My company uses Active Directory to manage users and track whether they have installed any third-party applications or any malicious applications that need to be blocked before allowing for the installation of the application. My company informs users whether the tools they use have any malicious activities or products.
Project Engineer at CDAC
Helpful to detect and identify worms and malware
Pros and Cons
- "It is a stable solution. Stability-wise, I rate the solution a ten out of ten."
- "The performance offered by the product needs improvement."
What is our primary use case?
What is most valuable?
In terms of protection, Intercept X Endpoint is very good as it detects and identifies issues at a very early stage, so it is up to date. In terms of usability, it consumes a lot of RAM space, which causes work machines in our company's environment to be very slow. In my company, we have to wait and allow for the tool to complete the scanning of all the files and other aspects, or else the machines get slow.
What needs improvement?
The machines get too heavy because of the background applications that run when the tool is used. The performance offered by the product needs improvement.
For how long have I used the solution?
I have been using Intercept X Endpoint for more than two years.
Buyer's Guide
Intercept X Endpoint
April 2025

Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
849,686 professionals have used our research since 2012.
What do I think about the stability of the solution?
It is a stable solution. Stability-wise, I rate the solution a ten out of ten.
What do I think about the scalability of the solution?
In terms of scalability, you have to pay for every user that uses the product. If you pay more, you can get more users to use the product.
Around 500 people in my company use the product.
The product is extensively used in my company, and we plan to increase the number of uses of the solution. As the number of users of the solution in our company increases, we have to implement the product in every employee machine in our organization. My company uses the product on Windows and Linux.
Which solution did I use previously and why did I switch?
I have no idea about the other products in the market since I directly started to use Intercept X Endpoint.
How was the initial setup?
The solution is deployed on an on-premises model.
What about the implementation team?
A representative or set of executives from Sophos' team is involved in the product's installation process and guides the use cases of the application.
What was our ROI?
The return on investment from the use of the solution is very good since it helps my company to keep our network secure and protected.
What's my experience with pricing, setup cost, and licensing?
On a per-user basis, my company has to pay a certain amount of money.
What other advice do I have?
The solution improves our company's endpoint protection strategy as it helps to protect our network from getting affected by any worm or malware.
It is a very good tool to use for stopping threats. The tool is also useful to manage the activities of users in our company.
The tool is very good to use and is always up to date. The product can identify malware and worms at an early stage. Additionally, the tool also helps identify crypto miners.
Our company's system performance was getting slow because of the product.
I rate the overall tool an eight out of ten.
Which deployment model are you using for this solution?
On-premises
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Network & Infrastructure Manager at Xanadu Realty
Stable solution with a helpful technical support team
Pros and Cons
- "It is a very scalable solution."
- "The solution's pricing could be better."
What is our primary use case?
We use the solution for antivirus threat detection and response.
What is most valuable?
The solution's most valuable feature is threat protection.
What needs improvement?
The solution's pricing could be better.
For how long have I used the solution?
We have been using the solution for four years.
What do I think about the stability of the solution?
It is a stable solution. I rate its stability as a ten.
What do I think about the scalability of the solution?
We have 1400 solution users in our organization. It is very scalable, and I rate its scalability a ten.
How are customer service and support?
The solution's customer service is helpful.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used ESET before. Later, we switched to Sophos for better features.
How was the initial setup?
The solution gets maintained automatically.
What other advice do I have?
I recommend the solution to others and rate it as a nine.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Buyer's Guide
Intercept X Endpoint
April 2025

Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: April 2025.
849,686 professionals have used our research since 2012.
System Integrator IT Manager at Tecnimex S.r.l.
Offers centralized controller providing access to every aspect of the deployment and works very well against ransomware
Pros and Cons
- "I appreciate the ability to use the latest endpoint protection features in case of an infection or cyber threat. This is especially true when using the product with a Sophos firewall solution, like the XG series. They collaborate effectively in the event of a cyber threat."
- "The customer service and support could be improved in regards to response time. It could be faster."
What is our primary use case?
We're a Sophos partner and generally use Intercept X software.
How has it helped my organization?
