After adding layers of firewall protection, our network runs smoothly, effectively combating viruses and malware. Whenever issues arise, we can promptly diagnose them using the error logs provided. Additionally, Sophos Intercept offers Sophos Central, allowing us to access our firewall from anywhere. This accessibility enables us to provide support to our team remotely. The firewall's GUI is user-friendly and intuitive, making issue identification and resolution straightforward. Using Sophos Intercept, we can pinpoint and address network issues, such as blocked websites.
Senior Network Engineer at a manufacturing company with 51-200 employees
A solution for firewall protection with diagnosis and remote access
Pros and Cons
- "One of the best features of Sophos Intercept is that it repairs without slowing down the system."
- "If Sophos Intercept allows users to restrict website access based on specific needs, such as streaming new videos for business purposes, we would prefer to use that."
What is our primary use case?
How has it helped my organization?
If a client system is attempting to download anything or if any other system file is trying to access it, an alert is triggered by Intercept and the firewall. Automatically, it is connected to Sophos Central daily. I can trace the issue from Sophos Central, and the Endpoint will provide all the necessary information. Endpoint security ensures that client systems, including servers, are protected. One of the best features of Sophos Intercept is that it repairs without slowing down the system.
What is most valuable?
The main feature of Sophos Intercept is the ability to block certain websites that we don't want users to access. A user can only uninstall Sophos Intercept if they contact the administrator. This is a very useful security measure. Sophos Intercept Endpoint is strong in resolving issues.
What needs improvement?
We received an alert from a client where we have installed Sophos Endpoint Security. There is a vulnerability in some applications, compromising their integrity. They have used a crack version, which is not genuine. These cracks contain malware and tokens. Someone attempted to copy a file into the system. Fortunately, with the help of Sophos Intercept, we received an alert promptly. We immediately halted our work on the infrastructure. Sophos Endpoint Security can scan files instantly and provide alerts.
If Sophos Intercept allows users to restrict website access based on specific needs, such as streaming new videos for business purposes, we would prefer to use that. They have categorized details in the web policy in the Endpoint security setup. For example, I had to use the MCU tool under the 'Entertainment' option. I had to choose whether to allow it. If I block this category, all video-related applications, including Skype, will cease functioning. Therefore, they need to provide separate options. For instance, if they include 'Streaming' as an option under web policies for entertainment, users can differentiate and choose to block streaming websites individually, such as Daily Motion. This would give users more control over their access.
Buyer's Guide
Intercept X Endpoint
January 2026
Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,733 professionals have used our research since 2012.
For how long have I used the solution?
I have been using Intercept X Endpoint for five years.
What do I think about the stability of the solution?
The product is stable.
What do I think about the scalability of the solution?
The solution is scalable. 50 users are using this solution.
Sophos also launched DNS protection. We can use DNS protection if a client has no more than ten users. With DNS protection, we can monitor and block sites that are not business-related, allowing us to monitor and control the traffic of every user in the branch. DNS protection offers the option to log and control the traffic of your branch effectively.
How are customer service and support?
Customer support will contact you after two days after you open a ticket.
How would you rate customer service and support?
Negative
Which solution did I use previously and why did I switch?
No Built-in Email Security: Intercept X does not include email protection (phishing, spam, or attachment scanning). A separate solution like Sophos Email or third-party service is needed. More expensive than basic antivirus solutions.
My advice: They must include email security features.
How was the initial setup?
The initial setup is straightforward. They have divided it into three categories: MacOS, Windows, and server. So, if you are installing it on Windows 10, you must download the Windows installer and select the Windows installer option. In Sophos Central, they have separated the installation files. The server-required files are separate, the client system files for Windows are separate, and there are separate files for MacOS.
What other advice do I have?
Sophos can block the ransomware. It is very easy to understand. A new user using that firewall can easily understand and handle it.
Overall, I rate the solution a ten out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 15, 2025
Flag as inappropriateProject Engineer at a computer software company with 1,001-5,000 employees
Helpful to detect and identify worms and malware
Pros and Cons
- "It is a stable solution. Stability-wise, I rate the solution a ten out of ten."
- "The performance offered by the product needs improvement."
What is our primary use case?
My company uses Active Directory to manage users and track whether they have installed any third-party applications or any malicious applications that need to be blocked before allowing for the installation of the application. My company informs users whether the tools they use have any malicious activities or products.
What is most valuable?
In terms of protection, Intercept X Endpoint is very good as it detects and identifies issues at a very early stage, so it is up to date. In terms of usability, it consumes a lot of RAM space, which causes work machines in our company's environment to be very slow. In my company, we have to wait and allow for the tool to complete the scanning of all the files and other aspects, or else the machines get slow.
