SentinelOne is for users wanting an enhanced level of endpoint security.
Technical Director at a tech services company with 11-50 employees
Scalable solution with a straightforward setup that provides an enhanced level of endpoint security, but has issues with stability
Pros and Cons
- "Scalable endpoint protection solution that takes seconds to set up per device. It has a rollback feature and offers good technical support."
- "The stability of SentinelOne should be improved."
What is our primary use case?
What is most valuable?
What I like about SentinelOne is that it sparks your curiosity. I also like its rollback feature.
What needs improvement?
The stability of SentinelOne should be improved.
For how long have I used the solution?
I've been using SentinelOne for three years.
Buyer's Guide
SentinelOne Singularity Complete
December 2025
Learn what your peers think about SentinelOne Singularity Complete. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,477 professionals have used our research since 2012.
What do I think about the stability of the solution?
We're using SentinelOne through one of our partners, and we have had some stability issues with it due to Windows 10 features updates. It should be more stable.
What do I think about the scalability of the solution?
SentinelOne is a scalable solution.
How are customer service and support?
Technical support for SentinelOne is fine.
How was the initial setup?
The initial setup for SentinelOne is straightforward. Setting up the solution doesn't take long, e.g. on a per-device basis, it would take just 30 seconds.
What about the implementation team?
We did the implementation of this solution ourselves.
What's my experience with pricing, setup cost, and licensing?
Our customers pay for monthly for the license of SentinelOne.
What other advice do I have?
We're an MSP, so we deploy SentinelOne for customers, e.g. 70 to 80 endpoints.
We've had some stability issues with the solution, and that's definitely a concern. I'm still pushing forward with SentinelOne, because it's the only kind of option we have in this space.
In terms of recommending SentinelOne, I'd give it a six out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
IT Manager at a tech services company with 11-50 employees
Protects our network end users from malware and eliminates ransom ware with timely alerts and automatic resolution
Pros and Cons
- "Prevents ransomware getting through."
- "Communication and documentation could be improved."
What is our primary use case?
My primary use case for this solution to protect my clients and sites that I support from malware and ransom ware. It is installed on the end point clients and servers as a client and then it clean and protects after a reboot. As a managed service provider we found it instrumental at preventing viruses and especially preventing ransom ware. We went from 30% ransom ware infections to zero. The software stops the infection before it executes.
How has it helped my organization?
It has saved hundreds of hours fixing destroy and encrypted computers. In the old days even if you restored the files Windows was still damaged. This stops the software from executing.
What is most valuable?
The valuable feature of this solution is the ability for it to stop a virus or ransom ware. It uses a SOC for active monitoring and AI software that watches where you go and what gets executed. If it sees danger I get alerted and the machine is frozen. If the SOC believes it to be a virus the machines network card is frozen or the machine is automatically returned to the state before the file was executed and the file is erased. If it's safe the machine is auto unfrozen. I can go in look at the logs, verify if it's a false positive and unfreeze the machine. If I believe it is a virus I can return the machine to before the file got executed. Erasing any damage. If I believe it's a false positive I can mark it benign and re execute the file. So far it's stopped four ransomware cases from getting through, so it's doing a good job.
What needs improvement?
I think communication and documentation could be improved in the solution. When you get a virus alert, there's not a lot of upfront training to let you know how to resolve a situation when it occurs. The first couple of times you're flailing a little bit until you get it sorted. I would probably also suggest that the interface could use a little bit of help. It's a little hunt and peck.
For additional features, I'd like to see the ability to control it on a cell phone. It would be great if I could have it in the palm of my hand so that if I get a false positive, I can just look at the dashboard on my phone.
For how long have I used the solution?
I've been using this solution for seven months.
What do I think about the stability of the solution?
The solution seems super stable, although you do get some false positives, especially when it encounters a new piece of software. But the SOC is able to quickly whitelist and adopt to the new software fairly quickly.
What do I think about the scalability of the solution?
The solution is scalable. I'm able to put it both in a script and I can see it being able to be deployed in a large environment as well as a small one. I have 285 end points and the roles are anywhere from financial traders to insurance agents. All employees have access to the solution, it's actually turned into my main route for antivirus end protection and the product doesn't require any maintenance except for when it finds a virus.
How are customer service and technical support?
I've used technical support a few times and it's very good. They're very responsive and they alert you very quickly when there's an issue. They lean heavier on protection, which can sometimes be a problem. A lot of times, by the time I'm logged in to look at it, they've already figured out that it's a false positive and they mark it and whitelist it and put the machine back online. All that can take less than a couple of seconds.
Which solution did I use previously and why did I switch?
I've previously used several antivirus programs and then I got to the point where I wanted to use an artificial intelligence program. Originally I used CrowdStrike, which I also liked, but the main reason I switched to SentinelOne is because it's incorporated as part of my MSP solution suite.
