No more typing reviews! Try our Samantha, our new voice AI agent.
Lee Houghton - PeerSpot reviewer
Technical Manager, Infrastructure at a healthcare company with 5,001-10,000 employees
Real User
Top 20
Mar 5, 2026
Unified controls have replaced multiple tools and now streamline secure app access and approvals
Pros and Cons
  • "The benefits of using ThreatLocker Zero Trust Endpoint Protection Platform for my company include removing previous tools that we did not prefer, replacing them with this solution, and enjoying a significantly better user experience."
  • "My experience with the pricing, setup cost, and licensing is that it is expensive, but it is what you would expect because it is a comprehensive platform."

What is our primary use case?

My main use cases for ThreatLocker Zero Trust Endpoint Protection Platform are Application Whitelisting, Elevation Control, and Storage Control.

What is most valuable?

The features of ThreatLocker Zero Trust Endpoint Protection Platform that I find most valuable are the application control and Elevation Control.

My impression of the solution's allow-listing feature in terms of managing which software, scripts, and libraries run on my devices is positive. We can implement it at a global level or a user device level, and it is straightforward to execute. By placing it in learning mode, the system does most of the work automatically, and we only need to address occasional edge cases as they arise.

The role of Elevation in facilitating just-in-time administrative access for approved applications is critical for us. Our industry software is twenty years old, and everything needs to run as local admin. We obviously cannot do that from a security perspective, so having only this application run as admin is essential for us to keep the devices secure.

By using ThreatLocker Zero Trust Endpoint Protection Platform, my company has been able to eliminate or consolidate three solutions: BeyondTrust, USB Lock, and Active Directory Software Restriction Policy for Application Whitelisting.

The benefits of using ThreatLocker Zero Trust Endpoint Protection Platform for my company include removing previous tools that we did not prefer, replacing them with this solution, and enjoying a significantly better user experience. It should reduce some overhead and save time in processes that are now faster.

What needs improvement?

To improve ThreatLocker Zero Trust Endpoint Protection Platform, I would prefer grouping done in the console rather than in how you deploy the software, so that we can automate that more effectively. Additionally, more integrations with our specific tools, such as Arctic Wolf, which is our SOC, would be beneficial so that it can feed security logs out of ThreatLocker into that system.

For how long have I used the solution?

I have been using ThreatLocker Zero Trust Endpoint Protection Platform for nine months.

Buyer's Guide
ThreatLocker Zero Trust Platform
August 2026
Learn what your peers think about ThreatLocker Zero Trust Platform. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,683 professionals have used our research since 2012.

What do I think about the stability of the solution?

Regarding the stability and reliability of the platform, I have experienced no downtime, crashes, or performance issues. It works reliably and performs as quickly as expected.

What do I think about the scalability of the solution?

ThreatLocker Zero Trust Endpoint Protection Platform scales effectively with the growing needs of my company, with expanded usage being primarily about the learning mode, which makes it straightforward to roll out.

How are customer service and support?

I have not yet engaged with customer service or technical support. We are currently working with our Solutions Engineer, who is available when we need assistance.

Which solution did I use previously and why did I switch?

The factors that led me to consider a change when switching from three different tools to ThreatLocker Zero Trust Endpoint Protection Platform included usability more than anything else. The previous tools were all very manual and intensive, representing basically a full-time job for one person. Now that everything is in ThreatLocker Zero Trust Endpoint Protection Platform, we have that single pane of glass again where we can do all things in the same console, much more granularly, allowing us to apply controls to just specific devices or whitelist Office for the whole business, which is something we had struggled with.

I eliminated those tools because we wanted that single pane of glass, so everything was done in one console with full visibility. We now have an audit in the unified audit that shows what is happening, which we have never previously had.

What was our ROI?

I would say ThreatLocker Zero Trust Endpoint Protection Platform has helped my company save on operational costs or tasks because long-term it will provide savings once we are fully up and running. It should help reduce our team's overhead of approving applications, allowing us to delegate it to other departments or automate the process.

What's my experience with pricing, setup cost, and licensing?

My experience with the pricing, setup cost, and licensing is that it is expensive, but it is what you would expect because it is a comprehensive platform. Obviously, there is some savings there, but overall, the cost has increased, although there are some optimization savings that the business will probably realize long-term that will help offset the investment.

Which other solutions did I evaluate?

I did not consider any other tools or solutions before choosing ThreatLocker Zero Trust Endpoint Protection Platform. The previous tools we used were ones we switched to initially and then decided we did not prefer, so we were switching again. ThreatLocker Zero Trust Endpoint Protection Platform does everything we need it to do, making it an easy choice.

What other advice do I have?

I believe the long-term impact that Ringfencing has on controlling the behavior of approved applications will be beneficial for us because currently, everything is very open. We can start limiting applications so that they can only communicate with the services they need to access, rather than having the ability to reach everywhere and do whatever it wants. Currently, this represents a significant attack surface for us.

I have not used the Storage Control feature much. I have not used the Ringfencing feature of ThreatLocker Zero Trust Endpoint Protection Platform, but we have seen it somewhat. I have not really engaged with the Network Control feature yet, but it is more of a phase two for us, focusing on Application, Elevation, and the other features as a first step.

I would rate ThreatLocker Zero Trust Endpoint Protection Platform overall as a nine out of ten because I do not give anything a perfect ten, which effectively means it is a ten. My advice to other companies considering it is to proceed with a proof of concept. The POC took less than an hour to complete, we had it running at the site, and the site did not even notice the implementation. It is not difficult to enable, and I recommend seeing what happens and discovering what it can do for your organization. I would rate this solution nine out of ten overall.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 5, 2026
Flag as inappropriate
PeerSpot user
Bryan Watson - PeerSpot reviewer
Manager, Corporate Information Technology at Nexen Group, Inc.
Real User
Top 20
Mar 4, 2026
Zero trust controls have protected endpoints and currently allow secure self-service installs
Pros and Cons
  • "ThreatLocker Zero Trust Endpoint Protection Platform has helped my company save on operational costs and expenses."
  • "From one to ten, I would rate the solution overall as a nine out of ten just because the initial setup was a little confusing."

What is our primary use case?

My main use cases for ThreatLocker Zero Trust Endpoint Protection Platform are to prevent applications from running that we do not want to run and to keep our endpoints safe and secure. We have had a breach in the past and so we are really focused on security now. Luckily, that happened before I started. The primary goal is to prevent applications that are not meant to run.

How has it helped my organization?

Examples of how those features benefit my company include that we are a small manufacturing company and our engineers have a tendency to think they should have admin rights and be able to download anything they want. Being able to protect the company from this mindset is handy. Being able to prevent them from installing whatever they think they want is beneficial.

What is most valuable?

The features of ThreatLocker Zero Trust Endpoint Protection Platform that I like the most include being able to get alerts from end users when they want to install something. When they are trying to install something and it gets denied, they can click the request this application button. Then we get alerts and we can review it. The sandbox testing is also really nice.

My impression of the solution's allow listing feature in terms of managing which software, scripts, and libraries run on my devices is that I really like it because you can set those programs and libraries to an elevated mode. When an end user needs to install the software, IT does not have to get involved. It has already been approved and elevated, so they do not need to call us for administrative credentials to install it.

What needs improvement?

I do not think I would add or change anything at this time. The only thing that comes to mind would be when I am working on an endpoint trying to install software and I need to move it to application learning mode or maintenance mode. I have to go back to my desktop to do that. It would be nice if I could right-click from the system tray and enter my credentials to enter into application learning mode directly there.

