In this article, you'll learn how to integrate SentinelOne's endpoint protection platform (EPP) with Real-Time Coaching. Once the integration is complete, data from SentinelOne will be available for use under the Coaching tab of your KnowBe4 Security Awareness Training (SAT) console. This data can be viewed in Real-Time Coaching reports and used to create detection rules for Real-Time Coaching categories. For general information about Real-Time Coaching, see our overview article.
Set Up the Integration in SentinelOne
Before you can set up this integration in Real-Time Coaching, you'll need to create a SentinelOne API key in your SentinelOne Cloud console by following the steps below:
- Log in to your SentinelOne Cloud console.
- Select Settings.
- Select the Users tab.
- Select Service Users.
- Select Actions, then select Create New Service User. A Create New Service User window will display.
- Enter a Name and Description, then select an Expiration Date.
- Select Next.
-
Select Account, then select Viewer for your account.
- Select Create User.
- Select Copy API Token to copy the API key to your keyboard, or select Download API Token to download a copy of the API key. Make sure to save this token somewhere you can easily access later. You'll need the key to set up the integration in Real-Time Coaching.
Locate the API Domain
Next, you'll also need to locate your API domain. This domain is displayed in the URL of your SentinelOne Cloud console.
For example, in the image below, the API domain is "usea1-partners.sentinelone.net".
You'll need this API domain to complete the setup process in the Set Up the Integration in Real-Time Coaching section below.
Set Up the Integration in Real-Time Coaching
Once you've created your SentinelOne API key and located your API domain, you can set up the integration in Real-Time Coaching by following the steps below:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the SentinelOne vendor tile and select Configure.
- Enter your API Key and the API Domain in the corresponding fields.
- Select Authorize.
Map Your Users
After you've finished integrating SentinelOne, you can map your users either through mapping rules (recommended) or through a CSV file upload. For more information about user mapping, see our user mapping article.
Manage Detection Rules
Once you've successfully authorized this integration, you can also manage SentinelOne detection rules from Coaching > Detection Rules. For a full list of available system detection rules for this vendor, see our System Detection Rules by Vendor article.
Delete the Integration in Real-Time Coaching
If you want to delete the SentinelOne integration from Real-Time Coaching, follow these steps:
- Log in to your KnowBe4 SAT console.
- Navigate to Coaching > Setup > Security Vendor Integrations.
- Locate the SentinelOne vendor tile and select Edit.
- Select Delete Integration near the bottom of the page.

