We primarily use the solution for our employees. It was packaged with our solution provider.
Service Delivery Lead at a comms service provider with 1-10 employees
A standard offering with good threat analysis but reduces machine performance
Pros and Cons
- "The threat analysis center is nice."
- "The policies could be nicer to manage."
What is our primary use case?
What is most valuable?
It's a standard offering. It has all the basic features needed.
The threat analysis center is nice.
What needs improvement?
In general, the solution has gone south. I'm not the biggest fan. Sophos just has too many services, and the CPU memory usage is just too high. It causes a reduction in performance. You have to be running on a machine with at least 16GB of RAM to have it actually function properly. It's very labor intensive as every action is scanned by Sophos. It uses up way too many resources.
The policies could be nicer to manage. The same with users and groups. The central experience is not great right now.
I'd like better API access into Azure and InTune, although I suspect it will not happen as they are competing products.
For how long have I used the solution?
I've been using the solution for a month or so. I'm still rather new to the product.
Buyer's Guide
Intercept X Endpoint
May 2026
Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
893,244 professionals have used our research since 2012.
What do I think about the stability of the solution?
It's very resource hungry and expensive.
What do I think about the scalability of the solution?
It is not very scalable. It's very static. There's no real evidence for ways to expand it, unless you want to buy more stuff or add-ons.
We have just under 300 people using the solution.
We are trying to migrate away. We do not plan to increase usage.
How are customer service and support?
I haven't reached out to support in the context of my current role. I have worked within Sophos support in the past.
Which solution did I use previously and why did I switch?
I'm also using InTune.
I do have colleagues and therefore some visibility into CloudFlare, Symantec, and Trend Micro. We likely will go with Microsoft based on cost and the ability to integrate everything together. We have a small tech team, and we are a charity, so we are looking for effective solutions that do not drain our budget.
How was the initial setup?
It's not too difficult to set up, although I wasn't involved in this particular deployment. You just need to create and set policies. It is what it is. They could be more flexible in terms of policies.
What about the implementation team?
The implementation process was rolled out by the solution provider.
What was our ROI?
Historically, I have not witnessed any ROI.
What's my experience with pricing, setup cost, and licensing?
It is an expensive product. We are moving away from it partly for that reason.
What other advice do I have?
The solution doesn't fit our use case.
I'd advise other users not to use the product.
I'd rate the solution six out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Infrastructure Manager/Deployment Manager at Hivedome Consultancy Services
Protects organizations, performs well, and the deployment is pretty seamless
Pros and Cons
- "The solution protects us."
- "The cloud management console could be a little more user-friendly."
What is our primary use case?
We have a script that deploys the solution on machines when a user joins the local Active Directory domain. We manage it from Sophos Central in the cloud.
What is most valuable?
The solution protects us. The performance and stability are good.
What needs improvement?
The solution can tie up a computer. We're software developers. Sometimes, when we do a build, it has a lot of files. The scanning can slow it down quite a bit. We put exceptions to stop the tool from looking at those folders.
The cloud management console could be a little more user-friendly. There is a graph showing what happens when something is discovered. It's interesting, but I think the information could be presented better and that there could be more information.
For how long have I used the solution?
I have been using the solution for about 18 years.
What do I think about the stability of the solution?
The tool’s stability is fine.
What do I think about the scalability of the solution?
The tool is scalable. We use it to protect 40 endpoints, and we have other customers who have more than 100 endpoints. Our technical team needs two people.
How are customer service and support?
The support is good.
How was the initial setup?
The setup is straightforward. If we're installing it locally on a computer that's just joined to the domain, it would require a script. Setting up the script is quite simple. Setting up, testing, and getting it right takes about half an hour. It works out of the box.
If we have to set up a computer that has not joined our domain, we must log on to the cloud portal and choose to protect the computer. We can download the file that we run on the computer. It's pretty straightforward. We don't need any external help. The deployment is seamless across our organization's endpoints.
What's my experience with pricing, setup cost, and licensing?
The product is moderately priced. We pay a yearly license fee.
What other advice do I have?
We haven’t had any major incidents. The product occasionally picks up and prevents something from happening. We're lucky not to have had any major incidents. Every now and again, the solution pops up and tells us that it stopped something, but we don't keep data on it. We wouldn't know how it's impacted us.
