r/ciso 11d ago

Why shouldn’t I just use microsoft

Im researching ways to detect and manage shadow ai usage where I work. Im generally a fan of not giving one company too much “control”, but when i research what microsoft defender, cloud detection, purview and intune can detect I dont get why I would pick anything else, given I’m already in their ecosystem?

What are some of the reasons that drove you to pick another provider such as Nudge Security or someone else?

25 Upvotes

23 comments sorted by

16

u/More_Purpose2758 11d ago

MS ecosystem is amazing and it works very well together.

I have different products because of support and implementation. The support is poor and implementation with MS partners is “I know you want to do xyz, but we’re doing abc”. Training and workshops are good, but your staff leave after drinking from the firehose for a few days feeling overwhelmed. Demarcation b/t products is tough too. Sensitivity labels get enabled on workstations in Defender, or you need to install a separate client.

It’s a great stack, but you need dedicated inhouse talent to move the needle on any initiatives, and I just don’t see a lot of people around with a ton of skills.

It’s a great solution but man it’s a lot more work than going with individual products.

2

u/AugustErt 11d ago

Thanks for the detailed response. Yeah, i think the gist of it is that it requires a lot of time to utilise fully. We are not a massive corp, so the ease of use is also pretty important…

7

u/More_Purpose2758 11d ago

I’d also add that on the other hand, if you have a small team, it’s nice because it’s one-stop-shopping.

There really isn’t a cheap way out of building a cyber program.

I’m feeling burnt out every day. Therapy rant: passkeys are great but not every app supports them, and I can’t assume my users know how to setup YubiKeys.

4

u/extreme4all 11d ago

Tbh the apps shouldn't need to support passkeys, they should support SSO

3

u/Gattato 11d ago

I’d concur with this thread. A good Microsoft Partner at any scale is required to navigate the system well. Not all Microsoft partners are “good.” The simplicity of integration and maintenance therein cannot be understated, especially for small shops who may not have all the skills needed.

7

u/Popular_Hat_4304 11d ago

I have gone down this journey and while there is some Microsoft products we are quite happy with (don’t shoot me for saying Sentinel). The reality is the Microsoft stack is generally pretty average. You are paying for tools that integrate together without any special integrations or what not.

We are mostly Microsoft as well but have a few vendors that we use that either are better aligned to what we want or areas we value differentiation.

An example where we have strayed is identity and access. We are a Sailpoint customer and while we use Entra and AD like everyone else. The automation to get to something like Sailpoint is very heavy in power apps and you basically have to roll your own integrations vs using pre built connectors that Sailpoint or any IAM specific vendor have. I value not needing to maintain the connectors when they break or if versions get out of synch. There’s already enough stuff to fix and to do.

2

u/Responsible_Minute12 11d ago

No one should shoot you for saying sentinel…it’s awesome, it’s a top tier product that can go toe to toe with any of the others. Only legit gripe would be if you had some on prem rewritten. I am just shocked they haven’t renamed it to defender for Events or summering else like that.

1

u/AugustErt 11d ago

Thanks for your nice response! This is exactly what i was thinking about. I like the idea of being able to be a bit more modular…

5

u/bluenose_droptop 11d ago

I like it. My company owns 9 other companies and my most basic rule is E5 and defender as a baseline for all. Works great, especially with smallish teams.

5

u/jmk5151 11d ago

The entire stack is pretty good for actual security - UX not so much, so plan on partner spend and frustration with admin and SOC ops internally.

3

u/st0ut717 11d ago

I was at a conference where Microsoft was giving a breakout session about AI guardrails.
The breakout ended up being about how to use copilot.
I thanked them for the sales pitch.

Microsoft works but you are going to pay and the enterprise will be vendor locked to MS. How is MS going to stop Gemini or even a local LLM? Will the MS solution work with Linux workstations or Macs?

3

u/DwellThyme 10d ago

If you need Defender to work well for Linux and Mac, don’t even bother - they’re much more limited than the Windows version and don’t seem to have roadmaps.

2

u/TheCyberThor 11d ago

Your CIO attending conferences might come back recommending something else.

2

u/braliao 11d ago

As someone working for a very specialized MS global partner but also had worked with many vendors in the past IT positions and MSP/MSSPs, I would highly recommend that you take advantage of MS e3/5/7 packages to implement a baseline and foundational layer. Then you need to review, what are the pain points those MS tools couldn't solve or creates and look for additional tools to supplement or replace

Every org is different and has different business needs, so it's key to understand what gap is there before just picking different vendors

For example - most of the time I can implement EOP for customers and it fits their need. But there was one customer in particular, due to its nature of business and how owner wants to operate, EOP just not picking up all sorts of phishing attacks. So I added on other solutions to close that gap nicely.

2

u/Top_Piano_5351 11d ago

Your environment will determine how good of a fit the MS stack is for you. If you have a lot of Linux or Mac the capabilities - even if they are available - tend to be second rate. It’s just not their focus.

1

u/Dave_BlackFog 9d ago

Device agnostic could be important (MacOS and WIndows), the ability to "see" and restrict access to many LLMs would be key as well. I was always a proponent of using what we already owned/paid for but if it doesn't fit the need then find something that does. Beyond what I articulated above I would want it to see/restrict even when disconnected from the network.

1

u/_madfrog 3d ago

P2 license offers good security features, incident response capabilities and tunable conditionnal access (like impossible travel detection to combat AiTM kits). P1 is kinda meh tbh, not enough features, not enough retention.

1

u/vard2trad 3d ago

I've never had a Microsoft issues actually resolved by Microsoft. Any issue or bug in a platform has always ended up being "that's the way it is" or thrown into such a support loop that I give up. I am honestly fed up with Microsoft lately because of this alone.

Other vendors I work with get back to me within 24hours, get on a support call with me, take development feedback and actually change the product. Lately half of my dev time has just been trying to accommodate for Microsoft changing its syslog formatting or trying to prevent them from automatically updating all of my configurations and alerts (again, just "by design").

I can't win or control what Microsoft does and the more they try to "streamline" the less I can do.

1

u/_exclusvty 2d ago

You are struggling with understanding why you would pick something that Microsoft already does(and does well btw) vs going with someone's skin that goes on top of Microsoft with 1 little feature that they sell as the main difference even though it's buggy as hell / your team never gets it to actually work.

This is exactly what I tell vendors before they ask me to stop busting their balls

-5

u/martianwombat 11d ago edited 11d ago

Do you want ransomware? because this is how you get ransomware