0% found this document useful (0 votes)
1K views

Installing and Upgrading The Windows Agent Sentinel One Using An MSI Package

The document provides instructions for installing and upgrading the Windows agent using an MSI package. It describes supported installation and upgrade methods from different agent versions to newer versions using MSI packages. It also provides details on installing and configuring the MSI package through various methods like GPO, SCCM, manually or through the management console.
Copyright
© © All Rights Reserved
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
1K views

Installing and Upgrading The Windows Agent Sentinel One Using An MSI Package

The document provides instructions for installing and upgrading the Windows agent using an MSI package. It describes supported installation and upgrade methods from different agent versions to newer versions using MSI packages. It also provides details on installing and configuring the MSI package through various methods like GPO, SCCM, manually or through the management console.
Copyright
© © All Rights Reserved
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 18

23/01/2024, 23:20 Installing and Upgrading the Windows Agent Using an MSI Package

Home (/s/) Knowledge Base (/s/knowledge-base) Digital Guided Onboarding M

SEARCH SENTINELONE

Search...

Getting Started All Categories (/s/knowledge-base)


> Working With The Agent (/s/topic/0TO69000000as1OGAQ)

Agent Requirements > Installing Agents (/s/topic/0TO69000000as2EGAQ)


> Installing Agents On Windows Endpoints
Release Notes (/s/topic/0TO69000000as5OGAQ)
> Installing and Upgrading the Windows Agent Using an MSI Package
Working With Endpoints (/s/article/000005520)

Using The Management Console


Article Detail (?tab… Attachments (?tabs…

Working With The Agent

Managing Agents Installing and Upgrading the


Support For UWF-Protected De…
Windows Agent Using an MSI
Installing Agents

Installing Agents On Endpoints


Package
Installing Agents On Window… Last Updated: Jan 23, 2024

Installing Agents On macOS E…

Sentinelctl

API Tips  Important


The macOS Agent Do not modify or try to customize MSI installation
packages provided by SentinelOne. If you do,
Mobile Management installation and future upgrades will fail.

Cloud Workload Security


You can also use the MSI package to run a new installation, or
Threat Detection And Investigati… upgrade an Agent installed from an MSI installer or from an EXE
installer. The method used depends on the source Agent version
Deep Visibility
and the target Agent version.

Skylight - Visibility Enhanced

https://community.sentinelone.com/s/article/000005520 1/18
23/01/2024, 23:20 Installing and Upgrading the Windows Agent Using an MSI Package

SentinelOne uploads MSI packages to Consoles. Use the 32-bit


Identity And Deception
version to install on a 32-bit OS, and the 64-bit version to install
Cloud Data Security on a 64 bit OS.

If you upgrade endpoints locally (not through the Management


Integrations And Interoperability
Console), read Upgrading Agents with a Local Upgrade
(https://community.sentinelone.com/s/article/000005396)for
Troubleshooting Management An…
instructions.

New Installations from an MSI Package

Agent
Supported New Installation Methods
Version
Getting Started
Manually
Agent Requirements
3.6.2+
External deployment systems (including
Release Notes
GPO)

Working With Endpoints

Using The Management Console


Upgrading Agents Installed from an MSI Package with an MSI
Package (MSI to MSI)
Working With The Agent

Managing Agents Source


Target Agent Supported MSI to MSI
Support For UWF-Protected De…
Agent
Version Upgrade Methods
Version
Installing Agents

Installing Agents On Endpoints


Manually
Installing Agents On Window…

Installing Agents On macOS E… External deployment


Sentinelctl 3.6.2+ 4.2.5+ systems except GPO

API Tips
Remotely from the
The macOS Agent
Console
Mobile Management

Cloud Workload Security


Upgrading Agents Installed from an EXE Package with an MSI
Threat Detection And Investigati… Package (EXE to MSI)

Deep Visibility

Skylight - Visibility Enhanced

Identity And Deception

Cloud Data Security

Integrations And Interoperability

https://community.sentinelone.com/s/article/000005520 2/18
23/01/2024, 23:20 Installing and Upgrading the Windows Agent Using an MSI Package

Troubleshooting Management An… Source


Target Agent Supported EXE to MSI
Agent
Version Upgrade Methods
Version

Manually

External
deployment
4.1.5, 4.2.5+ with
systems except
4.1.6, or Management
GPO
4.2.2+ Version Kauai SP3+

Remotely from the


Management
Console

This article contains these topics:

Installation Methods.

