We are using SentinelOne for an endpoint view of the corporate network.
Director Information Technology at a wellness & fitness company with 201-500 employees
Effective detection capabilities, scalable, and reliable
Pros and Cons
- "The most valuable features of SentinelOne are the endpoint detection of threats, and it does not only rely on signatures for detection."
- "SentinelOne could improve by creating an autopilot or automated way to roll out the solution more efficiently which would be helpful."
What is our primary use case?
What is most valuable?
The most valuable features of SentinelOne are the endpoint detection of threats, and it does not only rely on signatures for detection.
What needs improvement?
SentinelOne could improve by creating an autopilot or automated way to roll out the solution more efficiently which would be helpful.
For how long have I used the solution?
I have been using SentinelOne for approximately one year.
Buyer's Guide
SentinelOne Singularity Complete
February 2026
Learn what your peers think about SentinelOne Singularity Complete. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
884,933 professionals have used our research since 2012.
What do I think about the stability of the solution?
SentinelOne is stable.
I rate the stability of SentinelOne a five out of five.
What do I think about the scalability of the solution?
The scalability of SentinelOne is not a problem. These solutions can easily host up to 10,000 endpoints if not more, and we have 500. We do not have an immediate need to scale, but it is not an issue. As the company grows, the company will increase the usage of the solution.
How are customer service and support?
I am satisfied with the support from SentinelOne.
How was the initial setup?
SentinelOne is not too difficult to set up. The full deployment took a couple of months. The lengthy installation was caused by the fact that many people are remote working and we had 500 systems to install the solution on.
What about the implementation team?
We did our own deployment of SentinelOne. We used three to five people for the deployment.
What other advice do I have?
I rate SentinelOne an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Owner at FirewallHire.com
Quick and easy to deploy with good performance
Pros and Cons
- "It's quite scalable."
- "The solution works well in general."
- "It is an expensive product."
- "Every site has its own key. I'm not sure how I can implement the key for the setup package, therefore with every installation I need to do it manually and put on the site keys."
What is our primary use case?
We primarily use the solution for endpoint detection.
What is most valuable?
The solution works well in general.
It's a small size and offers an easy deployment. It's very quick to deploy.
The solution is stable.
It's quite scalable.
What needs improvement?
Every site has its own key. I'm not sure how I can implement the key for the setup package. Therefore, with every installation, I need to do it manually and put on the site keys.
It is an expensive product. They could work on lowering the price a bit.
For how long have I used the solution?
I've used the solution for one year.
What do I think about the stability of the solution?
It is stable and reliable. There are no bugs or glitches. It doesn't crash or freeze.
What do I think about the scalability of the solution?
The solution is quite scalable.
How was the initial setup?
The initial setup and deployment are easy. I can get it up and running in five minutes.
What's my experience with pricing, setup cost, and licensing?
The cost is a bit high. It's around $8 per client per month.
What other advice do I have?
We are partners. We are using the latest version of the product.
I'd recommend the solution to others. We really like it in general.
I'd rate the solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Buyer's Guide
SentinelOne Singularity Complete
February 2026
Learn what your peers think about SentinelOne Singularity Complete. Get advice and tips from experienced pros sharing their opinions. Updated: February 2026.
884,933 professionals have used our research since 2012.
Technical Director at Etelligence
Scalable solution with a straightforward setup that provides an enhanced level of endpoint security, but has issues with stability
Pros and Cons
- "Scalable endpoint protection solution that takes seconds to set up per device. It has a rollback feature and offers good technical support."
- "The stability of SentinelOne should be improved."
What is our primary use case?
SentinelOne is for users wanting an enhanced level of endpoint security.
What is most valuable?
What I like about SentinelOne is that it sparks your curiosity. I also like its rollback feature.
What needs improvement?
The stability of SentinelOne should be improved.
For how long have I used the solution?
I've been using SentinelOne for three years.
What do I think about the stability of the solution?
We're using SentinelOne through one of our partners, and we have had some stability issues with it due to Windows 10 features updates. It should be more stable.
What do I think about the scalability of the solution?
SentinelOne is a scalable solution.
How are customer service and support?
Technical support for SentinelOne is fine.
How was the initial setup?
