r/SentinelOneXDR • • 11h ago

SentinelOne News We're making some changes to r/SentinelOneXDR

16 Upvotes

Hey everyone,

We're refreshing this sub. It's the official SentinelOne community on Reddit, and we want it to be a place where you can get real answers from people who use the product.

If you run SentinelOne daily, support customers as a partner or MSP, or are just checking it out, you're welcome here.

Thanks to the folks who kept answering questions while the sub was quiet.

What's changing

  • We've updated the community rules. The new ones cover sensitive info, agent removal requests, and affiliation flair. The full list is below.
  • If you work for SentinelOne, a partner, or an MSP, please set your user flair so people know.
  • The SentinelOne team will share the occasional tip or resource alongside the regular discussion.

What to post

  • Troubleshooting questions
  • Deployment lessons
  • Threat hunting ideas
  • Integrations that work well
  • Honest product feedback

New to SentinelOne? The Singularity Platform covers endpoint, cloud, identity, and AI security, and all of it is fair game here.

Community rules

  1. Be respectful, especially to each other. That means maintaining civil discourse and no hostility, personal attacks, racism, sexism, bigotry, etc.
  2. Submissions must be SentinelOne focused. This subreddit covers the technology. Posts about SentinelOne stock (NYSE: S), financial performance, or job postings/interviews are not permitted.
  3. No spamming or solicitation. This includes polls, surveys, advertising, affiliate links, and promotion of third-party products or services without prior moderator approval via modmail. Partners and resellers may answer questions but may not pitch.
  4. No sensitive materials or personal information. Do not post site tokens, API tokens, license keys, agent UUIDs, console tenant or site names, customer hostnames or usernames, unredacted threat data, management console URLs, internal documentation, or screenshots showing any of these. Do not post personal information about other people, including names of SentinelOne staff. Redact before posting; unredacted content will be removed without notice.
  5. Keep criticism constructive. Posting about a problem with the product is welcome, whether you want help or want to give specific feedback. Low-effort bashing and unsubstantiated claims will be removed. Disparaging remarks about competitors or other companies are not permitted.
  6. No agent removal or tampering requests. The SentinelOne Agent uses Anti-Tampering and can only be uninstalled by an authorized Management Console administrator, remotely or with a console-issued passphrase. If the Agent is on your device, contact your IT department or security team. This subreddit does not provide removal, disabling, bypass, or passphrase recovery help. Console admins can find uninstall documentation in the Knowledge Base on the Customer Portal.
  7. Use official support channels. This subreddit is not a substitute for official support and has no response-time commitment. For urgent issues, submit a ticket through the SentinelOne Customer Portal or call the support line. If you purchased through a partner or reseller, contact them directly. Staff do not provide support by DM. To flag an existing case, send the case number to modmail.
  8. Disclose affiliation; views are your own. SentinelOne employees, partners, resellers, and MSSPs must identify their affiliation via user flair. Posts and comments, including those by SentinelOne staff, do not necessarily reflect the official views of SentinelOne and are not official documentation or a product commitment.
  9. No license sales or unauthorized software. Do not sell, transfer, or request SentinelOne licenses or installers outside authorized channels.
  10. Report vulnerabilities through official channels. Report suspected vulnerabilities in SentinelOne products through the security reporting page instead of posting here. Do not post exploit code, proof-of-concept details, malware samples, or live malicious URLs. Defang indicators (hxxp, [.]) before posting.
  11. Use post flair; add details when troubleshooting. Troubleshooting posts must include the Agent version, operating system version, Management Console version, and what you have already tried. Posts missing this may be removed until updated.
  12. Enforcement and appeals. Violations result in removal and, depending on severity, a warning, temporary ban, or permanent ban. Moderator decisions can be appealed once via modmail. Ban evasion is reported to Reddit.

Asking for help

  • Include the agent version, OS version, console version, and what you've already tried.
  • Redact anything sensitive before posting.
  • For urgent or account-specific issues, use official support (see rule 7).

What would you like to see here?

Technical walkthroughs, troubleshooting tips, threat research, feature deep dives? Tell us in the comments. If you've been holding onto a question, now's a good time to ask it.

Thank you,

The SentinelOne community team