The solution is useful for protecting against ransomware and malwares.
Easy to install, but has slow performance and response time
Pros and Cons
- "The solution is easy to install."
- "The performance is very slow and should be faster."
What is our primary use case?
What needs improvement?
The performance is very slow and should be faster.
Data resources will be consumed, affecting the performance, when there is a concurrent login involving a server with multiple RDP users.
The installation of the solution will start the 17 services involved.
While the tech support is knowledgeable, it's response time should be faster, as it will only get back to us the day after raising a ticket.
For how long have I used the solution?
We have been using Sophos Intercept X for around two years.
How are customer service and support?
Technical support, while knowledgeable, is not adequately responsive, as it will take a day from when the ticket was raised to receive a response. This needs improving.
Buyer's Guide
Intercept X Endpoint
March 2025

Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
841,164 professionals have used our research since 2012.
How was the initial setup?
The solution is easy to install. Downloading time takes only 15 minutes.
What about the implementation team?
Our technical team consists of a team leader, team manager and administrators.
What other advice do I have?
The solution has around 60 licenses.
It is cloud-based.
We have around 10 clients making use of the solution.
We would recommend the solution to others.
I rate Sophos Intercept X as a seven out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Implementer
Director at a comms service provider with 201-500 employees
Very stable although after-sales technical support is lacking
Pros and Cons
- "Very stable solution."
- "The after sales service and support could be improved."
What is our primary use case?
We're currently implementing this solution in our company, but we generally implement it for our clients. I'm a director and we are resellers of Sophos Intercept X.
What is most valuable?
The product is very stable which is great.
What needs improvement?
The after sales service and support could be improved, particularly on the technical side. The solution has room for additional features.
For how long have I used the solution?
I've been using this solution for two years.
What do I think about the stability of the solution?
The product is stable, although one of my clients suffered a bit from downtime. The clients are happy with it.
What do I think about the scalability of the solution?
We purchase different boxes according to the needs of the client, because every single box has a limitation on number of users. The lowest one, which is 110, supports up to 20 users, 10 to 20 users. 125 supports around 30 users and so on. Most of our clients are medium and enterprise size companies.
What's my experience with pricing, setup cost, and licensing?
I'd like to see the price lowered.
What other advice do I have?
Although this is quite an expensive solution when you compare it to products like Automate or Cisco, Sophos does better on pricing.
I rate this solution a seven out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer: reseller
Buyer's Guide
Intercept X Endpoint
March 2025

Learn what your peers think about Intercept X Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: March 2025.
841,164 professionals have used our research since 2012.
Founder and Managing Partner at a tech services company with 1-10 employees
Responsive support, compatible with multi-platforms, and highly scalable
Pros and Cons
- "The key factor that attracted me to Sophos Intercept X was the multi-platform. I have multiple clients that have mixed environments of Mac and Windows. I am able to deliver a standard solution, regardless of the platform."
- "There are not any solutions that are a 10 out of 10. A 10 would be perfect protection with no impact on the performance of the device. This is not the case, there is some impact on the performance of the device."
What is our primary use case?
We are using Sophos Intercept X for network and system security.
What is most valuable?
The key factor that attracted me to Sophos Intercept X was the multi-platform. I have multiple clients that have mixed environments of Mac and Windows. I am able to deliver a standard solution, regardless of the platform.
Most of my clients I have central management, they receive updates automatically.
What needs improvement?
There are not any solutions that are a 10 out of 10. A 10 would be perfect protection with no impact on the performance of the device. This is not the case, there is some impact on the performance of the device.
For how long have I used the solution?
I have been using Sophos Intercept X since it has been released, it has been many years.
What do I think about the stability of the solution?
Sophos Intercept X is very stable. However, we had a few issues when Apple released Big Sur. At the time the version of Sophos Intercept X that was running on the Macs wouldn't work properly with Big Sur. We had to install a beta, but that problem was resolved fairly quickly.
What do I think about the scalability of the solution?
Sophos Intercept X is highly scalable.
How are customer service and support?
I have found the Sophos office staff to be far more responsive than other vendors, such as Sonic Wall which is awful. I dealt with them for a number of years and I finally couldn't stand it anymore. I felt that Dell destroyed them.
I have been very pleased with tech support. As a partner, I have access directly to their engineers and developers. Their technical support is superior.
How was the initial setup?
The initial setup is very straightforward.
In the centrally managed environments, you create a downloadable install that you can either email to the end-user or, can have available on thumb drives for customers to install. Once it's installed, it's automatically kept up to date with the most current version.
What's my experience with pricing, setup cost, and licensing?
The price of Sophos Intercept X is competitive.
What other advice do I have?