The initial setup for SentinelOne is straightforward. Setting up the solution doesn't take long, e.g. on a per-device basis, it would take just 30 seconds.
What about the implementation team?
We did the implementation of this solution ourselves.
What's my experience with pricing, setup cost, and licensing?
Our customers pay for monthly for the license of SentinelOne.
What other advice do I have?
We're an MSP, so we deploy SentinelOne for customers, e.g. 70 to 80 endpoints.
We've had some stability issues with the solution, and that's definitely a concern. I'm still pushing forward with SentinelOne, because it's the only kind of option we have in this space.
In terms of recommending SentinelOne, I'd give it a six out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
IT Manager at Telecorp Inc.
Protects our network end users from malware and eliminates ransom ware with timely alerts and automatic resolution
Pros and Cons
- "Prevents ransomware getting through."
- "We went from 30% ransom ware infections to zero."
- "Communication and documentation could be improved."
- "I think communication and documentation could be improved in the solution."
What is our primary use case?
My primary use case for this solution to protect my clients and sites that I support from malware and ransom ware. It is installed on the end point clients and servers as a client and then it clean and protects after a reboot. As a managed service provider we found it instrumental at preventing viruses and especially preventing ransom ware. We went from 30% ransom ware infections to zero. The software stops the infection before it executes.
How has it helped my organization?
It has saved hundreds of hours fixing destroy and encrypted computers. In the old days even if you restored the files Windows was still damaged. This stops the software from executing.
What is most valuable?
The valuable feature of this solution is the ability for it to stop a virus or ransom ware. It uses a SOC for active monitoring and AI software that watches where you go and what gets executed. If it sees danger I get alerted and the machine is frozen. If the SOC believes it to be a virus the machines network card is frozen or the machine is automatically returned to the state before the file was executed and the file is erased. If it's safe the machine is auto unfrozen. I can go in look at the logs, verify if it's a false positive and unfreeze the machine. If I believe it is a virus I can return the machine to before the file got executed. Erasing any damage. If I believe it's a false positive I can mark it benign and re execute the file. So far it's stopped four ransomware cases from getting through, so it's doing a good job.
What needs improvement?
I think communication and documentation could be improved in the solution. When you get a virus alert, there's not a lot of upfront training to let you know how to resolve a situation when it occurs. The first couple of times you're flailing a little bit until you get it sorted. I would probably also suggest that the interface could use a little bit of help. It's a little hunt and peck.
For additional features, I'd like to see the ability to control it on a cell phone. It would be great if I could have it in the palm of my hand so that if I get a false positive, I can just look at the dashboard on my phone.
For how long have I used the solution?
I've been using this solution for seven months.
What do I think about the stability of the solution?
The solution seems super stable, although you do get some false positives, especially when it encounters a new piece of software. But the SOC is able to quickly whitelist and adopt to the new software fairly quickly.
What do I think about the scalability of the solution?
The solution is scalable. I'm able to put it both in a script and I can see it being able to be deployed in a large environment as well as a small one. I have 285 end points and the roles are anywhere from financial traders to insurance agents. All employees have access to the solution, it's actually turned into my main route for antivirus end protection and the product doesn't require any maintenance except for when it finds a virus.
How are customer service and technical support?
I've used technical support a few times and it's very good. They're very responsive and they alert you very quickly when there's an issue. They lean heavier on protection, which can sometimes be a problem. A lot of times, by the time I'm logged in to look at it, they've already figured out that it's a false positive and they mark it and whitelist it and put the machine back online. All that can take less than a couple of seconds.
Which solution did I use previously and why did I switch?
I've previously used several antivirus programs and then I got to the point where I wanted to use an artificial intelligence program. Originally I used CrowdStrike, which I also liked, but the main reason I switched to SentinelOne is because it's incorporated as part of my MSP solution suite.
How was the initial setup?
The initial setup is very straightforward. When you implement, it goes through and does the initial scan and it makes the configuration changes that it needs. I haven't had a problem with any deployment at all and it's a very quick process.
What about the implementation team?
It's deployed in house
What's my experience with pricing, setup cost, and licensing?
The cost of the solution varies and depends on your relationship with the supplier. My cost is USD $6 per end point. I don't have additional costs on top of that.
Which other solutions did I evaluate?
