SentinelOne logo
Drafting

SentinelOne

Every endpoint SentinelOne protects — health, threats, policy — answerable in plain English.

SentinelOne is the endpoint protection on your clients' machines, and the console knows things your RMM cannot: whether the agent is actually online and current, which threats are open and for how long, and which sites are on a detect-only policy. Connect your console and a session can read all of it across every site — agents, threats and their timelines, sites and licences, groups, policies and exclusions, application inventory and vulnerability counts. Read-only today: no credential we issue carries a write scope, and no connected session can reach a write tool, so nothing here isolates a machine, kills a process, changes a policy or edits an exclusion. Switchboard connects through an MSPStuff-hosted MCP server, so there is nothing to install and no API token to hand your techs.

In development. Not available to connect yet.

The path to connecting

A clear view of what is being built.

Explore the planned scope while this integration is in development. Successful sessions will depend on the released tools and your granted access.

SentinelOne · planned coverage
  1. 01
    Your platformSentinelOne
  2. 02
    Integration in developmentCoverage and setup are being prepared.
  3. 03
    Preview the documented scopeRead the planned questions and connection requirements below.
Conceptual setup. This integration is in development.

The story

What changes once it’s connected.

"Installed" is not "protected". Your RMM can tell you the agent is on the box; only SentinelOne can tell you it is online, up to date, scanned, and on a policy that blocks rather than just detects. Connected, those get asked once and answered across the whole book of clients, ranked by site, instead of one console filter at a time.

The coverage follows how SentinelOne is really structured. Sites — the clients — with their licences and state, groups beneath them with the policy each inherits or overrides, and agents with everything the console holds about their health. Threats as incidents with a mitigation status, an analyst verdict and a timeline you can read end to end. Exclusions and blocklists with the scope they apply at, because a broad path exclusion at account scope is the kind of thing nobody remembers adding.

It also closes the loop with your RMM. When Automate or NinjaOne is connected too, a session can name the machines the RMM manages that carry no SentinelOne agent, and the agents SentinelOne has that the RMM has no record of — both halves of the onboarding gap. Nothing here acts on a threat or a machine; to isolate, quarantine or change a policy, a human uses the SentinelOne console. Write actions, when they exist, are switched on per customer after vetting.

What you’ll be able to ask

Here’s what’s coming.

>Which sites have agents that have not checked in for 30 days?
>What threats are still unresolved, and which clients are they on?
>Which machines in Automate have no SentinelOne agent?
>Are any sites running detect-only instead of protect?
>How many agents are behind the console's latest version, by site?
>What happened on that threat — walk me through its timeline.
>Which exclusions apply at account scope, and who added them?

Connecting

Connection preview.

How connecting will work

  1. 01In your SentinelOne console, create a service user (Settings → Users → Service Users) with the Viewer role on your account and an expiry date.
  2. 02Copy the API token when it is shown — it is shown once — and note your console URL, the sentinelone.net address you sign in at.
  3. 03Paste the console URL and the token on the connect page — it validates live against SentinelOne before saving.

Common questions

Asked before you had to ask.

Is there an AI skill for SentinelOne?

Yes — MSPStuff ships AI skills for SentinelOne, hosted in Switchboard. You connect your console once; sessions then answer questions about it in plain English. There is nothing to install to use Switchboard and no API token to hand your techs.

Is there a SentinelOne MCP server?

Yes. The SentinelOne integration is an MCP server that MSPStuff hosts and operates for you — Switchboard sessions call it with a credential you control, and every answer is traced to the real tool calls behind it.

Can it tell me which machines have no SentinelOne agent?

Yes, two ways. The console's own network discovery lists devices it sees with no agent, and with an RMM such as ConnectWise Automate or NinjaOne connected too, a session can name the machines the RMM manages that SentinelOne has no record of.

Can it change anything in SentinelOne?

No. Read-only today: no credential we issue carries a write scope, and no connected session can reach a write tool, so nothing here isolates a machine, kills a process, changes a policy or edits an exclusion. Write actions, when they exist, are switched on per customer after vetting. See the access section above for the exact guarantee.

Does this use the SentinelOne API?

Yes. The SentinelOne integration is an MSPStuff-hosted MCP server built on the SentinelOne Management API. Read-only today: no credential we issue carries a write scope, and no connected session can reach a write tool. You connect once with a service-user token you control; nothing is installed on your side.

Is there a SentinelOne connector for my AI?

Yes. Supported clients such as ChatGPT (OpenAI), Claude, Copilot and Cursor use the same MSPStuff MCP endpoint. Your admin controls access per person and data domain, and every call uses read-only permissions.

Get AI connected to your stack.

Apply for the beta: 14 days free on the Hosted plan against your own environment, read-only, every answer traced. Accepted MSPs get half off seats and client tenants for the first year. Dedicated infrastructure is priced separately.

MSPStuff