Skip to main content

Uninstalling the Windows Agent Using the SentinelOneInstaller Package

Updated this week

Overview:

The SentinelOneInstaller.exe package includes built-in cleanup capabilities and can be used to remove the SentinelOne Windows agent.

However, we recommend first attempting to uninstall the Windows agent directly from the Guardz platform (via the Devices tab) before using the SentinelOneInstaller.exe package.


Prerequisites:

  1. Download SentinelOneInstaller.exe. from Guardz (the same package used for installation)

  2. Confirm a local upgrade:

    1. In the sidebar, click Sentinels.

      Endpoints opens.

    2. Select the Agent or Agents you want to affect.

    3. Click Actions > Agent Actions > Confirm local Upgrade.

  3. Generate a passphrase for the relevant endpoints.

    If you cannot find the Agent in the Management Console, make sure to check decommissioned Agents.


Uninstallation Steps

This process should be used instead of the SentinelOne Cleaner utility. Using the new Stateless installer (SentinelOneInstaller.exe), perform the below steps to "Clean only" the impacted endpoint. This action uninstalls the SentinelOne Agent and does not reinstall one automatically after reboot.

Note:

In normal mode - you only need the passphrase. In safe mode - you do not need the passphrase. In both cases the site token is optional.

  1. Follow all steps in the Prerequisites section.

  2. Open the command line locally on the impacted endpoint.

  3. (Optional) If you have the passphrase, run:

    SentinelOneInstaller.exe -c -k "PASSPHRASE" -t sitetoken

    Example:

    SentinelOneInstaller_windows_64bit_v22_1_5_11025.exe -c -k "PASSPHRASE" -t sitetoken

    Replace sitetoken with the site token you got from the Prerequisites section, and replace PASSPHRASE with the passphrase you generated.

  4. If Agent anti-tampering is disabled, the passphrase is unavailable. Run:

    SentinelOneInstaller.exe -c -t sitetoken

    Example:

    SentinelOneInstaller_windows_64bit_v22_1_5_11025.exe -c -t sitetoken

    Replace sitetoken with the site token you got from the Prerequisites section.

  5. Get the return (exit) code. Run:

    • From CMD:

      echo %errorlevel%
    • From PowerShell:

      $LastExitCode

  6. Review Return Codes After Installing or Updating Windows Agents to determine the potential next action.

Did this answer your question?