutions
      • Citizen Service Delivery
      • Government Contracting Software
      • View All
    • Retail

      • Digital Commerce
      • Digital Commerce Payment Vendors (Transitioning to Digital Commerce Payment Platforms)
      • Retail Assortment Management Applications: Long Life Cycle Products
      • Retail Workforce Management Applications (Transitioning to Retail Workforce Management Technology)
      • Digital Shelf Analytics
      • View All
    • Sales

      • Revenue Enablement Platforms
      • Sales Force Automation Platforms (Transitioning to CRM Sales Platforms)
      • Revenue Intelligence (Transitioning to Revenue Action Orchestration)
      • Configure, Price and Quote Applications
      • Search and Product Discovery
      • View All
    • Supply Chain Management

      • Supply Chain Planning Solutions
      • Transportation Management Systems
      • Real-Time Transportation Visibility Platforms
      • Warehouse Management Systems
      • Supply Chain Strategy, Planning and Operations Consulting
      • View All
    • Utilities

      • Geospatial Information Systems for Energy and Utilities
      • Mobile Workforce Management Software for Utilities (Transitioning to Mobile Workforce Management Solutions for Power and Utilities)
      • Energy Management and Optimization Systems
      • Energy Trading and Risk Management
      • Advanced Distribution Management Systems
      • View All
    • Browse All Categories
  • FOR VENDORS

    • FOR VENDORS

    • Log In to Vendor Portal
    • Get Started
  • REVIEWS

    • REVIEWS

    • Write a Review
    • Product Reviews
    • Vendor Directory
    • Product Comparisons
  • GARTNER PEER COMMUNITY™
  • GARTNER.COM
  • Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQPrivacyTerms of Service
    ©2026 Gartner, Inc. and/or its affiliates.
    All rights reserved.
  • Categories

      • Application Development
      • Artificial Intelligence
      • Cloud Computing
      • Customer Relationship Management
      • Data and Analytics
      • Education
      • Enterprise Networking and Communications
      • Finance
      • Healthcare and Life Sciences
      • Human Resources
      • IT Infrastructure and IoT
      • IT Security
      • Legal
      • Manufacturing
      • Marketing
      • Productivity and Collaboration
      • Public Sector and Government
      • Retail
      • Sales
      • Supply Chain Management
      • Utilities
      Browse All Categories

      Application Development

      69 markets
      • Observability Platforms
      • Integrated Development Environment (IDE) Software
      • Enterprise Agile Planning Tools
      • Integration Platform as a Service
      • AI-Augmented Software Testing Tools
      • API Management
      • Enterprise Low-Code Application Platforms
      • Robotic Process Automation
      • DevOps Platforms (Transitioning to DevSecOps Platforms)
      • Business Process Automation Tools
      • Enterprise Architecture Tools
      • Business Orchestration and Automation Technologies
      • Custom Software Development Services
      • Code Review Tools
      • Digital Adoption Platforms
      • Domain Registrars
      • Game Engine Software
      • Public Cloud IT Transformation Services (Transitioning to Public Cloud Optimization and Transformation Services)
      • Website Builders
      • Developer Productivity Insight Platforms
      • AI Agents for Application Developers
      • Application Platforms (Transitioning to Cloud-Native Application Protection Platforms)
      • Feature Management
      • Application Crowdtesting Services
      • Test Data Management
      • API Generation Software
      • Prototyping Software
      • Mobile App Analytics
      • AI-Augmented Code Modernization Tools
      • Virtual Reality Development Software
      • Application Testing Services, Worldwide (Transitioning to Quality Engineering Services)
      • Green Software Engineering
      • Event Brokers
      • Application Integration Platforms
      • Digital Twin of an Organization Platforms
      • Independent Third-Party Software Support of Megavendors
      • Microsoft 365 Implementation and Support Services
      • Application Development Life Cycle Management (Transitioning to DevOps Platforms)
      • BPM-Platform-Based Case Management Frameworks
      • Microsoft Product Support Services
      • Product Roadmapping Tools for Software Engineering
      • Multiexperience Development Platforms
      • AI Agent Development Platforms for Software Engineering
      • Application Portfolio Management Tools
      • Application Composition Platform
      • Internal Developer Portals
      • Cloud Development Environments
      • Mobile Development Frameworks (Transitioning to Web and Mobile Development Frameworks)
      • Load Testing Tools
      • Blockchain Consulting and Proof-of-Concept Development Services
      • B2B Gateway Software
      • Citizen Application Development Platforms
      • Mobile Application Testing Services
      • SAP S/4HANA Application Services, Worldwide (Transitioning to Cloud ERP Services)
      • Oracle Cloud Application Services, Worldwide (Transitioning to Cloud ERP Services)
      • SAP Application Services, Worldwide
      • SAP SuccessFactors Service Providers (Transitioning to Cloud ERP Services)
      • Service Mesh
      • Value Stream Management Platforms
      • Business-Outcome-Driven Enterprise Architecture Consulting (Retired)
      • Oracle Application Services, Worldwide (Transitioning to Cloud ERP Services)
      • Rapid Mobile App Development Tools
      • SAP Selective Test Data Management Tools
      • API and MCP Testing Tools
      • Augmented Reality Development Software
      • Blockchain as a Service
      • Mobile Application Management (Transitioning to Endpoint Management Tools)
      • Mobile Back-End Services
      • R&D Outsourcing Providers
      View More
  • For Vendors

