Configuring SentinelOne Connector
This article explains how to configure the SentinelOne connector in Lenovo Device Orchestration (LDO). Once configured, the integration enables ThinkShield Firmware Assurance (TSFA) to send security posture change events to SentinelOne, improving security monitoring and event visibility.
Prerequisites
Before configuring the connector, ensure that:
- All devices you want to integrate are already enrolled in LDO. For instructions, see Onboarding Windows Devices.
- A TSFA license is assigned to the devices. For instructions, see Assigning and Managing Licenses.
- You have an active SentinelOne console with a SentinelOne Complete license, and the SentinelOne agent is installed on all devices you want to integrate.
- You have generated an API key in SentinelOne.
You must have SentinelOne Administrator permission at either the Site or Account level, depending on where you want the integration data to be written and displayed.
Configuring the Connector
- Go to Configuration & Settings > Organization Account > Connectors.
- Click Add Connection.
- Paste the API key generated in SentinelOne.
- In Tenant, enter a name to identify the SentinelOne tenant associated with your LDO account.
- Click Connect.
- LDO verifies the API credentials. If the connection is successful, the connector status changes to Active.
Verifying the Integration
To verify that the integration is working correctly:
- In the SentinelOne console, go to Event Search.
- Set the data source filter to All Data.
- Run the following search:
dataSource.vendor = 'Lenovo'
event.type = 'ThinkShield Firmware Assurance'
How the Integration Works
When the connector is active, TSFA sends the events to SentinelOne whenever a device incident results in a change to the device's security posture. For example:
- Healthy to Unhealthy
- Healthy to Suspect
- Suspect to Healthy
SentinelOne displays the event details, including the updated security posture and the corresponding timestamp, in the customer dashboard. The dashboard is created and configured by the customer in collaboration with their SentinelOne representative through the SentinelOne portal.
Disconnecting SentinelOne Connector from LDO
To disconnect the SentinelOne connection, edit or delete the API key in SentinelOne. For information, read
Creating an API key in the THINKSHIELD XDR Powered by SentinelOne knowledge base.
Related Articles
Getting Started with TSFA
ThinkShield Firmware Assurance (TSFA) evaluates device security posture based on security events generated by managed devices. TSFA can be used as a standalone solution or together with Lenovo Device Orchestration (LDO). A TSFA license is required to ...
Configuring Microsoft Intune Connector
I. Generate Client Secret and Apply Permissions Sign in to Microsoft Azure Portal. Go to Microsoft Entra ID > App registrations and select New registration. Register a new application, and securely note the following generated values: Application ...
Troubleshooting TSFA
TSFA device issues are typically related to compatibility, provisioning, or communication between the device and the system. Use the device status and security posture values to identify and troubleshoot these conditions. Device Status Issues BIOS ...
Configuring TSFA Settings
Managing Incident Severity and Notifications The TSFA Settings page allows administrators to configure incident notifications and manage prevalence thresholds used by ThinkShield Firmware Assurance (TSFA) to identify widespread issues. This feature ...
Configuring Google Workspace Integration
This article explains how to configure Google Workspace for ChromeOS within Lenovo Device Orchestration (LDO). This setup enables LDO to securely connect with your organization’s Google Cloud environment and retrieve ChromeOS device data for ...