I'm looking at moving to the EDR version of Sophos because I have a number of clients that have extremely critical data. One of them handles a lot of money for their clients, and the others are lawyers. The security of not only their own information, but their client information, is critical to them. The Intercept X EDR offering is starting to look like it might be a good solution for several of them because of the live monitoring of the threat attempts on their endpoints.
The EDR is an additional managed service that's a component of the antivirus, where depending upon which level you choose, you either have a team that is monitoring responses from your system, or at a higher level, you have dedicated resources that are monitoring your systems. If there's an alert, they immediately respond to that alert and research it, not only quarantine it, the AV quarantines it, but with the EDR function, it alerts the Sophos team that there has been a potential issue, and they'll immediately begin to research it.
My advice to others would be to use centralized management because it makes it much easier to implement, manage, track the installations, and the day-to-day usage. With the central management, you can see every PC or Mac that's connected, any activity, and any issues. You can narrow any issue down to the computer if it's had to quarantine anything. Additionally, you can tell how long it's been since the computer last communicated. It's a very powerful tool, I would recommend it. To the extent their clients are willing to accept the central manager, it is the best option.
I rate Sophos Intercept X a nine out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner
Manager at a real estate/law firm with 1,001-5,000 employees
The setup was simple, the EDR could be improved, and perhaps the user interface.
Pros and Cons
- "It's quite simple to use and user friendly."
- "The EDR could be improved, and perhaps the User Interface."
What is our primary use case?
We use it mostly for software protection.
What is most valuable?
It's quite simple to use and user friendly.
What needs improvement?
The EDR could be improved, and perhaps the User Interface. EDR machine learning could be included.
For how long have I used the solution?
We have been using Sophos Intercept X for about two years. It is the latest cloud version. We have about 200 people using it, daily. We are a Sophos customer.
What do I think about the stability of the solution?
It is a stable product.
What do I think about the scalability of the solution?
It is reasonable scalable. So, somewhere in the middle in terms of scalability.
How are customer service and technical support?
We have not needed to use support so far.
Which solution did I use previously and why did I switch?
We have been using Sophos since day one.
How was the initial setup?
The setup was simple. It took us about one day to set up and configure the software.
What about the implementation team?
The setup was done internally. We also perform maintenance internally.
What's my experience with pricing, setup cost, and licensing?
The pricing is average for software like this, but you can purchase additional services if you wish.
Which other solutions did I evaluate?
In the future, we may evaluate SentinelOne.
What other advice do I have?
I would recommend this to other users, and I would give the product 7 out of 10.
Which deployment model are you using for this solution?
Private Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Founder, Director at Tres Infosol Pvt. Ltd.
A stable and scalable solution which is easy to install and allows for synchronized protection
Pros and Cons
- "One of the best use cases involves synchronized security staff, which allows us to manage both the firewall and the anti-virus features from the cloud."
What is our primary use case?
One of the best use cases involves synchronized security staff, which allows us to manage both the firewall and the anti-virus features from the cloud. They work in tandem with each other. So, if there is any threat detected by the endpoint, it communicates information concerning this change to the firewall. For that particular client, at the firewall, it can update all other endpoints into the network to check if the same threat is visible on any other machine. Then, corrective action can be taken collectively with a single click.
What is most valuable?
We have not encountered any issues involving the solution. A point in its favor is that it has not slowed down our systems, such as occurred with McAfee, Symantec or even Quick Heal. This has been a positive experience for us. Also, the synchronized security, in which things work with each other, provides us with a pretty automated remediation methodology which cuts down on much of the manual steps and workload.
What needs improvement?
At present, the solution meets the needs of our business scale. Perhaps in the future, as we grow and face increased challenges, there would be a need to explore other options.
For how long have I used the solution?
We've been using Sophos Intercept X for around six months.
What do I think about the stability of the solution?
The solution is pretty stable.
What do I think about the scalability of the solution?
The solution is, indeed, scalable. As a cloud-based solution, it is all about scalability.
How are customer service and technical support?
We have yet to encounter a situation in which we had a need to call tech support.
How was the initial setup?
The solution is pretty straightforward and very easy to configure.
Installation took no more than two or three minutes.
What about the implementation team?
We, ourselves, are system integrators and we have a staff of around seven people, consisting of eight engineers and a person who is responsible for the accounts, meaning the support staff.
What's my experience with pricing, setup cost, and licensing?
One can pay for the license annually, or at two and five year intervals.
What other advice do I have?
The solution is cloud-based.
I would absolutely recommend this solution to others. So far, so good.
There are roughly 25 people making use of the solution in our organization.
I rate Sophos Intercept X as a ten out of ten.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
Good web filtering with an excellent central console and the capability to scale
Pros and Cons
- "The package we use also comes with spam filtering features, which are quite useful."