Upgrade Methods.

Download and run the MSI file.

To install the MSI with GPO.

To create a Deployment MSI Application in SCCM.

To install the MSI without disabling Windows Defender.

To Upgrade the Agent from the Management Console.

Troubleshooting

Installation Methods

Manually: Download and run the MSI file or open it from


the CLI.

From external deployment systems, such as SCCM and


GPO.

Upgrade Methods

https://community.sentinelone.com/s/article/000005520 3/18
23/01/2024, 23:20 Installing and Upgrading the Windows Agent Using an MSI Package

There are various ways to upgrade your Agents using an MSI


package. The method you use depends on the versions of the
source Agent and the target Agent.

Manually: Download and run the MSI file or open it from


the CLI.

From an external deployment system, such as SCCM. .

Remotely from the Management Console.

Download and run the MSI file

1. In the Sentinels toolbar, click Packages.

2. Click the Download icon next to the File Name of the MSI
package you want to install.

3. Double-click the file.

From version 4.5.1 double-clicking the MSI file opens a UI


Wizard.

a.  Note

A Site or Group token is only required when


you install the Agent. If used during an
upgrade, it is ignored.

b. Enter the Site/Group Token.

https://community.sentinelone.com/s/article/000005520 4/18
23/01/2024, 23:20 Installing and Upgrading the Windows Agent Using an MSI Package

c. Optional: Click the Advanced button to select a


customized path for the Agent installation and a customer
identifier.

A progress bar shows the progress of the installation.

To install the MSI with GPO

Note: SentinelOne only supports the site token property of the


MST file. SentinelOne does not support its other properties.

Before you begin, download the MSI file and get the Site token.

1. Launch ORCA and open the Agent MSI.

When deploying the Agent using a group policy, you need to


create a configuration file to include your unique parameters.
You can access the Orca installer for Windows 7, Windows 8,
Windows 8.1 and Windows 10 by downloading the Windows
SDK. Agent files are architecture specific. You must create
separate transform files for 32 bit and 64 bit agents. You can
download the Orca from https://docs.microsoft.com/en-
us/windows/win32/msi/orca-exe
(https://docs.microsoft.com/en-us/windows/win32/msi/orca-
exe).

https://community.sentinelone.com/s/article/000005520 5/18
23/01/2024, 23:20 Installing and Upgrading the Windows Agent Using an MSI Package

2. Click Transform > New Transform.

3. In the loaded SentinelInstaller window, click Tables >


Property. Right-click the other pane and select Add Row.

4. For the property name, enter SITE_TOKEN , and enter its


value - the Site Token string.

https://community.sentinelone.com/s/article/000005520 6/18
23/01/2024, 23:20 Installing and Upgrading the Windows Agent Using an MSI Package

 Note

A Site or Group token is mandatory when you


install the Agent. It is unnessecary to use a Site or
Group token when you upgrade the Agent, and if
you use one, it is ignored.

5. Click Transform > Generate Transform.

6. Save the MST file with the MSI file, in a path that all the target
endpoints can access.

7. From your AD Domain Server > Server Manager, click Tools >
Group Policy Management.

8. Right-click the domain and select Create a GPO in this


domain and Link it here.

9. In the window that opens, enter a name for the new policy and
click OK.

https://community.sentinelone.com/s/article/000005520 7/18
23/01/2024, 23:20 Installing and Upgrading the Windows Agent Using an MSI Package

10. In the Group Policy Manager window, right-click the new


policy and select Edit.

11. In the window that opens, expand Computer Configuration >


Policies > Software Settings. Right-click Software Settings
and select New > Package.