In my experience, it is a good product. Sophos family has many offerings, and the selling model is interesting for us as an MSP or Flex partner.
For end customers, you have a centralized controller providing access to every aspect of the deployment. While the platform isn't the easiest to use, if you properly set up the policies, it's very efficient. Sometimes, the platform itself can prevent security risks due to the product's capabilities.
It works very well against ransomware and similar threats.
What is most valuable?
I appreciate the ability to use the latest endpoint protection features in case of an infection or cyber threat. This is especially true when using the product with a Sophos firewall solution, like the XG series. They collaborate effectively in the event of a cyber threat.
Its ability to continuously query the data lake is beneficial. So, the deep learning technology in Intercept X Endpoint enhances threat detection capability.
However, the automated threat response for incident response times can be better if the user subscribes to Sophos service called EDR... I think it's called Managed Threat Response (MTR). There is a higher layer of support available. For big customers, this could a good option.
What needs improvement?
The price could always be better.
For how long have I used the solution?
I have experience with this solution. I have been using it for a lot of years.
What do I think about the stability of the solution?
It is a stable product.
What do I think about the scalability of the solution?
It is a scalable product. It covers laptops and essentially any Windows platform – servers, clients, and even home users. So, it protects a huge number of potential platforms.
There are around 300 endpoints.
How are customer service and support?
The customer service and support could be improved in regards to response time. It could be faster.
How was the initial setup?
The complexity of the setup depends on the environment.
For single deployments, it's quite easy to set up. You can organize customers using separate payments and policies for each through the centralized console. Integrating the product with other Sophos offerings makes it very efficient.
Customers mostly use the cloud solution. On-premises is probably less common among Sophos users.
It's difficult to have major issues with deployment. Problems usually arise due to the age of the platform. If you have older systems, support can be more expensive. Sophos might support older platforms for a while, but you'll likely have to pay additional subscriptions.
What was our ROI?
We have seen an ROI. We consider it a strategic product for our organization.
What's my experience with pricing, setup cost, and licensing?
We operate as an MSP, so we pay yearly. However, if the end customer is part of the Sophos Flex program, they have more flexibility and can adopt a monthly payment process.
What other advice do I have?
I suggest investing in training. It's a good product, but unlocking its full potential requires some training time.
Overall, I would rate the solution a nine out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
IT Manager at Redeemer Baptist School
A cloud-managed solution that has the ability to provide filtering for end users
Pros and Cons
- "Since it's cloud-managed, the solution is easy to administer, especially if the person using it is in a different geophysical location."
- "The solution is expensive, and it could be made cheaper."
What is most valuable?
Since it's cloud-managed, the solution is easy to administer, especially if the person using it is in a different geophysical location. I can access the cloud portal and allow or disallow it. I like the fact that the solution also has the ability to provide filtering for an end user.
What needs improvement?
The solution is expensive, and it could be made cheaper.
For how long have I used the solution?
I have been using Intercept X Endpoint for three years.
What do I think about the stability of the solution?
I rate Intercept X Endpoint an eight out of ten for stability.
What do I think about the scalability of the solution?
I rate Intercept X Endpoint an eight out of ten for scalability.
How was the initial setup?
The solution’s initial setup is easy.
I rate Intercept X Endpoint ten out of ten for the ease of its initial setup.
What about the implementation team?
The solution's deployment time depends on whether you're setting up a room full of computers or you're setting up one-off computers. It usually doesn't take very long. As part of installing the solution for a room full of computers, you might get someone to create the installed media, and then you'd enter each computer and install it.
Around one to five people are needed to install the solution.
What's my experience with pricing, setup cost, and licensing?
Intercept X Endpoint is an expensive solution.
On a scale from one to ten, where one is cheap and ten is expensive, I rate the solution's pricing ten out of ten.
What other advice do I have?
I am working with the latest version of Intercept X Endpoint. Intercept X Endpoint has to be installed on end-user devices, but it is managed in the cloud.
