Skip to content
Notifications
Clear all

Anyone using SentinelOne with Intune for management? How's the experience?

1 Posts
1 Users
0 Reactions
1 Views
(@devops_grunt)
Estimable Member
Joined: 4 months ago
Posts: 159
Topic starter   [#8295]

We're evaluating endpoint security vendors right now, and SentinelOne is a frontrunner. Our environment is heavily Microsoft-based: Azure AD, Intune for MDM, and we're pushing more configuration through Intune all the time. The sales rep is pushing the "deep integration" with Intune, but I want the real-world operational view from people who've deployed and manage it daily.

I'm specifically looking for details on the management experience that you won't get from the datasheet.

* **Deployment:** Did you use the Intune integration for initial agent rollout? Was it reliable at scale, or did you fall back to a different script/mechanism? Any issues with the Win32 app packaging or detection rules?
* **Policy Management:** Are you managing SentinelOne policies (like agent settings, exclusions, behavioral engine flags) directly from the Singularity console, or are you actually pushing those configurations through Intune? If through Intune, how granular is it? Can you truly replicate all the console settings via configuration profiles, or is it a limited subset?
* **Operational Overhead:** When you need to perform a remote action (isolate device, initiate a deep scan, collect forensic data), are you doing that from within Intune or do you still live in the S1 console? The integration claims to bring actions into Intune, but is it actually useful or just a gimmick that's slower than using the native tool?
* **Troubleshooting:** Where do the logs go? If an agent fails to install or update via Intune, is the telemetry any good, or are you left cross-referencing between two separate admin consoles?

Our current stack uses a different EDR with a separate management portal, and the context switching is a pain. The promise of a unified management plane inside Intune is attractive, but I'm skeptical about how "complete" it really is. I don't want to find out we've traded one management pane for two that are loosely glued together.

If anyone has actual Intune configuration profiles or custom JSON they're using for SentinelOne settings, those snippets would be gold. Especially anything around agent update controls, registry exclusions, or network exclusions pushed via Intune.


Automate everything. Twice.


   
Quote