What needs improvement?
The machines get too heavy because of the background applications that run when the tool is used. The performance offered by the product needs improvement.
For how long have I used the solution?
I have been using Intercept X Endpoint for more than two years.
What do I think about the stability of the solution?
It is a stable solution. Stability-wise, I rate the solution a ten out of ten.
What do I think about the scalability of the solution?
In terms of scalability, you have to pay for every user that uses the product. If you pay more, you can get more users to use the product.
Around 500 people in my company use the product.
The product is extensively used in my company, and we plan to increase the number of uses of the solution. As the number of users of the solution in our company increases, we have to implement the product in every employee machine in our organization. My company uses the product on Windows and Linux.
Which solution did I use previously and why did I switch?
I have no idea about the other products in the market since I directly started to use Intercept X Endpoint.
How was the initial setup?
The solution is deployed on an on-premises model.
What about the implementation team?
A representative or set of executives from Sophos' team is involved in the product's installation process and guides the use cases of the application.
What was our ROI?
The return on investment from the use of the solution is very good since it helps my company to keep our network secure and protected.
What's my experience with pricing, setup cost, and licensing?
On a per-user basis, my company has to pay a certain amount of money.
What other advice do I have?
The solution improves our company's endpoint protection strategy as it helps to protect our network from getting affected by any worm or malware.
It is a very good tool to use for stopping threats. The tool is also useful to manage the activities of users in our company.
The tool is very good to use and is always up to date. The product can identify malware and worms at an early stage. Additionally, the tool also helps identify crypto miners.
Our company's system performance was getting slow because of the product.
I rate the overall tool an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Intercept X Endpoint
January 2026
Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,733 professionals have used our research since 2012.
Head of IT at a sports company with 11-50 employees
Good managment and stability with reasonable pricing
Pros and Cons
- "The client isolation feature is a very effective feature."
- "Technical support is too slow to schedule meetings."
What is our primary use case?
The solution is primarily used for endpoint.
What is most valuable?
The client isolation feature is a very effective feature. There is a lot of information you can find in the console. Management is good. They're always giving you information on the products you have rather than trying to send you new products.
What needs improvement?
For how long have I used the solution?
I have been using Intercept X Endpoint for 3 months.
What do I think about the stability of the solution?
The solution is stable and I rate the stability an 8 out of 10.
How are customer service and support?
I have only spoken to technical support during installation.
When talking to sales support or technical people, I find that they're all very busy. It takes a few days to be able to actually have a meeting arranged. If I contact them that I want to have a meeting with somebody technical from Sophos to go over an implementation or something that I wanted to get out of the product, they may not be available for 6 or 7 days.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup is straightforward.
What's my experience with pricing, setup cost, and licensing?
The pricing is actually quite reasonable.
Which other solutions did I evaluate?
I was looking at the Rapid7 and Darktrace before choosing Intercept.
What other advice do I have?
Overall, I rate the solution an 8 out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Service Delivery Lead at a comms service provider with 1-10 employees
A standard offering with good threat analysis but reduces machine performance
Pros and Cons
- "The threat analysis center is nice."
- "The policies could be nicer to manage."
What is our primary use case?
We primarily use the solution for our employees. It was packaged with our solution provider.
What is most valuable?
It's a standard offering. It has all the basic features needed.
The threat analysis center is nice.
What needs improvement?
In general, the solution has gone south. I'm not the biggest fan. Sophos just has too many services, and the CPU memory usage is just too high. It causes a reduction in performance. You have to be running on a machine with at least 16GB of RAM to have it actually function properly. It's very labor intensive as every action is scanned by Sophos. It uses up way too many resources.
The policies could be nicer to manage. The same with users and groups. The central experience is not great right now.
I'd like better API access into Azure and InTune, although I suspect it will not happen as they are competing products.
For how long have I used the solution?
I've been using the solution for a month or so. I'm still rather new to the product.
What do I think about the stability of the solution?
It's very resource hungry and expensive.
What do I think about the scalability of the solution?
It is not very scalable. It's very static. There's no real evidence for ways to expand it, unless you want to buy more stuff or add-ons.
We have just under 300 people using the solution.
We are trying to migrate away. We do not plan to increase usage.
How are customer service and support?
I haven't reached out to support in the context of my current role. I have worked within Sophos support in the past.
Which solution did I use previously and why did I switch?
I'm also using InTune.
I do have colleagues and therefore some visibility into CloudFlare, Symantec, and Trend Micro. We likely will go with Microsoft based on cost and the ability to integrate everything together. We have a small tech team, and we are a charity, so we are looking for effective solutions that do not drain our budget.