For how long have I used the solution?

I have been using ThreatLocker Zero Trust Endpoint Protection Platform for about eight months.

What do I think about the stability of the solution?

My assessment of the stability and reliability of ThreatLocker Zero Trust Endpoint Protection Platform is that it has been up 100% of the time and running well.

How are customer service and support?

I would evaluate the customer service and technical support as excellent because I have not had to use them.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Before adopting ThreatLocker Zero Trust Endpoint Protection Platform, I was not using anything for application control. I have never seen anything similar to ThreatLocker Zero Trust Endpoint Protection Platform in the past.

How was the initial setup?

From one to ten, I would rate the solution overall as a nine out of ten just because the initial setup was a little confusing. Even though we had an MSP do it for us, we were following along, and it was a little confusing.

What was our ROI?

ThreatLocker Zero Trust Endpoint Protection Platform has helped my company save on operational costs and expenses. As I mentioned earlier, the elevated prompt and the allow listing mean we do not have to go around to each user to enter credentials to install software. We just tell them where the software package is and they can install it themselves.

What's my experience with pricing, setup cost, and licensing?

My experience with the pricing, the setup cost, and the licensing of ThreatLocker Zero Trust Endpoint Protection Platform has been fantastic.

Which other solutions did I evaluate?

My company has not been able to eliminate or consolidate any security tools or solutions. ThreatLocker Zero Trust Endpoint Protection Platform is actually a result of that process. When we moved to an MSP, they consolidated a bunch of our software and tools, and ThreatLocker Zero Trust Endpoint Protection Platform was one of the add-ons, which was nice.

What other advice do I have?

I do not use the Network Control feature, to my knowledge. I do use the Elevation Control feature. My assessment of its role in facilitating just-in-time administrative access for approved applications is that I think it is great. As I said earlier, you do not have to be bothered by the end user to come install a program that is on the allow list. It is elevated, so it allows the end user to install it without IT getting involved, and that saves us time, which is valuable. I do not think we use the Storage Control feature. I do not remember the setup process for that. I think we do use the DAC dashboard, and I think that would be part of the pending approvals section in that dashboard where users ask for approval for software, and we have to go and approve it, use the sandbox and all of that, and either approve or deny it. The ease of identifying which security and configurations settings need fixing using the DAC dashboard is something we have not gotten into because our MSP set it all up and handled all of that for us, which was nice. I have not used the Web Control feature.

We do use the Ring Fencing feature with ThreatLocker Zero Trust Endpoint Protection Platform, but I am not 100% certain on how we do it or how we use it because I know the MSP helped us set that up, but I know we do use it.

I would rate this review a nine out of ten overall.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 4, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
ThreatLocker Zero Trust Platform
August 2026
Learn what your peers think about ThreatLocker Zero Trust Platform. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
913,683 professionals have used our research since 2012.
CISO at Cyber Solutions
Real User
Top 20
Mar 4, 2026
Zero trust controls have protected clients and simplified replacing multiple security tools
Pros and Cons
  • "Overall, I rate ThreatLocker Zero Trust Endpoint Protection Platform a 10, and I would advise other companies considering the solution that they should have done it yesterday."
  • "ThreatLocker Zero Trust Endpoint Protection Platform could be improved by addressing the human identity piece, whether through ThreatLocker Zero Trust Endpoint Protection Platform or another tool."

What is our primary use case?

Our main use cases for ThreatLocker Zero Trust Endpoint Protection Platform are for all of our MSP clients; we use the total package. Every one of our clients gets ThreatLocker Zero Trust Endpoint Protection Platform. We do not have any opt-out or anything of that nature.

What is most valuable?

I would say I value Application Control the most about ThreatLocker Zero Trust Endpoint Protection Platform.

We operate from a default deny on our firewalls, so why wouldn't we do the same thing within our actual applications? Plus we have Shadow IT we have to worry about and of course, threat actors.

It benefits us by allowing me to sleep at night and having a true inventory of the applications that are in place. I think a lot of other security products overlook that inventory of applications to find out what is actually running in an environment and then being able to control who runs those applications.

By using ThreatLocker Zero Trust Endpoint Protection Platform, we have been able to eliminate some security tools; we did have SentinelOne, and while it is a good product, it was not doing anything because ThreatLocker Zero Trust Endpoint Protection Platform was preemptively taking action.

What needs improvement?

ThreatLocker Zero Trust Endpoint Protection Platform could be improved by addressing the human identity piece, whether through ThreatLocker Zero Trust Endpoint Protection Platform or another tool. Currently, ThreatLocker Zero Trust Endpoint Protection Platform does not have the human identity, and I would love to see them release something similar to that. Think MGM; everybody knows that a call center password reset was social engineered. A simple end-user verification would have stopped that whole attack, and I would like to see ThreatLocker Zero Trust Endpoint Protection Platform develop something of that nature.

For how long have I used the solution?

I have been using ThreatLocker Zero Trust Endpoint Protection Platform since 2021, which is five years.

What do I think about the stability of the solution?

I would assess the stability and reliability of ThreatLocker Zero Trust Endpoint Protection Platform as being on par or exceeding most uptime; we have not experienced any downtime, crashes, or performance issues.

What do I think about the scalability of the solution?

ThreatLocker Zero Trust Endpoint Protection Platform scales well with the growing needs of my company; I would say we have had 300% growth since the implementation of ThreatLocker Zero Trust Endpoint Protection Platform, and it scaled with no problem. It has actually gotten easier because we are becoming more proficient in the tool.

How are customer service and support?

I evaluate the customer service and technical support as being second to none.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We were using SentinelOne.

The factors that led me to consider a change from SentinelOne included the performance; SentinelOne was a good tool, but we just did not see it performing any duties because ThreatLocker Zero Trust Endpoint Protection Platform was on the proactive side, and SentinelOne was not taking any actions.

What was our ROI?

ThreatLocker Zero Trust Endpoint Protection Platform has helped my company save on operational costs by allowing us to remove some tools that had overlaps, which obviously leads to overall savings; I cannot tell you the exact amount though.

What's my experience with pricing, setup cost, and licensing?

My experience with the pricing, the setup cost, and the licensing of ThreatLocker Zero Trust Endpoint Protection Platform is that we have very good pricing. I think if you take the sum of the tools, they are very competitive, if not more affordable than most solutions out there.

Which other solutions did I evaluate?

Before choosing ThreatLocker Zero Trust Endpoint Protection Platform, we actually shopped around; there was no other solution out there that did what ThreatLocker Zero Trust Endpoint Protection Platform did. It was an obvious choice. We did pair that with SentinelOne initially, but then when ThreatLocker Zero Trust Endpoint Protection Platform became a full EDR/MDR solution, which honestly was performing those functions before they even branded it that way, we were able to let go of SentinelOne.

What other advice do I have?

The impact of the Ringfencing feature on controlling the behavior of approved applications is significant. You can take something that is not malicious, such as 7-Zip, which is used by a lot of users, but because it is maintained by Russia, you would not want to allow that call-out over the internet calling back home; you can Ringfence that internet connection entirely. Other tools of that nature can be used for encryption, and we do not want a non-malicious tool used for malicious purposes. Another good example is PowerShell; since PowerShell is built into every Windows computer, you have to let PowerShell do its job but nothing else.

The Network Control feature makes it much easier to manage network traffic across endpoints and servers because you do it without running VLANs and in some cases, rewiring a building. You can actually segment that network based on use need and the risk of that particular vertical.

