Skip to main content
Forge connects SentinelOne management and Data Lake APIs to bring endpoint identity, installed applications, security activity, and process and network evidence into your AI estate. SentinelOne-backed devices receive agentless Forge coverage through the agent already deployed in your environment. Forge uses RemoteOps for endpoint setup, inventory, validation, repair, credential rotation, and removal.

Sources

Management data and Data Lake telemetry use separate credentials and are reported as separate capability lanes.

Connection

Setup

  1. Open Settings → Integrations → SentinelOne and save the management console URL and service-user token.
  2. Add the SentinelOne Data Lake key only when process, network, DNS, and event telemetry are required.
  3. Test tenant scope, endpoint inventory, applications, threats, activity, telemetry, and response permissions independently.
  4. Run a sync to import endpoints, bind endpoint-user evidence, and collect each enabled telemetry lane.
  5. Enable RemoteOps for devices that will use SentinelOne as their Forge endpoint-management channel.

Sync phases

A sync ends as completed, partial, failed, timed_out, canceled, or abandoned. Partial results remain visible with their lane-specific reason. Forge reconciles SentinelOne endpoints with directory and endpoint sources so the same computer appears as one device with complete source history. Each sync keeps successful data available while clearly identifying anything that needs attention.

Health

For every lane, Forge records operation key, category, status, observed count, page count, permission state, failure class, and recommended next action.