![Prateek T.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Prateek T.")
PT

Prateek T.

Trainee Security Engineer

Information Technology and Services

Small-Business (50 or fewer emp.)

7/25/2026

"Top-Tier Endpoint Protection with Powerful Automation and Root Cause Analysis."

5/5

What do you like best about Sophos Endpoint?

From an operational standpoint, the biggest win with Sophos Endpoint is how much work Sophos Central Handles automatically without requiring constant manual intervention.

Ransomware & Anti-Exploit Defense : The behavioral engines (CryptoGuard and exploits mitigation) are genuinely strong. It catches fileless threats , malicious PowerShell Scripts, and unauthorized process injection at execution time rather than relying solely on legacy signature updates.

Root Cause Analysis (RCA) Graphs: When threat or suspicious file gets flagged, the threat graphs shows precisely where the vector originated , which child processes were spawned , what registry key were touched. It cuts incident triage time down from hours to minutes.

Automated Device Isolation : If an endpoint exhibits malicious behavior , Sophos isolates the machine from the local network while maintaining a management tunnel back to Sophos central. This gives as breathing room to remediate without risking lateral movement across our subnets or VPN .

Centralized Policy Management : Pushing global policies , web filtering , and USB control across remote and on premise endpoints is straightforward once you structure your device groups properly. Review collected by and hosted on G2.com.

What do you dislike about Sophos Endpoint?

While protection is top tier there are few practical trade offs every admin should keep in mind :

Resource Usage during Deep Scans & Compiles : Even with recent agent optimization ,heavy disk or CPU activity can still occur during full background scans. If you have developers constantly compiling code or engineers running heavy CAD/3D software, you will need to spend time configuring fine-grained application exclusions to prevent occasional slowdowns.

Granular Policy Navigation : Sophos Central is clean, but finding deep configuration toggles-like specific AMSI exemptions or subtle server policy overrides can sometimes feel buried under multiple sub minus.

False Positive on Custom Scripts: Of your internal team uses custom PowerShell deployment scripts or custom PowerShell deployment scripts or unassigned internal executables HitmanPro/behavioral monitoring may occasionally flag them as dynamic shellcode until you create explicit SHA-256 or folder exclusions. Review collected by and hosted on G2.com.

What problems is Sophos Endpoint solving and how is that benefiting you?

Sophos solved three critical problems for us :

Remote Device Visibility : Machines stay updated and policy compliant whether employees are on the corporate network or working remotely from home.

Remote Alert Fatigue: Automated remediation handles the majority of low-level web blocks and suspicious script kills automatically , so our team isn't chasing benign alerts all day.

Streamlined Incident Analysis: The threat visualizer gives us clear audit trails for internal security reporting and cyber insurance compliance without needing a full time dedicated SOC analysts team.

Advice to others considering Sophos Endpoint

Spend time setting up your Base Policies and Exclusion rules during the pilot phase rather than deploying out of box settings to your entire fleet at once .Start with a test group identify any custom application conflicts early and refine your exclusions before pushing the agent site wide Review collected by and hosted on G2.com.

Show More

Rating Updated (8/1/2026)
Current UserValidated ReviewerIncentivizedSource: G2 invite

See what 793 reviewers think of Sophos Endpoint

4.7 out of 5 · Verified reviews from real users

[
Read all reviews
](https://www.g2.com/products/sophos-endpoint/reviews)