Overall, I rate Intercept X Endpoint an eight out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior CyberSecurity Architect and Mentor at BlueTeamAssess LLC
It can get ahead of the ransomware attack and encrypt the data on clients in the path of the infection
Pros and Cons
- "The most valuable feature of Intercept X its ability to stay ahead of the infection. By the time the ransomware spreads to the next machine in line, the data has already been encrypted on that workstation. It didn't matter what the ransomware did because could go in and get it back."
- "They should keep doing what they're doing. Both of them have entered the EDR/MDR space, and they're keeping up with their competitors. I have a hard time understanding why their capabilities aren't garnering more attention."
What is our primary use case?
When Intercept X came out, the primary use case was stopping ransomware. It was one of the first products to claim that capability. When I was evaluating them back then, it was the only one I considered effective at analyzing and identifying where the infection started.
The synchronized security also helped because the firewall could isolate workstations that had the infection or were in the path of infection.
What is most valuable?
The most valuable feature of Intercept X its ability to stay ahead of the infection. By the time the ransomware spreads to the next machine in line, the data has already been encrypted on that workstation. It didn't matter what the ransomware did because could go in and get it back.
Sophos made such good headway with it because it wasn't traditional endpoint protection. It has a lot of additional capabilities, including web content filtering. It also has the ability to understand the traffic it was seeing at the endpoint,
It's sitting on the endpoint, so you don't have to worry about encryption messing up the intelligence that it could get out of the traffic. It was able to pinpoint where the infection was able to get ahead of Intercept X. It was called Intercept X because it can get ahead of the ransomware attack and encrypt the data on clients in the path of the infection.
What needs improvement?
It's hard to say what could be improved because we're in the middle of an endpoint protection arms race, and there are constant improvements on all fronts in Fortinet, Sophos, and products.
They should keep doing what they're doing. Both of them have entered the EDR/MDR space, and they're keeping up with their competitors. I have a hard time understanding why their capabilities aren't garnering more attention.
For how long have I used the solution?
I have been using Intercept X since it came out. It hasn't been out that long. Sophos has always had an endpoint client, but Intercept X added new technology. The whole idea of being able to drill down to do a root cause analysis was a novel approach to the endpoint game.
What do I think about the stability of the solution?
Intercept X is highly stable
What do I think about the scalability of the solution?
Sophos has the flexibility to scale from one user to a data center, but I've primarily used Sophos for small to medium-sized businesses.
How are customer service and support?
I was impressed the last time I called Sophos support. They have a "follow the sun" philosophy with coverage from tech support centers from around the world. Sophos began as a British company, and Fortinet is a Canadian company.
Which solution did I use previously and why did I switch?
Sophos and Fortinet have a firewall solution that can work in small business or home office situations, where you might have only one or two people protected by the techn. Still, yout you can look at it through a single pane of glass and see all of the different work sites you're protecting.
Sophos goes one step further with what it calls its RED product, which basically is a hardware firewall that travels with somebody. Say you have an executive in your company and you want to zero in to protect his or her workstation from infection and have control over it to manage its defenses. RED is a great product to do that. Fortinet and Sophos both have strong management capabilities for remote offices and offer centralized management through a cloud application.
How was the initial setup?
The basic setup is decent by itself. I have not had to do a lot of tweaking with either one of these products.
What other advice do I have?
I rate Sophos Intercept X nine out of 10. Its reporting, alterts, and configuration capabilities make it a formidable product. It's a great product that works as advertised. I haven't seen any serious conflicts between it and other products, whereas I wouldn't put some endpoint protection products on the same endpoint.
You have to do some work there, but generally speaking, there's always been a case where I've been able to have more than one product. It's probably the best of all the products that I work with because I've had Malwarebytes installed together with Sophos and FortiClient without undue pain. There are some others that I won't mention without that same track record.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
IT Coordinator at a pharma/biotech company with 51-200 employees
Services perform well, minimal resources, and synchronizes well with other solution
Pros and Cons
- "The solution is overall quite good, the services are performing well. It is very good for those who are using standard PC configurations. It does not block their system up by taking up a lot of resources."
- "This solution is not in the high ratings on many of the top review sites. This solution has to be near the top for me to continue using it."
What is our primary use case?