12. In the window that opens, select the SentinelOne MSI.

13. In the Deploy Software window, make sure Advanced is


selected.

https://community.sentinelone.com/s/article/000005520 8/18
23/01/2024, 23:20 Installing and Upgrading the Windows Agent Using an MSI Package

14. Click OK.

Wait for the Sentinel Agent Properties window to open.

15. Click Modifications > Add.

16. Select the MST file. Wait for it to load. Click OK.

17. On the endpoints, in cmd, run: gpupdate /force

18. When the policy is updated, enter Y to restart the endpoint.

https://community.sentinelone.com/s/article/000005520 9/18
23/01/2024, 23:20 Installing and Upgrading the Windows Agent Using an MSI Package

19. When the user logs in, see that the Agent is installed.

To create a SentinelOne Deployment MSI


Application in SCCM:

 Note

For instructions on how to upgrade a Windows Agent


with SCCM using a PowerShell script, see Upgrading
Agents with a Local Upgrade
(https://community.sentinelone.com/s/article/00000
5396).

Before you begin, download the MSI file, if you are installing the
Agent get the Site token, and create an SCCM collection
(https://docs.microsoft.com/en-
us/sccm/core/clients/manage/collections/create-collections) of
the endpoints on which you will install the new Agent.

1. Launch SCCM.

2. Click Software Library > Application Management.

3. Right-click Applications and select Create Application.


https://community.sentinelone.com/s/article/000005520 10/18
23/01/2024, 23:20 Installing and Upgrading the Windows Agent Using an MSI Package

4. From the Create Application Wizard, select Windows


Installer (*.msi file) and enter the location.

Click Next.

5. On the General Information page, in Name, enter: Sentinel


Agent .

https://community.sentinelone.com/s/article/000005520 11/18
23/01/2024, 23:20 Installing and Upgrading the Windows Agent Using an MSI Package

6. Click Browse to select the MSI file.

7. In the wizard, enter the Site Token as a command-line


argument.

For example:

msiexec /i "<path to SentinelInstaller.msi>" /q SITE_TOK

 Note

A Site or Group token is mandatory when you


install the Agent. It is unnessecary to use a Site or
Group token when you upgrade the Agent, and if

https://community.sentinelone.com/s/article/000005520 12/18
23/01/2024, 23:20 Installing and Upgrading the Windows Agent Using an MSI Package

you use one, it is ignored.

8. Click Next and complete the wizard.

To install the MSI without disabling Windows


Defender:

By default, the Windows Agent registers with Windows Security


Center (WSC) as anti-virus protection. When SentinelOne is
registered, Windows disables Windows Defender.

Note: SentinelOne does not recommend that you disable WSC.


You can install the Agent with a switch to not register with WSC
and to keep Windows Defender enabled.

Install the MSI with this command-line argument:

SentinelInstaller.msi /q SITE_TOKEN="string" WSC=false

 Note

A Site or Group token is mandatory when you


install the Agent. It is unnessecary to use a Site
or Group token when you upgrade the Agent,
and if you use one, it is ignored.

To Upgrade the Agent from the Management


Console

1. In the sidebar, click Sentinels.

Endpoints opens.

2. Select endpoints to update.

3. Click Actions > Agent Version Changes > Update Agent.

https://community.sentinelone.com/s/article/000005520 13/18
23/01/2024, 23:20 Installing and Upgrading the Windows Agent Using an MSI Package

4. Select an MSI package.

5. Click Update Agent.

MSI Installer Options

Action and Description Opt

Silent installation (no UI, no user interaction, no reboot). /q, /

With a Silent installation switch, you can use an optional


flag for endpoint reboot:

Install the Agent without an automatic reboot. Use


for mass deployment when you send a message to /NO
users to restart their computers at the end of the
day, or if you have a reboot scheduled for a specified /FO
time.

Always reboot.

Install the Agent with the UI disabled (no tray icon or


UI=
notifications).

Disable Agent logging. AG

https://community.sentinelone.com/s/article/000005520 14/18
23/01/2024, 23:20 Installing and Upgrading the Windows Agent Using an MSI Package

Action and Description Opt

Assign Agents to a Site or Group.

