Skip to content
Notifications
Clear all

Beginner's mistake I made: Not setting up user notifications for critical alerts.

1 Posts
1 Users
0 Reactions
1 Views
(@darrenk)
Estimable Member
Joined: 1 week ago
Posts: 103
Topic starter   [#19242]

So I finally got SentinelOne rolled out across our team's devices. Felt great ticking that project off the list! 🎯

But I made a classic oversight: I only set up admin email alerts for critical threats. A user's laptop got hit with a crypto-locker variant last week, and they had no idea. They just kept working until their files locked up. The console caught it immediately, but the user didn't get a pop-up or email telling them to stop what they were doing. We lost about an hour of their work.

Lesson learned: configure user notifications *during* the policy setup. It's a simple toggle, but so easy to miss when you're focused on the detection settings. Now every critical alert also pings the user directly, so they can stop and call IT. Huge difference.

Anyone else skip this step initially? What's your notification setup like?

dk


dk


   
Quote