How was the initial setup?
It's not too difficult to set up, although I wasn't involved in this particular deployment. You just need to create and set policies. It is what it is. They could be more flexible in terms of policies.
What about the implementation team?
The implementation process was rolled out by the solution provider.
What was our ROI?
Historically, I have not witnessed any ROI.
What's my experience with pricing, setup cost, and licensing?
It is an expensive product. We are moving away from it partly for that reason.
What other advice do I have?
The solution doesn't fit our use case.
I'd advise other users not to use the product.
I'd rate the solution six out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Network and Infrastructure Manager at a manufacturing company with 201-500 employees
Centralized management and reporting enhance experience with good reliability
Pros and Cons
- "Intercept X Endpoint has been stable, and I appreciate the centralized management and the reporting feature."
- "Technical support from Sophos is rated as nine out of ten, which represents high quality."
- "I would inquire why it is not sold directly to end users."
What is our primary use case?
We use Intercept X Endpoint because it has proved stable. We also have a Sophos firewall and Sophos server.
What is most valuable?
Intercept X Endpoint has been stable, and I appreciate the centralized management and the reporting feature. The Heartbeat is another valuable feature of Intercept X Endpoint.
What needs improvement?
I would inquire why it is not sold directly to end users.
For how long have I used the solution?
I have been using Intercept X Endpoint since 2018.
What do I think about the stability of the solution?
I rate the stability of Intercept X Endpoint as eight out of ten.
What do I think about the scalability of the solution?
I rate the scalability as eight out of ten.
How are customer service and support?
Technical support from Sophos is rated as nine out of ten, which represents high quality.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Before Intercept X Endpoint, we used McAfee and Kaspersky. We switched to Sophos because it provided a unified solution.
How was the initial setup?
The first setup is not very straightforward and requires a lot of expertise.
What was our ROI?
The solution is cost-effective.
What's my experience with pricing, setup cost, and licensing?
The pricing of Intercept X Endpoint is a bit high.
What other advice do I have?
Based on my experience, I would recommend Intercept X Endpoint to other people.
I'd rate the solution eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Infrastructure Manager/Deployment Manager at a tech services company with 11-50 employees
Protects organizations, performs well, and the deployment is pretty seamless
Pros and Cons
- "The solution protects us."
- "The cloud management console could be a little more user-friendly."
What is our primary use case?
We have a script that deploys the solution on machines when a user joins the local Active Directory domain. We manage it from Sophos Central in the cloud.
What is most valuable?
The solution protects us. The performance and stability are good.
What needs improvement?
The solution can tie up a computer. We're software developers. Sometimes, when we do a build, it has a lot of files. The scanning can slow it down quite a bit. We put exceptions to stop the tool from looking at those folders.
The cloud management console could be a little more user-friendly. There is a graph showing what happens when something is discovered. It's interesting, but I think the information could be presented better and that there could be more information.
For how long have I used the solution?
I have been using the solution for about 18 years.
What do I think about the stability of the solution?
The tool’s stability is fine.
What do I think about the scalability of the solution?
The tool is scalable. We use it to protect 40 endpoints, and we have other customers who have more than 100 endpoints. Our technical team needs two people.
How are customer service and support?
The support is good.
How was the initial setup?
The setup is straightforward. If we're installing it locally on a computer that's just joined to the domain, it would require a script. Setting up the script is quite simple. Setting up, testing, and getting it right takes about half an hour. It works out of the box.
If we have to set up a computer that has not joined our domain, we must log on to the cloud portal and choose to protect the computer. We can download the file that we run on the computer. It's pretty straightforward. We don't need any external help. The deployment is seamless across our organization's endpoints.
What's my experience with pricing, setup cost, and licensing?
The product is moderately priced. We pay a yearly license fee.
What other advice do I have?
We haven’t had any major incidents. The product occasionally picks up and prevents something from happening. We're lucky not to have had any major incidents. Every now and again, the solution pops up and tells us that it stopped something, but we don't keep data on it. We wouldn't know how it's impacted us.
I wouldn't recommend the solution because we are investigating alternatives. We are considering MDR solutions. We might choose Microsoft Defender because it is included with other Microsoft products. In an ideal world, the product has no benefit. It's like insurance. We hope we never have to use it. Overall, I rate the solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Manager at a recruiting/HR firm with 11-50 employees
Helps with internal alerts, application access, and triggering support teams
Pros and Cons
- "Intercept X helps with internal alerts, application access, and triggering support teams."
- "The integration has room for improvement, especially with Mac OS."
What is our primary use case?
I'm a partner with Sophos for Intercept X Endpoint. Our use cases are for main security needs, client needs, and handling urgent concerns.