How was the initial setup?
The initial setup is very straightforward. When you implement, it goes through and does the initial scan and it makes the configuration changes that it needs. I haven't had a problem with any deployment at all and it's a very quick process.
What about the implementation team?
It's deployed in house
What's my experience with pricing, setup cost, and licensing?
The cost of the solution varies and depends on your relationship with the supplier. My cost is USD $6 per end point. I don't have additional costs on top of that.
Which other solutions did I evaluate?
I evaluated, Norton 360, Windows antivirus, Webroot, Crowdstrike, and ESET
What other advice do I have?
With solutions like these it's important to keep in mind that any automated system can give false positives, especially when they first encounter your software. Be patient, work with the SOC and the technical support team. If your work is implementation, then do whole sites at one time. It's best to do it in sections, let it sit for a couple of weeks and then do the rest.
I would rate this solution a ten out of 10.
Which deployment model are you using for this solution?
On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
SentinelOne Singularity Complete
December 2025
Learn what your peers think about SentinelOne Singularity Complete. Get advice and tips from experienced pros sharing their opinions. Updated: December 2025.
879,477 professionals have used our research since 2012.
VP at a tech services company with 11-50 employees
Easy to set up and transparently offers effective protection
Pros and Cons
- "The most valuable feature is that it just unintrusively works in the background to carry out the protection."
- "Periodically we have an application that does not work correctly when SentinelOne is installed, yet performs as expected when SentinelOne is removed."
What is our primary use case?
We have SentinelOne installed on all of our workstations and servers. It is set up with the maximum protection except that Active is in Alert Mode, and everything else is blocked.
What is most valuable?
The most valuable feature is that it just unintrusively works in the background to carry out the protection. You don't have to babysit it. Instead, it will alert if it sees something, you deal with it and carry on from there.
What needs improvement?
Periodically we have an application that does not work correctly when SentinelOne is installed, yet performs as expected when SentinelOne is removed. SentinelOne gives no clue as to the problem, so to diagnose what is happening can be difficult. To make it worse, the behavior is inconsistent. Two people in the office might have the application working correctly, but a third person using the same program will have a problem.
Nothing is displayed by the agent that is running on the workstations, but it would be helpful to have a mode available where we can see feedback as to what it is doing. We wouldn't want it running all the time because there would be more overhead, but it could be helpful for debugging or diagnosing problems.
For how long have I used the solution?
I have been using SentinelOne for between six months and a year.
What do I think about the stability of the solution?
In terms of stability, it has been good so far.
What do I think about the scalability of the solution?
It appears to be scalable.
How was the initial setup?
The initial setup is very easy.
What's my experience with pricing, setup cost, and licensing?
Our licensing fees are about $5 USD per endpoint, per month.
What other advice do I have?
Overall, this is a good product and I recommend it. That said, there are always ways to make things better.
I would rate this solution a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Consultant at a tech services company with 51-200 employees
AI-powered protection, data-rollback ability, and seamless integration with SolarWinds
Pros and Cons
- "It has the ability to rollback a ransomware infection instantly and with minimal disruption to the user & provides robust reporting."
- "Set up is very labor-intensive."
What is our primary use case?
We are an MSP supporting various business verticals (including medical and pharmaceutical). Our core monitoring/deployment solution is SolarWinds RMM, through which we were recently introduced to SentinalOne. We use the bundled automation to install, patch, and monitor antimalware protection to endpoints. We are in the process of replacing Bitdefender with SentinalOne for several clients.
How has it helped my organization?
Deployment is automatable through the RMM, though a little clunky to do. The provided automation was a little challenging, but once you get it configured it's quite effective. Once we got it deployed to our users, it operates seamlessly and with minimal impact on system resources. Even our clients with lower-end workstations report improved performance since switching from Bitdefender.
After migrating, this also picked up some latent malware that was not previously detected & cleaned it immediately with almost no interaction required. I was impressed with how little this bogged down the affected system. This was in our pilot run, so I was on-site.
What is most valuable?
The fact that this runs using AI instead of heuristics provides the best protection I've seen. It has the ability to rollback a ransomware infection instantly and with minimal disruption to the user & provides robust reporting.
I tested this by deliberately infecting an unpatched test machine with WanaCry. First of all, SentinalOne blocked the initial infection attempt. I had to put S1 into "notify only" mode on that system to actually infect the machine. Once infected, WanaCry did what it does... encrypted all the documents I had copied to the test machine and put up the background.
We immediately got a notification on our dashboard that a system was infected. At the same time, we got a popup on the client machine notifying us of the infection, with the option to auto-repair the damage. It took less than a minute (granted, we only had about 200 MB of files on the test system) for S1 to repair the damage and put the machine back to normal with no evidence of the infection.