    • Log In to Vendor Portal 

    • Get Started 

  • Write a Review

Join / Sign In
  1. Home
  2. /
  3. Microsoft Defender for Identity
Logo of Microsoft Defender for Identity

Microsoft Defender for Identity

byMicrosoft
in
4.3
Market Presence: Insider Risk Management Solutions, Identity Threat Detection and Response (ITDR)

Overview

Product Information on Microsoft Defender for Identity

Updated 14th October 2025

What is Microsoft Defender for Identity?

Microsoft Defender for Identity is a software designed to help organizations detect and investigate advanced identity-related threats within on-premises Active Directory environments. It provides real-time monitoring and analysis of user activities, behaviors, and permissions to identify potential security risks such as compromised accounts, lateral movement, and reconnaissance efforts. The software uses data from Active Directory signals and network traffic to pinpoint suspicious actions and provide actionable insights for security operations teams. Its integration with broader security platforms allows streamlined incident response and supports investigations by enabling visibility into identity-based attacks targeting businesses.

Microsoft Defender for Identity Pricing

Microsoft Defender for Identity software adopts a subscription-based pricing model, typically offered per user per month. The pricing structure may vary depending on features, deployment size, and the integration with other Microsoft security solutions. Licenses are generally available as part of Microsoft 365 security packages or can be purchased separately with different tiers based on organizational requirements.

Overall experience with Microsoft Defender for Identity

CLOUD APPLICATION SECURITY ENGINEER
Gov't/PS/ED <5,000 Employees, Education
FAVORABLE

“Enhanced Threat Detection in Active Directory With Improved Microsoft Integration”

4.0
Nov 25, 2025
We have deployed Defender for Identity to cover our hybrid identities that exist within our on-prem AD instance and our Entra environment. In practice, it's been a net win due to its ability to spot identity driven attacks within Active Directory. The tradeoff on this was due to the initial alert volume for normal user behavior, so the value depends on your willingness to own and manage the tool internally.
It Security & Risk Management Associate
<50M USD, Energy and Utilities
CRITICAL

“Integrated Threat Detection in Defender for Identity for Microsoft-centric environments.”

3.0
Feb 24, 2026
The overall experience for admins in Microsoft Defender for Identity (MDI) is streamlined, intelligent and very well integrated, especially for Microsoft-centric environments. Administrators are now able to access this through the unified security portal, making it very easy to administer, review alerts and customise. This interface is very much designed with SOC users in mind, well done Microsoft!

