Integrate SentinelOne with Zero Trust Network Access
In this topic, you will find general instructions on how to integrate the SentinelOne console with Portnox™ Zero Trust Network Access.
Modify your identity provider configuration to support SentinelOne
SentinelOne SAML integration requires your identity provider to send claims that identify the user and the SentinelOne role to assign to the user. In this task, you will create a new identity provider configuration especially for SentinelOne and add these claims to it.
-
We strongly recommend that you create a separate identity provider configuration just for SentinelOne, rather than reusing an existing one. However, if only a few users need SentinelOne access, you may not need to do this. Instead, add those users manually in SentinelOne before they sign in with SSO. Manually added users don’t need a role ID in the claims (see below), so in that case reusing an existing configuration may be less work.
-
If you want SentinelOne to create new users automatically (auto-provision), it needs your identity provider to send a role identifier so that it knows which SentinelOne role to assign the user. The simplest approach is to send the same role for every user you want to automatically create in SentinelOne, and then move users into the appropriate SentinelOne role using the SentinelOne console. This guide shows that simple approach as a starting point.
If you want roles to be assigned automatically based on group/role membership in your identity provider, you can send a different role identifier for each group/role in your identity provider. However, that setup depends on your own environment, so we can’t provide exact steps for it.
-
SentinelOne accepts either a role claim (matches a role by exact, case-sensitive name) or a role_id claim (matches a role by its numeric ID), but never both at the same time. Sending both, or sending a claim with more than one value, causes SentinelOne to reject the login even if the role_id value is correct.
If you use an existing configuration that already sends a role claim for another application, adding role_id to it breaks SentinelOne login, and reusing that existing role claim instead would require your SentinelOne role names to exactly match the role names expected by the other application. A separate configuration avoids both problems.
Create a Portnox Cloud application configuration
In this step, you will create a configuration in Portnox Cloud that will contain all the information necessary to integrate with SentinelOne.
Enable SSO access to SentinelOne and set up the domain
In this section, you will access the SentinelOne SSO configuration page and set up the allowed SSO domain.
Copy configuration values from the Portnox tab to the SentinelOne tab
In this section, you will copy the values displayed by Portnox Cloud and paste them in the relevant fields in the SentinelOne SSO configuration page.
Copy configuration values from the SentinelOne tab to the Portnox tab
In this section, you will copy the values displayed in the SentinelOne SSO configuration page, and paste them in the relevant fields in Portnox Cloud.
Finalize the configuration
In this section, you will finalize the configuration in Portnox Cloud and SentinelOne.
-
Finalize the configuration in the Portnox tab.
-
Finalize the configuration in the SentinelOne tab.
Result: You have configured SentinelOne to be accessible using Portnox Zero Trust Network Access.































