I use this solution to protect my endpoints from malware, ransomware, and viruses. My company also implements this solution for some of our customers.
Founder Director at a tech services company with 1-10 employees
A very scalable solution with great tech support and valuable web and application control features
Pros and Cons
- "The web control and the application control are two good features."
- "From our enrollment perspective, I would say maybe it could be a little lighter in terms of agent usage so that there is less computer utilization."
What is our primary use case?
What is most valuable?
The web control and the application control are two good features.
What needs improvement?
My use case is very, very simple. The solution gives me protection from the latest attacks, and visibility into the cloud. I don't have any integration use cases, so from our enrollment perspective, I would say maybe it could be a little lighter in terms of agent usage so that there is less computer utilization.
For how long have I used the solution?
I started using this solution recently, about four or five months ago.
Buyer's Guide
Sophos Endpoint
January 2026
Learn what your peers think about Sophos Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,665 professionals have used our research since 2012.
What do I think about the stability of the solution?
It's a stable product. So far, I haven't had any issues from an endpoint perspective with it blocking something that I'm trying to use, or anything of that sort.
What do I think about the scalability of the solution?
Around 10 people are using this solution in my company. It's definitely scalable. I know people who are using it for over 500,000 users.
I don't plan to increase its capacity because my number of users won't be increasing much, so I would rather look at moving from endpoint protection to VDR. Then I would have the basic protection, and on top of that I would get the Zero-day endpoint protection and advanced protection for user-less attacks.
How are customer service and support?
If we require any support for integration, performance, or product-related issues, we reach out to technical support. We have been surprised that they have continued to improve their services in terms of response time and everything else.
I would rate the support as a five out of five.
Which solution did I use previously and why did I switch?
I used McAfee before I switched to this solution. I wanted to use this product to get our team used to it since we give it to our customers. Our renewal for McAfee came up, and I started looking for something we could install and manage centrally because previously, we were working with single-user legacies and standalone endpoints. I wanted something that was corporate-friendly and manageable.
How was the initial setup?
The setup was very straightforward. First, you need to have an account, and then you just install the agents, and communication between the cloud and the agents happens.
What about the implementation team?
I'm the technical person, so I did the implementation. It took me about a day. I would rate the setup as a four out of five because there is always room for improvement.
Since it is a cloud product, updates happen automatically. The only thing is that from time to time, an update happens, and the agent does not automatically restart, so it requires a restart.
What's my experience with pricing, setup cost, and licensing?
If you compare this to other solutions from a pricing perspective, the enterprise version of Sophos turns out to be cost-effective. For example, if you currently have endpoint protection from Felix, Sophos would be comparatively cost-effective. In terms of the difference, I would say around 15% to 20%. I would rate the pricing as a four out of five.
What other advice do I have?
My advice to those considering this solution would be to look for compatibility with the operating system. If you have a heterogeneous environment like Linux or Aqua, make sure they're compatible in terms of version support and everything. Nowadays, endpoint protection is quite mature for almost all of the ends, so the only thing you need to look at is the compatibility. Otherwise, it's simple because most of the time the server management is the most difficult thing, but it's all taken care of in the cloud version, so you don't have to do anything. You just install the license and push the policies on the central server.
I would rate this solution as a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
System Administrator at a consumer goods company with 1,001-5,000 employees
Highly scalable, responsive support, and beneficial cloud functionality
Pros and Cons
- "The most valuable feature Sophos EPP Suite is that it protects the computer beyond the premise. Whether the user is at home, in the office, or traveling, you are able to apply the policies as the user moves."
- "Sophos EPP Suite could improve the way it can be installed. They used to have one installer and now they have two, one for the server and one for the client. I don't know the difference, it brings confusion."
What is our primary use case?
We are using Sophos EPP Suite for web and application control, and antivirus
What is most valuable?
The most valuable feature Sophos EPP Suite is that it protects the computer beyond the premise. Whether the user is at home, in the office, or traveling, you are able to apply the policies as the user moves.
What needs improvement?
Sophos EPP Suite could improve the way it can be installed. They used to have one installer and now they have two, one for the server and one for the client. I don't know the difference, it brings confusion.
For how long have I used the solution?