About Company

Company Description

Updated 11th August 2023

Microsoft enables digital transformation for the era of an intelligent cloud and an intelligent edge. Its mission is to empower every person and every organization on the planet to achieve more. Microsoft is dedicated to advancing human and organizational achievement. Microsoft Security helps protect people and data against cyberthreats to give peace of mind.

Company Details

Updated 25th March 2024
Company type
Public
Year Founded
1975
Head office location
Redmond, Washington, United States
Number of employees
10000+
Annual Revenue
30B+ USD
Website
https://microsoft.com

Do You Manage Peer Insights at Microsoft?

Access Vendor Portal to update and manage your profile.

Key Insights

A Snapshot of What Matters - Based on Validated User Reviews

User Sentiment About Microsoft Defender for Identity
Reviewer Insights for: Microsoft Defender for Identity
Deciding Factors: Microsoft Defender for Identity Vs. Market Average
Performance of Microsoft Defender for Identity Across Market Features

Microsoft Defender for Identity Likes & Dislikes

Like

1. Active Directory focused detection. The detections around threats like lateral movement of credential theft were strong and gave us visibility we didn't have previously, to the point where we found real bad actors threats within the first month as a result. 2. Good context within Microsoft Defender XDR. Alerts come in with timelines and excellent context which enables faster triage without the pain points of engaging in raw log hunting. 3. Integration with the rest of the Microsoft Security stack made correlation clean and reduced much of the tool and context switching that came come from having disparate tools.

Like

The best feature is the strong identity-based threat detection. The behavioral analytics engine does an excellent job of detecting attacks such as Pass-the-Hash, Golden Ticket attacks, as well as identifying suspicious lateral movement. The attack timeline and entity mapping make it very easy to understand how an incident unfolded and can significantly speed up investigations. Another positive for MDI is its seamless integration with the Microsoft Security Ecosystem, embedded within Defender XDR, a truly unified experience can be achieved across endpoints, email, cloud apps and identities. Finally, its very low maintenance once setup. From an admin perspective, its heavily reliant on simple sensor deployment on domain controllers with minimal infrastructure maintenance and updates.

Like

Its seamless integration with Microsoft's security ecosystem provides visibility into on-prem and cloud environments. Its capability to analyze massive number of signals on a daily basis allows org to quickly identify and detect complex identity-based attacks and features like automated response can perform the pre-defined response for such attacks without human intervention.

Dislike

1. Initial setup can be painful if you don't have a solid understanding of your Active Directory topology, otherwise it's far too easy to scope sensors improperly or even misread alerts. 2. While detection is strong, the native one-click remediation actions are quite a bit lighter than what I've seen from other tools. Manual playbooks or custom created automated remediations are still required. 3. Pricing was reasonable given the number of identities and DCs we were working with, but it's still something to consider if you still have a small AD footprint still.

Dislike

One of the biggest drawbacks is the lack of use outside of Microsoft environments. While this is great within our Microsoft stack, we are left looking at other vendors for Identity protection among many of our other platforms. Also, during setup and onboarding, the platform can become very noisy with a lot of false-positive alerts. You will find that a lot of time needs to be allocated to tuning alerts in the early days to make best use of your analysts time. Finally, the flexibility and granular controls you would expect from a Microsoft solution are not present here. This is very much an off-the-shelf product with little room to customise if your environment has a particular niche.

Dislike

If the service is not configured properly, it can create an overwhelming number of alerts that can lead to many false-positive alerts. Although it integrates seamlessly with Microsoft services and platforms, it has limited integration capability with third parties.

