


Find out in this report how the two AI-Powered Cybersecurity Platforms solutions compare in terms of features, pricing, service and support, easy of deployment, and ROI.
They appreciate the rich telemetry data from the solution, as it provides in-depth threat identification.
Cortex XDR by Palo Alto Networks helps to reduce my total cost of ownership significantly.
In Cortex XDR by Palo Alto Networks, most of the remediation is automated and the accuracy is quite good.
Threat hunting and incident summarization workflows became significantly faster during large-scale phishing or ransomware investigations, helping the team manage more incidents without increasing SOC headcount proportionally.
The summary capability saves me fifty percent of the processing time on emails.
The biggest return on investment that I've seen when using Microsoft Security Copilot is the ability to scale.
We returned our investment within the first year.
After adopting Sophos Central, we can easily integrate with ServiceNow, which means fewer employees, and that translates to money saved.
We see a return on investment with Sophos Central because it saves manpower and time.
The technical support from Palo Alto deserves a mark of ten because they reach out within an hour whenever assistance is needed.
There is no back and forth, and they know what we are asking for and come up with the best resolution for a solution.
If any of these services are missed, it becomes a problem in terms of support tickets, follow-up, or special configuration that needs to be done in the system.
On a scale from one to ten, I would rate customer service and technical support for Microsoft Security Copilot as a nine.
They tend to be quite rigid with documentation and often redirect me to look at documents instead of directly assisting me, which can cause delays.
Based on our customers' experiences, I would rate their support a seven out of ten.
In my recent experience with a support ticket, the engineer was not very effective and took longer than I expected.
If I call support at any time, they will assign a new engineer according to SLA immediately or within one to three hours.
I received instant support and remote assistance, and the Sophos team is very cooperative and helped me a lot.
You can onboard 10,000 endpoints in just hours, which demonstrates the excellent scalability of this product.
Activating the newly purchased licenses is instantaneous, allowing installations without adjustments since it's cloud-based.
Cortex XDR by Palo Alto Networks can be expanded anytime by purchasing another license without any issues related to scalability.
We don't have any concerns whatsoever with scalability.
Scalability is the name of the game, involving understanding exactly where focus and money need to be placed and ensuring that where focus and money are placed can scale with the size, speed, and capabilities of organizations as they adopt AI in the workplace.
I think Microsoft Security Copilot scales well with the growing needs of our organization.
Sophos Central's scalability is excellent because I can add any licenses at any time without needing to create a new console.
I believe Sophos Central's scalability is good compared to other EDR solutions that we have.
Cortex remains fast and responsive, even with increasing data and alerts.
The thresholds we've seen on our firewall boxes at some instances reached 80% to 85%, but even at that level of utilization, we don't observe any latency or any issues reported with respect to accessing the application.
Cortex XDR is stable, offering high quality and reliable performance.
When talking about confidentiality, integrity, and availability, availability is the critical concern.
There are circumstances where we expected certain things to surface through our prompting with Microsoft Security Copilot, but they did not come up.
They have not had any incidents so far despite having everything on Microsoft Security Copilot.
Improving reporting and dashboard customization, along with the addition of real-time and exportable reports, would help SOC teams greatly.
The inclusion of this feature would allow the application of DLP policies alongside antivirus policies via a single agent and console, making it more competitive as other OEMs often offer DLP solutions as part of their antivirus products.
If the per GB data could be provided at a certain level free of cost or at the same cost which the customer is taking for the entire bundle, that would be better.
Microsoft needs to give at least some kind of à la carte option between E3 and E5, maybe an E4, to cherry-pick from E5.
If a way could be found to make it more cost-effective and streamline the licensing mechanism, they have the technology to succeed in the marketplace.
Even though Microsoft is a major technology company with insurance coverage, customers worry about potential data leaks, especially in sensitive industries such as banking and semiconductor manufacturing.
I would add that the logs in Sophos Central should be more detailed. Sometimes, when we're checking the logs, they simply state that a file is blocked, but we can't find out why that is the case.
I saw how I can query history from my workstation to do threat intelligence.
I think Sophos Central could be improved by offering an on-premises option because some users prefer to keep their data locally rather than in the cloud.
The pricing on SentinelOne is far more reasonable and cheaper than Cortex XDR by Palo Alto Networks.
I would say it is definitely not a cheap product, considering how mature it is and how scalable all Palo Alto products are together.
Cortex XDR is perceived as expensive by some customers, yet offers dynamic pricing.
Most of my customers are already within Microsoft stack, and the pricing is mostly well accepted.
We wanted something under one umbrella, which is something Microsoft is able to give.
Its pricing scares our customers the most.
