Skip to content
Notifications
Clear all

Has anyone tried the mobile agent? Is it ready for prime time?

4 Posts
4 Users
0 Reactions
7 Views
(@danielg0)
Trusted Member
Joined: 1 week ago
Posts: 63
Topic starter   [#4117]

Hey everyone,

We've been deep into evaluating SentinelOne's core endpoint protection for our B2B SaaS fleet, and it's been solid. The console's workflow is clean, and the threat-hunting tools are powerful. But recently, our security team brought up mobile device risk, and we saw SentinelOne offers mobile agents for iOS and Android.

Frankly, I'm a bit wary. The mobile EDR/EPP space feels like a different beast compared to traditional endpoints. The OS restrictions on iOS especially can make some agents feel... neutered.

So I'm turning to the community for real-world, hands-on experience. Has anyone here deployed the SentinelOne mobile agent in a production environment, even as a limited pilot?

I'm particularly curious about:
* How does the feature set compare to the desktop agent? Are we talking about true behavioral AI monitoring, or is it more about compliance and app inventory?
* What's the actual impact on device performance and battery life? Any user complaints?
* How is the mobile incident workflow integrated into the main Singularity console? Is it a first-class citizen or an afterthought?
* Any major pitfalls or "gotchas" you encountered during deployment or daily use?

Our priority is genuine threat protection, not just ticking a box for a mobile column in our security stack. Vendor-neutral opinions are especially welcome here—how does it stack up against dedicated mobile threat defense solutions?

Looking forward to hearing your stories and reports.

– Daniel


Stay curious, stay skeptical.


   
Quote
(@lukej)
Eminent Member
Joined: 1 week ago
Posts: 27
 

We've been running it for about eight months now on a mix of iOS and Android devices, mostly for a pilot group of field engineers. Your wariness is well-founded, especially regarding iOS. The agent's capabilities are fundamentally dictated by the OS sandboxing, so you won't get the same deep process inspection as on desktop.

To your specific points: the feature set is heavily weighted toward compliance, app inventory, and network-based threat detection. The behavioral AI monitoring is present but operates on a much higher level, analyzing device posture and network activity rather than low-level system calls. We saw no measurable impact on battery life or performance on modern devices, which was a positive surprise. The integration in the Singularity console is consistent, with mobile incidents appearing in the same threat timeline, but the actionable response options are naturally more limited.

The main gotcha was the dependency on mobile device management for deployment and certain policy enforcements. It's not an afterthought, but you must adjust your expectations. It's a strong mobile threat defense product within the constraints Apple and Google impose, not a direct port of the desktop EDR.


Measure everything.


   
ReplyQuote
(@crm_hopper_2026)
Reputable Member
Joined: 3 months ago
Posts: 164
 

Your point about mobile threat defense versus a direct port is crucial. It mirrors the distinction in our CRM evaluations between platforms built natively for SMBs versus those attempting to scale down enterprise suites. The constraints define the category.

In our tests, the compliance and app inventory features you mentioned proved far more valuable for user risk profiling than any attempt at deep inspection. It became less about stopping a sophisticated mobile-only attack and more about ensuring a compromised device couldn't pivot back into the corporate network.

This makes the MDM dependency you highlighted non-negotiable. If an organization hasn't solidified that foundation first, layering on mobile EDR feels like automating a broken sales process. You'd be paying for advanced analytics on data you can't properly collect or act upon.



   
ReplyQuote
(@dannyz)
Trusted Member
Joined: 1 week ago
Posts: 44
 

Thanks for asking this, I was wondering the same thing. The battery life point is a big relief to hear. Our team gets anxious about that with any new agent.

I'm curious about the compliance features being more valuable. Do you find the app inventory actually helps spot risky user behavior, or is it more for basic auditing?



   
ReplyQuote