Configuring SentinelOne Connector

Configuring SentinelOne Connector

This article explains how to configure the SentinelOne connector in Lenovo Device Orchestration (LDO). Once configured, the integration enables ThinkShield Firmware Assurance (TSFA) to send security posture change events to SentinelOne, improving security monitoring and event visibility.

Prerequisites

Before configuring the connector, ensure that:
  1. All devices you want to integrate are already enrolled in LDO. For instructions, see Onboarding Windows Devices.
  2. A TSFA license is assigned to the devices. For instructions, see Assigning and Managing Licenses
  3. You have an active SentinelOne console with a SentinelOne Complete license, and the SentinelOne agent is installed on all devices you want to integrate.
  4. You have generated an API key in SentinelOne.
Notes
You must have SentinelOne Administrator permission at either the Site or Account level, depending on where you want the integration data to be written and displayed.

Configuring the Connector

  1. Go to Configuration & Settings > Organization Account > Connectors
  2. Click Add Connection
  3. Paste the API key generated in SentinelOne. 
  4. In Tenant, enter a name to identify the SentinelOne tenant associated with your LDO account.
  5. Click Connect
  6. LDO verifies the API credentials. If the connection is successful, the connector status changes to Active

Verifying the Integration

To verify that the integration is working correctly:
  1. In the SentinelOne console, go to Event Search. 
  2. Set the data source filter to All Data. 
  3. Run the following search: 
dataSource.vendor = 'Lenovo'
event.type = 'ThinkShield Firmware Assurance'

How the Integration Works

When the connector is active, TSFA sends the events to SentinelOne whenever a device incident results in a change to the device's security posture. For example:
  1. Healthy to Unhealthy 
  2. Healthy to Suspect 
  3. Suspect to Healthy
SentinelOne displays the event details, including the updated security posture and the corresponding timestamp, in the customer dashboard. The dashboard is created and configured by the customer in collaboration with their SentinelOne representative through the SentinelOne portal.

Disconnecting SentinelOne Connector from LDO

To disconnect the SentinelOne connection, edit or delete the API key in SentinelOne. For information, read Creating an API key in the THINKSHIELD XDR Powered by SentinelOne knowledge base.