You also can't remove the client from the local machine without approving it within the dashboard. This is a nice feature to prevent tampering by either hapless users or even skilled threat actors.
What needs improvement?
Set up is very labor-intensive. You have to provide multiple codes from multiple places within the S1 dashboard in order to use the provided automation, and it's different for each client (or "sites" as they call it). It very much feels like an enterprise application that has been adapted for SMBs, but not very thoroughly. It would be better if they had a "site package" similar to the one offered by SolarWinds for the RMM. You just run the package on the client machine and done.
For how long have I used the solution?
We have been using this solution for approximately three months.
What do I think about the stability of the solution?
The stability is excellent so far. Once installed, it's "set it and forget it."
What do I think about the scalability of the solution?
Scalability is great if you're scaling up, but scaling down may prove to be challenging.
How are customer service and technical support?
Technical support is provided for us through SolarWinds, and they're very knowledgable.
Which solution did I use previously and why did I switch?
We used Bitdefender (also through SolarWinds) previously. SentinalOne was pitched by SolarWinds a few months ago as an alternative with robust ransomware protection. Being a small MSP, a single ransomware infection at a client could spell disaster for our business. We are always looking for the latest technology, but not marginal improvements.
How was the initial setup?
The setup script provided by SolarWinds (proprietary to their RMM) was a little challenging to get going, but once it worked, it worked perfectly. Except it didn't run on Win7 systems because it uses Powershell commands from a later version than what's available on Win7.
What about the implementation team?
The vendor team provided support, but we did the deployment.
What was our ROI?
We're making about seventy-five percent over the per-seat cost, and it's easy to sell at that price point.
What's my experience with pricing, setup cost, and licensing?
The per-seat cost is low, but you have to commit to a certain number of licenses for a year.
Which other solutions did I evaluate?
We really hadn't seen EDR solutions in action before. Our decision was based primarily on the fact that it has SolarWinds integration.
What other advice do I have?
Definitely worth the money compared to heuristic solutions, especially for clients who tend to "stretch" their hardware as long as possible. The low impact and robust reporting go a long way to make this an easy sell, and the cost is excellent for the price point.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Socio Fondatore e Proprietario at a tech services company with 201-500 employees
A stable solution that offers very good information surrounding attacks and threats
Pros and Cons
- "The solution offers very rich details surrounding threats or attacks."
- "The solution needs better reporting on new threats and malware. The reporting is present, but I can't find the information easily."
What is most valuable?
The solution offers very rich details surrounding threats or attacks.
What needs improvement?
The price is a bit high. They should make their pricing model more affordable.
The solution needs better reporting on new threats and malware. The reporting is present, but I can't find the information easily.
For how long have I used the solution?
We are in the process of testing the solution. We've been using it for three months.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
It's hard to give an impression on the stability at this time. We haven't used it on a large scale yet. We're still testing.
How are customer service and technical support?
We haven't needed to contact technical support yet.
Which solution did I use previously and why did I switch?
We are currently using Webhook as we test this new solution.
What other advice do I have?
We are using the public cloud deployment model.
I would rate the solution nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
IT Manager at a tech vendor with 51-200 employees
Receptor is good at finding many EFC files
Pros and Cons
- "We have a preference for their receptor. It's good at finding many EFC files. EFC files could have a virus."
- "It's fine. It's correcting all the EFC files with a virus. All the achievements, maximum EFC files. Many EFC files will be flagged as a virus. Some virus databases need to be updated. The model is good at finding many EFC files. The trouble is it needs to be updated."
What is our primary use case?
We use the public cloud version.
What is most valuable?
We have a preference for their receptor. It's good at finding many EFC files. Normally, EFC files could have a virus, but we need to exclude some of them.
What needs improvement?
It corrects all of the EFC files with a virus. All the achievements, maximum EFC files. Many EFC files will be flagged as a virus. Some virus databases need to be updated. The model is good at finding many EFC files. The trouble is it needs to be updated.
From the client-side, some scanning and other features can be enabled for scanning viruses better. If they want to scan for an individual reason other than viruses, such as scanning for legal files, they haven't been able to gather that from the client-side.
Some features could be more user-friendly. For instance, setting restrictions in the explorer for what level one must be to use it is not user-friendly. It is difficult to find what we're searching for.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
Out of ten, I would give this solution 8.5 for scalability.
How are customer service and technical support?
When we need partners, they support us well. There have been no issues with that.
What other advice do I have?
It's okay. It's a better solution than other competitors.
I would rate this solution as nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Managing Partner at a tech services company with 11-50 employees
Protects endpoints against malware and other threats
Pros and Cons
- "The most valuable feature of this solution is the user-friendly interface."
- "This solution would be more attractive to customers if the price were lower."
What is our primary use case?
We are an IT company that sells solutions, and this is one of the products that we provide to our customers. We work on certain opportunities that require the capabilities of SentinelOne, but we do not use it for our own purposes.