I have been using Sophos EPP Suite for approximately five years.
What do I think about the stability of the solution?
Sophos EPP Suite is stable because once we do the deployment, rarely do you receive corruptions. Additionally, once you deploy something on the cloud, it automatically applies to the client as long as the system is online.
What do I think about the scalability of the solution?
Sophos EPP Suite is highly scalable. We have close to 40 computers using this solution.
How are customer service and support?
I have contacted the support and I am satisfied with the speed of the answers.
How was the initial setup?
Sophos EPP Suite could be easier to implement and it is slow with the web installer. However, it depends on the internet speed.
What's my experience with pricing, setup cost, and licensing?
There are licenses to use this solution and we are on a three-year license.
What other advice do I have?
I would recommend this solution to others. The solution is highly scalable and we are using it in two companies and it works very well. You have control of what you want to be done or applied within your multiple sites.
I rate Sophos EPP Suite a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Sophos Endpoint
January 2026
Learn what your peers think about Sophos Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,665 professionals have used our research since 2012.
Pre-sales manager at a tech services company with 51-200 employees
Easy to deploy with good visibility and excellent AI capabilities
Pros and Cons
- "It's easy to deploy."
- "It would be ideal if the price could be lowered a little bit."
What is our primary use case?
It's an antivirus that can protect users and servers. It protects you from malware, from exploits, from viruses.
What is most valuable?
It's like any other antivirus solution, however, it's an advanced one. It has AI, Artificial Intelligence. It's lightweight, it doesn't affect your PC or your server, so it's something good to have. It's a must to have in this era. It's something very important to have for your users or even for your home, although they do offer Sophos Home for home. The normal one is for the business.
It works great.
It's easy to deploy.
The product gives you a full picture of what's happening on your endpoint, on your PC, or your server. You can trace where the virus came from, you can put rules in place, et cetera. You have full control.
The solution is stable.
The scalability is great.
We have found the technical support to be quite helpful.
What needs improvement?
There are no missing features. We're fine with its capabilities.
It would be ideal if the price could be lowered a little bit.
For how long have I used the solution?
I've been using the solution for eight years.
What do I think about the stability of the solution?
We've found the product to be quite stable. There are no bugs or glitches. It doesn't crash or freeze. It's reliable.
What do I think about the scalability of the solution?
The solution is easy to scale. If a company needs to expand it, it can do so.
As a partner, currently, we have about 30 customers using the solution. It all depends on the partners in my region. I'm in Kuwait. Every time you have to deploy, the customer would need to get three quotations, and then they choose the better price.
How are customer service and support?
Technical support is great. We have no complaints.
How was the initial setup?
The initial setup is easy. it takes about ten minutes to deploy. It's very fast and easy.
One person is enough in terms of the amount of personnel you need for implementation. However, if you have a large environment, you might require more assistance. For example, if you have hundreds of computers, you'll want more help. Likely you would need three for an enterprise setup and one for an SMB.
What about the implementation team?
As an integrator, we can implement the solution for our clients.
What's my experience with pricing, setup cost, and licensing?
Every organization, including Sophos or Microsoft, has its own pricing scheme. For Sophos, they have discounts for partners. That said, when looking at other markets, there are places they could reduce costs a bit. Mostly, the price is affordable, yet having more discounts will definitely bring more customers.
Customers must pay a yearly licensing fee. You can go monthly, however, it's cheaper to choose a yearly payment option. All of our customers go for annual licensing, not monthly.
What other advice do I have?
As a customer, you can choose whether to go on cloud or on-premise. We prefer to be on the cloud as it has better features now.
We are a partner and integrator.
I'd rate the solution to other companies. We recommend it to clients all of the time.
I would rate the solution at a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Manager of Information Security at a healthcare company with 1,001-5,000 employees
Good DLP capability, easy to set up, and the technical support is responsive
Pros and Cons
- "The most valuable feature is data loss prevention."
- "If we could bypass the first couple of levels of support when we have a problem then it would be easier and quicker when we need an issue resolved."
What is our primary use case?
We use EPP Suite for a lot of things including DLP, EDR, device management, and application control.
What is most valuable?
The most valuable feature is data loss prevention.
