Uninstalling SentinelOne MAC Agent through Recovery Mode

Description

This article explains how to remove the macOS Agent using the Terminal in Recovery Mode. This is used if the macOS Agent has tamper protection enabled but the passphrase is unavailable. This is also used if an incompatible Agent was installed on the endpoint.

Resolution

To uninstall the macOS Agent in macOS Recovery Mode:

1. During system start, press the Command and R keys (or leave the power button down on M1 Macs) to boot into macOS Recovery Mode.

2. Select the language, if prompted, and User > Next > Password (or Options > Continue > User > Next > Password on M1 Macs).

3. From the left-hand corner, click the Apple logo > Startup Disk

Image

4. Choose the Macintosh HD volume and unlock... > Password.

5. Click Startup Disk and select Quit Startup Disk.

6. Click Utilities > Terminal to launch the Terminal app within Recovery Mode.

Image

7. Uninstall the Agent:

• If the Agent version is 4.4.x or higher, run:

Image

• If the Agent version is 4.3.x or lower, run: 

Image

Note: The Macintosh HD directory could be Macintosh HD - Data

8. Restart the computer.

Related Articles

  • Integrating with 3rd Party Syslog and Threat Detection Platforms
    Read More
  • How to Generate a Capture Client (SentinelOne) API Key Using a Service User
    Read More
  • Integrating SonicWall Capture Client with SonicWall Firewalls
    Read More
not finding your answers?