My assessment of the Elevation Control feature in ThreatLocker Zero Trust Endpoint Protection Platform is that just-in-time elevation allows us to give the applications or the user that limited administrative privilege without posing a long-term threat.

My thoughts on the Storage Control feature when enforcing policy-driven access over various storage devices are that we can actually enforce control that HIPAA mandates with basically two policies. A lot of the HIPAA environments we walk into say they are doing it, but they are not. We can set that with two policies within Storage Control. We can also use Storage Control to do some data loss prevention, mandate encryption on removable storage, and we can even get a little bit more granular and alert based on activity around the particular storage area.

Identifying which security and configuration settings need fixing using the DAC dashboard is made much easier because we can go at the client's board level and see if there are any improper configurations or adjustments that could make a broader control overall.

The efficiency of the real-time threat intelligence and category controls employed by Web Control in blocking malicious and non-compliant sites can be very valuable, especially in a newly registered domain. A lot of phishing emails are linked to newly registered domains, so that is going to flag and block that potential phishing attempt or social engineering that leads inevitably to credential harvesting.

I would rate ThreatLocker Zero Trust Endpoint Protection Platform a 10 out of 10. Overall, I rate ThreatLocker Zero Trust Endpoint Protection Platform a 10, and I would advise other companies considering the solution that they should have done it yesterday. Most of my time here is talking to other MSPs about why they are not doing this yet, but it is a phenomenal solution. On the recovery side, we work active recoveries for people that are not our clients, and we have yet to see ThreatLocker Zero Trust Endpoint Protection Platform in place in any of those environments. I think that attests to how strong the solution is.

I would say the leadership at ThreatLocker Zero Trust Endpoint Protection Platform, from the C-suite all the way down to the Tier 1 cyber hero, is remarkable; they create a sense of family and partnership that really resonates with using ThreatLocker Zero Trust Endpoint Protection Platform.

Disclosure: My company has a business relationship with this vendor other than being a customer. Partners
Last updated: Mar 4, 2026
Flag as inappropriate
PeerSpot user
Systems Administrator at a consultancy with 11-50 employees
Real User
Top 20
Sep 16, 2026
Allow listing has cut shadow IT and now remote staff run updates securely with elevation control
Pros and Cons
  • "My advice for others looking into using ThreatLocker Zero Trust Platform is to reach out to them, and they will get you set up with a free trial and use the software and the dashboard."
  • "My impression of the solution's allow listing feature in terms of managing which software, scripts, and libraries run on my devices is that it's a little finicky when dealing with software that is proprietary and is updated regularly."

What is our primary use case?

My main use case for ThreatLocker Zero Trust Platform is allow listing software, as well as Elevation Control and Storage Control.

For a specific example of how I use allow listing or Elevation Control in my day-to-day work, I set a list of what software is allowed on our network computers and any software that is not those programs is simply not allowed to run. ThreatLocker makes that really easy to deploy.

What is most valuable?

The allow listing feature stands out to me as being especially reliable and helpful. We run the executable on people's computers, it gets them into the system, and then there's a really clean UI where we can go and see what is allowed or not allowed. It's clear and easy for people that have both industry experience and lack industry experience to use.

ThreatLocker Zero Trust Platform has positively impacted my organization by making us much more secure in the sense that people aren't able to just install any random software that they want anymore. It has cut down massively on Shadow IT, which is people going and installing programs without consulting the IT department first. The Elevation Control has been very useful for any remote employees when they try to go and run any software updates. We are able to elevate the permissions on those software in case they are running into any issues while across the world.

What needs improvement?

I would like to see ThreatLocker Zero Trust Platform improve by developing some sort of software deployment plan where we can use it for pushing out and installing software onto the computers through the remote agents. For example, if I wanted to go and install Adobe Acrobat onto every computer in the company, it would be really nice if I could go and do that through ThreatLocker by just pushing out the software to each person. We can already go and allow the software on each one of the machines and elevate the permissions so that I can actually install them, but being able to deploy out software or even being able to remote uninstall software from all the machines would be very useful as well.

For how long have I used the solution?

I have been using ThreatLocker Zero Trust Platform since December of last year, so about ten months.

What do I think about the stability of the solution?

ThreatLocker Zero Trust Platform is stable.

What do I think about the scalability of the solution?

ThreatLocker Zero Trust Platform's scalability is good; it's worked on a couple computers all the way up to every single one of the computers and servers in the company, and we've had no problems anywhere from the small number to the large number.

How are customer service and support?

Customer support is excellent.

The support team behind the product has been extremely helpful. We set up meetings where we go and meet every couple weeks or every month just to check in and make sure everything is going well. It's been a very nice white glove service and I've never felt lost trying to navigate the product due to the additional help that they have provided.

How was the initial setup?

We've seen an uptick in tickets since we've implemented ThreatLocker due to the allow listing not being implemented in our system beforehand, but the tickets are very easy to handle. It's really smooth, as well as it's hard to quantify a system being more secure via metrics, but the system is more secure now.

What was our ROI?

The biggest return on investment that I've seen is that there has been less security incidents at which people have installed nefarious software onto their machines. It's hard to go and prove that we've had less security incidents since this because they got stopped before they turned into a security incident. We've also seen a lot of increase of ease of use in the sense of people using the Elevation Control remotely, trying to go and run software updates or download various software from all across the continental United States.

What's my experience with pricing, setup cost, and licensing?

Regarding my experience with pricing, setup cost, and licensing, I remember reaching out to them and it was about over a month. I reached out to them directly and also a couple third-party service providers in my area to see if we could get any better pricing through them, and our best pricing was actually directly through ThreatLocker themselves. It wasn't bad; the other ones I went and tried to look through wanted us to pay a lot more than going directly through ThreatLocker. Their attendant support and everything was really nice, and we haven't had any problems with it so far.

Which other solutions did I evaluate?

I evaluated other options before choosing ThreatLocker Zero Trust Platform.

There were a couple of other solutions that I considered before deciding on ThreatLocker Zero Trust Platform, but the names escape me. ThreatLocker was given to me from glowing reviews from multiple of my IT friends, so I had bumped them up my list of folks I was going to look into quickly. It kind of stopped at them first and I never bothered looking at others.

What other advice do I have?

I'm not the biggest fan of AI, so I will say that I have not used ThreatLocker Zero Trust Platform's AI governance and security systems very much.

I largely try not to use any of its AI features because I don't support AI use, especially in tech. The DAC that it has set up is decent, but it still has its issues. I don't really use it that much. It's kind of an interesting feature, but I don't really use it.

We deploy ThreatLocker Zero Trust Platform out to everybody via installed agents on each one of their computers, but all the data is on their cloud.

My impression of the solution's allow listing feature in terms of managing which software, scripts, and libraries run on my devices is that it's a little finicky when dealing with software that is proprietary and is updated regularly. However, with any large software that's commercially available, it works flawlessly and we haven't had any issues with any of those.

I have used the Ringfencing feature with ThreatLocker; however, I haven't utilized it to the best of its abilities yet. It kind of acts as a pseudo, I'm going to allow this but not really. I don't see it as super useful unless I'm dealing with some sort of software that I'm on the fence about even allowing in the first place.

We do not have the Network Control module currently.

The DAC dashboard leaves something to be desired. It gives a decent starting point to where I need to go with some security configuration settings, but I don't use it as a one-stop shop.

My advice for others looking into using ThreatLocker Zero Trust Platform is to reach out to them, and they will get you set up with a free trial and use the software and the dashboard. Take a look at it yourself. There's an app that you can get on your phone. The ease of use cannot be understated and the support that their customer service provides is unparalleled in the industry.