The rollback feature that SentinelOne has would be a great addition to Sophos.
What needs improvement?
If we could bypass the first couple of levels of support when we have a problem then it would be easier and quicker when we need an issue resolved.
For how long have I used the solution?
I have been using the Sophos EPP Suite for about six months.
What do I think about the stability of the solution?
This product has been very stable and we haven't had any issues.
What do I think about the scalability of the solution?
We have been scaling its use to other parts of the organization and so far, that experience has gone fairly well. We have about 700 people using it at this point. The users include administrations, first-level users, who are reviewers, and the support team. The security team uses it for reporting purposes.
How are customer service and technical support?
Technical support is very responsive and also very timely in their responses. It does take time to get through the first, second, and third-level calls, but for the most part, they are timely.
Which solution did I use previously and why did I switch?
This is our first EDR product.
How was the initial setup?
The initial setup is very simple.
What about the implementation team?
Our in-house team deployed it. We did have a conversation with Sophos on how to get it deployed and testing it in our environment.
What's my experience with pricing, setup cost, and licensing?
We purchased a three-year license, which gave us a large discount.
Which other solutions did I evaluate?
I have seen CarbonBlack and McAfee, although I have not worked with them enough to know the differences.
What other advice do I have?
My advice for anybody who is implementing EPP Suite is to work with their integration team to learn the ins and outs of the product. They have got to spend a lot of time planning the process with Sophos, and Sophos has a team in place to help with that.
Overall, I would say that it is a good endpoint solution. I think that we're using every feature that they have. That said, I'm sure that there are some things that I'm missing.
I would rate this solution a nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Manager of Information Security at a healthcare company with 1,001-5,000 employees
Great DLP, very easy initial setup, and quite stable
Pros and Cons
- "The solution's most valuable aspect, for us, is the DLP portion of the product."
- "The solution has a strange technical support process where you need to move through all of these tiers before you can get to someone who can help you. They should streamline the process and make it easier to speak to the correct level of support from the outset."
What is our primary use case?
We use the Sophos suite for a lot of things. We use it for the DLP and we can use it for the EDR. We use it for mobile device management and in application control as well. Those are some of the main uses of the application.
What is most valuable?
The solution's most valuable aspect, for us, is the DLP portion of the product.
It's just a good endpoint solution. I can't say that it's better or worse than any other product, however, it has a pretty good feature set. There are good rules, etc.
That application, so far, is actually able to tell us if there are any issues with the machine and what they are.
What needs improvement?
I'm not sure if the solution is missing anything. For us, it seems to be covering our needs quite well.
The solution has a strange technical support process where you need to move through all of these tiers before you can get to someone who can help you. They should streamline the process and make it easier to speak to the correct level of support from the outset.
SentinelOne has what they call a rollback feature. It would be great if something similar was added to Sophos.
For how long have I used the solution?
We've been using the solution for the past six months.
What do I think about the stability of the solution?
We've only been using the solution for six months. That said, it appears to be stable. We haven't had any issues. There aren't bugs and glitches, at least, not that I've experienced. It doesn't crash. It's been good.
What do I think about the scalability of the solution?
So far, we've been able to scale the solution quite well. In terms of where we are right now, it's scaling quite well to other parts of the organization, and the experience has been pretty painless so far.
We've probably got about 700 to 800 people on it so far. We have administrators, and then first-level users, which I guess are just reviewers or support, and then support teams. That's probably about it. The security team, which is what I'm a part of, too, has access to the solution for reporting purposes.
How are customer service and technical support?
We've been in touch with technical support.
They're very responsive and very timely in their responses. We find them to be quite knowledgeable as well. That said, you hate everything with the first level call and the second level call and the third level call. However, for the most part, they're very timely.
Which solution did I use previously and why did I switch?
This is our first EDR solution, I probably don't have much to compare it to.
How was the initial setup?
The initial setup was not complex at all. It was a straightforward implementation. Everything was very simple.
What about the implementation team?
We handled the implementation ourselves completely in-house. We didn't hire any integrators or outside consultants.
What's my experience with pricing, setup cost, and licensing?
