This article guides you through transferring your SentinelOne console management to Zscaler MDR. This is typically necessary after completing a SentinelOne proof of concept or if you were previously managed by a different partner.
Prerequisites
You must have a SentinelOne account
You must have purchased Cloud Funnel from SentinelOne for the Zscaler MDR account
Step 1: Receive SentinelOne Site Token from Zscaler MDR
Zscaler MDR will create a new SentinelOne console for you in our managed instance and provide the site token.
The Zscaler MDR team will complete the required steps to provide you with a new SentinelOne account.
The Zscaler MDR team will create a Console User for you to gain access to it with the Admin role.
The Zscaler MDR team will provide you with the site token and this help article. You’ll use this in a later step.
Step 2: Export settings from your current SentinelOne console and import them to your new SentinelOne console
Review exclusions and blacklist items in your current SentinelOne console.
Export Exclusions manually (recreate on target Console) or through the Exclusion Tool.
For more information on this process, see the SentinelOne User Guide.
Import Exclusions to the new account manually (recreate on target Console) or through the Exclusion Tool.
For more information on this process, see the SentinelOne User Guide.
Copy over the policy configuration settings from the source to the target console.
Step 3: Migrate agents to the new Zscaler MDR managed console
Note: Dynamic groups will not require individual site or group tokens as they will filter automatically to their matching site or group. For everything else, you will likely go group by group. Additionally, all threats must be resolved in the current SentinelOne console, and an endpoint must be online to migrate it.
In the group or site, select Endpoint name.
Actions will automatically highlight; click Actions.
Type and then search for Migrate agent.
Input the site token provided by your Zscaler MDR contact from Step 1.3.
Click through prompts to initiate migrations, and a box will appear briefly at the top of Atlas, telling you how many agents will be migrated.
Repeat the above steps until all groups and sites have been migrated.