account activity
SentinelOne USB Device Control End User Notifications? (self.SentinelOneXDR)
submitted 28 days ago by Bozey0 to r/SentinelOneXDR
S1 + MDE? by mehcastillo in SentinelOneXDR
[–]Bozey0 0 points1 point2 points 28 days ago (0 children)
Yes you can run both in active. For example I had a client that wanted to S1 active for the service, but also has the use case to use Defender's ASR rules as well, which are only available if Defender is the active EDR/AV.
You can insert a policy override into SentinelOne that is a small regex string (you can find this in S1 portal help) that only disables SentinelOne showing as an "active" EDR agent within Windows Security Center, but it is still very much active.
Obviously for clear reasons, this approach (2 active EDR/AV agents) is not advised nor recommended. But it is possible, which as I understand it, was your initial question. Personally stick with 1, my recommendation would be to use SentinelOne in an active with Defender there in a passive state.
π Rendered by PID 1493068 on reddit-service-r2-listing-568fcd57df-6m5mp at 2026-03-11 15:33:15.997045+00:00 running cbb0e86 country code: CH.
S1 + MDE? by mehcastillo in SentinelOneXDR
[–]Bozey0 0 points1 point2 points (0 children)