I wouldn't recommend the solution because we are investigating alternatives. We are considering MDR solutions. We might choose Microsoft Defender because it is included with other Microsoft products. In an ideal world, the product has no benefit. It's like insurance. We hope we never have to use it. Overall, I rate the solution an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Intercept X Endpoint
May 2026
Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: May 2026.
893,244 professionals have used our research since 2012.
Head of IT at International Tennis Integrity Agency
Good managment and stability with reasonable pricing
Pros and Cons
- "The client isolation feature is a very effective feature."
- "Technical support is too slow to schedule meetings."
What is our primary use case?
The solution is primarily used for endpoint.
What is most valuable?
The client isolation feature is a very effective feature. There is a lot of information you can find in the console. Management is good. They're always giving you information on the products you have rather than trying to send you new products.
What needs improvement?
For how long have I used the solution?
I have been using Intercept X Endpoint for 3 months.
What do I think about the stability of the solution?
The solution is stable and I rate the stability an 8 out of 10.
How are customer service and support?
I have only spoken to technical support during installation.
When talking to sales support or technical people, I find that they're all very busy. It takes a few days to be able to actually have a meeting arranged. If I contact them that I want to have a meeting with somebody technical from Sophos to go over an implementation or something that I wanted to get out of the product, they may not be available for 6 or 7 days.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup is straightforward.
What's my experience with pricing, setup cost, and licensing?
The pricing is actually quite reasonable.
Which other solutions did I evaluate?
I was looking at the Rapid7 and Darktrace before choosing Intercept.
What other advice do I have?
Overall, I rate the solution an 8 out of 10.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Deputy Manager, Ict at Ushuru
An affordable and intelligent tool that provides good security features and can be managed centrally
Pros and Cons
- "It is an intelligent tool."
- "The tool is not stable on Linux systems."
What is our primary use case?
The product is used for security. It is like an antivirus.
What is most valuable?
The product learns the user’s behavior. It is an intelligent tool.
What needs improvement?
The product must also focus on other operating systems like Linux and macOS. The tool is not stable on Linux systems. It is heavy. It slows down the machine if the machine doesn't have good specifications.
For how long have I used the solution?
I have been using the solution for eight to nine years. I am using the latest version of the solution.
What do I think about the stability of the solution?
The product is stable on Windows machines. I rate the stability a seven out of ten.
What do I think about the scalability of the solution?
We have around 55 users from different departments. I rate the tool’s scalability a seven out of ten.
How are customer service and support?
Support is okay.
How was the initial setup?
The deployment is easy. I rate the ease of deployment a nine out of ten. The process is centralized. We have three engineers to maintain the tool. The frequency of maintenance depends on the alerts we receive about updates or viruses.
What's my experience with pricing, setup cost, and licensing?
The solution is not expensive. The pricing is manageable. We have to pay an annual subscription fee. I rate the pricing a six out of ten.
What other advice do I have?
I will recommend the solution to others. It is centrally managed. We do not have to go to the users’ machines to manage the product. Overall, I rate the product an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Manager at Redeemer Baptist School
A cloud-managed solution that has the ability to provide filtering for end users
Pros and Cons
- "Since it's cloud-managed, the solution is easy to administer, especially if the person using it is in a different geophysical location."
- "The solution is expensive, and it could be made cheaper."
What is most valuable?
Since it's cloud-managed, the solution is easy to administer, especially if the person using it is in a different geophysical location. I can access the cloud portal and allow or disallow it. I like the fact that the solution also has the ability to provide filtering for an end user.
What needs improvement?
The solution is expensive, and it could be made cheaper.
For how long have I used the solution?
I have been using Intercept X Endpoint for three years.
What do I think about the stability of the solution?
I rate Intercept X Endpoint an eight out of ten for stability.
What do I think about the scalability of the solution?
I rate Intercept X Endpoint an eight out of ten for scalability.
How was the initial setup?
The solution’s initial setup is easy.
I rate Intercept X Endpoint ten out of ten for the ease of its initial setup.
What about the implementation team?
The solution's deployment time depends on whether you're setting up a room full of computers or you're setting up one-off computers. It usually doesn't take very long. As part of installing the solution for a room full of computers, you might get someone to create the installed media, and then you'd enter each computer and install it.
Around one to five people are needed to install the solution.
