Skip to main content

Deploying SentinelOne with Guardz Ultimate Plan

Updated over 7 months ago

๐Ÿš€ Deploying SentinelOne with Guardz Ultimate Plan

๐Ÿ“Œ Introduction

Integrating SentinelOne within the Guardz Ultimate Plan provides a unified security experience, simplifying the provisioning, deployment, and management of Endpoint Detection and Response (EDR) directly from the Guardz platform.

โœ… What this integration enables:

  • ๐ŸŽฏ Unified Security Management: Monitor S1-protected endpoints alongside Guardz email, cloud, and identity protections.

  • ๐Ÿ” Streamlined Threat Response: SentinelOne-detected threats are automatically surfaced in Guardz Detection & Response.

  • ๐Ÿ›ก๏ธ Continuous Device Posture Monitoring: Identify and fix security misconfigurations to maintain strong endpoint security.

๐Ÿ’ก Important Notes:

  • Managed SentinelOne (S1) cannot be enabled simultaneously with BYO-S1.

  • A separate SentinelOne deployment is required per customer.

  • Site Tokens are unique per customer and should NOT be shared across organizations.


๐Ÿ“Œ Step 1: Enabling SentinelOne in Guardz

๐Ÿ”น Activate SentinelOne Security Control

1๏ธโƒฃ Log into Guardz.
2๏ธโƒฃ Navigate to Security Controls (left sidebar) > Endpoint Security.
3๏ธโƒฃ If required, click "Get Started" to enable the SentinelOne Security Control.


๐Ÿ“Œ Step 2: Provisioning the Managed SentinelOne Account

๐Ÿ”น Select & Enable SentinelOne Managed Deployment

1๏ธโƒฃ Under SentinelOne, click "Select" for the Managed SentinelOne option.
2๏ธโƒฃ Click "Continue" to provision the SentinelOne account.
3๏ธโƒฃ Once the SentinelOne account is provisioned, click "Deploy".

๐Ÿšจ Note:

  • A customer cannot use both Managed-S1 and BYO-S1 at the same time.

  • It is possible to mix and match SentinelOne deployment types across different customers.


๐Ÿ“Œ Step 3: Deploying SentinelOne to Devices

๐Ÿ”น Choosing a Deployment Method

Guardz provides two deployment options for SentinelOne agents:

1๏ธโƒฃ Installer-based deployment
2๏ธโƒฃ Script-based deployment (RMM, GPO, Intune, etc.)

๐Ÿ”น To deploy SentinelOne:

  1. Download the Installer or Deployment Script from Guardz.

  2. View the Site Token (assigned per customer).

    • ๐Ÿ“Œ Important: Do not reuse Site Tokens across different organizations.

  3. Deploy SentinelOne to the customerโ€™s devices using the preferred method.


๐Ÿ“Œ Step 4: Configuring SentinelOne Policy Settings in Guardz

๐Ÿ”น Adjust SentinelOne Security Policies

1๏ธโƒฃ Navigate to Security Controls > Endpoint Security > SentinelOne Managed.
2๏ธโƒฃ Click the edit icon to open SentinelOne Policy Settings.
3๏ธโƒฃ Modify detection sensitivity, mitigation responses, and security rules as required.
4๏ธโƒฃ If necessary, override the global policy settings per customer.

๐Ÿ“Œ What These Settings Control:
โœ” How the SentinelOne agent behaves on each device
โœ” How threats are mitigated (e.g., auto-quarantine, isolation)
โœ” Detection thresholds for security events

๐Ÿš€ Changes made in Guardz directly impact SentinelOne agent behavior on endpoints.


๐Ÿ“Œ Troubleshooting Common Issues

๐Ÿ”น Issue: "Managed SentinelOne is not provisioning."
โœ… Fix:

  • Ensure your Guardz account is enabled for the Ultimate Plan.

  • Retry provisioning after a few minutes.

๐Ÿ”น Issue: "SentinelOne installer fails to deploy."
โœ… Fix:

  • Verify the correct Site Token is being used.

  • Ensure the endpoint has internet access during installation.

๐Ÿ”น Issue: "Devices not appearing in Guardz."
โœ… Fix:

  • Confirm that the SentinelOne agent is successfully installed on the device.

  • Check if the correct SentinelOne site is linked to the Guardz customer.

๐Ÿ”น Issue: "Threats detected in SentinelOne are not showing in Guardz Detection & Response."
โœ… Fix:

  • Verify that the SentinelOne Security Control is active in Guardz.

  • Check if the SentinelOne API connection is functioning properly.


๐Ÿ“Œ Best Practices for Deployment & Management

โœ” Deploy SentinelOne using GPO, SCCM, or RMM for scalability.
โœ” Monitor SentinelOne alerts from within Guardz Detection & Response.
โœ” Review & customize SentinelOne policy settings per customer.
โœ” Ensure Site Tokens are used correctly for each customerโ€™s deployment.


Did this answer your question?