--- title: Microsoft Defender for Cloud Reviews meta_title: 'Microsoft Defender for Cloud Reviews 2026: Details, Pricing, & Features | G2' meta_description: Filter 456 reviews by the users' company size, role or industry to find out how Microsoft Defender for Cloud works for a business like yours. aggregate_rating: rating_value: 4.4 review_count: 456 scale: '5' date_modified: '2026-09-30' parent_category: name: Cloud Security url: https://www.g2.com/categories/cloud-security ---

Microsoft Defender for Cloud Pros and Cons: Top 5 Advantages and Disadvantages

Quick AI Summary Based on G2 Reviews

Generated from real user reviews

Users value the robust security features of Microsoft Defender for Cloud, effectively protecting against diverse cyber threats. (120 mentions)
Users appreciate the comprehensive security of Microsoft Defender for Cloud, effectively protecting against various cyber threats. (91 mentions)
Users praise the robust security features of Microsoft Defender for Cloud, enhancing threat detection and prevention effectively. (70 mentions)
Users appreciate the security alerts from Microsoft Defender for Cloud, enhancing their overall cloud security experience. (62 mentions)
Users value the effective threat detection of Microsoft Defender for Cloud, ensuring robust security for their cloud resources. (56 mentions)
Users find the complexity of configuration in Microsoft Defender for Cloud challenging, affecting their overall experience. (26 mentions)
Users note that while Microsoft Defender for Cloud is excellent, it can be expensive for small to medium businesses. (23 mentions)
Users experience delayed detection with Microsoft Defender for Cloud, often missing suspicious threats and alerts. (21 mentions)
Users find the complex interface and downtimes of Microsoft Defender for Cloud detracting from its overall usability. (19 mentions)
Users experience false positives in Microsoft Defender for Cloud, leading to confusion over legitimate files being flagged. (18 mentions)

5 Pros or Advantages of Microsoft Defender for Cloud

5 Cons or Disadvantages of Microsoft Defender for Cloud

Delon R.
DR
Delon R.
Graphic Designer
Graphic Design
Small-Business (50 or fewer emp.)
"Security and solid virus/malware defence "
4/5
What do you like best about Microsoft Defender for Cloud?

The ease of use with regards to reviewing the analytics and peace of mind not having to worry about viruses and malware on Microsoft Subsystems. Improving commerce and able to help efficiency as to which attempts to infiltrate the systems are thwarted. As a bonus, Microsoft offers free trials to those who are unsure whether this is the right software for enhanced peace of mind. Totally recommend! Review collected by and hosted on G2.com.

What do you dislike about Microsoft Defender for Cloud?

There's not that much to dislike about the software. It's a rather solid system that runs in the background, however memberships need to be renewed after a specified time in the contract. Review collected by and hosted on G2.com.

Aathikesavar V.
AV
Aathikesavar V.
Operations Executive
Small-Business (50 or fewer emp.)
"Comprehensive Cloud Security Made Easier with Microsoft Defender for Cloud"
5/5
What do you like best about Microsoft Defender for Cloud?

What I like best about Microsoft Defender for Cloud is that it gives you a clear, centralized view of your security across different cloud environments. Instead of having to check multiple tools, you can identify risks, get useful recommendations, and take action from one place. I also appreciate how it helps make cloud security feel more manageable and proactive rather than overwhelming. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Defender for Cloud?

One thing I dislike about Microsoft Defender for Cloud is that it can feel a bit complex, especially for new users. With so many features, alerts, and recommendations, it may take some time to understand and prioritize what needs immediate attention. The interface and configuration can also feel overwhelming at first, particularly for smaller teams with limited cloud security experience. Review collected by and hosted on G2.com.

DS
Dan S.
System Administrator
Enterprise (> 1000 emp.)
"Excellent Cloud Visibility and Threat Detection with Microsoft Defender for Cloud"
5/5
What do you like best about Microsoft Defender for Cloud?

Microsoft Defender for Cloud provides excellent visibility and protection across our cloud environment, helping us spot security risks before they turn into real issues. The recommendations are clear, practical, and easy to act on, which makes it simpler for our IT team to maintain a secure infrastructure day to day. As a hospitality business that handles both guest and business data, the continuous monitoring and threat detection give us peace of mind and help us maintain a strong security posture while keeping operations running smoothly. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Defender for Cloud?

There’s very little to dislike about Microsoft Defender for Cloud. However, the sheer number of recommendations and alerts can sometimes make it hard to quickly spot the most critical issues. Stronger prioritisation, along with more flexible filtering options, would make it easier to streamline security administration and focus on what matters most. Review collected by and hosted on G2.com.

Adrie B.
AB
Adrie B.
Chairman of the foundation
Small-Business (50 or fewer emp.)
"Attack Path Analysis That Makes Cloud Risk Actionable"
4.5/5
What do you like best about Microsoft Defender for Cloud?