What's my experience with pricing, setup cost, and licensing?
Intercept X Endpoint is an expensive solution.
On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing ten out of ten.
What other advice do I have?
I am working with the latest version of Intercept X Endpoint. Intercept X Endpoint has to be installed on end-user devices, but it is managed in the cloud.
Overall, I rate Intercept X Endpoint an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
System Integrator IT Manager at Tecnimex S.r.l.
Offers centralized controller providing access to every aspect of the deployment and works very well against ransomware
Pros and Cons
- "I appreciate the ability to use the latest endpoint protection features in case of an infection or cyber threat. This is especially true when using the product with a Sophos firewall solution, like the XG series. They collaborate effectively in the event of a cyber threat."
- "The customer service and support could be improved in regards to response time. It could be faster."
What is our primary use case?
We're a Sophos partner and generally use Intercept X software.
How has it helped my organization?
In my experience, it is a good product. Sophos family has many offerings, and the selling model is interesting for us as an MSP or Flex partner.
For end customers, you have a centralized controller providing access to every aspect of the deployment. While the platform isn't the easiest to use, if you properly set up the policies, it's very efficient. Sometimes, the platform itself can prevent security risks due to the product's capabilities.
It works very well against ransomware and similar threats.
What is most valuable?
I appreciate the ability to use the latest endpoint protection features in case of an infection or cyber threat. This is especially true when using the product with a Sophos firewall solution, like the XG series. They collaborate effectively in the event of a cyber threat.
Its ability to continuously query the data lake is beneficial. So, the deep learning technology in Intercept X Endpoint enhances threat detection capability.
However, the automated threat response for incident response times can be better if the user subscribes to Sophos service called EDR... I think it's called Managed Threat Response (MTR). There is a higher layer of support available. For big customers, this could a good option.
What needs improvement?
The price could always be better.
For how long have I used the solution?
I have experience with this solution. I have been using it for a lot of years.
What do I think about the stability of the solution?
It is a stable product.
What do I think about the scalability of the solution?
It is a scalable product. It covers laptops and essentially any Windows platform – servers, clients, and even home users. So, it protects a huge number of potential platforms.
There are around 300 endpoints.
How are customer service and support?
The customer service and support could be improved in regards to response time. It could be faster.
How was the initial setup?
The complexity of the setup depends on the environment.
For single deployments, it's quite easy to set up. You can organize customers using separate payments and policies for each through the centralized console. Integrating the product with other Sophos offerings makes it very efficient.
Customers mostly use the cloud solution. On-premises is probably less common among Sophos users.
It's difficult to have major issues with deployment. Problems usually arise due to the age of the platform. If you have older systems, support can be more expensive. Sophos might support older platforms for a while, but you'll likely have to pay additional subscriptions.
What was our ROI?
We have seen an ROI. We consider it a strategic product for our organization.
What's my experience with pricing, setup cost, and licensing?
We operate as an MSP, so we pay yearly. However, if the end customer is part of the Sophos Flex program, they have more flexibility and can adopt a monthly payment process.
What other advice do I have?
I suggest investing in training. It's a good product, but unlocking its full potential requires some training time.
Overall, I would rate the solution a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Manager at indian acrylics limited
Offers functions that are effective in offering protection against ransomware attacks
Pros and Cons
- "It is a very scalable solution."
- "I am not very satisfied with the product's reporting overall, and it needs improvement in this area."
What is our primary use case?
I use the solution in my company for endpoint protection or virus protection, as well as as an EDR tool.
The product is mostly used in the manufacturing industry.
What needs improvement?
I am not very satisfied with the product's reporting overall, and it needs improvement in this area.
For how long have I used the solution?
I have been using Intercept X Endpoint for six years. I am a user of the tool.
What do I think about the stability of the solution?
It is a very stable solution. Stability-wise, I rate the solution a nine out of ten.
I haven't faced any issues with the product in the last five to six years.
What do I think about the scalability of the solution?
It is a very scalable solution. Scalability-wise, I rate the solution a nine out of ten.
There are around 1,000 users of the product in my office since they need to use an antivirus solution.
There is no need to increase the usage of the product in the future in our company.
How are customer service and support?
I am happy with the technical support for the solution since they promptly responded to our company's calls. I rate the technical support a nine out of ten.
How would you rate customer service and support?
Positive
How was the initial setup?
