Skip to content
Notifications
Clear all

Anyone using SentinelOne with Intune for management? How's the experience?

6 Posts
6 Users
0 Reactions
10 Views
(@devops_rookie_22)
Honorable Member
Joined: 7 months ago
Posts: 311
Topic starter   [#27872]

Hi everyone! I'm pretty new to the whole endpoint security side of things. My team is exploring moving from our current AV to SentinelOne, and we're a heavy Microsoft shop using Intune for device management.

I was tasked with looking into the integration. For those already using this combo: how smooth is it really? Any gotchas with deploying the agent or managing policies through Intune? I'm especially curious about daily management – is the visibility and control good, or do you find yourself needing the SentinelOne console for everything?

Just trying to set realistic expectations as we plan this out. Any shared experiences would be super helpful



   
Quote
(@carlj)
Reputable Member
Joined: 3 months ago
Posts: 351
 

We've been on this stack for about 18 months. The deployment via Intune is straightforward if you package the MSI correctly with the proper token, but the ongoing policy management is where my skepticism kicks in.

You'll still need the SentinelOne console for meaningful visibility and control. The Intune integration is essentially a one-way street for deploying the agent and a very limited subset of policy settings. For daily ops - investigating threats, reviewing deep activity logs, or configuring behavioral AI settings - you're logging into their portal. The "management" through Intune is superficial; it's useful for ensuring the agent is present and reporting, but it's not a replacement.

Set the expectation that your security team will live in the S1 console. Intune becomes just the deployment and heartbeat mechanism. The gotcha is thinking you've unified your tooling - you haven't. You've just added another pane of glass that requires its own expertise and monitoring.


Trust but verify.


   
ReplyQuote
(@connork)
Reputable Member
Joined: 3 months ago
Posts: 216
 

That deployment bit is super useful to know. Makes sense that Intune is just for getting it on there.

As someone also new to this, I'm curious about the day to day. If you're mainly in the SentinelOne console anyway, does the Intune integration at least give you decent alerts? Or do you miss stuff if you're not constantly checking S1?

Just thinking about workflow.



   
ReplyQuote
(@consulting_contractor_mike)
Honorable Member
Joined: 6 months ago
Posts: 393
 

The deployment is indeed smooth if you get the packaging right, but user1185's point about the console dependency is critical. You'll still need it for everything beyond basic compliance.

Where the Intune integration provides actual value is in automated remediation workflows. You can set conditional access policies in Intune that block device access based on SentinelOne's health status sent via the MDM channel. That's a powerful, if narrow, control loop. For alerts, you're better off integrating SentinelOne with your SIEM or using their native email/messaging webhooks. The Intune alerting is too delayed for incident response.

Plan your training and access controls around the S1 console being the primary interface. The Intune piece becomes background infrastructure - it ensures the agent is there and can enforce a compliance boundary, but it's not a management pane.


Mike


   
ReplyQuote
(@davidr)
Honorable Member
Joined: 3 months ago
Posts: 373
 

Precisely this. The conditional access hook is the only piece that's truly integrated. We treat the health state as a compliance attribute in Intune to enforce network segmentation - if S1 reports a threat, the device gets quarantined in Azure AD conditional access before a human even looks at the alert.

But that's the limit. The real gotcha is the data latency in that MDM channel. It's fine for health status, but for any actual threat data, you're looking at a 15-30 minute delay versus near real-time in the S1 console or a direct SIEM integration. Relying on Intune for alerting means you're already behind.


—davidr


   
ReplyQuote
(@davek)
Reputable Member
Joined: 2 months ago
Posts: 281
 

The point about alerting is crucial. You'll miss a lot if you rely solely on Intune for that purpose. The data path for health status and threats via the MDM channel isn't built for speed; it's built for compliance state.

For workflow, you have two practical options. Integrate SentinelOne directly with your ITSM or SIEM for operational alerts. Alternatively, you can configure the S1 console to send email alerts for specific threat severities to a team mailbox or a chat webhook. That gives you near real-time notification without requiring constant manual logins. Intune's role is to enforce the consequence, like revoking network access, not to be the source of truth for the alert itself.


CPU cycles matter


   
ReplyQuote