I evaluated, Norton 360, Windows antivirus, Webroot, Crowdstrike, and ESET
What other advice do I have?
With solutions like these it's important to keep in mind that any automated system can give false positives, especially when they first encounter your software. Be patient, work with the SOC and the technical support team. If your work is implementation, then do whole sites at one time. It's best to do it in sections, let it sit for a couple of weeks and then do the rest.
I would rate this solution a ten out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
VP at a tech services company with 11-50 employees
Easy to set up and transparently offers effective protection
Pros and Cons
- "The most valuable feature is that it just unintrusively works in the background to carry out the protection."
- "The most valuable feature is that it just unintrusively works in the background to carry out the protection."
- "Periodically we have an application that does not work correctly when SentinelOne is installed, yet performs as expected when SentinelOne is removed."
- "Periodically we have an application that does not work correctly when SentinelOne is installed, yet performs as expected when SentinelOne is removed."
What is our primary use case?
We have SentinelOne installed on all of our workstations and servers. It is set up with the maximum protection except that Active is in Alert Mode, and everything else is blocked.
What is most valuable?
The most valuable feature is that it just unintrusively works in the background to carry out the protection. You don't have to babysit it. Instead, it will alert if it sees something, you deal with it and carry on from there.
What needs improvement?
Periodically we have an application that does not work correctly when SentinelOne is installed, yet performs as expected when SentinelOne is removed. SentinelOne gives no clue as to the problem, so to diagnose what is happening can be difficult. To make it worse, the behavior is inconsistent. Two people in the office might have the application working correctly, but a third person using the same program will have a problem.
Nothing is displayed by the agent that is running on the workstations, but it would be helpful to have a mode available where we can see feedback as to what it is doing. We wouldn't want it running all the time because there would be more overhead, but it could be helpful for debugging or diagnosing problems.
For how long have I used the solution?
I have been using SentinelOne for between six months and a year.
What do I think about the stability of the solution?
In terms of stability, it has been good so far.
What do I think about the scalability of the solution?
It appears to be scalable.
How was the initial setup?
The initial setup is very easy.
What's my experience with pricing, setup cost, and licensing?
Our licensing fees are about $5 USD per endpoint, per month.
What other advice do I have?
Overall, this is a good product and I recommend it. That said, there are always ways to make things better.
I would rate this solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Engineer II, Enterprise Client Support at a media company with 10,001+ employees
Visually appealing and customizable console, as well as a powerful API
Pros and Cons
- "We love the API. We use it to generate robust reporting, and we also developed tools to perform agent actions remotely without needing to provide all IT staff with console access."
- "SentinelOne has provided amazing security; we were getting new cryptolocker variant infections several times per month and the month following our SentinelOne rollout, the numbers dropped to zero, and we have not had a single infection since."
- "It would be nice if the console stored data daily, so that you could look at a timeline of events on a machine over a period of time, and currently this is not possible."
- "The agent update schedule is a little sporadic, and the updates are frequent."
What is our primary use case?
We use SentinelOne to secure our entire environment, including all user endpoints and servers. We are also currently testing the Deep Visibility addon. We were using a definition-based AV prior to SentinelOne, and we were getting daily/weekly infections of a variety of malware. We are a mix of PC, Mac, and Linux. We have on-premises machines and servers, as well as cloud VMs that we were wanting to protect. We wanted to purchase a Next Generation AV client that would be algorithm-based instead of definition file-based.
How has it helped my organization?
SentinelOne has provided amazing security. We were getting new cryptolocker variant infections several times per month and the month following our SentinelOne rollout, the numbers dropped to zero. We have not had a single infection since.
The new console is not only visually appealing and simple to use, but it allows you to customize and apply labels to different areas. I don't have a good gauge on how much money SentinelOne has saved us, but we only get a handful of security alerts in our console each day. It has freed up our security staff to perform other tasks.
What is most valuable?
We love the API. We use it to generate robust reporting, and we also developed tools to perform agent actions remotely without needing to provide all IT staff with console access.
The agent will now also report the location in AD. This allows you to create dynamic collections of machines in the cloud console based on their location in local AD. You can replicate your AD OU structure into the console and run deployments and reporting based on OU. It's a very powerful feature and something that was missing in our last product.
What needs improvement?