- "The initial setup can be a bit challenging."
What is our primary use case?
We primarily brought on the solution to replace Symantec's product, as Symantec was purchased by Broadcom. The company in question has a lot of stuff, and 40 users, and is a pure Windows environment. They don't do anything on Mac or Linux, for example.
What is most valuable?
So far, the solution has been working quite well.
Sophos offers a manuscript response.
The product has three tiers that you can choose from when you buy. The highest is a Managed Threat Response. We chose the middle range, which offers Intercept X and is more than just Malware protection.
This solution is a kind of Next-Gen anti-virus.
The product has some web filtering, which blocks people from going to websites they shouldn't be going to.
It supports the Windows 10 server platform.
The solution offers a centralized view of the status of protection, via a central console for users to check the status or the health of the endpoints.
So far, the solution has met all our expectations. It's blocked malicious websites effectively and stopped people from going to places online that they shouldn't be going to. It's automatic. We simply took the default settings and we were finding people right away that were going to illicit sites, and we were able to see that easily in the console.
The package we use also comes with spam filtering features, which are quite useful.
What needs improvement?
We're still new to the solution. We haven't come across any weakness yet. There aren't features that are missing.
The initial setup can be a bit challenging.
For how long have I used the solution?
I just deployed the solution a few weeks ago. It's quite new at this point. We've had it now for a little over a month.
What do I think about the stability of the solution?
The solution is extremely stable. It doesn't crash or freeze. There aren't bugs and glitches. It's kept us safe. Nothing has gotten through. It's reliable.
What do I think about the scalability of the solution?
Currently, the company only has 40 users, and therefore there are no scalability issues so far. However, it's a cloud-based centralized console, so that will help with scaling in the future if the company decides to expand. It wouldn't be hard to do. It's completely achievable.
How are customer service and technical support?
Technical support is okay. I'd give them higher scores if I didn't have to contact them about the initial console setup. That said, they were helpful. Their service so far has been about average.
Which solution did I use previously and why did I switch?
We previously used Symantec.
We switched solutions for a few reasons. The first one is that Symantec was bought by Broadcom and there were some unknowns about what would happen with the product. Support typically gets worse when Broadcom buys a product, and we wanted to step away on the off-chance that could happen in the near future.
We were also looking to consolidate and to find a replacement but to also get something that had spam protection and something that was easily obtainable for a small business. Sophos ultimately could hit all those checkmarks.
How was the initial setup?
The initial setup with the centralized console was a little bit challenging. It wasn't complex per se, however, due to the fact that the instructions weren't clear, you can get stuck at certain points. I opened up a case for support, and at that point, I was able to get under the console. You could say the onboarding of additional administrators was a challenge. The centralized console was also a bit difficult.
After that, the implementation was pretty easy. You simply remove the old one, add the new one, and then, with the new one, you could send the user an email link, or you could send them a path to where the software is.
What's my experience with pricing, setup cost, and licensing?
I do not know the exact costs offhand, however, it's my understanding that their pricing is listed publicly on their site and would be easy to find. Sophos seemed surprised that their pricing was public. They were shocked that I could just Google it and it came up.
There are extra add-ons you can purchase over and above this product. The add-ons cost a bit more, however, they offer extra security advantages.
What other advice do I have?
We are a reseller.
We deployed the latest version of the solution. I don't have the version number on hand, however.
It's a good product to consider if a company is looking to also do spam filtering. What Sophos has as well as a firewall, and it'll give a company a little bit of tighter integration, and that's good. Having those additional security tools as add-ons is an excellent option. We personally haven't gotten their firewall yet, however, it is nice that that is an option.
I would rate the solution at an eight out of ten. Overall, in the short amount of time we've used it, we've had a positive experience.
Disclosure: I am a real user, and this review is based on my own experience and opinions.
CIO LATAM at i-Track Systems Development, S.A. de C.V.
Enables us to watch the throughputs and the loading of the device to see how much traffic is happening
Pros and Cons
- "The most valuable feature is the supervisory side of it where we can watch the throughputs, and even the loading of the device, to see how much traffic is happening."
- "In terms of the site-to-site VPN elements, they tend to concentrate. It's quite simple when there are Meraki devices at both ends of the VPN but if there is another user at one end, on another device, it can be a bit tricky. So they could really simplify that process a bit."
What is most valuable?
The most valuable feature is the supervisory side of it where we can watch the throughputs and even the loading of the device, to see how much traffic is happening.
What needs improvement?
In terms of the site-to-site VPN elements, they tend to concentrate. It's quite simple when there are Meraki devices at both ends of the VPN but if there is another user at one end, on another device, it can be a bit tricky. So they could really simplify that process a bit.