Top Microsoft Defender for Identity Alternatives

Logo of Varonis Unified Data Security Platform
1. Varonis Unified Data Security Platform
4.7
(260 Ratings)
Logo of Falcon Next-Gen Identity Security
2. Falcon Next-Gen Identity Security
4.6
(148 Ratings)
Logo of Proofpoint Insider Threat Management
3. Proofpoint Insider Threat Management
4.6
(115 Ratings)
View All Alternatives

Peer Discussions

Microsoft Defender for Identity Reviews and Ratings

4.3

(163 Ratings)

Rating Distribution

5 Star
42%
4 Star
50%
3 Star
7%
2 Star
0%
1 Star
1%
Why ratings and reviews count differ?

Customer Experience

Evaluation & Contracting

4.3

Integration & Deployment

4.5

Service & Support

4.2

Product Capabilities

4.4

Filter Reviews
Sort By:
Most helpful
Last 12 Months
Star Rating
Reviewer Type
Reviewer's Company Size
Reviewer's Industry
Reviewer's Region
Reviewer's Job Function
  • It Security & Risk Management Associate
    <50M USD
    Energy and Utilities
    Review Source

    Integrated Threat Detection in Defender for Identity for Microsoft-centric environments.

    3.0
    Feb 24, 2026
    The overall experience for admins in Microsoft Defender for Identity (MDI) is streamlined, intelligent and very well integrated, especially for Microsoft-centric environments. Administrators are now able to access this through the unified security portal, making it very easy to administer, review alerts and customise. This interface is very much designed with SOC users in mind, well done Microsoft!
  • CLOUD APPLICATION SECURITY ENGINEER
    Gov't/PS/Ed
    Education
    Review Source

    Enhanced Threat Detection in Active Directory With Improved Microsoft Integration

    4.0
    Nov 25, 2025
    We have deployed Defender for Identity to cover our hybrid identities that exist within our on-prem AD instance and our Entra environment. In practice, it's been a net win due to its ability to spot identity driven attacks within Active Directory. The tradeoff on this was due to the initial alert volume for normal user behavior, so the value depends on your willingness to own and manage the tool internally.
  • IT SECURITY & RISK MANAGEMENT ASSOCIATE
    50M-1B USD
    Services (non-Government)
    Review Source

    Seamless Integration With Microsoft Ecosystem Enhances Hybrid Identity Security Monitoring

    4.0
    Sep 15, 2025
    Microsoft ITDR has proven to be an effective and robust solution to strengthen the identity security posture for organizations. It easily integrates with other Microsoft security platforms like Defender or Entra that can provide you with real-time threat detection and will also provide you with visibility across hybrid environments.
  • Network And Security Engineer
    50M-1B USD
    Services (non-Government)
    Review Source

    Tool Integrates with Security Systems to Enhance Identity Protection and Monitoring

    5.0
    Feb 26, 2026
    For over 5 years now, Microsoft Defender for Identity has consistently proven to be a highly effective tool for detecting and responding to threats, keeping both user identities and our organization’s environment safe and protected.The tool uses machine learning and advanced analytics to identify suspected malicious behavior and anomalies which helps us to know them at an early stage before any serious damage is caused to our network.Also seamlessly integrates wtih other Microsoft Defender tools and security systems which significantly simplifies the whole process of monitoring and protection.
  • Forensic Analyst
    <50M USD
    IT Services
    Review Source

    MS Defender Operates Quietly in Background While Alerting to Potential Threats

    5.0
    Dec 26, 2025
    My experience with MS Defender was smooth and seamless. I see it running in the background most of the time and I infrequently pull it up to see how things are going. Also when there are scans, I always know what's going on and if I have any threats to deal with.
...
Showing Result 1-5 of 208

Recommended Gartner Research

  • Market Guide for Insider Risk Management Solutions

Gartner Peer Insights content consists of the opinions of individual end users based on their own experiences, and should not be construed as statements of fact, nor do they represent the views of Gartner or its affiliates. Gartner does not endorse any vendor, product or service depicted in this content nor makes any warranties, expressed or implied, with respect to this content, about its accuracy or completeness, including any warranties of merchantability or fitness for a particular purpose.

This site is protected by hCaptcha and its Privacy Policy and Terms of Use apply.


Software reviews and ratings for EMMS, BI, CRM, MDM, analytics, security and other platforms - Peer Insights by Gartner
Community GuidelinesListing GuidelinesBrowse VendorsRules of EngagementFAQsPrivacyTerms of Use

©2026 Gartner, Inc. and/or its affiliates.

All rights reserved.