EDR - SentinelOne Windows Installation

Purpose: This is to install SentinelOne on a client's Windows PC for the EDR (End Point Detection and Response) Package

Login to TNN N-Ablehttps://n-able.secureworkplace.net/IndexAction.action

Navigate to the company in N-able

Select All Devices

Check for currently installed Anti-Virus

Select the machine to install SentinelOne 

Select Asset

Select Applications

Check for currently installed Antivirus

Note: if Antivirus is not uninstalled before installing SentinelOne, there can be performance issues or the script may not run.

In this case we can see that Bitdefender is installed. You need to contact the client, connect to the PC, and uninstall the Antivirus before continuing.

Once the current Antivirus is uninstalled Login to SentinelOne to get the Login URL, Username, and Password.

Login to SentinelOne

You need to login to Connect Wise to get the SentinelOne login URL and the Site Token

Login to ConnectWise > Service Desk Tab > Configurations

Search Visory or SentinelOne > Select "N-Able SentinelOne StandAlone Portal for Vigilance (SWIZZNET:USE THIS ONE)"

Scroll to the bottom of the Configuration and you will see the username, password, and login URL

Open a new tab in your browser and go to https://usea1-swprd5.sentinelone.net/login

Enter the Username and Password > Login

Select the arrow to open the navigation pane

Search for the company name (In this case Shuniyaaa Financial Services

Click Sentinels on the left

Select Site Info from the top menu

Click the copy to clipboard icon and copy the site token

Go back to N-Able > Company name > All Devices > select the PC to install SentinelOne > Add Task > Run an Automation Policy or you can select the Actions tab on the left > Run an Automation Policy

Under Automation Policy enter KB script number 90701 > Select the "SentinelOneInstall_MSI" policy

Paste the Site Token you saved to your clipboard from the SentinelOne Management Console earlier

Select Targets > Add the Device to install SentinelOne

Select Schedule

Type: Now

Time to Run: If you leave set to Only at specified time, the script will run right away or you can set it to run when you need it too > select Save to run the script

Go back to SentinelOne Management console > Under the company name select ENDPOINTS 

You should now see the users PC listed and in the Pending Request status. Once the PC is rebooted, the Pending request status should clear. 

 

Uninstalling SentinelOne

Onboarding does not have the permissions to uninstall SentinelOne. 

If we get a request, create a ticket in CW and assign it to the SecureWorkplace board.

Comments

0 comments

Please sign in to leave a comment.