The agent update schedule is a little sporadic, and the updates are frequent. You are definitely going to want to have a good management solution in place, such as SCCM, Intune, or Jamf in order to maintain the environment properly.
There is agent data, such as last known IP address, that is not stored historically. It would be nice if the console stored data daily, so that you could look at a timeline of events on a machine over a period of time, and currently this is not possible. You can see a snapshot of the data at the moment, but once it changes whatever was there previously is not stored.
For how long have I used the solution?
I have been using SentinelOne for four years.
What do I think about the stability of the solution?
The agent is very stable, especially the later versions of the product. Agent never crashes and consumes minimal system resources. New agent versions are constantly released (which can be slightly difficult to manage if you don't have a good endpoint third party management solution like SCCM\JAMF). Release over release both stability and features have improved and been more fleshed out.
What do I think about the scalability of the solution?
It is very scalable and easy to deploy over any of the standard management solutions.
How are customer service and technical support?
Customer service and our TAM are both very good. They are responsive and have never been unable to answer a question we asked.
Which solution did I use previously and why did I switch?
We switched because or old solution flat out was not picking up infections. It was really almost rather useless.
How was the initial setup?
The initial setup is straightforward. We do not have any on-premises infrastructure. Rather, we are using sentinel one in full-cloud mode. It was really just a matter of deploying the agent to the endpoints.
What about the implementation team?
Our in-house team handled the deployment.
What was our ROI?
ROI is kind of hard to quantify but we definitely do feel like we get our money worth.
What's my experience with pricing, setup cost, and licensing?
The costs are really rather minimal for what you receive with the product. No real advisement here. The larger count you have, the deeper discount you will receive in your contract.
Which other solutions did I evaluate?
We looked at Carbon Black. SentinelOne was more economical, and the feature set was comparable so we ultimately went with it.
What other advice do I have?
Be ready to dedicate a good amount of time to learn the API. To really get the most from the product you need to tap the REST API.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Consultant at NFC/IT
AI-powered protection, data-rollback ability, and seamless integration with SolarWinds
Pros and Cons
- "It has the ability to rollback a ransomware infection instantly and with minimal disruption to the user & provides robust reporting."
- "The fact that this runs using AI instead of heuristics provides the best protection I've seen."
- "Set up is very labor-intensive."
- "Set up is very labor-intensive."
What is our primary use case?
We are an MSP supporting various business verticals (including medical and pharmaceutical). Our core monitoring/deployment solution is SolarWinds RMM, through which we were recently introduced to SentinalOne. We use the bundled automation to install, patch, and monitor antimalware protection to endpoints. We are in the process of replacing Bitdefender with SentinalOne for several clients.
How has it helped my organization?
Deployment is automatable through the RMM, though a little clunky to do. The provided automation was a little challenging, but once you get it configured it's quite effective. Once we got it deployed to our users, it operates seamlessly and with minimal impact on system resources. Even our clients with lower-end workstations report improved performance since switching from Bitdefender.
After migrating, this also picked up some latent malware that was not previously detected & cleaned it immediately with almost no interaction required. I was impressed with how little this bogged down the affected system. This was in our pilot run, so I was on-site.
What is most valuable?
The fact that this runs using AI instead of heuristics provides the best protection I've seen. It has the ability to rollback a ransomware infection instantly and with minimal disruption to the user & provides robust reporting.
I tested this by deliberately infecting an unpatched test machine with WanaCry. First of all, SentinalOne blocked the initial infection attempt. I had to put S1 into "notify only" mode on that system to actually infect the machine. Once infected, WanaCry did what it does... encrypted all the documents I had copied to the test machine and put up the background.
We immediately got a notification on our dashboard that a system was infected. At the same time, we got a popup on the client machine notifying us of the infection, with the option to auto-repair the damage. It took less than a minute (granted, we only had about 200 MB of files on the test system) for S1 to repair the damage and put the machine back to normal with no evidence of the infection.
You also can't remove the client from the local machine without approving it within the dashboard. This is a nice feature to prevent tampering by either hapless users or even skilled threat actors.
What needs improvement?
