What is our primary use case?
SentinelOne is an antivirus and an EDR platform. We are using is simply for its antivirus and EDR features.
What is most valuable?
The solution is overall very good in terms of protecting endpoints and servers from malicious activities, malware, cyber attacks, viruses, worms, and so on. It offers really good security.
The initial setup is easy.
We have been happy with the stability.
It is possible to scale the product.
There is good documentation available, and support works to help users resolve issues.
What needs improvement?
It doesn't have application control capability. Other antivirus or EDR solutions have that. I would be happy if SentinelOne added that to their platform. This is the first point.
The second point is SentinelOne should provide support for legacy open-source operating systems. For example, old versions of Oracle are not supported by SentinelOne.
The third point is that SentinelOne does not support a few platforms, including IBM AIX and UNIX-based OS. These three platforms are almost all used in all enterprises, and SentinelOne does not support them. If SentinelOne provides agents for these missing platforms, it'll be very good.
It would be ideal if they offered video support for troubleshooting issues.
For how long have I used the solution?
I've been dealing with the solution for just over one year.
What do I think about the stability of the solution?
The solution is stable and reliable. We have been happy with its performance. There are no bugs or glitches, and it doesn't crash or freeze.
I'd give it a four out of five in terms of stability.
What do I think about the scalability of the solution?
The scalability has been very good.
There are thousands of both users and servers. Everyone uses it.
How are customer service and support?
I have raised a lot of tickets, and their support is very good. However, with other members, when we have raised tickets in the past, we were able to have technical sessions through Zoom, WebEx, or Teams very easily. That's true, for example, with Microsoft, Cisco, McAfee, and Kaspersky. With SentinelOne, they are providing very good support, excellent support, however, their engineers are not very interested in providing online sessions, which is more convenient.
When you face any issue, they always provide documentation and videos - and that's very good. However, sometimes it's required that they show us how something is done. Doing some sort of video call helps with the walk-through. SentinelOne engineers, most of them, are not so much interested in doing this.
Which solution did I use previously and why did I switch?
We did previously use a different solution. However, I can't speak to which product that was.
Other solutions that I usually use in other organizations were on-premises. This one is cloud-based. The point is, when you have your antivirus or EDR solution on-prem, that's your responsibility to troubleshoot the core server and do that maintenance patch and all of those kinds of tasks. When the solution is hosted in the cloud, all of these responsibilities belong to the provider, in this case, SentinelOne. When a new patch is getting released from the vendor, normally, if we were using legacy platforms, we would have to upgrade each endpoint one by one. By using cloud-based EDRs, it can be done automatically and reduces maintenance time.
How was the initial setup?
The solution is very easy to set up. It's not overly complex or difficult.
The implementation strategy was very simple: removing the old antivirus solution and replacing that with SentinelOne.
It took us three months to migrate and deploy.
We have ten to 14 people that can handle deployment and maintenance. Only one person, however, needs to handle typical maintenance tasks.
What about the implementation team?
We handled the initial setup ourselves. We did not need any outside assistance.
What's my experience with pricing, setup cost, and licensing?
Licensing is part of the procurement team. I can't speak to the exact cost of the product.
What other advice do I have?
We are a customer of SentinelOne.
SentinelOne does not have a version. SentinelOne is a centralized platform that is hosted in the cloud. It's the agent that we install on servers and clients, it has versions we are using the latest version of agents.
The product has two deployment options, cloud deployment, and on-prem deployment. Most people prefer to use cloud deployment in the way we do.
I recommend this solution often. I'd rate the solution eight out of ten.
My advice for other companies that do not use SentinelOne is this: that everyone, every company, likely has its own antivirus solution, whether it's McAfee, Symantec, Kaspersky, and so on. These platforms provide only an antivirus solution, however. If they replace their solutions with SentinelOne, they will have two features: EPP, endpoint protection from antiviruses, and EDR, endpoint protection and response features. They will not need to install two applications, one antivirus, and one EDR, on their clients' computers; only one agent can do anything.
SentinelOne provides an amazing amount of visibility over clients and servers. Anything done on a server, on a client, with a network connection, login, logout, changes in directories, et cetera, is recorded. Using query searches, you can find what happened very easily.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: I am a real user, and this review is based on my own experience and opinions.