I think ThreatLocker Zero Trust Platform is really good. They're constantly running updates and they're very aware of what their customer base wants and needs. They do a decent amount of outreach and help for the community in the sense of sending out cybersecurity training videos and webinars, as well as putting on the Zero Trust World.

My overall review rating for ThreatLocker Zero Trust Platform is ten out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 16, 2026
Flag as inappropriate
PeerSpot user
Cybersecurity at a tech services company with 1-10 employees
MSP
Top 20
Mar 5, 2026
Zero trust policies have protected endpoints and simplified managing application access
Pros and Cons
  • "We found that we did not need to pay for two of the same products when we could have an all-in-one solution using ThreatLocker."
  • "ThreatLocker Zero Trust Endpoint Protection Platform can be improved by exploring ways of ensuring it is deployed deeper in the device rather than through an extension on the browser and finding ways to integrate all browsers."

What is our primary use case?

I use ThreatLocker Zero Trust Endpoint Protection Platform for application control, network control, storage, ringfencing, policy, deployments, and cloud security.

What is most valuable?

The features of ThreatLocker Zero Trust Endpoint Protection Platform that I appreciate the most are Application Control and ThreatLocker Detect. Application Control locks things down and isolates the machines very well. For ThreatLocker Detect, if a user gets compromised and their email is exposed through a login from overseas in Europe, that would have gotten blocked by default, and then we would be alerted. That is why I value that feature significantly.

These features benefit our company primarily because of our scale. We do not have as many technicians under an MSP compared to how many clients we have. We handle well over 1,500 users at any given time.

What needs improvement?

ThreatLocker Zero Trust Endpoint Protection Platform can be improved by exploring ways of ensuring it is deployed deeper in the device rather than through an extension on the browser and finding ways to integrate all browsers.

For how long have I used the solution?

My company has been using ThreatLocker Zero Trust Endpoint Protection Platform for quite a long time, since ThreatLocker was just in application mode. I have been using it since working at our company.

What do I think about the stability of the solution?

I assess the stability and reliability of ThreatLocker Zero Trust Endpoint Protection Platform as very good. With the agents, there have been a couple of versions that have had some minor issues with blue screens that have been fixed. Every so often, the portal might go down, but it is down for a very small amount of time. Otherwise, it has been a very smooth and seamless experience with probably 99.5% uptime.

What do I think about the scalability of the solution?

ThreatLocker Zero Trust Endpoint Protection Platform scales well with the growing needs of our company. Last year, from 24 to 25, we scaled over 1,000 endpoints through a ramp process, and the process was smooth. We were able to audit devices, ensure devices were not being billed that were inactive, and identify new devices that we were missing. It was very seamless and on ThreatLocker's side, the billing, accountability, and device tracking was easy to do.

How are customer service and support?

Regarding customer service and technical support, I would evaluate ThreatLocker's side as very efficient and fast. They are able to get an answer through their ticketing system, their call center, or their help desk. I would say they are efficient and they know how to resolve problems usually.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting ThreatLocker Zero Trust Endpoint Protection Platform, we used Sophos as an antivirus and we used Huntress as the EDR solution. ThreatLocker replaced both of those items.

We replaced Huntress because it does endpoint detection and will identify if there is any ransomware or risk on a device. ThreatLocker does the exact same thing with ThreatLocker Detect. We found that we did not need to pay for two of the same products when we could have an all-in-one solution using ThreatLocker.

We replaced Sophos because it is just an antivirus, similar to Windows Defender, McAfee, and other applications. We noticed that because ThreatLocker integrates with Windows Defender or Windows Security, Sophos was too high of a cost for us, whereas ThreatLocker offered some of what Sophos does offer at a much more affordable option.

What was our ROI?

I would say ThreatLocker Zero Trust Endpoint Protection Platform has helped my company save on operational costs or expenses. I am more on the technical side of things, so I cannot really speak to operational costs, but with the MDR team at ThreatLocker, it does help us prevent having to have a 24/7 technician because the MDR team handles that for us.

What's my experience with pricing, setup cost, and licensing?

My experience with the pricing, setup costs, and licensing of ThreatLocker Zero Trust Endpoint Protection Platform is that we are a very legacy customer, so pricing is extremely cheap and affordable. Setup has been very seamless. We can make an organization instantly and set up as many devices as we need. It has very easy scalability.

What other advice do I have?

I have used the Ringfencing feature with ThreatLocker, and I would say the behavior it can control is very broad and restrictive because it blocks internet access and can block PowerShell and command prompts. It does a very good job if you want to isolate a program from accessing anything else. It is helpful.

The Network Control feature of ThreatLocker Zero Trust Endpoint Protection Platform impacts my ability to manage network traffic across my endpoints and servers in a way that is not frequently utilized because we use isolated networks and firewalls already. We have not had the need to use Network Control apart from disabling the ability for RDP.

I use the Elevation Control feature in ThreatLocker with specific privileges. Elevation Control is very good when it comes to letting a standard user launch something as an admin for a temporary period of time, provided we allow it. My assessment of the Elevation Control feature's role in facilitating just-in-time administrative access for approved applications is that it works well provided we have the staff available to take that request. Because it does restrict users from being able to access their work if they need to launch something with administrative privileges, it could use some more automation.

My thoughts on the Storage Control feature when it comes to enforcing policy-driven access over various storage devices are definitely excellent with restricting USB access or remote hard drive access. Being able to monitor and ensure with Storage Control that data exfiltration is prevented has been a very useful feature.

The DAC dashboard is something that seems still relatively new and not too purposeful for what we currently do as an MSP in terms of identifying which security and configuration settings need fixing.

I assess the efficiency of the real-time threat intelligence and category controls employed by Web Control in blocking malicious and non-compliant sites as very effective. Those work very well. However, it does not work in Firefox. It only works in Chrome and Edge. It also needs to be able to throw an extension onto a browser, so it is not a surefire way of blocking websites.

My impression of ThreatLocker Zero Trust Endpoint Protection Platform's Allowlisting feature in terms of managing which software, scripts, and libraries run on our devices is very good. ThreatLocker has many built-in policies or default denies that help us with scalability for devices, and being able to isolate them per device and per organization is very helpful simply because we work with many different clientele in accounting, medical, construction, and other industries. It is very helpful when it comes to isolating and grouping organizations with application control.

My advice for other companies that are considering ThreatLocker Zero Trust Endpoint Protection Platform is to try it out and demo it. It is really easy to install and very difficult to remove, so you should make sure you know how to remove it before demoing the product. I would rate ThreatLocker Zero Trust Endpoint Protection Platform a nine on a scale of one to ten.

Disclosure: My company has a business relationship with this vendor other than being a customer.
Last updated: Mar 5, 2026
Flag as inappropriate
PeerSpot user
Josh Peabody - PeerSpot reviewer
IT Operations Manager at a construction company with 201-500 employees
Real User
Top 20
Mar 4, 2026
Zero trust controls have reduced local admin access and are streamlining just-in-time elevation
Pros and Cons
  • "My impression of the allowlisting feature in ThreatLocker Zero Trust Endpoint Protection Platform for managing which software, scripts, and libraries run on my devices is that it is awesome."
  • "ThreatLocker Zero Trust Endpoint Protection Platform has reduced some of the operational costs in my company in terms of time spent on tickets, but nothing major."

What is our primary use case?