It’s not just a scanner—it’s a control plane that connects posture findings to real remediation, and it’s become genuinely strong at doing that.

A few things that stand out for me:

Attack path analysis. This is the feature that changed how I run client conversations. Instead of handing someone a spreadsheet with 400 “high severity” findings, I can show an actual graph: “this exposed VM connects to this database with this over-permissioned identity, and here’s the three-hop path an attacker would take.” It turns abstract risk into a story leadership can actually follow, and it pushes prioritization instead of the usual whack-a-mole.

Unifying CSPM and CWPP in one place. Before this was consolidated, I was stitching together posture data from one tool and runtime threat detection from another for every client. Now I can see recommendations and active threat alerts in the same console, often tied to the same resource. That correlation—“this resource is misconfigured and is also showing suspicious activity right now”—is where the real value shows up.

Multi-cloud without needing a separate product. Being able to onboard an AWS account and evaluate it against the same posture framework as an Azure subscription, all in the same portal, still feels like a genuine win. A lot of clients end up with hybrid environments almost by accident (for example, shadow IT AWS accounts spun up by a dev team), and having one pane of glass to catch that is worth a lot.

Native reporting. I’ve mentioned this earlier, but it deserves its own callout: being able to build a CNAPP Executive Summary report inside the product and export it for a board deck—rather than exporting raw data into Power BI every quarter—has saved me hours per client.

If I had to pick just one highlight, though, it’s the attack path graph. It’s what turns “here’s a wall of alerts” into “here’s what actually matters and why,” and that’s basically the whole job of a security consultant. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Defender for Cloud?

The recommendation-noise problem never fully goes away. Even with the shift to individual, per-finding recommendations, the practical effect for a lot of shops is more line items, not fewer. Grouped recommendations were easier to triage at a glance; now I’m explaining to a client why they have 40 near-identical “update this package” entries instead of one grouped item. Granularity is great for engineers doing the actual remediation, but it’s a rougher experience for anyone trying to get a quick posture read.

Licensing and plan boundaries are genuinely confusing. Walking someone through which Defender plan covers which capability—and which sub-features are metered separately (looking at you, per-resource billing on things like Defender for Open-Source Relational Databases)—eats up real time in every engagement. It’s not that the pricing is unreasonable; it’s that it stays opaque until you’re already three tabs deep in the Azure pricing calculator.

The pace of change is exhausting to keep up with. New GA features, new deprecations, new permission requests (like the GitHub connector’s new artifact_metadata:write scope), and new default-behavior changes all land more or less monthly. That’s good for the product, but rough on a consultant who has to read every release note or risk a client asking, “Why did this alert disappear?” and not having an answer. Nobody has time to be a full-time Defender for Cloud news-tracker.

Defaults also quietly shift under you. Foundational CSPM moving to opt-in for new subscriptions this October is the current example—sensible from Microsoft’s cost perspective, but it means immature orgs that relied on “it just works out of the box” are going to lose baseline visibility without realizing it. I’ve seen this pattern before with other default changes, and it always turns into a wave of “Wait, why isn’t this showing up anymore?” support tickets.

Cross-cloud parity isn’t quite there yet. AWS and GCP support has improved a lot, but the depth of coverage—especially on workload protection, not just posture—still lags what you get natively in Azure. If a client is AWS-heavy with just a toe in Azure, I’m upfront that this won’t feel as first-class as it does for an Azure-native shop.

There’s also alert fatigue on the identity/OAuth side. As Defender for Cloud Apps keeps absorbing more governance surface (AI agent protection, unused app insights, etc.), the volume of identity-related findings has grown fast. It’s good coverage, but without dedicated headcount to triage it, a lot of clients just let it pile up—which defeats the purpose.

None of this is a dealbreaker—I still recommend it to nearly every Azure client—but it’s not a “set it and forget it” tool. Anyone selling it to leadership as one is setting expectations wrong. Review collected by and hosted on G2.com.

DEEPAK M.
DM
DEEPAK M.
Information Technology Specialist
Mechanical or Industrial Engineering
Mid-Market (51-1000 emp.)
"All-in-One Security Visibility and Strong Threat Protection Across Hybrid and Multi-Cloud"
4.5/5
What do you like best about Microsoft Defender for Cloud?

What I like most about Microsoft Defender for Cloud is how it brings security visibility, recommendations, and threat protection together in one place. It helps me quickly understand the security posture of servers, cloud resources, and workloads without having to check multiple tools. The clear recommendations, continuous monitoring, and alerts make it easier to identify risks and take action before they become serious issues. I also appreciate that it supports hybrid and multi-cloud environments, which makes it very useful for organisations managing both on-premises and cloud infrastructure. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Defender for Cloud?

