Configuring SentinelOne Connector

Configuring SentinelOne Connector

This article explains how to configure the SentinelOne connector in Lenovo Device Orchestration (LDO). Once configured, the integration enables ThinkShield Firmware Assurance (TSFA) to send security posture change events to SentinelOne, improving security monitoring and event visibility.

Prerequisites

Before configuring the connector, ensure that:
  1. All devices you want to integrate are already enrolled in LDO. For instructions, see Onboarding Windows Devices.
  2. A TSFA license is assigned to the devices. For instructions, see Assigning and Managing Licenses
  3. You have an active SentinelOne console with a SentinelOne Complete license, and the SentinelOne agent is installed on all devices you want to integrate.
  4. You have generated an API key in SentinelOne.
Notes
You must have SentinelOne Administrator permission at either the Site or Account level, depending on where you want the integration data to be written and displayed.

Configuring the Connector

  1. Go to Configuration & Settings > Organization Account > Connectors
  2. Click Add Connection
  3. Paste the API key generated in SentinelOne. 
  4. In Tenant, enter a name to identify the SentinelOne tenant associated with your LDO account.
  5. Click Connect
  6. LDO verifies the API credentials. If the connection is successful, the connector status changes to Active

Verifying the Integration

To verify that the integration is working correctly:
  1. In the SentinelOne console, go to Event Search. 
  2. Set the data source filter to All Data. 
  3. Run the following search: 
dataSource.vendor = 'Lenovo'
event.type = 'ThinkShield Firmware Assurance'

How the Integration Works

When the connector is active, TSFA sends the events to SentinelOne whenever a device incident results in a change to the device's security posture. For example:
  1. Healthy to Unhealthy 
  2. Healthy to Suspect 
  3. Suspect to Healthy
SentinelOne displays the event details, including the updated security posture and the corresponding timestamp, in the customer dashboard. The dashboard is created and configured by the customer in collaboration with their SentinelOne representative through the SentinelOne portal.

Disconnecting SentinelOne Connector from LDO

To disconnect the SentinelOne connection, edit or delete the API key in SentinelOne. For information, read Creating an API key in the THINKSHIELD XDR Powered by SentinelOne knowledge base.

    • Related Articles

    • Getting Started with TSFA

      ThinkShield Firmware Assurance (TSFA) evaluates device security posture based on security events generated by managed devices. TSFA can be used as a standalone solution or together with Lenovo Device Orchestration (LDO). A TSFA license is required to ...
    • Configuring Microsoft Intune Connector

      I. Generate Client Secret and Apply Permissions Sign in to Microsoft Azure Portal. Go to Microsoft Entra ID > App registrations and select New registration. Register a new application, and securely note the following generated values: Application ...
    • Troubleshooting TSFA

      TSFA device issues are typically related to compatibility, provisioning, or communication between the device and the system. Use the device status and security posture values to identify and troubleshoot these conditions. Device Status Issues BIOS ...
    • Configuring TSFA Settings

      Managing Incident Severity and Notifications The TSFA Settings page allows administrators to configure incident notifications and manage prevalence thresholds used by ThinkShield Firmware Assurance (TSFA) to identify widespread issues. This feature ...
    • Configuring Google Workspace Integration

      This article explains how to configure Google Workspace for ChromeOS within Lenovo Device Orchestration (LDO). This setup enables LDO to securely connect with your organization’s Google Cloud environment and retrieve ChromeOS device data for ...