Skip to main content

SentinelOne Agent Requirements on Windows

This article covers the OS, hardware, and dependency requirements for deploying the SentinelOne Agent on Windows endpoints managed through Guardz.

Important: Windows Agent packages released after July 1, 2026 use a code-signing certificate from SSL.com in place of DigiCert, for a subset of code signing. This is separate from the TLS certificate migration for Agent-to-Console communication. It does not apply to the 26.1.2 GA Agent, but does apply to the Windows 26.2.1 EA Agent. Most endpoints require no action.

Windows OS groups

SentinelOne divides Windows operating systems into three groups. The Agent version you install depends on which group the endpoint's OS falls into.

Group

Windows OSs

Details

1 (Modern)

Windows 11, 11 23H2, 11 24H2 (64-bit), 11 25H2* (64-bit)
Windows 10 (64-bit)
Windows 8.1 (64-bit)
Windows Server IoT 2019/2022/2025
Server/Server Core 2025
Server/Storage Server/Server Core 2022 (64-bit)
Server/Server Core 2019 (64-bit)
Server/Storage Server/Server Core 2016 (64-bit)
Server/Storage Server 2012 R2 (64-bit)

See Agent installers for Group 1

2 (Legacy Plus)

Windows 10 (32-bit)
Windows 8.1 (32-bit)
Windows 8 (32/64-bit)
Windows 7 SP1 (32/64-bit)
POSReady 7
Server/Storage Server/Server Core 2012 (not R2, 32/64-bit)
Server 2008 R2 SP1 (32/64-bit)

The only supported Agent version for this group is 23.4. See Agent installers for Group 2

3 (Legacy)

Windows Vista SP2 (32/64-bit)
Windows XP SP3 (32/64-bit)
Windows XP SP2 (64-bit AMD64/EM64T)
Windows Embedded POSReady 2009
Server 2008 SP2 (not R2, 32/64-bit)
Server 2003 R2 SP2 (32/64-bit)
Server 2003 SP2 (32/64-bit)

See Agent installers for Group 3

*Windows 11 25H2 is supported with Agent versions 24.2, 25.1, and 25.2.

Agent installers for Group 1 Windows OSs (Modern)

For endpoints running any Group 1 OS, use the Standard Agent installer: SentinelOneInstaller_windows_64bit_v<version>.exe or SentinelOneInstaller_windows_64bit_v<version>.msi.

Note: Group 1 installers use 64-bit architecture only. 32-bit Agent installers are not compatible with Group 1 endpoints.

Agent installers for Group 2 Windows OSs (Legacy Plus)

For endpoints running any Group 2 OS, use version 23.4: SentinelOneInstaller_windows_32/64bit_v23.4.exe or .msi. Earlier versions are no longer supported, as they are end of life.

Note: Windows 8.1 and Windows 10 in 32-bit architecture can only run up to Agent version 23.4.x. On 64-bit architecture, Windows 8.1 or Windows 10 endpoints can run Agent version 24.1 or later — this is recommended as best practice.

If critical security issues arise, SentinelOne may release a new Legacy Plus Agent version with security enhancements and bug fixes. The Legacy Plus Agent may not receive new features unrelated to endpoint security posture.

Agent installers for Group 3 Windows OSs (Legacy)

For endpoints running any Group 3 OS, use the Legacy Agent Installer: SentinelOneInstaller-32/64bit_windows_legacy_v<version>.exe.

Both the x64 and x86 Legacy Agent installers are essentially identical and contain artifacts for both architectures. The installer determines and installs the appropriate binaries based on the target system's architecture.

Agent installer compatibility with each Windows OS group

Agent Installer

Group 1 (Modern)

Group 2 (Legacy Plus)

Group 3 (Legacy)

Version 24.1 and higher

Supported — 64-bit only

Not supported

Not supported

Version 23.4 (Legacy Plus)

Not supported

Supported — 32 or 64-bit (some OSs)

Not supported

Legacy Agent

Not supported

Not supported

Supported — 32 or 64-bit

Note: Supported editions include Home, Pro, Pro for Workstations, Enterprise, Education, Pro Education, Enterprise LTSC, Embedded, and Windows 10 IoT Enterprise. Windows Agent versions 25.1.1.223 and higher support Windows 365. Mobile and Windows 10 IoT Core are not supported.

Required Microsoft security updates per operating system

Important: After installing the security updates below, restart the endpoint and run the Agent installation again.

Windows OS

Required Microsoft security updates

Windows 365, Windows Server/Server Core 2025, Windows Server IoT 2025

None

Windows 11, Windows 11 23H2, Windows 11 24H2

None

Windows Server/Server Core 2022, Windows Server IoT 2022

KB5005619

Windows Server/Server Core 2019, Windows Server IoT 2019

KB5005625

Windows Server/Storage Server/Server Core 2016

KB4093119 (ensures old logs in ProgramData\Sentinel\logs are deleted — an endpoint should have only 16 log files, totaling no more than 1.6 GB)

Windows 10 (32/64-bit)

KB4093119 (log cleanup, as above)
KB5005625 for version 1809
KB5005611 for version 1903 and later
KB5005624 for version 1909

Windows 8.1 (64-bit), Windows Server/Storage Server 2012 R2

KB2919442
KB2919355 (includes KB2932046, KB2959977, KB2937592, KB2938439, KB2934018)
KB3042058 (updates default TLS cipher suites)
KB5022661 (Azure Code Signing support)

Windows 8.1 (32-bit)

