We just swapped from Sophos to Sentinel One, so I do have some thoughts. On mobile currently but I'll try to add more detail later, so this'll be headlines SentinelOne was significantly cheaper SentinelOne was much more pleasant to deal with (via our VAR) Sophos does theoretically integrate with a lot of stuff but it'll usually be at additional cost SentinelOne/Sophos installed fairly similarly at scale SentinelOnes UI feels like a UI that someone designed to do the job it's doing, Sophos feels like a bunch of services that's vaguely bolted together Reporting in Sophos was inconsistent between the ThreatGraph, Detections, Device Events Sophos repeatedly failed to react to Detections, we had a couple of instances where we knew they were false positives, Sophos did not, but the device did not automatically isolate, as it should, there was no MDR case, just... Nothing. We had to spend our time doing what we were in theory paying Sophos for, investigating it. Sophos was consistently getting itself into a position on Mac where it couldn't run, couldn't update, lost disk access, it became a significant manual effort. SentinelOne is absolutely heavier on endpoints, more CPU, more RAM, more noticeable disk use SentinelOne has better automation In short, after the fact, I would make the same choice again. SentinelOne isn't perfect but in my opinion it's the better option. Answer from WeleaseBwianThrow on reddit.com
🌐
SentinelOne
sentinelone.com › cybersecurity-101 › services › what-is-managed-detection-response-mdr
What is MDR (Managed Detection and Response)?
March 17, 2023 - By using the power of SentinelOne’s advanced endpoint protection platform and expert security analysts, Vigilance can help organizations stay ahead of emerging threats and maintain a strong security posture in today’s challenging cybersecurity landscape. MDR stands for Managed Detection and Response. According to the Managed Detection and Response definition, MDR is a cybersecurity service where third-party experts handle continuous threat monitoring, detection, and response across your networks, endpoints, and cloud environments.
🌐
SentinelOne
sentinelone.com › global-services › vigilance-respond
Vigilance MDR – 24/7 MDR Service | SentinelOne
August 6, 2024 - Call for backup with Vigilance MDR, SentinelOne’s global Managed Detection and Response (MDR) service. Vigilance Respond enlists our in-house experts to review, act upon, and document every product-identified threat that puts your network ...
🌐
SentinelOne
sentinelone.com › lp › vigilance-mdr
Vigilance MDR | SentinelOne
January 30, 2023 - It’s your cybersecurity program, customized for you, and delivered by a world-class team of cybersecurity experts. Ready to give it a try and see the difference today? SentinelOne’s Vigilance Managed Detection & Response (MDR) Delivers Efficient ...
🌐
SentinelOne
sentinelone.com › global-services › singularity-mdr
Wayfinder Managed Detection & Response Services | SentinelOne
August 6, 2024 - Stop threats at machine speed with Wayfinder MDR. 24/7 expert-led detection, threat hunting, and AI-powered operations that keep you ahead of attacks.
🌐
Reddit
reddit.com › r/sysadmin › sophos mdr vs. sentinelone singularity mdr – real-world experiences?
r/sysadmin on Reddit: Sophos MDR vs. SentinelOne Singularity MDR – real-world experiences?
May 28, 2025 -

Hey everyone, We’re currently evaluating Sophos MDR Complete and SentinelOne Singularity MDR (with Singularity Complete) and would love to hear your real-world experiences — especially regarding support quality, response times, and how “hands-off” the MDR service really is.

Our situation: • We’re currently using SentinelOne without MDR – and generally happy with it. • We don’t have the manpower or expertise to handle serious security incidents ourselves. • We manage our own Sophos Firewall – firewall rules, NAT etc. are no issue. • Ideally, we want to just deploy the agent and have the SOC handle everything else.