My main use cases for ThreatLocker Zero Trust Endpoint Protection Platform include application elevation. We started using the web portion where you can control ports and filtering. Elevation and application elevation for local administration rights are primarily what we focus on, taking away local admin access.

What is most valuable?

The features of ThreatLocker Zero Trust Endpoint Protection Platform that I like the most include the elevation, which has been huge. We just got the web portal, so I'm starting to like that a lot and I plan to explore it more.

The application elevation feature of ThreatLocker Zero Trust Endpoint Protection Platform benefits my company by reducing help desk tickets and users needing to install software when we can mass enable an installation or mass approve an EXE. I can publish applications and then people can self-install them if they've been added to our repository.

What needs improvement?

To improve ThreatLocker Zero Trust Endpoint Protection Platform, I think the team is already working on it. One of the things was the ease of application allowlisting. They actually covered this on day one with the approval process, but you get multiple approvals. I think it would be better to have clearer descriptions on what each of the installation modes are.

For how long have I used the solution?

I have been using ThreatLocker Zero Trust Endpoint Protection Platform for two years.

What do I think about the stability of the solution?

I assess the stability and reliability of ThreatLocker Zero Trust Endpoint Protection Platform as excellent since I have had no issues at all. It has been very reliable.

What do I think about the scalability of the solution?

ThreatLocker Zero Trust Endpoint Protection Platform scales well to the growing needs of my company as we have expanded a couple of modules. We just added a new one and it was very easy to turn up. We still have some backend development and setting adjustments, but it has been very easy to scale, add and reduce computers.

How are customer service and support?

The customer service and technical support of ThreatLocker Zero Trust Endpoint Protection Platform have been excellent. The Cyber Heroes are phenomenal and are right there with you. They get involved and help you. It has been really easy to access support and they are great people.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting ThreatLocker Zero Trust Endpoint Protection Platform, we were not using another solution to address similar needs.

What was our ROI?

ThreatLocker Zero Trust Endpoint Protection Platform has reduced some of the operational costs in my company in terms of time spent on tickets, but nothing major.

What's my experience with pricing, setup cost, and licensing?

My experience with the pricing, setup costs, and licensing of ThreatLocker Zero Trust Endpoint Protection Platform is that it has been very reasonable and very easy to set up. Licensing is through our MSP, so it is not something I deal with directly, but it was very easy to acquire and implement into our industry.

Which other solutions did I evaluate?

Before choosing ThreatLocker Zero Trust Endpoint Protection Platform, I did consider CyberQP.

In the evaluation process, both positive and negative aspects stood out to me when comparing ThreatLocker Zero Trust Endpoint Protection Platform and CyberQP. Both are excellent programs. CyberQP is a little easier for the elevation piece, but there are far fewer controls and it has a much smaller platform footprint in terms of the security side. Each has their own niche and then they have a little overlap. I was more focused on the elevation portion as our primary problem.

What other advice do I have?

My impression of the allowlisting feature in ThreatLocker Zero Trust Endpoint Protection Platform for managing which software, scripts, and libraries run on my devices is that it is awesome. I think the allowlisting feature in ThreatLocker Zero Trust Endpoint Protection Platform is very intuitive and extremely well done. It is easy to allow and deny certain things and it is a great tool.

I have used the Ringfencing feature in ThreatLocker Zero Trust Endpoint Protection Platform. Ringfencing has opened our eyes to many things and how when you elevate something, it also gets extra access. It has helped us focus and keep things in the wheelhouse that they are supposed to be and helped us eliminate a threat vector that we did not know about or that we knew about but could not control.

I have not used the network control feature in ThreatLocker Zero Trust Endpoint Protection Platform yet. I am not using the storage control feature in ThreatLocker Zero Trust Endpoint Protection Platform. I have not used the DAC Dashboard in ThreatLocker Zero Trust Endpoint Protection Platform.

I do not have extensive insight on the efficiency of the real-time threat intelligence and category controls employed by Web Control in blocking malicious and non-compliant sites because it is very new to us. I had just demoed it before attending this event and started playing with it here, so I do not have a huge insight into that yet.

My assessment of ThreatLocker Zero Trust Endpoint Protection Platform's role in facilitating Just-In-Time administrative access for approved applications is that it has made life very easy for Just-In-Time accounts and Just-In-Time elevations. It has reduced our local admin footprint and the entry of credentials on end user machines. It has increased our overall security stature and reduced our footprint.

On a scale of one to ten, I would rate ThreatLocker Zero Trust Endpoint Protection Platform an eight or nine. It would be an easy ten, but you really need to have people who know how to use the application. My advice is to really take the time and learn it. It is really easy to put on, really easy to deploy, and really easy to deploy wrong. If you take the time and do it correctly, it is a phenomenal product.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 4, 2026
Flag as inappropriate
PeerSpot user
Cybersecurity at a construction company with 51-200 employees
Real User
Top 20
Mar 4, 2026
Zero trust controls have streamlined just-in-time access and strengthened endpoint protection
Pros and Cons
  • "Our assessment of Elevation Control's role in facilitating Just-In-Time administrative access for approved applications is that we are loving it so far."
  • "ThreatLocker Zero Trust Endpoint Protection Platform could be improved by being able to consolidate even more with an EDR for deeper scanning as needed."

What is our primary use case?

The main use cases for ThreatLocker Zero Trust Endpoint Protection Platform at my company are the Auto-Elevate platform and Application Control. Those were two big priorities for us. We needed something to replace our Just-In-Time admin access. We wanted to find something smoother than having to accept every time someone needed to elevate.

How has it helped my organization?

By using ThreatLocker Zero Trust Endpoint Protection Platform, we are considering whether we can eliminate or consolidate any security tools or solutions. We are still wanting to explore everything it can do versus something like a good EDR platform, but we are very interested in what we have seen from ThreatLocker's endpoint protection as well as their Cyber Hero and MDR platform.

ThreatLocker Zero Trust Endpoint Protection Platform has helped our company save on operational costs and expenses. So far, we are still fairly early into using it, but we can already tell from the time that we are starting to save that we are going to get a lot back out of it.

What is most valuable?

I am a big fan of the Application Control and Ringfencing features of ThreatLocker Zero Trust Endpoint Protection Platform, as well as the elevation capabilities and how fairly easy it is to make a policy based on those elevation requests and all of the built-in protections that they have.

A lot of the value comes from time and speed. Once you make the policy, you are set. You do not have to keep going back to it over and over again. We can definitely see a breakpoint where once we have these policies in place, we will not need to keep going into ThreatLocker Zero Trust Endpoint Protection Platform on a day-to-day basis and monitoring these elements. Once we have all of that in place, it is going to be a huge time-saver for us.

The allow-listing feature of ThreatLocker Zero Trust Endpoint Protection Platform has a steep learning curve at first, but once you understand it, it is very smooth. We are looking forward to reaching that break-even point. It does seem that it is going to be very low hassle and low time management once we have all of those application controls in place.

The Ringfencing feature makes it much more secure. I would assess its impact on controlling the behavior of approved applications very positively. It will help us with things such as auditing down the line, being able to know what PowerShell is actually interacting with and who can and cannot run applications such as PowerShell. We can tell from everything we have seen that it does a great job at ring-fencing everything.

The network control feature impacts my ability to manage network traffic across my endpoints and servers very positively. So far, we have not implemented too much on the network control side, but it is nice having those audit logs and being able to see where people are making those connections. Once we are ready to really go full-in on the network control, we will have a good amount of information and signals in front of us to be able to make those decisions so we can lock that down just as much as the application controls.

