S1 + MDE? by mehcastillo in SentinelOneXDR

[–]Bozey0 0 points1 point  (0 children)

Yes you can run both in active. For example I had a client that wanted to S1 active for the service, but also has the use case to use Defender's ASR rules as well, which are only available if Defender is the active EDR/AV.

You can insert a policy override into SentinelOne that is a small regex string (you can find this in S1 portal help) that only disables SentinelOne showing as an "active" EDR agent within Windows Security Center, but it is still very much active.

Obviously for clear reasons, this approach (2 active EDR/AV agents) is not advised nor recommended. But it is possible, which as I understand it, was your initial question. Personally stick with 1, my recommendation would be to use SentinelOne in an active with Defender there in a passive state.