 Note

A Site or Group token is mandatory when you SIT


install the Agent. It is unnessecary to use a
Site or Group token when you upgrade the
Agent, and if you use one, it is ignored.

Customize the path for Agent database, logs, and large


data files.

Requirements

The path must be in English, 150 characters or less.

The path must be a fixed drive (it cannot be a USB or INS


other removable media), and it must be NTFS.

If the path is not on the System drive, it must have at


least 4 GB free space.

(Supported from Agent versions 3.6)

Set a proxy server between the Agent and its


Management.

Mode valid values:

auto = use the Windows LAN settings (PAC file)

system = use Other proxy (not from OS) SER


configured in the local Agent

user ,fallback[:port] = user mode on Windows

http:// {IP | FQDN}:[ port]

Set credentials to authenticate with the Management


SER
proxy.

https://community.sentinelone.com/s/article/000005520 15/18
23/01/2024, 23:20 Installing and Upgrading the Windows Agent Using an MSI Package

Action and Description Opt

Set a proxy server between the Agent and the Deep


Visibility™ EDR data server.

Mode valid values:

single = use the same proxy for Management and


for Deep Visibility™

auto = use the Windows LAN settings (PAC file)


IOC

system = use Other proxy (not from OS)


configured in the local Agent

user ,fallback[:port] = user mode on Windows

http:// {IP | FQDN}:[ port]

Set credentials to authenticate with the Deep Visibility™


IOC
proxy.

Prevent fallback to direct communication if the proxy is


not available.

Important! If the Management proxy or the Deep FOR


Visibility™ proxy is configured with user mode, do not
use Force Proxy.

Set the Agent installation to disable (true) or not disable


WS
(false) Windows Defender.

Add a user-defined Identifier string to the endpoint. CUS

Install on Virtual Desktop Infrastructure or VMs with a


Golden (Master) Image.

Important: This property is NOT recommended for all VM


installation types. See Installing Windows Agents on VM VD
or VDI
(https://community.sentinelone.com/s/article/000005519)
for when this property is recommended.

Important for all endpoints: We recommend that you enhance


endpoint security with protection against physical theft and
hacking (such as unauthorized disk mount modification). Enable

https://community.sentinelone.com/s/article/000005520 16/18
23/01/2024, 23:20 Installing and Upgrading the Windows Agent Using an MSI Package

full disk encryption, apply OS patches, and maintain measures


according to your vendor recommendations and corporate
policies.

Troubleshooting

To troubleshoot issues, see the MSI installation log or call


Support.

The MSI installation log is named MSI <string>.log .

If you run the installation/upgrade from a specific user, the


installation log will be in the folder %temp% .

If you run the installation/upgrade from a system user (like


from the Management Console) the installation log will be
in the folder %systemroot%\temp .

Was this article helpful? Yes No

Related Articles

Updating the Windows Agent 22.1+ with the New


Installation Package
(/s/article/000005389)

Uninstalling the Windows Agent Using the


SentinelOneInstaller Package
(/s/article/000005378)

Installing Windows Agent 22.1+ with the New Installation


Package
(/s/article/000005521)

Installing the Windows Agent


(/s/article/000005515)

New Windows Installation Package FAQ


(/s/article/000005391)

(https://twitter.com/SentinelOne) 444 Castro Street Suite 400 Mountain View, CA 94041


(https://www.linkedin.com/company/sentinelone/) +1-855-868-3733

https://community.sentinelone.com/s/article/000005520 17/18
23/01/2024, 23:20 Installing and Upgrading the Windows Agent Using an MSI Package

(https://www.facebook.com/SentinelOne/) [email protected]
(https://www.youtube.com/c/Sentinelone-inc) (mailto:[email protected])

©2024 SentinelOne, All Rights Reserved


Privacy Policy (https://www.sentinelone.com/legal/privacy-
policy/)
Terms of Service
(https://www.sentinelone.com/legal/terms-of-service/)
Customer Community Terms of Use
(https://www.sentinelone.com/legal/customer-
community-terms-of-use/)

https://community.sentinelone.com/s/article/000005520 18/18

You might also like