This solution is used to protect endpoints against malware and other threats.
A lot of the deployments are hybrid. In Lebanon, the cloud is not used to a large extent. Most of the customers use on-premises solutions.
What is most valuable?
The most valuable feature of this solution is the user-friendly interface. Our customers ask for something that is easy to use, easy to manipulate and doesn't require too much intervention. This is where SentinelOne scored big against CrowdStrike and Carbon Black.
This solution is easy to install.
What needs improvement?
This solution would be more attractive to customers if the price were lower.
For how long have I used the solution?
We have been working with this solution for about one year.
What do I think about the stability of the solution?
The stability seems ok at this point because there is no negative feedback from the customers.
What do I think about the scalability of the solution?
This solution is scalable and expandable with no issues.
How are customer service and technical support?
We have support from both vendor and distributor, and up to now, it has been satisfactory. The response has been very good, which is something the customers really appreciate and is always considered a plus.
How was the initial setup?
The initial setup of this solution is straightforward. The deployment is very easy and very fast, taking perhaps two or three hours, depending on the size of the project.
It is a centralized deployment.
A maximum of two people are required for the setup and maintenance.
What about the implementation team?
The implementation of this project is a joint effort between our team and the vendor's technical team.
What other advice do I have?
I have done POCs with this solution for two customers and there has been no negative feedback.
My advice for anybody considering this product is to do a POC and check to ensure it fits their environment. In some areas, this may be the best product to use, but in another environment, another product or another solution would be a better fit. It's always a matter of doing the POC and trying to get the most out of the product, depending on the environment.
I would rate this solution an eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller.
IT Operations Manager at a retailer with 1,001-5,000 employees
Offers better protection for corporate environments particularly with a lot of cloud integration and platforms like Office 365
Pros and Cons
- "All of the features are valuable. The way that it integrates into management with fault correction capabilities over is especially valuable. Any of the full gamut of the features that it provides are useful to us."
- "In terms of improvement, I would like to see better alerting to let us know if there is anything wrong with SentinelOne working on the endpoint of the computer."
What is our primary use case?
Our primary use case of this solution is to have as a next-generation security product for our endpoint devices.
What is most valuable?
All of the features are valuable. The way that it integrates into management with fault correction capabilities over is especially valuable. Any of the full gamut of the features that it provides are useful to us.
What needs improvement?
In terms of improvement, I would like to see better alerting to let us know if there is anything wrong with SentinelOne working on the endpoint of the computer.
For how long have I used the solution?
I have been using SentinelOne for six months.
What do I think about the stability of the solution?
It's very stable.
What do I think about the scalability of the solution?
It's scalable. We don't have any plans to increase usage.
How are customer service and technical support?
We haven't had to engage with their technical support.
Which solution did I use previously and why did I switch?
We were previously using another solution and it was a corporate decision to switch to this solution.
How was the initial setup?
The initial setup was straightforward. The deployment took around two weeks.
What about the implementation team?
We did the integration in-house.
Which other solutions did I evaluate?
We didn't evaluate other options before choosing this solution.
What other advice do I have?
I strongly recommend this solution. I would recommend that you get onto a next-generation endpoint security device like this one. It's much better protection for corporate environments particularly with a lot of cloud integration and platforms like Office 365. If you're going to start using those sort of services, then you really need a next-generation endpoint protection device like SentinelOne.
I would rate it an eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free SentinelOne Singularity Complete Report and get advice and tips from experienced pros
sharing their opinions.
Updated: December 2025
Product Categories
Endpoint Detection and Response (EDR) Endpoint Protection Platform (EPP) Anti-Malware Tools Extended Detection and Response (XDR) AI ObservabilityPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
Fortinet FortiEDR
IBM Security QRadar
HP Wolf Security
Cortex XDR by Palo Alto Networks
Microsoft Defender XDR
Elastic Security
Huntress Managed EDR
WatchGuard Firebox
Fortinet FortiClient
Trellix Endpoint Security Platform
Buyer's Guide
Download our free SentinelOne Singularity Complete Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Carbon Black CB Defense, CrowdStrike, and SentinelOne?
- Which is better - SentinelOne or Darktrace?
- What do you recommend to choose when replacing Symantec EDR: SentinelOne or CrowdStirke Falcon?
- Cortex XDR by Palo Alto vs. Sentinel One
- Which solution do you prefer: CrowdStrike Falcon or SentinelOne Singularity Complete?
- Does SentinelOne have a Virtual Patching functionality?
- What is the biggest difference between EPP and EDR products?
- What is the difference between EDR and traditional antivirus?
- What is your recommendation for a 5-star EDR with low resource consumption for a financial services company?
- Which is the best EDR for a logistics company with 500-1000 employees?