What I like least about Microsoft Defender for Cloud is that the initial setup and configuration can feel complex, especially for organisations that are new to cloud security. Some recommendations and alerts may also require additional investigation to understand their actual priority, which can be time-consuming. The pricing structure for advanced features can be difficult to estimate as the environment grows. However, once properly configured and managed, the platform provides strong security visibility and valuable protection. Review collected by and hosted on G2.com.

Ahyar R.
AR
Ahyar R.
IBM IIS Server Upgrade – Bank Mandiri
Mid-Market (51-1000 emp.)
"Seamless Azure Integration with Robust, Real-Time Threat Detection"
5/5
What do you like best about Microsoft Defender for Cloud?

"The seamless integration with the Azure ecosystem and native Microsoft tools is a major plus. It offers robust, real-time threat detection and advanced protection for workloads like EKS/AKS containers, VMs, and databases without requiring complex agent deployments. The security alerts are highly detailed and help our team respond to incidents quickly." Review collected by and hosted on G2.com.

What do you dislike about Microsoft Defender for Cloud?

While it supports AWS and GCP, the integration and feature parity are not as seamless or deep as they are for native Azure resources. Setting up connectors can sometimes be clunky, and navigating the sub-menus within Microsoft Purview or the wider security center can feel overwhelming due to frequent UI layout updates. Review collected by and hosted on G2.com.

Bala V.
BV
Bala V.
Associate Data scientist
Enterprise (> 1000 emp.)
"Multi-Cloud Security Alerts and Compliance Audits in One Dashboard"
4/5
What do you like best about Microsoft Defender for Cloud?

The best thing is definitely the multi-cloud support. Like it allows you to see all the security alerts for Azure, AWS, and GCP in just one single dashboard. This saves a lot of time because you don't have to jump between different consoles to check if everything is safe.

Also, the regulatory compliance dashboard is super useful for audits. It tells you exactly where you are lacking and gives clear recommendations to fix it up quickly. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Defender for Cloud?

The biggest issue is definitely the costing, it can get very expensive real quick when you start turning on the advanced protection features for multiple environments. If you don't keep an eye on it, the monthly bill can give you a big surprise.

Another thing is the alerts can be too much sometimes. It gives a lot of false positives, which gets a bit annoying because you waste time investigating things that aren't actually a threat. Also, the UI feels a little sluggish or overwhelming when you trying to navigate through deep policy settings Review collected by and hosted on G2.com.

Ishita S.
IS
Ishita S.
Student
Small-Business (50 or fewer emp.)
"Centralized, Real-Time Cloud Security with Actionable Insights"
4.5/5
What do you like best about Microsoft Defender for Cloud?

What I like most about Microsoft Defender for Cloud is how it centralizes security monitoring across different cloud environments. It continuously evaluates security risks, provides clear, actionable recommendations, and helps detect threats in real time. Its integration with Microsoft Azure and other cloud services also streamlines security management and makes the overall process much more efficient. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Defender for Cloud?

One thing I dislike is that the platform can feel complex for new users because there are so many security features and configuration options to navigate. Some of the more advanced security capabilities can also drive up costs, and making sense of all the alerts and recommendations takes time and comes with a learning curve. Review collected by and hosted on G2.com.

Verified User in Information Technology and Services
CI
Verified User in Information Technology and Services
Mid-Market (51-1000 emp.)
"Strong Cloud Security with Actionable Recommendations"
4.5/5
What do you like best about Microsoft Defender for Cloud?

What I like most about Microsoft Defender for Cloud is the centralized view it gives me of the security posture across my cloud resources. It helps identify vulnerabilities, configuration gaps, and potential security risks, and then offers practical recommendations to remediate them. The Secure Score, along with the prioritized recommendations, makes it much easier to see what needs attention first and focus on the most important issues. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Defender for Cloud?

The biggest drawback for me is that the pricing and feature structure can be confusing. It also tends to generate a lot of recommendations, which can make it hard to tell which issues need immediate attention. Review collected by and hosted on G2.com.

Syed Junaid A.
SA
Syed Junaid A.
Cybersecurity Lead
Small-Business (50 or fewer emp.)
"Unified Security Dashboard with Strong XDR and Secure Score"
4.5/5
What do you like best about Microsoft Defender for Cloud?

It provides a single dashboard to monitor security recommendations, compliance status, vulnerabilities, and threats across the whole environment. The secure score is also a good feature it helps to remediate the risks and increase our score. The XDR feature is also very strong when integrated with Microsoft Sentinel. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Defender for Cloud?

I cannot say I dislike Microsoft Defender, but here are some points I want to highlight, like some features of Defender require an additional subscription they should be available in the Business Premium Plan, and I observe sometimes that the multi-cloud capabilities are not as seamless as Azure native integrations. Review collected by and hosted on G2.com.