KB2919355 (includes KB2932046, KB2959977, KB2937592, KB2938439, KB2934018)
KB3042058
KB5022661

Windows 8, Windows Server/Storage Server/Server Core 2012 (not R2)

KB3003729
KB3042058

Windows 7 SP1, Windows Server 2008 R2 SP1, POSReady 7

KB2758857, KB4457144, KB4490628, KB3042058, KB3140245, KB2864202, KB3020369, KB5022661, KB3033929 (SHA2), KB2685811

Windows Vista SP2, Windows Server 2008 SP2 (not R2)

KB4474419, KB2685811

Windows XP SP2 (64-bit), Windows XP SP3, Windows Embedded POSReady 2009, Server 2003 SP2/R2

KB968730

Notes:

  • If a KB2919355 error appears on Windows 8.1 or Server 2012 R2 even when the update is installed, enable these cipher suites: TLS_DHE_RSA_WITH_AES_256_GCM_SHA384, TLS_DHE_RSA_WITH_AES_128_GCM_SHA256, TLS_RSA_WITH_AES_256_GCM_SHA384, TLS_RSA_WITH_AES_128_GCM_SHA256.

  • On Windows 7, KB3140245 enables TLS 1.2 as the default secure protocol in WinHTTP and requires a registry subkey addition — Management-Agent communication uses TLS 1.2, which is not enabled by default on Windows 7.

  • For Agent EXE installers earlier than version 22.1, .NET Framework 4 or later is required. This is not needed for the MSI installer or the EXE installer from Agent version 22.1 onward.

Minimum hardware requirements

Minimum

Recommended

1 GHz CPU or better

Dual-core

1 GB RAM
(0.5 GB for Agent version 26.1.1+)

2 GB RAM or more

2 GB free disk space on the Windows partition
(3.5 GB for Agent version 26.1.1+), plus 10% of disk per drive for VSS snapshots

3 GB recommended, plus 10% of disk per drive for VSS snapshots

Note: These are the resources the Agent needs to run — not a minimum spec for the system overall. Even if an endpoint technically meets these numbers, contention from other applications can still cause Agent performance issues.

  • Upgrading via the MSI installer requires an additional 350 MB of disk space.

  • Upgrading via the SentinelOneInstaller requires an additional 500 MB of disk space.

  • The Agent is not supported in environments using WyseRAM disk.

Windows Agent dependencies

Important: Ensure endpoints are updated with all applicable Microsoft patches for the OS, including — but not limited to — the updates listed above.

Dependency

Notes

Windows Defender

On Windows Servers, Microsoft Defender Antivirus does not enter passive or disabled mode when SentinelOne is installed. Guardz recommends uninstalling Microsoft Defender Antivirus on Windows Servers to avoid interoperability issues. Behavior varies by Windows OS version.

Volume Shadow Copy Service (VSS)

Configure VSS before installing the Agent. The Agent fills the available VSS allocation, typically 10% of the system drive.

Windows Event Log

The Windows Event Log service must be enabled before installing the Agent.

GPO Chrome Extensions

The SentinelOne Chrome extension is installed as part of the Agent. Chrome extensions must be enabled when installing or upgrading via GPO.

GPO Privileges

The administrator running the installation via group policy must have RESTORE and TAKE OWNERSHIP privileges to prevent an installer crash.

Sectigo

If the endpoint does not receive Windows updates, Sectigo must be installed manually for the Agent to communicate with the Management console.

Azure Code Signing (Agent 22.3+)

If the endpoint does not receive Windows updates, KB5022661 must be installed, since the SentinelOne installation package is signed using a Microsoft-controlled root certificate.

Windows Root Certificates

Keep Windows Root Certificates up to date to avoid invalid signature errors.

Windows Services set to Automatic

Base Filtering Engine Service and Windows Update Service. Applies only to Legacy and Legacy Plus Agents.

USN change journal

Required for Full Disk Certificate Scan and improves Full Disk Scan performance.

Required Windows Administrator permissions

The Windows Agent installer is designed to work on supported Windows endpoints with default settings. If an environment has been hardened, the installer may fail or crash unless the following requirements are met:

  • Installation requires Administrator permissions, with write access to C:\Users\Public\Documents and the C:\ root. Install only as an Administrator (local, remote, GPO, or otherwise).

  • The Agent Anti-Tampering process restores and takes ownership of files during installation — the installing user must have Restore and Take Ownership privileges (default for Windows Administrators).

  • The installer adds a trusted publisher to the machine certificate store to sign the PowerShell profile script used by PowerShell Protection. The local Administrator must have permission to install trusted publisher certificates.

  • The installer creates an ELAM driver backup in the ELAM backup directory (ELAMBKUP), configured in the system registry. This directory must exist.

  • The Agent installs drivers to the Program Files directory, which must reside on the system boot volume.

  • The Windows System user is required — do not delete it.

  • The Windows Management Instrumentation (WMI) service (winmgmt) is required.

Support for ARM-based architecture

From Agent version 24.1.1, SentinelOne supports a version of the Windows Agent compatible with ARM-based endpoints. It installs the same way as any Windows Agent 22.1+ EXE.

Limitations:

  • Compatible only with Windows 11 on ARM processors.

  • On a self-hosted Management Console, run the following command before uploading the ARM package:
    sudo sentinelmgmtctl set_global_switches win_arm_64_packages --value on

  • Identity Detection and Response is not currently supported on this version.

  • Ensure no previous Agent installation exists on the endpoint before installing.

Did this answer your question?