I'm not sure of what our licensing costs are. There are two and three-year packages available. I know we took a three-year package with a large discount applied to it. I'm not sure if there are different tiers, like silver or platinum. There might be. I don't know what the differences would be between them if there are.
Which other solutions did I evaluate?
I've seen other solutions such as SentinalOne, Carbon Black, and McAfee. I've seen them, however, to be truthful, I can't really explain what I'm missing and what features these options offer instead.
What other advice do I have?
We're just a Sophos customer. We don't have a special relationship with the client.
We're using the latest version of the solution.
In terms of adopting this technology, I'd advise other organizations to work with their integration team and know the products in and out before getting started. They will have to spend a lot of time planning the process with Sophos. However, Sophos has a team that will help companies do that, which really helps simplify the process.
We personally didn't use them for the integration piece, but we did have the conversation with how to get it deployed, and testing, and all those kind of things within our environment.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Good anti-malware and filtering, but shows a lot of false positives
Pros and Cons
- "The anti-malware and web filtering are the solutions most valuable aspects."
- "The solution isn't quite accurate enough. It provides a lot of false positives."
What is our primary use case?
We primarily use the solution for endpoint protection. We use it as an antivirus and for web filtering.
How has it helped my organization?
There isn't an easy way to describe how it's helped our company. It's just a good source of protection.
What is most valuable?
The anti-malware and web filtering are the solutions most valuable aspects.
The solution has the capability to detect and prevent attacks.
What needs improvement?
The solution isn't quite accurate enough. It provides a lot of false positives.
For example, if you log onto the portal, you'll be able to see the endpoints. You'll see the health status, but when you click on one, you'll find everything right there, even though it might not be clear from the health status overview. The accuracy of the status needs to be better represented.
For how long have I used the solution?
I've been using the solution for several years.
What do I think about the stability of the solution?
The stability is pretty good. the only complaint is the operation of the solution.
What do I think about the scalability of the solution?
The solution is only capable of being used on a Linus or Mac. It's limiting.
We don't plan to increase usage at this time. We already use 80% of its capabilities and we don't plan to expand beyond that.
How are customer service and technical support?
I'd rate the technical support as average. It's not outstanding, however, it's also not the worst we've dealt with.
Which solution did I use previously and why did I switch?
I'm not sure if another solution was used previously. By the time I was hired, the company was already using Sophos.
How was the initial setup?
The initial setup is pretty straightforward. It's a typical setup. It's just a regular implied agent.
What's my experience with pricing, setup cost, and licensing?
I don't have any information about the cost or how much we pay. I'm not involved in the finance aspect of managing the solution.
What other advice do I have?
Although I don't know the version number, I'm using the most up to date one.
I'd advise organizations considering implementing the solution to first consider their requirements. They need to know what they are looking for. There are a lot of vendors out there that offer many of the same features. However, if there's just one critical feature that's necessary, you need to be sure it will work correctly for your company.
You also need to make sure you are choosing something that is compatible with other solutions that intersect. We've had experiences where we thought that a certain piece of software would work with Sophos and we realized that it didn't.
I'd rate the solution seven out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Engineer at a tech services company with 11-50 employees
Effective AI-powered threat detection with valuable ransomware rollback
Pros and Cons
- "The AI and EDR features are the most effective for threat detection and security."
- "The resource usage of the agent should be less intensive on the CPU and RAM."
What is our primary use case?
Our customers mainly use the Sophos Endpoint Protection Suite for an all-rounded solution, including simple DLP, next-generation firewall, antivirus, EDR, and rollback capabilities for ransomware.
How has it helped my organization?
Sophos EPP Suite provides effective threat detection by identifying suspicious behavior and terminating malicious processes. It also offers rollback capabilities for ransomware, which is not available in some other antivirus solutions.
What is most valuable?
The AI and EDR features are the most effective for threat detection and security. The behavioral-based AI can recognize suspicious activities and terminate malicious processes. The rollback capability for ransomware is also a valuable feature.
What needs improvement?
The resource usage of the agent should be less intensive on the CPU and RAM. This would make Sophos EPP Suite a better antivirus solution, especially for clients with only the minimum required specifications.
For how long have I used the solution?
I have been working with Sophos Endpoint Protection Suite for over two years.