I rate the product's initial setup phase a nine out of ten, where ten means it was a very easy process.
The solution is deployed on a public cloud.
For endpoint installation, it takes some time, but for agent installation, it takes a day to deploy the product. As a server-based tool, the installation takes a day to complete.
During the deployment part, there are some restrictions as well as the need to sign up with the console in Sophos Central. There are multiple options provided by the product and our company has to follow the on-screen instructions provided by the solution. I am not in a position to convey all the details regarding the deployment process.
What's my experience with pricing, setup cost, and licensing?
The price of the product is okay, in my opinion. The tool's cost per user and per annum basis is around INR 700 to 800.
Which other solutions did I evaluate?
My company has evaluated other options in the market against Intercept X Endpoint, but my company already has a subscription to the tool until 2026.
What other advice do I have?
Intercept X Endpoint has an in-built technology in it that works to protect our company from ransomware attacks.
With signature and behavioral-based scanning options, the product is effective in protecting against ransomware attacks.
There are multiple options for threat detection, like application filters, peripherals, device control, and web control. There are multiple options to protect systems from threats.
The exploit prevention capabilities in Intercept X Endpoint have benefited our company's security posture since it will prevent attacks in our company's environment.
I would rate the product's ability to reduce threats a nine out of ten.
The reporting part of the product is good enough for endpoints, but it is not as good as CrowdStrike or SentinelOne in the market.
The tool does impact our company's system profile in the areas of performance and productivity.
Anyone can use the tool. The console is user-friendly, and the endpoint protection is okay.
I rate the tool a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Manager at One All Solutions
Helps with internal alerts, application access, and triggering support teams
Pros and Cons
- "Intercept X helps with internal alerts, application access, and triggering support teams."
- "The integration has room for improvement, especially with Mac OS."
What is our primary use case?
I'm a partner with Sophos for Intercept X Endpoint. Our use cases are for main security needs, client needs, and handling urgent concerns.
What is most valuable?
Intercept X helps with internal alerts, application access, and triggering support teams. I've used temporary protection for quick responses, and it is user-friendly and manageable.
What needs improvement?
Last year, my company faced an attack due to disabled compression in our antivirus software. Intercept X Endpoint didn’t work, so we had to uninstall it and restore. Also,Integration has room for improvement, especially with Mac OS.
For how long have I used the solution?
I have been using Intercept X Endpoint for the past 17 years.
What do I think about the stability of the solution?
There are occasional glitches, like online applications not reaching the cloud server properly.
What do I think about the scalability of the solution?
Scaling depends on XDR or MDR versions, with a reset needed for upgrades.
How are customer service and support?
Support in India is limited to email and can be better through MSP partners.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I've used Kaspersky but prefer Sophos for its features.
How was the initial setup?
Deployment is easy and fast, requiring two to three people for configuration.
What about the implementation team?
Maintenance is easy, and scalability depends on whether using XDR or MDR, with a reset needed between upgrades.
What's my experience with pricing, setup cost, and licensing?
It is not very expensive but I don't have specific pricing details. The licensing is usually done on yearly basis.
What other advice do I have?
I'd rate it an eight. It's a solid solution for centralized security needs and threat monitoring.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: May 2026
Product Categories
Endpoint Protection Platform (EPP) Endpoint Detection and Response (EDR) ZTNA Managed Detection and Response (MDR) Extended Detection and Response (XDR) Ransomware ProtectionPopular Comparisons
Fortinet FortiGate
CrowdStrike Falcon
Microsoft Defender for Endpoint
Cortex XDR by Palo Alto Networks
SentinelOne Singularity Endpoint
Cloudflare One
IBM Security QRadar
Elastic Security
Huntress Managed EDR
HP Wolf Security
Trellix Endpoint Security Platform
WatchGuard Firebox
Microsoft Defender XDR
Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Sophos Intercept X or Symantec End-User Endpoint Security - which is the better solution?
- Can Sophos Intercept X and Carbon Black be used side by side on endpoints?
- Which endpoint solution is more effective in terms of protection and remote administration: Sophos Intercept X or Kaspersky Endpoint Security?
- How does Crodwstrike Falcon compare with Sophos Intercept X?
- Sophos Intercept X: renewal cost for a security system integrator
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?


















