I use it for policy fine-tuning.
Security Analyst at a tech services company with 1,001-5,000 employees
Identifies Zero-day attacks, provides good visibility, and it's straightforward to use
Pros and Cons
- "It has good visibility features and it's straightforward."
- "SentinelOne uses behavioral analysis and artificial intelligence to detect unknown malware."
- "There is not much flexibility in terms of policy fine-tuning. We can turn it off or turn it on, but, there's nothing much else to do. Everything is predefined. It's good in a way, but you don't get much flexibility if you want to do something particular."
What is our primary use case?
How has it helped my organization?
SentinelOne uses behavioral analysis and artificial intelligence to detect unknown malware. That is what all enterprises require today. They don't want to go with some normal anti-malware tool, which has less sophisticated detection. Even if something suspicious or a Zero-day enters the environment, SentinelOne will be able to identify it.
What is most valuable?
It has good visibility features and it's straightforward. It's not so complex.
What needs improvement?
There is not much flexibility in terms of policy fine-tuning. We can turn it off or turn it on, but there's nothing much else to do. Everything is predefined. It's good in a way, but you don't get much flexibility if you want to do something particular.
Buyer's Guide
SentinelOne Singularity Endpoint
August 2026
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
911,493 professionals have used our research since 2012.
For how long have I used the solution?
Less than one year.
What do I think about the stability of the solution?
We do not have any issues with stability at the moment. Before I joined the company, I heard that there were some issues with the agent, that they were having some performance issues, a portlet application was crashing. There were minor issues which are fine now.
What do I think about the scalability of the solution?
In my organization, we are planning to deploy some 30,000 agents. I would say that it's scalable. I don't see any problem with scalability.
What other advice do I have?
I just had a conversation with a colleague who has bought McAfee ePO. He was saying that he was able to do much more in that tool than in SentinelOne. For example, he mentioned that he was able to see traffic on a particular port on a particular system, using ePO. We cannot do that using SentinelOne. In this tool, everything is already in place and there's not much that we can do.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
System Engineer at a tech services company
It has provided overall endpoint status visibility
Pros and Cons
- "SentinelOne’s Rollback is its best feature."
- "No solution can ever provide a 100% protection, but their rollback feature closes this gap in endpoint security giving end users a ray of hope in the event of a worst case scenario endpoint breach, especially in ransomware attacks."
- "They could add “right click>scan” where most users were trained to do so in handling flash drives."
- "They need to improve their UI and the way they show that the scanning is running on the endpoint."
How has it helped my organization?
Before it was a challenge for us to know who had an existing endpoint issue or who had the most attacks within the corporate network. Since SentinelOne was introduced, it has provided overall endpoint status visibility for us. Giving us the ability to easily pinpoint endpoints which had the most attacks and respond at a faster rate.
What is most valuable?
SentinelOne’s Rollback is its best feature. No solution can ever provide a 100% protection, but their rollback feature closes this gap in endpoint security giving end users a ray of hope in the event of a worst case scenario endpoint breach, especially in ransomware attacks.
What needs improvement?
They need to improve their UI and the way they show that the scanning is running on the endpoint. Sometimes users wanted to see whether their AV is working via visual context.
They could add “right click>scan” where most users were trained to do so in handling flash drives.
Also, add remote code execution via the management console, application control, device control, and all other common features found on the legacy antiviruses. This would help administrators to fully shift from legacy to Next Gen EPP without sacrificing usable features.
What do I think about the stability of the solution?
There have been a few cases where the agent cannot report to the management console, thus this requires a manual restart of the agent via a command prompt.
What do I think about the scalability of the solution?
There are no problems with scalability, I could say that the product is easily scalable, since it is not limited to a physical server.
How are customer service and technical support?
The technical support is quick and very helpful. They often response within the day or by the next business day.
Which solution did I use previously and why did I switch?
As of now, SentinelOne still serves as an augmentation for our existing AV, but some of our devices are now using it as their sole endpoint protection.
How was the initial setup?
The setup is very easy and straightforward. It is just like installing an ordinary program and it automatically reports back to the management console.
