Onboarding Devices
Device onboarding is the process of registering a device in the system so it can be managed and receive additional functionality. The onboarding process is the same as for LDO devices and is described in
LDO > Device Management > Onboarding articles. After successful onboarding:
- The device appears in Device Management > Devices.
- The device is ready for license assignment.
Assigning Licenses to Devices
Assigning a TSFA license enables TSFA functionality on a device. Licenses are assigned and managed in Organization Settings > Organization Account.
Purchasing a TSFA license at the organization level does not automatically activate TSFA. You must assign a TSFA license to each device. For more information, see
Assigning and Managing Licenses.
After a license is assigned:
- The TSFA plugin is installed on the device.
- TSFA data becomes available, and the device status changes to Active. If the device does not appear as Active, see Troubleshooting TSFA.
- The device starts reporting firmware events from BIOS and the embedded controller on the device.
How TSFA Collects and Surfaces Device Data
Security events appear on the Issues and Errors tab on the Device Details page. To access these events, go to:
Device Management > Devices > select a device > Device Details > Issues and Errors, then select Security Events from the search box.
These events are processed using predefined rules to determine the device’s security posture. The system updates the posture automatically as new events are received. For more information, see
Device Status and Security Posture.
TSFA device data is available in:
- The Dashboard, through TSFA-specific widgets.
- Device Management > Devices list, where you can view device-level TSFA information. To view detailed information, select a device to open the Device Details page.
For more information, see:
TS XTR Firmware Intelligence Connector
LDO provides a connector that integrates ThinkShield Firmware Assurance (TSFA) with SentinelOne. Once the connector is configured, whenever a device's security posture changes, such as from Healthy to Unhealthy or from Suspect to Healthy, TSFA automatically sends the corresponding event to SentinelOne.