What is it all about?
This article lists the SentinelOne policy settings Guardz recommends for every site, with a one-line explanation of each. It covers Detection Engines, Agent Security Settings, Event Collection and Malicious Macro Mitigation.
Please note: If your console looks different from what is described here, contact Guardz MDR before changing anything.
Where to find the Policy settings
All settings in this article are on the Policy page of the SentinelOne console.
Sign in to your SentinelOne console.
Use the scope selector at the top of the page to select your account and site.
In the left menu, select Policies and settings.
Under Products and services, find Endpoint Security and Cloud Workload Security.
Select Policy.
Protection Mode: Malicious Macro Mitigation
Guardz recommends ticking Malicious Macro Mitigation. It removes the harmful macro and keeps the Office document, instead of quarantining the whole file.
Please note: This setting works only while Static AI is enabled and Malicious Threats is set to Protect.
For the rest of Protection Mode (Protect/Detect, Kill, Quarantine, Remediate, Rollback), see SentinelOne Deployment Checklist and Mitigation and Threat Actions.
Detection Engines
Guardz recommends enabling all Detection Engines.
Each engine looks for a different kind of attack, such as malicious files, scripts, in-memory attacks, or an attacker moving between devices. Switching one off leaves that kind of attack unseen.
Please note: A switch that is greyed out cannot be changed from your policy. Leave it as it is.
Agent Security Settings
Guardz recommends turning on all five settings below.
Setting | Guardz recommends | What it does |
Snapshots | On | Keeps Windows restore points so Rollback can bring files back after a ransomware attack. |
Anti-Tamper | On | Stops anyone, including malware or a local user, from switching off or removing the agent. |
Scan New Agents | On | Scans the whole device when SentinelOne is first installed, to find threats already there. |
Suspicious Driver Blocking | On, Windows Unsigned Drivers only | Blocks suspicious drivers with no publisher signature. Signed hardware vendor drivers are left alone. |
Logging | On | Keeps the agent's own logs on the device so Guardz and SentinelOne support can troubleshoot. |
Please note: Anti-Tamper events are not sent to the MDR queue. Monitor agent health directly in the SentinelOne console.
Event Collection
Guardz recommends keeping Event Collection enabled, with every event type and Advanced Setting left as shown in the screenshot below, including Data Masking and Focused File Monitoring.
Event Collection records what happens on each device: programs started, files changed, network connections and logins. Guardz MDR uses these records to investigate every alert.
Please note: Activity that was not collected cannot be recovered later.
