SentinelOne
Bring your SentinelOne Singularity EDR into Dex - browse agents, threats, activities, and groups per customer Site in plain language.
Dex connects to the SentinelOne Singularity Management API so you can run your EDR fleet conversationally. Read-only on this first ship: list agents, threats, activities, and groups, and read Site details across your console. SentinelOne is built for MSSPs and deploys as an MSP global app - one shared ApiToken (a Service User) across the console, with each Dex tenant confined to its own SentinelOne Site via site_id. The framework forces the Site scope onto every collection read so a scoped customer only ever sees its own agents and threats.
What Dex does with SentinelOne
Dex handles both admin workflows and employee self-service — all policy-guardrailed and audit-logged.
For admins (Dex Pro)
- List SentinelOne agents for a Site and review their details
- Browse threats detected on a Site
- Review the activity log for a Site
- List the groups configured on a Site
- Read Site details by id, and list every Site from the MSSP master connection
- Deploy as an MSP global app - one shared ApiToken, each customer confined to its own SentinelOne Site via site_id
Just ask Dex
Your team types a request in plain language. Dex investigates, plans, and executes — with the right guardrails.
Admin prompts
- >List the SentinelOne agents for the Contoso Site
- >Show me the threats detected on this Site
- >What activity has SentinelOne logged for this Site recently?
- >List the groups configured on this Site
- >Show me every Site on the SentinelOne console
Policy actions
Every action Dex can take on SentinelOne is declared, scoped, and guardrailed. Admins control which apply, who approves them, and whether they're limited to self-service.
| Action | What it does |
|---|---|
sentinelone_list_sites | List every SentinelOne Site (master connection only) |
sentinelone_get_site | Read one SentinelOne Site by id (path-forced to this tenant on a scoped child) |
sentinelone_list_agents | List SentinelOne agents for this Site (forced siteIds= on a scoped child) |
sentinelone_list_threats | List SentinelOne threats for this Site (forced siteIds=) |
sentinelone_list_activities | List SentinelOne activities for this Site (forced siteIds=) |
sentinelone_list_groups | List SentinelOne groups for this Site (forced siteIds=) |
How to configure SentinelOne
Onboarding takes minutes. Dex validates your credentials before saving them.
Setup steps
- 1In the SentinelOne console, go to Settings > Users > Service Users and create a Service User (or use My User > API Token).
- 2Copy the ApiToken value shown once, and note your console hostname (e.g. usea1-partners.sentinelone.net).
- 3In Dex, enable the SentinelOne integration and paste the ApiToken and console host.
- 4Leave site_id blank on the MSP-master connection so Dex can look up each customer Site, then set the Site id on each tenant connection.
- 5Dex validates the credentials with a live read before saving and confirms the Site id against the master before scoping a tenant.
Credentials required
- api_token
- SentinelOne ApiToken from a Service User (Settings > Users > Service Users); stored as a secret and never surfaced
- host
- SentinelOne console hostname ending with .sentinelone.net (e.g. usea1-partners.sentinelone.net); strip https:// and any path
- site_id
- This tenant's SentinelOne Site id (large numeric digit string) - leave blank on the MSP-master connection, set per tenant for Site scoping
Requirements
- •A SentinelOne Singularity console (typically an MSSP or partners host ending with .sentinelone.net)
- •A Service User ApiToken with permission to read Sites, agents, threats, activities, and groups
- •Read-only on this first ship - mass remediate, disconnect, and shutdown writes are not available until site-scoped fail-closed write paths are verified live
- •Deploy as an MSP global app: one shared ApiToken, each Dex tenant confined to its own Site via site_id (by-id agent/threat/activity/group reads are default-denied on a scoped child)
Related integrations
- Security & Backup
CrowdStrike Falcon
Triage Falcon detections and respond to hosts conversationally - inventory sensors, isolate compromised machines, and run Real Time Response.
Learn more → - Security & Backup
Huntress
Run Huntress managed security conversationally - fleet health, SOC-reviewed incident triage, usage and billing - without dashboard hopping.
Learn more → - RMM & Endpoint
Action1
Run Action1 patch, software, and endpoint operations from plain-language requests.
Learn more →
See Dex run SentinelOne
Book a 30-minute walkthrough with our team and see how autonomous IT works in your environment — or get started for free.