What do I think about the stability of the solution?
I rate the stability of Sophos Endpoint Protection Suite as a seven. It can be resource-intensive, consuming significant CPU and RAM, which can affect performance.
What do I think about the scalability of the solution?
I have not faced any scalability issues. Even if the number of licenses exceeds the limit, Sophos EPP Suite still provides coverage for all endpoints.
How are customer service and support?
For tech support, I rate it between seven and eight. It might take some time to get a response, however, the support is considered good.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
Previously, I worked with McAfee, an on-premise solution where the agent could be pushed directly from the antivirus server.
How was the initial setup?
Setting up Sophos EPP Suite is relatively easy, and I would rate it as a nine out of ten. The deployment process for one PC takes about 30 to 40 minutes, considering the time needed to download signatures and files from the cloud.
What was our ROI?
The response time of Sophos EPP Suite is effective if the customer has their security operation center (SOC). Proper alerts are generated and can be analyzed by security operation engineers.
What's my experience with pricing, setup cost, and licensing?
Sophos EPP Suite is relatively expensive. If I were to rate the cost, it would be an eight out of ten.
Which other solutions did I evaluate?
I have evaluated other vendors. That said, currently, I only have experience working with Sophos EPP Suite.
What other advice do I have?
The protection offered by Sophos EPP Suite is versatile. It can detect hidden Trojans before they execute and protect vulnerable versions of Windows from exploitation.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer.
Pre-Sales at a tech services company with 51-200 employees
Offers multi-layer security through synchronization between endpoints and firewalls
Pros and Cons
- "Sophos EPP Suite's best feature is that the endpoints and firewalls remain synced."
- "With Sophos EPP Suite, inventory cannot be checked, and external applications cannot be installed."
What is our primary use case?
I deploy the solution on multiple EPP sites and firewalls.
What is most valuable?
Sophos EPP Suite's best feature is that the endpoints and firewalls remain synced. The aforementioned synchronization casts a multi-layer security. When I use a firewall or Kaspersky, this synchronization is unavailable. Sophos EPP Suite has a useful expert prevention feature that prevents ransomware attacks. The solution also helps me review multiple technical reports.
What needs improvement?
Sophos EPP Suite focuses completely on security and lacks managerial features or a management console. Competitors like Kaspersky have management control over endpoints. With Sophos EPP Suite, inventory cannot be checked, and external applications cannot be installed.
In the future version, a virtual patching feature can be included.
For how long have I used the solution?
I have been using Sophos EPP Suite for five years.
What do I think about the stability of the solution?
I am satisfied with the stability of the solution.
What's my experience with pricing, setup cost, and licensing?
Sophos EPP Suite is a competitive and affordable solution. The product is adaptable in economically weak countries, too.
What other advice do I have?
The solution's threat response feature is very productive. You not only get a response but also a root cause analysis. In my five years of experience with the product, I have never witnessed a compromised system with Sophos EPP Suite. In comparison, Kaspersky has been less successful in mitigating attacks.
When using the suite's Sophos MDR for root protection and threat response, if a solution doesn't respond properly due to missing configuration, the solution can recommend the best configuration for a sharp response on time as per the product's capability.
I would definitely recommend Sophos EPP Suite to others. The product has AI-driven and deep-security features. I would rate the solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Buyer's Guide
Download our free Sophos Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Endpoint Protection Platform (EPP)Popular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Complete
HP Wolf Security
Cortex XDR by Palo Alto Networks
Trellix Endpoint Security Platform
Fortinet FortiClient
Check Point Harmony Endpoint
Symantec Endpoint Security
Kaspersky Endpoint Security for Business
Trend Vision One Endpoint Security
Intercept X Endpoint
WatchGuard EPDR
Buyer's Guide
Download our free Sophos Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
- Which Endpoint Protection Solution offers Zero Trust (ZTN) as a feature?
- What to choose: an endpoint antivirus, an EDR solution or both?
- Which ransomware is the biggest threat in 2020?
- Are you aware of SIEM platforms that integrate both Active Directory auditing and security monitoring tools?
- What is the best solution for ransomware attack?

