What’s important to us: • Strong protection for Windows clients, servers, and Microsoft 365 • Low false positives • Responsive, high-quality support (bonus points for local or German-speaking) • A team that actively monitors and responds to threats • Minimal operational burden on our side

Our impressions so far: • SentinelOne seems very strong in automation, detection rules, and AI-driven telemetry analysis • Sophos offers native integration with Sophos Firewall, is listed as a BSI APT Response provider, and has local support in Germany • We had performance issues with Sophos Intercept X a few years ago, not sure if that’s still a thing.

We’re looking for insights like: • How well do these MDRs perform in practice? • Are alerts actionable? • Do they handle threat hunting and incident response effectively? • How’s the integration with Microsoft 365, firewalls, third-party logs, etc.?

Would love to hear any feedback, comparisons, or “lessons learned” from your deployments — thanks a lot!

Best regards stetze

Edit: We‘ve using Sophos MDR now.

Top answer
1 of 6
8
We just swapped from Sophos to Sentinel One, so I do have some thoughts. On mobile currently but I'll try to add more detail later, so this'll be headlines SentinelOne was significantly cheaper SentinelOne was much more pleasant to deal with (via our VAR) Sophos does theoretically integrate with a lot of stuff but it'll usually be at additional cost SentinelOne/Sophos installed fairly similarly at scale SentinelOnes UI feels like a UI that someone designed to do the job it's doing, Sophos feels like a bunch of services that's vaguely bolted together Reporting in Sophos was inconsistent between the ThreatGraph, Detections, Device Events Sophos repeatedly failed to react to Detections, we had a couple of instances where we knew they were false positives, Sophos did not, but the device did not automatically isolate, as it should, there was no MDR case, just... Nothing. We had to spend our time doing what we were in theory paying Sophos for, investigating it. Sophos was consistently getting itself into a position on Mac where it couldn't run, couldn't update, lost disk access, it became a significant manual effort. SentinelOne is absolutely heavier on endpoints, more CPU, more RAM, more noticeable disk use SentinelOne has better automation In short, after the fact, I would make the same choice again. SentinelOne isn't perfect but in my opinion it's the better option.
2 of 6
1
(Sophos Employee here): Just to recap some off your thoughts with some Sophos Knowledge: All Sophos products(like Firewall etc.) and Microsoft M365 is included in the MDR License, you purchase per User+Server. That means, if you decide later on to choose one of Sophos others products like Email to use, you could integrate it to the MDR Service - But you do not have to. The Starting Point for most MDR Customers is Endpoint+Server. You can also look into this: https://news.sophos.com/en-us/2022/11/30/introducing-the-sophos-breach-protection-warranty/ With Sophos Firewall, the Analyst Team can push their own IoCs to the Firewall to block certain events, in case of an Detection. Additionally the Firewall is sending the data of its own detection to MDR. In the current V21.5 Release, SFOS includes a NDR-E Feature, which gives more visibility to the Network part: https://partnernews.sophos.com/en-us/2025/04/products/sophos-firewall-v21-5-early-access-now-available/ One nice feature with SFOS + Endpoint is the authentication: Which gives you the option to authenticate against AD without the need of using STAS or anything.
🌐
Red Canary
redcanary.com › home › security integrations › red canary + sentinelone
SentinelOne MDR and Endpoint Protection - Red Canary
June 20, 2025 - Customers with SentinelOne Singularity can supercharge their deployments by adding Red Canary MDR, an advanced security operations platform with 24×7 security operations monitoring by experts at finding and stopping threats.
🌐
ConnectWise
connectwise.com › platform › mdr › connectwise-mdr-with-sentinelone
ConnectWise MDR™ with SentinelOne | ConnectWise