Set up is very labor-intensive. You have to provide multiple codes from multiple places within the S1 dashboard in order to use the provided automation, and it's different for each client (or "sites" as they call it). It very much feels like an enterprise application that has been adapted for SMBs, but not very thoroughly. It would be better if they had a "site package" similar to the one offered by SolarWinds for the RMM. You just run the package on the client machine and done.
For how long have I used the solution?
We have been using this solution for approximately three months.
What do I think about the stability of the solution?
The stability is excellent so far. Once installed, it's "set it and forget it."
What do I think about the scalability of the solution?
Scalability is great if you're scaling up, but scaling down may prove to be challenging.
How are customer service and technical support?
Technical support is provided for us through SolarWinds, and they're very knowledgable.
Which solution did I use previously and why did I switch?
We used Bitdefender (also through SolarWinds) previously. SentinalOne was pitched by SolarWinds a few months ago as an alternative with robust ransomware protection. Being a small MSP, a single ransomware infection at a client could spell disaster for our business. We are always looking for the latest technology, but not marginal improvements.
How was the initial setup?
The setup script provided by SolarWinds (proprietary to their RMM) was a little challenging to get going, but once it worked, it worked perfectly. Except it didn't run on Win7 systems because it uses Powershell commands from a later version than what's available on Win7.
What about the implementation team?
The vendor team provided support, but we did the deployment.
What was our ROI?
We're making about seventy-five percent over the per-seat cost, and it's easy to sell at that price point.
What's my experience with pricing, setup cost, and licensing?
The per-seat cost is low, but you have to commit to a certain number of licenses for a year.
Which other solutions did I evaluate?
We really hadn't seen EDR solutions in action before. Our decision was based primarily on the fact that it has SolarWinds integration.
What other advice do I have?
Definitely worth the money compared to heuristic solutions, especially for clients who tend to "stretch" their hardware as long as possible. The low impact and robust reporting go a long way to make this an easy sell, and the cost is excellent for the price point.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Socio Fondatore e Proprietario at 2DC srl
A stable solution that offers very good information surrounding attacks and threats
Pros and Cons
- "The solution offers very rich details surrounding threats or attacks."
- "The solution offers very rich details surrounding threats or attacks."
- "The solution needs better reporting on new threats and malware. The reporting is present, but I can't find the information easily."
- "The price is a bit high. They should make their pricing model more affordable."
What is most valuable?
The solution offers very rich details surrounding threats or attacks.
What needs improvement?
The price is a bit high. They should make their pricing model more affordable.
The solution needs better reporting on new threats and malware. The reporting is present, but I can't find the information easily.
For how long have I used the solution?
We are in the process of testing the solution. We've been using it for three months.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
It's hard to give an impression on the stability at this time. We haven't used it on a large scale yet. We're still testing.
How are customer service and technical support?
We haven't needed to contact technical support yet.
Which solution did I use previously and why did I switch?
We are currently using Webhook as we test this new solution.
What other advice do I have?
We are using the public cloud deployment model.
I would rate the solution nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free SentinelOne Singularity Complete Report and get advice and tips from experienced pros
sharing their opinions.
Updated: February 2026
Product Categories
Endpoint Detection and Response (EDR) Endpoint Protection Platform (EPP) Anti-Malware Tools Extended Detection and Response (XDR) AI ObservabilityPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Cortex XDR by Palo Alto Networks
IBM Security QRadar
Fortinet FortiEDR
HP Wolf Security
Huntress Managed EDR
Elastic Security
Microsoft Defender XDR
Trellix Endpoint Security Platform
WatchGuard Firebox
TrendAI Vision One
Buyer's Guide
Download our free SentinelOne Singularity Complete Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Carbon Black CB Defense, CrowdStrike, and SentinelOne?
- Which is better - SentinelOne or Darktrace?
- What do you recommend to choose when replacing Symantec EDR: SentinelOne or CrowdStirke Falcon?
- Cortex XDR by Palo Alto vs. Sentinel One
- Which solution do you prefer: CrowdStrike Falcon or SentinelOne Singularity Complete?
- Does SentinelOne have a Virtual Patching functionality?
- What is the biggest difference between EPP and EDR products?
- What is the difference between EDR and traditional antivirus?
- What is your recommendation for a 5-star EDR with low resource consumption for a financial services company?
- Which is the best EDR for a logistics company with 500-1000 employees?

















