SentinelOne Agent Admin Guide.
SentinelOne Agent Installation v22.1.2.217 x64 Aug 2022
(For Secondary scanning)
Installation:
Our secondary AV scanner - SentinelOne Agent, can be deployed to our PCs using one of the following methods:
For Intune/ Co-managed devices, use the AAD group - AAD-Device-CG-SentinelOne-Install. The install should get triggered in 30 mins.
For SCCM managed/ Servers/ expedite install, download the SentinelOne .exe installer and save it to C:\temp : SentinelOneInstaller_windows_64bit_v22_1_4_10010.exe
To run the .exe installer, open an elevated cmd prompt and go to c:\temp. Then run this line below to begin the install:
SentinelOneInstaller_windows_64bit_v22_1_4_10010.exe --dont_fail_on_config_preserving_failures -t eyJ1cmwiOiAiaHR0cHM6Ly91c2VhMS0wMTYuc2VudGluZWxvbmUubmV0IiwgInNpdGVfa2V5IjogIjQzYThhZjIyMDA4NGZhMjkifQ==
(P.S. Ensure our site token is included in the command: eyJ1cmwiOiAiaHR0cHM6Ly91c2VhMS0wMTYuc2VudGluZWxvbmUubmV0IiwgInNpdGVfa2V5IjogIjQzYThhZjIyMDA4NGZhMjkifQ== )
Alternatively, to run the installer from PowerShell:
./SentinelOneInstaller_windows_64bit_v22_1_4_10010.exe --dont_fail_on_config_preserving_failures -t eyJ1cmwiOiAiaHR0cHM6Ly91c2VhMS0wMTYuc2VudGluZWxvbmUubmV0IiwgInNpdGVfa2V5IjogIjQzYThhZjIyMDA4NGZhMjkifQ==
Once the install is complete (either thru Intune/ standalone .exe), a full scan will occur on the device in the background within the next hour. When instructed by Security, please retrieve the scan report/ resultant log files below from the device and forward them to ITSecurityAdmin@CGF.com .
C:\ProgramData\Sentinel\logs\*.scan_report.txt (e.g. 133034080899000000.scan_report.txt)
C:\ProgramData\Sentinel\logs\LastScanReport.log
Uninstallation:
Please email ITSecurityAdmin@cgf.com to request an Agent removal if necessary/ after a full scan is complete. The uninstallation will either have to be initiated thru the SentinelOne console, or by using a standalone local cleanup tool.