Getting StartedUpdated September 3, 20262 min read
SentinelOne exclusions for TAO
Add SentinelOne path and process exclusions (or exclusions policy) so TAO is not blocked or rolled back on Windows endpoints.
SentinelOne exclusions for TAO
SentinelOne agents may treat a new privileged service and its helpers as suspicious until an exclusions policy is in place. Use the shared list in TAO antivirus and EDR exclusions.
Console names differ by SentinelOne SKU and console generation. Have your SentinelOne administrator map the items below into the exclusions / allowlist policy for the TAO pilot scope.
Paths
C:\Program Files\Trustity\TAO\C:\ProgramData\Trustity\TAO\C:\ProgramData\Trustity\
Processes
tao-agent.exetao-gui.exetao-tray.exetao-lock.exetao-zerodevice.exeTrustity-Agent-Setup.exe
Service
TrustityAgent
Administrator checklist
- Create or edit an exclusions (or Interoperability) policy for the device group that will run TAO.
- Add path exclusions for the folders above.
- Add process / binary exclusions for the executables above when the policy type supports them.
- Ensure rollback / remediation will not undo an approved TAO install without an operator decision.
- Push the policy, confirm agents show the updated exclusion set, then install TAO from Deployment.
After a false positive
- In the SentinelOne console, locate the threat / suspicious activity for Trustity binaries.
- Mark as false positive / add to exclusions per your change process.
- Restore any quarantined files if required.
- Re-run
Trustity-Agent-Setup.exefrom a current Deployment download and verify SHA-256 when shown.
Validation
sc query TrustityAgent
Expect RUNNING, then confirm Online status and version in Managed devices.