We are not only using Sophos Endpoint with this solution, we are also using Sophos Email Security and firewall. It is a completely synchronized security package.
What is most valuable?
The solution is overall quite good, the services are performing well. It is very good for those who are using standard PC configurations. It does not block their system up by taking up a lot of resources.
What needs improvement?
This solution is not in the high ratings on many of the top review sites. This solution has to be near the top for me to continue using it. I do not think a lot of companies know about this solution, it could be a lack of marketing that is the reason why it is not at the top.
For how long have I used the solution?
I have been using the solution for two years.
What do I think about the scalability of the solution?
The solution is very good for small-sized businesses.
How are customer service and technical support?
The technical support sometimes is a bit delayed, but sometimes they are responding very fast. Overall they are good but could improve on the times they are having delays.
Which solution did I use previously and why did I switch?
Previously we used McAfee for our endpoint protection for our company. It was very problematic, it was using up a lot of resources and delaying the work of users. Users were not able to do multitasking in the system. It is blocking all access to our server at the time of scanning. We decided to move to some other good antivirus. After analyzing the market, we found Sophos. Sophos is best for the standard configuration PC.
Which other solutions did I evaluate?
Due to some circumstances, we are going to switch from this solution to Symantec. Additionally, we have evaluated Kaspersky before choosing Symantec as the replacement for this solution. Kaspersky has had a very good rating amongst review sites along with Symantec.
What other advice do I have?
I rate Sophos Intercept X a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Senior Security Consultant at First Technology
Comes with an option to switch off an endpoint, and does what it's supposed to do and better than anyone else
Pros and Cons
- "I find the security heartbeat feature with synchronized security very useful. It's a very nice feature that allows you to basically switch off an endpoint. When an endpoint has got a virus or something like that, or it's infected or compromised, you can isolate it from the network, but only if you've got an XG Firewall as well. It also provides ease of use. It is the only antivirus that can recognize 25 out of the 36 ransomware and virus techniques that have been often used in terms of the behavior base using heuristics. It's beautiful, utterly amazing. No other antivirus can do that."
- "The pricing could be a bit lower to match the normal retail pricing."
What is most valuable?
I find the security heartbeat feature with synchronized security very useful. It's a very nice feature that allows you to basically switch off an endpoint. When an endpoint has got a virus or something like that, or it's infected or compromised, you can isolate it from the network, but only if you've got an XG Firewall as well.
It also provides ease of use. It is the only antivirus that can recognize 25 out of the 36 ransomware and virus techniques that have been often used in terms of the behavior base using heuristics. It's beautiful, utterly amazing. No other antivirus can do that.
What needs improvement?
The pricing could be a bit lower to match the normal retail pricing.
For how long have I used the solution?
I have been using this solution for the last four months. Currently, I am using the latest version.
What do I think about the scalability of the solution?
It's really scalable. We easily did 5,000 installations in six hours. It's good at scalability.
Some of our SMB clients have 20 users, and some have around 200 to 300 users. A big enterprise client has around 5,000 users.
How was the initial setup?
I don't set these products up, but they look pretty straightforward and simple to set up. The deployment of 5,000 users happened in around six hours. The deployment was obviously automated a little bit.
What's my experience with pricing, setup cost, and licensing?
When you start going to the EDR technologies and the MTR, it is a little bit expensive. It's a very good technology, and obviously, you're going to pay for it, but the pricing could do a little bit of work.
What other advice do I have?
I would definitely recommend Sophos Intercept X. It's the number one product in my go-to-market strategy.
I haven't used it so much, but from what I've seen and played around with, it's a brilliant product. It has already got everything. It does what it's supposed to do and does it better than anyone else out there. If you look at Gartner Quadrants, they are at number three in terms of leaders. The Microsoft Defender ATP is number one.
I would rate Sophos Intercept X a nine out of ten. It is a beautiful product, and I love it.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Useful web filtering, effective URL sanity checks, and excellent support
Pros and Cons
- "The most valuable feature of Sophos Intercept X is a web filtering and URL sanity checks. Overall the solution is well balanced with all its features."
