SentinelOne Integration

Introduction

SentinelOne delivers AI-powered endpoint protection, combining next-gen antivirus and EDR/XDR in a single platform. Managed through the Singularity console, it uses autonomous AI and automation to prevent, detect, and rapidly remediate threats in real time.

The SentinelOne integration allows you to easily install the SentinelAgent or automate the installation using an Endpoint Security Policy within Splashtop. More capabilities such as viewing high-level threat and alert details are coming soon.

The integration supports both existing SentinelOne licenses and licenses purchased through Splashtop.

Supported Subscriptions & Licensing

Option 1: Purchase SentinelOne Through Splashtop

The SentinelOne integration is included when you purchase SentinelOne through Splashtop. Available offerings include the following SentinelOne products and add-ons:

  • Singularity Control (NGAV)
  • Singularity Complete (EDR)
  • Wayfinder MDR Essentials

Contact Us 

Option 2: Use Your Existing SentinelOne Licenses (BYOL)

To use existing SentinelOne licenses (Bring Your Own License), your team must have Splashtop Autonomous Endpoint Management (AEM) enabled.

With AEM enabled, the SentinelOne integration is included and supports both existing SentinelOne licenses and licenses purchased through Splashtop.

Requirements

  • Windows 10 and up; Streamer v3.8.2.0 and up
    (Exceptions: Windows 8/8.1, Windows server 2003)
  • macOS 14 and up; Streamer v3.8.2.0 and up
  • Your account must be using the SentinelOne Singularity Operations Center

Getting Started

Enabling the Integration
  1. Sign in to your SentinelOne Console with an admin account.

  2. In the left menu, select the Policies and settings section, then go to User Management -> Service users.
    Click New Service User.
    For Service Name and Description, enter any values you prefer.
    Select the Account or Site(s) that you want to manage. When choosing a role for the token, the role must include the following API scopes at minimum. The pre-defined Admin, IT, and IR Team roles include these permissions. Alternatively, you can create a custom role on the Roles tab:

    Category

    Minimum Permissions

    Endpoints View
    Show Passphrase
    Sites View
    Unified Alerts* Endpoint Alerts
    (View, Manage)

    * The integration will support displaying alert/threat info later in Q2 2026.
    Click Create.
    You’ll see the new API token - make sure to copy and save it.

  3. In the Splashtop console (my.splashtop.com/my.splashtop.eu), go to Management > Settings > AV / EDR Integrations, then click Detailed Setup.

  4. Enter your SentinelOne console URL and enter the API token you copied from SentinelOne.
    Once you see the Authorized badge in the top-right corner, you’re all set, the integration is live!

S1teamSettings-en_us.png

 

Installation

Once the integration is enabled, the Splashtop Streamer will automatically detect existing Sentinel Agent installations associated with your provided SentinelOne API token. Confirmed installations will show "Sentinel Agent" in the Primary Security column on the Endpoint Security page.

dashboard_installed-en-us.png

For enforcing Sentinel Agent installation or deploying new installations, use one of the methods below.

Install by Endpoint Policy (Automatic Enforcement)

Use Endpoint Policies to automatically install the Sentinel Agent on assigned computers. Splashtop attempts the installation up to three times every two hours until the agent is successfully installed. If the SentinelAgent is removed, Splashtop will automatically attempt to reinstall it using the same retry behavior.

  1. In the Splashtop console (my.splashtop.com/my.splashtop.eu), go to Management > Endpoint Policies, then create or edit an existing policy.
  2. Click the Endpoint Security tab and toggle it on.
    Select SentinelOne in the Security Product dropdown menu.
    Click the Installation checkbox to enable automatic installation.

    s1policy-en_us.png

Install from Endpoint Security Page (On-Demand)

On-demand installation is initiated by an admin and installs silently without user interaction. This option is useful if you do not want Splashtop to automatically enforce agent installation, or if you want to install the agent immediately on a computer without waiting for the two-hour policy retry interval.

  1. In the Splashtop console (my.splashtop.com/my.splashtop.eu), go to Management > Endpoint Security.
  2. Select/checkbox the computers that you would like to install SentinelOne on, then click Actions > SentinelOne > Install SentinelOne Agent.
    s1_install-en_us.png
Email Notifications

SentinelOne notification emails are managed through Endpoint Policies, separate from other antivirus notifications that are configured at Team Settings > Endpoint Security.

Automatic agent installation and notification emails are configured independently within the policy. You can enable SentinelOne notifications without enabling automatic agent installation. 

  1. In the Splashtop console (my.splashtop.com/my.splashtop.eu), go to Management > Endpoint Policies, then create or edit an existing policy.
  2. Click the Endpoint Security tab and toggle it on.
    Scroll to Notification Settings and select the alerts you would like to receive.
    s1_notifications-en_us.png
  3. Click the Edit Email List button to configure the email recipients.
    You can type or select users/user groups from the dropdown menu.
    Team users will be shown in blue, while external emails will be shown in grey.
    crowdstrike_email_list_en-us.png
Viewing Threats/Alerts

Viewing SentinelOne threats/alerts will be supported in the latter half of Q2 2026.

0 out of 0 found this helpful