Skip to content
Notifications
Clear all

Help: Can't get the agent to install on a bunch of our older Windows 10 builds.

2 Posts
2 Users
0 Reactions
25 Views
(@chloep)
Reputable Member
Joined: 3 months ago
Posts: 292
Topic starter   [#17608]

Alright, let's commiserate. I've just spent the better part of a Tuesday afternoon wrestling with SentinelOne's agent on what I can only describe as a digital geriatric ward—our collection of legacy Windows 10 builds (we're talking 1809, 1903... the classics). The deployment console cheerfully reports "success," but the devices are either ghosting us entirely or throwing a spectacular array of exit codes that feel like they're written in ancient Enochian.

I'm convinced S1's installer has a secret, deeply held prejudice against older Windows builds. The "system requirements" page is, as always, hilariously optimistic. "Windows 10 (all builds)" it says. Sure, Jan.

Here's the carnage so far, because I know someone will ask for the ritualistic steps:
* Cleaned the target machines with the official SentinelOne Cleaner utility (version 3.0.3). No residual ghosts from previous AVs, I promise.
* Verified all the usual suspects: admin rights, .NET framework states, pending reboots (none), disk space (plenty).
* Attempted both the MSI and the EXE packages from the portal, with every silent flag combo under the sun. The logs are... unhelpful. Mostly pointing to generic "installation failure" or a cryptic 1603.
* The real kicker? A handful of nearly identical machines from the same batch took the agent just fine. The inconsistency is maddening.

The core question I'm hitting—and where I'd love this community's forensic expertise—is what's the *actual* deep dependency we're missing on these older builds? Is it a specific C++ redistributable vintage? A Windows Update that's not listed as critical but S1 secretly pines for? A specific service status that's different post-1909?

I'm looking for the kind of obscure registry key or system file check that their support docs gloss over in a single bullet point. Has anyone successfully autopsied a failed install on 1809/1903 and found the smoking gun?

Pulling my hair out over here, and the "just upgrade Windows" crowd from management is starting to circle.

—chloe


Demos are just theater. Show me the real workflow.


   
Quote
(@avab)
Reputable Member
Joined: 3 months ago
Posts: 252
 

Oh, you're trusting the official cleaner utility? That's your first mistake. That tool is famous for leaving behind registry keys and service entries that the new installer chokes on. I've had to write custom PowerShell scripts to really scorch the earth before a reinstall on these older builds.

The "all builds" claim is a classic vendor move. It technically installs, so they can check the box. They don't mention the agent might be a brain-dead zombie consuming cycles without providing any actual visibility or protection. Have you checked if the service is even starting correctly, or just stuck in a permanent "start pending" state? The console will call that a success, too.

You need to look at the MSI verbose logs, not the S1 wrapper logs. Run the installer manually from an elevated command prompt with `/lvx* log.txt`. The error is usually buried in there, something like a failed custom action or a rejected DLL registration.


Question everything


   
ReplyQuote