However, relying solely on EDR ... and potential disruptions. ConnectWise MDR™ with SentinelOne transforms SentinelOne EDR into a 24/7/365 enterprise-grade managed cybersecurity solution....
🌐
SentinelOne
sentinelone.com › blog › managed-detection-and-response-mdr-beyond-the-endpoint
Managed Detection and Response (MDR) Beyond the Endpoint
February 25, 2025 - In this blog post, learn how SentinelOne is extending the scope of our MDR service to provide 24×7 detection and response coverage across endpoint, cloud, identity, email, network, and beyond.
Find elsewhere
🌐
SentinelOne
sentinelone.com › cybersecurity-101 › endpoint-security › edr-vs-mdr
EDR vs MDR: How to Choose the Best Security Solution
September 24, 2024 - MDR: Subscription-based model, potentially more cost-effective for organizations without in-house expertise. See how AI-powered endpoint security from SentinelOne can help you prevent, detect, and respond to cyber threats in real time.Get a Demo
🌐
SonicWall
sonicwall.com › medialibrary › serviceplans › mdr-for-sentinelone.pdf
MDR for SentinelOne - Endpoint Security
Discover the next wave in cybersecurity with SonicWall’s unified, intelligent platform—built to help MSPs and partners deliver smarter, scalable, and more secure solutions for the digital future.
🌐
Security Info Watch
securityinfowatch.com › cybersecurity › product › 55131226 › sentinelone-partners-with-phantom-to-extend-autonomous-endpoint-protection-across-the-enterprise-sentinelone-singularity-mdr
SentinelOne Singularity MDR | Security Info Watch
Combining the power of SentinelOne’s AI-powered Singularity Platform with deep security expertise, this new, full-scale Managed Detection and Response (MDR) service provides enterprises with coverage across endpoints, identities, networks, ...
🌐
SentinelOne
sentinelone.com › cybersecurity-101 › endpoint-security › mdr-monitoring
MDR Monitoring: Definition, Application, and Best Practices
October 17, 2024 - It will help you avoid costly data breaches and secure your enterprise. SentinelOne Vigilance MDR can help you on your journey. Book a free live demo with us to learn more about how it works.
🌐
SentinelOne
sentinelone.com › faq
FAQ | SentinelOne
March 14, 2025 - SentinelOne also offers an optional MDR service called Vigilance; Unlike CrowdStrike, SentinelOne does not rely on human analysts or Cloud connectivity for its best-in-class detection and response capabilities.
🌐
Avertium
avertium.com › managed-detection-response-sentinelone
Managed Detection + Response | SentinelOne
Avertium's MDR Services with SentinelOne's Singularity Platform provide you with limitless security. Traditional endpoint solutions can’t keep up with relentless, sophisticated threat actors.
🌐
Progent
progent.com › pdf › SentinelOne-Complete-with-MDR-Package-2.pdf pdf
Progent SentinelOne Complete with MDR Package from Progent
SentinelOne Complete with Vigilance MDR – 24x7 Monitoring and Threat Mitigation Co-Managed Environment
🌐
SentinelOne
sentinelone.com › global-services › vigilance-respond-pro
DFIR With Breach Readiness | SentinelOne
July 23, 2025 - Seamless integration with our MDR services provides end-to-end detection, investigation, and response coverage. Our global team of responders helps ensure rapid containment, investigation, and eviction.
🌐
Consultedge
consultedge.global › home › insights › mdr, edr, xdr: sentinelone’s cybersecurity solutions explained
MDR, EDR, XDR: SentinelOne's Cybersecurity Solutions Explained
October 14, 2025 - SentinelOne offers three primary services: Managed Detection and Response (MDR), Endpoint Detection and Response (EDR), and Extended Detection and Response (XDR). Understanding these services is crucial for businesses to choose the right protection ...
🌐
eSentire
esentire.com › homepage › esentire selects sentinelone to advance multi-signal mdr capabilities with ai-powered xdr
eSentire Selects SentinelOne to Advance Multi-Signal MDR Capabilities…
May 27, 2024 - “Our platform and strategy is tailored to enable partners to power their offerings with and through Singularity XDR,” said Brandon Andrews, VP Worldwide MSSP, SentinelOne. “eSentire is an MDR leader, and we’re proud they’ve selected ...