Falcon Complete is the most complete version of the buy-a-second-stack answer, and it is the most architecturally consequential provider in this series for a Microsoft estate. Not because it replaces Defender for Endpoint, which is the obvious part, but because CrowdStrike has moved into the identity plane and now sits inline in your Entra authentication flow. That is not a detection service riding your architecture. That is a second policy decision point in front of the one you built.
Start with what the service is. You deploy the Falcon sensor, their platform becomes the security system of record, third-party telemetry arrives through their next-generation SIEM, and their analysts operate the whole thing. It is coherent in a way that assembled stacks are not, because detection, response tooling and analyst workflow were designed together. That coherence is the product.
Full-cycle remediation means what it says
The response model is the most assertive in this series. Their analysts perform what the service description calls surgical remediation: remote access to the affected system through the platform’s own capability, removal of persistence mechanisms, termination of active processes, clearing of artefacts, restoration to a pre-intrusion state. The material is explicit that this happens without requiring action from your team, and independent profiles describe analysts taking direct remediation action within an agreed scope without waiting for approval.
I want to be fair about this rather than alarmist. For an organisation with no security staff and a genuine three in the morning problem, an operator who acts decisively without waiting for someone to wake up is exactly what you are paying for, and hesitation during ransomware deployment costs more than an occasional unnecessary isolation. The design is defensible on its own terms.
The scope is agreed once, at the start. After that the dial has essentially one setting, and it is on.
What you should not do is sign it without understanding that the granularity available elsewhere in this market is largely absent here. There are no per-action opt-ins with never-touch lists, no scoped remediation groups you nominate endpoint by endpoint, no default position where recommendations wait for your team. The negotiation about what they may do happens once, in the scoping conversation, and the artefact that records it is your contract. Treat that conversation as the design decision it is, and get the boundaries written down.
A warranty instead of a service level
CrowdStrike does not publish a response time commitment. Their stated position is outcome-focused rather than service-level based, and the metric they do publish is median time to contain, which measures the full cycle from detection through to containment. As metrics go it is the honest one, and notably it is the only measurement in this series that describes the thing buyers actually care about.
In place of a service level there is a breach prevention warranty, currently marketed up to two million dollars and backed by an insurance policy. The earlier version of this instrument was a million. This is a genuinely different commercial philosophy and it deserves to be understood rather than compared like for like against a response time. A service level promises behaviour and gives you a remedy when behaviour fails. A warranty promises nothing about behaviour and gives you money when the outcome fails. Both are legitimate. Which one you want depends on whether your board is buying assurance or insurance.
The exclusions matter more than the headline figure, and they live in a separate document rather than on the product page. If the warranty is part of your business case, read that document before the business case is approved.
The inline identity plane, and why it is an architecture decision
This is the section that matters most if you have built conditional access properly, and it is the reason this profile could not be written as a feature comparison.
Falcon Identity Protection for Entra ID went generally available in February 2025. It registers as an external authentication method, which means it sits inline in the authentication flow itself, evaluating device posture and risk context from across their platform and returning a decision: grant, block, or challenge with stronger authentication. It is not reading sign-in logs after the fact. It is in the path.
Alongside it sits a passwordless authentication service built on FIDO2, just-in-time privileged access with grants and revocations driven through Teams and their orchestration engine, and a SIEM ingesting raw Entra logs with prebuilt detection content for the attacks that matter on this surface: privileged role assignments made outside Privileged Identity Management, federation trust manipulation, device code phishing.
Taken together that is a second access control plane operating in front of Entra, with its own risk model, its own policy logic and its own failure modes. Every conditional access design assumes a single authoritative decision point. Introducing a second one is not an integration task. It changes where access decisions are made, whose risk signal wins when the two disagree, what happens to sign-ins when the external method is unavailable, and which console an engineer opens at two in the morning when a director cannot log in. Those questions have answers, and the answers can be good ones, but they need to be worked through deliberately by whoever owns your identity architecture rather than discovered during a rollout.
The upside is real and I will not undersell it. This is by a distance the deepest identity capability among the third-party providers in this series: hybrid Active Directory, Entra and other identity providers under one detection and response model, with inline prevention rather than after-the-fact alerting. For an organisation whose threat model is credential-driven, and most are, that depth is the strongest argument in CrowdStrike’s favour. It is simply an argument about architecture rather than about managed services.
The maximum overlap case
An E5 organisation adopting Falcon Complete with its identity and data modules is running two of nearly everything. Their sensor duplicates Defender for Endpoint. Their identity protection overlaps Defender for Identity, Entra ID Protection and parts of your conditional access design. Their SIEM overlaps whatever you were doing with Sentinel. Their data protection overlaps Purview. You are not paying twice for one thing, you are paying twice across most of a security stack.
That can still be the right call. Some organisations decide that a single coherent platform operated by its manufacturer beats an assembled Microsoft stack operated by a third party, and they accept the duplication as the cost of coherence. The decision I object to is the one made without arithmetic. Model both, including the E5 licensing you will continue to pay for and not use, and make the trade explicitly.
Commercially, expect per-endpoint pricing quoted rather than published, with independent aggregators putting enterprise-scale figures in the mid-teens to mid-twenties per endpoint per month, identity protection priced separately on top, and a floor around two hundred endpoints that puts the service out of reach for smaller estates. Treat all of those numbers as directional until you have a quote.
The AI claims, tested
On governing your users’ AI usage, the offering is endpoint data protection extended to cover generative AI tools, blocking sensitive content from leaving the device into managed and unmanaged AI applications through process-level control and inspection at the client. This is worth stating precisely because it is easy to conflate with a different architecture: enforcement happens on the endpoint through the sensor, not inline on the network through a proxy. On a fully managed estate that distinction may not matter to you. For unmanaged devices or traffic that never touches a corporate machine, it matters a great deal.
On AI inside their own operations, the claim is specific enough to pass the test I set for this series. Their triage system reached general availability in February 2025, operates under what they describe as customer-defined bounded autonomy, and human analysts validate before remediation. Accuracy and time-saved figures are their own, so treat them as vendor claims, but the mechanism and the human gate are documented rather than implied. That puts it among the more credible AI stories in this market, which is a low bar cleared properly.
Where this lands
Falcon Complete is the strongest technical proposition in this series and the one that asks the most of your architecture. If you are willing to make CrowdStrike your security platform rather than your managed service provider, you get depth, coherence and operators who act. If you want to keep the Microsoft stack you have invested in and add operators to it, this is the wrong door, and the identity module in particular is a decision your architecture team needs to be in the room for.
MDR
‹ Previous: [MDR 3] Microsoft Defender Experts: The First-Party Answer
Next: [MDR 5] Huntress: Operating the Licenses You Already Own ›




