About this article
This integration automates the collection of evidence for vulnerability scan results and proof of subsequent vulnerability remediation within your committed SLAs
Vanta requires read-only to endpoints, applications, endpoint policies and console users
Estimated setup time: Less than 10 minutes
How it works
Vanta schedule periodically fetching to official the SentinelOne API
Use Cases
Connecting SentinelOne will allow Vanta to perform the following tests:
Ensure SentinelOne accounts are linked in Vanta
Ensure a continuous visibility into application and OS vulnerabilities across different OS
SentinelOne groups have a secure prevention policy
SentinelOne alerts are addressed
Critical vulnerabilities identified in packages are addressed
High vulnerabilities identified in packages are addressed
Low vulnerabilities identified in packages are addressed
Medium vulnerabilities identified in packages are addressed
Overview
Step-by-step summary of what the user will do in this article. This is only required if there are multiple steps / sections in the article. For instance, creating an API key, install the integration, and map user profiles
To complete this setup, you will:
Create an user and role for the integration
Install the integration following the step-by-step instructions
Requirements
Clear list of prerequisites:
Admin role in SentinelOne console
Connecting Vanta & SentinelOne
You can connect SentinelOne to Vanta to ensure user access to SentinelOne is managed following your company's policies and to ingest and display vulnerabilities on the vulnerabilities page.
If you have already integrated with SentinelOne and you need to update the permissions, you may skip many of the steps in the instructions below and edit the existing Vanta Client in SentinelOne.
Navigate to the Integrations Page in Vanta
Select the Available tab
Search for SentinelOne
Click on Connect
Select the Product you would like to integrate
Configure RBAC (role-based access control permissions)
Login to SentinelOne
Navigate to the Settings, Users, Roles page in the SentinelOne console
Either create a new role or modify an existing role to have the following permissions
Endpoints: View
Applications: View
Applications: View Risks
Console Users: View
For the Alerts Management product, you need the next additional permissions:
STAR Rule Alerts: View
Endpoint Policy: View
Create Service User
Navigate to the Service Users tab within the Settings, Users page
Click on Actions and then Create New Service User.
Provide a name, description, and expiration date.
Press next
Select the account scope.
Select all relevant accounts and ensure they are set to the role configured in the previous Configure RBAC Permissions step.
Click on Create User.
Please note that this is the only time you can see the generated API token. If you close the dialog, you will no longer be able to access the service account and must create another one.
Keep the dialog open, or copy it for the next step!
Save API Token Details
Copy the displayed API token and paste into the appropriate box
Enter the Service Account name and the Base URL
Select Done
Permissions
Vanta accesses the following data from your SentinelOne account:
Vanta will be able to view:
Data about your users
Data about your user details
Data about your user groups
SentinelOne Monitored Host
SentinelOne Prevention Policy
SentinelOne Vulnerability Management Vulnerability
Vanta will be able to do:
Nothing