Overview

SentinelOne is an endpoint detection and response platform that uses on-device machine learning to autonomously detect, contain and roll back malicious activity on an endpoint without requiring a full reimage.

From the vendor

SentinelOne is an endpoint detection and response platform that uses on-device machine learning to detect and automatically contain malicious activity on an endpoint, without needing to send every decision back to a cloud service first. Its rollback feature can restore an endpoint to its pre-attack state, undoing file encryption or other changes, without requiring a full reimage of the machine. It suits MSPs who want strong autonomous detection with minimal manual triage built into the agent itself, and it also suits MSPs building a security practice who plan to layer their own analysts, or a partner MDR service, on top of SentinelOne's raw telemetry rather than relying on the agent alone to handle everything.

Pricing is per endpoint per month, quoted through a SentinelOne partner or distributor rather than published, with tiers based on how much extended detection and response functionality is included beyond core endpoint protection. SentinelOne integrates with major SIEM and SOAR platforms, and several third-party MDR providers build their managed services specifically on top of its API rather than treating it as just another EDR feed. RMM and PSA tools connect through partner-built connectors, so detections can flow into a service desk's normal ticket queue rather than a separate security console nobody checks. Before buying, an MSP should decide whether it wants SentinelOne's own response tooling alone or plans to add a third-party MDR service on top, since pricing and the alerting workflow differ meaningfully between those two ways of running it. It is also worth asking how SentinelOne's own reporting differentiates a fully autonomous containment from one that still needed a human analyst to intervene, since that distinction affects how much oversight a technician actually needs day to day.

Our take

SentinelOne suits MSPs who want strong autonomous detection and a genuine rollback option built into the agent, and who are comfortable either triaging alerts themselves or pairing it with a specific MDR partner. It is less of a fit for an MSP that wants a fully staffed SOC included in the base product, since that is a separate purchase layered on top. Confirm which tier includes the level of extended detection and response functionality actually needed, since pricing scales with that rather than endpoint count alone. Ask a prospective MDR partner which parts of SentinelOne's telemetry they actually monitor before assuming full coverage.

Pricing

The vendor does not publish pricing facts for SentinelOne.

Reported pricing

What MSPs report paying the vendor or a distributor, excluding VAT.

No prices reported yet.

Reports are anonymous to other MSPs and checked against your reported quantity before they count toward an aggregate.

Report a price

Features

EDR and XDR

Behavioural detection yes
Automated remediation yes
Rollback to pre-attack state yes
USB and device control unknown
Application allow-listing unknown
Offline protection yes
Threat hunting console unknown
Managed MDR add-on yes
SIEM and SOAR integration yes
RMM integration unknown
macOS support unknown
Linux support unknown

MDR and SOC

Show all 23 features

EDR and XDR

MDR and SOC

24-hour human-staffed SOC unknown
Managed threat response and isolation unknown
Own endpoint telemetry agent unknown
Identity threat detection unknown
Network monitoring unknown
Microsoft 365 monitoring unknown
Monthly threat reporting unknown
PSA integration for ticketing unknown
Multi-tenant console unknown
Works with third-party EDR unknown
Dedicated incident response unknown

Support and training

Deployment cloud
Platforms Windows, macOS, Linux, web
HQ United States
Founded 2013

Alternatives in EDR and XDR

All EDR and XDR software
Microsoft Defender for Business Endpoint protection built into the Microsoft 365 Business Premium licence. No reviews yet ThreatLocker Default-deny application control and ringfencing to stop what has not been approved. No reviews yet

Compare SentinelOne

FAQ

Is SentinelOne cloud or on-premises?
SentinelOne is available as cloud.
Does SentinelOne include a staffed SOC, or just the endpoint agent?

The core SentinelOne product is the endpoint agent and its own automated response tooling, not a staffed security operations centre. MSPs who want 24 hour human analyst monitoring on top of SentinelOne's telemetry typically add a third-party MDR provider that builds its service on SentinelOne's API, which is a separate purchase and a separate relationship from SentinelOne itself.

What does SentinelOne's rollback feature actually do?

Rollback restores an endpoint to its state before an attack, reversing file encryption or other malicious changes, without requiring a full reimage of the machine. It is one of the features that differentiates SentinelOne's autonomous response from EDR products that only detect and alert. MSPs should confirm which SentinelOne tier includes rollback, since it is tied to how much extended response functionality is licensed.

Does SentinelOne send alerts into a PSA ticket queue?

SentinelOne connects to RMM and PSA tools through partner-built connectors, so detections can open tickets in a service desk's normal queue rather than only appearing in a separate SentinelOne console. Which specific PSA connectors are available and how directly they are supported can vary, so confirm current integration coverage for the exact PSA in use before relying on it.

How is SentinelOne priced across different response tiers?

SentinelOne is priced per endpoint per month, quoted through a partner or distributor rather than published, with higher tiers unlocking more extended detection and response functionality rather than just covering more endpoints. An MSP should be clear on which specific capabilities, such as rollback or extended threat hunting, are included at the tier being quoted before comparing it against a competitor's price.

No reviews yet. Be the first MSP to review SentinelOne.