- "The majority of our systems are MacBooks and their solution release cycle is slow to endorsing or support the MacBook's latest OS or hardware platform. For example, when Sophos macOS Big Sur version 11 was released, it took them a while to support this version of OS. A similar situation occurred when the MacBook M1 hardware CPU was released. They have not fully supported the native M1 CPU to this day. They need to speed up the solutions release cycle."
What is our primary use case?
We use Sophos Intercept X to protect the endpoint devices in our organization, such as PCs and MacBooks.
How has it helped my organization?
Sophos Intercept X is a full package. It's more than only an antivirus solution to find the malicious code. We also use it to filter malicious websites and detect applications that have been outlined in our corporate policy.
What is most valuable?
The most valuable feature of Sophos Intercept X is a web filtering and URL sanity checks. Overall the solution is well balanced with all its features.
What needs improvement?
The majority of our systems are MacBooks and their solution release cycle is slow to endorsing or support the MacBook's latest OS or hardware platform. For example, when Sophos macOS Big Sur version 11 was released, it took them a while to support this version of OS. A similar situation occurred when the MacBook M1 hardware CPU was released. They have not fully supported the native M1 CPU to this day. They need to speed up the solutions release cycle.
The majority of our systems are Apple-based, this issue is more noticeable on the Apple platforms.
For how long have I used the solution?
I have been using Sophos Intercept X for approximately two years.
What do I think about the stability of the solution?
The stability or performance of Sophos Intercept X is good. However, sometimes users have needed to have their configuration fine-tuned to allow better performance.
What do I think about the scalability of the solution?
We have approximately 50 users using this solution.
We use Sophos Intercept X extensively and we use everything the solutions offer.
How are customer service and support?
The support I have experienced from Sophos Intercept X was great.
I would rate the support from Sophos Intercept X a five out of five.
Which solution did I use previously and why did I switch?
I have used other solutions other than Sophos Intercept X in other organizations but it has been over two years ago.
How was the initial setup?
I have been using Sophos Intercept X for over two years, in the beginning, the initial setup was straightforward but because they do not fully support the Apple platform, or they're pretty slow at supporting the Apple platform, the latest version supporting Apple is a little bit cumbersome to use. You need to walk the user through the process with some specific instructions or help the user directly. It's not as easy as it used to be.
I would rate the implementation process of Sophos Intercept X a four out of five.
What about the implementation team?
We did the implementation of Sophos Intercept X in-house.
I do the maintenance of the solution. We are a smaller company and I am sufficient for the maintenance of the solution.
What's my experience with pricing, setup cost, and licensing?
I have found the price of Sophos Intercept X to be reasonable.
What other advice do I have?
I would advise others that they have to look at their environment to determine if this solution would be best suited. Sophos Intercept X for a small business that has a mix of PCs, MacBooks, and has the need for multiple security controls, this tool fits us well. For different environments, the organization might need other or additional tools. For example, if they may need threat protection. There are different vendors that may have an edge in certain areas than Sophos Intercept X has. For us, we need a balanced, multi-pronged approach for securing in our environment, Sophos Intercept X works well.
I rate Sophos Intercept X an eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: April 2025
Product Categories
Endpoint Protection Platform (EPP) Endpoint Detection and Response (EDR) ZTNA Managed Detection and Response (MDR) Extended Detection and Response (XDR) Ransomware ProtectionPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Complete
Cortex XDR by Palo Alto Networks
Fortinet FortiClient
Cisco Secure Endpoint
Symantec Endpoint Security
HP Wolf Security
Trend Vision One Endpoint Security
Kaspersky Endpoint Security for Business
Trellix Endpoint Security
ESET Endpoint Protection Platform
Check Point Harmony Endpoint
Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Sophos Intercept X or Symantec End-User Endpoint Security - which is the better solution?
- Can Sophos Intercept X and Carbon Black be used side by side on endpoints?
- Which endpoint solution is more effective in terms of protection and remote administration: Sophos Intercept X or Kaspersky Endpoint Security?
- How does Crodwstrike Falcon compare with Sophos Intercept X?
- Sophos Intercept X: renewal cost for a security system integrator
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?