What's my experience with pricing, setup cost, and licensing?
The price for it is very competitive compared to other Next Gen EPP. You can really get a great value for it when it is integrated with EDR.
Which other solutions did I evaluate?
No, since we already had experience with other products. As of today, we have tested one of its competitor using AI, but their overall protection still cannot be compared to how SentinelOne protects your endpoint.
What other advice do I have?
They have an impressive product.
Understand how endpoint protection technologies work, since they do not rely on signature databases anymore. Also, follow deployment guidelines, such as initially deploying it in their production environment using a monitor only policy and giving the agents maturity of at least one to two weeks to allow the management console to build a solid behavior base for their environment.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
SentinelOne Singularity Endpoint
August 2026
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
911,493 professionals have used our research since 2012.
Account Director
The solution can search for hidden and dormant threats on encrypted traffic in your environment
Pros and Cons
- "The solution can search for hidden and dormant threats on encrypted traffic in your environment."
- "Yes, Sophos, I switched because SentinelOne does more things and guarantees against ransomware and can find hidden threats that other solution could not find."
- "Deployment strategy for large organizations that do not use active directory (AD)."
What is most valuable?
If I am breached, they will pay the ransom on my behalf.
Cybercrime is growing in the world of technology, the defense in today’s world has no accountability. If breached, all that is said is that it is zero-day, and you still pay license fees to those vendors. The solution can search for hidden and dormant threats on encrypted traffic in your environment.
How has it helped my organization?
With automation, the time wasted on malware, like ransomware, is dealt with on a scale where everything is centralized. The IT Technician does not have to wait for a user to bring the machine to IT, as all they need is an active internet connection.
What needs improvement?
- Deployment strategy for large organizations that do not use active directory (AD).
- Windows updates have not been done on the client side, so minimum requirements stop the installation.
For how long have I used the solution?
One year.
What do I think about the stability of the solution?
None.
What do I think about the scalability of the solution?
None.
How are customer service and technical support?
Excellent, they have customized reports on threats in our environment that we do not have knowledge of.
Which solution did I use previously and why did I switch?
Yes, Sophos, I switched because SentinelOne does more things and guarantees against ransomware and can find hidden threats that other solution could not find.
How was the initial setup?
It is both straightforward and complex to install.
Machines on Windows 10 are easy and seamlessly installed.
Users machines that are not updated require updates to be done first before the solution can be installed.
What's my experience with pricing, setup cost, and licensing?
Spend money on the security for the endpoint. That is where the data lies and where hackers try an attack, not the network or firewalls.
Which other solutions did I evaluate?
Sophos, AVG, Avast, McAfee, Kaspersky, and ESET.
What other advice do I have?
Ask about accountability for hidden and dormant threats that could be in your network.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller and Platinum partner of the solution through Cyber Intelligent Systems.
Business Development at a tech services company
Solution with competitive pricing which has the capacity to prevent new threats
Pros and Cons
- "Its capacity to prevent new threats."
- "We have been protecting more than 100 companies (with no infections) since the product was installed."
- "The management console."
How has it helped my organization?
We have been protecting more than 100 companies (with no infections) since the product was installed.
What is most valuable?
- The rollback functionality.
- Its capacity to prevent new threats.
What needs improvement?
The management console.
For how long have I used the solution?
Nine months.
What do I think about the stability of the solution?
No.
What do I think about the scalability of the solution?
No.
How are customer service and technical support?
Very fast and accurate.
Which solution did I use previously and why did I switch?
Yes, Kaspersky Lab. They don't have a good next gen endpoint in order to protect against new threats.
How was the initial setup?
Very easy. You can start your deploy with a single executable file or a massive deployment (GPO, etc.) with a MSI.
What's my experience with pricing, setup cost, and licensing?
The price is competitive, if you compare it with other solutions on the market.
Which other solutions did I evaluate?
Sophos Intercept X, Cylance, Traps and a few more.
What other advice do I have?