The Elevation Control feature is what made us look at ThreatLocker Zero Trust Endpoint Protection Platform to begin with. Our assessment of Elevation Control's role in facilitating Just-In-Time administrative access for approved applications is that we are loving it so far. Our users are loving it. They appreciate the fact that they do not have to continuously ask for elevation on certain programs. Once an elevation is set and once a policy is created for it, they are able to continuously run it as long as we know that it is a good application, which saves us a lot of time and saves them a lot of time too.

I think the storage control feature of ThreatLocker Zero Trust Endpoint Protection Platform is awesome. It is very granular compared to some other solutions that I have seen before. I have used some other vendors in the past for storage control, and a lot of it is just on and off, whereas with ThreatLocker Zero Trust Endpoint Protection Platform, you can build those policies out more comprehensively. It is easier to exclude or allow certain files and programs to run. You can have a specific device be able to talk to a specific host on a specific path, whereas with most others, it seems they can either use a USB or they cannot use a USB. This is great whenever we are dealing with our HR and finance departments that do need to have access to removable storage.

What needs improvement?

ThreatLocker Zero Trust Endpoint Protection Platform could be improved by being able to consolidate even more with an EDR for deeper scanning as needed. The philosophy for ThreatLocker does not quite seem to head in that direction, but it still would be very beneficial. Additionally, deeper browser control would be beneficial to be able to see DLP mismanagement where people are entering information into an AI platform that we do not want them to be able to enter that information into, or at the very least alert us to that type of activity.

For how long have I used the solution?

I have been using ThreatLocker Zero Trust Endpoint Protection Platform for approximately three months.

What do I think about the stability of the solution?

My assessment of the stability and reliability of ThreatLocker Zero Trust Endpoint Protection Platform is very positive. As long as we have had it, we have not had any complaints regarding performance, and we have not seen any downtime accessing the portal or from endpoints.

What do I think about the scalability of the solution?

ThreatLocker Zero Trust Endpoint Protection Platform scales very smoothly with the growing needs of our company. We have expanded usage, and so far, the process has been very smooth with the Application Control learning modes and the baseline scans. It has made it so we can shorten down those learning times where we are not quite as protected as we would prefer to be. At this point, we are able to roll it out to over 300 endpoints very seamlessly.

How are customer service and support?

I would evaluate the customer service and technical support from ThreatLocker as a ten out of ten. They are very good on both sides of that.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting ThreatLocker Zero Trust Endpoint Protection Platform, we were primarily using ScreenConnect's auto-elevate and Just-In-Time access management for similar needs. One factor that led us to consider a change was the price that we were paying for them for pretty much just that feature was close to what we ended up paying for ThreatLocker Zero Trust Endpoint Protection Platform entirely. So we got a lot more out of ThreatLocker Zero Trust Endpoint Protection Platform. Additionally, the rules that we could build in those platforms just were not as robust as what we can create in ThreatLocker Zero Trust Endpoint Protection Platform, giving us a much more secure platform.

What's my experience with pricing, setup cost, and licensing?

My experience with the pricing, the setup costs, and the licensing for ThreatLocker Zero Trust Endpoint Protection Platform is that they were very flexible with us. They worked with us to give us a good five-year term, starting off at where we needed to be in order to get ThreatLocker Zero Trust Endpoint Protection Platform. Then we were able to slowly adjust over those five years, so we were getting a very good rate upfront and then a solid rate continuing on from there.

Which other solutions did I evaluate?

We did not shop around too much for other providers before selecting ThreatLocker Zero Trust Endpoint Protection Platform. I was familiar with ThreatLocker from a previous company, so we were very quick to want to join up with ThreatLocker. They were very nice with the pricing and flexible with working with us, so it made the decision straightforward.

What other advice do I have?

It is very easy to identify which security and configuration settings need fixing using the DAC dashboard. It is pretty much one or two clicks. You can see all of the configuration mismanagements that you have, and then it is another one or two clicks to view a solution.

So far, we have not done too much on the real-time threat intelligence and category controls employed by web control in blocking malicious and non-compliant sites, so I cannot speak to that.

I would rate ThreatLocker Zero Trust Endpoint Protection Platform very highly. The biggest advice I would give to other companies considering this solution is to use the ThreatLocker Academy. Make sure you get the university package so you can really learn. There is a lot that you can do with ThreatLocker Zero Trust Endpoint Protection Platform, but there is a lot of misconfigurations you can put in there and accidentally take some people down for a while while you are trying to troubleshoot it. So definitely work with your solutions engineers and read those knowledge base articles. Overall, I would rate this review as a ten out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 4, 2026
Flag as inappropriate
PeerSpot user
Cybersecurity Engineer at a wholesaler/distributor with 51-200 employees
Real User
Top 20
Mar 4, 2026
Zero trust controls have blocked shadow IT and now protect users from unsafe apps and USBs
Pros and Cons
  • "From 1 to 10, I would rate ThreatLocker Zero Trust Endpoint Protection Platform as a 10; I've been super happy with it, advising other companies to just do it since it's a simple setup, easy to use, intuitive, and worth the money compared to potential losses."
  • "There are some programs that, when they update, they hit other folders; it would be nice to be able to see where that application is pointing when it wants to update, especially if it's updating in the AppData folder or C Windows folder since it might be the same application already whitelisted, but it changes around."

What is our primary use case?

My main use cases for it involve blocking what shouldn't be running or blocking software in our company that's not whitelisted, so people can't use what they want. We also get phishing emails, and people like to click on things and run applications, so ThreatLocker Zero Trust Endpoint Protection Platform has stopped that before in the past as well.

What is most valuable?

The feature of ThreatLocker Zero Trust Endpoint Protection Platform that I like the most is probably the deny access feature. I find the deny access feature easy to use; you can do it with Microsoft, but ThreatLocker Zero Trust Endpoint Protection Platform just makes it easy, allowing me to go right to the application, set it to deny all, and it's done without having to do anything else.

This deny feature benefits my company by stopping the shadow IT aspect of it; we know what's running on the machines, and we don't have people just installing whatever they want to install on their work machine, so we can manage the endpoints better.

By using ThreatLocker Zero Trust Endpoint Protection Platform, we have been able to eliminate or consolidate some security tools or solutions because there was some overlap, and ThreatLocker Zero Trust Endpoint Protection Platform covered it or the other application we used covered it, so we were able to save money.

I assess the impact of ThreatLocker Zero Trust Endpoint Protection Platform on controlling the behavior of legitimate applications as great since we don't have to worry about logging in to help someone update something that needs admin credentials; you can just whitelist it with ThreatLocker Zero Trust Endpoint Protection Platform, and it will do it, except for UPS WorldShip because that's a monster and a terrible application.

I do use the Elevation Control feature. My assessment of its role in facilitating just-in-time administrative access for approved applications is that it does not take our time to do it; it's set, it can go, and we give it to the end user so they can do it. There's no need to remote in and use my credentials; the credentials are used once and they're gone.

My thoughts on the Storage Control feature in enforcing policy-driven access over various storage devices involve blocking people from being able to use USB drives or thumb drives unless they were approved, especially in finance to prevent them from just plugging something in that they found in the parking lot.

My experience with it is that it's super simple to set up; it's all pretty intuitive on how to use it.

It's easy to identify which security and configuration settings need fixing using the DAC dashboard since it shows, and you can look at per machine to see what's been denied in the past, such as three days, five days, and seven days; you can decide if something should or shouldn't be running with just a two-second process to click approve or deny.