My thoughts on the pricing or licensing with Sophos Central are that it is very good.
It incorporates AI for normal behavior detection, distinguishing unusual operations.
The product provides automation responses in case of a threat attack, severity assessments, centralized manageability, and comprehensive compliance features, resulting in reduced costs.
It includes machine learning to easily analyze data and detect complex threats across endpoints, networks, or clouds.
The integration of Microsoft Security Copilot with other Microsoft solutions has had a positive impact on my company's security posture because it's integrated into the operating system.
One of the major use cases that we have seen is the reduced time spent on integrating and understanding Purview's output versus Sentinel's output, because the two speak to each other through Microsoft Security Copilot.
Microsoft Security Copilot has helped us and our clients reduce the mean time to resolution significantly.
If it detects malware, it blocks it and then it sends it through to Sophos Central, which then sends me an email notification that one of the workstations picked up an infection or encountered an issue.
Sophos Central has positively impacted my organization because it allows us to utilize Sophos products in a single pane of glass, and with its synchronized security, it helps to protect our environment more effectively by isolating infected devices from the internet.
Sophos Central is very user-friendly and easy to manage.
| Product | Mindshare (%) |
|---|---|
| Cortex XDR by Palo Alto Networks | 11.1% |
| Microsoft Security Copilot | 0.1% |
| Sophos Central | 1.9% |
| Other | 86.9% |



| Company Size | Count |
|---|---|
| Small Business | 46 |
| Midsize Enterprise | 20 |
| Large Enterprise | 49 |
| Company Size | Count |
|---|---|
| Small Business | 6 |
| Midsize Enterprise | 6 |
| Large Enterprise | 12 |
| Company Size | Count |
|---|---|
| Small Business | 33 |
| Midsize Enterprise | 9 |
| Large Enterprise | 8 |
Cortex XDR by Palo Alto Networks provides advanced threat detection with AI-driven endpoint protection and seamless integration, ensuring multi-layered security and automatic threat response.
Cortex XDR is designed to safeguard endpoints against malware and suspicious activities. It offers advanced threat detection and response capabilities using behavioral analysis, AI, and machine learning. It seamlessly integrates with security infrastructures, providing endpoint security, firewall integration, and enhanced visibility in both cloud-based and on-premises environments.
What are the key features of Cortex XDR?Organizations in diverse sectors deploy Cortex XDR to protect against malware, leveraging its advanced threat detection capabilities. Its integration with existing security infrastructures appeals to those seeking comprehensive protection in both cloud and on-premises environments, providing enhanced visibility and threat intelligence.
Microsoft Security Copilot offers innovative AI-driven security features tailored for efficient data management and protection, particularly in education and healthcare, ensuring streamlined operations and enhanced data security.
Microsoft Security Copilot enhances organizational security through its advanced features, including data sensitivity labeling and AI-driven insights, crucial for educational and healthcare sectors. Its auditing capabilities allow for efficient monitoring, while self-service analytics support active decision-making processes. With seamless integration with Microsoft platforms, it provides a synchronized ecosystem for effective data management. Improvements aim at extending capabilities across multiple systems and enhancing natural language processing to minimize prompt dependency.
What are the key features of Microsoft Security Copilot?
What benefits should organizations expect?
In the educational sector, Microsoft Security Copilot secures teacher and student data, manages incidents, and controls information access. Healthcare organizations utilize it to protect patient data, manage security incidents, and refine communication across hospitals and pharmacies. The platform's capabilities expand continually, aiding in tasks like summarizing discussions and rephrasing emails, while users explore further functions for increasing industry's operational efficiency.
Sophos Central provides centralized management for endpoint security, offering a cloud-based solution with intuitive controls and real-time threat detection to safeguard networks efficiently.
Sophos Central is a cloud-based management platform designed for comprehensive endpoint security, integrating valuable features like advanced AI for malware detection and synchronized security to streamline operations by linking endpoints and firewalls. With a user-friendly interface, Sophos Central enhances threat management efficiency and offers clear visibility through its dynamic dashboard. Organizations benefit from its seamless integration with other Sophos tools, ensuring consistent and automated updates for endpoint security. Despite the robust functionality, some areas for improvement include system speed with multiple devices and limited third-party integration.
What are the most important features?Sophos Central is implemented widely across industries, ensuring robust endpoint security for antivirus and ransomware protection. Companies leverage its centralized control for mobile and network device security, implementing secure VPNs and multi-factor authentication. The platform supports comprehensive monitoring, enforcing policies and facilitating compliance. Organizations rely on it for managing firewalls, reporting, and streamlining administration across geographic locations, enhancing both email and web security.
We monitor all AI-Powered Cybersecurity Platforms reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.