It's very important to understand how industry-wide endpoint security solutions work to avoid possible issues.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cybersecurity Analyst at a tech vendor with 10,001+ employees
A reasonably priced solution with EDR capabilities
Pros and Cons
- "The tool's most valuable feature is EDR."
- "I rate Singularity Cloud Workload Security's stability a four out of ten."
What is our primary use case?
I use the solution for EDR. We're in the process of deploying so log collection will be a use case later on.
How has it helped my organization?
We are certain it will improve our organization later on because today our cloud has limited AD and zero EDR. SentinelOne is replacing our current legacy and we're also getting the EDR functionality.
What is most valuable?
The tool's most valuable feature is EDR.
For how long have I used the solution?
I have been using the product for two months.
What do I think about the stability of the solution?
I rate Singularity Cloud Workload Security's stability a four out of ten.
What do I think about the scalability of the solution?
I rate the solution's scalability a four out of five.
Which solution did I use previously and why did I switch?
We chose Singularity Cloud Workload Security because our team wanted a cloud-native solution instead of a legacy.
How was the initial setup?
The tool's deployment is not complex. Our team got complex information, which made it complex.
What about the implementation team?
SentinelOne's team helped us with the deployment. We had an awesome experience working with them. There were some miscommunications also.
What's my experience with pricing, setup cost, and licensing?
The product is reasonably priced.
What other advice do I have?
I rate Singularity Cloud Workload Security an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Cybersecurity Analyst at a tech services company with 11-50 employees
Great test automation and improvement of use cases
Pros and Cons
- "SentinelOne has helped us to improve our security by fine-tuning our current use cases and creating new ones."
- "SentinelOne's performance and the accuracy of its incident filtering could be improved."
What is our primary use case?
I use SentinelOne for security.
How has it helped my organization?
We function as an internal red team and do numerous tests of attack simulations. SentinelOne has helped us to improve our security by fine-tuning our current use cases and creating new ones.
What is most valuable?
SentinelOne's best features are test automation, playbooks, incident response, use-case improvement, and compliance with MITRE ATT&CK techniques.
What needs improvement?
SentinelOne's performance and the accuracy of its incident filtering could be improved.
For how long have I used the solution?
I've been using SentinelOne for five years.
What do I think about the stability of the solution?
SentinelOne is stable.
What do I think about the scalability of the solution?
SentinelOne is scalable.
How was the initial setup?
The initial setup was straightforward because we created an implementation plan and did some diagnostics before starting.
What about the implementation team?
We used a third-party team.
What's my experience with pricing, setup cost, and licensing?
SentinelOne's pricing could be lower.
What other advice do I have?
I would give SentinelOne a rating of eight out of ten.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Buyer's Guide
Download our free SentinelOne Singularity Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: August 2026
Product Categories
Endpoint Detection and Response (EDR) Endpoint Protection Platform (EPP) Anti-Malware Tools Extended Detection and Response (XDR) AI-Powered Cybersecurity Platforms AI ObservabilityPopular Comparisons
CrowdStrike Falcon
Cortex XDR by Palo Alto Networks
Microsoft Defender for Endpoint
SentinelOne Singularity Cloud Security
IBM Security QRadar
Elastic Security
Huntress Managed EDR
TrendAI Vision One
Trellix Endpoint Security Platform
TrendAI Vision One – Cloud Security
WatchGuard Firebox
Buyer's Guide
Download our free SentinelOne Singularity Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Carbon Black CB Defense, CrowdStrike, and SentinelOne?
- Which is better - SentinelOne or Darktrace?
- What do you recommend to choose when replacing Symantec EDR: SentinelOne or CrowdStirke Falcon?
- Cortex XDR by Palo Alto vs. Sentinel One
- Which solution do you prefer: CrowdStrike Falcon or SentinelOne Singularity Complete?
- Does SentinelOne have a Virtual Patching functionality?
- What is the biggest difference between EPP and EDR products?
- What is the difference between EDR and traditional antivirus?
- What is your recommendation for a 5-star EDR with low resource consumption for a financial services company?
- Which is the best EDR for a logistics company with 500-1000 employees?
