For how long have I used the solution?
I've been using the solution for 18-20 months.
What do I think about the stability of the solution?
So far, the solution has been very stable.
What do I think about the scalability of the solution?
At the moment, we have no plans to expand further. We might in the next six months or so. I believe it will easily scale. We've just not gone into that yet but it looks promising. At the moment, we have around 50 users.
How are customer service and technical support?
I've only had to deal with technical support in relation to site-to-site VPN problems. I did find them to be very helpful.
What was our ROI?
At the moment, we don't have ROI because we've been given a very generous period of trial for this machine, we've not had to actually spend any money so far. So, in terms of return of the investment, it's not really applicable at the moment.
What other advice do I have?
In terms of advice, I would make sure that, in terms of capacity, to get the right version, to find the right level of device. MX64 is a fairly small business-scale device. We were a bit hesitant about going for that, given the scalability of it at that point. But, obviously, make sure that you go in with enough extra capacity to deal with any increases you have in traffic demand.
If you're setting up a VPN on the MX64, if both ends end up being a Meraki device, then it's simple to set it up. But when it isn't, it's a bit more complex. Eventually, it causes a lot of statistical information that they could provide if the devices are Meraki at both ends. If they could provide that same facility for setups where the network doesn't involve an MX64 or a Meraki device at both ends, that would be great.
I would rate this solution an 8 out of 10.
Disclosure: My company has a business relationship with this vendor other than being a customer: Partner.
CEO at a government with 1-10 employees
Good price and stability for firewall security but we had problems with using the software
Pros and Cons
- "We most value the price and interface quality with Sophos Intercept X. We focus on solution quality."
- "Sophos needs to create a YouTube channel with educational material for technicians or engineers."
What is our primary use case?
We develop software for brands and some enterprise companies. We need Sophos Intercept X to create hardware and software solutions.
We need to create research for a next-generation firewall security solution. We offer software and hardware solutions for banks, enterprises, and big companies.
How has it helped my organization?
We had some technical problems. Maybe in the new update of this solution, they could fix some technical bugs.
Sophos Intercept X has slow internal processes that could be better. Because of this, it hasn't improved our organization.
What is most valuable?
We most value the price and interface quality with Sophos Intercept X. We focus on solution quality.
What needs improvement?
This product has room for improvement in business areas for brand enterprises. Sophos Intercept X could improve in areas dealing with business, i.e. their internal processes.
For how long have I used the solution?
I have been using this solution for six months.
What do I think about the stability of the solution?
For the stability of the solution, I had some problems with uptime.
How are customer service and technical support?
Technical support could be of better quality.
How was the initial setup?
The initial setup was complex. Our deployment took six months to one year. It took us around one year to fully set up Sophos and get it running to take action for work.
What about the implementation team?
For the deployment, I set it up myself.
What other advice do I have?
Sophos needs to create a YouTube channel with educational material for technicians or engineers.
I would rate Sophos Intercept X at seven out of ten because of the technical problems that we have experienced.
Disclosure: I am a real user, and this review is based on my own experience and opinions.

Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: March 2025
Product Categories
Endpoint Protection Platform (EPP) Endpoint Detection and Response (EDR) ZTNA Managed Detection and Response (MDR) Extended Detection and Response (XDR) Ransomware ProtectionPopular Comparisons
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Complete
Cisco Secure Endpoint
Cortex XDR by Palo Alto Networks
Fortinet FortiClient
Symantec Endpoint Security
Trend Vision One Endpoint Security
Trellix Endpoint Security
Kaspersky Endpoint Security for Business
HP Wolf Security
ESET Endpoint Protection Platform
Check Point Harmony Endpoint
Buyer's Guide
Download our free Intercept X Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Sophos Intercept X or Symantec End-User Endpoint Security - which is the better solution?
- Can Sophos Intercept X and Carbon Black be used side by side on endpoints?
- Which endpoint solution is more effective in terms of protection and remote administration: Sophos Intercept X or Kaspersky Endpoint Security?
- How does Crodwstrike Falcon compare with Sophos Intercept X?
- Sophos Intercept X: renewal cost for a security system integrator
- What is the biggest difference between EPP and EDR products?
- Can Cylance be used with Symantec or Kaspersky endpoint solutions without conflict?
- When evaluating Endpoint Security, what aspect do you think is the most important to look for?
- What's the best way to trial endpoint protection solutions?
- What are the threats associated with using ‘bogus’ cybersecurity tools?
Hi,
From Sophos has to provide training to their customers to handle Sophos devices along with certification so that cannot depend on the reseller or any implementation partner always.