What is most valuable?
Intercept X helps with internal alerts, application access, and triggering support teams. I've used temporary protection for quick responses, and it is user-friendly and manageable.
What needs improvement?
Last year, my company faced an attack due to disabled compression in our antivirus software. Intercept X Endpoint didn’t work, so we had to uninstall it and restore. Also,Integration has room for improvement, especially with Mac OS.
For how long have I used the solution?
I have been using Intercept X Endpoint for the past 17 years.
What do I think about the stability of the solution?
There are occasional glitches, like online applications not reaching the cloud server properly.
What do I think about the scalability of the solution?
Scaling depends on XDR or MDR versions, with a reset needed for upgrades.
How are customer service and support?
Support in India is limited to email and can be better through MSP partners.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I've used Kaspersky but prefer Sophos for its features.
How was the initial setup?
Deployment is easy and fast, requiring two to three people for configuration.
What about the implementation team?
Maintenance is easy, and scalability depends on whether using XDR or MDR, with a reset needed between upgrades.
What's my experience with pricing, setup cost, and licensing?
It is not very expensive but I don't have specific pricing details. The licensing is usually done on yearly basis.
What other advice do I have?
I'd rate it an eight. It's a solid solution for centralized security needs and threat monitoring.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
IT Support Engineer at a non-tech company with 11-50 employees
Incorporates advanced features like deep learning analysis, anti-ransomware, and fileless attack protection
Pros and Cons
- "Everything in Intercept X Endpoints is much centralised which makes it easy for our team to work with. The functions are in a single portal."
- "In my opinion, there have been significant developments in the product. In my opinion, I don’t have any suggestions as of now, however I can suggest a cost deduction which will be beneficial for all the parties. It will also relieve our budget and benefit our team."
What is our primary use case?
We use Intercept X Endpoint across various devices such as PCs, laptops, servers, and mobiles in our engineering enterprise.
What is most valuable?
Everything in Intercept X Endpoints is much centralised which makes it easy for our team to work with. The functions are in a single portal.
What needs improvement?
In my opinion, there have been significant developments in the product. In my opinion, I don’t have any suggestions as of now, however, I can suggest a cost deduction which will be beneficial for all the parties. It will also relieve our budget and benefit our team.
For how long have I used the solution?
I've been using Intercept X Endpoint for six years now.
What do I think about the stability of the solution?
It is stable and I will rate it 10 out of 10, since we have no issues any far.
What do I think about the scalability of the solution?
I would rate the scalability 10 out of 10, and you can easily add licenses whenever you want. The scalability is immediate and currently, we employ almost 130 users. Based on the usage, we also have plans to increase the usage in the future.
How are customer service and support?
There haven’t been many calls that were regarding concerns with Sophos. We are satisfied with the service. Also, we have a monthly review coming up and looking forward to it.
I haven’t personally interacted with Sophos and haven’t raised a support call. However, in a particular instance, Sophos reached out to us regarding an issue. While we were dealing with the issue, I found the response time to be slow.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We have only engaged with one solution for endpoints and that is Intercept X Endpoint.
How was the initial setup?
The installation process is quite straightforward and easy. The process takes almost few minutes and requires not more than one person. In case the deployment is for everyone, one person might not suffice the task.
What about the implementation team?
It requires only one person to deploy and it was done in-house in our case.
What's my experience with pricing, setup cost, and licensing?
I would rate the price 7 out of 10, where 1 is most expensive and 10 is cheapest. Also, a little reduction in price can be a great move for Intercept X Endpoint.
What other advice do I have?
Intercept X Endpoint is a great solution for larger teams and has a great support system. I would totally recommend it and rate it 10 out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Endpoint Protection Platform (EPP) Endpoint Detection and Response (EDR) ZTNA Managed Detection and Response (MDR) Extended Detection and Response (XDR) Ransomware ProtectionPopular Comparisons
Fortinet FortiGate
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Complete
Fortinet FortiEDR
IBM Security QRadar
HP Wolf Security
Cortex XDR by Palo Alto Networks
Huntress Managed EDR
Elastic Security
Microsoft Defender XDR
WatchGuard Firebox
Trellix Endpoint Security Platform
Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Sophos Intercept X or Symantec End-User Endpoint Security - which is the better solution?
- Can Sophos Intercept X and Carbon Black be used side by side on endpoints?
- Which endpoint solution is more effective in terms of protection and remote administration: Sophos Intercept X or Kaspersky Endpoint Security?
- How does Crodwstrike Falcon compare with Sophos Intercept X?
- Sophos Intercept X: renewal cost for a security system integrator
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?

















