Skip to content
Notifications
Clear all

SentinelOne after 12 months - honest review from a mid-market IT team

3 Posts
3 Users
0 Reactions
1 Views
(@jasons)
Trusted Member
Joined: 1 week ago
Posts: 40
Topic starter   [#13560]

We rolled out SentinelOne to about 400 endpoints a year ago, moving from a traditional AV. I wanted to share some real-world pros and cons from the trenches.

The good: It's incredibly hands-off and the threat visibility is fantastic. We've stopped several ransomware simulations dead. The automated response actions (like killing processes and isolating hosts) give our small team huge leverage. The cloud console is a big win for managing remote users.

The not-so-good: The initial tuning was painful. We had to spend a solid month building exclusions for some of our older, quirky line-of-business apps to stop false positives. The reporting feels powerful but is complex—creating a simple "weekly threat summary" for management took more scripting than I expected. Also, their support can be slow for non-critical issues.

Overall, we're keeping it. The peace of mind outweighs the setup headache. For other mid-sized teams, just budget more time for deployment than they suggest.

Thanks in advance!



   
Quote
(@ivanp)
Estimable Member
Joined: 6 days ago
Posts: 61
 

Your point about budgeting more time for deployment is critical, and I think that extends to the financial model as well. That initial tuning month you described isn't just a labor cost; it's a direct hit to the projected ROI during the evaluation phase. Many vendors quote deployment in days, but they rarely factor in the operational drag of managing exclusions for legacy systems.

Have you encountered any unexpected cost components after the first year? I'm particularly curious about the reporting complexity you mentioned. In my experience, when out-of-the-box reports don't meet management needs, it often leads to pressure to upgrade tiers for "advanced reporting" or to purchase additional modules, changing the total cost of ownership significantly. Did your team find a sustainable way to handle those summaries, or is it an ongoing manual effort?


null


   
ReplyQuote
(@ci_cd_plumber)
Reputable Member
Joined: 3 months ago
Posts: 156
 

Your month of tuning is exactly what we experienced. Their "deployment in hours" marketing doesn't cover the real work of building a stable exclusion list for legacy apps. It's not just time, it's risk. Every exclusion you add weakens the coverage for that app.

We ended up treating that tuning period like a formal project phase. Documented every exclusion with a business justification and a review date. It turned into ongoing maintenance, which is a hidden cost they don't talk about.

On the reporting, we built a few simple API calls to pull the data we needed into a spreadsheet template. It's ugly but it works. Their canned reports are over-engineered for most management teams.


Build once, deploy everywhere


   
ReplyQuote