What needs improvement?

I don't know how ThreatLocker Zero Trust Endpoint Protection Platform can be improved, and I'm happy with how it is now, so I can't think of anything off the top of my head.

There are some programs that, when they update, they hit other folders; it would be nice to be able to see where that application is pointing when it wants to update, especially if it's updating in the AppData folder or C Windows folder since it might be the same application already whitelisted, but it changes around.

For how long have I used the solution?

I have been using ThreatLocker Zero Trust Endpoint Protection Platform for about a year and a half.

What do I think about the stability of the solution?

I have experienced none in terms of stability and reliability, with no downtime, crashes, or performance issues.

What do I think about the scalability of the solution?

ThreatLocker Zero Trust Endpoint Protection Platform scales with the growing needs of my company by just adding the agent on the machine, which goes into learning mode for about 30 days, and it's done.

How are customer service and support?

The customer service and technical support are great when I've needed them; I've never had to call, just get on the live chat, and someone's there within a minute or so who knows their stuff.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Prior to adopting ThreatLocker Zero Trust Endpoint Protection Platform, I used Defender a little bit, and it's kind of a bear to set up, but ThreatLocker Zero Trust Endpoint Protection Platform was super simple, especially with setting up; we had Adam, our technical rep from ThreatLocker, who walked us through it from the start, and we meet with him quarterly for usually just a five-minute check-in unless I have a question, but other than that, it's been simple, and he's been great.

What was our ROI?

ThreatLocker Zero Trust Endpoint Protection Platform has helped my company save on operational costs since we set it and don't have to spend time updating applications ourselves, giving more control to the user to run the applications they want without managing each and every one.

I don't know approximately how much was saved off the top of my head, but I can say we dropped an MSP that was supposed to be helping us and brought more of the security in-house, which was expensive, so we didn't have to pay them to monitor.

I have no idea by how much the operational costs have been saved, but I know we're not cheap and there's definitely a time savings.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup costs, and licensing is that it's super simple and easy; for what it is and what it replaces and can do, it's an easy peace of mind and an easy sell.

What other advice do I have?

We use the Ringfencing feature with ThreatLocker Zero Trust Endpoint Protection Platform on some of the PowerShell scripts just to keep it local.

From 1 to 10, I would rate ThreatLocker Zero Trust Endpoint Protection Platform as a 10; I've been super happy with it, advising other companies to just do it since it's a simple setup, easy to use, intuitive, and worth the money compared to potential losses. I give this review an overall rating of 10.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 4, 2026
Flag as inappropriate
PeerSpot user
Abhishek Saini - PeerSpot reviewer
Professional Services Engineer at Next7 IT
Real User
Top 5Leaderboard
Feb 25, 2026
Zero trust controls have strengthened endpoint protection and simplify real-time app approvals
Pros and Cons
  • "Overall, ThreatLocker Zero Trust Endpoint Protection Platform has significantly strengthened our endpoint security by enforcing zero trust principles while maintaining operational flexibility and user productivity."
  • "I took off one point because sometimes it can be a bit complicated for new engineers, such as my teammates, especially for those who don't have hands-on experience."

What is our primary use case?

As the administrator for ThreatLocker Zero Trust Endpoint Protection Platform, I manage it, deploy it for new clients, and if someone installs an application that ThreatLocker stops, I have to allow that. So we can say I am the admin of ThreatLocker in my day-to-day life.

Once, one of our big clients in the US installed a new application, but it was stopped by ThreatLocker. They emailed me that their application was not working, and then I reviewed it. I took approval from their senior managers before allowing that application in their environment, and afterward, I approved it.

I just do daily tasks where I create policies for the applications they use. There are some generic applications which they use, so I create policies for them to ensure new users will not encounter issues. Sometimes, I have to approve applications, but I need to get approval from their manager or some senior engineer before real-time approval.

Ring-Fencing technology helps me day-to-day by monitoring application behavior. If it thinks the application is malicious or has code that shouldn't run in the environment, it stops that. For example, if an SQL application throws some codes, and if the application stops working, we need to check why it stopped, and then we can approve it if it's justified.

What is most valuable?

The best features of ThreatLocker Zero Trust Endpoint Protection Platform include a deny-by-default approach, ensuring only approved applications and processes can run, which significantly reduces attack surfaces. It provides granular application control that prevents ransomware, unauthorized scripts, and unknown executables from executing. It stops ransomware before executing, which greatly improves endpoint security, along with its unique Ring-Fencing technology that restricts application behavior and prevents trusted applications from being exploited maliciously. Additionally, it provides precise control over USB devices, external storage, and network shares to help prevent data exfiltration.

The easy policy management with a centralized dashboard makes it effortless for IT teams and engineers to manage policies, approval workflows, and endpoint visibility. The real-time approval system allows administrators to approve or deny applications instantly without disrupting endpoint user productivity. Strong visibility of audit logs offers detailed logs and reporting that help with compliance, forensic analysis, and security investigations. The lightweight endpoint performance impact means it operates effectively without noticeable system downtime compared to traditional antivirus solutions, making it a highly scalable platform ideal for MSPs and organizations managing multiple clients or distributed environments.

Overall, ThreatLocker Zero Trust Endpoint Protection Platform has significantly strengthened our endpoint security by enforcing zero trust principles while maintaining operational flexibility and user productivity.

ThreatLocker Zero Trust Endpoint Protection Platform has positively impacted my organization by preventing unknown applications from running in my environment. Many clients cannot run applications without our permissions, and I also have great control over the endpoints, enhancing both productivity and security.

After implementing ThreatLocker Zero Trust Endpoint Protection Platform, we have seen a productive impact, including significantly reduced security incidents. The deny-by-default approach drastically minimizes malware and unauthorized application incidents, which reduces emergency remediation efforts and results in less endpoint downtime. Systems experience fewer disruptions caused by ransomware, malicious scripts, or unwanted software installations, leading to improved uptime for the end user.

Faster troubleshooting and detailed logging allow us to quickly identify blocked processes or unauthorized behavior, significantly reducing troubleshooting time. The real-time approval feature enables our IT team to instantly approve legitimate applications, avoiding long user wait times while maintaining security. Our IT team spends less time handling infections or cleanup tasks and more time on proactive infrastructure improvements. Once policies are properly tuned, users can work without interruption while security remains tight, enforced in the background.

Overall, ThreatLocker Zero Trust Endpoint Protection Platform has shifted our environment from reactive incident handling to proactive security management, leading to a measurable reduction in downtime and support overload.

What needs improvement?

ThreatLocker Zero Trust Endpoint Protection Platform is already an optimized platform. I have a great experience with this, so I don't think anything needs to be improved.

There might be a small thing, but I would need to assess that further.

I took off one point because sometimes it can be a bit complicated for new engineers, such as my teammates, especially for those who don't have hands-on experience. They occasionally find it difficult to check application approvals. Overall, for me, it's good.

For how long have I used the solution?

I have been using ThreatLocker Zero Trust Endpoint Protection Platform for about three years and I am continuously using it.

What do I think about the stability of the solution?

In my experience, ThreatLocker Zero Trust Endpoint Protection Platform is stable because we have not encountered any major crashes or reliability issues. The agent runs consistently in the background without causing system instability or performance degradation. Any operational challenges we experienced were mostly related to initial policy tuning or application allowing, which is expected when implementing a zero-trust model. Once policies were properly configured, the environment became very stable. Overall, I have not observed any unexpected agent crashes, minimal impact on endpoint performance, and consistent policy enforcement across devices. ThreatLocker Zero Trust Endpoint Protection Platform has proven to be a dependable and stable security solution for both daily operations and long-term endpoint protection.

What do I think about the scalability of the solution?

Regarding scalability, we have added new endpoints easily, as the policies were already made, and we just copied them to the new organization. So it's not a big deal.

How are customer service and support?

The customer support of ThreatLocker Zero Trust Endpoint Protection Platform is really quick, and they respond very promptly. I've had a good experience with them.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We have eliminated CrowdStrike because we were using it for security purposes before we started using ThreatLocker Zero Trust Endpoint Protection Platform, which has proven to work for us.

We used CrowdStrike before ThreatLocker Zero Trust Endpoint Protection Platform and switched because CrowdStrike was complicated. There was also a significant security concern last year that led us to make the switch.

How was the initial setup?

My advice for organizations looking into using ThreatLocker Zero Trust Endpoint Protection Platform would be to plan the initial deployment and policy configuration carefully, especially during the early learning phase of adopting a zero-trust model. Since ThreatLocker Zero Trust Endpoint Protection Platform works on a deny-by-default approach, which is extremely powerful for security, organizations should start with learning mode and a staged deployment to understand application behavior.

It's essential to ensure the IT team receives proper training, as policy management and application approvals may feel complex for engineers new to zero trust. Define approval workflows in advance to avoid user disruption by gradually enforcing policies instead of applying strict controls immediately. Once properly configured, ThreatLocker Zero Trust Endpoint Protection Platform becomes a highly effective and low-maintenance security solution that significantly strengthens endpoint protection while maintaining productivity.

What was our ROI?

I haven't observed specific metrics regarding return on investment, but I am aware of the general impacts.

I haven't noticed any specific benefits in terms of saving time, reducing the need for extra staff, or seeing fewer security incidents since using ThreatLocker Zero Trust Endpoint Protection Platform, so I can't provide numbers.

Which other solutions did I evaluate?

Before choosing ThreatLocker Zero Trust Endpoint Protection Platform, we did not evaluate any other options.

What other advice do I have?

The allowlisting feature in ThreatLocker Zero Trust Endpoint Protection Platform effectively manages which software, scripts, and libraries run on our devices, as it provides excellent control while enforcing security measures.

I find the allowlisting feature easy to use, and it gives me enough control over which software, scripts, and libraries can run.

I can say it is easy to identify which security and configuration settings need fixing using the DAC dashboard; I would rate it a 10 out of 10 for me.

The efficiency of the real-time threat intelligence and category controls employed by web control is a big plus, as it helps ensure that we are dynamically protected even as new threats emerge.

I would rate this review nine out of ten overall.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Feb 25, 2026
Flag as inappropriate
PeerSpot user
reviewer2807097 - PeerSpot reviewer
Cyber Security Specialist at a government with 10,001+ employees
Real User
Top 20
Mar 9, 2026
Zero trust controls have secured niche scientific apps and protect endpoints from obscure threats
Pros and Cons
  • "ThreatLocker's VDI environment, coupled with the ringfencing capabilities of policies, gives us confidence."
  • "We have had a few instances where the local database gets corrupted and starts blocking random Windows DLLs, and the support team has always been very quick at helping us identify and remediate that."

What is our primary use case?

My main use cases for ThreatLocker Zero Trust Endpoint Protection Platform are endpoint and server security. We have a lot of niche applications, many of which come from GitHub. ThreatLocker's ringfencing capabilities make us feel confident that if any of those niche, obscure applications were to be compromised, our endpoints would stay secure.

What is most valuable?

The features of ThreatLocker Zero Trust Endpoint Protection Platform that I have found most valuable include Application Control. We really appreciate the new DAST component of their Health Center and those vulnerability scans with results coming out.

The benefits of those features for my company are significant. My company has a lot of scientists using very specific applications that are not well-known, and VirusTotal has probably never inspected them before. ThreatLocker's VDI environment, coupled with the ringfencing capabilities of policies, gives us confidence.

My impression of ThreatLocker Zero Trust Endpoint Protection Platform's Allowlisting feature in terms of managing which software, scripts, and libraries run on my device is that it works great. We have lots of scripts that run on servers, and we use hash-based rules on them. If a user changes their script and does not let me know, their script will not run, which ensures I can review it. We have scientists who want random, obscure software to be installed, but it will not be installed even if the help desk agrees to assist with the installation until I approve it. This is a great all-around product.

I assess its impact on controlling the behavior of approved applications as very positive. It works really well, and I have nothing to add to that.

What needs improvement?

If I had one feature I would like added to ThreatLocker Zero Trust Endpoint Protection Platform, it would be the ability to clone a policy to a new machine. Right now, I have to manually clone it. If it is just a basic policy, its not a big deal. However, if there is one that is very specific with ringfencing rules and user-based rules, I do not have a way to just copy that to a new machine. I would either have to manually add all those same rules. That would be the one feature I think is needed.

For how long have I used the solution?

I have been using ThreatLocker Zero Trust Endpoint Protection Platform for one year.

What do I think about the stability of the solution?

My evaluation of the stability and reliability of ThreatLocker Zero Trust Endpoint Protection Platform is that the portal sometimes seems to crash. I can get logged in, but I cannot load anything and it will kick me out in about five minutes. There is no apparent pattern to it, and there is not a particular time when this happens. However, occasionally there are days where the portal has issues.

What do I think about the scalability of the solution?

I would assess how well ThreatLocker Zero Trust Endpoint Protection Platform scales with the growing needs of my company positively. We recently went through a replacement project of approximately 600 computers, and it went very smoothly. I did not hear any complaints about it.

How are customer service and support?

I would evaluate the customer service and technical support as great, with no complaints. They are all very responsive.

Which solution did I use previously and why did I switch?

I have not dropped any products since obtaining Threatlocker. Threatlocker is the most recent addition. I do not wish to disclose the other products I am using.

What was our ROI?

I would guess that ThreatLocker Zero Trust Endpoint Protection Platform has helped my company save on operational costs or expenses, but I would not be able to give specific numbers.

Which other solutions did I evaluate?

There was no other consideration in the evaluation process for another solution.

What other advice do I have?

By using ThreatLocker Zero Trust Endpoint Protection Platform, my company has an option now to eliminate or consolidate any security tools or solutions. We could get rid of a couple of things, but we have not gone down that path.

The reason we have not gone down that path is because we are in contracts with quite a few things right now.

Regarding the Network Control feature, we are still in audit mode. We have it purchased but have not enabled it.

For Elevation Control, we use that for a few things. Our developers do web app development, and if they need to debug, it opens in IIS, which is an admin-level feature. Elevation Control lets us automatically elevate Visual Studio, which is really useful there. We were able to get rid of admin accounts for that by using Elevation Control.

Concerning the Storage Control feature, we are still starting to use it.

I am using the DAST dashboard and we are reviewing it. We have enabled some policies based off of its recommendations.

Identifying which security and configuration settings need fixing using the DAST dashboard is pretty good at outlining what needs to happen. There have been some quirks. I understand it is still in its infancy. There are some quirks with its actual reporting. There was a period where it was saying we were 100% secured, and then a week later it showed we had a bunch of vulnerabilities. We are not fully relying on it, but as far as presenting vulnerabilities it has found and where to go to change things, it is pretty easy to understand.

I would rate this review overall as a 10.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 9, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free ThreatLocker Zero Trust Platform Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free ThreatLocker Zero Trust Platform Report and get advice and tips from experienced pros sharing their opinions.